The LastLogon and LastLogonTimeStamp attributes can help you to decide if an Active Directory user account or computer account is active or inactive.
Powershell to find inactive accounts Active Directory for 90 days or longer.
Another Powershell script to find inactive accounts for 90 days or longer.
In Order to Disable a User account, use this to see what accounts you are going to be disabling:
The below powershell lists all the disabled Active Directory users:
Search-ADAccount and list the selected properties of all disabled Active Directory users:
Find Disabled Active Directory Users from specific OU:
In Order to Export Disabled Active Directory Users to CSV using Powershell user below cmdlet:
You can check the below cmdlets which will export data in the following order – Givenname, Surname, SamAccountname, PrimarySMTPAddress
In Order to Move Disabled Active Directory Users and Computers to New OU
Let’s assume you have two OU’s in Active Directory; DisabledUserAccounts and DisabledComputerAccounts.
By following above steps you can easily find and remove Active Directory inactive user and computer accounts or you can move them to different OU by using Powershell.