The essentials
Quick reference
One focused task per row. Jump to the related section for complete, working examples.
| Use | Syntax | Examples |
|---|---|---|
| Check the AD module | Get-Module -ListAvailable ActiveDirectory |
Select-Object Name, Version, Path | View examples |
| Identify domain context | Get-ADDomain -Identity 'corp.example.com' -Server `
'dc01.corp.example.com' | View examples |
| Resolve one user | Get-ADUser -Identity 'alice.chen' -Properties `
mail,Enabled,LastLogonDate -Server `
'dc01.corp.example.com' | View examples |
| Search users in an OU | Get-ADUser -Filter 'Enabled -eq $true' -SearchBase `
'OU=People,DC=corp,DC=example,DC=com' -Server `
'dc01.corp.example.com' | View examples |
| Find inactive users | Search-ADAccount -UsersOnly -AccountInactive -TimeSpan `
(New-TimeSpan -Days 90) -SearchBase `
'OU=People,DC=corp,DC=example,DC=com' | View examples |
| Preview a disabled user | New-ADUser -Name 'Alice Chen' -SamAccountName `
'alice.chen' -Path `
'OU=People,DC=corp,DC=example,DC=com' -Enabled:$false `
-WhatIf | View examples |
| Preview a user update | Set-ADUser -Identity 'alice.chen' -Department 'Finance' `
-Title 'Analyst' -Server 'dc01.corp.example.com' `
-WhatIf | View examples |
| Preview account disable | Disable-ADAccount -Identity 'alice.chen' -Server `
'dc01.corp.example.com' -WhatIf | View examples |
| Preview moving an object | Move-ADObject -Identity $user.ObjectGUID -TargetPath `
'OU=Staged,DC=corp,DC=example,DC=com' -Server `
'dc01.corp.example.com' -WhatIf | View examples |
| Inspect a group | Get-ADGroup -Identity 'GG-Finance-Readers' -Properties `
GroupCategory,GroupScope,ManagedBy -Server `
'dc01.corp.example.com' | View examples |
| Expand nested members | Get-ADGroupMember -Identity 'GG-Finance-Readers' `
-Recursive -Server 'dc01.corp.example.com' | View examples |
| List principal groups | Get-ADPrincipalGroupMembership -Identity 'alice.chen' -Server 'dc01.corp.example.com' |
Sort-Object Name | View examples |
| Preview group creation | New-ADGroup -Name 'GG-Finance-Readers' -GroupScope `
Global -Path 'OU=Groups,DC=corp,DC=example,DC=com' `
-WhatIf | View examples |
| Preview adding a member | Add-ADGroupMember -Identity $group.ObjectGUID -Members `
$user.ObjectGUID -Server 'dc01.corp.example.com' `
-WhatIf | View examples |
| Preview removing a member | Remove-ADGroupMember -Identity $group.ObjectGUID `
-Members $user.ObjectGUID -Server `
'dc01.corp.example.com' -WhatIf | View examples |
| Search computer accounts | Get-ADComputer -Filter `
'OperatingSystem -like "Windows Server*"' -SearchBase `
'OU=Servers,DC=corp,DC=example,DC=com' | View examples |
| Preview a computer account | New-ADComputer -Name 'APP-042' -Path `
'OU=Staging,OU=Servers,DC=corp,DC=example,DC=com' `
-Enabled:$false -WhatIf | View examples |
| Find inactive computers | Search-ADAccount -ComputersOnly -AccountInactive `
-TimeSpan (New-TimeSpan -Days 60) -SearchBase `
'OU=Servers,DC=corp,DC=example,DC=com' | View examples |
| Verify on another DC | Get-ADUser -Identity $user.ObjectGUID -Properties `
Enabled,Department -Server 'dc02.corp.example.com' | View examples |
Active Directory Domain Services changes replicate beyond one server and can alter authentication or authorization across an organization. Use the Windows ActiveDirectory module from a trusted administrative workstation, pin important work to an explicitly named writable domain controller, resolve objects by immutable identity, scope every search, preview supported mutations, and verify the result after replication. These cmdlets manage on-premises AD DS or compatible AD LDS partitions, not Microsoft Entra ID.
Step by step
Detailed examples
Establish the management plane before querying the directory
The ActiveDirectory module ships with AD DS management tools on Windows Server and with the appropriate RSAT capability on supported Windows clients. A domain controller role is required somewhere in the target environment, but it should not be installed on the administrative workstation merely to obtain the cmdlets. Use Windows PowerShell 5.1 or a supported compatibility path when module behavior under PowerShell 7 has not been qualified. Read-only queries usually do not require local elevation, while feature installation can; directory changes require delegated AD permissions, network and DNS reachability, and a writable DC. Explicit -Server values make logs and replication expectations reproducible.
$PSVersionTable | Select-Object PSEdition, PSVersion
Get-ComputerInfo | Select-Object WindowsProductName, WindowsVersion, OsBuildNumber
Get-Module -ListAvailable ActiveDirectory | Select-Object Name, Version, Path
[System.Security.Principal.WindowsIdentity]::GetCurrent().Name
Get-ADDomain -Identity 'corp.example.com' -Server 'dc01.corp.example.com' |
Select-Object DNSRoot, NetBIOSName, PDCEmulator, RIDMaster, InfrastructureMaster
Get-ADDomainController -Identity 'dc01.corp.example.com' |
Select-Object HostName, Site, IsReadOnly, OperationMasterRoles Scope searches and request only the attributes you need
Get-ADUser returns a default property set; use -Properties for additional attributes and a bounded -SearchBase for inventories. -Filter uses the Active Directory PowerShell expression language, while -LDAPFilter accepts LDAP query syntax; neither should be assembled from untrusted text without validation. LastLogonDate is convenient replicated metadata derived from lastLogonTimestamp and is not an exact forensic sign-in record. Search-ADAccount inactivity output is a review signal, not proof that an identity is unused, so corroborate service, application, ownership, and audit evidence.
$server = 'dc01.corp.example.com'
$base = 'OU=People,DC=corp,DC=example,DC=com'
Get-ADUser -Filter 'Enabled -eq $true' -SearchBase $base `
-Properties mail,Department,Manager,LastLogonDate -Server $server |
Select-Object Name, SamAccountName, ObjectGUID, Enabled, mail, Department, LastLogonDate |
Sort-Object SamAccountName
Search-ADAccount -UsersOnly -AccountInactive `
-TimeSpan (New-TimeSpan -Days 90) -SearchBase $base -Server $server |
Select-Object Name, SamAccountName, ObjectGUID, LastLogonDate Stage identities disabled and prefer reversible containment
Create a user disabled in the exact OU, populate governed attributes, establish a compliant password through an approved secret-handling process, and enable only after approvals and access reviews. New-ADUser creates a disabled account when no password is supplied even if Enabled is requested. During offboarding or incident response, disabling preserves the SID and object for investigation; moving or deleting an object can change policy scope or break SID-linked dependencies. Cross-domain moves add RID-master requirements. None of these routine lifecycle commands requires a reboot, but authentication tokens, replication, and client refresh can delay the visible effect.
$server = 'dc01.corp.example.com'
$newUser = @{
Name = 'Alice Chen'
GivenName = 'Alice'
Surname = 'Chen'
SamAccountName = 'alice.chen'
UserPrincipalName = 'alice.chen@corp.example.com'
Path = 'OU=People,DC=corp,DC=example,DC=com'
Enabled = $false
Server = $server
}
New-ADUser @newUser -WhatIf
$user = Get-ADUser -Identity 'alice.chen' -Server $server
$user | Select-Object DistinguishedName, ObjectGUID, SID, Enabled
Disable-ADAccount -Identity $user.ObjectGUID -Server $server -WhatIf
Move-ADObject -Identity $user.ObjectGUID `
-TargetPath 'OU=Staged,DC=corp,DC=example,DC=com' -Server $server -WhatIf Note: WhatIf previews each supported cmdlet call, but it does not test downstream applications, ACLs, replication convergence, token renewal, uniqueness at execution time, or whether a later operator will run the same command against the same object.
Model authorization with intentional group scope and nesting
Choose security versus distribution category and DomainLocal, Global, or Universal scope from the domain and resource design rather than habit. Prefer role and resource groups whose ownership is documented. Get-ADGroupMember -Recursive expands nested membership but returns leaf members rather than the nesting path, and Get-ADPrincipalGroupMembership is not a substitute for evaluating a user's effective access token. Review circular nesting, protected accounts, foreign security principals, SIDHistory, and trusts before changing authorization.
$server = 'dc01.corp.example.com'
$group = Get-ADGroup -Identity 'GG-Finance-Readers' `
-Properties GroupCategory,GroupScope,ManagedBy,Description -Server $server
$group | Select-Object Name, ObjectGUID, SID, GroupCategory, GroupScope, ManagedBy, Description
Get-ADGroupMember -Identity $group.ObjectGUID -Server $server |
Select-Object Name, ObjectClass, ObjectGUID, DistinguishedName
Get-ADGroupMember -Identity $group.ObjectGUID -Recursive -Server $server |
Select-Object Name, ObjectClass, ObjectGUID, DistinguishedName New-ADGroup -Name 'GG-Finance-Readers' `
-SamAccountName 'GG-Finance-Readers' `
-GroupCategory Security -GroupScope Global `
-Path 'OU=Groups,DC=corp,DC=example,DC=com' `
-Description 'Approved identities eligible for Finance read access' `
-Server 'dc01.corp.example.com' -WhatIf Resolve both sides of a membership change before previewing it
A membership change is an authorization change. Resolve the group and member immediately before action, record their GUIDs, SIDs, distinguished names, owners, and current direct membership, and require a ticket or approval appropriate to the group's privilege. Add-ADGroupMember permissive modify normally does not error if the member already exists, and it can technically create self-membership with unstable consequences. WhatIf does not calculate nested effective permissions, Kerberos token refresh, replication timing, or application-specific authorization.
$server = 'dc01.corp.example.com'
$user = Get-ADUser -Identity 'alice.chen' -Server $server
$group = Get-ADGroup -Identity 'GG-Finance-Readers' -Properties ManagedBy -Server $server
$user, $group | Select-Object Name, ObjectClass, ObjectGUID, SID, DistinguishedName
Get-ADGroupMember -Identity $group.ObjectGUID -Server $server |
Where-Object ObjectGUID -eq $user.ObjectGUID
Add-ADGroupMember -Identity $group.ObjectGUID -Members $user.ObjectGUID `
-Server $server -WhatIf
Remove-ADGroupMember -Identity $group.ObjectGUID -Members $user.ObjectGUID `
-Server $server -WhatIf Separate computer-account state from machine reachability
An AD computer object is a security principal, not live proof that a host exists, is patched, or is reachable. Pre-stage accounts disabled in a staging OU when deployment controls require it, then let an approved join workflow establish the machine password and placement. PasswordLastSet and inactivity searches are useful inventory signals but can be distorted by snapshots, offline systems, replication, or broken secure channels. Never bulk-disable or delete computer accounts from age alone; correlate configuration management, DNS, DHCP, virtualization, monitoring, and owner records. Domain join, rename, and some secure-channel repairs may require restart, but creating, reading, moving, or disabling the directory object itself does not.
$server = 'dc01.corp.example.com'
$base = 'OU=Servers,DC=corp,DC=example,DC=com'
Get-ADComputer -Filter 'OperatingSystem -like "Windows Server*"' `
-SearchBase $base -Properties OperatingSystem,PasswordLastSet,LastLogonDate,Enabled `
-Server $server |
Select-Object Name, ObjectGUID, Enabled, OperatingSystem, PasswordLastSet, LastLogonDate
New-ADComputer -Name 'APP-042' `
-Path 'OU=Staging,OU=Servers,DC=corp,DC=example,DC=com' `
-Enabled:$false -Server $server -WhatIf
Search-ADAccount -ComputersOnly -AccountInactive `
-TimeSpan (New-TimeSpan -Days 60) -SearchBase $base -Server $server Treat WhatIf, replication, and rollback as separate controls
WhatIf is valuable only on cmdlets that implement ShouldProcess: it shows the intended target and suppresses that cmdlet's mutation. It is not a transaction, a permission test, a replication simulation, a policy-impact model, or a rollback plan; discovery and other commands in the same script still run. Changes against writable DCs replicate asynchronously and can conflict with concurrent administration. Capture before-state by GUID, use -PassThru or a fresh read when supported, verify on the write DC and another appropriate DC, and use the AD Recycle Bin or authoritative recovery procedures only when they were designed and tested in advance.
$identity = 'alice.chen'
$before = Get-ADUser -Identity $identity -Properties Enabled,Department,whenChanged `
-Server 'dc01.corp.example.com'
$before | Select-Object ObjectGUID, SID, Enabled, Department, whenChanged
# After an approved change, perform fresh reads rather than trusting cached objects.
Get-ADUser -Identity $before.ObjectGUID -Properties Enabled,Department,whenChanged `
-Server 'dc01.corp.example.com'
Get-ADUser -Identity $before.ObjectGUID -Properties Enabled,Department,whenChanged `
-Server 'dc02.corp.example.com' Sources and further reading
References
Authoritative documentation used to verify and expand this cheat sheet.
- MicrosoftActiveDirectory Modulelearn.microsoft.com
- Microsoftabout_ActiveDirectorylearn.microsoft.com
- MicrosoftGet-ADUserlearn.microsoft.com
- MicrosoftNew-ADUserlearn.microsoft.com
- MicrosoftAdd-ADGroupMemberlearn.microsoft.com
- MicrosoftGet-ADComputerlearn.microsoft.com
- MicrosoftMove-ADObjectlearn.microsoft.com
Help us improve
Found a typo or missing example?
Tell us what would make this cheat sheet clearer, more complete, or more useful.



