The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
Check the AD moduleGet-Module -ListAvailable ActiveDirectory | Select-Object Name, Version, PathView examples
Identify domain contextGet-ADDomain -Identity 'corp.example.com' -Server ` 'dc01.corp.example.com'View examples
Resolve one userGet-ADUser -Identity 'alice.chen' -Properties ` mail,Enabled,LastLogonDate -Server ` 'dc01.corp.example.com'View examples
Search users in an OUGet-ADUser -Filter 'Enabled -eq $true' -SearchBase ` 'OU=People,DC=corp,DC=example,DC=com' -Server ` 'dc01.corp.example.com'View examples
Find inactive usersSearch-ADAccount -UsersOnly -AccountInactive -TimeSpan ` (New-TimeSpan -Days 90) -SearchBase ` 'OU=People,DC=corp,DC=example,DC=com'View examples
Preview a disabled userNew-ADUser -Name 'Alice Chen' -SamAccountName ` 'alice.chen' -Path ` 'OU=People,DC=corp,DC=example,DC=com' -Enabled:$false ` -WhatIfView examples
Preview a user updateSet-ADUser -Identity 'alice.chen' -Department 'Finance' ` -Title 'Analyst' -Server 'dc01.corp.example.com' ` -WhatIfView examples
Preview account disableDisable-ADAccount -Identity 'alice.chen' -Server ` 'dc01.corp.example.com' -WhatIfView examples
Preview moving an objectMove-ADObject -Identity $user.ObjectGUID -TargetPath ` 'OU=Staged,DC=corp,DC=example,DC=com' -Server ` 'dc01.corp.example.com' -WhatIfView examples
Inspect a groupGet-ADGroup -Identity 'GG-Finance-Readers' -Properties ` GroupCategory,GroupScope,ManagedBy -Server ` 'dc01.corp.example.com'View examples
Expand nested membersGet-ADGroupMember -Identity 'GG-Finance-Readers' ` -Recursive -Server 'dc01.corp.example.com'View examples
List principal groupsGet-ADPrincipalGroupMembership -Identity 'alice.chen' -Server 'dc01.corp.example.com' | Sort-Object NameView examples
Preview group creationNew-ADGroup -Name 'GG-Finance-Readers' -GroupScope ` Global -Path 'OU=Groups,DC=corp,DC=example,DC=com' ` -WhatIfView examples
Preview adding a memberAdd-ADGroupMember -Identity $group.ObjectGUID -Members ` $user.ObjectGUID -Server 'dc01.corp.example.com' ` -WhatIfView examples
Preview removing a memberRemove-ADGroupMember -Identity $group.ObjectGUID ` -Members $user.ObjectGUID -Server ` 'dc01.corp.example.com' -WhatIfView examples
Search computer accountsGet-ADComputer -Filter ` 'OperatingSystem -like "Windows Server*"' -SearchBase ` 'OU=Servers,DC=corp,DC=example,DC=com'View examples
Preview a computer accountNew-ADComputer -Name 'APP-042' -Path ` 'OU=Staging,OU=Servers,DC=corp,DC=example,DC=com' ` -Enabled:$false -WhatIfView examples
Find inactive computersSearch-ADAccount -ComputersOnly -AccountInactive ` -TimeSpan (New-TimeSpan -Days 60) -SearchBase ` 'OU=Servers,DC=corp,DC=example,DC=com'View examples
Verify on another DCGet-ADUser -Identity $user.ObjectGUID -Properties ` Enabled,Department -Server 'dc02.corp.example.com'View examples

Active Directory Domain Services changes replicate beyond one server and can alter authentication or authorization across an organization. Use the Windows ActiveDirectory module from a trusted administrative workstation, pin important work to an explicitly named writable domain controller, resolve objects by immutable identity, scope every search, preview supported mutations, and verify the result after replication. These cmdlets manage on-premises AD DS or compatible AD LDS partitions, not Microsoft Entra ID.

Step by step

Detailed examples

01

Establish the management plane before querying the directory

The ActiveDirectory module ships with AD DS management tools on Windows Server and with the appropriate RSAT capability on supported Windows clients. A domain controller role is required somewhere in the target environment, but it should not be installed on the administrative workstation merely to obtain the cmdlets. Use Windows PowerShell 5.1 or a supported compatibility path when module behavior under PowerShell 7 has not been qualified. Read-only queries usually do not require local elevation, while feature installation can; directory changes require delegated AD permissions, network and DNS reachability, and a writable DC. Explicit -Server values make logs and replication expectations reproducible.

Confirm tools, edition, identity, and target DC
$PSVersionTable | Select-Object PSEdition, PSVersion
Get-ComputerInfo | Select-Object WindowsProductName, WindowsVersion, OsBuildNumber
Get-Module -ListAvailable ActiveDirectory | Select-Object Name, Version, Path
[System.Security.Principal.WindowsIdentity]::GetCurrent().Name
Get-ADDomain -Identity 'corp.example.com' -Server 'dc01.corp.example.com' |
  Select-Object DNSRoot, NetBIOSName, PDCEmulator, RIDMaster, InfrastructureMaster
Get-ADDomainController -Identity 'dc01.corp.example.com' |
  Select-Object HostName, Site, IsReadOnly, OperationMasterRoles
Back to quick reference ↑
02

Scope searches and request only the attributes you need

Get-ADUser returns a default property set; use -Properties for additional attributes and a bounded -SearchBase for inventories. -Filter uses the Active Directory PowerShell expression language, while -LDAPFilter accepts LDAP query syntax; neither should be assembled from untrusted text without validation. LastLogonDate is convenient replicated metadata derived from lastLogonTimestamp and is not an exact forensic sign-in record. Search-ADAccount inactivity output is a review signal, not proof that an identity is unused, so corroborate service, application, ownership, and audit evidence.

Build a bounded user review
$server = 'dc01.corp.example.com'
$base = 'OU=People,DC=corp,DC=example,DC=com'
Get-ADUser -Filter 'Enabled -eq $true' -SearchBase $base `
  -Properties mail,Department,Manager,LastLogonDate -Server $server |
  Select-Object Name, SamAccountName, ObjectGUID, Enabled, mail, Department, LastLogonDate |
  Sort-Object SamAccountName

Search-ADAccount -UsersOnly -AccountInactive `
  -TimeSpan (New-TimeSpan -Days 90) -SearchBase $base -Server $server |
  Select-Object Name, SamAccountName, ObjectGUID, LastLogonDate
Back to quick reference ↑
03

Stage identities disabled and prefer reversible containment

Create a user disabled in the exact OU, populate governed attributes, establish a compliant password through an approved secret-handling process, and enable only after approvals and access reviews. New-ADUser creates a disabled account when no password is supplied even if Enabled is requested. During offboarding or incident response, disabling preserves the SID and object for investigation; moving or deleting an object can change policy scope or break SID-linked dependencies. Cross-domain moves add RID-master requirements. None of these routine lifecycle commands requires a reboot, but authentication tokens, replication, and client refresh can delay the visible effect.

Resolve identity and preview a staged lifecycle change
$server = 'dc01.corp.example.com'
$newUser = @{
  Name = 'Alice Chen'
  GivenName = 'Alice'
  Surname = 'Chen'
  SamAccountName = 'alice.chen'
  UserPrincipalName = 'alice.chen@corp.example.com'
  Path = 'OU=People,DC=corp,DC=example,DC=com'
  Enabled = $false
  Server = $server
}
New-ADUser @newUser -WhatIf

$user = Get-ADUser -Identity 'alice.chen' -Server $server
$user | Select-Object DistinguishedName, ObjectGUID, SID, Enabled
Disable-ADAccount -Identity $user.ObjectGUID -Server $server -WhatIf
Move-ADObject -Identity $user.ObjectGUID `
  -TargetPath 'OU=Staged,DC=corp,DC=example,DC=com' -Server $server -WhatIf

Note: WhatIf previews each supported cmdlet call, but it does not test downstream applications, ACLs, replication convergence, token renewal, uniqueness at execution time, or whether a later operator will run the same command against the same object.

Back to quick reference ↑
04

Model authorization with intentional group scope and nesting

Choose security versus distribution category and DomainLocal, Global, or Universal scope from the domain and resource design rather than habit. Prefer role and resource groups whose ownership is documented. Get-ADGroupMember -Recursive expands nested membership but returns leaf members rather than the nesting path, and Get-ADPrincipalGroupMembership is not a substitute for evaluating a user's effective access token. Review circular nesting, protected accounts, foreign security principals, SIDHistory, and trusts before changing authorization.

Inspect group design and nested membership
$server = 'dc01.corp.example.com'
$group = Get-ADGroup -Identity 'GG-Finance-Readers' `
  -Properties GroupCategory,GroupScope,ManagedBy,Description -Server $server
$group | Select-Object Name, ObjectGUID, SID, GroupCategory, GroupScope, ManagedBy, Description
Get-ADGroupMember -Identity $group.ObjectGUID -Server $server |
  Select-Object Name, ObjectClass, ObjectGUID, DistinguishedName
Get-ADGroupMember -Identity $group.ObjectGUID -Recursive -Server $server |
  Select-Object Name, ObjectClass, ObjectGUID, DistinguishedName
Preview a purpose-specific group
New-ADGroup -Name 'GG-Finance-Readers' `
  -SamAccountName 'GG-Finance-Readers' `
  -GroupCategory Security -GroupScope Global `
  -Path 'OU=Groups,DC=corp,DC=example,DC=com' `
  -Description 'Approved identities eligible for Finance read access' `
  -Server 'dc01.corp.example.com' -WhatIf
Back to quick reference ↑
05

Resolve both sides of a membership change before previewing it

A membership change is an authorization change. Resolve the group and member immediately before action, record their GUIDs, SIDs, distinguished names, owners, and current direct membership, and require a ticket or approval appropriate to the group's privilege. Add-ADGroupMember permissive modify normally does not error if the member already exists, and it can technically create self-membership with unstable consequences. WhatIf does not calculate nested effective permissions, Kerberos token refresh, replication timing, or application-specific authorization.

Preview one GUID-bound membership grant and revocation
$server = 'dc01.corp.example.com'
$user = Get-ADUser -Identity 'alice.chen' -Server $server
$group = Get-ADGroup -Identity 'GG-Finance-Readers' -Properties ManagedBy -Server $server
$user, $group | Select-Object Name, ObjectClass, ObjectGUID, SID, DistinguishedName
Get-ADGroupMember -Identity $group.ObjectGUID -Server $server |
  Where-Object ObjectGUID -eq $user.ObjectGUID

Add-ADGroupMember -Identity $group.ObjectGUID -Members $user.ObjectGUID `
  -Server $server -WhatIf
Remove-ADGroupMember -Identity $group.ObjectGUID -Members $user.ObjectGUID `
  -Server $server -WhatIf
Back to quick reference ↑
06

Separate computer-account state from machine reachability

An AD computer object is a security principal, not live proof that a host exists, is patched, or is reachable. Pre-stage accounts disabled in a staging OU when deployment controls require it, then let an approved join workflow establish the machine password and placement. PasswordLastSet and inactivity searches are useful inventory signals but can be distorted by snapshots, offline systems, replication, or broken secure channels. Never bulk-disable or delete computer accounts from age alone; correlate configuration management, DNS, DHCP, virtualization, monitoring, and owner records. Domain join, rename, and some secure-channel repairs may require restart, but creating, reading, moving, or disabling the directory object itself does not.

Inventory and preview one staged computer object
$server = 'dc01.corp.example.com'
$base = 'OU=Servers,DC=corp,DC=example,DC=com'
Get-ADComputer -Filter 'OperatingSystem -like "Windows Server*"' `
  -SearchBase $base -Properties OperatingSystem,PasswordLastSet,LastLogonDate,Enabled `
  -Server $server |
  Select-Object Name, ObjectGUID, Enabled, OperatingSystem, PasswordLastSet, LastLogonDate

New-ADComputer -Name 'APP-042' `
  -Path 'OU=Staging,OU=Servers,DC=corp,DC=example,DC=com' `
  -Enabled:$false -Server $server -WhatIf

Search-ADAccount -ComputersOnly -AccountInactive `
  -TimeSpan (New-TimeSpan -Days 60) -SearchBase $base -Server $server
Back to quick reference ↑
07

Treat WhatIf, replication, and rollback as separate controls

WhatIf is valuable only on cmdlets that implement ShouldProcess: it shows the intended target and suppresses that cmdlet's mutation. It is not a transaction, a permission test, a replication simulation, a policy-impact model, or a rollback plan; discovery and other commands in the same script still run. Changes against writable DCs replicate asynchronously and can conflict with concurrent administration. Capture before-state by GUID, use -PassThru or a fresh read when supported, verify on the write DC and another appropriate DC, and use the AD Recycle Bin or authoritative recovery procedures only when they were designed and tested in advance.

Capture and compare an object across domain controllers
$identity = 'alice.chen'
$before = Get-ADUser -Identity $identity -Properties Enabled,Department,whenChanged `
  -Server 'dc01.corp.example.com'
$before | Select-Object ObjectGUID, SID, Enabled, Department, whenChanged

# After an approved change, perform fresh reads rather than trusting cached objects.
Get-ADUser -Identity $before.ObjectGUID -Properties Enabled,Department,whenChanged `
  -Server 'dc01.corp.example.com'
Get-ADUser -Identity $before.ObjectGUID -Properties Enabled,Department,whenChanged `
  -Server 'dc02.corp.example.com'
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. MicrosoftActiveDirectory Modulelearn.microsoft.com
  2. Microsoftabout_ActiveDirectorylearn.microsoft.com
  3. MicrosoftGet-ADUserlearn.microsoft.com
  4. MicrosoftNew-ADUserlearn.microsoft.com
  5. MicrosoftAdd-ADGroupMemberlearn.microsoft.com
  6. MicrosoftGet-ADComputerlearn.microsoft.com
  7. MicrosoftMove-ADObjectlearn.microsoft.com

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback