0 votes

Hello All

We have a question in regards to checking the Active Directory forest for currently active groups. With the automation process begininning for adding groups to each person based on their jobCode, we need to weed out the groups that don't actually control anything anymore. We are looking for a suggestion, script or tool on how to accomplish this so we can weed out the groups that do not control anything.

Thank you

by (3.2k points)


Could you specify exactly which groups should be deleted? How do we define that a group is inactive?


Our AD structure has been in place for many years and many incarnations of Admins before me. We know we have a few group (Office or internet) that were created way back when and no longer control anything in our environment. We are looking to discontinue using these groups and wanted to find all the groups that have been orphaned and no longer control anything.



find all the groups that have been orphaned and no longer control anything

How exactly do you define these groups? Are these groups that have no Security Roles assigned?

As a solution, you can delete all the groups created more than a certain number of days ago. Does it meet your needs?


Sorry, that would not meet our needs. We need to be able to verify without breaking the entire organization, that groups that do not control anything can be disabled and then turned off. We were looking to see if we had a way to check for groups to be "called" upon in AD.



Sorry, but we don't quite get which groups you want to delete? There is no such notion as 'active' or 'inactive' groups in AD, so you need to define it yourself. Maybe, you are searching for a way to clean up groups without any members in them? What are the criteria? Please explain.


Ok, we are gong a different way to test "active"groups. Sorry for any confusion.

Please log in or register to answer this question.

Related questions

0 votes
1 answer

We are testing Adaxes. After installing I tried the Self Service portal. I was impressed with how much it automatically found right out of the box. When I click on join a ... control this? How would I get it to see groups that are not showing? Thanks, Randy

asked Apr 25, 2024 by rjangelin (20 points)
0 votes
1 answer

Hello, I want to get a mail notification when a new Active-Directory Group Security is created on a specific Organization Unit. When an AD admin create a Local group security ... administrator about this new group. Is there a way to implement that on Adaxes ?

asked Feb 11 by wrobin68 (40 points)
0 votes
1 answer

Is there a comparison between the OnPrem user object and Entra user object in the built-in condition? Which determines the most recent inactivity from both environments. Or should a choice be made between the OnPrem domain or Entra based on the Activity scope?

asked Dec 13, 2024 by IwistIT (40 points)
0 votes
1 answer

We have a client that is using another product for tracking change history and Active Directory auditing. Does Adaxes provide such tracking for Active Directory objects, passwords, etc. ?

asked May 7, 2024 by daviddickerson (20 points)
0 votes
1 answer

We are in the process of updating our Active Directory Domain Controllers to server 2022 and the Domain/Forest function level. Our concern is that we still have Adaxes ... version of Windows server for our DCs and the Domain/Forest function level of 2016?

asked Oct 11, 2023 by sphoeinix (20 points)
3,633 questions
3,321 answers
548,760 users