1. Home
  2. Active Directory Policy for Resigned Employee Account

Active Directory Policy for Resigned Employee Account

*Note: This article is meant for System Administrator

Disable resigned employee's AD account

  1. Resigned employee account should be disabled immediately on employee last day after he/she has completed her handovers.
  2. Login domain controller & launch Active Directory Users & Computers.
  3. Locate the resigned employee account, reset the password & disable the account.
  4. Move the account to "disabled users" OU.
  5. Disabled accounts will retained for minimum 60 days in this OU before it is purged.

Purge disabled accounts after 60 days

  1. Launch Active Directory Users & Computers & expand the "Saved Queries" tree.
  2. Right click on the "Delete account" query & select refresh to run the query.
  3. The list of disabled account that has been inactive for more than 60 days will show up on the right panel.
  4. Select all the account in the list & delete. This action will permanently purge account from AD.
  5. It is recommended to run this query on weekly basis as part of AD housekeeping.

Updated on September 20, 2021