FAQ: Can I find the exact time a user was disabled in Active Directory?
This article explains how to find the exact time when a user was disabled in Active Directory. While ADManager Plus provides identity management functions, this type of real-time log-based auditing is only supported in ADAudit Plus.
FAQ
Q: How can I find the exact time a user was disabled in Active Directory?
A: This level of audit detail is not available in ADManager Plus, but is fully supported in ADAudit Plus through the Recently Disabled Users report.
Why it's not feasible in ADManager Plus:
ADManager Plus is primarily designed for provisioning, deprovisioning, and reporting based on current Active Directory data.
It does not collect or retain historical security logs from domain controllers.
There is no built-in audit trail for actions performed outside of ADManager itself (e.g., direct changes via ADUC or PowerShell).
Why it's feasible in ADAudit Plus:
ADAudit Plus collects and parses real-time security logs from all configured domain controllers.
It tracks all user management events, including who disabled the user, when, and from where.
Reports are timestamped and can be filtered, exported, or tied to alerts.
Steps to generate the Recently Disabled Users report in ADAudit Plus:
Log in to your ADAudit Plus console.
Navigate to Reports on the left panel.
Expand User Management.
Click Recently Disabled Users.
Use the filters at the top to set the date range or specify a username.
The report will display:
Click Export to download the report in PDF, CSV, or XLS format.
New to ADSelfService Plus?
Related Articles
Difference in last logon time for Active Directory accounts in ADManager Plus reports
In Active Directory, there are two attributes related to the user logon time: lastLogon and lastLogonTimeStamp. The lastLogon attribute is updated only in the Domain Controller (DC) which authenticates the user logon. This is a non-replicating ...
A technician is unable to delete an Active Directory user account using ADManager Plus but the same is possible from ADUC console.
ADManager Plus, an IGA tool, offers purpose built features for Active Directory (AD), Microsoft 365, Exchange, and Google workspace management and reporting operations. To successfully perform the required operation in these platforms, ADManager Plus ...
Active Directory-ADManager Plus data synchronization
Objects in Active Directory (AD) have to be synced and updated to ADManager Plus as frequently as possible for an unobstructed AD management and reporting experience. ADManager Plus triggers different types of sync at different time intervals, ...
Why are reports generated in ADManager Plus listing objects that no longer exist in Active Directory?
Issue description ADManager Plus reports may display user accounts, computers, or other Active Directory objects that no longer exist. This affects the accuracy of report data and can hinder functions that rely on up-to-date AD information, such as ...
How to configure an additional Active Directory domains in ADManager Plus
Objective This article explains how to configure Active Directory domains in ADManager Plus to enable full use of its capabilities. Proper domain configuration allows you to automate tasks, delegate responsibilities, generate detailed reports, ...