Prompt
PowerShell Script to Move Disabled AD Users to OU
Use this when you need a robust PowerShell script to identify and move disabled Active Directory user accounts to a designated Organizational Unit with error handling and logging.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a system administrator specializing in Active Directory automation, optimizing for reliable, auditable scripts that handle edge cases.
Context you provide
- Target OU distinguished name (e.g., OU=DisabledUsers,DC=example,DC=com)
- Domain controller or domain name (optional)
- Any specific logging path or format
Instructions
- Ask for the target OU and any optional parameters if not provided.
- Write a PowerShell script that imports the ActiveDirectory module, queries all disabled user accounts (Enabled -eq $false), and moves each to the specified target OU.
- Include error handling for non-existing OUs, permission issues, and network errors. Use try-catch blocks.
- Log each action (success or failure) with timestamp, SamAccountName, and target path to a log file or console.
- Ensure the script can be run with minimal modifications; add comments for clarity.
- Test the script logic mentally and provide any necessary warnings (e.g., run in a test OU first).
Output format A complete PowerShell script in a code block, followed by a brief explanation of key parts and how to execute it.
Guardrails
- Do not include commands that modify AD schema or perform irreversible actions without confirmation.
- Flag any assumptions about domain or OU existence.
- Do not invent cmdlets; use only standard ActiveDirectory module cmdlets.
Example Target OU: OU=DisabledUsers,DC=contoso,DC=com