AD Users (Inactive) web query displays Active Directory inactive user accounts, located in the domain or OU selected as a scope for the query. Default AD Users (Inactive) web query is included in the built-in Active Directory Admin Unit, and a custom copy of the AD Users (Inactive) web query is copied to every new custom Admin Unit.
Inactive Active Directory users are users who have not logged on in more than the specified number of days - OR - who have not changed their passwords in more than the specified number of days.
Web queries in a custom Admin Unit are used as a scope for role delegation and attribute policy. When limiting the scope of web queries to a specific OU, you limit the scope of objects available for management to delegated administrators. For more information, please see the New Virtual Admin Units article.
AD Users (Inactive) query settings
AD Users (Inactive) web query uses common query settings, available for every web query in Active Directory Admin Unit. For information about common settings, please refer to the following article:
Settings specific to AD Users (Inactive) web query
Minimum days past since last logon
Set a minimum number of days past since the last user logon.
Minimum days past since password last set
Set a minimum number of days past since the user password last set.
Tip: Best practices for Maximum password age
Minimum days past since account creation
Set a minimum number of days past since user account creation.