# LDAP (Active Directory) filter expired users

**URL:** <https://forum.keycloak.org/t/ldap-active-directory-filter-expired-users/21763>\
**Category:** Getting advice\
**Tags:** user-federation, ldap\
**Created:** [April 27, 2023, 9:58am UTC](https://forum.keycloak.org/t/ldap-active-directory-filter-expired-users/21763 "2023-04-27T09:58:14Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![gitdode](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/gitdode/32/1178_2.png) [@gitdode](https://forum.keycloak.org/u/gitdode)\
**Post date:** [April 27, 2023, 9:58am UTC](https://forum.keycloak.org/t/ldap-active-directory-filter-expired-users/21763/1 "2023-04-27T09:58:14Z")

</div>

How can we handle expired users with LDAP (Active Directory) user federation? Does the provider already consider the `accountExpires` attribute or is it necessary to configure this?

From what I found out so far is that I could filter for users that are not expired with a ‘User LDAP filter’ like

`(&(objectCategory=person)(objectClass=user)(accountExpires>now))`

so expired users are simply not found and login fails. But how could I replace ‘now’ with the current timestamp?

Also it seems that if a user has `accountExpires=0` or `accountExpires=9223372036854775807`, they are also not expired (never expire I suppose).
