---
title: "Get-DbaDbOrphanUser"
description: "Get orphaned users."
url: "https://dbatools.io/Get-DbaDbOrphanUser/"
availability: "Windows, Linux, macOS"
tags: ["Orphan", "Database", "User", "Login"]
author: "Claudio Silva (@ClaudioESSilva) | Garry Bargsley (@gbargsley) | Simone Bizzotto (@niphlod)"
source: "https://github.com/dataplat/dbatools/blob/master/public/Get-DbaDbOrphanUser.ps1"
last_updated: "2024-01-01"
---

# Get-DbaDbOrphanUser

## Synopsis

Get orphaned users.

## Description

An orphan user is defined by a user that does not have their matching login. (Login property = "").  
  
Note: Users in contained databases (Partial or Full containment type) are not considered orphaned for SQL logins,  
as these users authenticate directly to the database without requiring a server-level login.  
Windows users are still checked for orphaned status regardless of containment type.

## Syntax

```powershell
Get-DbaDbOrphanUser
    [-SqlInstance] <DbaInstanceParameter[]>
    [[-SqlCredential] <PSCredential>]
    [[-Database] <Object[]>]
    [[-ExcludeDatabase] <Object[]>]
    [-EnableException]
    [<CommonParameters>]

```

## Examples

### Example 1: Finds all orphan users without matching Logins in all databases present on server &#39;localhost\sql2016&#39;

```powershell
PS C:\> Get-DbaDbOrphanUser -SqlInstance localhost\sql2016
```

### Example 2: Finds all orphan users without matching Logins in all databases present on server &#39;localhost\sql2016&#39;

```powershell
PS C:\> Get-DbaDbOrphanUser -SqlInstance localhost\sql2016 -SqlCredential $cred
```

Finds all orphan users without matching Logins in all databases present on server 'localhost\sql2016'. SQL Server authentication will be used in connecting to the server.  

### Example 3: Finds orphan users without matching Logins in the db1 database present on server &#39;localhost\sql2016&#39;

```powershell
PS C:\> Get-DbaDbOrphanUser -SqlInstance localhost\sql2016 -Database db1
```

### Required Parameters

##### -SqlInstance

The target SQL Server instance or instances.

| Property | Value |
| --- | --- |
| Alias |  |
| Required | True |
| Pipeline | true (ByValue) |
| Default Value |  |

### Optional Parameters

##### -SqlCredential

Login to the target instance using alternative credentials. Accepts PowerShell credentials (Get-Credential).  
Windows Authentication, SQL Server Authentication, Active Directory - Password, and Active Directory - Integrated are all supported.  
For MFA support, please use Connect-DbaInstance.

| Property | Value |
| --- | --- |
| Alias |  |
| Required | False |
| Pipeline | false |
| Default Value |  |

##### -Database

Specifies which databases to check for orphaned users. Accepts database names, wildcards, or arrays.  
Use this when you need to focus the orphaned user search on specific databases rather than checking all databases on the instance.

| Property | Value |
| --- | --- |
| Alias |  |
| Required | False |
| Pipeline | false |
| Default Value |  |

##### -ExcludeDatabase

Specifies databases to skip when checking for orphaned users. Useful for excluding system databases or databases under maintenance.  
Commonly used to exclude tempdb, distribution, or databases where orphaned users are expected and acceptable.

| Property | Value |
| --- | --- |
| Alias |  |
| Required | False |
| Pipeline | false |
| Default Value |  |

##### -EnableException

By default, when something goes wrong we try to catch it, interpret it and give you a friendly warning message.  
This avoids overwhelming you with "sea of red" exceptions, but is inconvenient because it basically disables advanced scripting.  
Using this switch turns this "nice by default" feature off and enables you to catch exceptions with your own try/catch.

| Property | Value |
| --- | --- |
| Alias |  |
| Required | False |
| Pipeline | false |
| Default Value | False |

## Outputs

**PSCustomObject**

Returns one object per orphaned user found across the specified databases.

**Default display properties (via Select-DefaultView):**

- ComputerName: The computer name of the SQL Server instance
- InstanceName: The SQL Server instance name
- SqlInstance: The full SQL Server instance name (computer\instance)
- DatabaseName: Name of the database containing the orphaned user
- User: Name of the orphaned user

**Additional properties available:**

- SmoUser: The underlying Microsoft.SqlServer.Management.Smo.User object with all SMO properties

---

Part of [dbatools](https://dbatools.io/), a free and open source PowerShell module for SQL Server administration. Full command index: https://dbatools.io/commands/
