RE: How to generate a report of inactive domain user accounts

From: Amarante, Rodrigo P. (RPAmarante@directvla.com)
Date: 04/11/03

  • Next message: Benjamin D. Goldman: "RE: How to generate a report of inactive domain user accounts"
    Date: Fri, 11 Apr 2003 17:00:27 -0400
    From: "Amarante, Rodrigo P." <RPAmarante@directvla.com>
    To: "Brian E" <brian_anon@hotmail.com>, <focus-ms@securityfocus.com>
    

    Brian,

    Each time a Domain Controller authenticates a user, it records that time
    (in a funky format) in the lastLogon attribute of that user's object in
    active directory. The problem is that each domain controller has it's
    own values for that attribute. So, if joe user got authenticated by
    Domain Controller A in 04/09/2003 at 10:10AM and next day he gets
    authenticated by Domain Controller B at 09:00AM. The user's real last
    logon was 04/10/2003 at 09:00AM, but if you only query Domain Controller
    A it will show up as being 04/09/2003 at 10:10AM.
    So in order for you to get an accurate last logon, you must query all
    Domain Controllers for the domain and then compare the values of the
    lastLogon attribute. The value is stored as an INTERGER8, so in order
    for you to get the the high part and the low part to get it to work...

    I wrote a tool using the .NET framework that gives you the "real"
    lastlogon attribute of a given user or of all users in the domain. The
    only "complicated" thing is to convert the value to an actual human
    readable time format...
    -----Original Message-----
    From: Brian E [mailto:brian_anon@hotmail.com]
    Sent: Friday, April 11, 2003 7:56 AM
    To: focus-ms@securityfocus.com

    Can anyone provide some suggestions or list of tools available to
    generate

    a report of inactive domain user accounts within an OU?

    We're using Active Directory with Windows 2000 and have OU's defined for

    different groups of users. I'd like to generate the report by OU.

    We also have multiple domain controllers (I've had issues with "last
    true

    logon" in the past). I would like a list of user who have not logged in

    within X days (preferably 90 days, but I'd like to modify this
    threshold).

    Criteria for an inactive account:

    -Not logged on for X days (X will be provided at time of generating the

    report)

    -Not disabled

    -Password is set to expire

    Regard,

    Brian

    brian_anon@hotmail.com

    ----------------------------------------------------------------------
    Block Spam, Smut & Viruses
    SurfControl E-mail Filter for SMTP & Exchange leverages multiple layers
    of
    technology including filtering embedded and attached file content. Rid
    your
    enterprise of unwanted content.
    http://www.securityfocus.com/SurfControl-focus-ms2
    Download your free fully functional trial, complete with 30-days of free
    technical support.
    ----------------------------------------------------------------------

    ----------------------------------------------------------------------
    Block Spam, Smut & Viruses
    SurfControl E-mail Filter for SMTP & Exchange leverages multiple layers of
    technology including filtering embedded and attached file content. Rid your
    enterprise of unwanted content.
    http://www.securityfocus.com/SurfControl-focus-ms2
    Download your free fully functional trial, complete with 30-days of free
    technical support.
    ----------------------------------------------------------------------


  • Next message: Benjamin D. Goldman: "RE: How to generate a report of inactive domain user accounts"

    Relevant Pages

    • Re: number of logon users per domain controller per day
      ... I am not sure how domain controller keeps track ... However, when the user authenticates, the lastLogon attribute of the user ... VBScript program that appends to a log file linked here: ...
      (microsoft.public.scripting.vbscript)
    • Re: number of logon users per domain controller per day
      ... I am not sure how domain controller keeps track ... However, when the user authenticates, the lastLogon attribute of the user ... VBScript program that appends to a log file linked here: ...
      (microsoft.public.scripting.vbscript)
    • ldap authentication to win2k domain controller
      ... i've been given the task of writing an app with a login mechanism that authenticates against the active directory users list on a windows 2000 domain controller. ... can anyone tell me what i need to install/compile to get ldap authentication against my win2k domain controller going? ...
      (php.general)
    • Re: HELP! Need AD Query for Last login
      ... You want to do this only for the second query that runs on each DC. ... > and how long the revised script took. ... >> ' Because the lastLogon attribute is not replicated, ... Then, for each Domain Controller, ADO is used to search the ...
      (microsoft.public.scripting.vbscript)
    • Domain last-logon script -- can it also show where?
      ... ' Because the lastLogon attribute is not replicated, ... Then, for each Domain Controller, ADO is used to search the ... Dim objRootDSE, strConfig, objConnection, objCommand, strQuery ... Dim strDNSDomain, objShell, lngBiasKey, lngBias, k, arrstrDCs ...
      (microsoft.public.scripting.vbscript)