Date: Fri, 8 Sep 2006 13:12:41 +0200
We have recently developed a script to gather detailed user information from
our AD in order to identify user accounts not used for a long time and proceed
with deletion of such users.
During our test, at least we have observed that the LastLogon property is
changed not only with the interactively logon to a desktop system, but also
while mapping a network drive. We have not tested it with third party
applications that make use of the AD just as and LDAP for authentication, but
it is very likely that this property will also be updated this way.
I have a question regarding some data I pulled off a
customers AD. We recently ran AD scan to identify
several user accoutn violation types using AD
Inspector (www.obtuse.net/software/adinspector).
Basically the search contained filters for users who
dont have password expirations enabled and also users
who havent logged in in the last 90 days (stale
accounts). Anyways, the results were quite suprising
and I'd like to validate them.
My question is this. Is the lastLogon AD account
property updated any time a user authenticates to AD
regardless of the service? Like, if I login to a 3rd
party application which uses LDAP integration with AD
for authentication, will that update the users
lastLogon property in AD?
