Active directory question

How can I identify inactive workstations in Active directory and eDirectory(Novell)? Which field would tell me whether the workstation is active or inactive?

what does "whenchanged" field in AD means?
LVL 35
YZlatAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

JoeCommented:
you can use Bopup scanner to scan you network for active computers then compare it to your AD

http://www.blabsoft.com/products/scanner/   (this is free software)
0
michkoCommented:
Spiceworks is a very handy (and also free) network utility:
www.spiceworks.com
0
YZlatAuthor Commented:
that's not the question. The question is how can I determine from AD records which workstations are inactive
0
KuppingerCole Reviews AlgoSec in Executive Report

Leading analyst firm, KuppingerCole reviews AlgoSec's Security Policy Management Solution, and the security challenges faced by companies today in their Executive View report.

PowerITCommented:
You would have to look at 'lastlogintimestamp'
A command line query to do this:
> dsquery computer forestroot -inactive <NumWeeks>
(query also possible on domain or ou)

whenchanged just shows when the last change to the object took place. This does not relate to activity of the workstation itself.

J.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
YZlatAuthor Commented:
what about on eDirectory?
0
PowerITCommented:
eDirectory is not my speciality. Someone else?
0
PsiCopCommented:
Depends on how/why the Workstation is in eDirectory.

If you are using ZENworks for Workstation Management, then you can run a report against the ZENworks workstation inventory.

If you're not using ZENworks Workstation Management, then probably none of your workstations are in eDirectory, as there's no reason to add them.
0
ShineOnCommented:
How do you define "inactive?"

Do you mean not currently logged-in, or not responding to PING, or no longer in service, or something else?

There's a "modified" property on the Computer object in AD that has a date/time stamp of the last time the computer updated itself to AD.  Would that work?

If you have ZEN, a Workstation object also has a last-logged-in date/time stamp.

0
ShineOnCommented:
Are you hoping to determine when a computer object (AD) or workstation object (eDirectory) can be removed from either AD or eDir because you've got orphaned objects floating around from old systems that should be retired from the system as it were?

ZENworks should automatically purge itself of inactive workstation objects, if you've got it configured right, so eDir should take care of itself.  

I have no idea if there is anything of that nature with AD.  Haven't had the need to look yet.  I'd be interested to find out as it may be an issue for me someday as well.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Security

From novice to tech pro — start learning today.