Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17


Can I query for what times a user authenticated against AD using DSQUERY?

Posted on 2008-09-29
Medium Priority
Last Modified: 2013-12-24
Can I query for what times a user authenticated against AD using DSQUERY?  I'm running in mixed mode.
Question by:instaIT
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2

Expert Comment

ID: 22597023
dsquery * "cn=Bill Gates,ou=test,dc=microdomain,dc=com" -scope base -attr
LVL 71

Expert Comment

by:Chris Dent
ID: 22597067

That won't be entirely accurate. The attribute is described here:

And discussed here:

Which tells us that the attribute above may be off by as much as 14 days.

So it's great, depending on how accurate you need / want to be.


Author Comment

ID: 22597078
Is there a way to see the history over a period of time rather than just the last logon stamp?
LVL 71

Accepted Solution

Chris Dent earned 2000 total points
ID: 22597149

Nope, both lastLogon and lastLogonTimeStamp are single value attributes.

Basically, if you want a history you'd have to write something to maintain it, perhaps something through a logon script?

It would be possible to do it on the server side, but for accuracy you'll need the lastLogon attribute. The problem is, that one isn't replicated, which means you have to check every DC in your environment to get the actual value. That would be painful if it were required of a regular basis.


Featured Post

Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article, we’ll look at how to deploy ProxySQL.
Wouldn't it be nice if objects in Active Directory automatically moved into the correct Organizational Units? This is what AutoAD aims to do and as a plus, it automatically creates Sites, Subnets, and Organizational Units.
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

722 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question