Solved

AD Authentication Tracking

Posted on 2011-03-22
6
581 Views
Last Modified: 2013-12-07
We have about 200 workers from around the country that login and work remotely. They login according to their jobs.

Some login to....
* a VPN (this is a Linux machine) this authenticates via AD.
* SharePoint
* OWA
* Outlook (RPC over HTTP)
* Target Process
* Etc

This is a volunteer project and we just need to see who is active. So we would like to see if there is any software we already have or that we can get to record ever time someone authenticates via AD no matter if it is the VPN, OWA, Outlook ETC. Most server are 2008 R2 Datacenter.

Network made up of 2 DC, Exchange 2010 with an Edge Server, MS Threat Management Gateway, SharePoint 3.0 moving to 2010, WSUS, AV, 2 Spiceworks, Target Process, etc etc.

(MS Threat Management Gateway is not being used as a firewall it is used to publish things like SharePoint OWA etc to the internet so we do not have to use the VPN for those things)  
0
Comment
Question by:RickEpnet
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
6 Comments
 
LVL 57

Accepted Solution

by:
Mike Kline earned 500 total points
ID: 35191804
You could view security logs on your DCs, but one good way to ID old/stale accounts is a tool like old computer from Joe Richards

http://joeware.net/freetools/tools/oldcmp/index.htm

...also works with users

You can key off lastlogontimestamp which is accurate up to 9-14 days

Thanks

Mike
0
 
LVL 14

Author Comment

by:RickEpnet
ID: 35191934
I have something similar to this already. The problem with lastlogontimestamp is you really have to run it on both DC for an simi-accurate picture.

We are really looking for something a little more robust. Not necessarily need it to be free.
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 35191979
if you were looking at lastlogon then you would need to run it against all the DCs because it doesn't replicate but lastlogontimestamp does replicate

Thanks

Mike
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 14

Author Comment

by:RickEpnet
ID: 35195123
Ok so I am trying to figure out the commend line to get what I want but I am having a hard time can you help.
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 35195246
Are you trying to use oldcmp?  Is that the command line you are looking for?

Thanks

Mike
0
 
LVL 14

Author Closing Comment

by:RickEpnet
ID: 35195484
Thanks!!
0

Featured Post

Space-Age Communications Transitions to DevOps

ViaSat, a global provider of satellite and wireless communications, securely connects businesses, governments, and organizations to the Internet. Learn how ViaSat’s Network Solutions Engineer, drove the transition from a traditional network support to a DevOps-centric model.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article describes my battle tested process for setting up delegation. I use this process anywhere that I need to setup delegation. In the article I will show how it applies to Active Directory
Recently, Microsoft released a best-practice guide for securing Active Directory. It's a whopping 300+ pages long. Those of us tasked with securing our company’s databases and systems would, ideally, have time to devote to learning the ins and outs…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Suggested Courses

751 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question