Solved

AD Authentication Tracking

Posted on 2011-03-22
6
576 Views
Last Modified: 2013-12-07
We have about 200 workers from around the country that login and work remotely. They login according to their jobs.

Some login to....
* a VPN (this is a Linux machine) this authenticates via AD.
* SharePoint
* OWA
* Outlook (RPC over HTTP)
* Target Process
* Etc

This is a volunteer project and we just need to see who is active. So we would like to see if there is any software we already have or that we can get to record ever time someone authenticates via AD no matter if it is the VPN, OWA, Outlook ETC. Most server are 2008 R2 Datacenter.

Network made up of 2 DC, Exchange 2010 with an Edge Server, MS Threat Management Gateway, SharePoint 3.0 moving to 2010, WSUS, AV, 2 Spiceworks, Target Process, etc etc.

(MS Threat Management Gateway is not being used as a firewall it is used to publish things like SharePoint OWA etc to the internet so we do not have to use the VPN for those things)  
0
Comment
Question by:RickEpnet
  • 3
  • 3
6 Comments
 
LVL 57

Accepted Solution

by:
Mike Kline earned 500 total points
Comment Utility
You could view security logs on your DCs, but one good way to ID old/stale accounts is a tool like old computer from Joe Richards

http://joeware.net/freetools/tools/oldcmp/index.htm

...also works with users

You can key off lastlogontimestamp which is accurate up to 9-14 days

Thanks

Mike
0
 
LVL 14

Author Comment

by:RickEpnet
Comment Utility
I have something similar to this already. The problem with lastlogontimestamp is you really have to run it on both DC for an simi-accurate picture.

We are really looking for something a little more robust. Not necessarily need it to be free.
0
 
LVL 57

Expert Comment

by:Mike Kline
Comment Utility
if you were looking at lastlogon then you would need to run it against all the DCs because it doesn't replicate but lastlogontimestamp does replicate

Thanks

Mike
0
What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

 
LVL 14

Author Comment

by:RickEpnet
Comment Utility
Ok so I am trying to figure out the commend line to get what I want but I am having a hard time can you help.
0
 
LVL 57

Expert Comment

by:Mike Kline
Comment Utility
Are you trying to use oldcmp?  Is that the command line you are looking for?

Thanks

Mike
0
 
LVL 14

Author Closing Comment

by:RickEpnet
Comment Utility
Thanks!!
0

Featured Post

Better Security Awareness With Threat Intelligence

See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

Join & Write a Comment

OfficeMate Freezes on login or does not load after login credentials are input.
Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
This tutorial will give a short introduction and overview of Backup Exec 2012 and how to navigate and perform basic functions. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as conne…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now