Query AD user objects to report the samaccountname that was initially used to create user objects

I would like to know if there is a query (preferably csvde command line) to report the samaccountname that was initially used to create user objects. Thank you
h2zeroAsked:
Who is Participating?

Improve company productivity with a Business Account.Sign Up

x
 
Mike KlineConnect With a Mentor Commented:
Unfortunately  there is no attribute for whocreated  if you have old security logs and have auditing turned on you could look through those.

THanks

Mike
0
 
gurutcCommented:
You can find out if you're lucky.  If you do backups of your DC and include the Security Log you can restore that log from backup for the day the user object was created.  If your logs don't roll over too quickly you may be able to find the userid object creation event.

This is the only way you'd be able to find this info out at this point

And it wouldn't be a report, it'd be one at a time.

Good Luck,
- gurutc
0
 
h2zeroAuthor Commented:
What if I have a report of specific user object's samaccountname is there an ADSI query or edit that can be run against those samaccountnames to determine which samaccountname was initially used to create? Thank you
0
 
gurutcCommented:
There isn't an ADSI query that will do what you need.  There's no attribute in AD for 'userid object creator.'  The only place that ever records the creation of a userid object is the Security Log, which rolls over too quickly to help most of the time.

Sorry to tell you that.

- gurutc
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.