Solved

custom search ad users and computers.

Posted on 2014-03-26
9
352 Views
Last Modified: 2014-04-08
is there anyway in ad users and computers to run a report to list all users (logonname), their status (i.e. disabled/expired/active) and the fields lastlogon and lastlogontimestamp. I thought there may be a way to do it in custom search area of a new query in ADUC, but couldnt find the fields. If I double click a user objecy in ADUC the fields and dates can be found in the attribute editor tab.
 
Any help most welcome. Can it be done in the LDAP query section?
0
Comment
Question by:pma111
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
  • 2
  • +1
9 Comments
 
LVL 8

Expert Comment

by:Camy
ID: 39955989
Powershell would probably be the way to do it - what version of Windows Server are you running?
0
 
LVL 14

Accepted Solution

by:
Justin Yeung earned 300 total points
ID: 39956009
This one line powershell command can export the data that you want to get from AD

Import-Module ActiveDirectory
Get-Aduser -Filter * -Properties * | Select-Object Name,SamAccountName,Enabled,AccountExpirationDate,@{Name="LastLogonTimestamp"; Expression={[DateTime]::FromFileTime($_.lastLogonTimestamp)}},@{Name="Lastlgon"; Expression={[DateTime]::FromFileTime($_.lastlogon)}},LastlogonDate | Export-Csv C:\Export.csv

Open in new window

0
 
LVL 3

Author Comment

by:pma111
ID: 39956014
Do you have to download something first before this will work, i.e. the AD module?
0
Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

 
LVL 3

Author Comment

by:pma111
ID: 39956018
2008 - but I wanted to know (as per the question) if it was do-able within ADUC.
0
 
LVL 14

Expert Comment

by:Justin Yeung
ID: 39956036
probably not in ADUC
0
 
LVL 8

Assisted Solution

by:Camy
Camy earned 100 total points
ID: 39956052
Definitley not in ADUC, the columns available for results are limited.
If you are running it from the Domain Controller it should have the AD module (and powershell) available already.
0
 
LVL 3

Author Comment

by:pma111
ID: 39956069
will give the powershell solution a go. many thanks
0
 
LVL 14

Expert Comment

by:Justin Yeung
ID: 39956534
RSAT on workstation or run it directly on a Domain controller which already include Active Directory powershell Module.
0
 
LVL 3

Assisted Solution

by:chuckmccullough
chuckmccullough earned 100 total points
ID: 39960053
You can add to the columns available for display in ADUC using ADSIEdit. Here are a few sites with examples:

http://markparris.co.uk/2011/12/12/add-operating-system-and-service-pack-information-to-active-directory-users-and-computers/

http://pberblog.com/post/2009/06/21/Add-extra-columns-to-Active-Directory-Users-and-Computers-display.aspx

I ran a quick test just now and unfortunately ADUC doesn't produce much for the fields you need for this particular report. The examples provided on the links above might prove useful for future reports, though.

If you aren't comfortable diving into PowerShell as mentioned above, most of the popular GUI utilities out there should give you this report fairly easily. The company I work for has a product called Hyena that allows you to create reports like this by picking and choosing the attributes you want:

http://www.systemtools.com/hyena/
0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Background Information Recently I have fixed file server permission issues for one of my client. The client has 1800 users and one Windows Server 2008 R2 domain joined file server with 12 TB of data, 250+ shared folders and the folder structure i…
In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

756 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question