Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

AD property in UserPrincipal is not the same as in AD Users and Computer snap-in

Posted on 2014-12-24
1
Medium Priority
?
88 Views
Last Modified: 2014-12-28
Hi, I'm using VS2013, C# and asp.net

In my code,my UserPrincipal object's AccountExpirationDate property shows 12/21/2014.  But when I check in AD Users and Computer snap-in, Account tab, it shows the account expires end of 12/19/2012.  That's 2 days difference.  Is this a known bug?  How to fix this?

Also, if the account is expired, today's date is 12/24/2012, however, UserPrincipal object's Enabled property still shows true and in AD Users and Computer snap-in the account doesn't have the account disabled checked either.  This data is correct but is mis-leading.  So when an account is expired, even though it's not disabled, user still can't log in using that account?

Thank you.
0
Comment
Question by:lapucca
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
1 Comment
 
LVL 17

Accepted Solution

by:
Tony Massa earned 2000 total points
ID: 40517297
ADUC, and other tools generally decode this attribute to align with the date/time of the computer you're viewing the information from.

The accountExpires attribute is stored in a large integer that represents number of 100 millisecond intervals from Jan 1, 1601 (UTC)

http://msdn.microsoft.com/en-us/library/ms675098(v=vs.85).aspx

Here's some decode infomation for C#
http://stackoverflow.com/questions/6360284/convert-ldap-accountexpires-to-datetime-in-c-sharp
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Auditing domain password hashes is a commonly overlooked but critical requirement to ensuring secure passwords practices are followed. Methods exist to extract hashes directly for a live domain however this article describes a process to extract u…
Group policies can be applied selectively to specific devices with the help of groups. Utilising this, it is possible to phase-in group policies, over a period of time, by randomly adding non-members user or computers at a set interval, to a group f…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
Suggested Courses

722 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question