Solved

AD property in UserPrincipal is not the same as in AD Users and Computer snap-in

Posted on 2014-12-24
1
78 Views
Last Modified: 2014-12-28
Hi, I'm using VS2013, C# and asp.net

In my code,my UserPrincipal object's AccountExpirationDate property shows 12/21/2014.  But when I check in AD Users and Computer snap-in, Account tab, it shows the account expires end of 12/19/2012.  That's 2 days difference.  Is this a known bug?  How to fix this?

Also, if the account is expired, today's date is 12/24/2012, however, UserPrincipal object's Enabled property still shows true and in AD Users and Computer snap-in the account doesn't have the account disabled checked either.  This data is correct but is mis-leading.  So when an account is expired, even though it's not disabled, user still can't log in using that account?

Thank you.
0
Comment
Question by:lapucca
1 Comment
 
LVL 17

Accepted Solution

by:
Tony Massa earned 500 total points
ID: 40517297
ADUC, and other tools generally decode this attribute to align with the date/time of the computer you're viewing the information from.

The accountExpires attribute is stored in a large integer that represents number of 100 millisecond intervals from Jan 1, 1601 (UTC)

http://msdn.microsoft.com/en-us/library/ms675098(v=vs.85).aspx

Here's some decode infomation for C#
http://stackoverflow.com/questions/6360284/convert-ldap-accountexpires-to-datetime-in-c-sharp
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Media.Imaging 1 18
Video Player 11 23
Import groups from "Member Of" of user to a notepad. 4 44
Existing Office 365 implement on-premise AD 4 36
Find out how to use Active Directory data for email signature management in Microsoft Exchange and Office 365.
While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

785 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question