Link to home
Start Free TrialLog in
Avatar of rdefino
rdefinoFlag for United States of America

asked on

Does a windows server "login" or check into active directory?

We are trying to determine if some of our windows are being used or not. I was hoping there is a way to check in AD for the last login time-stamp or some way that the server will login or check into AD.

Is there any such way to determine if the server if actively logging into AD?
Avatar of John
John
Flag of Canada image

You need to enable auditing in the server going forward to determine this. Without auditing, I do not think you can accurately determine this.
Avatar of rdefino

ASKER

So you mean enable it on all the servers that I need to pull this info for?  Once it's enabled, what will that produce? What would I look for to determine this?
ASKER CERTIFIED SOLUTION
Avatar of John
John
Flag of Canada image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
You should only need to enable auditing on the main DC, where AD is installed, no matter which server is logged into it will always go back to authenticate with Kerberos.  There should also be a section under each user account in AD that shows the last time the account authenticated.
Avatar of deroode
In Active Directory Users and Computers, make sure you have View - Advanced Features checked; Then find the server object, and on the Object tab you can see the date that the server object is created and also the date Modified, which is usually the last time the server has been restarted; When restarting a server it will log into Active Directory, thus updating the Modified date;
Avatar of rdefino

ASKER

Is there any other reason the "Modified date" would change other than a reboot?
Yes. For example if one of your system admins moves a computer object to a different OU the modified date will change. I'm not aware of anything the server itself can do to change the modified date exept for rebooting...
Avatar of rdefino

ASKER

So any idea what attribute I could use to determine if a system is being used or just sitting there? I was thinking the lastlogin time stamp. I have a report toll that will look at every DC and take the newest timestamp for each system. But I;'m not sure what caused the lastlogin time stamp to get modified and if it's a good way to good to determine what system are used or not.
Well, if you do not want the time the server is logging in into AD, but the time any users are logging in to the server you will need auditing as John Hurst suggested.
@rdefino - Thanks and good luck with implementing server auditing.