🖥️
Active Directory Software

ASN Active Directory Manager

Comprehensive bulk AD management — create, modify, delete and report on users, groups, computers, contacts, OUs and more across unlimited domains from one install.

130+
AD Report Types
Domains
14
Day Free Trial

Real Last Logon Report

It is important for the Active Directory Administrators to find the inactive users and computers periodically and make necessary actions such as disable, delete the inactive users to avoid security threatens.

Inactive users are found out by querying their lastLogon attribute values. Whenever the user authenticated by a Domain controller, the lastLogon attribute is updated with the authenticated time. The lastLogon attribute is not a replicated between the Domain controllers to reduce the replication traffic. So, querying inactive users by the lastLogon attribute on a particular Domain controler will lead into incorrect results.

To exactly track all the inactive users and computers, lastLogon attribute needs to be queried in all the domain controllers and the most recent date & time value needs to be taken. So this report is called as Real last logon report.

ASN Active Directory Manager queries the given domain controllers to generate the inactive users and computers report (Users not logged on in last few days). And the report table shows the resolved most recent logon as well as the lastLogon attribute values in all the given domain controllers. Administrators can easily view the inactive users reports and their last authenticated time on all the given domain controllers. This helps the Administrators to take any actions such as disable, delete, move on the inactive users and computers.

ASN Active Directory Manager requires two inputs to generate the inactive users and computers reports. The inputs are,

  1. Number of days - Users/Computers being inactive for last mentioned days.
  2. Specify Domain Controllers - The specified domain controllers are queried with the lastLogon attribute for the all the users in the given container scope.

Please refer the below image to know about specifying inputs to generate the real inactive users report,

Specifying inputs for Real Last Logon Report

All the domain controllers are listed under the domain controller options section. The domain controllers that are currently not accessible are disbled and are not included in the query. Tick the domain controllers that are needs to queried, all the connected domain controllers are ticked by default. At least one domain controller must be ticked to generate the report.

Please refer the below image for the sample inactive users report,

Sample Inactive Users Report

In the report table, it can be noticed that the last two columns are the selected domain controllers. Last logged on column shows the resolved last logon value.