none
ldap query find active users

    Question

  • Hi All,
    I need help with ldap query . I search the internet and all I could find is
    inactive user accts query for accounts that have NOT logged on the last x
    days .
     
    I need the reverse ldap query to find active/enabled user accounts that HAVE
    logged on within the last 120 days.
     
    Thanks in advance for your help.
     
     
    Friday, October 05, 2012 3:08 PM

Answers

  • Hello,

    As others mentioned, you can create an LDAP query which will query the lastlogontimestamp attribute to get approximately the last logon date of users. Based on it, you can determine the users which logged on recently. Here, note that the lastlogontimestamp can be delayed with 9-14 days behind the current date. If you want to get a more precise date, you have to query lastlogon attribute on each DC you have (This attribute is not replicated) and keep the highest value of it.

    To get lastlogonattribute in a readable format with a batch file, refer to this thread: http://social.technet.microsoft.com/Forums/en/ITCG/thread/19d35656-2be4-4665-822e-34c111e07da2


    This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.   

    Microsoft Student Partner 2010 / 2011
    Microsoft Certified Professional
    Microsoft Certified Systems Administrator: Security
    Microsoft Certified Systems Engineer: Security
    Microsoft Certified Technology Specialist: Windows Server 2008 Active Directory, Configuration
    Microsoft Certified Technology Specialist: Windows Server 2008 Network Infrastructure, Configuration
    Microsoft Certified Technology Specialist: Windows Server 2008 Applications Infrastructure, Configuration
    Microsoft Certified Technology Specialist: Windows 7, Configuring
    Microsoft Certified Technology Specialist: Designing and Providing Volume Licensing Solutions to Large Organizations
    Microsoft Certified IT Professional: Enterprise Administrator
    Microsoft Certified IT Professional: Server Administrator
    Microsoft Certified Trainer

    Friday, October 05, 2012 6:18 PM
  • If you are using QMM and taking about DirectorySync filter, you can still use the same LDAP filter.  But combing both can be a challenge inside QMM.  You may want run this through QMM supports guys.  It is not the LDAP issue.    FYI..I have used many crazy filters inside QMM J


    Santhosh Sivarajan | Houston, TX
    http://www.sivarajan.com/

    FaceBook Twitter LinkedIn SS Tech Forum

    This posting is provided AS IS with no warranties,and confers no rights.

    Friday, October 05, 2012 6:50 PM
    Moderator

All replies