Don Jones
2007-07-31 07:44:16 UTC
We are using scripts to retrieve the LastLogon and LastLogonTimeStamp and are
finding that the values retrieve do not correspond with data in the security
log. With LastLogon, going to all the domain controllers and the value
retrieved is about 4 weeks older than what is in the security log. Using
LastLogonTimeStamp isn't much better, it's about 3 weeks older.
If we run the scripts against our development test AD Forest the scripts
appear to retrieve the values that are close to what is in the Security Log,
but when running against our production AD Forest,that is were we see a major
difference. We have found a single domain controller that wasn't having
changes applied. It was about 4 months behind. We do not manage our
Production AD Forest.
Is there any special privileges that are required to extract the lastlogon
or lastlogon timestamp info, that if you don't have the necessary rights will
produce bogus results? Is there a way to check the last time a domain
controller had changes applied without being a domain administrator?
Thanks.
Don Jones
finding that the values retrieve do not correspond with data in the security
log. With LastLogon, going to all the domain controllers and the value
retrieved is about 4 weeks older than what is in the security log. Using
LastLogonTimeStamp isn't much better, it's about 3 weeks older.
If we run the scripts against our development test AD Forest the scripts
appear to retrieve the values that are close to what is in the Security Log,
but when running against our production AD Forest,that is were we see a major
difference. We have found a single domain controller that wasn't having
changes applied. It was about 4 months behind. We do not manage our
Production AD Forest.
Is there any special privileges that are required to extract the lastlogon
or lastlogon timestamp info, that if you don't have the necessary rights will
produce bogus results? Is there a way to check the last time a domain
controller had changes applied without being a domain administrator?
Thanks.
Don Jones