Real Last Logon Report on Windows Users
Many a time, Active Directory administrators find it difficult to decipher the exact true last logon time of users. As in most cases, multiple domain controllers are present in a domain, each of them would be holding a different last logon value. With each Domain controller showing up different logon details for the same user account, the identification process becomes even complicated. Native AD tools, PowerShell, etc. only add to the already hige list of complexities. Since synchronization of login data does not essentially happen between the domain controllers, it becomes quite tedious to retrieve the users' correct last logon values from the DC, which recently authenticated the Users' latest logon. This is exactly when, the Real Last Logon Report from ADManager Plus comes in handy. Using ADManager Plus you can,
The Real Last Logon Report from ADManager Plus, displays the actual date and time when a user last logged on to the Windows network. This information is retrieved by querying all the configured Domain Controllers in a given Domain. This information retrieval mechanism offers greater reliablity of the user logon details by ensuring accuracy of the user's login data. The real last logon report is surely an advantage for administrators, who can easily retrieve the most recent last login value of all users in their organization's active directory infrastructure.Administrators can either generate real last logon reports for individual users in AD or can restrict report generation to specific domains, groups or Organizational Units.
When you generate the Real Last Logon Report, the default attributes namely Display Name, SAM Account name, When Created (Detail on when the user account was created, Last Logon Time and Logon Count will be displayed. However, ADManager Plus comes with in-built options to customize the attributes that need to be displyed along with the user last logon details. You can simply add customized attributes from extended schemas to desired reports by supplying details like Display Name, the attribute's LDAP Name, data type, etc. The add/remove columns option in the Real Last Logon report, helps perform this functionality.
Active directory administrators can perform various actions based on the Users' Real Last Logon values. Users can be easily disabled, deleted or enabled from the generated report using the right options. Functions like Reset password, unlock user accounts, move users, modify profile attributes,inheritable permissions, group attributes, etc, can be carried out the on the results of the generated Real Last Logon report.
The Active Directory Real Last Logon Report, plays an important role in the Active directory Clean Up procedure. From the results displayed in the Real Last Logon Report, administrators can identify unused or obsolete user accounts. Stale/inactive user accounts are determined based on the true last logon time of users. Administrators can then isolate these accounts by moving them to separate OUs or simply delete or disable them. This is considered to be security routine to avoid any unforeseen security threat as a result of their existence. To know more about the Clean Up Activity, visit our page on Active Directory Clean Up.
Need Features? Tell Us
"We evaluated ADManager Plus along with several other Active Directory Management and Reporting software. After using it really made life easy for administrators. It is very understandable and fast to learn, I didn't even read the manual."
Bogdan Campeanu, Network Engineer