Active Directory LastLogonTimeStamp 属性已关闭
我制作了一份报告,确定了 60 天以上的陈旧帐户。对于这一时间范围,我认为使用一个 DC 的 LastLogonTimeStamp 值就可以了。即使有 9-14 天的准确度警告,它也达到了目的。
问题是,有人发现了一个似乎不正确的帐户。此帐户的 LastLogonTimeStamp 包含 2011 年 7 月的日期。该用户自 2010 年以来就不再在该公司工作。
为了解决此差异,我查询了每个 DC 的 LastLogon 属性。它们全部要么是从不,要么是 2010 年。
我还查询了每个 DC 的 LastLogonTimeStamp,它们都是相同的,报告的日期是 2011 年 7 月。 LastLogonTimeStamp 对于绝大多数用户来说都是正确的,因此不存在潜在的复制问题。
那么这个 LastLogonTimeStamp 到底是从哪里来的,怎么会这么错误呢?
有什么想法吗?
非常感谢, 桑德拉
I produced a report identifying stale accounts older than 60 days. For this time frame, I figured it is fine to use the LastLogonTimeStamp value from one DC. Even with the 9-14 day accuracy caveat, it serves the purpose.
The problem is, someone identified one account that didn't seem right. LastLogonTimeStamp for this account contained a date in July 2011. The user has not been with the company since 2010.
To resolve the discrepancy, I queried each and every DC for the LastLogon attribute. ALL of them are either Never, or they are in 2010.
I also queried each DC for LastLogonTimeStamp, and they are all identical, reporting the July 2011 date. LastLogonTimeStamp is correct for the vast majority of users, so there isn't an underlying replication issue.
So where on earth is this LastLogonTimeStamp coming from, and how can it be so wrong?
Any ideas?
Thanks much,
Sandra
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(3)
请注意,LastLogon 和LastLogonTimestamp 属性不会使用相同的登录条件(即登录类型)进行更新。请参阅 http://support.microsoft.com/default.aspx? scid=kb;EN-US;939899 具体解释了它们可能不同的原因。
Note that the LastLogon and LastLogonTimestamp attributes are not updated using the same logon criteria (i.e. logon types). See http://support.microsoft.com/default.aspx?scid=kb;EN-US;939899 which explains specifically why they may be different.
来自 LastLogonTimeStamp 属性 – 它的设计目的及其工作原理
From The LastLogonTimeStamp Attribute – What it was designed for and how it works
LastLogonTimeStamp 是可复制属性,但该属性不会在用户每次成功登录时更新。仅当该属性的当前值早于当前时间减去 msDS-LogonTimeSyncInterval 属性的值时,才会更新该属性。
LastLogonTimeStamp is the replicable attribute but this attribute is not updated every time a user successfully logs in. This attribute is updated only when its current value is older than the current time minus the value of the msDS-LogonTimeSyncInterval attribute.