LastLogonTimeStamp Attribute Not Updated for Computer Account Over SSL-VPN
we use lastlogontimestamp (llts) find stale computer accounts, disable them, , delete time. have found domain member computers connect domain exclusively ssl-vpn (for instance in case of employees work home office) not update llts. consequently these computers appear on stale computer reports.
i suppose required logon type never used when connecting on ssl-vpn. therefore know if there way via a logon script or other method can update attribute.
that normal connect vpn using locally cached credentials user , computer accounts.
my recommendation track these computers have agent periodically report computer status (example: using microsoft intune) or have scheduled task run script when user connected vpn , register computer name active in file hosted in share.
this posting provided no warranties or guarantees , , confers no rights.
ahmed malek
my website link my linkedin profile my mvp profile
Windows Server > Directory Services
Comments
Post a Comment