LastLogonTimeStamp Attribute Not Updated for Computer Account Over SSL-VPN


we use lastlogontimestamp (llts) find stale computer accounts, disable them, , delete time.  have found domain member computers connect domain exclusively ssl-vpn (for instance in case of employees work home office) not update llts.  consequently these computers appear on stale computer reports.

i suppose required logon type never used when connecting on ssl-vpn.  therefore know if there way via a logon script or other method can update attribute.

that normal connect vpn using locally cached credentials user , computer accounts.

my recommendation track these computers have agent periodically report computer status (example: using microsoft intune) or have scheduled task run script when user connected vpn , register computer name active in file hosted in share.


this posting provided no warranties or guarantees , , confers no rights.

ahmed malek

my website link

my linkedin profile

my mvp profile



Windows Server  >  Directory Services



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS