LastLogonTimeStamp Attribute Not Updated for Computer Account Over SSL-VPN


we use lastlogontimestamp (llts) find stale computer accounts, disable them, , delete time.  have found domain member computers connect domain exclusively ssl-vpn (for instance in case of employees work home office) not update llts.  consequently these computers appear on stale computer reports.

i suppose required logon type never used when connecting on ssl-vpn.  therefore know if there way via a logon script or other method can update attribute.

that normal connect vpn using locally cached credentials user , computer accounts.

my recommendation track these computers have agent periodically report computer status (example: using microsoft intune) or have scheduled task run script when user connected vpn , register computer name active in file hosted in share.


this posting provided no warranties or guarantees , , confers no rights.

ahmed malek

my website link

my linkedin profile

my mvp profile



Windows Server  >  Directory Services



Comments

Popular posts from this blog

Azure MFA with Azure AD and RDS

Failed to setup initiator portal. Error status is given in the dump data.

Invalid pointer on gpresult /h gpreport.html