Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted
On a closed network, my administrator needed a script/automated tool to disable any users in Active Directory who had not logged in for 90 days. I checked the GUI to see the users that had not logged in recently. There were 5. I opened up a command window and showed him dsquery. When I ran "dsquery user", I got the expected results. I then ran "dsquery user -inactive 13" and only received 1 user as the result. I thought maybe the others were borderline on the 90-91 days, so I changed my query to "dsquery user -inactive 1" and still only received the 1 user for the result. After adding in the proper ou, dc, dn...I get the same results. I have looked on this site and researched online, but I cannot find anyone that has had this issue. I hope I am just doing something wrong, but this query is pretty basic. Could there be a server setting that is causing just the 1 user to be returned. I would think that it was a setting if I received no results. Thanks in advance for any help troubleshooting this.
Posted

If you know what users you are missing, could you try running a lastlogon against their samaccountname to see what the system thinks was their last logon was, so you can work out why the inactive query isn't picking them up like it should be?

 

Or have a read through this - I've just googled this so it might be overkill...

 

Option Explicit

Dim adoCommand, adoConnection, strBase, strFilter, strAttributes
Dim objRootDSE, strDNSDomain, strQuery, adoRecordset, strName
Dim intDays, dtmDate, objShell, lngBiasKey, lngBias, k
Dim lngSeconds, str64Bit, strDisplay
Dim objDate, dtmLastDate, lngHigh, lngLow
Dim strFile, objFSO, objFile

Const ForWriting = 2
Const OpenAsASCII = 0
Const CreateIfNotExist = True

' Specify number of days.
intDays = 180

' Specify file for report.
strFile = "c:\Scripts\StaleUsers.csv"

' Open text file for writting.
Set objFSO = CreateObject("Scripting.FileSystemObject")

' Open the file for write access.
Set objFile = objFSO.OpenTextFile(strFile, _
   ForWriting, CreateIfNotExist, OpenAsASCII)

' Determine date the specified number of days in the past.
dtmDate = DateAdd("d", - intDays, Now())

' Obtain local Time Zone bias from machine registry.
' This bias changes with Daylight Savings Time.
Set objShell = CreateObject("Wscript.Shell")
lngBiasKey = objShell.RegRead("HKLM\System\CurrentControlSet\Control\" _
   & "TimeZoneInformation\ActiveTimeBias")
If (UCase(TypeName(lngBiasKey)) = "LONG") Then
   lngBias = lngBiasKey
ElseIf (UCase(TypeName(lngBiasKey)) = "VARIANT()") Then
   lngBias = 0
   For k = 0 To UBound(lngBiasKey)
       lngBias = lngBias + (lngBiasKey(k) * 256^k)
   Next
End If

' Convert the datetime value to UTC.
dtmDate = DateAdd("n", lngBias, dtmDate)

' Find number of seconds since 1/1/1601 for this date.
lngSeconds = DateDiff("s", #1/1/1601#, dtmDate)

' Convert the number of seconds to a string
' and convert to 100-nanosecond intervals.
str64Bit = CStr(lngSeconds) & "0000000"

' Setup ADO objects.
Set adoCommand = CreateObject("ADODB.Command")
Set adoConnection = CreateObject("ADODB.Connection")
adoConnection.Provider = "ADsDSOObject"
adoConnection.Open "Active Directory Provider"
Set adoCommand.ActiveConnection = adoConnection

' Search entire Active Directory domain.
Set objRootDSE = GetObject("LDAP://RootDSE")
strDNSDomain = objRootDSE.Get("defaultNamingContext")
strBase = ""

' Filter on disabled users that have not logged on in 6 months.
strFilter = "(&(objectCategory=person)(objectClass=user)" _
   & "(userAccountControl=2)(lastLogonTimeStamp<=" & str64Bit & "))"

' Comma delimited list of attribute values to retrieve.
strAttributes = "sAMAccountName,displayName,lastLogonTimeStamp"

' Construct the LDAP syntax query.
strQuery = strBase & ";" & strFilter & ";" & strAttributes & ";subtree"
adoCommand.CommandText = strQuery
adoCommand.Properties("Page Size") = 200
adoCommand.Properties("Timeout") = 30
adoCommand.Properties("Cache Results") = False

' Run the query.
Set adoRecordset = adoCommand.Execute

' Enumerate the resulting recordset.
Do Until adoRecordset.EOF
   ' Retrieve values and display.
   strName = adoRecordset.Fields("sAMAccountName").Value
   strDisplay = adoRecordset.Fields("displayName").Value
   On Error Resume Next
   Set objDate = adoRecordset.Fields("lastLogonTimeStamp").Value
   If (Err.Number <> 0) Then
       On Error GoTo 0
       dtmLastDate = #1/1/1601#
   Else
       On Error GoTo 0
       lngHigh = objDate.HighPart
       lngLow = objDate.LowPart
       If (lngLow < 0) Then
           lngHigh = lngHigh + 1
       End If
       If (lngHigh = 0) And (lngLow = 0) Then
           dtmLastDate = #1/1/1601#
       Else
           dtmLastDate = #1/1/1601# + (((lngHigh * (2 ^ 32)) _
               + lngLow)/600000000 - lngBias)/1440
       End If
   End If
   ' Write to file, with comma delimited fields.
   objFile.WriteLine """" & strName & """,""" & strDisplay _
       & """,""" & CStr(dtmLastDate) & """"
   ' Move to the next record in the recordset.
   adoRecordset.MoveNext
Loop

' Clean up.
objFile.Close
adoRecordset.Close
adoConnection.Close

 

From: https://social.technet.microsoft.com/Forums/windowsserver/en-us/c86504ff-d10e-4f20-bb32-d5a6e9a74546/using-dsquery-to-list-inactive-users-with-last-logon-date?forum=winserverDS

Posted
Thanks, Oaktech. I used a dsquery that I found online to check out everyone's lastlogon and lastlogontimestamp. Out of all of the users, only 6 had values for those two. I meant to update earlier, but I've been in a class. Thanks for pointing me in the right direction. Now, I just need to find out why they have those values in the GUI but not when I use dos.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...