For more information about the lastLogonTimestamp attribute, click the following article number to view the article in the Microsoft Knowledge Base:
886705
 A
			 network logon that uses NTLM authentication does not update the
			 lastLogonTimestamp attribute in the Active Directory schema of a Windows Server
			 2003-based domain controller
 To
		  display all domain users who have been inactive for 10 weeks or more, type the
		  following command at a command prompt:    
DSQUery.exe user inactive
		  10
For more information, visit the following Microsoft Web sites:
Note When you visit the last Web site that is listed, search for the "Security protocols that update lastLogonTimeStamp in Windows Server 2003" topic.