Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

The lastLogon attribute is not updated when a client computer runs an LDAP simple bind operation against a Windows Server 2003-based domain controller


View products that this article applies to.

Symptoms

A client computer runs a Lightweight Directory Access Protocol (LDAP) simple bind operation against a Windows Server 2003-based domain controller. The logon process does not update the lastLogon attribute in the Active Directory directory service schema of the domain controller. However, the lastLogonTimestamp attribute is updated.

↑ Back to the top


Cause

The lastLogon attribute reflects the last interactive logon, not the last network-based logon. The lastLogonTimestamp attribute reflects simple bind operations and NTLM network-based logons. This behavior enables stale account cleanup in Active Directory without affecting LDAP client authentication that uses only simple bind operations.

↑ Back to the top


Resolution

To resolve the problem, switch the domain to the Windows 2003 Domain Mode. Then, you can use the lastLogonTimestamp attribute.

↑ Back to the top


Status

Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section.

↑ Back to the top


More information

For more information about the lastLogonTimestamp attribute, click the following article number to view the article in the Microsoft Knowledge Base:
886705 A network logon that uses NTLM authentication does not update the lastLogonTimestamp attribute in the Active Directory schema of a Windows Server 2003-based domain controller
To display all domain users who have been inactive for 10 weeks or more, type the following command at a command prompt:
DSQUery.exe user inactive 10
For more information, visit the following Microsoft Web sites:Note When you visit the last Web site that is listed, search for the "Security protocols that update lastLogonTimeStamp in Windows Server 2003" topic.

↑ Back to the top


Keywords: kbtshoot, kbexpertiseinter, kbprb, KB939899

↑ Back to the top

Article Info
Article ID : 939899
Revision : 6
Created on : 11/20/2007
Published on : 11/20/2007
Exists online : False
Views : 323