Many a time, Active Directory administrators find it difficult to decipher the exact true last logon time of users. As in most cases, multiple domain controllers are present in a domain, each of them would be holding a different last logon value. With each Domain controller showing up different logon details for the same user account, the identification process becomes even complicated. Native AD tools, PowerShell, etc. only add to the already huge list of complexities. Since synchronization of login data does not essentially happen between the domain controllers, it becomes quite tedious to retrieve the users' correct last logon values from the DC, which recently authenticated the Users' latest logon. This is exactly when, the Real Last Logon Report from ADManager Plus comes in handy. Using ADManager Plus you can,
The Real Last Logon Report from ADManager Plus, displays the actual date and time when a user last logged on to the Windows network. This information is retrieved by querying all the configured Domain Controllers in a given Domain. This information retrieval mechanism offers greater reliablity of the user logon details by ensuring accuracy of the user's login data. The real last logon report is surely an advantage for administrators, who can easily retrieve the most recent last login value of all users in their organization's active directory infrastructure.Administrators can either generate real last logon reports for individual users in AD or can restrict report generation to specific domains, groups or Organizational Units.
When you generate the Real Last Logon Report, the default attributes namely Display Name, SAM Account name, When Created (Detail on when the user account was created, Last Logon Time and Logon Count will be displayed. However, ADManager Plus comes with in-built options to customize the attributes that need to be displyed along with the user last logon details. You can simply add customized attributes from extended schemas to desired reports by supplying details like Display Name, the attribute's LDAP Name, data type, etc. The add/remove columns option in the Real Last Logon report, helps perform this functionality.
Active directory administrators can perform various actions based on the Users' Real Last Logon values. Users can be easily disabled, deleted or enabled from the generated report using the right options. Functions like Reset password, unlock user accounts, move users, modify profile attributes,inheritable permissions, group attributes, etc, can be carried out the on the results of the generated Real Last Logon report. Get the free download of this Active Directory reporting tool's trial version to try out all the management from reports features.
The Active Directory Real Last Logon Report, plays an important role in the Active directory Clean Up procedure. From the results displayed in the Real Last Logon Report, administrators can identify unused or obsolete user accounts. Stale/inactive user accounts are determined based on the true last logon time of users. Administrators can then isolate these accounts by moving them to separate OUs or simply delete or disable them. This is considered to be security routine to avoid any unforeseen security threat as a result of their existence. To know more about the Clean Up Activity, visit our page on Active Directory Clean Up.
Featured reports
Fire a shotgun-shell of AD User Management Tasks in a Single Shot. Also use csv files to manage users. Effect bulk changes in the Active Directory, including configuring Exchange attributes.
Manage your Active Directory Security Groups. Create, Delete and Modify Groups...all in a few clicks. Configure Exchange attributes of AD Groups and effect bulk group changes to your AD security groups.
Active Directory reports to assist you for compliance to Government Regulatory Acts like SOX, HIPAA, GLBA, PCI, USA PATRIOT...and much more! Make your organization compliance-perfect!
Unload some of your workload without losing your hold. Secure & non-invasive helpdesk delegation and management from ADManager Plus! Delegate powers for technician on specific tasks in specific OUs.
Get rid of the inactive, obsolete and unwanted objects in your Active Directory to make it more secure and efficient...assisted by ADManager Plus's AD Cleanup capabilities.
A complete automation of AD critical tasks such as user provisioning, inactive-user clean up etc. Also lets you sequence and execute follow-up tasks and blends with workflow to offer a brilliant controlled-automation.
Need Features? Tell Us
If you want to see additional features implemented in ADManager Plus, we would love to hear. Click here to continue