|
Yep.
This is exactly how it should be done. If you have any Samba or crappy CIFS/SMB
emulators (won't mention specific storage companies but they know who they
are and hopefully are fixing this issue at the speed of light) watch out though
because they set the password to never expire on the machine account and then
don't change it.
If you
don't want to script, go grab secdata from www.joeware.net on the free win32 tools page.
With the /computers option it will dump a csv type format of computers (you can
specify a base dn and/or computer name filter) and some of the security info
including last logon (for that dc), password change, useraccount flags, etc.
joe
|
Title: Message
- RE: [ActiveDir] LDAP & LastLogin for Com... Robbie Allen
- RE: [ActiveDir] LDAP & LastLogin fo... Roger Seielstad
- RE: [ActiveDir] LDAP & LastLogin fo... Steve Rochford
- RE: [ActiveDir] LDAP & LastLogin fo... Coleman, Hunter
- Re: [ActiveDir] LDAP & LastLogi... Glenn Corbett
- RE: [ActiveDir] LDAP & LastLogin fo... England, Christopher M
- RE: [ActiveDir] LDAP & LastLogin fo... Coleman, Hunter
- RE: [ActiveDir] LDAP & LastLogin fo... Coleman, Hunter
- Re: [ActiveDir] LDAP & LastLogi... Glenn Corbett
- Re: [ActiveDir] LDAP & Last... Jan Wilson
- Re: [ActiveDir] LDAP & ... Glenn Corbett
- RE: [ActiveDir] LDAP & LastLogin fo... Bjelke John A Contr AFRL/VSIO
