|
Yep.
Accounts flagged to change their password on next
logon are indicated by pwdLastSet being set to 0. Much easier to search for
that than that useraccountcontrol flag. I actually MS pulls them all out of that
thing. Bit flags are a pain in the butt with LDAP.
Locked Out accounts are maintained in lockoutTime but it is
kind of involved on how to really check it. I suggest unlock.exe for
checking - www.joeware.net on the free
win32 tools page. Recipe 6.9 in Robbie's book. ;o)
Note that pwdLastSet will not go to 0 when a password
expires. That becomes an issue with decoding the value of the attribute and
comparing to the domain policy like with lockouts.
joe
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Robbie Allen Sent: Thursday, December 04, 2003 11:49 PM To: [EMAIL PROTECTED] Subject: RE: [ActiveDir] UserAccountControl Bitwise question The problem is the KB article, not you Mark. The
userAccountControl attribute isn't updated when the password expires. Same
for the lockout flag.
Regards.
Robbie Allen
|
- [ActiveDir] UserAccountControl Bitwise question Creamer, Mark
- RE: [ActiveDir] UserAccountControl Bitwise question Mulnick, Al
- RE: [ActiveDir] UserAccountControl Bitwise question Creamer, Mark
- RE: [ActiveDir] UserAccountControl Bitwise question Robbie Allen
