<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Replication of lastLogonTimeStamp</title>
	<atom:link href="http://blog.joeware.net/2007/05/01/864/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.joeware.net/2007/05/01/864/</link>
	<description>Information about joeware mixed with wild and crazy opinions...</description>
	<lastBuildDate>Wed, 17 Mar 2010 15:23:36 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Yogesh</title>
		<link>http://blog.joeware.net/2007/05/01/864/comment-page-1/#comment-50707</link>
		<dc:creator>Yogesh</dc:creator>
		<pubDate>Wed, 10 Sep 2008 14:00:08 +0000</pubDate>
		<guid isPermaLink="false">http://blog.joeware.net/2007/05/01/864/#comment-50707</guid>
		<description>Hi Joe,

We have to run a report every month for all domain users with their 2 attributes that are : LastLogon and lastlogontimestamp. 

But this time I have noticed that all lastlogontimestamp is not same on all DCs . Moreover users I have checked are those which have not logged in for past 3 months. 

Also difference in lastlogontimestamp is more tham 2 months in some cases which ideally shd not be more than 14 days (as per microsoft).

Kindly look into the above issue and help resolving this.

Note: except above issue rest is seems to be fine as far as replication is concerned. Specailly I checked schema partition replication among DC and it is fine.


Yogesh Malhotra</description>
		<content:encoded><![CDATA[<p>Hi Joe,</p>
<p>We have to run a report every month for all domain users with their 2 attributes that are : LastLogon and lastlogontimestamp. </p>
<p>But this time I have noticed that all lastlogontimestamp is not same on all DCs . Moreover users I have checked are those which have not logged in for past 3 months. </p>
<p>Also difference in lastlogontimestamp is more tham 2 months in some cases which ideally shd not be more than 14 days (as per microsoft).</p>
<p>Kindly look into the above issue and help resolving this.</p>
<p>Note: except above issue rest is seems to be fine as far as replication is concerned. Specailly I checked schema partition replication among DC and it is fine.</p>
<p>Yogesh Malhotra</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: joe</title>
		<link>http://blog.joeware.net/2007/05/01/864/comment-page-1/#comment-24567</link>
		<dc:creator>joe</dc:creator>
		<pubDate>Tue, 11 Sep 2007 15:38:34 +0000</pubDate>
		<guid isPermaLink="false">http://blog.joeware.net/2007/05/01/864/#comment-24567</guid>
		<description>Lifecycle management is a process problem, not technical. 

You need to come up with a process to mark every object in the directory that is created on behalf of some app/person/whatever and have a way to revalidate the need on some frequency (monthly, quarterly, yearly, bi-annually, whatever) and then enforce it. 

Some companies do this by adding new attributes to the top class and then populating them on all managed lifecycle objects and coming up with the background processes to keep everything current and if something goes out of currency, it gets smoked. 

It is a problem I would love to work on but no time to really dedicate to it. It can definitely be helped by technical solutions but it is at its core a process problem. 

There are no magic bullets.</description>
		<content:encoded><![CDATA[<p>Lifecycle management is a process problem, not technical. </p>
<p>You need to come up with a process to mark every object in the directory that is created on behalf of some app/person/whatever and have a way to revalidate the need on some frequency (monthly, quarterly, yearly, bi-annually, whatever) and then enforce it. </p>
<p>Some companies do this by adding new attributes to the top class and then populating them on all managed lifecycle objects and coming up with the background processes to keep everything current and if something goes out of currency, it gets smoked. </p>
<p>It is a problem I would love to work on but no time to really dedicate to it. It can definitely be helped by technical solutions but it is at its core a process problem. </p>
<p>There are no magic bullets.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John Ebuna</title>
		<link>http://blog.joeware.net/2007/05/01/864/comment-page-1/#comment-24566</link>
		<dc:creator>John Ebuna</dc:creator>
		<pubDate>Tue, 11 Sep 2007 15:33:35 +0000</pubDate>
		<guid isPermaLink="false">http://blog.joeware.net/2007/05/01/864/#comment-24566</guid>
		<description>Thanks for the fast reply. So do you have any suggestions on how to truly determine if a user account is being used within an AD environment?  Or is that just a pipe dream?</description>
		<content:encoded><![CDATA[<p>Thanks for the fast reply. So do you have any suggestions on how to truly determine if a user account is being used within an AD environment?  Or is that just a pipe dream?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: joe</title>
		<link>http://blog.joeware.net/2007/05/01/864/comment-page-1/#comment-24564</link>
		<dc:creator>joe</dc:creator>
		<pubDate>Tue, 11 Sep 2007 13:33:16 +0000</pubDate>
		<guid isPermaLink="false">http://blog.joeware.net/2007/05/01/864/#comment-24564</guid>
		<description>No way that I know of. This is a common problem, occurs with many VPN clients as well as cluster accounts and any machines that people have just turned off password changes on. Password changes are not required for computers like they are for users, it is entirely up to the machine if it wants to change the password or not.</description>
		<content:encoded><![CDATA[<p>No way that I know of. This is a common problem, occurs with many VPN clients as well as cluster accounts and any machines that people have just turned off password changes on. Password changes are not required for computers like they are for users, it is entirely up to the machine if it wants to change the password or not.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John Ebuna</title>
		<link>http://blog.joeware.net/2007/05/01/864/comment-page-1/#comment-24563</link>
		<dc:creator>John Ebuna</dc:creator>
		<pubDate>Tue, 11 Sep 2007 13:10:08 +0000</pubDate>
		<guid isPermaLink="false">http://blog.joeware.net/2007/05/01/864/#comment-24563</guid>
		<description>I&#039;ve seen many posts concerning the use of scripts and your utility, OLDCMP to remove unused accounts.  My problem is that I have remote users using Cisco VPN client to establish a connection to our internal network and their user and computer lastlogon properties don&#039;t appear to be updated.  How can I get these VPN users/computers to update their lastlogon attribute?</description>
		<content:encoded><![CDATA[<p>I&#8217;ve seen many posts concerning the use of scripts and your utility, OLDCMP to remove unused accounts.  My problem is that I have remote users using Cisco VPN client to establish a connection to our internal network and their user and computer lastlogon properties don&#8217;t appear to be updated.  How can I get these VPN users/computers to update their lastlogon attribute?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
