Share via

keytab vs lastlogon

Lan, John 81 Reputation points
2023-10-13T14:53:20.9066667+00:00

From DC point of view, is there any difference between a normal user logon and an app using keytab? What event IDs are expected for a keytab logon? Does DC update lastlogon attribute for a keytab?

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
0 comments No comments

1 answer

Sort by: Most helpful
  1. Joe Sullivan 0 Reputation points
    2024-01-06T17:24:24.4133333+00:00

    For me, John, when I initiated a kinit (on Linux) to obtain a credential, it did update the last logon. It did not update password last set. When a Keytab file is issued, it updated the password last set, regardless of what password I entered. When loading the keytab, for ME, the lastLogon was updated correctly.

    I also used smbclient to verify that I could see a share that is on a Synology NAS with Active Directory integration.

    Joe

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.