Active Directory Reset pasword vs lastLogonTimestamp

KatTer 6 Reputation points
2021-03-23T11:07:36.97+00:00

We noticed that in Active Directory configured at Windows Server 2019 reset password is changing lastLogonTimestamp. Is it correct behavior?

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,906 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Fan Fan 15,291 Reputation points Microsoft Vendor
    2021-03-24T00:54:39.733+00:00

    Hi,

    Interactive, Network, and Service logons will update the lastLogontimeStamp . So if a user logs on interactively, browses a network share, access the email server, runs an LDAP query etc… the lastLogontimeStamp attribute will updated if the right condition is met.
    The lastLogontimeStamp attribute is not updated every time a user or computer logs on to the domain. The decision to update the value is based on the current date minus the value of the ( ms-DS-Logon-Time-Sync-Interval attribute minus a random percentage of 5).
    For more information , you can refer to the following link:
    https://techcommunity.microsoft.com/t5/ask-the-directory-services-team/8220-the-lastlogontimestamp-attribute-8221-8211-8220-what-it-was/ba-p/396204

    When you reset the password through the ADUC, It will not effect the lastLogonTimestamp attribute .
    The Lastlogon attribute will change immediately, but not the lastLogonTimestamp attribute.

    80790-3241.jpg
    80769-3242.jpg