How to find out the User's Last Logon using ADAudit Plus

How to find out the User's Last Logon using ADAudit Plus

In this article:  

  • Objective

  • Prerequisites

  • Step to follow

  • Validation and confirmation

  • Best practices

  • Related topics and articles

 Objective   

This article explains how to retrieve a user’s last logon details using ADAudit Plus.

 Prerequisites   

  • Ensure you have access to the ADAudit Plus console.

  • Log in with an administrator role or a technician account that has the necessary privileges.

  • Verify that all domain controllers are added and configured in ADAudit Plus.

  • Confirm that data collection is occurring in real time.

  • Make sure the required audit policies are enabled.

 Steps to follow 

  1. Log in to the ADAudit Plus console as an administrator.

  2. Navigate to the Active Directory tab.

  3. Click the User Logon Reports category to expand it, then select Users Last Logon.

  4. Enter the name you're looking for in the search bar below the USER NAME column.

  5. The report will display the last successful authentication time below the LOGON TIME column.

 Validation and confirmation   

  • Verify that the displayed logon time matches recent authentication attempts.

  • Cross-check the information with Active Directory event logs for consistency.

 Tips 

  • Regularly monitor user logon reports to detect unusual activity.

  • Use filtering options in ADAudit Plus to generate specific reports for auditing.

  • Configure alerts for inactive accounts to improve security and compliance.

 Related topics and articles   

  • How to track inactive user accounts in ADAudit Plus