The script below will need to run from a domain controller. Run this in PowerShell as Administrator or in Terminal as Admin.
$Cutoff = (Get-Date).AddDays(-30)
Get-ADComputer -Filter 'Enabled -eq $true' `
-Properties LastLogonDate,OperatingSystem,DNSHostName |
Where-Object {
$_.LastLogonDate -ge $Cutoff -and
$_.OperatingSystem -like "*Windows*" -and
$_.OperatingSystem -notlike "*Server*"
} |
Select-Object Name,DNSHostName,OperatingSystem,LastLogonDate |
Sort-Object LastLogonDate -Descending |
Format-Table -AutoSize
If you'd like to export this to CSV to work with it many way, run this command and it will export it to .csv. Just make sure the C:\Temp folder exists first.
$Cutoff = (Get-Date).AddDays(-30)
Get-ADComputer -Filter 'Enabled -eq $true' `
-Properties LastLogonDate,OperatingSystem,DNSHostName |
Where-Object {
$_.LastLogonDate -ge $Cutoff -and
$_.OperatingSystem -like "*Windows*" -and
$_.OperatingSystem -notlike "*Server*"
} |
Select-Object Name,DNSHostName,OperatingSystem,LastLogonDate |
Sort-Object Name |
Export-Csv "C:\Temp\AD-ActiveWorkstations-30Days.csv" -NoTypeInformation
Important distinction: LastLogonDate is based on the replicated lastLogonTimestamp attribute. It helps with inventory comparisons but can lag actual logons by about 9–14 days under default AD settings. It also represents computer-account activity, not necessarily an interactive user sign-in.