Friday, October 09, 2026

List Computers That Logged into the Domain in the Past 60 Days

 The script below will need to run from a domain controller.  Run this in PowerShell as Administrator or in Terminal as Admin.

$Cutoff = (Get-Date).AddDays(-30)


Get-ADComputer -Filter 'Enabled -eq $true' `

    -Properties LastLogonDate,OperatingSystem,DNSHostName |

    Where-Object {

        $_.LastLogonDate -ge $Cutoff -and

        $_.OperatingSystem -like "*Windows*" -and

        $_.OperatingSystem -notlike "*Server*"

    } |

    Select-Object Name,DNSHostName,OperatingSystem,LastLogonDate |

    Sort-Object LastLogonDate -Descending |

    Format-Table -AutoSize


If you'd like to export this to CSV to work with it many way, run this command and it will export it to .csv.  Just make sure the C:\Temp folder exists first.

$Cutoff = (Get-Date).AddDays(-30)


Get-ADComputer -Filter 'Enabled -eq $true' `

    -Properties LastLogonDate,OperatingSystem,DNSHostName |

    Where-Object {

        $_.LastLogonDate -ge $Cutoff -and

        $_.OperatingSystem -like "*Windows*" -and

        $_.OperatingSystem -notlike "*Server*"

    } |

    Select-Object Name,DNSHostName,OperatingSystem,LastLogonDate |

    Sort-Object Name |

    Export-Csv "C:\Temp\AD-ActiveWorkstations-30Days.csv" -NoTypeInformation


Important distinction: LastLogonDate is based on the replicated lastLogonTimestamp attribute. It helps with inventory comparisons but can lag actual logons by about 9–14 days under default AD settings. It also represents computer-account activity, not necessarily an interactive user sign-in.


Monday, October 05, 2026

How to Remove a Stale DHCP Server from Active Directory

When a Windows DHCP server is retired or removed improperly, its authorization can remain in Active Directory. This stale entry may continue to appear in the DHCP management console and should be cleaned up.

1. Check Authorized DHCP Servers

From an elevated PowerShell session on a domain controller or management system with the DHCP tools installed, run:

Get-DhcpServerInDC

You may see something similar to:

DnsName              IPAddress
-------              ---------
DHCP01.contoso.local 10.10.10.20
OLD-DHCP.contoso.local 10.10.10.15

Confirm that the server you intend to remove is actually retired and no longer providing DHCP services.

2. Remove the Stale Authorization

Remove the old DHCP server from Active Directory:

Remove-DhcpServerInDC -DnsName "OLD-DHCP.contoso.local" -IPAddress 10.10.10.15

Confirm the operation when prompted.

3. Verify the Removal

Run the following again:

Get-DhcpServerInDC

The retired server should no longer appear in the list of authorized DHCP servers.

Optional: Clean Up the DHCP Management Console

If the retired server still appears in the DHCP MMC console, right-click DHCP and select Manage Authorized Servers or remove the old server from the console.

Final Check

Removing a stale DHCP authorization does not delete DHCP scopes or modify another DHCP server. It removes the retired server's authorization record from Active Directory.

Before removing anything, verify the server name and IP address carefully—especially in environments where DHCP services have recently been migrated to a replacement server.

Friday, March 27, 2026

Migrating NPS Settings from Old Domain Controller to New Domain Controller

If you're using RADIUS on your Windows network, and you need to do Domain Controller upgrades, rebuilding RADIUS can be a pain if there are a lot of entries.  Using this process, you can easily back it up and then restore it on the new server.

NOTE:  This process assumes you are using the same name and IP address on the new OS for your new DC.

1.  Backup NPS on the old server.  Run this command:

netsh nps export filename="C:\NPS-Export.xml" exportPSK=YES

2.  For good measure, backup DHCP as well.

netsh dhcp server export C:\dhcp.txt all

3.  Copy these two files to a place where you can access them on your new DC.

4.  Once your new OS is promoted to a Domain Controller with the same name and IP address as the old DC, you can begin the import process.

5.  Install NPS on the new DC.

Install-WindowsFeature NPAS -IncludeManagementTools

6.  Import your NPS configuration file

netsh nps import filename="C:\NPS-Export.xml"

7.  Register NPS in AD

netsh ras add registeredserver

8.  Restart the NPS service

net stop ias

net start ias

PRO TIP:  Just in case, it's a good idea to grab a backup of the NPS registry key.  I personally haven't had to use it but it can't hurt to have it.

reg export HKLM\SYSTEM\CurrentControlSet\Services\IAS C:\NPS-Registry.reg

That's really all there is to it.  Good luck!

Monday, May 12, 2025

Exchange Anonymous Connector

 If you're like most, you need an internal relay on your Exchange server to allow devices and applications inside to send email without the need for credentials.  Since the connector can be scoped to the IP address of the source, this is a pretty good way to set it up.

I ran into a new issue on our new Exchange server today.  When you create the new Internal Relay receive connector to allow anonymous access, you must run a PowerShell command to make the connector accept messages.  This assumes you have the correct IP addresses in the relay.

Run this first:

Get-ADPermission "YourConnectorName" |

Where-Object { $_.User -like "NT AUTHORITY\ANONYMOUS LOGON" -and $_.ExtendedRights -like "*SMTP-Accept-Any-Recipient*" }

If this returns nothing, and it probably will, run this command to add the permissions:

Get-ReceiveConnector "YourConnectorName" |

Add-ADPermission -User "NT AUTHORITY\ANONYMOUS LOGON" `

-ExtendedRights "Ms-Exch-SMTP-Accept-Any-Recipient"

Good luck!

Monday, June 03, 2024

Can't Remove Old Exchange UCC Certificate - Certificate Bound to Send Connector

I've been running into this a lot lately where an old certificate can't be removed from Exchange as it is bound to a send connector and most commonly it's on a hybrid-mode Exchange configuration.

Here's how to get rid of it easily on Exchange and then delete the old certificate.

First, run the command to get the certificates on the Exchange server.:

Get-ExchangeCertificate | fl

This will return a full list of all certificates on the server.  Make a note of the Thumbprint of the certificate you want to keep.  That's the only one needed.

Now, shut off the "Microsoft Exchange Transport" service using Exchange PowerShell:

net stop "Microsoft Exchange Transport" or Stop-Service -Name MSExchangeTransport whichever you prefer.

Next is to get the name of your Send Connector shown in the error when trying to remove the certificate.  You'll need that name in the next command to remove any certificates that are bound to the connector:

Set-SendConnector -Identity "Outbound to Office 365 - 5c10806d-35cb-6645-8b8f-fde431830769" -TlsCertificateName $Null

At this point you can now delete the old certificate(s) as they're no longer bound to the connector.

Now run these two commands to set the variables for the certificate you want to keep.  This is where having the Thumbprint for the new certificate is needed.

$cert = Get-ExchangeCertificate -Thumbprint 6B6CB53DF162724D4F3AD97E508C5BBF072DCE8

$tlscertificatename = "<i>$($cert.Issuer)<s>$($cert.Subject)"

Do not change the syntax on the 2nd command.  That's used to pickup that variable for the final command.

Use this command finally to assign the new certificate only to the Send Connector:

Set-SendConnector -Identity "Outbound to Office 365 - 5c10806d-35cb-6645-8b8f-fde431830769" -TlsCertificateName $tlscertificatename

Finally, restart the Microsoft Exchange Transport service and you're finished.

net start "Microsoft Exchange Transport" or Start-Service -Name MSExchangeTransport

This completes the removal of any old certificates bound to the Send Connector so you can delete them from the server.  As a precaution, always test your mail flow service to make sure everything is working properly.

Good luck!