Friday, October 09, 2026

List Computers That Logged into the Domain in the Past 60 Days

 The script below will need to run from a domain controller.  Run this in PowerShell as Administrator or in Terminal as Admin.

$Cutoff = (Get-Date).AddDays(-30)


Get-ADComputer -Filter 'Enabled -eq $true' `

    -Properties LastLogonDate,OperatingSystem,DNSHostName |

    Where-Object {

        $_.LastLogonDate -ge $Cutoff -and

        $_.OperatingSystem -like "*Windows*" -and

        $_.OperatingSystem -notlike "*Server*"

    } |

    Select-Object Name,DNSHostName,OperatingSystem,LastLogonDate |

    Sort-Object LastLogonDate -Descending |

    Format-Table -AutoSize


If you'd like to export this to CSV to work with it many way, run this command and it will export it to .csv.  Just make sure the C:\Temp folder exists first.

$Cutoff = (Get-Date).AddDays(-30)


Get-ADComputer -Filter 'Enabled -eq $true' `

    -Properties LastLogonDate,OperatingSystem,DNSHostName |

    Where-Object {

        $_.LastLogonDate -ge $Cutoff -and

        $_.OperatingSystem -like "*Windows*" -and

        $_.OperatingSystem -notlike "*Server*"

    } |

    Select-Object Name,DNSHostName,OperatingSystem,LastLogonDate |

    Sort-Object Name |

    Export-Csv "C:\Temp\AD-ActiveWorkstations-30Days.csv" -NoTypeInformation


Important distinction: LastLogonDate is based on the replicated lastLogonTimestamp attribute. It helps with inventory comparisons but can lag actual logons by about 9–14 days under default AD settings. It also represents computer-account activity, not necessarily an interactive user sign-in.


No comments: