For more information about the lastLogonTimestamp attribute, click the following article number to view the article in the Microsoft Knowledge Base: 886705
A network logon that uses NTLM authentication does not update the lastLogonTimestamp attribute in the Active Directory schema of a Windows Server 2003-based domain controller
To display all domain users who have been inactive for 10 weeks or more, type the following command at a command prompt:
DSQUery.exe user inactive 10
For more information, visit the following Microsoft Web sites:Note
When you visit the last Web site that is listed, search for the "Security protocols that update lastLogonTimeStamp in Windows Server 2003" topic.