Azure Monitor监控本地AD:Log Analytics AD健康检查方案能否满足需求?
Great question! Let’s walk through each of your requirements one by one to see if the Log Analytics Active Directory Health Check solution has you covered:
a. Detailed info on disabled AD users
Absolutely. The solution collects core user attributes from AD into theADUsertable. You can run a Kusto query like this to pull all disabled users and their details:ADUser | where Enabled == false | project UserName = Name, DistinguishedName, DisabledTimestamp = WhenChanged, DescriptionThis will return usernames, their full AD paths, when they were disabled, and any descriptions associated with the accounts.
b. Users who don’t require a password
Yep, this is covered too. TheADUsertable includes aPasswordRequiredfield. Filter for records where this isfalseto get your list:ADUser | where PasswordRequired == false | project UserName = Name, DistinguishedNamec. Users with passwords that never expire
The solution captures thePasswordNeverExpiresattribute in theADUsertable. A simple query will surface these accounts:ADUser | where PasswordNeverExpires == true | project UserName = Name, DistinguishedName, PasswordLastSetd. Users with Kerberos pre-authentication disabled
This one relies on parsing theuserAccountControlattribute (a bitmask that stores AD account settings). The AD Health Check solution collects this field, so you can write a query to identify accounts where the "disable pre-authentication" bit (0x80000) is set:ADUser | where bitwise_and(userAccountControl, 0x80000) == 0x80000 | project UserName = Name, DistinguishedNamee. Users who haven’t logged in in the past 90 days
TheADUsertable has aLastLogonTimestampfield (stored as a 100-nanosecond epoch value). You can convert this to a readable time and filter for accounts inactive for 90+ days:ADUser | where LastLogonTimestamp < ago(90d) | project UserName = Name, DistinguishedName, LastLogin = datetime_add('second', LastLogonTimestamp/10000000, datetime(1601-01-01))Note:
LastLogonTimestampis replicated across domain controllers, so it’s reliable for tracking inactive accounts.f. Expired or 90-day inactive computers
The solution collects computer data into theADComputertable, which includesLastLogonTimestampandAccountExpiresfields. Use this query to find stale or expired machines:ADComputer | where LastLogonTimestamp < ago(90d) or AccountExpires < now() | project ComputerName = Name, DistinguishedName, LastActive = datetime_add('second', LastLogonTimestamp/10000000, datetime(1601-01-01)), ExpirationDate = datetime_add('second', AccountExpires/10000000, datetime(1601-01-01))g. Objects trusted for authentication delegation
Delegation settings are stored in attributes likemsDS-AllowedToDelegateTo(for constrained delegation) or viauserAccountControlbits (for unconstrained delegation). The AD Health Check solution captures these attributes, so you can query for them:// For constrained delegation union ADUser, ADComputer | where isnotempty(msDS-AllowedToDelegateTo) | project ObjectName = Name, ObjectType = Type, DelegatedServices = msDS-AllowedToDelegateTo // For unconstrained delegation union ADUser, ADComputer | where bitwise_and(userAccountControl, 0x800000) == 0x800000 | project ObjectName = Name, ObjectType = Typeh. Average uptime of all domain controllers
The AD Health Check solution doesn’t include this metric out of the box, but you can easily add it by enabling performance counter collection for your domain controllers. Log Analytics can collect theSystem\Uptimecounter, which you can then aggregate to get the average:Perf | where ObjectName == "System" and CounterName == "Uptime" | where Computer has "<your-DC-prefix>" // Filter to your domain controllers | summarize AvgUptimeHours = avg(CounterValue) by bin(TimeGenerated, 1d)Just make sure you’ve configured the performance counter collection rule for your DCs in Azure Monitor.
Final Verdict
All your requirements are achievable with the Active Directory Health Check solution in Log Analytics. For the domain controller uptime metric, you just need a small additional configuration to collect the necessary performance data—no extra tools required.
内容的提问来源于stack exchange,提问作者Vasavi Cherukuri

