473,695 Members | 2,754 Online
Bytes | Software Development & Data Engineering Community
+ Post

Home Posts Topics Members FAQ

User Must Change Password At Next Logon - LDAP And .NET

Ram
Hey,
I'v managed to set the "User Must Change Password At Next Logon" flag on the
LDAP protocol,
Using the - "pwdLastSet " property - by setting it to - "0" (for on) or -
"-1" (for off).
The problem is, I dont know how to check what's the current status of this
user -
When I try and read this property from the user's DirectoryEntry,
I get a "System.ComObje ct" object, and I cant get any data from this object.
Does Anyone has an idea what object is this, or how can I get this value
otherwise?
Thanks ahead

--Ram
Nov 16 '05 #1
5 20264
The PropertyValueCo llection element 0 contains a COM IDispatch Pointer
(__ComObject), use late binding to retrieve the HighPart
and LowPart properties, of the LastLogon Date.
Combine both into a long and pass it to FromFileTime.

Add a reference to activeds.tlb
Try this:

Dim de As DirectoryEntry = _
New DirectoryEntry( "LDAP://xxxx/CN=Users,DC=xx, DC=yy,DC=zz")
Dim mySearcher as DirectorySearch er = new DirectorySearch er(de)
mySearcher.Filt er = "(samAccountNam e=administrator )"
mySearcher.Prop ertiesToLoad.Ad d("samAccountNa me")
mySearcher.Prop ertiesToLoad.Ad d("lastLogon" )
Dim myResult as SearchResult
myResult = mySearcher.Find One()
de = new DirectoryEntry( myResult.Path)
Dim pcoll as PropertyCollect ion = de.Properties
Dim li as LargeInteger
Dim oli as object = pcoll("lastLogo n")(0) ' Set object reference to
ILargeInteger
Dim lDate as Long = (oli.HighPart * &h100000000) + oli.LowPart 'Combine
LowPart and HighPart
Console.WriteLi ne("DATE = {0:D}" ,DateTime.FromF ileTime(lDate)) 'Convert
from FileTime foramt to DateTime
--
Tamir Khason
You want dot.NET? Just ask:
"Please, www.dotnet.us "
"Ram" <ni***@bezeqint .net> wrote in message
news:eA******** ******@TK2MSFTN GP10.phx.gbl...
Hey,
I'v managed to set the "User Must Change Password At Next Logon" flag on the LDAP protocol,
Using the - "pwdLastSet " property - by setting it to - "0" (for on) or -
"-1" (for off).
The problem is, I dont know how to check what's the current status of this
user -
When I try and read this property from the user's DirectoryEntry,
I get a "System.ComObje ct" object, and I cant get any data from this object. Does Anyone has an idea what object is this, or how can I get this value
otherwise?
Thanks ahead

--Ram

Nov 16 '05 #2
BTW, your clock is 1 hour ahead. Please check this!

--
Tamir Khason
You want dot.NET? Just ask:
"Please, www.dotnet.us "
"Ram" <ni***@bezeqint .net> wrote in message
news:eA******** ******@TK2MSFTN GP10.phx.gbl...
Hey,
I'v managed to set the "User Must Change Password At Next Logon" flag on the LDAP protocol,
Using the - "pwdLastSet " property - by setting it to - "0" (for on) or -
"-1" (for off).
The problem is, I dont know how to check what's the current status of this
user -
When I try and read this property from the user's DirectoryEntry,
I get a "System.ComObje ct" object, and I cant get any data from this object. Does Anyone has an idea what object is this, or how can I get this value
otherwise?
Thanks ahead

--Ram

Nov 16 '05 #3
Ram
Hey Tamir,
Thanks for your replies (both in this thread and in the past ones)!
The - "LowPart" and "HighPart" methods work great,
But the thing is, when I create a new user, it gets - by default - the "Must
Change Password At Next Logon" flag.
And when I check the LowPart or HighPart at this time, they both equles to -
0.
Are there some other methods/properties for this object?
Thanks again,

--Ram
"Tamir Khason" <ta**********@t con-NOSPAM.co.il> wrote in message
news:O1******** ******@TK2MSFTN GP11.phx.gbl...
The PropertyValueCo llection element 0 contains a COM IDispatch Pointer
(__ComObject), use late binding to retrieve the HighPart
and LowPart properties, of the LastLogon Date.
Combine both into a long and pass it to FromFileTime.

Add a reference to activeds.tlb
Try this:

Dim de As DirectoryEntry = _
New DirectoryEntry( "LDAP://xxxx/CN=Users,DC=xx, DC=yy,DC=zz")
Dim mySearcher as DirectorySearch er = new DirectorySearch er(de)
mySearcher.Filt er = "(samAccountNam e=administrator )"
mySearcher.Prop ertiesToLoad.Ad d("samAccountNa me")
mySearcher.Prop ertiesToLoad.Ad d("lastLogon" )
Dim myResult as SearchResult
myResult = mySearcher.Find One()
de = new DirectoryEntry( myResult.Path)
Dim pcoll as PropertyCollect ion = de.Properties
Dim li as LargeInteger
Dim oli as object = pcoll("lastLogo n")(0) ' Set object reference to
ILargeInteger
Dim lDate as Long = (oli.HighPart * &h100000000) + oli.LowPart 'Combine
LowPart and HighPart
Console.WriteLi ne("DATE = {0:D}" ,DateTime.FromF ileTime(lDate)) 'Convert
from FileTime foramt to DateTime
--
Tamir Khason
You want dot.NET? Just ask:
"Please, www.dotnet.us "
"Ram" <ni***@bezeqint .net> wrote in message
news:eA******** ******@TK2MSFTN GP10.phx.gbl...
Hey,
I'v managed to set the "User Must Change Password At Next Logon" flag on

the
LDAP protocol,
Using the - "pwdLastSet " property - by setting it to - "0" (for on) or -
"-1" (for off).
The problem is, I dont know how to check what's the current status of this user -
When I try and read this property from the user's DirectoryEntry,
I get a "System.ComObje ct" object, and I cant get any data from this

object.
Does Anyone has an idea what object is this, or how can I get this value
otherwise?
Thanks ahead

--Ram


Nov 16 '05 #4
After you create the new user you need to set the password. Assuming your
DirectoryEntry variable representing the user is called "de" you would
simple do:

de.Invoke("SetP assword", "userinitialpas sword");

Also note that if the domain is set to a higher security than default you
will need to create the user, set the password and THEN set the
userAccountCont rol attribute to enable the account (high security will not
allow you to enable a user account with blank passwords)

Arild

"Ram" <ni***@bezeqint .net> wrote in message
news:uc******** ******@TK2MSFTN GP11.phx.gbl...
Hey Tamir,
Thanks for your replies (both in this thread and in the past ones)!
The - "LowPart" and "HighPart" methods work great,
But the thing is, when I create a new user, it gets - by default - the "Must Change Password At Next Logon" flag.
And when I check the LowPart or HighPart at this time, they both equles to - 0.
Are there some other methods/properties for this object?
Thanks again,

--Ram
"Tamir Khason" <ta**********@t con-NOSPAM.co.il> wrote in message
news:O1******** ******@TK2MSFTN GP11.phx.gbl...
The PropertyValueCo llection element 0 contains a COM IDispatch Pointer
(__ComObject), use late binding to retrieve the HighPart
and LowPart properties, of the LastLogon Date.
Combine both into a long and pass it to FromFileTime.

Add a reference to activeds.tlb
Try this:

Dim de As DirectoryEntry = _
New DirectoryEntry( "LDAP://xxxx/CN=Users,DC=xx, DC=yy,DC=zz")
Dim mySearcher as DirectorySearch er = new DirectorySearch er(de)
mySearcher.Filt er = "(samAccountNam e=administrator )"
mySearcher.Prop ertiesToLoad.Ad d("samAccountNa me")
mySearcher.Prop ertiesToLoad.Ad d("lastLogon" )
Dim myResult as SearchResult
myResult = mySearcher.Find One()
de = new DirectoryEntry( myResult.Path)
Dim pcoll as PropertyCollect ion = de.Properties
Dim li as LargeInteger
Dim oli as object = pcoll("lastLogo n")(0) ' Set object reference to
ILargeInteger
Dim lDate as Long = (oli.HighPart * &h100000000) + oli.LowPart 'Combine
LowPart and HighPart
Console.WriteLi ne("DATE = {0:D}" ,DateTime.FromF ileTime(lDate)) 'Convert
from FileTime foramt to DateTime
--
Tamir Khason
You want dot.NET? Just ask:
"Please, www.dotnet.us "
"Ram" <ni***@bezeqint .net> wrote in message
news:eA******** ******@TK2MSFTN GP10.phx.gbl...
Hey,
I'v managed to set the "User Must Change Password At Next Logon" flag on
the
LDAP protocol,
Using the - "pwdLastSet " property - by setting it to - "0" (for on)
or - "-1" (for off).
The problem is, I dont know how to check what's the current status of

this user -
When I try and read this property from the user's DirectoryEntry,
I get a "System.ComObje ct" object, and I cant get any data from this

object.
Does Anyone has an idea what object is this, or how can I get this value otherwise?
Thanks ahead

--Ram



Nov 16 '05 #5
Ram
Thanks Arild - when I set the password before I Commit Changes, the - "Must
Change Password At Next Logon" flag is set to off!
Thanks for both of you for your help!

--Ram
"Arild Bakken" <ar*****@hotmai l.com> wrote in message
news:O4******** ******@TK2MSFTN GP12.phx.gbl...
After you create the new user you need to set the password. Assuming your
DirectoryEntry variable representing the user is called "de" you would
simple do:

de.Invoke("SetP assword", "userinitialpas sword");

Also note that if the domain is set to a higher security than default you
will need to create the user, set the password and THEN set the
userAccountCont rol attribute to enable the account (high security will not
allow you to enable a user account with blank passwords)

Arild

"Ram" <ni***@bezeqint .net> wrote in message
news:uc******** ******@TK2MSFTN GP11.phx.gbl...
Hey Tamir,
Thanks for your replies (both in this thread and in the past ones)!
The - "LowPart" and "HighPart" methods work great,
But the thing is, when I create a new user, it gets - by default - the "Must
Change Password At Next Logon" flag.
And when I check the LowPart or HighPart at this time, they both equles

to -
0.
Are there some other methods/properties for this object?
Thanks again,

--Ram
"Tamir Khason" <ta**********@t con-NOSPAM.co.il> wrote in message
news:O1******** ******@TK2MSFTN GP11.phx.gbl...
The PropertyValueCo llection element 0 contains a COM IDispatch Pointer
(__ComObject), use late binding to retrieve the HighPart
and LowPart properties, of the LastLogon Date.
Combine both into a long and pass it to FromFileTime.

Add a reference to activeds.tlb
Try this:

Dim de As DirectoryEntry = _
New DirectoryEntry( "LDAP://xxxx/CN=Users,DC=xx, DC=yy,DC=zz")
Dim mySearcher as DirectorySearch er = new DirectorySearch er(de)
mySearcher.Filt er = "(samAccountNam e=administrator )"
mySearcher.Prop ertiesToLoad.Ad d("samAccountNa me")
mySearcher.Prop ertiesToLoad.Ad d("lastLogon" )
Dim myResult as SearchResult
myResult = mySearcher.Find One()
de = new DirectoryEntry( myResult.Path)
Dim pcoll as PropertyCollect ion = de.Properties
Dim li as LargeInteger
Dim oli as object = pcoll("lastLogo n")(0) ' Set object reference to
ILargeInteger
Dim lDate as Long = (oli.HighPart * &h100000000) + oli.LowPart 'Combine LowPart and HighPart
Console.WriteLi ne("DATE = {0:D}" ,DateTime.FromF ileTime(lDate)) 'Convert from FileTime foramt to DateTime
--
Tamir Khason
You want dot.NET? Just ask:
"Please, www.dotnet.us "
"Ram" <ni***@bezeqint .net> wrote in message
news:eA******** ******@TK2MSFTN GP10.phx.gbl...
> Hey,
> I'v managed to set the "User Must Change Password At Next Logon"
flag on the
> LDAP protocol,
> Using the - "pwdLastSet " property - by setting it to - "0" (for on) or - > "-1" (for off).
> The problem is, I dont know how to check what's the current status
of
this
> user -
> When I try and read this property from the user's DirectoryEntry,
> I get a "System.ComObje ct" object, and I cant get any data from this
object.
> Does Anyone has an idea what object is this, or how can I get this

value > otherwise?
> Thanks ahead
>
> --Ram
>
>



Nov 16 '05 #6

This thread has been closed and replies have been disabled. Please start a new discussion.

Similar topics

2
5249
by: Frederick | last post by:
Hi, I am using ADAM as my Data Store for my web application and although this seems to be fine when using windows authentication with my local account when I try to create a new user and use this to log on to the adam instance an exception with the following message is thrown "Logon Failure: unknown username or bad password" I set up the user in the ADAM instance and have assigned this user as a member of the Administrators group. I...
1
6449
by: Ram | last post by:
Hey, I'v managed to set the "User Must Change Password At Next Logon" flag on the LDAP protocol, Using the - "pwdLastSet" property - by setting it to - "0" (for on) or - "-1" (for off). The problem is, I dont know how to check what's the current status of this user - When I try and read this property from the user's DirectoryEntry, I get a "System.ComObject" object, and I cant get any data from this object. Does Anyone has an idea what...
8
1837
by: Maxi | last post by:
Hello, i'm sorry my bad english :( I have CR9 Webservice, how to change databadse name and User_name into Webservice method? (not Viewer Control) Tks!! -- --------------------------
1
2116
by: moi | last post by:
Hello, I have make a Active Directory Membership to change the user password in the active directory with ASP.NET2 after a logo page, and it works fine. BUT i add this code when the password is changed to Add this user in a group, but i get an 0x80070005 (E_ACCESSDENIED)... : why ? the user is well authentified with my logon.aspx page .. no ? Dim objgroup, objuser objgroup =
18
23783
by: Arthur | last post by:
Hi All, I would like to get the name of the user given their networkID, is this something Active Directory would be useful for?(For intranet users) If so, can you please point me to some sample code/examples? Thanks in advance, Arthur
10
26803
by: Jeff Williams | last post by:
How can I get a list of the Groups both Local and Domain groups a User belongs to.
9
15523
by: webrod | last post by:
Hi all, how can I check a user/password in a LDAP ? I don't want to connect with this user, I would like to connect to LDAP with a ADMIN_LOG/ADMIN_PWD, then do a query to find the user and check the password. The thing is I can't access the password attribute to compare with the user's password provided.
8
4442
by: Michael Howes | last post by:
I have some code that manages local user logins. When I create a new user I want to set the password to expire every x days and the number of failed login attempts before the account is disable/locked out. I can't seem to figure out how. I saw two properties in MSDN BadPasswordAttempts and MaxPasswordAge but I can't seem to set them on the new user. my code looks like this DirectoryEntry newUser = null; ;
3
5039
by: =?Utf-8?B?QXhlbCBEYWhtZW4=?= | last post by:
Hi, we've got a strange problem here: We've created an ASP.NET 2.0 web application using Membership.ValidateUser() to manually authenticate users with our website. The problem is: If the user has the "User must change password" flag set in Active Directory, ValidateUser() always returns false if that user wants to log in.
0
8630
marktang
by: marktang | last post by:
ONU (Optical Network Unit) is one of the key components for providing high-speed Internet services. Its primary function is to act as an endpoint device located at the user's premises. However, people are often confused as to whether an ONU can Work As a Router. In this blog post, we’ll explore What is ONU, What Is Router, ONU & Router’s main usage, and What is the difference between ONU and Router. Let’s take a closer look ! Part I. Meaning of...
0
8568
by: Hystou | last post by:
Most computers default to English, but sometimes we require a different language, especially when relocating. Forgot to request a specific language before your computer shipped? No problem! You can effortlessly switch the default language on Windows 10 without reinstalling. I'll walk you through it. First, let's disable language synchronization. With a Microsoft account, language settings sync across devices. To prevent any complications,...
1
8845
by: Hystou | last post by:
Overview: Windows 11 and 10 have less user interface control over operating system update behaviour than previous versions of Windows. In Windows 11 and 10, there is no way to turn off the Windows Update option using the Control Panel or Settings app; it automatically checks for updates and installs any it finds, whether you like it or not. For most users, this new feature is actually very convenient. If you want to control the update process,...
0
7660
agi2029
by: agi2029 | last post by:
Let's talk about the concept of autonomous AI software engineers and no-code agents. These AIs are designed to manage the entire lifecycle of a software development project—planning, coding, testing, and deployment—without human intervention. Imagine an AI that can take a project description, break it down, write the code, debug it, and then launch it, all on its own.... Now, this would greatly impact the work of software developers. The idea...
1
6491
isladogs
by: isladogs | last post by:
The next Access Europe User Group meeting will be on Wednesday 1 May 2024 starting at 18:00 UK time (6PM UTC+1) and finishing by 19:30 (7.30PM). In this session, we are pleased to welcome a new presenter, Adolph Dupré who will be discussing some powerful techniques for using class modules. He will explain when you may want to use classes instead of User Defined Types (UDT). For example, to manage the data in unbound forms. Adolph will...
0
5839
by: conductexam | last post by:
I have .net C# application in which I am extracting data from word file and save it in database particularly. To store word all data as it is I am converting the whole word file firstly in HTML and then checking html paragraph one by one. At the time of converting from word file to html my equations which are in the word document file was convert into image. Globals.ThisAddIn.Application.ActiveDocument.Select();...
0
4340
by: TSSRALBI | last post by:
Hello I'm a network technician in training and I need your help. I am currently learning how to create and manage the different types of VPNs and I have a question about LAN-to-LAN VPNs. The last exercise I practiced was to create a LAN-to-LAN VPN between two Pfsense firewalls, by using IPSEC protocols. I succeeded, with both firewalls in the same network. But I'm wondering if it's possible to do the same thing, with 2 Pfsense firewalls...
1
3003
by: 6302768590 | last post by:
Hai team i want code for transfer the data from one system to another through IP address by using C# our system has to for every 5mins then we have to update the data what the data is updated we have to send another system
2
2272
muto222
by: muto222 | last post by:
How can i add a mobile payment intergratation into php mysql website.

By using Bytes.com and it's services, you agree to our Privacy Policy and Terms of Use.

To disable or enable advertisements and analytics tracking please visit the manage ads & tracking page.