I need to get the last password change for a group of account in an Active Directory security group, and I feel like this is something Power Shell should be good at.
Right now, I'm already stuck at how to read the pwd Last Set attribute from the AD account I'm looking at.
Thinking about time in ticks is a good way to get a headache, so it's usually necessary to convert human readable dates and times into ticks for query purposes.
I never did figure it out, so I used the above example and moved on.
Last week I found a long-forgotten, almost empty bag of bread in the back of my pantry.
Some bizarre reaction had resulted in the mold hardening and warping the plastic, which left an oily residue on my fingers as I rapidly flung it across the kitchen into my rubbish bin.
Can you confirm that the change to the pwd Last Set attribute from null to -1 is only done once Pass Core has successfully authenticated the user using the current password?
Your code appears to come before the original section commented "Validate user credentials." It also does not appear that the patch resets the value from -1 to null in the event of a failed Set Password or Change Password attempt.