Find Recently Active Windows Servers Across an AD Forest

This report lists enabled computer accounts running a server operating system that have a recorded logon within the last 60 days. It searches each domain in the forest and exports the results to CSV. “Recently active” here means the directory’s replicated last-logon timestamp is recent; it is not a live reachability test.

Requirements and timestamp limits

Run on Windows with the ActiveDirectory module and permission to read computer accounts in each domain. The script uses LastLogonDate, which is derived from the replicated lastLogonTimestamp attribute. That value is intentionally updated periodically, so it can lag actual logon activity by several days. Use a per-domain-controller lastLogon comparison when you need a more precise audit.

Export recently active server accounts

$forest = Get-ADForest -ErrorAction Stop
$daysActive = 60
$cutoff = (Get-Date).AddDays(-$daysActive)
$fileName = "{0}-Windows-Servers-Active-{1}.csv" -f $forest.RootDomain, (Get-Date -Format "yyyyMMdd")
$outputFile = Join-Path $env:TEMP $fileName

$results = foreach ($domain in $forest.Domains) {
    Write-Host "Querying $domain"

    try {
        Get-ADComputer -Filter 'OperatingSystem -like "*server*" -and Enabled -eq $true' -Properties DNSHostName, OperatingSystem, OperatingSystemServicePack, IPv4Address, LastLogonDate, Modified, Description, DistinguishedName, Created -Server $domain -ErrorAction Stop |
            Where-Object { $_.LastLogonDate -and $_.LastLogonDate -ge $cutoff } |
            Select-Object Name, DNSHostName, OperatingSystem, OperatingSystemServicePack, IPv4Address, LastLogonDate, Modified, Description, DistinguishedName, Created
    }
    catch {
        Write-Warning "Could not query ${domain}: $_"
    }
}

if ($results) {
    $results | Export-Csv -Path $outputFile -NoTypeInformation
    Write-Host "Exported results to $outputFile"
}
else {
    Write-Host "No matching computer accounts were returned."
}

The cutoff is applied after retrieving enabled server accounts so the date is compared as a DateTime value. This can return a substantial number of objects in a large domain; consider narrowing the search base if appropriate. A computer account with a recent timestamp may still be offline, and an active machine may have a timestamp that has not replicated yet.

See Microsoft’s Get-ADComputer documentation and the reference for the lastLogonTimestamp attribute.