← cd ~/tools
// tools/timestamps
Timestamp converter
Paste a lastLogonTimestamp, pwdLastSet or accountExpires value, a Unix timestamp, .NET ticks, an AD generalised time or an ISO date. The format is detected for you.
Runs entirely in your browser. Nothing you paste is sent anywhere.
What the AD and Entra attributes mean
| Attribute | Format | Notes |
|---|---|---|
lastLogonTimestamp | FILETIME | Replicated between domain controllers, but only updated when the previous value is more than about 9 to 14 days old. Good for finding stale accounts, not for exact last logons. |
lastLogon | FILETIME | Exact, but stored per domain controller and not replicated. Query every DC and take the latest. |
pwdLastSet | FILETIME | 0 means the user must change their password at next logon. |
accountExpires | FILETIME | 0 or 9223372036854775807 both mean the account never expires. |
whenCreated, whenChanged | Generalised time | For example 20261009083000.0Z, in UTC. |
signInActivity.lastSignInDateTime | ISO 8601 | Microsoft Graph, in UTC. Reading it needs the AuditLog.Read.All permission and an Entra ID P1 or P2 licence. |
approximateLastSignInDateTime | ISO 8601 | On Entra device objects. Useful for stale device clean-ups. |
# FILETIME to a date in PowerShell
[datetime]::FromFileTimeUtc(134044416000000000)
# Stale users by lastLogonTimestamp (90 days)
$cutoff = (Get-Date).AddDays(-90).ToFileTimeUtc()
Get-ADUser -Filter "lastLogonTimestamp -lt $cutoff -and enabled -eq 'true'" -Properties lastLogonTimestamp