Can you display last logon information on a AADJ laptop?

Sage Mirror 220 Reputation points
2023-07-10T09:16:33.2133333+00:00

Hi,

From Intune > Devices > Device configuration profiles, I set up a configuration profile with Settings catalog > Administrative Templates > Windows Components > Windows Logon options > Display information about previous logons during user logon.

I set up this configuration profile on an AADJ laptop. The profile is successfully applied to the laptop. However, I get this message at logon:

"Security policies on this computer are set to show information about the last interactive sign-in, but Windows couldn't retrieve that information. Contact your network administrator for help."

The documentation (https://video2.skills-academy.com/en-us/windows/client-management/mdm/policy-csp-admx-winlogon?WT.mc_id=Portal-fx#admx-winlogon-displaylastlogoninfodescription "DisplayLastLogonInfoDescription") only writes about Windows Server, so I don't have much information.

Can you tell me if this option is possible in AADJ devices, and if not, is there any alternative?

Thank you.

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
417 questions
Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,893 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,053 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
21,699 questions
0 comments No comments
{count} votes

Accepted answer
  1. Azar 22,860 Reputation points MVP
    2023-07-10T09:45:55.32+00:00

    Hi

    As an alternative, you can consider using other methods to track and monitor user logons on AADJ devices. Some possibilities include:

    Azure AD Sign-in logs: Review the Azure AD Sign-in logs to get information about user sign-ins and related details.

    Security Information and Event Management (SIEM) solutions: Integrate your AADJ devices with a SIEM solution that can collect and analyze log data to provide insights into user logons and activities.

    Endpoint security solutions: Explore endpoint security solutions that offer logging and reporting capabilities, which can help track user logon events.

    1 person found this answer helpful.
    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Lu Dai-MSFT 28,401 Reputation points
    2023-07-11T01:31:18+00:00

    @Sage Mirror Thanks for posting in our Q&A.

    Based on my understanding, this option is not supported in AADJ devices.

    For this issue, did you consider using Graph Api to get the target device's last signed-in user? We can see more details in the following links:

    https://video2.skills-academy.com/en-us/graph/api/resources/intune-devices-windowsmanageddevice?view=graph-rest-beta

    https://video2.skills-academy.com/en-us/graph/api/intune-devices-windowsmanageddevice-get?view=graph-rest-beta

    I have done the test in my lab.

    User's image

    Hope it will give you some ideas.


    If the answer is the right solution, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.