Security Compliance

How to locate the last logged-on user for a managed computer

Patch Manager does not collect the last logged-on user for managed computers by default. This article describes how to create an Inventory Configuration Template to pull this information from the Registry of the managed computer.

First published date

10/10/2018 7:43 PM

Last published date

10/10/2018 7:43 PM

Overview

Patch Manager does not collect the last logged-on user for managed computers by default. This article describes how to create an Inventory Configuration Template to pull this information from the Registry on the managed computer.

Product section

Patch Manager

Resolution

Use the following Registry keys and string values in your Inventory Configuration Template.

For managed computers running an operating system prior to Microsoft® Windows® Vista or Windows Server® 2008:

  • Registry Hive: HKEY_LOCAL_MACHINE
  • Registry Key Path: SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon
  • Registry Value (String): DefaultUserName
    And
  • Registry Hive: HKEY_LOCAL_MACHINE
  • Registry Key Path: SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon
  • Registry Value (String): DefaultDomainName

For managed computers running Windows Vista or Windows Server 2008 and later:

  • Registry Hive: HKEY_LOCAL_MACHINE
  • Registry Key Path: SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\LogonUI
  • Registry Value (String): LastLoggedOnUser
     

Note: Creating this new Inventory Configuration Template does not alter any existing scheduled Inventory tasks. To add this information to your scheduled Inventory tasks, replace those tasks with new ones using your new template.