MS-Logon I restricts the user accounts to be in the same domain than the machine account, but is available on Windows 9x. MS-Logon II allows for cross-domain authentication, but only works on Windows NT, 2000, XP and 2003. Classic VNC Authentication. For a domain user, the command would be as below. C:\>net user john /domain | findstr /C:"Last logon" Last logon 9/18/2013 10:18:41 AM

Domain Controllers are the central critical components in the Active Directory from where AD changes are effected. Domain Controller logon is restricted to privileged or Admin users and complete information on logon attempts done by other users equips administrators to take informed corrective measures.

Domain\User is the "old" logon format, called down-level logon name. Also known by the names SAMAccountName and pre-Windows 2000 logon name. is a UPN - User Principal Name. It's the "preferred", newer logon format. It's an Internet-style login name, that should map to the user email name. (Ref. at MSDN)

