| UserLogon Name |
userPrincipalName |
The LDAP attribute is logonPrincipalName, which prefixes the Logon Name drop-down menu and adds the full text to the value of the entry. |
User logon name (pre-Windows 2000) |
sAMAccountname |
None. |
| Account is locked out |
userAccountControl |
Toggles a bit in the userAccountControl bitmask (flag: UF_ACCOUNTSDISABLE). |
| User must change password at next logon |
pwdLastSet |
None. |
| User cannot change password |
Not applicable. |
This is the Change Password control in the access-control list. |
| Other Account Options |
userAccountControl |
The remaining items in Account Options toggle bits in the userAccountControl bitmask (flags in a DWORD). |