Home All Groups Group Topic Archive Search About

Windows Server Active Directory

microsoft.public.windows.server.active_directory
Score Install R2 results in incomplete AD setup
Keith Rosenfeld - 30 Sep 2006 9:48 PM - 3 messages
Tried to install a new W2K-R2 server -- as the only server in a new domain.  Used the 'Configure Your Server' utility to add roles. Everything looked good until we installed Active Directory and ran the recommended DCDIAG test.  It kept failing the first section (connectivity ...
Score hide server
Rui Lemos - 30 Sep 2006 9:32 PM - 3 messages
Hi I have a school as client, and i need to implement de following solution. They just have one server with active directory and a domain, this server is dns, and dhcp server, i they just have one internet connection. ...
Score Errors 1038 & 1050
Smogthedog - 30 Sep 2006 8:10 PM - 4 messages
Infuriating this is!  New domain of 4 servers 1 dc and 2 bdc.  when rolled out first of all everything worked fine, after 2 weeks or so these errors 1038 & 1050 started showing in the event log saying that the gpo could not ...
Score AD Schema change button is greyed out
Phil Buzzette - 30 Sep 2006 5:20 PM - 6 messages
I want to change the AD schema from one server to another, but the change button is greyed out. How can I change that? ...
Score Help! Need to know how to set DC as default for logon...
Phil Buzzette - 30 Sep 2006 3:26 PM - 4 messages
On our network we have 2 DC's. Server1 and Server2. Server1 was the default for logging on, but I need to have it be Server2. Currently, I added Server2 as a domain controller and AD was copied over, but if I pull down Server1, ...
Score Adding additional w2003 to a w2003 domain and can not access share
Trez - 30 Sep 2006 1:10 PM - 6 messages
Adding second windows 2003 server to a w2003 domain.  Users are unable to create files on the new server. Have tried setting system up with and without active directory.  Only the administrator can do anything other than read files. ...
Score RE:SETUP 2003 and exchange 2003 DC
winwoo3_68 - 30 Sep 2006 12:05 PM - 13 messages
I have 2 Servers with Windows 2003 Server Enterprise Editions. I would like to the First Server as DC for eg: genesis.mcity.com which will have my users accounts and group policies. The second server is my e-mail exchange server 2003. This server should ...
Score No DC shown in NTDSUTIL.exe in Single DC network
Nick Moore - 29 Sep 2006 11:34 PM - 10 messages
I have a 2003 Server w/SP1 that runs on my domain, it is the global catalog server and Operations masters for everything.  It is the only domain controller on my network.  Active directory seemingly works just fine except ...
Score logging failed logins
SilvrT - 29 Sep 2006 10:54 PM - 8 messages
Is there a way to log Failed Login attempts? ...
Score roaming profile creates problems
Will Sellers - 29 Sep 2006 9:32 PM - 9 messages
I set up a roaming profile test to make sure that it would do what I expected. I expected the users my document folder would be accessible from other PC's. The profile was created but no documents were available even though the user ...
Score Unable to promote a new server
Quo Vadis - 29 Sep 2006 9:26 PM - 25 messages
A brand new server was purchased, configured with Server 2003, and put into a domain.  When attempting to promote the server, we get the following error message, "The operation failed because: The Active Directory Installation Wizard was unable to convert the computer account SERVER3$ to a domain ...
Score Password settings via Group Policy
Jane Doe - 29 Sep 2006 9:18 PM - 5 messages
If I have a GP that forces a password change every 90 days, will it also effect the users who's has the "Password never expires" option checked on their account?  Or does their password never need to be changed. ...
Score Distribution List
randy.duly@nationaltubeform.com - 29 Sep 2006 7:27 PM - 2 messages
I have read several post on Distribution List in AD using Outlook. But I have not found what I am really looking for yet. First, of all, we don't have an Exchange server. So don't tune me out yet, ...
Score Delegating right to helpdesk
John - 29 Sep 2006 7:25 PM - 4 messages
Hi, Just wanted to get few  ideas how some of you manage the addition and removal of computername in your AD environment. I am task with coming up with a solution that would allow the desktop group the ability to ONLY  add and remove computers based on a particular OU in AD ...
Score Redirected My Documents and My Pictures/My Music
Jeremy Revitch - 29 Sep 2006 6:16 PM - 2 messages
is there any way to exclude My Pictures and My Music when redirecting My Documents. If not is there a way to setup a file mask so that certian file extensions (.mp3, .jpg etc.) are only stored locally? ...
Score Screensaver GPO
Dave - 29 Sep 2006 5:31 PM - 8 messages
I want to push out a custom GPO to allow the screensaver to come on our PC after a time/  I first attempted to use the marque screensaver with custom text and that did not take when pushed out through GPO.  I googled ...
Score LDIFDE Error when trying to change passwords.
JBaxter - 29 Sep 2006 4:39 PM - 15 messages
I am trying to update user passwords with the LDIFDE tool and I am recieving an error, I am running a completely patched 2003 server, the Domain Pass Security is: Enforce History  Not Defined Max Age   Not Defined ...
Score ADMT v3 Automatically disables migrated account
KingBuzzo - 29 Sep 2006 4:03 PM - 6 messages
Hi Guys: I am testing ADMT to perform a migration from NT to AD. After I migrate the user and password, the user account is automatically disabled in the destination domain. Any idea why this is happening? Thanks! ...
Score Migrate users from one DC to another on the same domain
Phil Buzzette - 29 Sep 2006 3:46 PM - 7 messages
I have 2 domain controllers on the domain. The primary and the secondary. I want transfer the users, etc. from the primary to the secondary and make the secondary the new primary. How can I go about this? When I added the ...
Score Multiple domain trees
John - 29 Sep 2006 3:42 PM - 7 messages
Hello All Neeed some clarification on domain trees .Let say I have two separate Win2003 forest then I explicitly create a two -way transitive forest trust between both forests root domains.. Now is this considered as a single forest with 2 domain trees (non contigoious name space) .. ...
Score Group and permissions
Robert - 29 Sep 2006 2:57 PM - 2 messages
I have a client that when you add group mebership to either 1 or more users they group membership is removed after a couble of days.the same thing happens with the script directory add permmision unchec the propagate and the ...
Score Proxy
Tesdall - 29 Sep 2006 2:15 PM - 4 messages
Any idea why my server would not be pushing out a proxy to computers when its the only group policy object? ...
Score Question about Migration from AD to OpenLDAP
male08star@yahoo.com - 29 Sep 2006 12:51 PM - 3 messages
Can you provide detail information about migrating Process from Active Directory to OpenLDAP and vice versa ? Please tell me about each stage of Migrating Process and What objects or configurations are migrated from AD to OpenLDAP ? Thank you very much ...
Score DCPROMO Windows 2003 into 2000, cannot find updated AD Schema chan
Jason F - 29 Sep 2006 12:29 PM - 4 messages
Hello all, I have a WIndows 2000 domain with a single Windows 200 DC, all functionality, data, etc. resides on the single server.  Oh yeah, and Excahnge 5.5.  We are in the process of upgrading the domain to Windows 2003 ...
Score Converting contacts to users
edmundward209 - 29 Sep 2006 11:48 AM - 5 messages
Hi I want to convert a load of contacts to users. Is there an easy way to do this, or do I have to create a new user based on the old contact's properties? I have started down the latter route, by writing a script ...
Score Ad Login from a different site
Manuel - 29 Sep 2006 11:32 AM - 2 messages
Hello, I have a test lab setup fpor AD. PDC 1 ON 10.1.0. subnet that is accessible to everyone. PDC2 in on 192.1.1 network. When I try to login to domain from an 10.23 network (DNS is set to PDC ...
Score SOX compliant .. different password policy need for privilege accounts
John - 29 Sep 2006 9:14 AM - 5 messages
Hello All Due to recent SOX requirements we are require to have a different password policy for all privilege accounts however our Win2003 forest consist of a single domain . We would of like to implement the empty root design model in ...
Score Restoring A DC using the NTBACKUP
RALLO - 29 Sep 2006 9:08 AM - 4 messages
Hi All We have 2 DC the main DC replicates to our backup DC in the same Network that works well. What we are trying to do is, backing up our DC using NTBACKUP full backup and trying to restore the it to a New Server, to test DR in the event both DC ...
Score Before you can install or remove Active Directory, you must remove
Steve - 29 Sep 2006 8:32 AM - 4 messages
Hi there, I'm trying to do a dcpromo to demote an old win 2003 dc, and I'm getting this error: Before you can install or remove Active Directory, you must remove Certificate Services Can someone point me to a kb article or something that shows how to move ...
Score prefer logon server is failure, can't failover to another
Dennis - 29 Sep 2006 8:19 AM - 3 messages
In our domain, we have 3 AD server for our logon. one of AD controll is failure, so some of client can't logon. Any solution for prevent this occur? is there any setting for this failover? Thanks Dennis. ...
Score Change administrator password in a TS environment
Tony Bragagnolo - 29 Sep 2006 8:07 AM - 2 messages
I have to change the user "administrator" password in a server environment in which we have serparate servers: DC, FS, 3 separate application servers with citrix metaframe. Do I have to take care of something before proceed, or it's just a ...
Score Problem with global catalog
JN - 29 Sep 2006 6:45 AM - 2 messages
Hi, We bought new server, I installed Windows 2000 server on the new machine as domain controller under primary domain controler (old server W2k). After that I used Ntdsutil to sieze FSMO roles. Than the old server was switch off. ...
Score How can retrive UsersID's & names in Notepad?
Mansoor - 29 Sep 2006 6:36 AM - 3 messages
we are running Windows 2003 server envoirnment. we have approx 200 users in Active Directory. which resides in diffrent OU,s. I just want a list of all enable users ID's on notepad with names. Any one can help me ...
Score Accessing files from other domain on another subnet
Igor - 29 Sep 2006 4:50 AM - 3 messages
Hello Windows experts Need an advise for a Windows novice. I setup site-to-site VPN using two routers, all protocols are allowed between the two subnets. Both subnets have a Domain Controller each running Windows 2003 Standard Server, they are two different domains. domain1.local on one subnet and ...
Score fail on logon
wahchai - 29 Sep 2006 3:29 AM - 4 messages
currently there infra is like this , node1 and node 2 is cluster mode , node one is AD with 5 fsmo , cluster active and sql active , while node2 is member server with cluster passive , sql passive . after i import securedc.inf , the cluster service cant start up . i have try ...
Score Deleted AD object still referenced somwhere?
W. Cody Anderson - 29 Sep 2006 2:46 AM - 2 messages
Hi everyone, A client of mine running Exchange 2003 Std/Windows 2003 Std had an admin asst that left the company.  She was assigned full permissions to the boss' mailbox.  After leaving the company, the assistant's user object and mailbox were deleted from AD.  Now, whenever the boss receives a meeting request from any of the employees, the sender of the request receives an NDR: ...
Score sysvol and netlogon share missing
Ivan - 29 Sep 2006 1:57 AM - 2 messages
i'm trying to migrate a 2000 domain to 2003 domain so i installed the os2003 enterprise on a clean server then promote it to DC, i left it for 2 weeks in order to replicate between AD's once they finished replicating i passed the ...
Score Run As / Secondary Logon username fill-in history
Spin - 29 Sep 2006 12:43 AM - 2 messages
Gurus, You know how you can click Run As and enter alternate credentials in which to run a program?  I'm talking about when you select the "The following User" radio button, and select the drop-down menu, sometimes their are ...
Score Install Updates and shutdown???
Dan - 29 Sep 2006 12:20 AM - 4 messages
Hello,   Is there a way via GPO that when updates have been downloaded to a desktop to enforce that users install them at shutdown?  I know generally that the shut down and the install updates and shutdown options are available but when ...
Score File Security and Share permissions
annie12 - 29 Sep 2006 12:20 AM - 2 messages
I created a hidden share (HomeDir$) for all of the users. The group everyone has the share permission "change". I then created via script each users home directory. Each home directory has the adminstrators@ full control as well as the user. The old content of the users home directory was copied over from a ...
Score Article 320138, Disable Automatic Search for Network Printers
Bob - 28 Sep 2006 8:26 PM - 6 messages
Hi, I have 2K3 Server R2. I read at the end of article 320138 "How To Disable Automatic Search for Network Printers and Folders in Windows XP", that this functionality is disabled ... if you are joined to a domain, ... if an administrator has ...
Score Unable to logon locally to windows 2003 DC
ehinkle27 - 28 Sep 2006 7:05 PM - 7 messages
I am unable to logon locally using a domain admin account to a windows 2003 domain controller if the network cable is unplugged. Has anyone seen this. The domain controllers run DNS and are configured to point to them selves so ...
Score very long login times for certain user accounts
Mike - 28 Sep 2006 4:56 PM - 7 messages
We have a small single domain (no-subs) network running WIN2003 sp1 servers. We have so far 2 accounts that have experienced a very long time to login and logoff. Approximately 10 mins. We have re-created of of those accounts and it ...
Score Using Adprep on Windows 2000 Server to upgrade to 2003
Marty Mash - 28 Sep 2006 4:35 PM - 4 messages
I have a 2000 network running.  I took our backup domain controller off line and put it on a private network with our new 2003 server which will be one of our domain controllers.  I ran adprep /forestprep and adprep /domainprep and ...
Score Domain Upgrade
Barrycuda - 28 Sep 2006 4:26 PM - 3 messages
Planning on an upgrade from Windows 2000 AD to Windows 2003 AD. I have read most of the posts on this and have looked at the Microsoft Docs. I however have a few questions that I cannot seem to find. ...
Score More-Even Worse problems AD-
Phreeze - 28 Sep 2006 4:10 PM - 3 messages
I tied a bunch of times to post but the site didn't take the post. This is my reply to the followig topic [link] ...
Score can't make a trust
Michael - 28 Sep 2006 3:38 PM - 8 messages
We are trying to make a 2-way trust between 2 domains in different forests across a firewall i think we have all the right ports open but when I try to make the trust says it can't connect to the other domain.  Ping works both ways and I ...
Score Which process trigger lsass.exe for using lsarpc to start LsarLook
Nico - 28 Sep 2006 3:22 PM - 4 messages
Hi, we have already an performanceproblem within our application. If we start some tasks with our DB2-Client we couldn't act within our application for an duration from 10 to 15 seconds. Our sniffer on the network shows that lsass.exe use the lsarpc interface to ...
Score Exceeded Tombstone Lifetime
tandrist - 28 Sep 2006 3:08 PM - 6 messages
Getting this error on many of the windows servers. "Replication generated an error, AD cannot replicate to because the time since the last replication with this server has exceeded the tombstone lifetime" Servers are trying to contact the DC's and keep getting this error? ...
Score MS06-055: no catalog update?
K Steele - 28 Sep 2006 2:49 PM - 4 messages
Waiting on the catalog/XML to be updated for MS06-055, as SMS clients will not properly report inventory back to the site database unless the catalog contains the information for MS06-055. In the absence of a catalog update, is anyone aware of a method to ...
Score Active Directory Forests
Frank - 28 Sep 2006 2:37 PM - 6 messages
I am evaluating a Windows 2000 Active Directory environment and I am not sure if I have two forests with one domain each or one forest with two separate domains.  I have domaina.com and domainb.com. How can I determine this? ...
Score Backing up of Group Policies
Brendon B - 28 Sep 2006 2:36 PM - 2 messages
Hi Everyone I know of backing using GPMC (Group Policy Management Console) to backup group policies but is there a way to automate the backup of these i.e with a command line script? Your help is appreciated Regards Brendon ...
Score script for adding printer
Senad Isanovic - 28 Sep 2006 2:09 PM - 3 messages
Where can I find info about how to create an logon script that automaticaly adds one or several printers localy on the machine when the user log on AD account (win 2000 server). I looked at MS Script center but did not find ...
Score Policy question after AD upgrade
TomSmith - 28 Sep 2006 1:38 PM - 2 messages
After my AD upgrade I will still have several NT workstations on the network. In my test scenario, I noticed that the NT workstations no longer had any policy. How can I get my remaining NT workstations to use the new policy from the AD 2003 DC's or continue to use it from the ...
Score Installing selective programs with AD GPO or other
AJ - 28 Sep 2006 1:29 PM - 2 messages
Hello everyone, Is there a way that I can allow users via AD GPO or other the right to install certain applications or executables? I imagin it being something like the security tab in IE where I can just say ...
Score Network problems after installing server 2003 SP1
Paul_Kelly - 28 Sep 2006 1:02 PM - 6 messages
Hi, I'm having some weird problems with my entire network, that i can't seem to isolate. They started after SP1 was loaded on one of our DC's. Here is a brief overview of our network                                   forest ...
Score move printer shares
John - 28 Sep 2006 12:39 PM - 2 messages
If I want to replace a windows 2000 DC with a new 2003R2 DC is there an easy way to move the printer shares from the old to the new and have the clients automatically use the new? ...
Score Audit File permissions from Group Memberships
hrbutler - 28 Sep 2006 12:22 PM - 2 messages
We are going to start the process of auditing our groups that we have in Active Directory.  Does anyone know of any utilites that can help find his information.  I will be testing Visual Click's DSRazor for Active Directory ...
Score Roaming Profiles and Permissions
Andrew McNab - 28 Sep 2006 11:43 AM - 4 messages
Hey I have a pretty simple issue. The university I go to has the same issue and they've never fixed it. I've setup SBS 2003 on a machine. I've created a roaming profile and it all works fine. The problem is that if I don't set ...
Score AD transition
Manuel - 28 Sep 2006 11:31 AM - 2 messages
Hello all, I will be implementing Win 2003 AD on about 76 companies to create a big AD domain.My question is: Is there any script or any practical way that you use/ used for the migration of the clients?I have to backup their profiles, add them to ...
Score Can you have two AD Forest on the same network?
villagod - 28 Sep 2006 11:29 AM - 6 messages
Building a lab environment and I am wondering if it is possible to have two AD Forest on the same network segment: IP Address range: 128.190.101.130 - 192 Mask: 255.255.255.192 Gateway:128.190.101.129 ...
Score External Trust - Firewall
Russ - 28 Sep 2006 11:16 AM - 2 messages
Greetings, I have successfully setup a one way external trust between two W2k3 AD Forests - Dom A trusts Dom B. I have opened the required firewall ports between the DC's in Dom A and Dom B. Enumerating user accounts in Dom B from the DC's in Dom A works fine. ...
Score Delegating permissions to update "City" filed in AD
Curtis Fray - 28 Sep 2006 10:48 AM - 3 messages
Hi, I need to delegate permissions to an individual who specifically needs to update the "City" field under the address tab of an AD user object. I've gone through delegation wizard and advanced security permissions but can't spot where to apply this specific permission. Could someone tell me how to ...
Score NTDS Replication error 2042, despite increased tombstone lifetime
Sune T. Tougaard - 28 Sep 2006 10:00 AM - 9 messages
Hi All, Have seen this a couple of times, and would like to have some comments on the issue. For a couple of AD setups, i've had to increase the tombstone lifetime. Doing this, has made a few issues show up. ...
Score NetUserChangePassword API
Oriane - 28 Sep 2006 9:51 AM - 6 messages
Hello, I am in the process of writing utilities to allow for password changes to be automated in my environment. In the old NT domain arch, we were using the NetUserChangePassword API Call to make password changes, that would also verify and validate the new password ...
Score logon and network resources slow when logging on accross domains
CK - 28 Sep 2006 8:41 AM - 2 messages
I have a empty root with 3 child domains all win 2k3. When users logon on from different sites, they complain of considerable slower network performance and longer logon times. Is there anyway around this aside from placing a DC for each domain at each site? This is becoming problematic as we ...
Score Tracking user log on and off
HWhite - 28 Sep 2006 6:54 AM - 5 messages
What is the easiest way to track, filter the results, and then make reports based on users logging in and out of their workstation? ...
Score child domai user logging on to parent domain server
BBbb - 28 Sep 2006 6:00 AM - 4 messages
Hi, A child domain and the parent domain are in two sites. Users in the child domain need to logon to the terminal server in the parent domain (using their child domain credentials)but only find the logon process is extremely slow, due to the logon server is the child DC in the remote ...
Score How to tell who created an object in AD?
Coop - 28 Sep 2006 5:04 AM - 2 messages
When a user obect is created in Windows Server 2003 AD, is the object stamped with the creation date and userid of the administrator who created the obect? How can I see that metadata? Thanks. ...
Score Group Policy question
HWhite - 27 Sep 2006 10:40 PM - 5 messages
I would like to change the local admin password on all of the workstations in my domain and I would like to use Group Policy to accomplish this.  If there isn't a GP way of doing this, I would appreciate alternative solutions. ...
Score Creating Roaming profile problem
Will Sellers - 27 Sep 2006 9:27 PM - 7 messages
I'm having trouble trying to create a test roaming profile on a win2003 server.. I did the following procedures: setup test user in AD went to a laptop and logged in as test user logged off laptop **now here is where the trouble begins  ** ...
Score Checking site replication
John - 27 Sep 2006 8:11 PM - 2 messages
Hi, I noticed something strange, our AD environment consists of 4 DCs in 3 sites.  There's this account "krbtgt" which is for Kerbos authentication is set to disabled (I think it's normal), but it's only found on 2 ADs.  The ...
Score authentication between trusted domains
synrat - 27 Sep 2006 8:03 PM - 9 messages
hi everybody, I have 2 2003 domain controllers, each in its own forest and domain. I successfully setup a 2 way trust relationship and got as far as seeing some printers from another domain, but I don't seem to be able to login ...
Score Local DC Group Policy being applied for passwrds not the Default D
Collin [MCSE:Messaging] - 27 Sep 2006 7:55 PM - 9 messages
Okay her is an interesting issue. Brand new install of Server 2003 R2, changed the Default Domain Policy to include different password requirements and some minor admin changes (like removing the run from start menu.). The minor admin changes worked perfectly, the run was removed, the ...
Score Migrate existing XP machines to new domain keeping home dirs?
Thomas Cameron - 27 Sep 2006 7:47 PM - 4 messages
All - I have a very small client who runs Windows 2003 server on one machine, and XP on another machine, in an AD domain model.  The server is used as a workstation, and is configured with AdAware, Spybot S&D, and McAfee, ...
Score Remote DC over IPSec
Eric - 27 Sep 2006 7:07 PM - 2 messages
Hello, We have a Windows 2003 standard net work with a Primary DC and a catalogue server. Our main office is connected to two different offices in different cities over IPSec through watch Guard products. Due to the slow traffic we ...
Score Remote Desktop Connection - Group Policy
Billy - 27 Sep 2006 6:16 PM - 3 messages
How I can activate a the RDC to all my XP computers? My Computer\properties\system properties\Remote\Remote Desktop\ Allow users to connect remotely to this computer ...
Score Tools for troubleshooting active directory
Jonathan Koda - 27 Sep 2006 3:46 PM - 4 messages
Does anyone know of any third party tools for checking and diagnosing problems with active directory and the global catalog server?  I have run dcdiag and frsdiag and every other diag but they just say everything is great but I get errors on not finding the domain controllers. ...
Score Re: Create a "App Install Admin" account?
bill artemik - 27 Sep 2006 3:00 PM - 2 messages
I need to create a user or group that will have the ability to add/remove applications to a local workstation (only...not a server admin account). This user account should be able to install apps, and update settings for ...
Score Primary Domain Controller (PDC) emulator cannot be contacted?
tandrist - 27 Sep 2006 2:20 PM - 5 messages
Windows 2003 server, cannot connect to the PDC? Where is the best place to start looking for problems? Any suggestions? ...
Score Big Trouble- Demoting a W2K DC from a Domain with 3 W2K3 DC's
Phreeze - 27 Sep 2006 2:10 PM - 11 messages
Man this is frustrating! What should have took 15 minutes never happened and I beat my head against the wall until 2 AM...ugh 4 hours of sleep doesn't work I have a domain I am trying to move to 2003. It was originally a 2000 ...
Score ADMT
JX - 27 Sep 2006 2:01 PM - 2 messages
Hi all, Just wanted to know some good reasons not to user ADMT 2.0/3.0.  I mean any issues with resource migrations, ACLing, SID, pass complex, rollback issues etc.  I wanted to compare it against third party tools like qmm or NetIQ.  ...
Score KDC error 14
setecastronomy - 27 Sep 2006 1:58 PM - 2 messages
Since the 1st of September on my Domain Controller there is a system error event every hour. It is about KDC, event number 14 and translated into english it sounds like: "During the computing of a request AS to the service krbtgt, it happened ...
Score DFSR - 2003 R2. EventID 5012
Hayden - 27 Sep 2006 1:46 PM - 3 messages
I have 3 Windows 2003 R2 servers in my test environment.  (A, B and C) When a DFS replication group is created on A or B, it replicates to all other servers (A,B and C) quickly showing up in DFS management (and file ...
Score Workstations not receiving Group Policies?
Gerrard Shaw - 27 Sep 2006 1:33 PM - 7 messages
Hi, We recently undertook a server replacement project and installed new AD Servers running Server 2003 R2 x64 edition on our network. We upgraded the forest \ domain using ADprep in order to install R2 Domain Controllers and have also kept the old servers running as extra DCs (Server 2003 based). We ...
Score ADAM gives the users from an Active Directory
Martin Komischke - 27 Sep 2006 1:19 PM - 14 messages
Hi Newsgroup, I have the following scenario: An ADAM instance is running on an XP machine it gives the users from an Active Directory from the Domain Controller on another machine. Now I want to give all the users in the ADAM additional attributes, I ...
Score Join Client PC to domain without domain admin right
John - 27 Sep 2006 1:05 PM - 6 messages
Hi all, I hope to let one of my teammate (who is IT support) have right to join domain after PC setup and meanwhile not giving him domain admin right. How to do so? Thanks for all professional advice. ...
Score ADFS issues
Francois Kreutz - 27 Sep 2006 12:27 PM - 4 messages
Hi, Any help, or even better, forwarding these issues to the product team would be greatly appreciated. We would like to use ADFS for Web single sign-on for our extranet users. We have succesfully set up the following test environment: ...
Score Accidentally removed computer accounts
anton.vinokurov - 27 Sep 2006 11:52 AM - 12 messages
Hi All, I have a bunch of W2K3R2 computers in W2K3 domain. Accidentally these computer accounts were removed from the AD. Now I cannot log on to the domain from these computers (for sure - domain contoller has no info about it). MS suggestion is to re-join computer to the domain back, but ...
Score Account where LDAP authentification succeds but login is disalowed
Søren_Schimkat - 27 Sep 2006 8:28 AM - 3 messages
Hi guys Would it be possible to completely deactivate login for a particular user - but still allow the user to be authenticated though LDAP? Regards Søren Schimkat ...
Score password expired corresponding with "accountExpires"?
newbie admin - 27 Sep 2006 8:23 AM - 3 messages
Hi, today one of our AD/Novell users reported his AD password has expired, but when I looked into AD Users and Computers I found "user must change password at next logon" checkbox is empty, while his password did expired and ...
Score ftp/IIS/AD could not log on
Fabio Pardi - 27 Sep 2006 8:13 AM - 2 messages
Hi everyone, here is my problem i've 2 machines: a server running windows 2003 server, acting as domain controller (domain  name: nlbtest.it) a server running windows 2003 with an IIS's ftp server installed. This  second server is in the domain nlbtest.it and configured using active  ...
Score NTFS Permissions
Net Admin - 27 Sep 2006 3:39 AM - 3 messages
I have an administrator at one of my other sites that needs full control permissions on a drive of the DC, it's a seperate drive used for file sharing. He is not a Domain Admin but he needs access to that drive. If I ...
Score Removing windows 2000 as a DC
NewsGr - 27 Sep 2006 3:13 AM - 5 messages
We have 2 DCs 1 2003 and 1 2000.    I need to upgrade the functional level to 2003, so I need to remove the 2000 DC.   I have another 2003 server I could add as a DC  also.    Is there a preferred method for removing a 2000 ...
Score Default Domain Policy Problem
hitec - 27 Sep 2006 12:51 AM - 5 messages
W2003 AD, single domain, windows 2000 native, 2 DC=2003, 1 DC=2000 When I rht-click on the Default domain policy object (usingGPMC) and select edit, a message is displayed "The system cannot find the path specified". Also, if  I click on mydomain.com to display the linked GPO's, no group ...
Score Migration question
Gray - 26 Sep 2006 11:57 PM - 5 messages
How do you add an administrator from one domain to another? Example: Administrat***@123.com administrators group on 456.com ...
Score How to Add Domain Admin to Local Admin Group on all Workstations
celticmcse - 26 Sep 2006 11:47 PM - 3 messages
I have a Windows 2000 network with about 15 XP Pro workstations. What is the easiest way to add the Domain Admins group to the local Admin group of the workstations.  Some sneaky folks have removed it. Can this be done with a group policy? ...
Score Seized FSMO role adding server back to domain
Brian - 26 Sep 2006 10:57 PM - 10 messages
Had a DC go down (W2k), I seized the AD schema FSMO role from this downed W2k DC to a W2K3 DC.  I didn't know when or if I could get the down DC back up.  Have made repairs to the W2K DC and would now like to reconnect this server ...
Score Security using positions and organizations
nugget - 26 Sep 2006 10:45 PM - 13 messages
Hello: My group in the company with which I work has a design for organizational security using Active Directory.  However, this design is not being received well by the AD operations folk and information security department.  The line I have received is "this is not the ...
Score LDAP Query
Dan - 26 Sep 2006 10:33 PM - 11 messages
I am trying to query my company's active directory using LDAP. I need to find what groups a specific employee is in. I can't get the query string to work, even typing it in my Explorer address. Our structure is set up as: domain - ...
Next » 2 3 4 5 6 7 8 9 10