|
server
newsgroups
|
|||||||||||||||||||||||
|
|||||||||||||||||||||||
Windows Server Active Directorymicrosoft.public.windows.server.active_directory
james henderson -
23 Dec 2006 3:33 PM - 3 messages
I have two values that I would like to make available for all computers connected to a domain: a URL and a port number. I am trying to avoid running a script (I will if I need to), but isn't there a way to create a ...
Will Sellers -
23 Dec 2006 4:37 AM - 7 messages
I have followed several well documented steps for creating a mandatory profile that will be used by all students in the students group. Created a share on the server \\server\student profile gave student group full control logged on at a workstation with a test.student account ...
dadockter -
23 Dec 2006 3:16 AM - 4 messages
My company has just purchase another company. We both have our own 2003 AD structure. I would like to merge their AD structure xyz.com into ours abc.com. There are very few users and computers that will need to migrated ...
JacksonS -
22 Dec 2006 8:45 PM - 2 messages
We justed posted a freeware management pack that enables monitoring of ADAM instances from MOM 2005. In summary, the MP provides the following capabilities: - monitoring the services that ADAM itself is critically dependant on - monitoring the health of ADAM including replication, LDAP, net logon ...
Steven Davidson -
22 Dec 2006 5:56 PM - 4 messages
I'm interested in understanding more about how the KCC generates replication connections. In my test enviornment, I created 2 sites in addition to the default site (NOTE: I renamed the default site from "Default-First-Site-Name" to "Datacenter"). The two additional sites are MPLSBranchOffice and ...
Dennis -
22 Dec 2006 5:06 PM - 3 messages
Windows Server 2003 STD SP1 with Active Directory - DC - DNS Server - WINS Server - DHCP server. I am troubleshooting DHCP server errors (Event 1014, DHCPserver - Jet errors -1022, -1032, and -524) in the system log and ESENT errors (Event ID 215, ...
Bruce -
22 Dec 2006 4:27 PM - 4 messages
how can i create carrige return in my logon banner message, or increase the number of chars allowed in the banner window??? ...
Owen -
22 Dec 2006 3:35 PM - 5 messages
I have a single domain 2003 native domain with 40 domain controllers that is not on service pack 1. All DC's are GC's. We would like to upgrade to R2. I understand that first I should upgrade the ...
samir shah -
22 Dec 2006 3:10 PM - 2 messages
I have systems in workgroup and I am planning them to joing into the domain My problem is that when users logon to the domain they will have new profile but in anyways I want to retain the same profile for all the users seating on ...
Wingnut -
22 Dec 2006 2:13 PM - 6 messages
This is wierd, over the last day somehow Something has been changed that has not allowed me to log on locally (interactively) to either of our DC's. I checked the default domain controler policy and eveything looks ok....I am using the administrator account and the admin account ...
jwilmer -
22 Dec 2006 1:59 PM - 3 messages
We are getting the following error on one of our DCs. It states there is a summary of warnings but it does not list what the problem is. I looked at some tech notes and they all talk about referencing what the warning is. ...
Will Sellers -
22 Dec 2006 12:20 PM - 2 messages
I'm creating a mandatory profile that will be stored on a share folder with redirection from a GPO. When I select user profiles on the target workstation that I want to mirror, and then select the user profile it will not let me do the copy to function. So as admin I decided to just ...
Shrikant -
22 Dec 2006 11:42 AM - 5 messages
Hi, I want to reset the local administrator password remotely of all the systems in domain simultaniously. Does anybody know utility or link. ...
Dan -
21 Dec 2006 9:30 PM - 2 messages
Hey guys, Is there any way to get a Linux or Mac client to use DFS namespaces for access to file shares? I can get them to use the virtual server name of my cluster but no love from using the domain based DFS name. ...
dasmay@gmail.com -
21 Dec 2006 7:37 PM - 5 messages
I'm trying to setup some virtual machines to do a proof of concept with ADFS and group claims. I'm following the MSDN article in November's issue. I've walked through the procedure twice now creating these VMs ...
CB -
21 Dec 2006 6:51 PM - 2 messages
Greetings, I've been doing my Group Policy mgmt. from my trusty XPSP2 laptop via GPMC (SP1) for a few years. I've added a few .adm templates in that time as well. Now I'm getting a new laptop and wondering if I need to take any ...
oj.groups -
21 Dec 2006 6:24 PM - 2 messages
Here's the scenario... (I'm brand new to AD so please forgive me if I say something that doesn't make sense.) -We plan to build out an AD forest on-site in the next year. Currently, we have nearly 70 Windows servers configure as standalones. One of ...
Andre Santos -
21 Dec 2006 5:33 PM - 10 messages
Hiya, Here's the problem, I have installed in a server the windows 2003 R2 Enterprise 120 day trial, and now we bought the license of windows 2003 R2 (not enterprise) and we have to install the OS again, as well make it domain ...
Ryan Sanders -
21 Dec 2006 5:07 PM - 4 messages
A few days ago I asked if you could programatically set a users account to the locked out status, not disabled. I was told this could not be done. Now I want to know (and I assume not) if the account can be unlocked by ...
Jeff -
21 Dec 2006 5:03 PM - 5 messages
We have a mixed environment of 2003/2000 servers with one of the DC's being 2000, sp4. On the 2000 DC we are showing the following error message every few minutes: Event Type: Error Event Source: Userenv ...
webrod -
21 Dec 2006 3:27 PM - 3 messages
Hi, I would like to know the way to authenticate a user within ADAM. Suppose a user is logging on my web site, it provides his user/pwd. Now, I need to query ADAM to check whether the user is there and if the ...
RC -
21 Dec 2006 3:26 PM - 4 messages
I was thinking about using RIS to roll out servers from central. My question is this: How easy is it to use RIS and roll out windows 2003 server to multiple servers. Some will be on HP servers and some on ...
Cwhitmore -
21 Dec 2006 2:07 PM - 2 messages
I'm running Certificate Authority on our email server that is also running as a DC on Windows 2003. I would like to move Certificate Authority off of the existing DC and onto another server. The KB that I found on this required ...
Patrice Bruhat -
21 Dec 2006 2:07 PM - 6 messages
Hello, I have a problem with a new domain controler to join my existing 2003 domain. It can't fully complete the initial synchronisation with partners (everything looks OK without this new server). I have an error with RidSetReferences attribute missing in AD for this new ...
p.o -
21 Dec 2006 12:56 PM - 2 messages
Hi I've renamed domain. I think all working ok, but I've problem with CDP. I want to add another CDP but completly I don't know how to do it. Regards ...
Hong Jin -
21 Dec 2006 10:38 AM - 3 messages
Hi, I have a Domain Controller and a few clients connected to it. Once i reformat the DC, i put back the same domain controller name and used back the same domain. However, when existing clients try to connect to the domain, ...
Several Login attempt -
21 Dec 2006 6:56 AM - 19 messages
hi we are using windows 2003 ent server as dc. my problem is, im not able to create any new user from AD users & computers console. the error is: "An error occured, contact your system administrator". No error code is in ...
Will Sellers -
21 Dec 2006 4:47 AM - 3 messages
I have 350 students that are currently in a group called students. I need to create an OU and group policy that will run a logon.bat for the students. Is there a way that I can avoid having to add 350 students to the OU? ...
Phillip McIntosh -
21 Dec 2006 3:25 AM - 4 messages
I need to be able to list the ACE entries in a domains ACL. i.e. I want to output to a file, the permissions that have been delegated to the various users/groups list in a particlaur domains ACL. ...
Drew -
21 Dec 2006 2:09 AM - 3 messages
I am hoping there is a tool that will alllow me to get a report on the following: Default Group Policies Current Settings of Group Policies I want this to apply to the entire domain as well as list each OU. ...
DavidV -
21 Dec 2006 1:39 AM - 2 messages
Hi All, A customer of mine is currently migrating from NT 4.0 to a Windows 2003 environment. During an in-place upgrade of the first 2003 domain controller it asked the question whether we wanted a Windows 2003 Interim domain/forest ...
Keith -
20 Dec 2006 9:41 PM - 2 messages
Does anyone know of a best practices document about building a Exchnage site within an AD infrastructure? I found a how-to article, but I am looking for a best practices doc... ...
Keith -
20 Dec 2006 9:40 PM - 3 messages
Is there a limitation number of CPUs that a Windows 2003 DC can use or is it based upon the OS limitations for standard, enterprise, data center? I thought I remember a limtition for Windows 2000 Domain controllers could only utilize 2 CPUs at a time…Could be wrong... ...
Haywood Jaeblowmie -
20 Dec 2006 9:39 PM - 6 messages
Is there a way to list Global catalog members in the forest using a command-line utility like adfind? Thanks, Hj ...
Tim Kelley -
20 Dec 2006 8:54 PM - 4 messages
We have a single forest / single domain network with 3 DCs. Currently only one of the DCs if a GC. Should we also make each of the other DCs a GC? Thanks, ...
Archi -
20 Dec 2006 8:38 PM - 33 messages
I need to give admin access to domain controllers for a certain domain group but without accessing Active directory. Any options? ...
da1308ve -
20 Dec 2006 7:46 PM - 2 messages
I have two NT domains, one has working trusts with the new 2003 server and I am manually copying the profile from the old to new user on new domain for certain reasons, and it is working very well, but my other NT domain the ...
Steven -
20 Dec 2006 7:32 PM - 2 messages
Situation: -Windows 2000 Domain (about 5 years old) with 10 Win2K workstations -System partition on the DC is nearly full (3.5 GB of 4 GB, high fragmentation, dynamic disk) -domain policies not replicating/being applied properly --example: "don't display last logon" isn't being honored by new or old ...
Elizabeth -
20 Dec 2006 7:30 PM - 4 messages
Hi, I have 3 DC´s. User have been authenticate in DC3. How can I change this to users authenticate in DC2? Thanks, Elizabeth ...
Dan -
20 Dec 2006 7:20 PM - 4 messages
Hello, I understand that if a DC is offline for 60 days (by default) that very bad things will happen if the DC comes back on the network. What I don't understand is why that happens? Why is that behavior necessary? Shouldn't ...
pkoch -
20 Dec 2006 6:38 PM - 6 messages
I presently have seven child domains under one root domain.If user X who belongs to the X domain logs into a computer that is in a different domain but he/she selects the X domain from the “logon to†drop down menu. Is there ...
WANNABE -
20 Dec 2006 6:26 PM - 6 messages
Sorry I previously posted this as "Group policy push to HKLM/software/ODBC" I have a script that runs fine for local admin users, but I have not YET found a way to have this run on all network PC's. It fails on users that do ...
WANNABE -
20 Dec 2006 5:13 PM - 5 messages
I have a script that runs fine for local admin users, but I have not YET found a way to have this run on all network PC's. It fails on users that do not have permissions to HKLM. (Network; Win2000 Domain Controller, some ...
jrm73 -
20 Dec 2006 4:09 PM - 2 messages
I am in the midst of a migration to Exchange 2003. We have to Exchange environments going (5.5 and 2003) and therefore users have accounts in both. We also have the dist. groups in both. I need to export the ...
IainM -
20 Dec 2006 3:55 PM - 6 messages
I've done the research in MS kB articles 179442, 154596, 224196, 319553, 555381 and I have the document "Active Directory in Networks Segmented by Firewalls" regarding restricting the ports that AD uses to sync. I plan to do the registry changes on DCs 1 at a time, but do I need to do ...
Greg Smith -
20 Dec 2006 3:36 PM - 2 messages
I want to rebuild my AD server. Before I do this I want to backup AD so it can be restored after the process. What is the best way to do this? ...
ocean -
20 Dec 2006 3:00 PM - 3 messages
Hello friends: I have recently setup a Vista Business workstation and joined it Windows 2003 Active Directory domain, but when I logged on to the AD domain from this workstation, I didn't get any drives mapped or printers installed. Is ...
SC -
20 Dec 2006 2:04 PM - 2 messages
Hi, I'm trying to setup a config as told in the ADFS Step by Step Guide but I still have troubles. -----DCs (adfsresource & adfsaccount)----- It seems that both DCs -adfsaccount and adfs resource- (with ADFS Federation Service, self signed cert,....) are well configured except ...
Marc -
20 Dec 2006 1:19 PM - 3 messages
We are designing a large AD Forest 70k+user accounts with an OU structure to divide by continents then by country and then within each country users, computers etc. Within each country we would need to have different laptop and desktop ...
Rocky -
20 Dec 2006 12:57 PM - 7 messages
I have a native 2003 active directory domain spread across 2 sites, site A and site B. I have set up the 2 sites and associated the respective subnet to them. I have 2 domain controllers, 1 in each site. Site A have the ...
fiordialiso -
20 Dec 2006 8:33 AM - 2 messages
I would like some advice on how to use AD to control membership of groups in a non-MS selfdeveloped application. Currently we use the AD to align users with in our application. Thereafter we enroll the mass of users to the appropiate application groups from the ...
Darren@community.nospam -
20 Dec 2006 3:33 AM - 2 messages
update...Used dcpromo /forceremoval and then ran metadata cleanup . All Child DC's and child domain have been removed successfully Thanks ...
Dan -
20 Dec 2006 2:27 AM - 8 messages
Hi, I know there are all sorts of bad things that happen when a DC goes offline (cannot connect to other DC's) for 60 days. Is there anything that can be done once the connection is restored to get things back to normal? Is ...
JMCColorado -
20 Dec 2006 12:18 AM - 2 messages
I am being asked to investigate the possible side-effects of having a single Active Directory 2003 (Native) security group with 250,000+ users. Is this realistic. Is there anyone out there with a group of this size in production? ...
Bruce -
19 Dec 2006 11:24 PM - 2 messages
How can i change the size of text or color in the prelogon network warning message. I am referring to the legal notice caption and text in the registry. ...
CHANGING FAIL OVER CLUSTER TO NLB -
19 Dec 2006 10:02 PM - 3 messages
Simple question. Since, I am unable to test it right now, asking this question. Trying to access a remote share using the following in a 2003 ADS environment: \\servername.abc.defgh.com Will appreciate a quick response. Thanks. Victor ...
Roberto R -
19 Dec 2006 9:42 PM - 2 messages
Trying to resolve this issue with AD DC, event log is showing an error 1801 under Directory Services. The partition DC=DomainDnsZones,DC=GMGPartners,DC=Net should be hosted at site CN=EmailHQ,CN=Sites,CN=Configuration,DC=GMGPartners,DC=Net, but has not ...
Kevin J -
19 Dec 2006 5:48 PM - 5 messages
I am building out a domain that will possibly have over 100 sites with the next year or so and could easily grow to over 200 with 3 years. These sites are accessible over satellite connections. Should I create child domains for all sites? ...
ahertenstein -
19 Dec 2006 5:43 PM - 8 messages
I have an awkward script to write and I need a little advice. I have installed ADAM because I have an application that needs a bunch
of user attributes and the customer doesn’t want to affect the AD
schema, so in comes ADAM. ...
Kevin J -
19 Dec 2006 5:02 PM - 11 messages
I have created a child domain and I am having big problems creating the Default Application Directory Partition for DNS. When I attempt to create the ADP for the local domain, I receive no error through the DNS GUI. But when I attempt to change replication for the zone to ...
Ian Becker -
19 Dec 2006 3:54 PM - 4 messages
In our current environment, we have a Tivoli Directory server that is our main LDAP server, would it be possible to have Active Directory pass through logons to that to authenticate users without actually replicating the databases? Thanks, Ian ...
John -
19 Dec 2006 3:39 PM - 3 messages
Hi all, There are one OU users (60 users) that are going to move out of our company and become the new company with seperate domain in different location. What's the easy way to set their users account up in the new location with ...
Ryan Sanders -
19 Dec 2006 3:01 PM - 7 messages
After reading this I am unclear on what to set this value to in order to accomplish my task. [link] I want to remember invalid login attempts forever, meaning if you ever ...
John -
19 Dec 2006 3:00 PM - 2 messages
Hi, We recently moved a Windows 2003 DC to another site physically, what's the best way to do this? All other DCs still have the old IP information. Do I just rename all the DNS records, or there's a better way to accomplish this? ...
ahertenstein -
19 Dec 2006 2:56 PM - 2 messages
I have an easy issue. Here are the things I need to do and want to know
if each of these are possible: Can I only Sync AD Objects based on a Group Membership? I.E. I only
want to Sync user and group objects if that are in a Security Group
called ADAM. ...
Managori -
19 Dec 2006 11:13 AM - 3 messages
Hello We have windows 2000 domain with four domain controller, one of my domain controller was crashed then we have formated and rebuild the domain controller with the same name and same IP. This domain controller was schema master and before rebuild we did not sieze the role to another DC. Now we are ...
Emmett -
19 Dec 2006 9:09 AM - 7 messages
Hi, Does anyone know if it is possible to read a user's password from AD. Thanks. ...
Ali Kemal -
19 Dec 2006 9:09 AM - 2 messages
Hi, I wonder, whether it is right to use "_" character by naming computer in W2K3 domain. Because the system tells not to use nonstandart characters like "_", but it accepts that. might it be a problem such as the Active Directory can drop those computer ...
Hong Jin -
19 Dec 2006 9:09 AM - 3 messages
Is there a setting that i could enable so that a particular user of the domain could edit the registry value? Thanks in advance. ...
remontnik -
19 Dec 2006 7:32 AM - 4 messages
I have a Windows 2003 AD domain in a lab environment. I have installed Longhorn Server x64 (the August CTP release) on a member server and want to make it a domain controller. My question is, do I have to extend the AD ...
paok -
19 Dec 2006 6:17 AM - 2 messages
hi, i have a dc running but has old hardware and i bought a new server and i want to replica from the old to the new one.I installed the new server as additional server and configured as global catalog.My dns service is ...
Milind Sadavarte -
19 Dec 2006 3:10 AM - 3 messages
Hi, is any body there to guide me for the following issue?. How can i get the details of user accounts in AD that are not frequeantly used or not used from the logn duration. is there any windows utility or ...
Marco Shaw -
19 Dec 2006 1:04 AM - 3 messages
I'm just wanting to write some 'proof of concept' scripts relating to AD that would help in troubleshooting any issues. Like the AD connections/second, etc. Are there any other qualitative data that can be used in general ...
Alan C -
19 Dec 2006 12:55 AM - 6 messages
I have a client with 5 W2k3 servers (pdc, bdc, exch, ts, security) that have all been migrated/updated from w2k. There are obvious inconsistencies in the AD as some objects still have references to the old servers, etc, Can anyone point me to a 'best practice' or white paper relating to cleaning ...
PeterP -
19 Dec 2006 12:13 AM - 2 messages
When I am running the netdiag /l /debug on DC, I am getting the following error DC list for domain CURR: ec-ms-bh01.curr.vsb.bc.ca [DS] Site: Data-Center-Site ...
Mrpush -
18 Dec 2006 10:36 PM - 2 messages
Hello, I'm joining users to my new domain and have setup ROAMING profiles by coping existing local Worstation profiles to the romaing profile share. I then set the ROAMING profile path through AD. When I do this and logon to a WS via the domain, I can no longer run ...
jatdesi -
18 Dec 2006 10:29 PM - 9 messages
Hi, My current setup has 2 AD DCs and both are running AD-integrated DNS i.e. 2 DCs for contoso.com running DNS. So all servers in this environment have these DNS servers listed as Pri and Sec. I need to add a Child domain in ...
Mike Bonvie -
18 Dec 2006 9:14 PM - 7 messages
the adfind query I'm using from Joe Richards reply is: adfind -sc exchmbxs -af "msexchhomeservername=/o=Com of Mass/ou=MassMail-01/*" >output.txt The output looks like: Directory: Windows Server 2003 22220 Objects returned ** dn:CN=SystemMailbox{56FDE209-20CC-443D-BD4C-4723F8CA129F},CN=Microsoft ...
Sergio -
18 Dec 2006 8:43 PM - 4 messages
Hi, I'm looking for a way to audit the Domain Administrator user. I would like to know when this user logs in and on witch computer or server in the Domain he logs in. Is there a way to audit all this information? ...
Andy L -
18 Dec 2006 7:48 PM - 3 messages
I have an AD forest with 1 root domain and 3 child domains that originated from the upgrade of 3 separate NT4 domains. All domains are running in Windows 2000 Mixed mode as a result of the NT4 upgrade, but all domain ...
kjs -
18 Dec 2006 7:47 PM - 3 messages
I am a newbie to active directory and am working on a project that needs to have the active directory linked to our open ldap database that is sitting on a linux server. We have over 30K accounts there and I'm trying to find a way ...
Alex -
18 Dec 2006 7:40 PM - 3 messages
Hi. We have recently added a 2003 DC to a single 2000 DC domain. The addition of the new DC went smoothly, dcdiag /v, repadmin /showrepl and netdiag tests were all clear and everything appeared to be working ...
chewbacca -
18 Dec 2006 5:15 PM - 4 messages
I'm running Win2K3 server. We've set a password policy in place and I went through GPO editor >> Computer Config >> Windows Settings >> Security Settings >> Account Policy >> Password Policy and set the Enforce pw History, Max pw, Min pw, min pw lengh, ...
Stan -
18 Dec 2006 4:11 PM - 3 messages
Hi I am wondering if someone can help me ... We have a large forest with 3 regional domains connected to a ADROOT domain. With AD User administration delegated to regional offices. Each office (approx 30+) can create user accounts and manage groups, etc. ...
Thom Paine -
18 Dec 2006 2:30 PM - 2 messages
I have a nice shiney new Dell Poweredge 2850 that I deployed this weekend and I'm having all sorts of issues with it. When I add a user to active directory, and add them to the administrators group, they are unable to install software on a workstation. ...
Dominique -
18 Dec 2006 1:37 PM - 3 messages
We had some issues lately where DNS entries of some of our domain controllers have disappeared and caused replication issues. We run several tests and one thing that bothers me is the following error message from DCDIAG: Warning: Attribute userAccountControl of <domaincontroller> is: ...
Matt MC -
18 Dec 2006 1:16 PM - 7 messages
Hi Guys, Its been so long since I studied this stuff and its not something I've worked with much so a bit confused. 12 sites all connected to one DataCentre SiteLinks created between each site and the DataCentre with Default ...
filip -
18 Dec 2006 1:10 PM - 4 messages
on my domain, I need to change on few computers the 'dns server' ip. How can it be done through active directory ? thanks ...
Gibraltar -
18 Dec 2006 10:21 AM - 3 messages
Hi, I have an application running on a Unix server and I have an ADAM server. Can I retrieve the information of the objects in ADAM usind LDAP queries from the unix server through a simple bind? Are there any foreseen issues? ...
Mathias Erlandsson -
18 Dec 2006 9:22 AM - 3 messages
Hi! Is it possible to use ADFS to authenticate in OWA? Does anyone know how to do this? /Mathias ...
vanceazvb -
18 Dec 2006 8:01 AM - 3 messages
Soon I'll be setting up 2 servers, each in it's own site. The idea is to have a SBS 2003 Server at the main location and 2003 Standard at the other. Both will be DCs and GCs. There will be a VPN connecting the ...
snoop -
18 Dec 2006 4:56 AM - 4 messages
Hi all, I need to bulk change group membership in users in a OU. How do i do this? Thanks in advance ...
MackS -
18 Dec 2006 4:17 AM - 7 messages
Hello I am looking for a more secure method of having password for our users in windows 2003 AD network. Is there a way to automatically expire password at the end of each day and assign a new password. I would like to generate a password for each day in ...
Milind Sadavarte -
18 Dec 2006 3:45 AM - 3 messages
i want to take the backup of 2003 server. which are the important files and folders i have to backup from the win 2003 server ...
Alex -
17 Dec 2006 3:41 PM - 5 messages
Hi. We have been having a problem with a test network which we are using to test an upgrade from 2000 to 2003. The network was built from a restored 2000 DC image before the first 2003 DC was added. The restore completed ...
Colin -
17 Dec 2006 12:33 PM - 11 messages
Problem you may have heard numerous times! Senario: 1:) PC connected to Bekin Router/Modem. No problem 2:) Promote PC to a DC with Active Directory, DNS, DHCP 3:) No way to acces router controls (explore page 192.168.2.1) ...
IT Mgr -
17 Dec 2006 2:02 AM - 2 messages
We are sarting a Service Bureau and wil have multiple financial clients. Security is the main concern with management secondary. We aren't sure whether we can put multiple different clients under on forrest and setup directory security. Or would it be better to just maintain seperate forrests ...
|
|||||||||||||||||||||||