[ActiveDir] Unresolved SIDs in ACL

2006-01-18 Thread neil.ruston
Title: Unresolved SIDs in ACL joe, The script owner realised just after I posted that the domain name was constructed wrongly in the script :( Sorry to waste your time. neil From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of joeSent: 17 January 2006 23:50To:

RE: [ActiveDir] Migrate domain to separate forest

2006-01-18 Thread Larry Wahlers
Thanks for your reply, Gil. You wrote: Just out of curiosity, why do they think they want their own forest? Because they want to have their out-of-office replies go to the internet, and our security policy won't let 'em do it because it affects everybody else, too! In any case, there's no way

[ActiveDir] Multiple Password Policies

2006-01-18 Thread Carerros, Charles
Title: Unresolved SIDs in ACL I was just asked to look at this application that was recently released: http://www.specopssoft.com/products/specopspasswordpolicy/Default.asp It seems like someone did some good programming around the password filter dll concept and then tied it into

RE: [ActiveDir] Manage Your Server - Removing from Default User

2006-01-18 Thread Justin_Leney
Everyone, thanks for the replies. Appreciate the help. Yes, we deploy new servers almost daily, and we have developers and application administrators who log in to the systems. That being said, I did not want them to be able to configure server roles (among many other things...) Also locked

RE: [ActiveDir] Multiple Password Policies

2006-01-18 Thread neil.ruston
Title: Unresolved SIDs in ACL I have not used or assessed a product like this, but I would guess that a client side GPO extension is required. This may not be feasible in certain environments. neil From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Carerros, CharlesSent: 18

RE: [ActiveDir] Manage Your Server - Removing from Default User

2006-01-18 Thread Rich Milburn
Ah Darren you need the Make-or-Buy talk J funny that you could write one quicker than you could find it. I hope longhorn server includes the ability to search for a group policy setting the way vista lets you search the start menu that would be nice

RE: [ActiveDir] Congrat Jorge !!!!!

2006-01-18 Thread Rich Milburn
Title: Congrat Jorge ! Brian when I need your help Ill ask :op Who wouldve thought there were TWO people from here on this list?? (Ill bet there are THREE hehe) --- Rich Milburn MCSE, Microsoft MVP - Directory

RE: [ActiveDir] Manage Your Server - Removing from Default User

2006-01-18 Thread joe
If you can write one faster than finding it, I saw write away! From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Rich MilburnSent: Wednesday, January 18, 2006 9:53 AMTo: ActiveDir@mail.activedir.orgSubject: RE: [ActiveDir] Manage Your Server - Removing from Default User Ah

RE: [ActiveDir] Multiple Password Policies

2006-01-18 Thread joe
Title: Unresolved SIDs in ACL Ditto whjat Neil said. These are things you need to test very very very very very much. They are hooked into a very core part of your DCs. You want to really load a DC up and stress test the crap out of the tool it to see how it handles things and try to get as

RE: [ActiveDir] Unresolved SIDs in ACL

2006-01-18 Thread joe
Title: Unresolved SIDs in ACL Ah. Kind of scary that the script created the ACEs at all, should have errored every time that you tried to apply a bad ACE. From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of [EMAIL PROTECTED]Sent: Wednesday, January 18, 2006 7:37 AMTo:

RE: [ActiveDir] ADPrep Version Questions

2006-01-18 Thread joe
Ah don't worry about it, I figured you were just disconnected there when I saw the first question at all. That is why I counted it out. :) From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Noah EigerSent: Tuesday, January 17, 2006 8:38 PMTo:

RE: [ActiveDir] Congrat Jorge !!!!!

2006-01-18 Thread Brian Desmond
Title: Congrat Jorge ! Im here when you need me. Thanks, Brian Desmond [EMAIL PROTECTED] c - 312.731.3132 From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Rich Milburn Sent: Wednesday, January 18, 2006 9:58 AM To: ActiveDir@mail.activedir.org

RE: [ActiveDir] Multiple Password Policies

2006-01-18 Thread Darren Mar-Elia
Title: Unresolved SIDs in ACL I know these guys at Specopssoft and they have done some cool stuff with GP, but its not clear to me how this could be accomplished with just some CSEs. This seems like it would require some fiddling at the DCs as well. Maybe one of them is on this list and can

RE: [ActiveDir] Multiple Password Policies

2006-01-18 Thread Carerros, Charles
Title: Unresolved SIDs in ACL This company doesn't provide a large amount of documentation on how they are doing this password change but it seems like they are using the MS supported method. As for scripting password resets, I'm very concerned especially if this gets implemented I will

RE: [ActiveDir] Manage Your Server - Removing from Default User

2006-01-18 Thread Darren Mar-Elia
That would be nice, but...no, I don't think search will be any better. I suppose you could consider it a step up that the "new" ADM file format will be XML. However I think in that case, the equation below would have been reversed. I don't know about you, but I'm much slower creating

RE: [ActiveDir] Unresolved SIDs in ACL

2006-01-18 Thread Rich Milburn
Title: Unresolved SIDs in ACL Amazing what On Error Resume Next will do for you eh? --- Rich Milburn MCSE, Microsoft MVP - Directory Services Sr Network Analyst, Field Platform Development Applebee's International,

RE: [ActiveDir] ADPrep Version Questions

2006-01-18 Thread neil.ruston
It's a common source of confusion. Ask a user if version 1.4.4 is newer or older than 1.4.3.4 :) Some say "344 therefore the latter is newer" some say "43 therefore the former is newer" neil PS The purist in me would say that without a leading 0, the 196 below looks like 1 thousand 9

Re: [ActiveDir] ADPrep Version Questions

2006-01-18 Thread Jeremy Olson
The versionj of adprep.exe that is included with R2. is 5.2.3790.2075JeremyOn 1/17/06, Noah Eiger [EMAIL PROTECTED] wrote: Hi- I am preparing to upgrade a W2k domain to W2k3. I want to use the latest version of ADPrep. I have found the following info and am confused: For

[ActiveDir] OT: Gauging AD experience

2006-01-18 Thread Douglas M. Long
I am trying to figure out how one gauges their AD experience. For example, I have designed, implemented and maintained an AD/Exchange environment of 5000 users with 1000 workstations from the ground up, alone. The environment is only 3 sites, with little complexity. I now work for a

RE: [ActiveDir] ADPrep Version Questions

2006-01-18 Thread Noah Eiger
Oh just what I need: more of those number-things to confuse me ;-) But seriously folks, would you recommend using this R2 version for the migration from W2k to W2k3? Yes, we plan to implement R2 on some machines in the domain. -- nme From: Jeremy Olson [mailto:[EMAIL

RE: [ActiveDir] OT: Gauging AD experience

2006-01-18 Thread Brian Desmond
Consulting is the way to see the world (sometimes quite literally) and figure out what in particular you like most and are best at IMHO. My biggest project, AD and Exchange for half million users, 80K devices, 650 sites, 70 DCs is really two people running it. Thanks, Brian

[ActiveDir] Move AD from one SBS Server to another?

2006-01-18 Thread Dan Tesch
I have a friend that has an SBS 2003 Server running in his business. The server was installed from an eval. disk and then someone used some kind of hack on it to get it to not expire. The server now cannot be updated to the latest service packs, etc. and has other problems. I was asked to help

RE: [ActiveDir] Multiple Password Policies

2006-01-18 Thread Thorbjörn Sjövold
Title: Unresolved SIDs in ACL Darren, you are correct, as usual when it is anything related to GP :) No, this is not possible to perform using only CSEs, Specops Password Policy uses a Password Filter as Joe implicitly stated in another post regarding this. I’ll keep this post as short as

[ActiveDir] AD computer accounts being removed

2006-01-18 Thread Brenda Casey
Occasionally computers will lose their account in Active Directory for no apparent reason.Sometimes it is a computer that has just joined the domain, while other times the machine has been a member of the domain for 2 years. The computer can only be logged on by a local account (not a

[ActiveDir] AD DNS in Windows delegation to Novell DNS

2006-01-18 Thread Chandra Burra
Hi Team, Wanted to know what are the pro's and con's of delegating the DNS zone created in Windows DNS for 2003AD being delegated to Novell DNS as the client wants to use Novell as the primary Regards, Chandra Burra

RE: [ActiveDir] AD computer accounts being removed

2006-01-18 Thread Brian Desmond
Brenda- I see the k12 email address (I run AD for Chicago Public Schools), first question I have to ask is do you have any lockdown software on these computers? DeepFreeze, Fortress, or similar? This will screw with and hose up computer password sync. Thanks, Brian Desmond [EMAIL

RE: [ActiveDir] Site link connection not created

2006-01-18 Thread Harding, Devon
Joe, youre exactly right, only I DO have the site link defined. Any other reason why it may not get created automatically? From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of joe Sent: Wednesday, January 11, 2006 8:55 PM To:

RE: [ActiveDir] AD computer accounts being removed

2006-01-18 Thread Gil Kirkpatrick
When you say "lose their account", do you mean the computer object in AD disappears? Or something else? -g From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Brenda CaseySent: Wednesday, January 18, 2006 10:42 AMTo: ActiveDir@mail.activedir.orgSubject: [ActiveDir] AD computer

RE: [ActiveDir] OT: Gauging AD experience

2006-01-18 Thread Robinson, Chuck
Internosis is now EMC Microsoft Practice. Doug, contact me offline if you are considering this option. [EMAIL PROTECTED] From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Gil Kirkpatrick Sent: Wednesday, January 18, 2006 12:17 PM To:

RE: [ActiveDir] AD DNS in Windows delegation to Novell DNS

2006-01-18 Thread Gil Kirkpatrick
I'm not familiar with Novell's DNS implementation... I assume it is based on BIND? See http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/ServerHelp/73c0ae36-8058-43d1-8809-046eb03b73fb.mspxand

RE: [ActiveDir] OT: Gauging AD experience

2006-01-18 Thread Bernard, Aric
Gils thoughts match with mine as well. AD is a critical infrastructure component and designing it properly is important. However, the real complexities of AD come into play as the ancillary systems leveraging the directory increase and as multiple directories need to be integrated in some

RE: [ActiveDir] OT: Gauging AD experience

2006-01-18 Thread Gil Kirkpatrick
Yikes, I missed that one! When did that happen? -g From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Robinson, ChuckSent: Wednesday, January 18, 2006 11:09 AMTo: ActiveDir@mail.activedir.orgSubject: RE: [ActiveDir] OT: Gauging AD experience Internosis is now EMC

RE: [ActiveDir] OT: Gauging AD experience

2006-01-18 Thread al_maurer
Avanade is another onea joint venture between Microsoft and Accenture. Looking at the same question myself in the last couple of months, Ive come to the same conclusion as Gil. Al Maurer Service Manager, Naming and Authentication Services IT | Information Technology Agilent

RE: [ActiveDir] AD computer accounts being removed

2006-01-18 Thread Brenda Casey
No, there is not any lockdown type of software on these machines. Thanks, Brenda Brenda CaseyNetwork Manager Billings Public Schools [EMAIL PROTECTED] 406-247-3792 From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Brian DesmondSent: Wednesday, January 18, 2006 11:02

RE: [ActiveDir] AD computer accounts being removed

2006-01-18 Thread Brenda Casey
Yes, their computer account in AD is actually gone. Thanks, Brenda Brenda CaseyNetwork Manager Billings Public Schools [EMAIL PROTECTED] 406-247-3792 From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Gil KirkpatrickSent: Wednesday, January 18, 2006 11:14 AMTo:

RE: [ActiveDir] AD computer accounts being removed

2006-01-18 Thread Garyphold
Title: Message Brenda, FWIW: It happens to me when I clone a workstation then try to join that workstation to the domain in order to change the computer name. AD sees 2 machines with the same name, gives me a notification and lets the 2nd one in. Then when the original machine with that

RE: [ActiveDir] OT: Gauging AD experience

2006-01-18 Thread Robinson, Chuck
Last week, http://www.emc.com/news/emc_releases/showRelease.jsp?id=3796 From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Gil Kirkpatrick Sent: Wednesday, January 18, 2006 1:53 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] OT: Gauging AD

RE: [ActiveDir] AD computer accounts being removed

2006-01-18 Thread Crawford, Scott
I dont have any suggestions for why its happening or how to prevent it, but I do have a tip for speeding up the rejoin process. Ive never had a problem ignoring the reboot prompt after you remove it from the domain. So basically, I just add it to a workgroup, ignore the reboot prompt, add

RE: [ActiveDir] AD computer accounts being removed

2006-01-18 Thread Navroz Shariff
Title: Message Hi Gary, Try looking at this article from MS regarding 'Resetting computer accounts in Windows 2000 and Windows XP'. http://support.microsoft.com/kb/216393/EN-US/ Also, you join the computer to the domain and then change its name? Do you reset the SIDs of the cloned

RE: [ActiveDir] AD computer accounts being removed

2006-01-18 Thread Brian Desmond
Title: Message Gary- Are you implying you dont sysprep your images? Thanks, Brian Desmond [EMAIL PROTECTED] c - 312.731.3132 From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Garyphold Sent: Wednesday, January 18, 2006 3:04 PM To:

RE: [ActiveDir] AD computer accounts being removed

2006-01-18 Thread Gil Kirkpatrick
You might enable auditing on the appropriate OU to find out who is doing the deleting. You need to enable AD auditing in the Domain Controllers group policy, and then add auditing entries on the security descriptor of the appropriate OU, e.g CN=Computers to track creation and deletion of

RE: [ActiveDir] AD computer accounts being removed

2006-01-18 Thread Doug Ferguson
We have seen the same thing in our organization, and I am investigating whether our technician that does the images for our desktop deployments has been using the wrong version of Sysprep. I read on the MS site that there are versions of Sysprep for different OS levels (or service packs).

RE: [ActiveDir] Migrate domain to separate forest

2006-01-18 Thread Grillenmeier, Guido
Because they want to have their out-of-office replies go to the internet hmm - that puts a whole new meaning to the requirements of a different forest. So just to get OOO replies configured the way they want, they're giving up being managed in the same forest and being in the same Exchange Org,

Re: [ActiveDir] AD computer accounts being removed

2006-01-18 Thread AdamT
On 1/18/06, Crawford, Scott [EMAIL PROTECTED] wrote: For example, if the domain box shows MICROSOFT, change it to Microsoft.com or vice-versa. This seems to trigger a domain rejoin without having to join the workgroup. snip On a side-note - is there a command line utility which will allow

RE: [ActiveDir] OU Delegation

2006-01-18 Thread al_maurer
Boy, I just had a consultant recommend an empty root as best practice for a divestiture were doing. Like Gil and Joe, I really dont see the benefit (nor could the consultant name anything specifically). We have a single domain and delegate OU rights based basically on an administrative

RE: [ActiveDir] AD computer accounts being removed

2006-01-18 Thread Coleman, Hunter
Look at netdom.exe -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of AdamT Sent: Wednesday, January 18, 2006 3:03 PM To: ActiveDir@mail.activedir.org Subject: Re: [ActiveDir] AD computer accounts being removed On 1/18/06, Crawford, Scott [EMAIL PROTECTED]

RE: [ActiveDir] AD computer accounts being removed

2006-01-18 Thread Doug Ferguson
I would use NETDOM JOIN. Type NETDOM JOIN /? To see the syntax. -;) Doug Ferguson Windows Systems Administrator Hynix Semiconductor Manufacturing America, Inc. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of AdamT Sent: Wednesday, January 18, 2006 2:03

[ActiveDir] adfind question

2006-01-18 Thread Noah Eiger
Hi I am trying to write a little batch file that will report various version numbers to me on each DC to help monitor the W2k3 upgrade process. I am having trouble getting adfind to report the objectVersion of the Schema. When I run: adfind DC1 b

RE: [ActiveDir] AD computer accounts being removed

2006-01-18 Thread Aaron Visser
Title: Message Gary, Brian, I do not use Sysprep on my images and have yet to come across any problems, but there may be one big difference with my images, before I ghost them or create the image I put the said machine into a workgroup and then create image. After I have imaged a

RE: [ActiveDir] OU Delegation

2006-01-18 Thread Gil Kirkpatrick
Tell him he needs to go to DEC. Its where all the cool AD people go :) -g From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of [EMAIL PROTECTED]Sent: Wednesday, January 18, 2006 3:11 PMTo: ActiveDir@mail.activedir.orgSubject: RE: [ActiveDir] OU Delegation Boy, I just had a

RE: [ActiveDir] adfind question

2006-01-18 Thread David Cliffe
Maybe you want "-h DC1"? Otherwise I'm not sure of the arg you're passing there. From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Noah EigerSent: Wednesday, January 18, 2006 5:27 PMTo: ActiveDir@mail.activedir.orgSubject: [ActiveDir] adfind question

RE: [ActiveDir] Migrate domain to separate forest

2006-01-18 Thread Gil Kirkpatrick
Someone needs to do a cost-benefit analysis. I would guess that 2 forests = 1.6x the operations costs more or less. I don't know Exchange at all... isn't there some way to constrain the policy to a subset of mailboxes? -gil -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL

Re: [ActiveDir] AD computer accounts being removed

2006-01-18 Thread AdamT
On 1/18/06, Aaron Visser [EMAIL PROTECTED] wrote: snip I have had to actually ghost computers in order to rejoin the domain because I do not have any local accounts active on my computers in the school, makes it a little safer J but with that comes more work L Surely it's not possible to

Re: [ActiveDir] AD computer accounts being removed

2006-01-18 Thread AdamT
On 1/18/06, Doug Ferguson [EMAIL PROTECTED] wrote: I would use NETDOM JOIN. Type NETDOM JOIN /? To see the syntax. Thanks, I'll look in to that. Would save me lots of time talking engineers through the process of joining a domain when they turn up to install new PCs. I'm also somewhat unhappy

RE: [ActiveDir] adfind question

2006-01-18 Thread Coleman, Hunter
Try it as adfind -h DC1 -b "cn=schema,cn=configuration,dc=myco,dc=private" -s base objectVersion From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Noah EigerSent: Wednesday, January 18, 2006 3:27 PMTo: ActiveDir@mail.activedir.orgSubject: [ActiveDir] adfind question Hi

RE: [ActiveDir] adfind question

2006-01-18 Thread Almeida Pinto, Jorge de
Try: adfind -schema -s base objectVersion AdFind V01.27.00cpp Joe Richards ([EMAIL PROTECTED]) November 2005 Using server: DC:389 Directory: Windows Server 2003 Base DN: CN=Schema,CN=Configuration,DC=domain,DC=local dn:CN=Schema,CN=Configuration,DC=domain,DC=local objectVersion: 30 1 Objects

RE: [ActiveDir] OU Delegation

2006-01-18 Thread al_maurer
Well, if I were going this time, Id tell you in person which consulting firm he worked for. HINT: its none of the ones weve mentioned in this thread as being AD experts. J Al Maurer Service Manager, Naming and Authentication Services IT | Information Technology Agilent Technologies

FW: [ActiveDir] adfind question

2006-01-18 Thread David Cliffe
Whoops...sorry...and also "-s base" From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of David CliffeSent: Wednesday, January 18, 2006 6:07 PMTo: ActiveDir@mail.activedir.orgSubject: RE: [ActiveDir] adfind question Maybe you want "-h DC1"? Otherwise I'm

[ActiveDir] LDAP and Global Catalog

2006-01-18 Thread Ravi Dogra
Hi all, Please update me that on which port communication between LDAP and Global Catalog takes place. -- RD List info : http://www.activedir.org/List.aspx List FAQ: http://www.activedir.org/ListFAQ.aspx List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

RE: [ActiveDir] OU Delegation

2006-01-18 Thread Gil Kirkpatrick
I heard you weren't going to make it this year. High suckage factor. -g From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of [EMAIL PROTECTED]Sent: Wednesday, January 18, 2006 4:21 PMTo: ActiveDir@mail.activedir.orgSubject: RE: [ActiveDir] OU Delegation Well, if I were going

RE: [ActiveDir] adfind question

2006-01-18 Thread Noah Eiger
Thanks all. I guess I needed the –s base. And yes, David, I omitted the –h. I checked and that omission was only in my post, not in the actual script. Thanks again. -- nme _ From: Almeida Pinto, Jorge de [mailto:[EMAIL PROTECTED] Sent: Wednesday, January 18, 2006 3:11 PM To:

RE: [ActiveDir] AD computer accounts being removed

2006-01-18 Thread Brian Desmond
Title: Message NO NO NO NO NO BAD BAD BAD You have to use sysprep. Youre getting duplicate SIDs here bad. Thanks, Brian Desmond [EMAIL PROTECTED] c - 312.731.3132 From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Aaron Visser Sent: Wednesday,

RE: [ActiveDir] LDAP and Global Catalog

2006-01-18 Thread Jerry Welch
Defaults: LDAP 3268 LDAP/S 3269 Jerry Welch CPS Systems US/Canada: 888-666-0277 International: +1 703 827 0919 (-4 GMT) IP Phone (Skype): Jerry_Welch ( www.skype.net ) -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Ravi Dogra Sent: Wednesday,

RE: [ActiveDir] AD computer accounts being removed

2006-01-18 Thread Gil Kirkpatrick
Title: Message Let me find my rolled up newspaper... :) From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Brian DesmondSent: Wednesday, January 18, 2006 4:50 PMTo: ActiveDir@mail.activedir.orgSubject: RE: [ActiveDir] AD computer accounts being removed NO NO NO NO NO BAD

RE: [ActiveDir] AD computer accounts being removed

2006-01-18 Thread Aaron Visser
No it is not possible to delete that account. (As far as I know) but there are times when the account has been disabled thru a Policy (that is how I disable it) and that program has not worked, I know it doesn't make a lot of sense because why is the policy being enforced if it will not connect to

RE: [ActiveDir] AD computer accounts being removed

2006-01-18 Thread Aaron Visser
Title: Message Well I would agree that is not a safe practice for most but for my application where all Local accounts are disabled I do not see a problem. Taken from http://www.sysinternals.com/Utilities/NewSid.html under the SID Duplication Problem Duplicate SIDs aren't an issue in a

RE: [ActiveDir] Site link connection not created

2006-01-18 Thread Lee, Wook
Just because there is a link defined doesnt mean that a connection object will necessarily be generated. For example, if there are three sites SiteA, SiteB and SiteC all with links to each other and all at the same cost, the ISTG may only create connection objects linking SiteA to SiteB

[ActiveDir] Accout policy

2006-01-18 Thread Mike Hogenauer
Sorry for the newbie question. So is it true you can only apply an account policy, for example a password policy to change passwords every 90 days only to the default domain policy? I need to change my policy setting per groups for password expiration, ex finance, HR, etc, for

RE: [ActiveDir] Accout policy

2006-01-18 Thread Darren Mar-Elia
Mike- Its a common question. There is currently only one *domain* password policy supported per AD domain. It does not have to be set in the DDP but it does have to be set on a GPO that is linked to the domain (if you have more than one, then the highest in the list wins). So you can't

RE: [ActiveDir] AD computer accounts being removed

2006-01-18 Thread Brian Desmond
Title: Message Sysprep also removes other information which identifies the computer. For example, I once had the pleasure of repairing a network where they had used NewSID to do this and also had bound NetBEUI to every NIC in the LAN. I had 500 computers all claiming the same NetBEUI name.

RE: [ActiveDir] adfind question

2006-01-18 Thread joe
Yep by default I assume you want a subtree search so you get everything, if you want a base level search (i.e. only object that is the base of the query) you use -s base. If you want just the children (not the object, not the grandchildren) you want -s one. Another assumption - if no filter is

RE: [ActiveDir] Site link connection not created

2006-01-18 Thread joe
Does both the DC in the site and the DCs outside of the site see that site link object and that it is connected? Are there connection objects under other DCs that point at the DC that is by itself? From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Harding, DevonSent:

RE: [ActiveDir] AD computer accounts being removed

2006-01-18 Thread joe
Title: Message Well not really. The important SID in question is the Domain SID and that isn't duped. The domain doesn't care about the machine SID. It is still good practice to newsid the machines though. If the accounts are disappearing it is one of two things 1. Someone is deleting it.

RE: [ActiveDir] AD computer accounts being removed

2006-01-18 Thread joe
Title: Message NetBEUI? Ouch. From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Brian DesmondSent: Wednesday, January 18, 2006 7:59 PMTo: ActiveDir@mail.activedir.orgSubject: RE: [ActiveDir] AD computer accounts being removed Sysprep also removes other information which

RE: [ActiveDir] OU Delegation

2006-01-18 Thread joe
Well I didn't say I don't see the benefit of an empty root. I just don't see it as a generic best practice. Sometimes it makes a ton of sense, sometimes someone needs to be slapped for bringing it up. ;o) joe From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of [EMAIL

RE: [ActiveDir] Migrate domain to separate forest

2006-01-18 Thread joe
Yeah if that is true that sounds like a great DCR or maybe something besides Exchange handling the EDGE... -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Grillenmeier, Guido Sent: Wednesday, January 18, 2006 4:44 PM To: ActiveDir@mail.activedir.org

Re: [ActiveDir] AD computer accounts being removed

2006-01-18 Thread AdamT
On 1/19/06, Aaron Visser [EMAIL PROTECTED] wrote: Taken from http://www.sysinternals.com/Utilities/NewSid.html under the SID Duplication Problem snip Taken from: http://www.windowsitpro.com/Article/ArticleID/14919/14919.html At the start of the GUI phase of installation each NT/2000

RE: [ActiveDir] OT: Gauging AD experience

2006-01-18 Thread joe
I would say focusing on the design of big directories is pigeon-holing a little too much. There are only so many big directories that need to be designed. I personally find much more fun in diagnosing good directories that have gone bad than trying to design them. I design if I have to but

RE: [ActiveDir] Multiple Password Policies

2006-01-18 Thread joe
Title: Unresolved SIDs in ACL Custom password filters can be extremely troublesome. I know ~Eric has mentioned having to deal with several issues that came down to custom filters after digging through debug dumps. They are tied in at a very tender spot of the DCs and the slightest problems

Re: [ActiveDir] LDAP and Global Catalog

2006-01-18 Thread Ravi Dogra
Please explain... Wht abt port 389 and 636. and GC at 3268. i m a bit confused here -- RD List info : http://www.activedir.org/List.aspx List FAQ: http://www.activedir.org/ListFAQ.aspx List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

RE: [ActiveDir] ADPrep Version Questions

2006-01-18 Thread joe
Yes. From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Noah EigerSent: Wednesday, January 18, 2006 11:56 AMTo: ActiveDir@mail.activedir.orgSubject: RE: [ActiveDir] ADPrep Version Questions Oh just what I need: more of those number-things to confuse me ;-) But seriously

RE: [ActiveDir] Unresolved SIDs in ACL

2006-01-18 Thread joe
Title: Unresolved SIDs in ACL It sure as heck shouldn't allow you to write an invalid SID to the ACL though... The interface should kick back an error of that name can't be resolved and not set anything. The last time I looked the stuff you could use from _vbscript_ didn't let you see SIDS,

RE: [ActiveDir] AD computer accounts being removed

2006-01-18 Thread Brian Desmond
Title: Message Dozen other reasons to run it. Not running sysprep is just a bad idea. Thanks, Brian Desmond [EMAIL PROTECTED] c - 312.731.3132 From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of joe Sent: Wednesday, January 18, 2006 8:11 PM To:

Re: [ActiveDir] Migrate domain to separate forest

2006-01-18 Thread Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP]
As a newsgrouper/listserver person who gets massive amounts of OOO...can I respectfully say that has to be the stupidest reason for network design in my personal opinion. The amount of social engineering data I can get from OOO's that I on the Internet have no business having at least set

RE: [ActiveDir] ADPrep Version Questions

2006-01-18 Thread joe
LOL. It isn't a decimal number though... It is a series of variable length decimal numbers separated by the period character... Sort of like an OID 1.2.840.113556.1.4.7000.102.7038 Versioning is a lost art I think though. I am big on xx.yy.zz. xx.=major, yy=minor, zz=really minor,

RE: [ActiveDir] AD computer accounts being removed

2006-01-18 Thread joe
I would like to see the details of what the issues are. Windows IT Pro mag is a nice mag and all, but there is no real technical review of the articles, you can say about anything you want to and I have seen several examples. Ditto for Redmond Mag and SearchWindows*, etc. I don't think the

RE: [ActiveDir] AD computer accounts being removed

2006-01-18 Thread joe
Don't get me wrong though... Sysprep/newsid, follow the process. I am absolutely not telling people to image machines and deploy them without cleaning them up. If you have odd things happening and are not following the recommended processes, it is all on you and you get to take responsibility for

RE: [ActiveDir] AD DNS in Windows delegation to Novell DNS

2006-01-18 Thread David Adner
Unless Novell's changed what flavor of DNS/feature set they have since NetWare 5.1 (last time I ever saw Novell) it did not support dynamic updates. More specifically, it supported "dynamic updates" but only via a NetWare DHCP server. Also, at the time, the GUI for managing records didn't

RE: [ActiveDir] LDAP and Global Catalog

2006-01-18 Thread joe
It looked like you asked for the GC ports, those are 3268 and 3269. If you want the LDAP ports, those are 398 and 636. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Ravi Dogra Sent: Wednesday, January 18, 2006 8:36 PM To:

[ActiveDir] Possibly useful mod

2006-01-18 Thread joe
For those using character set 409 a possible useful addition to ADUC for them. Adds "Operating System Service Pack" to the searchable fields for computers in ADUC, also allows you to select the column to display. adfind -config -f "attributedisplaynames=operatingSystemVersion,Operating

RE: [ActiveDir] LDAP and Global Catalog

2006-01-18 Thread Brian Desmond
389 is the standard LDAP port. 636 is LDAPS - LDAP Over SSL it's comparable to 80 and 443 ... one is unecrypted and one isn't. As far as the GC port, this is LDAP too, but, it's only listening on domain controllers which are global catalogs in your forest. The global catalog holds a partial

RE: [ActiveDir] AD computer accounts being removed

2006-01-18 Thread joe
And further, I am not trying to say I am always right. Quite the contrary, fully 50% of what I say is flat out incorrect, made up, or complete opinion. Your job is to try to figure out what is and isn't in that 50%. Preferably prior to changing your environment based on something I said. :o) Or

RE: [ActiveDir] AD computer accounts being removed

2006-01-18 Thread joe
Title: Message Yep sorry, didn't intend to say it wasn't a good idea. At some point the list will catch up and my post that says that will show up. :) From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Brian DesmondSent: Wednesday, January 18, 2006 8:39 PMTo:

RE: [ActiveDir] AD computer accounts being removed

2006-01-18 Thread Brian Desmond
Title: Message We have roughly 650 unique nightmare LANs here. Ive seem some interesting things. Have a folder full of screenshots and JPEGs from site visits to prove it. Thanks, Brian Desmond [EMAIL PROTECTED] c - 312.731.3132 From: [EMAIL PROTECTED]

Re: [ActiveDir] Move AD from one SBS Server to another?

2006-01-18 Thread Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP]
Where did I miss this one? To make an eval of SBS into a real box you put SBS retail over the top let it run and voila [and hit that person for hacking up a box] www.sbsmigration.com is a package of information/how to/scripts but mostly support. If you've never done this AD glue suck out

Re: [ActiveDir] Move AD from one SBS Server to another?

2006-01-18 Thread Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP]
I don't know if I made it clear enough but in version one ...the domain name is the same as the original box, the computer name, etc. The worksations won't freak. Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] wrote: Where did I miss this one? To make an eval of SBS into a real box you put

Re: [ActiveDir] Move AD from one SBS Server to another?

2006-01-18 Thread Matt Johnson
One way to do this is use Jeff Middleton's Swing Migration to accomplish this. I have done this many times with great success. http://www.sbsmigration.com/ The essentials are below. There is more to this process but it is only an overview. Plan on about 8 hours or more the first time you do it

[ActiveDir] Changing Employee ID from workstation

2006-01-18 Thread Marko Inkinen
Sähköpostiosoitteeni muuttuu 31.12.2005, käyttäjätunnusosa pysyy entisenä, uusi toimialuetunnus on PKSSK.FI. ([EMAIL PROTECTED]).---BeginMessage--- Hello list, I've been using vbs-script for some time already to add an Employee ID manually through ADUC, but the problem is that I always have