[ActiveDir] Delete only one object in the Tombstone.

2006-05-22 Thread TIROA YANN
Hello, I'd like to know if it is possible to delete *only one* object in the tombstone instead of purging all the objects ? Thanks, Yann

RE: [ActiveDir] Delete only one object in the Tombstone.

2006-05-22 Thread Ulf B. Simon-Weidner
Hello Tiroa, it is not possible to purge Tombstones, no matter if one or all. For all you'd be able to modify tombstone lifetime and the system time, however I strongly doubt this would be supported by MS (tombstone-lifetime is supported, modifying systemtime to enforce garbage collection

[ActiveDir] Error dialog while modifying a mail enabled group (DL) with delegated account

2006-05-22 Thread David Cliffe
Hi, In an environment running Exchnage 2003 SP1 under Windows 2003 SP1...I've delegated WP (write property) on the member attribute of a mail-enabled distribution list to a specific user. That user is nowable to modify the members of the group via ADUC (the change does get applied), but

Re: [ActiveDir] Error dialog while modifying a mail enabled group (DL) with delegated account

2006-05-22 Thread Al Mulnick
Nothing specific, but I think you can say that the Exchange-enhanced ADUC is trying to do something it doesn't need to do. You have a better answer which is to give the user a different tool. Trying to remember if the Outlook tools allow you to manage the groups (I believe they will if you have

RE: [ActiveDir] Error dialog while modifying a mail enabled group (DL) with delegated account

2006-05-22 Thread Presley, Steven
Outlook does indeed let you manage groups if, in ADUC, you tick the check box "Manager can update membership list" and you define a manager of the list (on the "Managed By" tab). From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Al MulnickSent: Monday, May 22, 2006

RE: [ActiveDir] Error dialog while modifying a mail enabled group (DL) with delegated account

2006-05-22 Thread joe
The Exchange GUIs (and many MSFT GUIs) are traditionally bad with this kind of stuff.The GUIs will suprisingly often require more permissions than you really need to do things because they aren't necessarilly doing the work correctly. On the flip side MSFT likes to try and enforce security

RE: [ActiveDir] Error dialog while modifying a mail enabled group (DL) with delegated account

2006-05-22 Thread David Cliffe
Most likely I'll use that "Manager can update" attribute and have him do this via Outlook. The end user previously had ADUC for this when permissions werealso 'abit heavy'(!), so I didn't even have that in mind at first, and then of course I got curious about the errors... Thanks for

[ActiveDir] [OT] Service ChangeConf

2006-05-22 Thread Bernier, Brandon \(.\)
Title: [OT] Service ChangeConf Is there another way to delegate the startup type of a service besides using CC (ChangeConf), this would be fine but it also gives whomever has access to change the service context to localsystem. -Brandon

RE: [ActiveDir] Error dialog while modifying a mail enabled group (DL) with delegated account

2006-05-22 Thread David Cliffe
Thanks. I suspectedthiswhen both DSMODand ADMODmodified the object without error during testing. We'd rather go with the principal of least privilege! From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of joeSent: Monday, May 22, 2006 2:35 PMTo:

RE: [ActiveDir] [OT] Service ChangeConf

2006-05-22 Thread joe
Title: [OT] Service ChangeConf I don't believe so, at least not through the SCuM, it isn't that granular. You would need to delegate the actual registry value for startup and allow the "admin" to get to that value to tweak it manually. -- O'Reilly Active Directory Third Edition -

RE : [ActiveDir] Delete only one object in the Tom bstone.

2006-05-22 Thread TIROA YANN
Hello Ulf, Thank you very much for your answer and have a nice day. Best Regards, Yann De: [EMAIL PROTECTED] de la part de Ulf B. Simon-Weidner Date: lun. 22/05/2006 14:34 À: ActiveDir@mail.activedir.org Objet : RE: [ActiveDir] Delete only one object in the

RE: [ActiveDir] Delete only one object in the Tombstone.

2006-05-22 Thread Ulf B. Simon-Weidner
You're welcome, and have a nice day too! Gruesse - Sincerely, Ulf B. Simon-Weidner Profile Publications: blocked::http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F 2F1214C811D http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F2F1214C811 D Weblog:

[ActiveDir] IIS 6

2006-05-22 Thread Za Vue
I have a web server running IIS6 hosting 3 websites-using host header. How can I access the individual URL using IP? -Z.V. List info : http://www.activedir.org/List.aspx List FAQ: http://www.activedir.org/ListFAQ.aspx List archive:

RE: [ActiveDir] IIS 6

2006-05-22 Thread Ken Schaefer
: -Original Message- : From: [EMAIL PROTECTED] [mailto:ActiveDir- : [EMAIL PROTECTED] On Behalf Of Za Vue : Sent: Tuesday, 23 May 2006 10:54 AM : To: ActiveDir@mail.activedir.org : Subject: [ActiveDir] IIS 6 : : I have a web server running IIS6 hosting 3 websites-using host

Re: [ActiveDir] IIS 6

2006-05-22 Thread Za Vue
What if all 3 websites uses the same name, index,html? -Z.V. Ken Schaefer wrote: : -Original Message- : From: [EMAIL PROTECTED] [mailto:ActiveDir- : [EMAIL PROTECTED] On Behalf Of Za Vue : Sent: Tuesday, 23 May 2006 10:54 AM : To: ActiveDir@mail.activedir.org : Subject:

Re: [ActiveDir] IIS 6

2006-05-22 Thread Za Vue
Ignore... I figured it out. Z.V Za Vue wrote: What if all 3 websites uses the same name, index,html? -Z.V. Ken Schaefer wrote: : -Original Message- : From: [EMAIL PROTECTED] [mailto:ActiveDir- : [EMAIL PROTECTED] On Behalf Of Za Vue : Sent: Tuesday, 23 May 2006 10:54 AM : To:

RE: [ActiveDir] IIS 6

2006-05-22 Thread Brian Desmond
A hosts file does the trick. Thanks, Brian Desmond [EMAIL PROTECTED] c - 312.731.3132 -Original Message- From: [EMAIL PROTECTED] [mailto:ActiveDir- [EMAIL PROTECTED] On Behalf Of Za Vue Sent: Monday, May 22, 2006 8:54 PM To: ActiveDir@mail.activedir.org Subject: [ActiveDir]

RE: [ActiveDir] OldCmp question

2006-05-22 Thread joe
I wouldn't be adverse to seeing at least adfind and admod in the support or resource kit tools. :) -- O'Reilly Active Directory Third Edition - http://www.joeware.net/win/ad3e.htm -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Ulf B. Simon-Weidner

RE: [ActiveDir] [OT] RAID 5 Best Practice

2006-05-22 Thread joe
There is quite a bit of docs out there on designing good disk subsystems for Exchange. It comes down to how many IOPS are needed. If your design isn't around that, you will probably end up with issues. -- O'Reilly Active Directory Third Edition - http://www.joeware.net/win/ad3e.htm

RE: [ActiveDir] [OT] RAID 5 Best Practice

2006-05-22 Thread joe
Access is crap to use for a multiuser app. Don't discount the fact that the perf could be simply related to that. -- O'Reilly Active Directory Third Edition - http://www.joeware.net/win/ad3e.htm _ From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Dave Wade Sent:

RE: [ActiveDir] [OT] RAID 5 Best Practice

2006-05-22 Thread joe
How will the remote site users be using the local DC? Will Exchange be local? Anything besides domain function on the DC? If no to both of those items, a single RAID 1 will _probably_ be ok but that is shooting from the hip knowing nothing about your environment or your directory soYMMV. As

RE: [ActiveDir] [OT] RAID 5 Best Practice

2006-05-22 Thread joe
This is a dart thrown against a wall. Use it for a starting point but make sure you verify it makes sense for your environment. I have been in environments where that recommendation is actually high and others where it is woefully low. Again with the Eric comments, test test test and verify

RE: [ActiveDir] OT: Disk Capacity

2006-05-22 Thread joe
What are you looking for? Redundancy, speed, pure capacity? If you are just looking for a place to stick all of these images and you want fast access to them and redundancy isn't important (i.e. your daily backups are good enough) you could go with a stripe set. If you need the redundancy

RE: [ActiveDir] [Exchange] Full Mailbox Directory Name holds wrong Administrative Group name

2006-05-22 Thread joe
Yep I agree with Steven here. If you really feel you need to change this, stop feeling that way. ;o) It can impact mail delivery when someone tries to respond to a message as well as calendar entry ownership, etc. If you ABSOLUTELY must change the legacyExchangeDN, then search the

RE: [ActiveDir] Search AD for groups that have specific rights

2006-05-22 Thread joe
Yep, this is a PITA in Windows. It is why you should have really good process and standards around ACLing. Thing is most people don't think about it until after they are in trouble. Take a look at the script at http://rallenhome.com/books/ad3e/source/ch_26_list_aces.vbs.txt, it shows you

RE: [ActiveDir] How to identify a users current site?

2006-05-22 Thread joe
I agree with Al, the solution is in the wireless hardware for this, not in AD. -- O'Reilly Active Directory Third Edition - http://www.joeware.net/win/ad3e.htm From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Al MulnickSent: Friday, May 19, 2006 8:33 AMTo:

RE: [ActiveDir] [OT] RAID 5 Best Practice

2006-05-22 Thread Jef Kazimer
Speaking of Exchange... Any good resources for Exchange info?(IE real world lessons, etc) I just got told today that we are going to be leaving a company we just bought on Exchange instead of migrating them to lotus notes (Talk about dodging a bullet). Sadly I have not done Exchange work since

RE: [ActiveDir] Group audit

2006-05-22 Thread joe
Title: Message I would set the output up for csv output (see -csv) which will make things easier to parse out. Once parsed you should be able to drive the modifications pretty easily. -- O'Reilly Active Directory Third Edition - http://www.joeware.net/win/ad3e.htm From: [EMAIL

RE: [ActiveDir][OT] DNS on a DC or NOT

2006-05-22 Thread joe
Does the application dictate what the directory can do? Or should the directory dictate what the application does? But Exchange isn't the only app for the directory... Exchange is generally leveraging the NOS directory for E2K+ deployments, now if you got o a resource forest for

RE: [ActiveDir] [OT] DNS on a DC or NOT

2006-05-22 Thread joe
I saw the Wizard and got a heart and a can of oil. -- O'Reilly Active Directory Third Edition - http://www.joeware.net/win/ad3e.htm From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Al MulnickSent: Thursday, May 18, 2006 9:02 PMTo: ActiveDir@mail.activedir.orgSubject: Re:

RE: [ActiveDir] [OT] RAID 5 Best Practice

2006-05-22 Thread joe
As someone else mentioned, for the storage aspects of Exchange, look at the HP storage docs, I keep hearing good things about them. In general go to every link on the Exchange site and read the white papers and docs. For AD itself, I tend to lean towards isolating DCs for Exchange into

RE: [ActiveDir] I try to execute applications in a script of a GPO but close after a few seconds

2006-05-22 Thread joe
You need a GPO expert here but it sounds like the GPO processing is finishing up and it is closing out all of the outstanding processes it spawned. -- O'Reilly Active Directory Third Edition - http://www.joeware.net/win/ad3e.htm From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On

RE: [ActiveDir] Removing ADAM from configuration set

2006-05-22 Thread joe
Title: Removing ADAM from configuration set Define "it doesn't work". Also go chat with Snyder, he had a fun little tool called Whack-A-DC that was used for the lifeboats that you may be able to modify for this. But yes, the ADAM tools aren't all polished yet, and may not be polished

RE: [ActiveDir] User Object Attribute mismatches on different DC's

2006-05-22 Thread joe
That is a trifle scary... Rerun that and see if it has changed, also change your query to use objectcategory=person instead of objectclass=user unless you have indexed objectclass, you will find it runs faster that way. If the counts are still off like that I would start looking for the specific

RE: [ActiveDir] [OT] RAID 5 Best Practice

2006-05-22 Thread Brian Desmond
Yeah if you can get through the boatloads of obnoxious registration logon crap on the HP site, there are Excel sheets for Exchange and sharepoint for figuring the hardware you need (storage and servers). Works great. Thanks, Brian Desmond [EMAIL PROTECTED] c - 312.731.3132

RE: [ActiveDir] OldCmp question

2006-05-22 Thread Ulf B. Simon-Weidner
Big fat ditto - and even better in the support tools. Gruesse - Sincerely, Ulf B. Simon-Weidner Profile Publications: http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F2F1214C811 D Weblog: http://msmvps.org/UlfBSimonWeidner Website: http://www.windowsserverfaq.org