RE: [ActiveDir] Selective auth, allowed to auth right, group policy

2006-11-27 Thread Dean Wells
GP is unnecessary, simply add the extended right at a suitable OU (as you inferred) ... you'll need the advanced ACL editor dialog to do so ... look carefully, it's there. -- Dean Wells MSEtechnology t Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL

RE: [ActiveDir] Recreate BUILTIN\Incoming Forest Trust Builders

2006-08-17 Thread Dean Wells
root domain, re-read the same ACL when focused on a DC in a peer-root or child-domain ... note the claimed affiliation of the Administrators ACE. -- Dean Wells MSEtechnology t Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL PROTECTED] [mailto:ActiveDir

RE: [ActiveDir] ADFind Query

2006-08-15 Thread Dean Wells
. -- Dean Wells MSEtechnology Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL PROTECTED] [mailto:ActiveDir- [EMAIL PROTECTED] On Behalf Of Tony Murray Sent: Monday, August 14, 2006 8:24 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir

RE: [ActiveDir] ADFind Query

2006-08-15 Thread Dean Wells
I'll assume for the moment that you were able to get it from the web site, let me know if otherwise. -- Dean Wells MSEtechnology t Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL PROTECTED] [mailto:ActiveDir- [EMAIL PROTECTED] On Behalf Of WATSON

RE: [ActiveDir][OT]Dean's kick-a## article

2006-08-15 Thread Dean Wells
) ... uhhh, okey dokes :0/ -- Dean Wells MSEtechnology t Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL PROTECTED] [mailto:ActiveDir- [EMAIL PROTECTED] On Behalf Of Brett Shirley Sent: Tuesday, August 15, 2006 9:12 AM To: ActiveDir@mail.activedir.org

RE: [ActiveDir][OT]Dean's kick-a## article

2006-08-15 Thread Dean Wells
Inline ... -- Dean Wells MSEtechnology Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL PROTECTED] [mailto:ActiveDir- [EMAIL PROTECTED] On Behalf Of Brett Shirley Sent: Tuesday, August 15, 2006 11:31 AM To: ActiveDir@mail.activedir.org Cc: Send

RE: [ActiveDir] ADFind Query

2006-08-15 Thread Dean Wells
Most welcome, glad it's working out for you. -- Dean Wells MSEtechnology t Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL PROTECTED] [mailto:ActiveDir- [EMAIL PROTECTED] On Behalf Of WATSON, BEN Sent: Tuesday, August 15, 2006 12:48 PM

RE: [ActiveDir] Recreate BUILTIN\Incoming Forest Trust Builders

2006-08-14 Thread Dean Wells
was deleted, it may assist in understanding what's going on here? -- Dean Wells MSEtechnology t Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL PROTECTED] [mailto:ActiveDir- [EMAIL PROTECTED] On Behalf Of Han Valk Sent: Monday, August 14, 2006 3:45 AM

RE: [ActiveDir]

2006-08-14 Thread Dean Wells
Why thank you … but who said otherwise?  ;0) -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Matheesha Weerasinghe Sent: Monday, August 14, 2006 2:35 PM

RE: [ActiveDir][OT]Dean's kick-a## article

2006-08-14 Thread Dean Wells
Cheeky git my head, your stomach at least well have the plane to ourselves! :0) Best start working on that pilots license! -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED

RE: [ActiveDir] ADFind Query

2006-08-14 Thread Dean Wells
If not, though less efficient, dump them all and pipe it through find -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of joe Sent: Monday, August 14, 2006 5:53 PM

RE: [ActiveDir] ADFind Query

2006-08-14 Thread Dean Wells
Ok, finally managed to download the version on the site, it's up-to-date ... use that if interested. -- Dean Wells MSEtechnology t Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: Dean Wells [mailto:[EMAIL PROTECTED] Sent: Monday, August 14, 2006 8:12 PM

RE: [ActiveDir] Setting FFL=2 automatically when building first DC in forest

2006-08-04 Thread Dean Wells
Can you elaborate as to the NC-repl-locations update issue? -- Dean Wells MSEtechnology t Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL PROTECTED] [mailto:ActiveDir- [EMAIL PROTECTED] On Behalf Of Paul Williams Sent: Friday, August 04, 2006 3:29

RE: [ActiveDir] Setting FFL=2 automatically when building first DC in forest

2006-08-04 Thread Dean Wells
Resolved offline, a policy issue ... not a technical one. -- Dean Wells MSEtechnology t Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL PROTECTED] [mailto:ActiveDir- [EMAIL PROTECTED] On Behalf Of Dean Wells Sent: Friday, August 04, 2006 8:10 AM

RE: [ActiveDir] LDAP Ping

2006-08-04 Thread Dean Wells
response -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Bahta, Nathaniel V CTR USAF NASIC/SCNA Sent: Friday, August 04, 2006 8:54 AM To: ActiveDir

RE: [ActiveDir] Setting FFL=2 automatically when building first DC in forest

2006-08-03 Thread Dean Wells
it out). The result should be msDs-Behavior-Version=2 ; msDs-Behavior-Version=$REGISTRY=InstallForestBehaviorVersion HTH -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED

RE: [ActiveDir] Setting FFL=2 automatically when building first DC in forest

2006-08-03 Thread Dean Wells
wise, (i.e. when a new domain is created within an existing forest), we simply need to tell the forest func. level to seed itself with a value of 2 see my previous post for instructions on how to do that. -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com

RE: [ActiveDir] Remove Defunct domains..

2006-08-03 Thread Dean Wells
I’m gonna read between the lines a little and ask if you previously trusted these domains? -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of HBooGz Sent: Wednesday

RE: [ActiveDir] Setting FFL=2 automatically when building first DC in forest

2006-08-03 Thread Dean Wells
here would have likely stumbled across it before now). Re: your 2nd comment hahahaha, LAMO :0) PS for those not English or confused, sorry the explanation wouldnt work anyway! -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com

RE: [ActiveDir] Setting FFL=2 automatically when building first DC in forest

2006-08-03 Thread Dean Wells
Title: Setting FFL=2 automatically when building first DC in forest Nod, but sfkds sdkfk skdwpoe cdof slkap d dkds y dlsdk lspw dod sfd qwpw slla dsk ccdpow yours too. -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com From

RE: [ActiveDir] Setting FFL=2 automatically when building first DC in forest

2006-08-03 Thread Dean Wells
system (in this case, system-purposed attributes in AD) is beyond an unattend file's scope. -- Dean Wells MSEtechnology t Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL PROTECTED] [mailto:ActiveDir- [EMAIL PROTECTED] On Behalf Of Brian Desmond Sent

RE: [ActiveDir] Setting FFL=2 automatically when building first DC in forest

2006-08-03 Thread Dean Wells
a feature suggestion ... -- Dean Wells MSEtechnology t Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL PROTECTED] [mailto:ActiveDir- [EMAIL PROTECTED] On Behalf Of Brett Shirley Sent: Thursday, August 03, 2006 8:34 PM To: ActiveDir@mail.activedir.org

RE: [ActiveDir] Automating GC promotion during dcpromo

2006-08-02 Thread Dean Wells
forest 3. Copy that entry into the [DEFAULTADDLMACHINE] section 4. Run DCpromo Regards. Dean -- Dean Wells MSEtechnology t Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL PROTECTED] [mailto:ActiveDir- [EMAIL PROTECTED] On Behalf Of Tomasz Onyszko Sent

RE: [ActiveDir] Automating GC promotion during dcpromo

2006-08-02 Thread Dean Wells
I'm not following, if you're creating an answer file to feed DCpromo when building new DCs ... why can you not also supply a modified schema.ini that contains the changes per my earlier post? -- Dean Wells MSEtechnology t Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message

RE: [ActiveDir] DNS oddities?

2006-08-01 Thread Dean Wells
) -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Matheesha Weerasinghe Sent: Monday, July 31, 2006 7:10 PM To: ActiveDir@mail.activedir.org Subject: Re: [ActiveDir] DNS oddities

RE: [ActiveDir] DNS oddities?

2006-07-30 Thread Dean Wells
  -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Matheesha Weerasinghe Sent: Sunday, July 30, 2006 3:07 PM To: ActiveDir

RE: [ActiveDir] RootDSE requires admin privileges

2006-07-22 Thread Dean Wells
Windows or 3rd party firewall related?? -- Dean Wells MSEtechnology t Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL PROTECTED] [mailto:ActiveDir- [EMAIL PROTECTED] On Behalf Of Sakari Kouti Sent: Saturday, July 22, 2006 11:39 AM To: ActiveDir

RE: [ActiveDir] Where's that account being used?

2006-07-02 Thread Dean Wells
This thread appears to have been answered but I've enclosed the script for those interested, let me know if you experience issues receiving it ... (it may be too large per Tony's throttles). -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com -Original

RE: [ActiveDir] OT: Self grown AD webtool sample output - any takers in joint dev ?

2006-05-17 Thread Dean Wells
Title: OT: Self grown AD webtool sample output - any takers in joint dev? I'd be happy to take a look Freddy, I'm permanently on-site now so my joint dev. efforts would be sporadic at best but I would hope I'll have something of value to contribute. Nice work! --Dean WellsMSEtechnology*

RE: [ActiveDir] how to find DNS servers in a forest?

2006-05-17 Thread Dean Wells
Dump the msDs-masteredBy attribute of the forestDNSzones NC head to determine the DCs running 2K3 upon which MS' DNS is installed and is (or at least was) running. You can further qualify that list using WMI or SC.EXE or any means of remotely querying the installed services. This is quite

RE: [ActiveDir] how to find DNS servers in a forest?

2006-05-17 Thread Dean Wells \(MSETechnology\)
That was actually my original post ... but it was harder to identify the DN of the crossRef than that of the NC head (which is kinda easy ;0) and keeping the "query efficiency" mantra in mind,I preferred not to query period and thus changed my thinking and subsequently my post. In

RE: [ActiveDir] how to find DNS servers in a forest?

2006-05-17 Thread Dean Wells \(MSETechnology\)
hmmm ...interesting idea but since it must be scoped to a onelevel query at best, a subtree query at worst ... it consumes more resources than merely dumping a single property from the NC head (using a base scope). It may provide a more up-to-date state though ... I don't recollect if the

RE: [ActiveDir] DNS on a DC or NOT

2006-05-17 Thread Dean Wells
It's not the thread's topic per se... you inferred a criticism directed toward his "@work" children ;0) ... haha --Dean WellsMSEtechnology* Email: dwells@msetechnology.comhttp://msetechnology.com From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of joeSent:

RE: [ActiveDir] DNS on a DC or NOT

2006-05-17 Thread Dean Wells
on that one I'm afraid ... but suffice it to say that for me; I prefer app. NCs where possible. -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of joe Sent: Wednesday, May 17

RE: [ActiveDir] [OT] DNS on a DC or NOT

2006-05-17 Thread Dean Wells
LOL! -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of joe Sent: Wednesday, May 17, 2006 3:32 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] [OT] DNS

RE: [ActiveDir][OT] DNS on a DC or NOT

2006-05-17 Thread Dean Wells
Try again - http://www.peevish.co.uk/slang/m.htm- "Noun. Friend. E.g."Alright my old mucker." [1940s]" ... Neil or Mark or any of the other English folk will no doubt attest to its usage. --Dean WellsMSEtechnology* Email: dwells@msetechnology.comhttp://msetechnology.com From:

RE: [ActiveDir][OT] DNS on a DC or NOT

2006-05-17 Thread Dean Wells
That would imply I had a reason to ya pillock ... believe me, you'll know when I insult you ;0) --Dean WellsMSEtechnology* Email: dwells@msetechnology.comhttp://msetechnology.com From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of joeSent: Wednesday, May 17, 2006

RE: [ActiveDir] Image a DC?

2006-05-12 Thread Dean Wells
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of joeSent: Friday, May 12, 2006 5:33 PMTo: ActiveDir@mail.activedir.orgSubject: RE: [ActiveDir] Image a DC? From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of [EMAIL

RE: [ActiveDir] Image a DC?

2006-05-12 Thread Dean Wells
First and foremost --that's "Dean" and joe -- ya young whipper-snapper ;0) Secondly, fear not -- the content was merely "ground-breaking" :0) --Dean WellsMSEtechnology* Email: dwells@msetechnology.comhttp://msetechnology.com From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On

RE: [ActiveDir] Image a DC?

2006-05-12 Thread Dean Wells
Heh, made me laugh too ... and no, not remotely ... I only think you're being an ass when you actually are ;0) -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Brett

RE: [ActiveDir] ExtraColumns attribute

2006-04-20 Thread Dean Wells
Per my original repsonse and having just tested it, modifying the default does indeed have the desired effect. I'm uncertain as to why it's not working for you. Which displaySpecifier are you modifying? --Dean WellsMSEtechnology* Email: dwells@msetechnology.comhttp://msetechnology.com

RE: [ActiveDir] User Accounts

2006-04-19 Thread Dean Wells
Inline ... -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Ulf B. Simon-Weidner Sent: Wednesday, April 19, 2006 2:40 AM To: ActiveDir@mail.activedir.org Subject

RE: [ActiveDir] ExtraColumns attribute

2006-04-19 Thread Dean Wells
Try editing the extraColumns attribute on the default-Display object, adding the property of your choosing as follows- LDAP name,display name,default visibility,pixel width,0 - IIRC, this is reserved and must be 0 for now. ... highlighting the Saved Query in question and selecting

RE: [ActiveDir] ExtraColumns attribute

2006-04-19 Thread Dean Wells
OK, so the 1st trailing 0 says "don't show by default" ... which I assume is what you want on the default displaySpecifier. You may also find it useful to know that when these columns do appear, they have a habit of initially being 0 pixels wide so you have to go dragging columns widths

RE: [ActiveDir] User Accounts

2006-04-18 Thread Dean Wells
. -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Brett Shirley Sent: Tuesday, April 18, 2006 5:11 PM To: ActiveDir@mail.activedir.org Cc: Send - AD mailing list Subject

RE: [ActiveDir] User Accounts

2006-04-16 Thread Dean Wells
). -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Brett Shirley Sent: Sunday, April 16, 2006 8:47 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] User Accounts

RE: [ActiveDir] User Accounts

2006-04-15 Thread Dean Wells
Title: User Accounts That number isn't accurate I'm afraid. The underlying store used by AD supports a theoretical maximum of 4.2 billion rows (limited by the 32 bit DNT or distinguished name tag) within its lifetime, deleted objects (garbage collected or otherwise) do not return row

RE: [ActiveDir] User Accounts

2006-04-15 Thread Dean Wells
Title: User Accounts A long and unbelievably off-topic IM with Eric (and joe towards the end) re: this thread touched on some of ESE'slesser-known artifacts or behaviors ... thanks for the input Eric. Inline ... --Dean WellsMSEtechnology* Email:

RE: [ActiveDir] AD replication compression algorithms

2006-04-12 Thread Dean Wells
Title: AD replication compression algorithms  I've never thoroughly tested it having not encountered perf. issues with the now legacy MSZIP algorithm nor have I seen any published stats. from MS outlining tangible differences on shrink-wrapped hardware. I'd suggest running through a few

RE: [ActiveDir] AD replication compression algorithms

2006-04-12 Thread Dean Wells
Title: AD replication compression algorithms  Thanks for the URL ... --Dean WellsMSEtechnology* Email: dwells@msetechnology.comhttp://msetechnology.com From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of [EMAIL PROTECTED]Sent: Wednesday, April 12, 2006 9:49 AMTo:

RE: [ActiveDir] Deleting default-first-site-name site

2006-04-12 Thread Dean Wells
No, IIRC it defaults to the site of the DC from which the directory was sourced. -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Daniel Gilbert Sent: Wednesday

RE: [ActiveDir] OU's Structure

2006-04-12 Thread Dean Wells
The OU structure and depth does not directly influence logon time (AD hierarchy is in fact something of a simulation). Hierarchy can influence login performance only when nested sufficiently deeply and with a large number of linked GPOs at each or most of the superior OUs, a choice made by

RE: [ActiveDir] Deleting default-first-site-name site

2006-04-12 Thread Dean Wells
Title: RE: [ActiveDir] Deleting "default-first-site-name" site I think you must have missed the answer in the follow-up reply ... that response contained - paste No, IIRC it defaults to the site of the DC from which the directory was sourced. /paste ... let me know if that doesn't cover

RE: [ActiveDir] Disable site link bridging and DFS site costing

2006-04-06 Thread Dean Wells
Title: Disable site link bridging and DFS site costing  Thisswitch is used topermit automatic site link bridgingto be disabled without affectingDFS's ability to usethe legacy ISM to calculate the cost matrix. The change ismaintained on the NTDS Site Settings object and is effective only

RE: [ActiveDir] Disable site link bridging and DFS site costing

2006-04-06 Thread Dean Wells
Title: Disable site link bridging and DFS site costing  ... sorry, got carried away and forgot to address your more direct questions - Is this a forest wide or site wide change? I believe it prevents the affected ISTGfrom creating connection objects on its bridgeheads sourced from DCs in

RE: [ActiveDir][OT] Documentation regarding ADLB

2006-04-06 Thread Dean Wells
You assume too much :o) -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of joe Sent: Thursday, April 06, 2006 10:37 PM To: ActiveDir@mail.activedir.org Subject: RE

RE: [ActiveDir] Install from Media

2006-03-14 Thread Dean Wells
A logical question, but happily no! --Dean WellsMSEtechnology* Email: dwells@msetechnology.comhttp://msetechnology.com From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Amy HunterSent: Tuesday, March 14, 2006 8:08 AMTo: ActiveDir@mail.activedir.orgSubject:

RE: [ActiveDir] repadmin info oddity

2006-02-22 Thread Dean Wells
}}. The query below exploits that feature permitting repadmin's GUID format to be supplied directly. C:\adfind -config -binenc -f (retiredReplDSASignatures=*{{GUID:6cc4a8e0-2019-4e4f-81cd-f35926de38a3}}*) -dn -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com -Original

RE: [ActiveDir] repadmin info oddity

2006-02-22 Thread Dean Wells
there. -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Scott Klassen Sent: Wednesday, February 22, 2006 9:55 AM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir

RE: [ActiveDir] repadmin info oddity

2006-02-22 Thread Dean Wells
Inline ... -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Brett Shirley Sent: Wednesday, February 22, 2006 2:35 AM To: ActiveDir@mail.activedir.org Cc: Send - AD

RE: [ActiveDir] repadmin info oddity

2006-02-21 Thread Dean Wells
words, not mine) and professes his innocence :0). -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M. Sent: Tuesday, February 21, 2006 7:44 AM To: ActiveDir

RE: [ActiveDir] repadmin info oddity

2006-02-21 Thread Dean Wells
retiredReplDSASignatures=*\E0\A8\C4\6C\19\20\4F\4E\81\CD\F3\59\26\DE\38\A3* retiredReplDSASignatures Fingers crossed that Joe will have a hidden switch to do the decoding for you, until then, this is it I'm afraid. -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message

RE: [ActiveDir] repadmin info oddity

2006-02-20 Thread Dean Wells
whose invocation ID has changed due to a restore operation or the removal and -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of SCOTT KLASSEN Sent: Monday, February 20, 2006 9

RE: [ActiveDir] repadmin info oddity

2006-02-20 Thread Dean Wells
(wherever the heck that is). -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of David Adner Sent: Monday, February 20, 2006 10:43 PM To: ActiveDir@mail.activedir.org Subject: RE

RE: [ActiveDir] repadmin info oddity

2006-02-20 Thread Dean Wells
whose invocation ID has changed due to a restore operation or the removal and subsequent re-addition of a NDNC (again, a normal occurrence), -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED

RE: [ActiveDir] ability to create container objects not in ADUC

2006-02-16 Thread Dean Wells
If memory serves, it was a choice ... not a technical reason - Locate the schema definition for the structural class in question within the schema NC using ADSIEDIT.MSC or equiv. (in this case, a Container), bring up its properties and set DefaultHidingValue to FALSE. -- Dean Wells MSEtechnology

RE: [ActiveDir] Deleted OU issue

2006-02-16 Thread Dean Wells
Title: [ActiveDir] Deleted OU issue ... but couldn't he loose data (new objects or attribute changes) that did not also replicate to the other DC, by "overwriting the database? Other unrelated changes? Certainly ... assuming (as Guido says) replication hasn't occurred yet. --Dean

RE: [ActiveDir] Script to transfer FSMO roles.

2006-02-14 Thread Dean Wells
Inline ... -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL PROTECTED] Sent: Tuesday, February 14, 2006 7:57 PM To: ActiveDir@mail.activedir.org Cc: Send - AD mailing list Subject: RE: [ActiveDir] Script to transfer FSMO

RE: [ActiveDir] Script to transfer FSMO roles.

2006-02-14 Thread Dean Wells
In hindsight, the same is true of the PDC regardless of whether it is seized or transferred so that's somewhat moot ... my scotch = my bad :O) -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL

RE: [ActiveDir] Script to transfer FSMO roles.

2006-02-13 Thread Dean Wells
Title: [ActiveDir] Script to transfer FSMO roles. A few thoughts -- I'm not entirely adverse to the idea of throwing commands at NTDSUTIL and seizing roles (and relying upon the mandatory pre-emptive transfer attempt) but I prefer not to perform such actions when the capability to trap

RE: [ActiveDir] Script to transfer FSMO roles.

2006-02-13 Thread Dean Wells
. --Dean WellsMSEtechnology* Email: dwells@msetechnology.comhttp://msetechnology.com From: Dean Wells [mailto:[EMAIL PROTECTED] Sent: Monday, February 13, 2006 9:06 AMTo: Send - AD mailing list ([EMAIL PROTECTED])Subject: RE: [ActiveDir] Script to transfer FSMO roles. A few thoughts

RE: [ActiveDir] Script to transfer FSMO roles.

2006-02-13 Thread Dean Wells
Title: [ActiveDir] Script to transfer FSMO roles. Can you elaborate on what you mean by "replication threshold" (or fresh hold if you prefer ... gotta love spell checkers :o)? --Dean WellsMSEtechnology* Email: dwells@msetechnology.comhttp://msetechnology.com From: [EMAIL PROTECTED]

RE: [ActiveDir] Script to transfer FSMO roles.

2006-02-13 Thread Dean Wells
Title: [ActiveDir] Script to transfer FSMO roles. Not that's springing to mind. Some related thoughts - * inbound replication is single threaded (i.e. no concurrency limitation is required) * in 2k, 15 mins. represented the anticipated end-to-end replication within a site * the KCC in

RE: [ActiveDir] Script to transfer FSMO roles.

2006-02-13 Thread Dean Wells
Title: [ActiveDir] Script to transfer FSMO roles. Great, sounds like you're good to go! Re: W2K3 Standard vs. Enterprise: there's a mass of information concerning the feature differences and supported hardware, the following is as good a place as any to start -

RE: [ActiveDir] Merging Multiple AD Groups

2006-02-10 Thread Dean Wells
I haven't directly investigated the issues you're having so a solution may well be available as opposed to the workaround outlined below - for /f "tokens=*" %m in ('dsget group "CN=domain admins,cn=users,dc=mset,dc=local" -members') do @dsget group "cn=other admins,dc=mset,dc=local"

RE: [ActiveDir] DSQUERY filter for space character only

2006-02-08 Thread Dean Wells
Interesting that'user' is not a valid objectcategory. When I had ADUC create the query for me, it automatically generated the filter that included objectCategory=user. New Query / Custom Search / then Display Name Is Exactly (space character). The attribute "objectCategory" is of

RE: [ActiveDir] OT: Any Programming courses for Systems Administrators?

2006-02-08 Thread Dean Wells
] On Behalf Of Brian DesmondSent: Wednesday, February 08, 2006 2:23 PMTo: ActiveDir@mail.activedir.orgSubject: RE: [ActiveDir] OT: Any Programming courses for Systems Administrators? Dean Wells @ www.msetechnology.com does AD training and from what I hear on this list its top notch. Thanks,Brian

RE: [ActiveDir] OT: Any Programming courses for Systems Administrators?

2006-02-08 Thread Dean Wells
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Brian DesmondSent: Wednesday, February 08, 2006 2:23 PMTo: ActiveDir@mail.activedir.orgSubject: RE: [ActiveDir] OT: Any Programming courses for Systems Administrators? Dean Wells @ www.msetechnology.com does AD training

RE: [ActiveDir] Schema Extension

2006-02-08 Thread Dean Wells
I really don't agree in the confined scenario Ulf described. Can you explain your point further or is it merely an issue of Microsoft supporting it? -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL

RE: [ActiveDir] DSQUERY filter for space character only

2006-02-07 Thread Dean Wells
IIRC, the query processor barks at the use of values comprised entirely of spaces. As such, use the following - dsquery * dc=mset,dc=local -scope subtree -filter "((objectcategory=user)(displayname=\20)) ... or for a more creative approach - dsquery * dc=mset,dc=local -scope subtree

RE: [ActiveDir] Problem in assigning permissions to the user in parent domain over the shared folder in child domain

2006-02-06 Thread Dean Wells
Directory Sites and Services). -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of V Lakshmi Sent: Monday, February 06, 2006 2:47 AM To: 'Send - AD mailing list'; [EMAIL PROTECTED

RE: [ActiveDir] DNS Restart

2006-02-06 Thread Dean Wells
... since we're getting silly - net stop dns net start dns || echo Well bugger, it didn't work :-[ --Dean WellsMSEtechnology* Email: dwells@msetechnology.comhttp://msetechnology.com From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Ulf B. Simon-WeidnerSent: Monday,

RE: [ActiveDir] Delegating attribute in property Set (Personal Information set)

2006-02-06 Thread Dean Wells
Title: Delegating attribute in property Set (Personal Information set) Probably a DSSEC.DAT related issue ... google the filename for instructions. --Dean WellsMSEtechnology* Email: dwells@msetechnology.comhttp://msetechnology.com From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf

RE: [ActiveDir] Getting better control over DHCP

2006-02-04 Thread Dean Wells
not seen IPsec implemented to secure initial address leases though I can envisage ways in which that could be achieved. -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Brian Puhl

RE: [ActiveDir] Problem in assigning permissions to the user in parent domain over the shared folder in child domain

2006-02-03 Thread Dean Wells
Is replication functioning? -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of V Lakshmi Sent: Friday, February 03, 2006 12:44 AM To: [EMAIL PROTECTED]; ActiveDir

RE: [ActiveDir] Script to determine a machine's site

2006-02-03 Thread Dean Wells
Title: Script to determine a machine's site Does this suffice - nltest /dsgetsite /server:domain FQDN Haven't tried anything of this kind myself under Wimpy so I'm uncertain of its suitability. --Dean WellsMSEtechnology* Email: dwells@msetechnology.comhttp://msetechnology.com From:

RE: [ActiveDir] Problem in assigning permissions to the user in parent domain over the shared folder in child domain

2006-02-03 Thread Dean Wells
(based on minor sanitizing-edits only). If you're interested, let me know and I'll provide you with availability and rates ... they're cost effective at a minimum of ~4+ students. Kindest regards. Deano -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com -Original

RE: [ActiveDir] Script to determine a machine's site

2006-02-03 Thread Dean Wells
Title: Script to determine a machine's site Indeed it does, that's what I ran it on ... --Dean WellsMSEtechnology* Email: dwells@msetechnology.comhttp://msetechnology.com From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Grillenmeier, GuidoSent: Friday, February 03, 2006 4:32

RE: [ActiveDir] Script to determine a machine's site

2006-02-03 Thread Dean Wells
Title: Script to determine a machine's site ... to be clear, it does require that some level of credential first be established but, nonetheless, it functions. --Dean WellsMSEtechnology* Email: dwells@msetechnology.comhttp://msetechnology.com From: [EMAIL PROTECTED] [mailto:[EMAIL

RE: [ActiveDir] Script to determine a machine's site

2006-02-03 Thread Dean Wells
Title: Script to determine a machine's site Per my previous post, I'd forced some creds. down the target DCs throat prior to executing NLTEST ... and, no, my local creds. do not match those of the virtual domain in question ... 'cause that would be all kinds ofjust plain wrong :o) --Dean

RE: [ActiveDir] Script to determine a machine's site

2006-02-03 Thread Dean Wells
Title: Script to determine a machine's site Nod, have since learned that ... my apologies. I'm guessing there's a mean of achieving that with nltest (or perhaps a few iterations and some output parsing). --Dean WellsMSEtechnology* Email: dwells@msetechnology.comhttp://msetechnology.com

RE: [ActiveDir] Getting better control over DHCP

2006-02-03 Thread Dean Wells
Microsoft uses 802.1x auth. I believe ... as do many. -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] Sent: Friday, February

RE: [ActiveDir] ADUC updates - Was Expired Accounts

2006-01-13 Thread Dean Wells
Title: RE: [ActiveDir] ADUC updates - Was Expired Accounts Note that the available columns can be extended via Display Specifiers (i.e. a distributed configuration). --Dean WellsMSEtechnology* Email: dwells@msetechnology.comhttp://msetechnology.com From: [EMAIL PROTECTED] [mailto:[EMAIL

RE: [ActiveDir] Expired Accounts

2006-01-12 Thread Dean Wells
No, expired accounts are calculated on-the-fly based on their expiry date and the DC's date. AD UC doesn't treat that as disabled ... 'cause it is isn't ;o). -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL PROTECTED

RE: [ActiveDir] Strange deleted object issue

2006-01-12 Thread Dean Wells
Please note that a handful of objectClasses are not moved to the Deleted Objects container. Although supplying the Deleted Objects dn as the base is a general rule of thumb worth following, be aware that there will be instances where it will fail to identify every deleted object. --Dean

RE: [ActiveDir] FSMO Role Transfer GUI

2005-12-17 Thread Dean Wells
Title: FSMO Role Transfer GUI I used to use LDIFDE (I imagine that still works) ... oops, typo'd it again ... what I meant to say was "I use toADmod.exe" (he's sensitive you know ;o) --Dean WellsMSEtechnology* Email: dwells@msetechnology.comhttp://msetechnology.com From: [EMAIL

RE: [ActiveDir] Reducing number of Global Catalogs

2005-12-14 Thread Dean Wells
not alone and that someone else gets to feel his pain in an org. of similar size and in the same industry ;o) -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of joe Sent: Wednesday

RE: [ActiveDir] dsHeuristics and list object access mode

2005-12-14 Thread Dean Wells
To clarify, note the syntax of dsHeuristics(Unicode string) ... it requires that you enter a sequence of characters (bytes not bits ... nor the decimal representation of those bits), e.g. - 01000. --Dean WellsMSEtechnology* Email: dwells@msetechnology.comhttp://msetechnology.com

RE: [ActiveDir] Reducing number of Global Catalogs

2005-12-14 Thread Dean Wells
How so? --Dean WellsMSEtechnology* Email: dwells@msetechnology.comhttp://msetechnology.com From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of [EMAIL PROTECTED]Sent: Wednesday, December 14, 2005 8:15 AMTo: ActiveDir@mail.activedir.orgSubject: Re: [ActiveDir] Reducing number of

RE: [ActiveDir] Ntds.dit file corruption

2005-12-06 Thread Dean Wells
Great topic and, IMO, great answer ... I've only a few comments in addition to Joe's reply (inline). --Dean WellsMSEtechnology* Email: dwells@msetechnology.comhttp://msetechnology.com From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of joeSent: Tuesday, December 06, 2005 8:56

  1   2   3   4   5   >