RE: [ActiveDir] Overlapping AD Subnet Boundaries

2007-01-26 Thread Thommes, Michael M.
An AD client will try to associate itself with the site that it is most specific for its IP. Mike Thommes From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Brian Cline Sent: Friday, January 26, 2007 3:20 PM To: ActiveDir@mail.activedir.org

[ActiveDir] OT: maintaining creation date when copying directories?

2007-01-25 Thread Thommes, Michael M.
What move/copy tools can be used to copy directories/files to another location and still retain the creation date value? Robocopy seems to keep creation date on files but directories are given the current date. Am I missing a switch in Robocopy to do this? A backup/restore operation (with

RE: [ActiveDir] OT: maintaining creation date when copying directories?

2007-01-25 Thread Thommes, Michael M.
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M. Sent: Donnerstag, 25. Januar 2007 13:10 To: ActiveDir@mail.activedir.org Subject: [ActiveDir] OT: maintaining creation date when copying directories? What move/copy tools can be used to copy directories/files

RE: [ActiveDir] Kerberos Question

2007-01-25 Thread Thommes, Michael M.
I think you are seeing your Kerberos tickets start to reach their expiration time. The kerbtray icon will go from green to red. I think the last 5 or 15 minutes the default configuration will also issue an audible (and very distinctive) sound. The tickets will renew automatically (and the icon

RE: [ActiveDir] OT: maintaining creation date when copying directories?

2007-01-25 Thread Thommes, Michael M.
/UlfBSimonWeidner blocked::http://msmvps.org/UlfBSimonWeidner Website: http://www.windowsserverfaq.org blocked::http://www.windowsserverfaq.org/ From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M. Sent: Donnerstag, 25. Januar 2007 14:18 To: ActiveDir@mail.activedir.org

RE: [ActiveDir] PHP Module for Windows

2007-01-24 Thread Thommes, Michael M.
Is this what you are looking for? http://www.php.net/downloads.phpI have not used it, however, and can't speak to how well it works but it seems to come from the right place. ;) Mike Thommes From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf

[ActiveDir] moving server local groups to AD?

2007-01-24 Thread Thommes, Michael M.
(I sure hope this doesn't sound like too dumb a question!) We have a server where local security groups were created for local file access. The files on this server are going to be moved to a file server cluster. Can ADMT v3 migrate these security groups up to the AD structure with the hopes of

[ActiveDir] OT: Apache LDAP authentication oddity

2007-01-19 Thread Thommes, Michael M.
We have an application that is using an Apache server to do LDAP authentications against our active directory. (Yeah, I know; if only I were king! LOL!) The application developer tells me that if he tries doing an auth against our root base (dc=yyy,dc=zzz), the auth fails. If he uses a search

RE: [ActiveDir] 1054 Error (Windows cannot contact DC - Group Policy)

2007-01-19 Thread Thommes, Michael M.
You might want to test the network connection. We have a public tester at http://miranda.ctd.anl.gov:7123/ that might detect duplex mismatches or faulty cables. Mike Thommes -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Darren Mar-Elia Sent: Friday,

[ActiveDir] release date for W2K3/SP2?

2007-01-19 Thread Thommes, Michael M.
Has anyone heard of a release date for Windows Server 2003/SP2? Thanks. Mike Thommes

RE: [ActiveDir] Shares with Computer Account Permissions

2007-01-09 Thread Thommes, Michael M.
Hi Laura, That's what I thought of first but that would stop all traffic to the server, not just a particular share. Mike Thommes From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Laura A. Robinson Sent: Tuesday, January 09, 2007 4:19

RE: [ActiveDir] Disabled user + when

2007-01-03 Thread Thommes, Michael M.
If nothing else has been done to the account, I wonder if you could use the whenChanged attribute. Mike Thommes From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Parag Nagwekar Sent: Wednesday, January 03, 2007 9:28 AM To:

[ActiveDir] how to get ALL users in Domain Users

2007-01-02 Thread Thommes, Michael M.
I am trying to get a list of all of the users in the builtin group Domain Users. I am using the following commands, but get incomplete results. Can someone tell me why? Thanks! And Happy New Year to everyone! dsquery group -name domain users | dsget group -members c:\temp\domain_users.txt

[ActiveDir] OT: help with running a scheduled job

2006-12-15 Thread Thommes, Michael M.
We are trying to get a particular account to run a scheduled backup job on a server. Our results are puzzling. Here are the particulars: 2003 R2 standard server Domain account, non privileged, doesn't belong to domain users Added to local backup operators group Trying to run a system state

RE: [ActiveDir] OT: help with running a scheduled job

2006-12-15 Thread Thommes, Michael M.
where we have ordinary users executing batch jobs I've setup a local group to grant read and execute. http://support.microsoft.com/kb/867466 Mike From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M. Sent: Friday, December 15

RE: [ActiveDir] dynamic variables within an event log entry?

2006-12-01 Thread Thommes, Michael M.
, sorry. I'm sleep deprived. Laura From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M. Sent: Thursday, November 30, 2006 10:40 PM To: ActiveDir@mail.activedir.org Subject: RE

RE: [ActiveDir] Split pagefile

2006-12-01 Thread Thommes, Michael M.
How about a remote shutdown like shutdown /m \\computername /r /f Mike Thommes -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Kevin Brunson Sent: Friday, December 01, 2006 9:51 AM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] Split pagefile

[ActiveDir] dynamic variables within an event log entry?

2006-11-30 Thread Thommes, Michael M.
I wonder if someone could explain to me (or point me at some reference) about what mechanism is used to populate the information in a Windows event log entry. The reason why I ask is that I see in the Security log when a new user account is created by an account which is a member of the Domain

RE: [ActiveDir] dynamic variables within an event log entry?

2006-11-30 Thread Thommes, Michael M.
:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M. Sent: Thursday, November 30, 2006 7:33 PM To: ActiveDir@mail.activedir.org Subject: [ActiveDir] dynamic variables within an event log entry? I wonder if someone could explain to me (or point me at some reference) about

RE: [ActiveDir] AD Security Group Information

2006-10-31 Thread Thommes, Michael M.
adfind -default -f (objectclass=group)(groupType=-2147483646) -tdc whenChanged hth, Mike Thommes From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Frank Abagnale Sent: Tuesday, October 31, 2006 2:51 AM To: activedir@mail.activedir.org Subject: [ActiveDir] AD

RE: [ActiveDir] List Groups I'm In?

2006-10-25 Thread Thommes, Michael M.
Hi Deji, My version of whoami shows the usage as: whoami /groups. Thanks for pointing me at this; I always just used whoami. Mike Thommes From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Akomolafe, Deji Sent: Wednesday, October 25, 2006 11:58 AM To:

RE: [ActiveDir] The remote computer has ended the connection.

2006-10-18 Thread Thommes, Michael M.
, Michael M. Sent: Tue 10/17/2006 8:33 AM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] The remote computer has ended the connection. I have also seen where a second reboot is necessary for RDP to work.  I have not determined the cause of this yet.  It does not happen on all

RE: [ActiveDir] The remote computer has ended the connection.

2006-10-17 Thread Thommes, Michael M.
I have also seen where a second reboot is necessary for RDP to work. I have not determined the cause of this yet. It does not happen on all servers. Mike Thommes From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Vinnie Cardona Sent: Tuesday, October 17, 2006

RE: [ActiveDir] The remote computer has ended the connection.

2006-10-17 Thread Thommes, Michael M.
Hi Susan, I didn't mean to imply that this was just with the last set of patches. I think your note says that you have been seeing this for a while. We have too. One of the guys in my group uses Update Expert to patch and he sees it more often than I do. Of course, he patches a lot more

RE: [ActiveDir] Determine disabled computer accounts

2006-10-16 Thread Thommes, Michael M.
Check out oldcmp at http://www.joeware.net/win/free/tools/oldcmp.htm Mike Thommes -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Condra, Jerry W Mr HP Sent: Monday, October 16, 2006 12:50 PM To: ActiveDir@mail.activedir.org Subject: [ActiveDir]

RE: [ActiveDir] Discovering LDAPS availability

2006-10-11 Thread Thommes, Michael M.
In this context, would it make sense to write/use a servicePrincipalName value? (maybe even using admod/adfind 8-) ) Mike Thommes -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of joe Sent: Wednesday, October 11, 2006 9:42 AM To:

[ActiveDir] problem changing employeeID attribute value

2006-10-10 Thread Thommes, Michael M.
For an AD user account, we normally populate the attribute employeeID with a value. Circumstances surrounding some accounts requires me to unpopulate this value. In ADSIEdit, however, when I go to this Unicode String valued attribute with the Edit function, I can delete the value but when

RE: [ActiveDir] problem changing employeeID attribute value

2006-10-10 Thread Thommes, Michael M.
: [ActiveDir] problem changing employeeID attribute value Try clicking the 'Clear' button instead of deleting the value. -Andrew From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M. Sent: Tuesday, October 10, 2006 11:29 AM To: ActiveDir

RE: [ActiveDir] Who keeps creating this folder files?!

2006-10-05 Thread Thommes, Michael M.
Try FileNotify freeware at http://www.xtware.com/ Mike Thommes From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Kurt Falde Sent: Thursday, October 05, 2006 1:19 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] Who keeps creating this folder files?!

RE: [ActiveDir] 200 users network. Adding 2 classes to the GC

2006-10-03 Thread Thommes, Michael M.
Hi Rezuma, I suspect you might run into the same issue I had when I did the R2 forestprep with SFU 3.5 (although you have the earlier SFU 3.0). If so, see the fixup from Steve Linehan posted to this newsgroup on 8/7/06 (and my comment from 8/12/06). Mike Thommes From:

RE: [ActiveDir] different version of R2 available?

2006-09-21 Thread Thommes, Michael M.
Thanks for all of the replies! I actually was able to get a hold of the Standard and Enterprise versions of R2 (aka Disk 2) to do a compare (windiff.exe) and there are differences. Mike Thommes From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M

[ActiveDir] different version of R2 available?

2006-09-20 Thread Thommes, Michael M.
My officemate and I were discussing whether there are different versions of the R2 CD depending on whether youre running Server 2003 Standard or Server 2003 Enterprise. Or is there only one version of R2? TIA! Mike Thommes

RE: [ActiveDir] OT: Protecting against Spyware/Adware

2006-09-14 Thread Thommes, Michael M.
Touche 8-) Mike Thommes From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of joe Sent: Thursday, September 14, 2006 5:04 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] OT: Protecting against Spyware/Adware I run as local admin and have zero issues

[ActiveDir] OT: uptime.exe in a 2003/sp1 world - problem

2006-09-07 Thread Thommes, Michael M.
Hi, I have moved a job that employs uptime.exe (in a loop using the FOR command) from a Windows 2000/SP4 server to a Windows 2003/SP1 server. Now part way through the job, I get: Event Type: Information Event Source: Application Popup Event Category: None Event ID: 26 Date:

RE: [ActiveDir] Seperate Administrator password policy

2006-08-31 Thread Thommes, Michael M.
We are still testing PassFiltPro software (http://www.altusnet.com/products/) which supposedly has the ability with one of its versions (MPE) to enforce different password policies based on global groups. This is mentioned only for information, not endorsement, at this time. Mike

[ActiveDir] www.activedir.org MIA?; storing pictures in AD?

2006-08-30 Thread Thommes, Michael M.
Can anyone else get to the archives? Specifically, I was looking for a thread from, I think, a couple of years ago where there was discussion about storing (not storing?) employee pictures in AD. I am concerned about how that attribute will grow our DIT. I seem to recall that maybe just a

RE: [ActiveDir] nslookup. AD beginer question

2006-08-29 Thread Thommes, Michael M.
I am guessing, based on the port number, you have a DNS A record for this computer in gc._msdcs.domain.com . Mike Thommes From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Ramon Linan Sent: Tuesday, August 29, 2006 10:06 AM To: ActiveDir@mail.activedir.org

RE: [ActiveDir] nslookup. AD beginer question

2006-08-28 Thread Thommes, Michael M.
You should get back your domain controllers IP addresses. Is it possible that your users computer has gotten the IP of an old DC? Mike Thommes From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Ramon Linan Sent: Monday, August 28, 2006 3:03 PM To:

RE: [ActiveDir] Secure LDAP queries from the outside -- problem solved

2006-08-23 Thread Thommes, Michael M.
PROTECTED] On Behalf Of Thommes, Michael M. Sent: Tuesday, August 22, 2006 9:36 AM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] Secure LDAP queries from the outside Hi Robert, Yes, the command is *exactly* the same. We are thinking that our CRL location is not available outside

RE: [ActiveDir] Secure LDAP queries from the outside -- problem solved

2006-08-23 Thread Thommes, Michael M.
in that regard. joe -- O'Reilly Active Directory Third Edition - http://www.joeware.net/win/ad3e.htm From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M. Sent: Wednesday, August 23, 2006 8:06 AM To: ActiveDir

[ActiveDir] Secure LDAP queries from the outside

2006-08-22 Thread Thommes, Michael M.
Hi, We are trying to set up secure LDAP queries from the outside to AD for pulling email addresses but are running into an issue. Port 636 has been opened up to our DCs but we get a 0x51 error like the one shown below in this example of using adfind: adfind -h dc1.abc.com:636 -u

RE: [ActiveDir] Secure LDAP queries from the outside

2006-08-22 Thread Thommes, Michael M.
returned? I tried using adfind to connect to my test DC using port 636 and got the exact same errorbut I dont have a cert installed on my DC so Id expect mine not to work. Robert Williams From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M. Sent: Tuesday

RE: [ActiveDir] User AutoEnrollment

2006-08-16 Thread Thommes, Michael M.
Maybe the CRL (Certificate Revocation List) location is not available? Mike Thommes -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Za Vue Sent: Wednesday, August 16, 2006 8:17 AM To: ActiveDir@mail.activedir.org Subject: [ActiveDir] User AutoEnrollment

RE: [ActiveDir] Adding the first Win2003 R2 DC

2006-08-15 Thread Thommes, Michael M.
I fixed this issue with ldp and Steve Linehans instructions to the list about two weeks ago. Microsoft supposedly has an unofficial patch to fix this issue. Talk to your TAM. Mike Thommes From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of joe Sent: Tuesday, August

RE: [ActiveDir] joe - please say it isn't so!

2006-08-14 Thread Thommes, Michael M.
So here I went to take a look at Deans article, and I find this: http://blog.joeware.net/cat/recipes/ , expecting to find more of joes great adfind codes. At first, I thought it got misfiled and should have been filed under humor but I suspect this is hardly funny. Joe, are you pulling our

RE: [ActiveDir] [OT] joe - please say it isn't so!

2006-08-14 Thread Thommes, Michael M.
Of Thommes, Michael M. Sent: Monday, August 14, 2006 3:28 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] joe - please say it isn't so! So here I went to take a look at Deans article, and I find this: http://blog.joeware.net/cat/recipes/ , expecting to find more of joes great adfind codes

RE: [ActiveDir] OT: Enterprise Terminal Server Licensing Server question

2006-08-06 Thread Thommes, Michael M.
Of Thommes, Michael M. Sent: Saturday, August 05, 2006 5:04 AM To: ActiveDir@mail.activedir.org Subject: [ActiveDir] OT: Enterprise Terminal Server Licensing Server question Hi, This is not causing any issues that I am aware of, but something does not seem right. We set up two Enterprise Terminal

[ActiveDir] OT: Enterprise Terminal Server Licensing Server question

2006-08-04 Thread Thommes, Michael M.
Title: OT: Enterprise Terminal Server Licensing Server question Hi, This is not causing any issues that I am aware of, but something does not seem right. We set up two Enterprise Terminal Server Licensing Servers, both DCs. They are both identified in

RE: [ActiveDir] root admin account able to be locked out?

2006-07-22 Thread Thommes, Michael M.
MVP Windows Server- Directory Services LogicaCMG Nederland B.V. (BU RTINC Eindhoven) ( Tel : +31-(0)40-29.57.777 ( Mobile : +31-(0)6-26.26.62.80 * E-mail : see sender address From: [EMAIL PROTECTED] on behalf of Thommes, Michael M. Sent: Tue 2006-07-18

[ActiveDir] OT: Microsoft Acquires Winternals Software

2006-07-21 Thread Thommes, Michael M.
Title: OT: Microsoft Acquires Winternals Software You may find this of interest (from todays WServerNews): Mike Thommes = Microsoft Acquires Winternals Software Mark Russinovich and Bryce Cogswell have been snagged up by Redmond. And

[ActiveDir] root admin account able to be locked out?

2006-07-18 Thread Thommes, Michael M.
Title: root admin account able to be locked out? Hi AD Gurus! We have penetration testing going on and I saw a security event log entry that showed our root admin account getting locked out. I was surprised because I thought this account could never get locked out. In addition, we had a

RE: [ActiveDir] Account Password Expiration Tool

2006-07-11 Thread Thommes, Michael M.
joe's tools again ( 8-) ): adfind -b ou=Employees,dc=xyz,dc=com -bit -f ((objectcategory=person)(useraccountcontrol:AND:=65536)) samaccountname c:\temp\pw_never_expires.txt Mike Thommes -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Alex Alborzfard

[ActiveDir] importance of gc._msdcs.mycompany.com A records?

2006-06-29 Thread Thommes, Michael M.
Title: importance of gc._msdcs.mycompany.com A records? What is the importance of the gc._msdcs.mycompany.com A records? Environment: 1) Split DNS Unix Bind and AD integrated DNS 2) DCs use: [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters]

RE: [ActiveDir] Ammunition, please!

2006-06-28 Thread Thommes, Michael M.
Hi Larry, You might want to check this reference which was posted to this group a few days ago: http://iase.disa.mil/stigs/checklist/AD_Checklist_V1R11_20060607.pdf It discusses physical security and not running other services on DCs, among other things. Mike Thommes -Original

RE: [ActiveDir] [OT] DC Configuration

2006-06-22 Thread Thommes, Michael M.
I know, I know...how about the AD Party? We're ethical, right? joe's probably the most ethical guy around. And he gives stuff away for free. When was the last time you saw a politician do that? I nominate him for President! ;-) Mike Thommes -Original Message- From: [EMAIL PROTECTED]

[ActiveDir] can I exclude a particular user account from authenticated users?

2006-06-19 Thread Thommes, Michael M.
Title: can I exclude a particular user account from authenticated users? This may sound like an off the wall question, but I would like to exclude a particular user account from the built-in security principal Authenticated Users. Is there any way to do this? TIA! Mike Thommes

RE: [ActiveDir] OT: srvinfo output incomplete -- solution!

2006-06-02 Thread Thommes, Michael M.
PROTECTED] On Behalf Of Thommes, Michael M. Sent: Thursday, June 01, 2006 8:55 AM To: ActiveDir@mail.activedir.org Subject: [ActiveDir] OT: srvinfo output incomplete Situation: running srvinfo \\computer_name file://\\computer_name with domain admin credentials from a remote computer. One w2k3/sp1

RE: [ActiveDir] PCs hang at Applying computer settings after upgradingDCs to 2K3 SP1

2006-06-02 Thread Thommes, Michael M.
This is the same issue I posted to this group on 5/25/06. We never did figure out the cause. The local admins were rebuilding the workstation in question yesterday since that seemed to be the most expedient thing to do. I will be interested in future postings to this thread. Mike

[ActiveDir] OT: srvinfo output incomplete

2006-06-01 Thread Thommes, Michael M.
Title: OT: srvinfo output incomplete Situation: running srvinfo \\computer_name with domain admin credentials from a remote computer. One w2k3/sp1 server target returns the full complement of information, including CPU, BIOS info, hotfixes, network card info, uptime. Another w2k3sp1 server

RE: [ActiveDir] MSC pointing at untrusted domain?

2006-05-31 Thread Thommes, Michael M.
How about: Runas /netonly /user:target_computer\username eventvwr.exe /auxsource=target_computer Mike Thommes -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of AdamT Sent: Wednesday, May 31, 2006 11:39 AM To: ActiveDir@mail.activedir.org Subject:

RE: [ActiveDir] MSC pointing at untrusted domain?

2006-05-31 Thread Thommes, Michael M.
Sorry for the last incorrect answer. Try this: runas /netonly /user:domain_or_target_computer\username mmc.exe eventvwr.msc /computer=target_computer Mike Thommes -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of AdamT Sent: Wednesday, May 31, 2006 11:39

RE: [ActiveDir] OT: stuck processing policy

2006-05-26 Thread Thommes, Michael M.
related to authentication, etc. Darren From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M. Sent: Thursday, May 25, 2006 2:12 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] OT: stuck processing policy Hi Darren! Here you go. Thanks! Mike

RE: [ActiveDir] OT: stuck processing policy

2006-05-26 Thread Thommes, Michael M.
to this point could easily be related to network issues (especially at the NIC/Router) as well. Al On 5/26/06, Thommes, Michael M. [EMAIL PROTECTED] wrote: Hi Shariff (and Darren too!), Yeah, I saw some entries in WINS that I didn't like. I believe it is some issue where

RE: [ActiveDir] AD DNS along with Bind

2006-05-25 Thread Thommes, Michael M.
. Could just be a personal preference I suppose... Aric -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M. Sent: Wednesday, May 24, 2006 12:47 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] AD DNS along with Bind Hi Freddy

[ActiveDir] OT: stuck processing policy

2006-05-25 Thread Thommes, Michael M.
Title: OT: stuck processing policy I have a user on a computer that takes forever to log in. She can go to any other computer and log in quickly. Anyone else can go to the computer in question and log in quickly. It is only THIS user on the THIS computer. We have renamed her local profile to

RE: [ActiveDir] OT: stuck processing policy

2006-05-25 Thread Thommes, Michael M.
, 2006 4:07 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] OT: stuck processing policy Hi Mike. Can you post the lines of userenv right around that GetUserNameEx error? From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M. Sent: Thursday, May 25

RE: [ActiveDir] view only rights on ADI DNS Zone

2006-05-24 Thread Thommes, Michael M.
The Microsoft link at the bottom of an event log entry has gotten much better. Mike Thommes From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Myrick, Todd (NIH/CC/DNA) [E] Sent: Wednesday, May 24, 2006 10:21 AM To: ActiveDir@mail.activedir.org Subject: RE:

RE: [ActiveDir] AD DNS along with Bind

2006-05-24 Thread Thommes, Michael M.
Engineer InternationalSOS Pte Ltd mail: [EMAIL PROTECTED] phone: (+65) 6330-9785 -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M. Sent: Wednesday, May 24, 2006 4:38 AM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] AD DNS along

RE: [ActiveDir] Naming conventions (quasi-OT)

2006-05-24 Thread Thommes, Michael M.
Title: Naming conventions (quasi-OT) Following this thread, I want to comment that we name workstations with their local serial numbers. In addition, we have a process to look through the local security log to see who is the most common user of the workstation and put their name in the

RE: [ActiveDir] AD DNS along with Bind

2006-05-23 Thread Thommes, Michael M.
Adeel, Here is a response from our DNS guy. I hope it helps you. Mike Thommes = Here are the steps I took for delegating the AD zones for example.com: 1) In the example.com zone on the BIND server I added these NS records to delegate the zone

RE: [ActiveDir] how to find DNS servers in a forest?

2006-05-17 Thread Thommes, Michael M.
Hi Deji, I was thinking about the following but the results are wrong (and I don't understand why!): For /F %a IN ('dsquery server -o rdn -forest') do srvinfo \\%a |find /i DNS Server Can anyone tell me what I am doing wrong? Thanks! Mike Thommes -Original Message- From: [EMAIL

RE: [ActiveDir] Test Windows 23K Firewall

2006-05-09 Thread Thommes, Michael M.
telnet or portqry? telnet [-a][-e escape char][-f log file][-l user][-t term][host [port]] -a Attempt automatic logon. Same as -l option except uses the currently logged on user's name. -e Escape character to enter telnet client prompt. -f File name for client side

RE: [ActiveDir] Schema extension

2006-05-09 Thread Thommes, Michael M.
DefaultHidingValue? defaultHidingValue A Boolean value that specifies the default setting of the showInAdvancedViewOnly property of new instances of this class. Many directory objects are not interesting to end users. To keep these objects from cluttering the UI,

RE: [ActiveDir] which GC answers?

2006-05-03 Thread Thommes, Michael M.
Hi Jorge,     I dont mean to hijack this thread but I have also been having an issue with lingeringobjects.  I ran your repadmin command shown below on one of the lingering objects I have.  For the lingering object I specified, the output lists a GUID (Originating DC) that doesnt exist

[ActiveDir] how to get rid of an obsolete DC?

2006-05-02 Thread Thommes, Michael M.
In a child domain I have what I believe is the remnants of an old NT4 DC. Using ADUC, it shows up in the child domain's Domain Controllers OU. When I try to delete it, I get The DSA object cannot be deleted. When I use ADSIEdit and go to the domain, it only shows me the two functioning DCs and

RE: [ActiveDir] how to get rid of an obsolete DC?

2006-05-02 Thread Thommes, Michael M.
] On Behalf Of Hutchins, Mike Sent: Tuesday, May 02, 2006 3:06 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] how to get rid of an obsolete DC? ntdsutil -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M. Sent: Tuesday, May 02

RE: [ActiveDir] how to get rid of an obsolete DC?

2006-05-02 Thread Thommes, Michael M.
H.so *is* ADSIEdit a valid tool to use? I can see the object I want to delete in ADSIEdit. (Would I be talking to myself if I reply to my own post?) Mike Thommes -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M. Sent

[ActiveDir] dealing with authentication errors after password change?

2006-05-02 Thread Thommes, Michael M.
How do other admins deal with the copious authentication errors a user will generate after the user resets his password with a CNTL+ALT+DEL and stays logged into the session with his old credentials? Mike Thommes List info : http://www.activedir.org/List.aspx List FAQ:

[ActiveDir] 2003/SP1 TS Licensing Server registry key confusion

2006-05-01 Thread Thommes, Michael M.
Hi, In trying to determine why my TS Licensing Server (located on a W2K3/SP1 DC) is only handing out temporary licenses, although we have successfully entered the license data, I find the registry key for the type of license is spelled differently (an extra space) than what I find in KB834651.

[ActiveDir] anyone using IPV6?

2006-04-27 Thread Thommes, Michael M.
Has anyone tried IPV6 yet? Production? Or just testbed? Any gotchas? What kind of infrastructure (eg, switches) is needed to support it? How does AD play in this sandbox? I am probably out of my league pretty quickly with subject. I've done a little googling but it seems like a pretty big

[ActiveDir] any experiences with PassFilt Pro software? (again)

2006-04-24 Thread Thommes, Michael M.
(I didn't get any response to my first query. I thought I would try it again). This software (http://www.altusnet.com/products/pfp/) supposedly enhances the default passflt.dll, allowing an admin to enforce/control password complexity and, at the same time, does a dictionary check. The price

RE: [ActiveDir] Lsasrv error

2006-04-24 Thread Thommes, Michael M.
Maybe this will help.  From eventid.net: Matthew C. Miller (Last update 11/24/2005): The error in our server (domain controller) System Event Log was: The Security System detected an authentication error for the server server. The failure code from authentication protocol Kerberos was

[ActiveDir] any experiences with PassFilt Pro software?

2006-04-18 Thread Thommes, Michael M.
Anybody out there have any experience with the PassFilt Pro software by Altus Networks Solutions, Inc.? TIA, Mike Thommes List info : http://www.activedir.org/List.aspx List FAQ: http://www.activedir.org/ListFAQ.aspx List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

[ActiveDir] how to report on scheduled jobs?

2006-04-17 Thread Thommes, Michael M.
Is there a script to output scheduled job information? Maybe something I could call in a for loop driven by a list of servers. Ideally, I would like to see the job and who's credentials it is running under, with maybe the schedule. Mike Thommes List info : http://www.activedir.org/List.aspx

RE: [ActiveDir] how to report on scheduled jobs?

2006-04-17 Thread Thommes, Michael M.
Excellent! Just what I was looking for! Thanks, Jef! Mike Thommes From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Jef Kazimer Sent: Monday, April 17, 2006 3:15 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] how to report on scheduled jobs?

RE: [ActiveDir] issue with R2 upgrade; SFU confusion?

2006-04-13 Thread Thommes, Michael M.
] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M. Sent: Friday, February 17, 2006 2:18 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] issue with R2 upgrade; SFU confusion? Our MS TAM has indicated this is a known bug! I will keep the group posted as I learn more

[ActiveDir] how to display DC services on a single line?

2006-04-13 Thread Thommes, Michael M.
Brain freeze active There is a command that shows on a single line what services are running on a DC. The output is something like DS::GC::Time::LDAP:: Can someone help this poor, tired brain out? Thanks! Mike Thommes List info : http://www.activedir.org/List.aspx List FAQ:

[ActiveDir] default values for net time /querysntp on new systems?

2006-04-11 Thread Thommes, Michael M.
Hi, I've noticed in our Active Directory environment default settings on Windows XP and Server 2003 computers for net time /querysntp to be one of two values: net time /querysntp The current SNTP value is: time.windows.com,0x1 net time /querysntp This computer is not currently configured to

[ActiveDir] Server 2003 DNS Admins group permissions

2006-04-06 Thread Thommes, Michael M.
The default DNS Admins group has permission to use the DNS GUI (dnsmgmt.msc) and to make changes in it but does not have permission to view the DNS event log (DnsEvent.Evt). Would this just be an oversight on Microsoft's part? TIA, Mike Thommes List info : http://www.activedir.org/List.aspx

RE: [ActiveDir] 2003 DFS/open files

2006-04-06 Thread Thommes, Michael M.
From: [EMAIL PROTECTED] on behalf of Thommes, Michael M. Sent: Wed 4/5/2006 7:25 AM To: ActiveDir@mail.activedir.org Subject: [ActiveDir] 2003 DFS/open files Can someone tell me what happens with DFS/replication when a file is updated on one DFS server and a client has that same file open

RE: [ActiveDir] Server 2003 DNS Admins group permissions

2006-04-06 Thread Thommes, Michael M.
- |From: [EMAIL PROTECTED] |[mailto:[EMAIL PROTECTED] On Behalf Of |Thommes, Michael M. |Sent: Thursday, April 06, 2006 5:54 PM |To: ActiveDir@mail.activedir.org |Subject: [ActiveDir] Server 2003 DNS Admins group permissions | |The default DNS Admins group has permission to use the DNS GUI

[ActiveDir] 2003 DFS/open files

2006-04-05 Thread Thommes, Michael M.
Can someone tell me what happens with DFS/replication when a file is updated on one DFS server and a client has that same file open on another DFS server? TIA! Mike Thommes List info : http://www.activedir.org/List.aspx List FAQ: http://www.activedir.org/ListFAQ.aspx List archive:

RE: [ActiveDir] Empty hostname for a Win 2003 server belonging to an AD domain

2006-04-04 Thread Thommes, Michael M.
How about: dsquery computer -samid computer_name_here | dsget computer sid Mike Thommes From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of matheesha weerasinghe Sent: Tuesday, April 04, 2006 10:56 AM To: ActiveDir@mail.activedir.org Subject: Re: [ActiveDir] Empty

RE: [ActiveDir] Mass AD Full Name Display Name Changes - Last name, first name

2006-03-01 Thread Thommes, Michael M.
These may be of interest to you: http://support.microsoft.com/kb/277717/en-us http://support.microsoft.com/?kbid=300427 Mike Thommes -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Danny Sent: Wednesday, March 01, 2006 1:42 PM To:

RE: [ActiveDir] repadmin info oddity

2006-02-21 Thread Thommes, Michael M.
Adfind (http://www.joeware.net/win/free/tools/adfind.htm) to the rescue! I recently had to do this and got it accomplished with the following syntax (with a little help from joe :) ): adfind -default -binenc -f objectGUID={{GUID:0B3F5BC4-5713-4611-8F6A-752A3B0DE664}} dn (adfind /??? For lots of

RE: [ActiveDir] issue with R2 upgrade; SFU confusion?

2006-02-17 Thread Thommes, Michael M.
where SFU 3.5 had been installed. Thanks! Mike Thommes -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M. Sent: Thursday, February 16, 2006 9:07 AM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] issue with R2 upgrade; SFU confusion

RE: [ActiveDir] issue with R2 upgrade; SFU confusion?

2006-02-17 Thread Thommes, Michael M.
Our MS TAM has indicated this is a known bug! I will keep the group posted as I learn more details. Mike Thommes -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M. Sent: Friday, February 17, 2006 10:52 AM To: ActiveDir

RE: [ActiveDir] issue with R2 upgrade; SFU confusion?

2006-02-16 Thread Thommes, Michael M.
from a Win2003 schema to Win2003 R2... /Guido -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M. Sent: Donnerstag, 16. Februar 2006 02:53 To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] issue with R2 upgrade; SFU confusion? Hi

[ActiveDir] ability to create container objects not in ADUC

2006-02-16 Thread Thommes, Michael M.
Is there a technical reason why the ability to create a new container is not available in the Active Directory Users and Computers (ADUC) mmc? (Sorry if this is a dumb question.) Mike Thommes List info : http://www.activedir.org/List.aspx List FAQ: http://www.activedir.org/ListFAQ.aspx List

[ActiveDir] issue with R2 upgrade; SFU confusion?

2006-02-15 Thread Thommes, Michael M.
Hi, We did a adprep /forestprep from the W2K3/SP1 R2 Disk 2 CD today on our testbed FSMO DC. It gave the following errors (only a portion shown below) because, I am guessing, that we had already installed SFU 3.5 on this forest some time ago. Should I assume these errors can be ignored? Has

  1   2   3   4   >