Title: Message
FYI. I submitted a request to have this article reviewed and corrected as deemed necessary.


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Rich Milburn
Sent: Thursday, January 19, 2006 3:08 PM
To: [email protected]
Subject: RE: [ActiveDir] AD computer accounts being removed

Well, XP is kind of obscure, esp when you include Server 2003 SP1 in an imaging article <being very sarcastic by the way for those who have never been to England and do not catch such things J>

 

-----------------------------------------------------------------------
Rich Milburn
MCSE, Microsoft MVP - Directory Services
Sr Network Analyst, Field Platform Development
Applebee's International, Inc.

4551 W. 107th St
Overland Park, KS 66207
913-967-2819
----------------------------------------------------------------------
”I love the smell of red herrings in the morning” - anonymous


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of joe
Sent: Thursday, January 19, 2006 12:30 PM
To: [email protected]
Subject: RE: [ActiveDir] AD computer accounts being removed

 

Most likely oversight. I submit quite a few requests to get articles like this updated that are missing specific OS versions or App versions. At one point I asked that they have an additional field of "doesn't apply to" for OSes so you at least knew they weren't forgetting it. I was told to piss off.

 

 


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Rich Milburn
Sent: Thursday, January 19, 2006 8:44 AM
To: [email protected]
Subject: RE: [ActiveDir] AD computer accounts being removed

Any idea why XP is omitted in this article, but 2k and 2k3 are included?

http://support.microsoft.com/?id=162001

"Do Not Disk Duplicate Installed Versions of Windows NT"

 

 

-----------------------------------------------------------------------
Rich Milburn
MCSE, Microsoft MVP - Directory Services
Sr Network Analyst, Field Platform Development
Applebee's International, Inc.

4551 W. 107th St
Overland Park, KS 66207
913-967-2819
----------------------------------------------------------------------
”I love the smell of red herrings in the morning” - anonymous


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Aaron Visser
Sent: Wednesday, January 18, 2006 6:27 PM
To: [email protected]
Subject: RE: [ActiveDir] AD computer accounts being removed

 

Well I would agree that is not a safe practice for most but for my application where all Local accounts are disabled I do not see a problem.

 

Taken from http://www.sysinternals.com/Utilities/NewSid.html under the SID Duplication Problem

Duplicate SIDs aren't an issue in a Domain-based environment since domain accounts have SID's based on the Domain SID. But, according to Microsoft Knowledge Base article Q162001, "Do Not Disk Duplicate Installed Versions of Windows NT", in a Workgroup environment security is based on local account SIDs. Thus, if two computers have users with the same SID, the Workgroup will not be able to distinguish between the users. All resources, including files and Registry keys, that one user has access to, the other will as well.

 

Aaron

 

 

 


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Brian Desmond
Sent: Wednesday, January 18, 2006 3:50 PM
To: [email protected]
Subject: RE: [ActiveDir] AD computer accounts being removed

 

NO NO NO NO NO BAD BAD BAD

 

You have to use sysprep. You’re getting duplicate SIDs here – bad.

 

Thanks,
Brian Desmond

[EMAIL PROTECTED]

 

c - 312.731.3132

 

 


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Aaron Visser
Sent: Wednesday, January 18, 2006 5:44 PM
To: [email protected]
Subject: RE: [ActiveDir] AD computer accounts being removed

 

Gary, Brian,

 

I do not use Sysprep on my images and have yet to come across any problems, but there may be one big difference with my images, before I ghost them or create the image I put the said machine into a workgroup and then create image.  After I have imaged a computer I log on and change the Computer Name reboot and then join the domain with the new computer name, should I be using Sysprep?

 

And Brenda I have experienced your problem but I have never noticed the accounts actually being out of AD, anyways most times for me a simple reboot works although I have had to actually ghost computers in order to rejoin the domain because I do not have any local accounts active on my computers in the school, makes it a little safer J but with that comes more work L

 

 

 

 


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Brian Desmond
Sent: Wednesday, January 18, 2006 12:38 PM
To: [email protected]
Subject: RE: [ActiveDir] AD computer accounts being removed

 

Gary-

 

Are you implying you don’t sysprep your images?

 

Thanks,
Brian Desmond

[EMAIL PROTECTED]

 

c - 312.731.3132

 

 


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Garyphold
Sent: Wednesday, January 18, 2006 3:04 PM
To: [email protected]
Subject: RE: [ActiveDir] AD computer accounts being removed

 

Brenda,

 

FWIW:  It happens to me when I clone a workstation then try to join that workstation to the domain in order to change the computer name.  AD sees 2 machines with the same name, gives me a notification and lets the 2nd one in.  Then when the original machine with that name logs in next time, it isn't seen on the network.  Then I have to do the same thing you did - with the original machine.  Then all is well again.  Don't know if that will help, but it might narrow down the problem some.

 

Gary

 

Gary Polvinale

Denton ATD

 

 

-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Brenda Casey
Sent: Wednesday, January 18, 2006 2:24 PM
To: [email protected]
Subject: RE: [ActiveDir] AD computer accounts being removed

Yes, their computer account in AD is actually gone.

 

Thanks,

Brenda

 

Brenda Casey
Network Manager

Billings Public Schools

[EMAIL PROTECTED]

406-247-3792

 

 


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Gil Kirkpatrick
Sent: Wednesday, January 18, 2006 11:14 AM
To: [email protected]
Subject: RE: [ActiveDir] AD computer accounts being removed

When you say "lose their account", do you mean the computer object in AD disappears? Or something else?

 

-g

 


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Brenda Casey
Sent: Wednesday, January 18, 2006 10:42 AM
To: [email protected]
Subject: [ActiveDir] AD computer accounts being removed

Occasionally computers will lose their account in Active Directory for no apparent reason. Sometimes it is a computer that has just joined the domain, while other times the machine has been a member of the domain for 2 years.  The computer can only be logged on by a local account (not a domain account).  To remedy this, the computer has to be disjoined from the domain, join a workgroup, then join the domain again.  As I am sure you all are aware, this is not only time consuming, but very inappropriate to have to do.

 

 Has anyone else had this experience and how have you fixed it?

 

Thanks,

Brenda


-------APPLEBEE'S INTERNATIONAL, INC. CONFIDENTIALITY NOTICE-------
PRIVILEGED / CONFIDENTIAL INFORMATION may be contained in this message or any attachments. This information is strictly confidential and may be subject to attorney-client privilege. This message is intended only for the use of the named addressee. If you are not the intended recipient of this message, unauthorized forwarding, printing, copying, distribution, or using such information is strictly prohibited and may be unlawful. If you have received this in error, you should kindly notify the sender by reply e-mail and immediately destroy this message. Unauthorized interception of this e-mail is a violation of federal criminal law. Applebee's International, Inc. reserves the right to monitor and review the content of all messages sent to and from this e-mail address. Messages sent to or from this e-mail address may be stored on the Applebee's International, Inc. e-mail system.



-------APPLEBEE'S INTERNATIONAL, INC. CONFIDENTIALITY NOTICE-------
PRIVILEGED / CONFIDENTIAL INFORMATION may be contained in this message or any attachments. This information is strictly confidential and may be subject to attorney-client privilege. This message is intended only for the use of the named addressee. If you are not the intended recipient of this message, unauthorized forwarding, printing, copying, distribution, or using such information is strictly prohibited and may be unlawful. If you have received this in error, you should kindly notify the sender by reply e-mail and immediately destroy this message. Unauthorized interception of this e-mail is a violation of federal criminal law. Applebee's International, Inc. reserves the right to monitor and review the content of all messages sent to and from this e-mail address. Messages sent to or from this e-mail address may be stored on the Applebee's International, Inc. e-mail system.


Reply via email to