RE: [ActiveDir] Stupid question alert... where exactly is the tombstone value set?

2005-10-16 Thread Ulf B. Simon-Weidner
-b3da-9b56de3d187c.mspx Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz Weblog: http://msmvps.org/UlfBSimonWeidner Website: http://www.windowsserverfaq.org Profile: http://mvp.support.microsoft.com/profile=35E388DE

RE: [ActiveDir] salary(OT)

2005-10-16 Thread Ulf B. Simon-Weidner
Hi Rick, Stop whining ;-) You've been asked on 7/17 by Robbie. Ulf |-Original Message- |From: [EMAIL PROTECTED] |[mailto:[EMAIL PROTECTED] On Behalf Of Rick Kingslan |Sent: Sunday, October 16, 2005 2:14 PM |To: ActiveDir@mail.activedir.org |Subject: RE: [ActiveDir] salary(OT) | |Oh, a

RE: [ActiveDir] Knowing when users were deleted.

2005-10-16 Thread Ulf B. Simon-Weidner
I'd be interested as well. BTW for the original request (don't have it here separatelly to reply) I've been told that there are some 3rd party tools which allow that kind of Audit. E.g. inTrust from Quest claims to plug in front of the LSASS and control which actions to log, which ones to apply an

RE: [ActiveDir] Stupid question alert... where exactly is the tombstone value set?

2005-10-16 Thread Ulf B. Simon-Weidner
otherwise we are still at 60 days. My box at home 'and' |at the office are 60 days. |My slip installed one is the only one with the new 180 value. | |I'm barely planting desktops let alone deploying forests. :-) | |Ulf B. Simon-Weidner wrote: | |>Hi Susan, |> |>

RE: [ActiveDir] Knowing when users were deleted.

2005-10-16 Thread Ulf B. Simon-Weidner
Hmm. Do we really want to excuse prior failure of proper auditing by putting more data into AD? Wouldn't that lead into every request of non-configured auditing to requests for extending the AD? Do it right the first way. I completely agree that we should make the people more auditing aware, and

RE: [ActiveDir] Global Catalog

2005-10-17 Thread Ulf B. Simon-Weidner
Hmm - I wouldn't 100% call the domain the authentication "boundary". Authentication in a W2k+ Network without any mods not to rely on the GC is done - as you said - via DC of the same domain the account resides plus any GC of the forest - not necessarily that a GC which resides in the same domain

RE: [ActiveDir] salary(OT)

2005-10-17 Thread Ulf B. Simon-Weidner
BTW - let us know when we can start the ad-campaign in our blogs / websites ;-) Ulf |-Original Message- |From: [EMAIL PROTECTED] |[mailto:[EMAIL PROTECTED] On Behalf Of |[EMAIL PROTECTED] |Sent: Monday, October 17, 2005 2:40 PM |To: ActiveDir@mail.activedir.org |Subject: RE: [ActiveDir

RE: [ActiveDir] Knowing when users were deleted.

2005-10-17 Thread Ulf B. Simon-Weidner
ve deeper pockets, and larger needs. For |the small to |>medium businesses, it should not be so difficult nor should |it *require* SQL |>licensing or expertise. |> |> |> |>[1] I'm not saying that the quality has kept up, only that |the hardware is |>bigger, faster, stron

RE: [ActiveDir] Knowing when users were deleted.

2005-10-17 Thread Ulf B. Simon-Weidner
lity has kept up, only that the |hardware is bigger, faster, stronger and cheaper. |[2] I'm making that up, but it sounds reasonable | | | | |-Original Message- |From: [EMAIL PROTECTED] |[mailto:[EMAIL PROTECTED] On Behalf Of Ulf B. |Simon-Weidner |Sent: Sunday, October 16, 2005 4:42 PM |T

RE: [ActiveDir] Global Catalog

2005-10-17 Thread Ulf B. Simon-Weidner
| |So why don't you agree with the "general - forest is the |security boundary - statement"? |Jorge | |________ | |From: [EMAIL PROTECTED] on behalf of Ulf B. |Simon-Weidner |Sent: Mon 10/17/2005 11:24 PM |To: ActiveDir@mail.activedir.org |Subject: RE: [Act

RE: [ActiveDir] Knowing when users were deleted.

2005-10-17 Thread Ulf B. Simon-Weidner
uld be and should |meet those criteria above. | |We may just need to knock a few more edges off before |submitting this FMR ;) | | |>From: "Ulf B. Simon-Weidner" <[EMAIL PROTECTED]> |>Reply-To: ActiveDir@mail.activedir.org |>To: |>Subject: RE: [ActiveDir] Knowing when use

RE: [ActiveDir] Global Catalog

2005-10-17 Thread Ulf B. Simon-Weidner
y don't you agree with the "general - forest is the security ||boundary - statement"? ||Jorge || || || ||From: [EMAIL PROTECTED] on behalf of Ulf B. ||Simon-Weidner ||Sent: Mon 10/17/2005 11:24 PM ||To: ActiveDir@mail.activedir.org ||Subject: RE: [Ac

RE: [ActiveDir] Knowing when users were deleted.

2005-10-18 Thread Ulf B. Simon-Weidner
t info", _is_ AD |replication. Implying the data is in AD. | |Cheers, |-Brett | | |On Tue, 18 Oct 2005, Ulf B. Simon-Weidner wrote: | |> | Wherever the information gets put, it should be a) done as the |> |default yet configurable b) centrally viewable (I should |NOT have to |

RE: [ActiveDir] Subinacl print queue

2005-10-18 Thread Ulf B. Simon-Weidner
Subinacls has issues with spaces and is used in Rich's script. When doing files I didn't find a fast way around and had to use the 8.1 name. Sucks - doesn't it?   Ulf From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Frank AbagnaleSent: Tuesday, October 18, 2005 3:4

RE: [ActiveDir] Knowing when users were deleted.

2005-10-18 Thread Ulf B. Simon-Weidner
mere typo - | | |"Hi Bratt" | | |... still laughing at the irony ;o) | |ah hahahahaha | |-- |Dean Wells |MSEtechnology |* Email: [EMAIL PROTECTED] |http://msetechnology.com | | |-Original Message- |From: [EMAIL PROTECTED] |[mailto:[EMAIL PROTECTED] On Behalf Of Ulf B. |Simon-Wei

RE: [ActiveDir] Global Catalog

2005-10-18 Thread Ulf B. Simon-Weidner
increase costs but provide more isolation. Do |the costs outweigh the benefits? It all depends on the |particular organization. | |BTW, ich bin halb-deutsch. Mein mutter ist aus Berlin. | |-g | | |-Original Message----- |From: [EMAIL PROTECTED] |[mailto:[EMAIL PROTECTED] On Behalf Of Ulf B.

RE: [ActiveDir] Force a Domain Sync

2005-10-19 Thread Ulf B. Simon-Weidner
IIRC Repadmin /syncall /Aje Ulf |-Original Message- |From: [EMAIL PROTECTED] |[mailto:[EMAIL PROTECTED] On Behalf Of Free, Bob |Sent: Wednesday, October 19, 2005 10:48 PM |To: ActiveDir@mail.activedir.org |Subject: RE: [ActiveDir] Force a Domain Sync | |Look into repadmin /syncall | |h

RE: [ActiveDir] Virtual Servers in Branch Offices

2005-10-20 Thread Ulf B. Simon-Weidner
Title: Message Hi Al,   you don't need IIS running on the machine where Virtual Server is running. IIS supports the admin website, and you can put this on any other server, and have couple servers managed from one machine. Since we are talking about VS in BOs I'd recommend putting the virtual

RE: [ActiveDir] Virtual Servers in Branch Offices

2005-10-20 Thread Ulf B. Simon-Weidner
I have to second that - I don't see much performance issues when admininterface and the vs-host are seperated. The mgmt traffic should be pretty low, the higher traffic is when connecting onto a machine via RDP, VSRC or the webbased VSRC. Either or they will cause the traffic between the VS-host an

RE: [ActiveDir] Windows 2000 / Exchange 2000 Upgrade to 2003

2005-10-24 Thread Ulf B. Simon-Weidner
I've done it during the day at a customer, but without much experience I would strongly recommend doing it after hours! There are always minor things which might happen, and without experience you don't know how to respond to them right away, so give yourself the rest and peace of after hours. Ulf

RE: [ActiveDir] AD Lag Site

2005-10-25 Thread Ulf B. Simon-Weidner
I did those too, and some other things to consider were: * Putting them inside a virtual machine with faked Subnetting in AD: Take a class C Network and split it in AD Sites and Services, not TCP/IP, then you can spare the router * Assign the site membership for the host via GPO if it is in o

RE: [ActiveDir] script to check the "inheritance" from the security Tab...

2005-10-25 Thread Ulf B. Simon-Weidner
Hallo Michel, Look a the VB-Script in KB 817433 ( http://support.microsoft.com/?id=817433 ), especially the SetInheritanceFlag-Function. Ulf |-Original Message- |From: [EMAIL PROTECTED] |[mailto:[EMAIL PROTECTED] On Behalf Of |Bruyere, Michel |Sent: Wednesday, October 26, 2005 12:48 AM

RE: [ActiveDir] AD Lag Site

2005-10-26 Thread Ulf B. Simon-Weidner
uot;? Is it a site that you don't replicate for a |specific period of time in so if there is a disaster, you can |get the data from the lag site?? | |Thanks | |Russ | | | |From: [EMAIL PROTECTED] |[mailto:[EMAIL PROTECTED] On Behalf Of Ulf |B. Sim

RE: [ActiveDir] AD Lag Site -> solves the groups memberships issue ?

2005-10-26 Thread Ulf B. Simon-Weidner
//support.microsoft.com/default.aspx?scid=kb;en-us;840001> http://support.microsoft.com/default.aspx?scid=kb;en-us;840001) in order to repopulate the group memberships information (member and memberof attributes). Yann _ De: [EMAIL PROTECTED] de la part de Ulf B. Simon-Weidner D

RE: [ActiveDir] NT enumeration

2005-11-01 Thread Ulf B. Simon-Weidner
3. IIRC W2k and XP has a password age of 30 days, NT4 of 15 days. The Clients usually start to attempt to renew the password after half of the password age, so 7,5-15 on NT and 15-30 on W2k+.   Ulf From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Tom KernSent: Tues

RE: [ActiveDir] Crashed Root DC HELP!

2005-11-02 Thread Ulf B. Simon-Weidner
Hello Nathaniel, What about the last known good bootoption (might work if you experience the bsod before logon)? Any other possibilities like save boot? If one of these work you can try to find the failing device, and get rid of the driver / whatever it needs to get it working again. What about ch

RE: [ActiveDir] Reset Domain Admin Password in Windows Server 2003 AD

2005-11-04 Thread Ulf B. Simon-Weidner
That was working with W2k, doesn't work anymore since the screensaver has lower priviledges in XP, WS2k3. From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Ken CornetetSent: Friday, November 04, 2005 6:41 PMTo: ActiveDir@mail.activedir.orgSubject: RE: [ActiveDir]

RE: [ActiveDir] Certificate Services & AD

2005-11-06 Thread Ulf B. Simon-Weidner
Hello Devan, The book Ken references is pretty good, the author, Brian Komar, did a lot of PKI-Deployment at major companies across the US and the world, is a visiting speaker at a lot of conferences like TechEds and is MVP for Windows Security. His company is specialized in PKI-Deployments. He a

RE: [ActiveDir] Incorporating external users.......

2005-11-08 Thread Ulf B. Simon-Weidner
> [mailto:[EMAIL PROTECTED] On Behalf Of Susan > Bradley, CPA aka Ebitz - SBS Rocks [MVP] > > Windows 2003 r2 Enterprise [not standard] [and not a free upgrade] > Excepting for customers with Software Assurance, and you only need the enterprise version on the Federation Servers and Federation

[ActiveDir] Netlogon.dns (2)

2005-11-08 Thread Ulf B. Simon-Weidner
ere this might come from and if anyone has seen it before. Gruesse - Sincerely, Ulf B. Simon-Weidner   MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz  Weblog: http://msmvps.org/UlfBSimonWeidner  Website: http://www.windowsserverfaq.org  

RE: [ActiveDir] Netlogon.dns (2)

2005-11-08 Thread Ulf B. Simon-Weidner
DCs were W2k SP4. Anyone seen this before? OK - I've already fixed it by renaming netlogon.dns and restarting netlogon, but I'm curious if anyone has ideas where this might come from and if anyone has seen it before. Gruesse - Sincerely, Ulf B. Simon-Weidner   MVP-Book &

RE: [ActiveDir] Netlogon.dns (2)

2005-11-08 Thread Ulf B. Simon-Weidner
nyone has ideas where this might come from and if anyone has seen it before. Gruesse - Sincerely, Ulf B. Simon-Weidner   MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz  Weblog: http://msmvps.org/UlfBSimonWeidner  Website: http://www.windowsserverfaq.org  

RE: [ActiveDir] Improving your AD's fault tolerance with old hardware?

2005-11-08 Thread Ulf B. Simon-Weidner
Hi Danny, I also agree that using not state-of-the-art hardware is better than missing redundancy. I've done multiple lag-site dcs virtualized on one physical hardware, used clients or virtual machines for domain migrations as the update server, and would also recommend to use better older har

RE: [ActiveDir] Export Users in a group

2005-11-14 Thread Ulf B. Simon-Weidner
Title: Export Users in a group You can do this easily with dsget group cn=groupdn.. -members   Ulf From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Mark OrlandoSent: Monday, November 14, 2005 4:27 PMTo: Active Directory Mailing ListSubject: [ActiveDir] Export Use

RE: [ActiveDir] Query out all user members in nested groups

2005-11-25 Thread Ulf B. Simon-Weidner
dsquery group domainroot -name mygroup | dsget group -members Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz Weblog: http://msmvps.org/UlfBSimonWeidner Website: http://www.windowsserverfaq.org Pro

RE: [ActiveDir] Query out all user members in nested groups

2005-11-25 Thread Ulf B. Simon-Weidner
ards, | |Martin | |-Original Message- |From: [EMAIL PROTECTED] [mailto:ActiveDir- |[EMAIL PROTECTED] On Behalf Of Tomasz Onyszko |Sent: Friday, November 25, 2005 1:06 PM |To: ActiveDir@mail.activedir.org |Subject: Re: [ActiveDir] Query out all user members in nested groups | |Ulf B. Simon-Weidn

RE: [ActiveDir] How to restrict .exe file copy on my local exchange server

2005-11-27 Thread Ulf B. Simon-Weidner
to the system folder I’d be very careful and test it prior to implementation. Also be aware that you need to disable the file screening policy every time you are deploying an update or servicepack or when you are installing new components.   Gruesse - Sincerely, Ulf B. Simon-Weidner   MVP

RE: [ActiveDir] Tombstone value

2005-11-27 Thread Ulf B. Simon-Weidner
Hi Susan, I've seen issues with tombstones sitting around, such as bad written software who still sees them. The main other reason for finally getting rid of the tombstones is to free Active Directory space, but that shouldn't be an issue in a SBS-Domain. On the other hand I do not see the need in

RE: [ActiveDir] Disabling "Distributed Link Tracking Server" on domain Controllers

2005-11-28 Thread Ulf B. Simon-Weidner
So they don't age out if you disable the DLT-S-S, only if you stop the DLT-C-S and let the DLT-S-S run for another 90 days. Hmm - thinking if it wouldn't be neat to use dynamic objects for DLT (and DNS?) Ulf |-Original Message- |From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf

RE: [ActiveDir] Preventing local admin from rebooting servers

2005-11-28 Thread Ulf B. Simon-Weidner
If you want somehow prevent admins from rebooting the system remove them from the local security setting which enables them to shutdown the system.   Note: the other group joe mentioned is created so you can controll who’s able to shutdown the system (such as domain admins) Note 2: the a

RE: [ActiveDir] Saved Query for Distinguished Name Contains

2005-12-05 Thread Ulf B. Simon-Weidner
Hi Dan,   as joe said you can also modify the search base, so when creating the saved query select the seach base (it’s on the first screen of the dialog which let’s you add a saved query, not in the definition of the query itself). Sorry – don’t have the interface in front of me so I’m n

RE: [ActiveDir] Getting computer name from a username

2005-12-06 Thread Ulf B. Simon-Weidner
Hello Shane, look at psloggedon from www.sysinternals.com, this might help you. Ulf |-Original Message- |From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Shane De Jager |Sent: Thursday, December 01, 2005 10:50 AM |To: ActiveDir@mail.activedir.org |Subject: [ActiveDir] Getti

RE: [ActiveDir] Delegate disable/enable user accounts

2005-12-06 Thread Ulf B. Simon-Weidner
, Ulf B. Simon-Weidner MVP-Book "Windows XP - Die Expertentipps": <http://tinyurl.com/44zcz> http://tinyurl.com/44zcz Weblog: <http://msmvps.org/UlfBSimonWeidner> http://msmvps.org/UlfBSimonWeidner Website: <http://www.windowsserverfaq.org> http://www.windowss

RE: [ActiveDir] Domain case

2005-12-08 Thread Ulf B. Simon-Weidner
nobody knows or would be willing to support this. Theoretically changing the name to lowercase shouldn’t influence anything, but is anyone really sure that there’s no application or process who relies on the same domain name and does not a unsensitive case compare?   Gruesse - Sincerely, Ulf B

RE: [ActiveDir] Help with VB script to map printers

2005-12-08 Thread Ulf B. Simon-Weidner
need to run one command in your startup and logon-scripts to make the clients aware of that policy.   Gruesse - Sincerely, Ulf B. Simon-Weidner   MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz   Weblog: http://msmvps.org/UlfBSimonWeidner   Web

RE: [ActiveDir] Time Service

2005-12-28 Thread Ulf B. Simon-Weidner
32time using net stop w32time && net start w32time Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book "Windows XP - Die Expertentipps": <http://tinyurl.com/44zcz> http://tinyurl.com/44zcz Weblog: <http://msmvps.org/UlfBSimonWeidner> http://msmvps.org/UlfBSim

RE: [ActiveDir] Urgently Yes or No

2005-12-31 Thread Ulf B. Simon-Weidner
William.   Gruesse - Sincerely, Ulf B. Simon-Weidner   MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz   Weblog: http://msmvps.org/UlfBSimonWeidner   Website: http://www.windowsserverfaq.org   Profile:   http://mvp.support.microsoft.com/profile="">

RE: Re: [ActiveDir] icmp's

2006-01-02 Thread Ulf B. Simon-Weidner
Cool – Darren is blogging.   And already in OPML-o-Matter: http://msmvps.com/blogs/ulfbsimonweidner/archive/2005/12/30/80015.aspx Gruesse - Sincerely, Ulf B. Simon-Weidner   MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz   Weblog: http://

RE: [ActiveDir] Enable Windows Integrated Authentication through GPO

2006-01-04 Thread Ulf B. Simon-Weidner
enabling it for “Trusted Sites” or other Zones which are outside your DMZ.   Gruesse - Sincerely, Ulf B. Simon-Weidner   MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz   Weblog: http://msmvps.org/UlfBSimonWeidner   Website: http://www.windowsserverfaq.org

RE: [ActiveDir] OT: Request for Test AD Poplulation Data

2006-01-04 Thread Ulf B. Simon-Weidner
d a OU-Structure out of these), and if you need more you can also take the list of firstnames and lastnames and create more sample users. Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz Weblog: http://msmvps.org/Ul

RE: [ActiveDir] DCs generating SRV records for 2 sites!?

2006-01-04 Thread Ulf B. Simon-Weidner
?q=%22automatic+site+coverage%22+%2Bsite%3Amicrosoft.com&FORM=QBRE Gruesse - Sincerely, Ulf B. Simon-Weidner   MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz   Weblog: http://msmvps.org/UlfBSimonWeidner   Website: http://www.windowsserverfaq.org   P

RE: [ActiveDir] Enable Windows Integrated Authentication through GPO

2006-01-04 Thread Ulf B. Simon-Weidner
that users don’t have the rights to change them again.   Gruesse - Sincerely, Ulf B. Simon-Weidner   MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz   Weblog: http://msmvps.org/UlfBSimonWeidner   Website: http://www.windowsserverfaq.org   Profi

RE: [ActiveDir] OT: DEC 2006

2006-01-05 Thread Ulf B. Simon-Weidner
I’ll be there. I’m looking forward to meet everyone (again) – I love those Conferences with a lot of community interaction!   Gruesse - Sincerely, Ulf B. Simon-Weidner   MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz   Weblog: http://msmvps.org/UlfBSi

RE: [ActiveDir] OT: DEC 2006

2006-01-05 Thread Ulf B. Simon-Weidner
ption")!!   Kat Collins   On 1/5/06, Ulf B. Simon-Weidner <[EMAIL PROTECTED]> wrote: I'll be there. I'm looking forward to meet everyone (again) – I love those Conferences with a lot of community interaction!   Gruesse - Sincerely, Ulf B. Simon-Weidner  

RE: [ActiveDir] OT: DEC 2006

2006-01-06 Thread Ulf B. Simon-Weidner
– bummer. Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book "Windows XP - Die Expertentipps": <http://tinyurl.com/44zcz> http://tinyurl.com/44zcz Weblog: <http://msmvps.org/UlfBSimonWeidner> http://msmvps.org/UlfBSimonWeidner Website: <http://www.w

RE: [ActiveDir] OT: DEC 2006

2006-01-06 Thread Ulf B. Simon-Weidner
areas of the hotels.   Hope that Vegas is a more fun place – in Orlando they were shutting everything down at 1am, in Barcelona at least the Hilton did the same.   Gruesse - Sincerely, Ulf B. Simon-Weidner   MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz   We

RE: [ActiveDir] USB Detection in my Network

2006-01-07 Thread Ulf B. Simon-Weidner
27;USBSTOR'",,48) Background: USBStor is the device which takes care that USB-Memory-Devices such as a thubdrive are working. Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz Weblog: http://msmvps.org/UlfBSimonW

RE: [ActiveDir] ADUC updates - Was Expired Accounts

2006-01-13 Thread Ulf B. Simon-Weidner
roperty of the next user (Or Enter / Arrow-right for the next attribute of the same user). Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz Weblog: http://msmvps.org/UlfBSimonWeidner Website: http://www.windowsserverfaq

RE: [ActiveDir] Multiple Password Policies

2006-01-22 Thread Ulf B. Simon-Weidner
didn’t take care of the issues mentioned above since I don’t know that for sure, however those are the things I’d check before implementing them into a production environment I’m responsible for.   Gruesse - Sincerely, Ulf B. Simon-Weidner   MVP-Book "Windows XP - Die Expertentipps&q

RE: [ActiveDir] OT: speaking of AD books...

2006-01-23 Thread Ulf B. Simon-Weidner
Don't search for the book - search for yourself: "Joe Richards" "Active Directory" ... gets you straight to your book. Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz Weblog: http://msmvps.o

RE: [ActiveDir] OT: Gauging AD experience

2006-01-27 Thread Ulf B. Simon-Weidner
Agreed – multi mon rocks – I’d never go without again!   Other than that I stripped everything down – I’m mainly using my favorite laptop (Tablet) but got another one sitting around, one desktop which I’m rarely using (mainly for larger downloads or processing I don’t want to bother my ma

RE: [ActiveDir] DC II

2006-01-27 Thread Ulf B. Simon-Weidner
AFAIK the clients will first contact the last DC which is stored in the registry, this DC will verify their IP with the site-informations stored in AD. He will reply the sites DCs to the client in the NetlogonEx-Packet, and the client will try to contact one of these. Note that the client may retri

RE: [ActiveDir] Permissions are resetting

2006-02-01 Thread Ulf B. Simon-Weidner
See http://msmvps.com/blogs/ulfbsimonweidner/archive/2005/05/29/49659.aspx   Ulf   From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Aguilar, Louis Sent: Wednesday, February 01, 2006 11:06 PM To: ActiveDir@mail.activedir.org Subject: [ActiveDir] Permissions are res

RE: [ActiveDir] Script to change owner?

2006-02-01 Thread Ulf B. Simon-Weidner
wOwner   objAD.Put "ntSecurityDescriptor", Array(objSD)objAD.SetInfo     There might be some settings or commands missing (for example you can set how/what should be updated by using objAD.SetOption ), but it should work as a starting point for you. Gruesse - Sincerely, Ulf B. Simon-We

RE: [ActiveDir] OT: Roaming Profiles

2006-02-03 Thread Ulf B. Simon-Weidner
Hi Frank,   with those large roaming profiles you need to 1. educate your users 2. question the use of roaming profiles   In fact I've seen a lot of companies who tend to stick to local only profiles in the recent past. Roaming profiles are great - however I see them in infrastructures where

RE: [ActiveDir] OT: Roaming Profiles

2006-02-03 Thread Ulf B. Simon-Weidner
would be a good start.   thanks   Frank   Ulf - you are not the first to mention Carl Hanratty, you won't be the last!"Ulf B. Simon-Weidner" <[EMAIL PROTECTED]> wrote: Hi Frank,   with those large roaming profiles you need to 1.

RE: [ActiveDir] Getting better control over DHCP

2006-02-04 Thread Ulf B. Simon-Weidner
or a meeting or presentation can have network access and VPN into his own company if needed, and your employees are also able to gain access and VPN into their company. Gruesse - Sincerely, Ulf B. Simon-Weidner P.S.: Not directed to you Brian, but to the others. This post just fits here after

RE: [ActiveDir] Schema Extension

2006-02-06 Thread Ulf B. Simon-Weidner
ted attributes like MapiIDs or LinkIDs? You are able to change them, but not supported. However PSS will tell you how to do it if you need it.   [1] want to see your custom attributes in the GAL? Welcome to the world of MapiIds ;-) Gruesse - Sincerely, Ulf B. Simon-Weidner   MVP-Book "Win

RE: [ActiveDir] DNS Restart

2006-02-06 Thread Ulf B. Simon-Weidner
If you want a single command line which only starts if it stopped correctly ...   net stop dns && net start dns   ;-)   (sorry - couldn't resist)   From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of joeSent: Tuesday, February 07, 2006 12:57 AMTo: ActiveDir@mail.act

RE: [ActiveDir] Schema Extension

2006-02-08 Thread Ulf B. Simon-Weidner
Go for it   Redundant Disks for the OS + AD: First suggestion with 1-6, but instead of backup pull and resync disks.   Gruesse - Sincerely, Ulf B. Simon-Weidner   MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz  Weblog: http://msmvps.org/UlfBSimonWe

RE: [ActiveDir] Schema Extension

2006-02-08 Thread Ulf B. Simon-Weidner
hema extension". Gruesse - Sincerely, Ulf B. Simon-Weidner   MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz  Weblog: http://msmvps.org/UlfBSimonWeidner  Website: http://www.windowsserverfaq.org  Profile:   http://mvp.support.microsoft.com/profile="&quo

RE: [ActiveDir] Schema Extension

2006-02-08 Thread Ulf B. Simon-Weidner
Hm - you're right - don't write tired and exhausted. Seize it and clean the old one out of AD. Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz Weblog: http://msmvps.org/UlfBSimonWei

RE: [ActiveDir] Schema Extension

2006-02-09 Thread Ulf B. Simon-Weidner
s. However I'm always curious for other suggestions ;-) Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz Weblog: http://msmvps.org/UlfBSimonWeidner Website: http://www.windowsserverfaq.org Profile: http://mvp.sup

RE: [ActiveDir] Schema Extension

2006-02-09 Thread Ulf B. Simon-Weidner
esult will always be a non-updated schema. Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz Weblog: http://msmvps.org/UlfBSimonWeidner Website: http://www.windowsserverfaq.org Profile: http://mvp.support.microsoft.

RE: [ActiveDir] NTDS.DIT Size

2006-06-29 Thread Ulf B. Simon-Weidner
on x64 will perform better than on 32-bit, since it’s very likely you already have some of the newer servers with x64 I’d just give it a try for one DC yourself.   Gruesse - Sincerely, Ulf B. Simon-Weidner   Profile & Publications:   http://mvp.support.microsoft.com/profile=""

RE: [ActiveDir] Vendor Domain

2006-07-23 Thread Ulf B. Simon-Weidner
different domain or even forest to manage them, or want to know very closely what the requirements are and keep an extra eye on those machines. Don’t put lives at jeopardy b/c of a misconfigured GPO.   Gruesse - Sincerely, Ulf B. Simon-Weidner   Profile & Publications:   

RE: [ActiveDir] ldp in ADAM-SP1

2006-08-04 Thread Ulf B. Simon-Weidner
Hi Dmitri, And DSAcls still does not display a computer accounts ACL if someone was being delegated permission to join a computer to this account using ADUC: http://www.windowsserverfaq.org/faq/CompACLs.asp Gruesse - Sincerely, Ulf B. Simon-Weidner Profile & Publications:

RE: [ActiveDir] ldp in ADAM-SP1

2006-09-30 Thread Ulf B. Simon-Weidner
Just stepped across this - thanks for fixing it! Ulf -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Ulf B. Simon-Weidner Sent: Freitag, 4. August 2006 09:26 To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] ldp in ADAM-SP1 Hi Dmitri, And

RE: [ActiveDir] Delegate VPN rights

2006-11-30 Thread Ulf B. Simon-Weidner
nTab.asp Gruesse - Sincerely, Ulf B. Simon-Weidner Profile & Publications: http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F 2F1214C811D> http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F2F1214C811 D Weblog: http://msmvps.org/UlfBSimo

RE: [ActiveDir] Delegate VPN rights

2006-12-03 Thread Ulf B. Simon-Weidner
user you can use ldp\script etc.. to set the msNPAllowDialin == true. It should reflect properly in ADUC when you next view that user.. spat - Original Message - From: Ulf B. Simon-Weidner <mailto:[EMAIL PROTECTED]> To: ActiveDir@mail.activedir.org Sent: Thursday,

RE: [ActiveDir] AD Schema Extensions and Exchange System Manager

2006-12-18 Thread Ulf B. Simon-Weidner
ge from MS that this is respected. Gruesse - Sincerely, Ulf B. Simon-Weidner Profile & Publications: http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F 2F1214C811D> http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F2F1214C811 D Weblog:

RE: [ActiveDir] Quest Recovery Manager

2007-01-21 Thread Ulf B. Simon-Weidner
: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Ulf B. Simon-Weidner Sent: 10 December 2006 12:06 To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] Quest Recovery Manager I do disagree since we might have other withes, issues, possibilities with Longhorn, so I'd wait when sp

RE: [ActiveDir] release date for W2K3/SP2?

2007-01-21 Thread Ulf B. Simon-Weidner
I can't remember exactly, but I think I've heard a Q1 at one of the conferences last year. IIRC. Gruesse - Sincerely, Ulf B. Simon-Weidner Profile & Publications: http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F 2F1214C811D> http://mvp.support.micr

RE: [ActiveDir] AdminSDHolder orphans

2007-01-21 Thread Ulf B. Simon-Weidner
he inheritance flag would be complicated, but it's complicated to generalize that it should be reset in any case. Gruesse - Sincerely, Ulf B. Simon-Weidner   Profile & Publications:   http://mvp.support.microsoft.com/profile=35E388DE-4885-4308- B489-F2F1214C811D     

RE: [ActiveDir] AdminSDHolder orphans

2007-01-21 Thread Ulf B. Simon-Weidner
Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Ulf B. Simon-Weidner Sent: Monday, 22 January 2007 11:32 a.m. To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] AdminSDHolder orphans Hi Tony, late response as well - sorry. I guess why this isn't cleane

RE: [ActiveDir] Question about DNS SRV registration.

2007-01-23 Thread Ulf B. Simon-Weidner
DC A in Site B, however make sure that you are only deleting the SRV-Records underneath the DNS-Subdomains of the Site-specific Records in the “Site B”-DNS-Domains (looks like folders in the DNS Managementconsole). Gruesse - Sincerely, Ulf B. Simon-Weidner Profile & Publications:

RE: RE: [ActiveDir] Question about DNS SRV registration.

2007-01-24 Thread Ulf B. Simon-Weidner
in controller policy). So it seems that DCa is still advertising himself as DC in site B. I will look why the process does not work in our case... :( We did not configured automatic aging/scavenging, i will look also into this option. Thanks again, Yann "Ulf B. Simon-Weidner"

RE: RE: RE: [ActiveDir] Question about DNS SRV registration.

2007-01-24 Thread Ulf B. Simon-Weidner
approaching ;-) ). Gruesse - Sincerely, Ulf B. Simon-Weidner Profile & Publications: http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F 2F1214C811D> http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F2F1214C811 D Weblog: http://msmvps.org/UlfBSimon

RE: [ActiveDir] [OT] Odd Folder under Forward Lookup Zone

2007-01-24 Thread Ulf B. Simon-Weidner
created manually, you might just recreate it without a .1 at the end (test this and verify the printers name), if it was registered automatically you need to change the name of the printer. Gruesse - Sincerely, Ulf B. Simon-Weidner Profile & Publications: http://mvp.supp

RE: [ActiveDir] [OT] Odd Folder under Forward Lookup Zone

2007-01-24 Thread Ulf B. Simon-Weidner
No Zone – no properties ;-) From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Al Mulnick Sent: Mittwoch, 24. Januar 2007 20:24 To: ActiveDir@mail.activedir.org Subject: Re: [ActiveDir] [OT] Odd Folder under Forward Lookup Zone What are properties of the 1 zone? On 1/24/07, EI

RE: [ActiveDir] ftp access

2007-01-24 Thread Ulf B. Simon-Weidner
urity Options And is named Interactive logon: Prompt user to change password before expiration Just a guess. Gruesse - Sincerely, Ulf B. Simon-Weidner Profile & Publications: http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F 2F1214C811D> http://mvp.support.m

RE: [ActiveDir] [OT] Odd Folder under Forward Lookup Zone

2007-01-24 Thread Ulf B. Simon-Weidner
things? See you in March? Gruesse - Sincerely, Ulf B. Simon-Weidner Profile & Publications: http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F2F1214C811D> http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F2F1214C811D Weblog: http://msm

RE: [ActiveDir] [OT] Odd Folder under Forward Lookup Zone

2007-01-24 Thread Ulf B. Simon-Weidner
sure it was someone (probably me!) just typed a .1 in some setting on the printer and allowed it to register in DNS. Many thanks. -- nme Noah Eiger _ From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Ulf B. Simon-Weidner Sent: Wednesday, January 24, 2007 12:29

RE: [ActiveDir] OT: maintaining "creation date" when copying directories?

2007-01-25 Thread Ulf B. Simon-Weidner
Robocopy with the /B-Switch should work. Ulf From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M. Sent: Donnerstag, 25. Januar 2007 13:10 To: ActiveDir@mail.activedir.org Subject: [ActiveDir] OT: maintaining "creation date" when copying directories? What "m

RE: [ActiveDir] [OT] Odd Folder under Forward Lookup Zone

2007-01-25 Thread Ulf B. Simon-Weidner
Many thanks. -- nme Noah Eiger _ From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Ulf B. Simon-Weidner Sent: Wednesday, January 24, 2007 12:29 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] [OT] Odd Folder under Forward Lookup Zone Just 9:30

RE: [ActiveDir] OT: maintaining "creation date" when copying directories?

2007-01-25 Thread Ulf B. Simon-Weidner
Weird. Gruesse - Sincerely, Ulf B. Simon-Weidner Profile & Publications: http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F 2F1214C811D> http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F2F1214C811 D Weblog: http://msmvps.org/UlfBSimonWeidner> ht

RE: [ActiveDir] How to find non-primary SMTP addresses?

2007-01-25 Thread Ulf B. Simon-Weidner
Hi Stu, I don't think there's a way to expose mulitvalued attributes with CSVDE - you'd either have to use LDIFDE or VBScript or anything else to view all values of those attributes. Gruesse - Sincerely, Ulf B. Simon-Weidner Profile & Publications: http://mvp.su

RE: [ActiveDir] OT: maintaining "creation date" when copying directories?

2007-01-25 Thread Ulf B. Simon-Weidner
the trick. Thanks for bringing this up so I had to look into it - I'll blog this since it's a very interesting change. Gruesse - Sincerely, Ulf B. Simon-Weidner Profile & Publications: http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F 2F1214C811D> http://mvp.su

RE: [ActiveDir] Disable CD ROM through GP

2007-01-27 Thread Ulf B. Simon-Weidner
OU, site) where you linked the GPO. Gruesse - Sincerely, Ulf B. Simon-Weidner   Profile & Publications:   http://mvp.support.microsoft.com/profile=35E388DE-4885-4308- B489-F2F1214C811D      Weblog: http://msmvps.org/UlfBSimonWeidner   Website: http://www.windowsserverfaq.org -Original M

RE: [ActiveDir] Limit Logon thru GPO

2006-02-18 Thread Ulf B. Simon-Weidner
icy which allows logon only if homedir is available, however doing it in the logon-script works pretty well. Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz Weblog: http://msmvps.org/UlfBSimonWeidner Website: h

  1   2   3   >