RE: [ActiveDir] Active Directory Log

2002-11-06 Thread David N. Precht
Title: Message http://www.sunbelt-software.com/product.cfm?id=871 could be part of the solution -Original Message-From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] On Behalf Of Jones, Rick J.(Desktop Engineering)Sent: Tuesday, November 05, 2002 22:37To: [EMAIL

RE: [ActiveDir] Biztalk

2002-11-06 Thread Salandra, Justin A.
I read that web page but can't make head and tails of what BizTalk will actually do for me. -Original Message- From: Sullivan, Kevin [mailto:KSullivan;aelita.com] Sent: Tuesday, November 05, 2002 4:24 PM To: [EMAIL PROTECTED] Subject:RE: [ActiveDir] Biztalk

RE: [ActiveDir] Biztalk

2002-11-06 Thread Roger Seielstad
What do you *want* it to do for you? -- Roger D. Seielstad - MCSE Sr. Systems Administrator Inovis - Formerly Harbinger and Extricity Atlanta, GA -Original Message- From: Salandra, Justin A. [mailto:jasalandra;chcsnet.org] Sent:

RE: [ActiveDir] Biztalk

2002-11-06 Thread Rick Kingslan
Point(s) taken. Thanks for the correction, Roger. I wasn't aware that EDI was still so 'alive and kicking'. Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone - www.microsoft.com/windowsxp/expertzone -Original Message- From: [EMAIL

[ActiveDir] Move computer within domain question....

2002-11-06 Thread cflesher
Title: Message I'm trying to delegate authority to a user to move computer objects from the Computers Containerto another OU. What permissions are required to do this? I gave the user create/delete computer objects for the Computer Container and create/delete computer objects for the target

RE: [ActiveDir] Biztalk

2002-11-06 Thread Salandra, Justin A.
I am just trying to understand basically what it does, I think that my CIO wants to use it as an interface between medical systems like IDX, Siemens and iMckesson. -Original Message- From: Roger Seielstad [mailto:roger.seielstad;inovis.com] Sent: Wednesday, November 06, 2002 9:56 AM

RE: [ActiveDir] Biztalk

2002-11-06 Thread Larry A. Duncan
These are all good points, but is this the platform for discussing BizTalk issues? Larry A. Duncan, MCSA/MCSE Directory Services Engineer/ Systems Management Consultant [EMAIL PROTECTED] ph. 615.598.0241 -Original Message- From: [EMAIL PROTECTED]

RE: [ActiveDir] Biztalk

2002-11-06 Thread Roger Seielstad
Trust me. I've got a million transactions a day of it running through our systems. ;) Its one of many things we do. -- Roger D. Seielstad - MCSE Sr. Systems Administrator Inovis - Formerly Harbinger and Extricity Atlanta, GA -Original

RE: [ActiveDir] IIS behind firewall

2002-11-06 Thread Rick Kingslan
Documents of interest: http://www.nsa.gov/snac/win2k/index.html (look for the guide on IIS, but IIS hardening is worthless unless the base OS is hardened as well) http://www.microsoft.com/technet/treeview/default.asp?url=/technet/secur ity/prodtech/windows/windows2000/staysecure/default.asp

RE: [ActiveDir] Move computer within domain question....

2002-11-06 Thread Rick Kingslan
Chris, You're likley going to have to give them Full Control on the Computer objects in the Advanced properties in the Computer Container and the target OU. You're not giving up much by giving them FC on a computer object - because if you want them to move it, they have to be able to delete it,

RE: [ActiveDir] Biztalk

2002-11-06 Thread Rick Kingslan
Probably not - and I agree. But there are a lot of off-topic issues that are discussed here, Larry. If Tony wants to stop it, I'd invite him to do so. I have no problems with the list owner killing a conversation. Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert

RE: [ActiveDir] Biztalk

2002-11-06 Thread Roger Seielstad
To some degree, yes. Its probably gone a bit off topic, however. Personally, I've been thinking about looking at Biztalk to manage Exchange/AD stuff. I'm thinking it would be relatively trivial to write some AD interfaces for Biztalk such that you can plug it into any of a number of HR packages

RE: [ActiveDir] Move computer within domain question....

2002-11-06 Thread cflesher
Thanks for the response. I'm not sure if that's a solution, though. If I have to manually give that right to each object in the Computers container, it sort of defeats the purpose of delegating out the authority. Is giving them full control over the Computers container itself the same thing? Can

RE: [ActiveDir] Move computer within domain question....

2002-11-06 Thread Rick Kingslan
Yes, you can delegate the permission at the Computers container level. As to the repurcussions - it could be worse. If the most damage one can do is to delete some computer accounts, then that's a mitigatable risk - given that the alternative is that they won't be able to move them. I wouldn't

[ActiveDir] which attribute to use for disabled account

2002-11-06 Thread pio eqbal
Hi, is there an attribute in the user class, that I can use in the LDAP query to find if the user account is disabled? If so what is the name of the attribute? Thanks Eqbal __ Do you Yahoo!? HotJobs - Search new jobs daily now

Re: [ActiveDir] which attribute to use for disabled account

2002-11-06 Thread Al Lilianstrom
pio eqbal wrote: Hi, is there an attribute in the user class, that I can use in the LDAP query to find if the user account is disabled? If so what is the name of the attribute? Look at userAccountcontrol. al -- Al Lilianstrom CD/OSS/CSI [EMAIL PROTECTED] List info :

RE: [ActiveDir] Move computer within domain question....

2002-11-06 Thread cflesher
Thank you, RickI'll let you know how it turns out. Chris Flesher The University of Chicago NSIT/DCS 1-773-834-8477 -Original Message- From: [EMAIL PROTECTED] [mailto:ActiveDir-owner;mail.activedir.org] On Behalf Of Rick Kingslan Sent: Wednesday, November 06, 2002 11:00 AM To: [EMAIL

RE: [ActiveDir] Active Directory Log

2002-11-06 Thread Jones, Rick J.(Desktop Engineering)
Title: Message Every System has a log within the registry! http://support.microsoft.com/default.aspx?scid=KB;EN-US;Q201453 Rick Jones -Original Message- From: David N. Precht [mailto:[EMAIL PROTECTED]] Sent: Wednesday, November 06, 2002 5:43 AM To: [EMAIL

RE: [ActiveDir] Unsuccessful Domain controller demotion.

2002-11-06 Thread STEVEN DANIELS
Hi all, We recently moved a domain controller to our test environment. We did this by bringing it up in live "unpluging from the network"and then using the information from KB Q216498 at http://support.microsoft.com/default.aspx?scid=KB;EN-US;Q216498. To remove the controller from AD But I'm

[ActiveDir] Unable to update public free / busy data.

2002-11-06 Thread Chris J. Popp
Has anyone gotten a error that says Unable to update public free / busy data ? I have only one user that is getting this error out of 20 in the AD. We are running W2K sp3 with Exchange 2000 SP3. Thanks, Chris List info : http://www.activedir.org/mail_list.htm List FAQ:

RE: [ActiveDir] IIS behind firewall

2002-11-06 Thread Ken Cornetet
Microsoft recommends using ISA server in the DMZ to proxy the HTTP to the IIS/OWA server. -Original Message- From: Garello, Kenneth [mailto:KGarello;worcester.edu] Sent: Wednesday, November 06, 2002 2:19 PM To: '[EMAIL PROTECTED]' Subject: RE: [ActiveDir] IIS behind firewall Rick,

RE: [ActiveDir] Unable to update public free / busy data.

2002-11-06 Thread Bryan Schlegel
http://support.microsoft.com/default.aspx?scid=KB;EN-US;Q223459; -Original Message- From: Chris J. Popp [mailto:chris.popp;sharpeengineering.com] Sent: Wednesday, November 06, 2002 3:55 PM To: [EMAIL PROTECTED] Subject: [ActiveDir] Unable to update public free / busy data. Has anyone

RE: [ActiveDir] IIS behind firewall

2002-11-06 Thread Rick Kingslan
Ken, OWA is a tough one - but it's not as bad as an IIS server. Primarily, most of IIS is shut off. OWA acts as a HTTP/HTTPS protocol front end to your back end message stores on the Exchange servers. Microsoft recommends having them on the internal network to alleviate all of the ports that

RE: [ActiveDir] stupid stupid question

2002-11-06 Thread Joe L. Casale
Am I the only one that doesn't understand WTF you are saying? Rephrase it maybe, I am confused... I follow until the installing nt4 part Where does that come in? Also, why would you need to install AD on the 2k server from an NT4 box? jlc -Original Message- From: Jennifer Fountain

RE: [ActiveDir] which attribute to use for disabled account

2002-11-06 Thread Sullivan, Kevin
How about this... Option Explicit Dim objUser Dim objAccountDisabled Set objUser = GetObject(LDAP://CN=User,DC=Domain,DC=MSFT;) If objUser.AccountDisabled = True Then objAccountDisabled = Yes Else objAccountDisabled = No End If WScript.Echo objAccountDisabled