Re: [ActiveDir] Checking who deleted Files

2005-04-22 Thread Peter Jessop
More specifically: To detect file deletion you must audit Succesful object access. Additionally you must then enable auditing on the folders by means of the security tab. You must then look for securiy events with ID 560. The following is a query you can use with logparser to extract the delete

RE: [ActiveDir] Native Mode Switch

2005-04-22 Thread Nicolas Blank
Perfect sense, thank for the reply. Understand about Lanman rep to downlevel versions. What effect would it have if a DC was authorativelly restored pre native mode and the other dc's were native mode? This presumes no group nesting had taken place. On the DC, the built in groups (scema admin,

RE: [ActiveDir] Native Mode Switch

2005-04-22 Thread Jorge de Almeida Pinto
Good question! That would not work... Why? With NTDSUTIL you have the following options: ? - Show this help information Help - Show this help information List NC CRs - Lists Partitions and cross-refs. You need

RE: [ActiveDir] Native Mode Switch

2005-04-22 Thread Grillenmeier, Guido
Hey Nicolas - how is life is South Africa? I see Jorge has basically touched all aspects of why you'd want to prepare for a forest DR, if you really want to undo the switch to native mode of a Win2k domain. He's even given you a usable workaround to test just that business critical SNA

Re: [ActiveDir] IPsec policy

2005-04-22 Thread Dennis Depp
Windows IPSEC policies are applied based on IP addresses. You could possibly do this per user if you had a batch file that would create and resind the IPSEC policy. You could then apply the IPSEC policy in a logon script and remove it in a log off script. Dennis On 4/21/05, Kern, Tom [EMAIL

RE: [ActiveDir] Native Mode Switch

2005-04-22 Thread Beelders, Ivor
I would consider moving all the FSMO roles to this DC. Then doing a P2V snapshot of this DC with VM. Bring up the VM on a machine not connected to the live network and then doing the native mode switch as a Proof of Concept before doing it in the live environment. Ivor Beelders Global Directory

RE: [ActiveDir] GC's

2005-04-22 Thread Bernard, Aric
Tom, Most likely the reason that MS instructed them to remove the GC role from all the DCs, only later to re-enable the role, as well as the answer to your question around why would these deleted objects show up on a GC is lingering objects. Basically a lingering object is an object that has

Re: [ActiveDir] Export and import essential AD objects for new forest

2005-04-22 Thread Danny
Thank you all for your most helpful responses! You guys are fantastic. Specifically: Jose Medeiros, Ken Jensen, and Ken Cornentet. Due to time constraints, I think I am going to go with the swing method, so here is my proposed plan of attack: Temp Server/ Server B: 1) Install Windows Server

[ActiveDir] How can I see which processes an XP machine is running?

2005-04-22 Thread Jason B
We have an XP machine on our network that is running automated queries on a search engine. Is there a way that I can see which processes/programs this PC is running without the user knowing?

[ActiveDir] GPO errors on logon

2005-04-22 Thread Bruyere, Michel
Hi, I have 2 laptops that have the same problem. They are very slow to logon the domain and they generates the following events: Event Type: Error Event Source: Userenv Event Category: None Event ID: 1030 Date: 4/22/2005 Time: 3:55:08 PM User:

[ActiveDir] Windows 2003 setings

2005-04-22 Thread Kern, Tom
I forgot, but where are the settings kept in AD where you can see if forest/domain prep has been run and which domain/forest functional level a domain/forest is on? thanks List info : http://www.activedir.org/List.aspx List FAQ: http://www.activedir.org/ListFAQ.aspx List archive:

Re: [ActiveDir] Export and import essential AD objects for new forest

2005-04-22 Thread Danny
One follow-up to my last post: Should I be transferring or seizing the FSMO roles during this migration? Thank you, ...D List info : http://www.activedir.org/List.aspx List FAQ: http://www.activedir.org/ListFAQ.aspx List archive:

RE: [ActiveDir] Windows 2003 setings

2005-04-22 Thread Grillenmeier, Guido
to check prep ADPREP /FORESTPREP cn=forest name cn=Configuration cn=ForestUpdates cn=windows2003update ADPREP /DOMAINPREP cn=domain name cn=SYSTEM cn=DomainUpdates cn=Windows2003Update to

RE: [ActiveDir] Windows 2003 setings

2005-04-22 Thread Kern, Tom
I have the windows2003update folder in both the config and domain NC, but its empty. What does that mean? Thanks Grillenmeier, Guido wrote: to check prep ADPREP /FORESTPREP cn=forest name cn=Configuration cn=ForestUpdates cn=windows2003update

RE: [ActiveDir] Export and import essential AD objects for new forest

2005-04-22 Thread Oliver Ryf
Just for those able to speak German (all others can you babblefish ;). Nils Kaczenski wrote some nice tools to get around most of the problems of exporting and importing AD information with CSVDE.EXE, ie an Excel Makro that adds the around DNs (they get lost while importing the CSV-File in

RE: [ActiveDir] How can I see which processes an XP machine is running?

2005-04-22 Thread Charlie Kaiser
Check out PSTools... http://www.sysinternals.com/ntw2k/freeware/pstools.shtml Dameware utilities will do similar stuff. I'm sure there are other tools that do the same... You can query and view a lot of stuff on remote machines. As far as doing it stealthily? That depends on how tightly the

RE: [ActiveDir] Windows 2003 setings

2005-04-22 Thread Kern, Tom
Reading the rootDSE, I get - 1 domainFunctionality: 0; 1 forestFunctionality: 0; 1 domainControllerFunctionality: 2; Grillenmeier, Guido wrote: to check prep ADPREP /FORESTPREP cn=forest name cn=Configuration cn=ForestUpdates

RE: [ActiveDir] Windows 2003 setings

2005-04-22 Thread Grillenmeier, Guido
that's a perfectly valid state: this is a Windows 2003 DC (DC functionality = 2) in a domain that's still running at Win2000 mixed or native functional level (0) and a forest that's running at Win2000 functional level (0). Naturally, the DC won't turn on certain features (e.g. LVR) prior to the

RE: [ActiveDir] Windows 2003 setings

2005-04-22 Thread Eric Fleischman
I would point out.the presence of the objects Guido cited does not say that forest/domain prep has been run, it says it completed successfully. If you ran forest/domain prep and it failed, that object would not be present, but instead you'd only have the operational GUIDs for each of the

Re: [ActiveDir] Export and import essential AD objects for new forest

2005-04-22 Thread Glenn Corbett
Transfer the roles, since the existing domain contoller will be running during this pricess (ie, before you dcpromo it out). G. Danny wrote: One follow-up to my last post: Should I be transferring or seizing the FSMO roles during this migration? Thank you, ...D List info :

RE: [ActiveDir] Export and import essential AD objects for new forest

2005-04-22 Thread Medeiros, Jose
Danny, You will need to seize ( Not Transfer ) the roles on the new DC once it is disconnected from your production network. If you transfer your FSMO roles and then move the server to your test network, you will need to seize the roles on a another DC in your production network. Regards,