RE: [ActiveDir] Revoke domain administrator's right to create GPO?

2006-08-02 Thread Darren Mar-Elia
Alex- I think you've proved my point by saying, "having local admin rights is definitely a bad thing as far as security is concerned". :-). But of course you are pointing out the underlying dilemma that administrators have faced while trying to create a least-privileged user environment. Fra

RE: [ActiveDir] Moving Sysvol .

2006-08-08 Thread Darren Mar-Elia
Yea, I'm not sure why one has to do with the other (GPO delegation and security of the DIT). GPO delegation simply involves granting permissions on a individual GPC objects in AD and individual folders in the GPT (SYSVOL). The only risk I can see is that it is marginally easier to fill up a

RE: [ActiveDir] Moving Sysvol .

2006-08-08 Thread Darren Mar-Elia
much difference there on a 4 - 6 disk set -the argument is political to do with different standards for the management people.  But then, the SYSVOL volume is also a scratch area for administrators.  The DIT and OS volumes are very much off limits, and secured thus.     --Paul   - Original Mes

RE: [ActiveDir] machine GP load

2006-08-09 Thread Darren Mar-Elia
GPOs are not denied for some reason that you can control. If the component status shows that GP Infrastructure processing Failed, then its probably something other than the obvious and we can go from there.   Darren   Darren Mar-Elia For comprehensive Windows Group Policy Information, check out

RE: [ActiveDir] re: Computer bootup speeds

2006-08-09 Thread Darren Mar-Elia
There's lot of reasons for slow boot up, as folks have indicated. Enabling userenv logging and observing the time stamps will give you a clue as to whether its related to user profiles or group policy. Also, as per the network issues, check out http://support.microsoft.com/default.aspx?scid=k

RE: [ActiveDir] Computer bootup speeds

2006-08-09 Thread Darren Mar-Elia
That's a new one on me. Its kind of ironic because in Vista, the NLA service replaces ICMP slow link detection for GP processing...   Darren From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Rimmerman, RussSent: Wednesday, August 09, 2006 2:14 PMTo: ActiveDir@mail.activedir.o

RE: [ActiveDir] Computer bootup speeds

2006-08-09 Thread Darren Mar-Elia
Yes, good point Susan. NLA is used to let Windows know that a network connection state has changed. So if you're using Windows Firewall and have both domain and standard profiles, by disabling NLA, you prevent that state change from notifying the firewall that it may need to switch from one profile

Re: RE: [ActiveDir] Computer bootup speeds

2006-08-09 Thread Darren Mar-Elia
--- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] On Behalf Of Darren Mar-Elia > Sent: Wednesday, August 09, 2006 5:29 PM > To: ActiveDir@mail.activedir.org > Subject: RE: [ActiveDir] Computer bootup speeds > > Yes, good point Susan. NLA is used to let Windows know that a

Re: RE: [ActiveDir] Computer bootup speeds

2006-08-09 Thread Darren Mar-Elia
We aren't using Windows Firewall, we're using the firewall that comes > with our desktop antivirus solution. So I guess we're OK turning off > NLA (via GPO)? > > -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] On Behalf Of Darren Ma

RE: [ActiveDir] [OT] Longhorn Beta

2006-08-17 Thread Darren Mar-Elia
bit torrent? (just kidding) From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of WATSON, BENSent: Thursday, August 17, 2006 8:35 AMTo: ActiveDir@mail.activedir.orgSubject: [ActiveDir] [OT] Longhorn Beta Outside of my MSDN account is there a preferred way to obtain Longhorn Bet

RE: [ActiveDir] Viewing GPO processing

2006-08-21 Thread Darren Mar-Elia
operation described below. However, outside of that its trial and error to find why the operation is getting stopped. Darren Darren Mar-Elia For comprehensive Windows Group Policy Information, check out www.gpoguy.com-- the best source for GPO FAQs, video training, tools and whitepapers. Also

RE: [ActiveDir] Viewing GPO processing

2006-08-21 Thread Darren Mar-Elia
one policy item at a time until you find the problematic one. Darren Darren Mar-Elia For comprehensive Windows Group Policy Information, check out www.gpoguy.com-- the best source for GPO FAQs, video training, tools and whitepapers. Also check out the Windows Group Policy Guide, the definitive resou

Re: [ActiveDir] Active Directory Delegation & Management tools...

2006-08-23 Thread Darren Mar-Elia
James- Its been a while, but since it was my job to know this stuff, I can give you some general comments here. First off, its important to know your requiirements before asking the various vendors how they can help. What do you need to manage AD here? One thing I can tell you about the Scriptlo

RE: [ActiveDir] Active Directory Delegation & Management tools...

2006-08-23 Thread Darren Mar-Elia
FI.  We're also considering ScriptLogic, Quest, NetIQ and NetPro.   Teo  On 8/23/06, Darren Mar-Elia <[EMAIL PROTECTED]> wrote: James-Its been a while, but since it was my job to know this stuff, I can give you some general comments here. First off, its important to know your

RE: [ActiveDir] management of group policy links (GPMC)

2006-08-23 Thread Darren Mar-Elia
Graham- The Inheritance and Delegation tabs (when you're sitting on a container object like an OU in GPMC) provides the information indicated below. I guess I'm wondering what you're missing from that? Its true that GPMC backup/restore does not restore links, link order or Enforced flags, but there

RE: [ActiveDir] adm file management

2006-09-06 Thread Darren Mar-Elia
"Supported" tags in the newer ADMs. Darren Darren Mar-Elia For comprehensive Windows Group Policy Information, check out www.gpoguy.com-- the best source for GPO FAQs, video training, tools and whitepapers. Also check out the Windows Group Policy Guide, the definitive resource for Gr

RE: [ActiveDir] adm file management

2006-09-06 Thread Darren Mar-Elia
> etc. And it is definitely best to manage such a mixed environment from > the latest platform (e.g. XP). The key of course, is to pay attention > to the "Supported" tags in the newer ADMs. > > Darren > > Darren Mar-Elia > For comprehensive Windows Group

RE: [ActiveDir] adm file management

2006-09-06 Thread Darren Mar-Elia
of each >> other--2003, SP1 is a superset of XP,SP2, XP is a superset of 2000, >> etc. And it is definitely best to manage such a mixed environment >> from the latest platform (e.g. XP). The key of course, is to pay >> attention to the "Supported" tags in the

RE: [ActiveDir] OT: admin account in Vista

2006-09-07 Thread Darren Mar-Elia
safe location == post-it note on the side of CPU From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Al MulnickSent: Thursday, September 07, 2006 10:36 AMTo: ActiveDir@mail.activedir.orgSubject: Re: [ActiveDir] OT: admin account in Vista "Write down your username and password

RE: [ActiveDir] OT: Management Solutions

2006-09-11 Thread Darren Mar-Elia
Alan- I ran one of these evalutions a while back for a 25,000 desktop environment. I would highly advise putting together a spreadsheet of your *real* requirements prior to narrowing the vendor list. Don't let the vendor tell you what you need or the choice will become obvious. Apart from tha

RE: [ActiveDir] Specifying builtin accounts in GPO settings.

2006-09-12 Thread Darren Mar-Elia
Matt- I don't think these accounts have well-known SIDs, so I'm not sure that's going to help. You can easily verify using psgetsid from Sysinternals. I checked a couple accounts here (though they were domain accounts) and they were not well-known SIDs.   Darren   Darr

RE: [ActiveDir] Block Inheritance on DC OU

2006-09-13 Thread Darren Mar-Elia
Well, the obvious effect is that it prevents domain-linked policies from being delivered correctly, including password policy. This is probably not desirable. I can't think of a good scenario where this would be useful.   Darren From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf

RE: [ActiveDir] Block Inheritance on DC OU

2006-09-14 Thread Darren Mar-Elia
in the case of password policy. This can only be set at the top level of the domain. Does this block actually prevent it being applied? I would guess that is does, but I wonder if any one has tested it or has any docs on what actually happens. From: [EMAIL PROTECTED] [mailto:[EMAIL PRO

RE: [ActiveDir] Block Inheritance on DC OU

2006-09-15 Thread Darren Mar-Elia
it. This helped for keeping a consistent password policy across all OUs and Domain. And also "saving" DCs from domain level general purpose GPOs. Long term, soln is to rethink the OU structure. Kamlesh On 9/13/06, Darren Mar-Elia <[EMAIL PROTECTED]> wrote: > > Well, the obvi

RE: [ActiveDir] Block Inheritance on DC OU

2006-09-15 Thread Darren Mar-Elia
This helped for keeping a consistent password policy across all OUs and Domain.And also "saving" DCs from domain level general purpose GPOs.Long term, soln is to rethink the OU structure.Kamlesh On 9/13/06, Darren Mar-Elia <[EMAIL PROTECTED]> wrote: Well, the obvious

RE: [ActiveDir] Block Inheritance on DC OU

2006-09-15 Thread Darren Mar-Elia
at DC OU2) Create Password Policy at Domain level and enforce it. This helped for keeping a consistent password policy across all OUs and Domain.And also "saving" DCs from domain level general purpose GPOs.Long term, soln is to rethink the OU structure.Kamlesh On 9/13/06, Darren Mar-Eli

RE: [ActiveDir] I'm Baaaaaaack!

2006-09-21 Thread Darren Mar-Elia
I smell sulfur... ;-) From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Akomolafe, DejiSent: Thursday, September 21, 2006 11:49 AMTo: ActiveDir@mail.activedir.orgSubject: RE: [ActiveDir] I'm Baaack! Yikes! Is it Halloween yet?   Sincerely,    _   

RE: [ActiveDir] DC Establishing Session to client on TCP139

2006-09-21 Thread Darren Mar-Elia
Brian- You might want to run TCPView on the DC (http://www.sysinternals.com/Utilities/TcpView.html). It will tell you which process owns the communication on that port.   Darren From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Al MulnickSent: Thursday, September 21, 2006 12:

RE: [ActiveDir] Replace UNC by DFS path in Group Policy

2006-09-25 Thread Darren Mar-Elia
migrating a GPO from one forest or domain to another. Problem is that I think it would be pretty invasive doing it this way because essentially you need to backup your existing GPOs and then re-import the changed ones over them. Darren Darren Mar-Elia For comprehensive Windows Group Policy

RE: [ActiveDir] Struggling to find AD authentication code

2006-09-26 Thread Darren Mar-Elia
You actually shouldn't have to use Interop or PInvoke like that to authenticate to AD using VB.Net. I do it all the time in WinForms using the DirectoryEntry class, which allows you to pass creds to your AD connection. You just need to front those creds with a simple form and away you go. Ju

[ActiveDir] OT: DesktopStandard acquired by Microsoft

2006-10-02 Thread Darren Mar-Elia
  http://www.desktopstandard.com/PressReleases/02Oct2006.aspx     In case anyone is interested...     Darren Mar-Elia For comprehensive Windows Group Policy Information, check out www.gpoguy.com-- the best source for GPO FAQs, video training, tools and whitepapers. Also check out the Windows

Re: RE: [ActiveDir] OT: DesktopStandard acquired by Microsoft

2006-10-02 Thread Darren Mar-Elia
akomolafe.com> - > we > know IT > -5.75, -3.23 > Do you now realize that Today is the Tomorrow you were worried about > Yesterday? -anon > > ________ > > From: [EMAIL PROTECTED] on behalf of Darren Mar-Elia > Sent: Mon 10/2/2006 9:47 AM

RE: RE: [ActiveDir] OT: DesktopStandard acquired by Microsoft

2006-10-02 Thread Darren Mar-Elia
least. :) On 10/2/06, Darren Mar-Elia <[EMAIL PROTECTED]> wrote: Haha. This is the first time I've been on the receiving end Deji. You can't blame ME for this one :). Just for the record, I'm not going to MS ( http://blogs.dirteam.com/blogs/gpoguy/archive/2006/10/02/D

RE: [ActiveDir] Folder Redirection Issue

2006-10-04 Thread Darren Mar-Elia
27;re getting the Access Denied.   Darren   Darren Mar-Elia For comprehensive Windows Group Policy Information, check out www.gpoguy.com-- the best source for GPO FAQs, video training, tools and whitepapers. Also check out the Windows Group Policy Guide, the definitive resource for Group P

RE: [ActiveDir] OT: wikis

2006-10-05 Thread Darren Mar-Elia
You mean Jet Blue doesn't have TV on their flights??? -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Brett Shirley Sent: Thursday, October 05, 2006 10:12 AM To: ActiveDir@mail.activedir.org Subject: Re: [ActiveDir] OT: wikis Except when 99% of the commo

RE: [ActiveDir] Disk Space Hogs

2006-10-06 Thread Darren Mar-Elia
I've used/liked FolderSizes (www.foldersizes.com) -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Steve Comeau Sent: Friday, October 06, 2006 8:01 AM To: ActiveDir@mail.activedir.org Subject: [ActiveDir] Disk Space Hogs Is there a tool or utility out th

RE: [ActiveDir] Assign User rights overs computers with AD

2006-10-06 Thread Darren Mar-Elia
Minor nit below. Otherwise, spot on observations. From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Matt HargravesSent: Friday, October 06, 2006 7:56 AMTo: ActiveDir@mail.activedir.orgSubject: Re: [ActiveDir] Assign User rights overs computers with AD Just to cover some thin

RE: [ActiveDir] Change default User-Account-Control behavior

2006-11-02 Thread Darren Mar-Elia
This article, http://msdn.microsoft.com/library/default.asp?url=/library/en-us/ad/ad/exten ding_the_user_interface_for_directory_objects.asp, describes display specifiers, which is what Guido is referring to here. It is possible to add, for example, a context menu item to an object class in ADUC th

RE: [ActiveDir] OT: Folder Redirection query

2006-11-02 Thread Darren Mar-Elia
Mark- That sounds like you're users are being created from some pre-created template user? Normally, when FR occurs, it would not append the administrator's account to those folders. Darren -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Mark Parris Sen

RE: [ActiveDir] Event ID 108

2006-11-07 Thread Darren Mar-Elia
Dan- I would resolve the problem before upgrading. It sounds like you have at least two things going on. First off, the sw. deployment error sounds like something deeply wrong with AD. The software installation data object referred to below is probably something called a packageRegistration

RE: [ActiveDir] Event ID 108

2006-11-08 Thread Darren Mar-Elia
Dan- The 2 packageRegistration objects represent two separate packages. The MSI and MST are referenced within the msiFileList attribute on each packageRegistration object. Its possible that one of those packageRegistration objects is a "removed" package--removed packages don't actually get d

RE: [ActiveDir] Event ID 108

2006-11-08 Thread Darren Mar-Elia
Yes, if you deleted and recreated the GPO, it would have a different GUID. So I'm guessing that one of those packageRegistration objects is the package you've deployed and one is a package that has been removed. I can't think of any reason why software deployment would just fail like that, ac

RE: [ActiveDir] Beginner's Book on Scripting - WSH or VBScript?

2006-11-09 Thread Darren Mar-Elia
Also. Check out Don's site at www.scriptinganswers.com. Lots of good resources there. Since you're learning scripting anew, you might even want to consider jumping right into PowerShell, which is MS' new scripting environment. The TechNet scripting center cited below has links to PowerShell

RE: [ActiveDir] OT: M$

2006-11-09 Thread Darren Mar-Elia
I didn't honestly see anything in the risk factors of the 10Q that any other software business doesn't declare. I read it as basically saying that Microsoft has competition from various sources that could threaten its business model. That's pretty normal. I think its fair to say, based on the big d

RE: [ActiveDir] GPO Error on Domain Controller

2006-11-10 Thread Darren Mar-Elia
That indicates that something is preventing Admi. Template policy from running. Posting the relevants part of userenv.log would be helpful. Darren -Original Message- From: "Paul G. DaSilva" <[EMAIL PROTECTED]> Cc: ActiveDir@mail.activedir.org Sent: 11/10/2006 10:43 AM Subject: [ActiveDi

RE: [ActiveDir] how to access blocked site.

2006-11-13 Thread Darren Mar-Elia
Hmm. That's a dubious stretch. Does that mean all those folks in China that find ways to bypass their government-controlled proxy are endangering us all and should be stopped? There may be lots of legitimate reasons why someone needs to do this. I don't think it should be assumed that suddenly we a

[ActiveDir] Timeout period on object moves?

2006-11-13 Thread Darren Mar-Elia
P processing to determine its location in AD. Its almost as if AD is caching the previous location of the object to dampen excessive object moves. Sounds weird but I'm wondering if anyone has an explanation to this?   Darren   Darren Mar-Elia For comprehensive Windows Group Policy In

RE: [ActiveDir] Timeout period on object moves?

2006-11-13 Thread Darren Mar-Elia
vices LogicaCMG Nederland B.V. (BU RTINC Eindhoven) ( Tel : +31-(0)40-29.57.777 ( Mobile : +31-(0)6-26.26.62.80 * E-mail : _ From: [EMAIL PROTECTED] on behalf of Darren Mar-Elia Sent: Mon 2006-11-13 18:23 To: ActiveDir@mail.activedir.org Subject: [ActiveDir] Timeout period on object

RE: [ActiveDir] how to access blocked site.

2006-11-13 Thread Darren Mar-Elia
have a business justification for a web site, ask. If you are in China or insert Country of your choice, that's a tougher call but if he was I'd strongly recommend that he not ask about it on a public listserve that could be easily found later. Darren Mar-Elia wrote: > Hmm. That'

RE: [ActiveDir] OT: "new" ms-Sysinternals utils: .exe size gone up like crazy!

2006-11-13 Thread Darren Mar-Elia
Which tool and what is the prompt? One thing I've done in the past, when asked for 'y' or 'n', is simply do this: Command | echo y -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of [EMAIL PROTECTED] Sent: Monday, November 13, 2006 2:04 PM To: ActiveDir@m

RE: [ActiveDir] Timeout period on object moves?

2006-11-13 Thread Darren Mar-Elia
ed. I expect you will see that when it is not updating, the client isn't even querying AD. joe -- O'Reilly Active Directory Third Edition - http://www.joeware.net/win/ad3e.htm _ From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Darren Mar-Elia Sent: Mo

RE: [ActiveDir] Locating empty GPOs in a domain / forest

2006-11-15 Thread Darren Mar-Elia
Title: Locating empty GPOs in a domain / forest Another option is  to perform an LDAP search on the cn=policies, cn=system container for GPC objects, and on each GPC object, look for a versionNumber attribute == 0. Its probably slightly faster than first generating the HTML report and then pa

RE: [ActiveDir] Locating empty GPOs in a domain / forest

2006-11-15 Thread Darren Mar-Elia
Title: Locating empty GPOs in a domain / forest Well, it depends upon the purpose of you quest, but you're correct. For example, you may not want to delete a GPO that has no settings (but does have versionNumber >0) because that may be a desirable state for it. In other words, if a GPO had se

RE: [ActiveDir] Locating empty GPOs in a domain / forest

2006-11-15 Thread Darren Mar-Elia
: +31-(0)40-29.57.777 ( Mobile : +31-(0)6-26.26.62.80 * E-mail : _ From: [EMAIL PROTECTED] on behalf of Darren Mar-Elia Sent: Wed 2006-11-15 17:04 To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] Locating empty GPOs in a domain / forest Well, it depends upon the purpo

RE: [ActiveDir] Locating empty GPOs in a domain / forest

2006-11-16 Thread Darren Mar-Elia
tinue to use the setting and ignore the change from enabled to 'not defined'. e.g. wallpaper set to A, originally. Then wallpaper set to 'not defined'. I always believed clients would ignore any 'not defined' settings and thus continue to use wallpaper A. Am I wrong?

RE: [ActiveDir] computer policy processing -retry behaviour

2006-11-22 Thread Darren Mar-Elia
GP processing cycle failed, then as soon as I detect that the DC is back online, I will trigger a background policy refresh". So, it doesn't help with the foreground issues stated above, but does significantly reduce the refresh time of up to 120 minutes. Hope that helps. Darren Da

RE: [ActiveDir] Granting rights to 'Manage GPOs'

2006-11-25 Thread Darren Mar-Elia
ver the cn=policies,cn=system container in AD and, similarly on the SYSVOL Policies folder, it should have Change rights over that container. Darren Darren Mar-Elia For comprehensive Windows Group Policy Information, check out <http://www.gpoguy.com/> www.gpoguy.com-- the best sou

RE: [ActiveDir] Exclude Vista from GPO

2006-11-28 Thread Darren Mar-Elia
Right, or security group filtering where you create a security group that includes all your Vista machines and deny it Apply Group Policy rights on that GPO. If you use a WMI Filter, then, assuming all the targets are XP, you would do something like this: Select * from Win32_OperatingSystem Whe

RE: [ActiveDir] MS / Desktopstandard

2006-11-28 Thread Darren Mar-Elia
Nathan- I can't speak specifically about what DesktopStandard's plans are but frankly, when I asked MS about supporting existing 3rd party CSEs in Vista a while ago, they said that there should not be any issues. Of course, it is up to the vendor to test and support this, and since that vendor is n

RE: [ActiveDir] Exclude Vista from GPO

2006-11-28 Thread Darren Mar-Elia
, I want the GPO to run on ALL machines EXCEPT Vista. I also want it to be dynamic (I don't want to manually add computers to groups) From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Darren Mar-Elia Sent: Tuesday, November 28, 2006 12:24 PM To: ActiveDir@mail.activedir.or

RE: [ActiveDir] Exclude Vista from GPO

2006-11-28 Thread Darren Mar-Elia
On Behalf Of Darren Mar-Elia Sent: Tuesday, November 28, 2006 3:47 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] Exclude Vista from GPO Ok. So, you could also use this: Select * from Win32_OperatingSystem Where BuildNumber< 6000 Since Vista's build # is 6000, that

RE: [ActiveDir] Script to delete unwanted profiles form desktop

2006-12-03 Thread Darren Mar-Elia
Check out delprof.exe. Its either in the reskit or part of suppor tools or part of the OS, depending upon which version of the OS you have. You would have to run it in a GPO-based computer startup script so that it runs when no users are logged on. Darren From: [EMAIL PROTECTED] [mail

RE: [ActiveDir] Granting rights to 'Manage GPOs'

2006-12-04 Thread Darren Mar-Elia
Neil- You can modify the defaultSecurityDescriptor attribute in the schema to change which groups are automatically granted rights on a newly created GPO. Its described here: http://support.microsoft.com/kb/321476/en-us Darren Darren Mar-Elia CTO & Founder www.sdmsoftware

RE: [ActiveDir] Quest Recovery Manager

2006-12-06 Thread Darren Mar-Elia
Tim- Sadly in our business I think you'd have a hard time finding someting akin to a decent, educated and un-biased review of this stuff. No Consumer Reports for software. What I would always recommend is to gather your requirements clearly and evaluate all players against those requirements an

RE: [ActiveDir] Quest Recovery Manager

2006-12-06 Thread Darren Mar-Elia
"The Quest guys told me the other day they had a lot of leeway on some pricing for one of my clients so I'm wondering if this is the end of the year for the salesmen and they need to make their year this month (if so this is an excellent time to buy Quest software)" Ha! Show me a sales person f

RE: [ActiveDir] OT: SpecOps GPUPDATE tool

2006-12-07 Thread Darren Mar-Elia
I know the SpecOps guys lurk on this forum so you should get a response, but I would also suggest that they have a forum on their website for asking questions and getting feedback from other users. Darren From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of McCann, Danny Sent:

RE: [ActiveDir] Quest Recovery Manager

2006-12-07 Thread Darren Mar-Elia
Crazy Eddy's TV ads in New York. Of course its free like a puppy... :) -gil ________ From: [EMAIL PROTECTED] on behalf of Darren Mar-Elia Sent: Wed 12/6/2006 4:18 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] Quest Recovery Manager "The Que

RE: [ActiveDir] Quest Recovery Manager

2006-12-09 Thread Darren Mar-Elia
the same dance every year. -- O'Reilly Active Directory Third Edition - http://www.joeware.net/win/ad3e.htm _ From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Darren Mar-Elia Sent: Wednesday, December 06, 2006 7:18 PM To: ActiveDir@mail.activedir.org Subject: RE: [A

RE: [ActiveDir] group policy object

2006-12-12 Thread Darren Mar-Elia
If you have GPMC installed, then the GP tab is removed from ADU&C and you'll need to manage GP from the GPMC. From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of John Sent: Tuesday, December 12, 2006 8:16 AM To: ActiveDir@mail.activedir.org Subject: [ActiveDir] group policy object

RE: [ActiveDir] Lockdown CD-ROM access for some

2006-12-13 Thread Darren Mar-Elia
Ben- You might want to consider one of the 3rd party solutions for this. There are several on the market that both use and don't use Group Policy to implement lockdown. Check out Securewave and DesktopStandard, among others. If you don't have a budget, then there is a policy hack you can use to ju

RE: [ActiveDir] Lockdown CD-ROM access for some

2006-12-13 Thread Darren Mar-Elia
Theoretically you could do that, but besides the obvious security downside, the registry tweaks really only disable the driver startup, so you would still have to reboot for that to take effect. All in all, the ADM approach talked about in that article is pretty weak and only good for completely di

RE: [ActiveDir] Vista GPO

2006-12-14 Thread Darren Mar-Elia
What do you mean Za? I'm not familiar with any GPO plug-in for Win2K3, unless you mean the LDIF files that are in sources\adprep on the Vista CD? -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Za Vue Sent: Thursday, December 14, 2006 9:57 AM To: ActiveDir

RE: [ActiveDir] Vista GPO

2006-12-14 Thread Darren Mar-Elia
Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] On Behalf Of Darren Mar-Elia > Sent: Thursday, December 14, 2006 10:34 AM > To: ActiveDir@mail.activedir.org > Subject: RE: [ActiveDir] Vista GPO > > What do you mean Za? I'm not familiar with

RE: [ActiveDir] Vista GPO

2006-12-14 Thread Darren Mar-Elia
The converter (ADMX Migrator) is only meant to convert ADMs into ADMXs-- not the other way around unfortunately. Darren -Original Message- From: "Mark Parris" <[EMAIL PROTECTED]> To: "ActiveDir.org" Sent: 12/14/2006 2:20 PM Subject: Re: [ActiveDir] Vista GPO www.microsoft.com/downloads

RE: [ActiveDir] Vista GPO

2006-12-14 Thread Darren Mar-Elia
Vista ADMX format, is it a better implementation to have central ADMX storage on the DCs? === Weiming Lu Emory College Computing Support (404)727-7917 -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Darren Mar-Elia Sent: Thu

RE: [ActiveDir] Vista GPO

2006-12-15 Thread Darren Mar-Elia
are a superset of the latest and greatest ADMs (i.e. they include 2003, XP and Vista settings) so you can happily manage Vista and non-Vista targeted GP settings from a Vista machine. Darren Darren Mar-Elia CTO & Founder www.sdmsoftware.com [EMAIL PROTECTED] -Original Message- Fro

RE: [ActiveDir] Vista GPO

2006-12-15 Thread Darren Mar-Elia
-- "I love the smell of red herrings in the morning" - anonymous -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Darren Mar-Elia Sent: Friday, December 15, 2006 10:05 AM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveD

RE: [ActiveDir] Vista GPO

2006-12-15 Thread Darren Mar-Elia
ly from the DCs, best practices be damned. Sincerely, _ (, / | /) /) /) /---| (/_ __ ___// _ // _ ) /|_/(__(_) // (_(_)(/_(_(_/(__(/_ (_/ /) (/ Microsoft MVP - Directory Services www.akomolafe.com - we know IT -5.75, -3.23 Do you now realize that Today is the Tomorrow you were worried about Yesterday? -anon _ From: Darren Mar-Elia Sent: Fri 12/15/200

RE: [ActiveDir] Vista GPO

2006-12-15 Thread Darren Mar-Elia
realistically, the "ideal" is always the exception in this field. Microsoft should know that. People will insist on managing GPO directly from the DCs, best practices be damned. Sincerely, _ (, / | /) /) /) /---| (/_ __ ___// _ // _ ) /|_/(__(_) // (_(_)(/_(_(_/(__(/_ (_/ /) (/ Microsoft MVP

RE: [ActiveDir] DesktopStandard

2006-12-18 Thread Darren Mar-Elia
I don't think the decision has been made yet. I could be wrong but I think the first iteration of the "Advanced Group Policy Management" only includes the GP change control product, and not the PolicyMaker extensions. I'm not sure yet if its been announced or even decided what the ship vehicle is f

RE: [ActiveDir] push a URL in the trusted zone with GPO...

2007-01-05 Thread Darren Mar-Elia
Explorer\Internet Control Panel\Security Page\Site to Zone assignment list Darren Darren Mar-Elia CTO & Founder SDM Software, Inc. www.sdmsoftware.com Speed Group Policy Troubleshooting with the NEW GPHealth Reporter tool at http://www.sdmsoftware.com/products.php -Original Message-

RE: [ActiveDir] push a URL in the trusted zone with GPO...

2007-01-06 Thread Darren Mar-Elia
ECTED] On Behalf Of Darren Mar-Elia -> Sent: January 5, 2007 6:05 PM -> To: ActiveDir@mail.activedir.org -> Subject: RE: [ActiveDir] push a URL in the trusted zone with GPO... -> -> Alternatively, if you have the IE 6, XP,SP2 version of inetres.adm or the -> IE7 ADMs, you can use

RE: [ActiveDir] Roaming Profiles not updating

2007-01-08 Thread Darren Mar-Elia
Ernesto- Profiles are notorious for not completely unloading at logoff (i.e. resource handles "leak" and remain open). As a result, the profile is unable to copy up to the central server and therefore the server version doesn't get updated. If that is the problem here, then you can get a hold of th

RE: [ActiveDir] DNS Comments

2007-01-08 Thread Darren Mar-Elia
I like these guys: http://www.miceandmen.com/ From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Brian Desmond Sent: Monday, January 08, 2007 4:56 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] DNS Comments Well there hasn’t been some sort of ruling on whethe

RE: [ActiveDir] Policy Failing to apply

2007-01-15 Thread Darren Mar-Elia
Dave- Does that same proxy policy work for any other users correctly? Darren From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Dave Wade Sent: Monday, January 15, 2007 3:49 AM To: ActiveDir@mail.activedir.org Subject: [ActiveDir] Policy Failing to apply Folks, I have a

RE: [ActiveDir] Policy Failing to apply

2007-01-15 Thread Darren Mar-Elia
ilto:[EMAIL PROTECTED] On Behalf Of Darren Mar-Elia Sent: 15 January 2007 15:24 To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] Policy Failing to apply Dave- Does that same proxy policy work for any other users correctly? Darren From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On

RE: [ActiveDir] 1054 Error (Windows cannot contact DC - Group Policy)

2007-01-15 Thread Darren Mar-Elia
Is this the only system that is having this problem? Are you doing anything on your network to limit ICMP packet size? -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Donavon Yelton Sent: Monday, January 15, 2007 9:39 AM To: ActiveDir@mail.activedir.org S

RE: [ActiveDir] 1054 Error (Windows cannot contact DC - Group Policy)

2007-01-15 Thread Darren Mar-Elia
as the network admin account through remote desktops (the account I made the registry edit for GroupPolicyMinTransferRate under). Donavon -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Darren Mar-Elia Sent: Monday, January 15, 2007 12:52 P

RE: [ActiveDir] 1054 Error (Windows cannot contact DC - Group Policy)

2007-01-15 Thread Darren Mar-Elia
e! > > Donavon > > -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] On Behalf Of Susan > Bradley, CPA aka Ebitz - SBS Rocks [MVP] > Sent: Monday, January 15, 2007 1:39 PM > To: ActiveDir@mail.activedir.org > Subject: Re: [ActiveDir] 1054

RE: [ActiveDir] 1054 Error (Windows cannot contact DC - Group Policy)

2007-01-15 Thread Darren Mar-Elia
Behalf Of Darren Mar-Elia Sent: Monday, January 15, 2007 12:50 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] 1054 Error (Windows cannot contact DC - Group Policy) Sorry, just catching up here. In terms of updating the driver, if it's a MS provided driver, I think it would say

RE: [ActiveDir] 1054 Error (Windows cannot contact DC - Group Policy)

2007-01-19 Thread Darren Mar-Elia
this driver version is the root cause of the issue >> but I do need the drivers updated to have a place to start from. >> >> Susan, is there a known issue with Broadcom's that could possibly >> affect the problem I'm having? Thanks for the assistance! >>

RE: [ActiveDir] 1054 Error (Windows cannot contact DC - Group Policy)

2007-01-19 Thread Darren Mar-Elia
t driver and installing this new >>> >>> >> driver from HP. >> >> >>> Updating the driver and choosing the new driver explicitly doesn't >>> work and running HP's update package for the driver obviously fails >&

RE: [ActiveDir] "Add or Remove Programs" GPO

2007-01-25 Thread Darren Mar-Elia
You would not get a permissions problem from that admin. templates policy. They just don't work that way. So my guess is its something else. What happens, as administrator, when you run "appwiz.cpl" from a command prompt? Darren From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf

RE: [ActiveDir] Hash-based Software Restriction Policy

2006-02-14 Thread Darren Mar-Elia
I agree Alexander--if you're trying to manage system executables with SAFER policy its going to be a maintenance hassle over time. I think if your approach is to implicitly disallow everything and then try and allow all OS executables, you're going to have a big headache, between getting all the OS

RE: [ActiveDir] Limit Logon thru GPO

2006-02-16 Thread Darren Mar-Elia
There is no native way of doing this in GP, but there is the Resource Kit utility Cconnect.exe that tries to accomplish the same thing without messy AD partitions (not at all to imply that anything remotely related to AD is messy :))   Darren From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTE

RE: [ActiveDir] The system administrator has set policies to prevent this installation

2006-02-22 Thread Darren Mar-Elia
Antonio- You might want to try running Regmon (www.sysinternals.com) while you are performing the operation that generates this message. Then, look in the output log to see if you notice any read operations against reg keys within the various policy keys:   HKEY_LOCAL_MACHINE\Software\Polici

RE: [ActiveDir] Stupid Group Policy CSE behavior

2006-02-23 Thread Darren Mar-Elia
Well, it won't be the first time I've heard something about GP called "stupid" :).   I suspect it depends upon how you think about this. Certain CSEs are more resilient than others. I honestly haven't come across your scenario but in a lot of cases, if a CSE fails to do something, GP process

RE: [ActiveDir] GPO Security Filtering to a group not working

2006-02-23 Thread Darren Mar-Elia
Joe- Are you removing the Authenticated Users ACE before you add the discretionary group? You don't have any Deny ACEs on that GPO, do you? Darren -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Joe Lagreca Sent: Thursday, February 23, 2006 10:08 AM To:

RE: [ActiveDir] GPO Security Filtering to a group not working

2006-02-23 Thread Darren Mar-Elia
deny "apply group policy" only for all the admin groups, so I don't accidentally appy the GPO to any of them. The group I am trying to apply the GPO to, is not part of any other group. Joe On 2/23/06, Darren Mar-Elia <[EMAIL PROTECTED]> wrote: > Joe- > Are you remov

RE: [ActiveDir] Stupid Group Policy CSE behavior

2006-02-23 Thread Darren Mar-Elia
~~"Be the change you want to see in the World"~~~~~~~~~ On 2/23/06, Darren Mar-Elia <[EMAIL PROTECTED]> wrote: Well, it won't be the first time I've heard something about GP called "stupid" :).   I susp

<    1   2   3   4   5   6   >