RE: [ActiveDir] Disable CD ROM through GP

2007-01-27 Thread Ulf B. Simon-Weidner
. Gruesse - Sincerely, Ulf B. Simon-Weidner   Profile Publications:   http://mvp.support.microsoft.com/profile=35E388DE-4885-4308- B489-F2F1214C811D      Weblog: http://msmvps.org/UlfBSimonWeidner   Website: http://www.windowsserverfaq.org -Original Message- From: [EMAIL PROTECTED

RE: [ActiveDir] OT: maintaining creation date when copying directories?

2007-01-25 Thread Ulf B. Simon-Weidner
Robocopy with the /B-Switch should work. Ulf From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M. Sent: Donnerstag, 25. Januar 2007 13:10 To: ActiveDir@mail.activedir.org Subject: [ActiveDir] OT: maintaining creation date when copying directories? What

RE: [ActiveDir] [OT] Odd Folder under Forward Lookup Zone

2007-01-25 Thread Ulf B. Simon-Weidner
Noah Eiger _ From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Ulf B. Simon-Weidner Sent: Wednesday, January 24, 2007 12:29 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] [OT] Odd Folder under Forward Lookup Zone Just 9:30 pm here, so not really late

RE: [ActiveDir] OT: maintaining creation date when copying directories?

2007-01-25 Thread Ulf B. Simon-Weidner
. Gruesse - Sincerely, Ulf B. Simon-Weidner Profile Publications: blocked::http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F 2F1214C811D http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F2F1214C811 D Weblog: blocked::http://msmvps.org/UlfBSimonWeidner http

RE: [ActiveDir] How to find non-primary SMTP addresses?

2007-01-25 Thread Ulf B. Simon-Weidner
Hi Stu, I don't think there's a way to expose mulitvalued attributes with CSVDE - you'd either have to use LDIFDE or VBScript or anything else to view all values of those attributes. Gruesse - Sincerely, Ulf B. Simon-Weidner Profile Publications: blocked::http

RE: [ActiveDir] OT: maintaining creation date when copying directories?

2007-01-25 Thread Ulf B. Simon-Weidner
. Thanks for bringing this up so I had to look into it - I'll blog this since it's a very interesting change. Gruesse - Sincerely, Ulf B. Simon-Weidner Profile Publications: blocked::http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F 2F1214C811D http://mvp.support.microsoft.com

RE: RE: [ActiveDir] Question about DNS SRV registration.

2007-01-24 Thread Ulf B. Simon-Weidner
on default domain controller policy). So it seems that DCa is still advertising himself as DC in site B. I will look why the process does not work in our case... :( We did not configured automatic aging/scavenging, i will look also into this option. Thanks again, Yann Ulf B. Simon-Weidner

RE: RE: RE: [ActiveDir] Question about DNS SRV registration.

2007-01-24 Thread Ulf B. Simon-Weidner
approaching ;-) ). Gruesse - Sincerely, Ulf B. Simon-Weidner Profile Publications: blocked::http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F 2F1214C811D http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F2F1214C811 D Weblog: blocked::http://msmvps.org

RE: [ActiveDir] [OT] Odd Folder under Forward Lookup Zone

2007-01-24 Thread Ulf B. Simon-Weidner
this and verify the printers name), if it was registered automatically you need to change the name of the printer. Gruesse - Sincerely, Ulf B. Simon-Weidner Profile Publications: blocked::http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F 2F1214C811D http

RE: [ActiveDir] [OT] Odd Folder under Forward Lookup Zone

2007-01-24 Thread Ulf B. Simon-Weidner
No Zone – no properties ;-) From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Al Mulnick Sent: Mittwoch, 24. Januar 2007 20:24 To: ActiveDir@mail.activedir.org Subject: Re: [ActiveDir] [OT] Odd Folder under Forward Lookup Zone What are properties of the 1 zone? On 1/24/07,

RE: [ActiveDir] ftp access

2007-01-24 Thread Ulf B. Simon-Weidner
Options And is named Interactive logon: Prompt user to change password before expiration Just a guess. Gruesse - Sincerely, Ulf B. Simon-Weidner Profile Publications: blocked::http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F 2F1214C811D http

RE: [ActiveDir] [OT] Odd Folder under Forward Lookup Zone

2007-01-24 Thread Ulf B. Simon-Weidner
are things? See you in March? Gruesse - Sincerely, Ulf B. Simon-Weidner Profile Publications: blocked::http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F2F1214C811D http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F2F1214C811D Weblog: blocked::http

RE: [ActiveDir] [OT] Odd Folder under Forward Lookup Zone

2007-01-24 Thread Ulf B. Simon-Weidner
it was someone (probably me!) just typed a .1 in some setting on the printer and allowed it to register in DNS. Many thanks. -- nme Noah Eiger _ From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Ulf B. Simon-Weidner Sent: Wednesday, January 24, 2007 12:29 PM

RE: [ActiveDir] Question about DNS SRV registration.

2007-01-23 Thread Ulf B. Simon-Weidner
of DC A in Site B, however make sure that you are only deleting the SRV-Records underneath the DNS-Subdomains of the Site-specific Records in the “Site B”-DNS-Domains (looks like folders in the DNS Managementconsole). Gruesse - Sincerely, Ulf B. Simon-Weidner Profile Publications: blocked

RE: [ActiveDir] Quest Recovery Manager

2007-01-21 Thread Ulf B. Simon-Weidner
] [mailto:[EMAIL PROTECTED] On Behalf Of Ulf B. Simon-Weidner Sent: 10 December 2006 12:06 To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] Quest Recovery Manager I do disagree since we might have other withes, issues, possibilities with Longhorn, so I'd wait when spending a lot of money

RE: [ActiveDir] release date for W2K3/SP2?

2007-01-21 Thread Ulf B. Simon-Weidner
I can't remember exactly, but I think I've heard a Q1 at one of the conferences last year. IIRC. Gruesse - Sincerely, Ulf B. Simon-Weidner Profile Publications: blocked::http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F 2F1214C811D http://mvp.support.microsoft.com

RE: [ActiveDir] AdminSDHolder orphans

2007-01-21 Thread Ulf B. Simon-Weidner
complicated to generalize that it should be reset in any case. Gruesse - Sincerely, Ulf B. Simon-Weidner   Profile Publications:   http://mvp.support.microsoft.com/profile=35E388DE-4885-4308- B489-F2F1214C811D      Weblog: http://msmvps.org/UlfBSimonWeidner   Website: http

RE: [ActiveDir] AdminSDHolder orphans

2007-01-21 Thread Ulf B. Simon-Weidner
PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Ulf B. Simon-Weidner Sent: Monday, 22 January 2007 11:32 a.m. To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] AdminSDHolder orphans Hi Tony, late response as well - sorry. I guess why this isn't cleaned up is the same thing as in many other

RE: [ActiveDir] AD Schema Extensions and Exchange System Manager

2006-12-18 Thread Ulf B. Simon-Weidner
that this is respected. Gruesse - Sincerely, Ulf B. Simon-Weidner Profile Publications: BLOCKED::http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F 2F1214C811D http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F2F1214C811 D Weblog: BLOCKED::http

RE: [ActiveDir] Delegate VPN rights

2006-12-03 Thread Ulf B. Simon-Weidner
you can use ldp\script etc.. to set the msNPAllowDialin == true. It should reflect properly in ADUC when you next view that user.. spat - Original Message - From: Ulf B. Simon-Weidner mailto:[EMAIL PROTECTED] To: ActiveDir@mail.activedir.org Sent: Thursday, November 30

RE: [ActiveDir] Delegate VPN rights

2006-11-30 Thread Ulf B. Simon-Weidner
- Sincerely, Ulf B. Simon-Weidner Profile Publications: blocked::http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F 2F1214C811D http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F2F1214C811 D Weblog: blocked::http://msmvps.org/UlfBSimonWeidner http

RE: [ActiveDir] ldp in ADAM-SP1

2006-09-30 Thread Ulf B. Simon-Weidner
Just stepped across this - thanks for fixing it! Ulf -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Ulf B. Simon-Weidner Sent: Freitag, 4. August 2006 09:26 To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] ldp in ADAM-SP1 Hi Dmitri

RE: [ActiveDir] ldp in ADAM-SP1

2006-08-04 Thread Ulf B. Simon-Weidner
Hi Dmitri, And DSAcls still does not display a computer accounts ACL if someone was being delegated permission to join a computer to this account using ADUC: http://www.windowsserverfaq.org/faq/CompACLs.asp Gruesse - Sincerely, Ulf B. Simon-Weidner Profile Publications: http

RE: [ActiveDir] Vendor Domain

2006-07-24 Thread Ulf B. Simon-Weidner
to manage them, or want to know very closely what the requirements are and keep an extra eye on those machines. Dont put lives at jeopardy b/c of a misconfigured GPO. Gruesse - Sincerely, Ulf B. Simon-Weidner Profile Publications:http://mvp.support.microsoft.com/profile="">

RE: [ActiveDir] NTDS.DIT Size

2006-06-29 Thread Ulf B. Simon-Weidner
on x64 will perform better than on 32-bit, since its very likely you already have some of the newer servers with x64 Id just give it a try for one DC yourself. Gruesse - Sincerely, Ulf B. Simon-Weidner Profile Publications:http://mvp.support.microsoft.com/profile=""> Weblog: http

RE: [ActiveDir] New DC can't find the machine account

2006-05-31 Thread Ulf B. Simon-Weidner
Every joe is someones joe, but Joe McNicholas Joe joeware Richards Gruesse - Sincerely, Ulf B. Simon-Weidner Profile Publications: http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F2F1214C811 D Weblog: http://msmvps.org/UlfBSimonWeidner Website: http

RE: [ActiveDir] AD lag sites and replication

2006-05-31 Thread Ulf B. Simon-Weidner
. 3) Lag-Sites dont make any sense if they do replicate in between the scheduled times so in this scenario you may worry about both. Gruesse - Sincerely, Ulf B. Simon-Weidner Profile Publications:http://mvp.support.microsoft.com/profile=""> Weblog: http://msmvps.org/Ulf

RE: [ActiveDir] Machine Psswd Age

2006-05-31 Thread Ulf B. Simon-Weidner
to share this info on a blog? It's great, and we could give you credits and avoid typing whenever there's a discussion of that topic. Might be worth to include the imaged-client and reset password on a computer account discussions. Gruesse - Sincerely, Ulf B. Simon-Weidner Profile

RE: [ActiveDir] AD lag sites and replication

2006-05-30 Thread Ulf B. Simon-Weidner
the tombstone-lifetime I don't see any reasons why this should not be supported since we are just talking about lag-sites without any memberservers / clients / users who log onto those DCs. Gruesse - Sincerely, Ulf B. Simon-Weidner Profile Publications:http://mvp.support.microsoft.com/profile

RE: [ActiveDir] AD lag sites and replication

2006-05-30 Thread Ulf B. Simon-Weidner
no client is hitting a lag sites DC. Gruesse - Sincerely, Ulf B. Simon-Weidner Profile Publications:http://mvp.support.microsoft.com/profile=""> Weblog: http://msmvps.org/UlfBSimonWeidner Website: http://www.windowsserverfaq.org From: [EMAIL PROTECTED] [mailto:[EMA

RE: [ActiveDir] AD lag sites and replication

2006-05-30 Thread Ulf B. Simon-Weidner
! And right after hitting OK there's a head banging against the monitor-sound - Aahrg - Lag sites. Gruesse - Sincerely, Ulf B. Simon-Weidner Profile Publications: http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F2F1214C811D Weblog: http://msmvps.org/UlfBSimonWeidner

RE: [ActiveDir] [OT]Identity Access Mangement

2006-05-28 Thread Ulf B. Simon-Weidner
did attend should be able to find the sessions. Currently you are able to use Biztalk as workflow engine, or the Office 2007 workflow engine when available. Gruesse - Sincerely, Ulf B. Simon-Weidner Profile Publications: http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489

RE: [ActiveDir] OT help with VBS/WMI Script

2006-05-28 Thread Ulf B. Simon-Weidner
an example for you at http://msdn.microsoft.com/library/default.asp?url=/library/en-us/wmisdk/wmi/ wmi_tasks__networking.asp - look at the last example. Gruesse - Sincerely, Ulf B. Simon-Weidner Profile Publications: http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F2F1214C811 D

RE: [ActiveDir] OT help with VBS/WMI Script

2006-05-28 Thread Ulf B. Simon-Weidner
You can also use WMI to ping the machine - works fast and you don't have to text-analyze the output of the ping-command. I've just dug out an example for you at http://msdn.microsoft.com/library/default.asp?url=/library/en-u s/wmisdk/wmi/ wmi_tasks__networking.asp - look at the last example.

RE: [ActiveDir] Machine Psswd Age

2006-05-28 Thread Ulf B. Simon-Weidner
: http://www.microsoft.com/technet/archive/winntas/maintain/ntopt4.mspx?mfr=tr ue However I stand corrected - need to update my brains cache from google more often - to bad brains don't support TTL of websites. Gruesse - Sincerely, Ulf B. Simon-Weidner Profile Publications: http

RE: [ActiveDir] Machine Psswd Age

2006-05-24 Thread Ulf B. Simon-Weidner
AFAIK the password change interval is set to 30 in XP (15 in NT, W2k), but the computer accounts starts to request renewal after 50% of the time is over. After 30 days it'll change it if being logged onto the domain for sure (unless otherwise configured or connected). Gruesse - Sincerely, Ulf B

RE: [ActiveDir] Delete only one object in the Tombstone.

2006-05-22 Thread Ulf B. Simon-Weidner
of tombstones most likely not). Gruesse - Sincerely, Ulf B. Simon-Weidner Profile Publications:http://mvp.support.microsoft.com/profile=""> Weblog: http://msmvps.org/UlfBSimonWeidner Website: http://www.windowsserverfaq.org From: [EMAIL PROTECTED] [mailto:[EM

RE: [ActiveDir] Delete only one object in the Tombstone.

2006-05-22 Thread Ulf B. Simon-Weidner
You're welcome, and have a nice day too! Gruesse - Sincerely, Ulf B. Simon-Weidner Profile Publications: blocked::http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F 2F1214C811D http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F2F1214C811 D Weblog

RE: [ActiveDir] OldCmp question

2006-05-22 Thread Ulf B. Simon-Weidner
Big fat ditto - and even better in the support tools. Gruesse - Sincerely, Ulf B. Simon-Weidner Profile Publications: http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F2F1214C811 D Weblog: http://msmvps.org/UlfBSimonWeidner Website: http://www.windowsserverfaq.org

RE: [ActiveDir] OldCmp question

2006-05-21 Thread Ulf B. Simon-Weidner
this hazzle. So I'm mainly limited to ds-tools or vbs. Something like this should work: Dsquery user -stalepwd 90 | dsget user -dn -disabled | find No Gruesse - Sincerely, Ulf B. Simon-Weidner Profile Publications: http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489

RE: [ActiveDir] OldCmp question

2006-05-20 Thread Ulf B. Simon-Weidner
I didn't catch it because I didn't bother enough to read the adfind syntax. If you'd provided a standard LDAP-Filter with DSQuery ... ;-) Gruesse - Sincerely, Ulf B. Simon-Weidner Profile Publications: http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F2F1214C811 D

RE: [ActiveDir] DSACLS bug maybe?

2006-05-19 Thread Ulf B. Simon-Weidner
published more details and a script to fix the ACLs on my website, and also mentioned it during one of my sessions at DEC: http://windowsserverfaq.de/faq/CompACLs.asp Gruesse - Sincerely, Ulf B. Simon-Weidner Profile Publications:http://mvp.support.microsoft.com/profile="">

RE: [ActiveDir][OT] DNS on a DC or NOT

2006-05-17 Thread Ulf B. Simon-Weidner
Hi Mark, You are right - Exchange is great - what I love especially is it's capabilities of administrative delegation. See you in Boston? Gruesse - Sincerely, Ulf B. Simon-Weidner Profile Publications: http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F2F1214C811 D

RE: [ActiveDir][OT] Is there a way to force users to logon to domain?

2006-05-16 Thread Ulf B. Simon-Weidner
I can't see them as well, OL2k3 into POP, provider is using ESMTP (Nemesis) and POP appears to be mimap12 (at least that's what telnetting against the pop tells me). Gruesse - Sincerely, Ulf B. Simon-Weidner Profile Publications:http://mvp.support.microsoft.com/profile="&quo

RE: [ActiveDir][OT] Is there a way to force users to logon to domain?

2006-05-16 Thread Ulf B. Simon-Weidner
If all of those were intended I did get everything correct as well. Mainly one thread IIRC. Gruesse - Sincerely, Ulf B. Simon-Weidner Profile Publications:http://mvp.support.microsoft.com/profile=""> Weblog: http://msmvps.org/UlfBSimonWeidner Website: http://www.windows

RE: [ActiveDir] User Accounts

2006-05-15 Thread Ulf B. Simon-Weidner
(and it's actually way to early here to handle thinking like that). Gruesse - Sincerely, Ulf B. Simon-Weidner Profile Publications: http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F2F1214C811 D Weblog: http://msmvps.org/UlfBSimonWeidner Website: http

RE: [ActiveDir] Group Name (Pre-Win2k) - Is it important

2006-05-15 Thread Ulf B. Simon-Weidner
- Sincerely, Ulf B. Simon-Weidner Profile Publications:http://mvp.support.microsoft.com/profile=""> Weblog: http://msmvps.org/UlfBSimonWeidner Website: http://www.windowsserverfaq.org From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Teo De Las HerasSent

RE: [ActiveDir] Group Name (Pre-Win2k) - Is it important

2006-05-15 Thread Ulf B. Simon-Weidner
GREP? Whats GREP! ;-) Great idea- forgot about that one. GPOs are really a big point here - I've seen an enterprise going down because of that. GPMC with backup / import (instead of backup / restore) might help here as well. Gruesse - Sincerely, Ulf B. Simon-Weidner Profile

RE: [ActiveDir] Is there a way to force users to logon to domain?

2006-05-15 Thread Ulf B. Simon-Weidner
What about the origin - are they created using OL2k7? If so must be a new bug - I was using a bit older version for quite a while (and everything was readable), but it almost corupted my mailstore - so I switched temporarily back. Gruesse - Sincerely, Ulf B. Simon-Weidner Profile

RE: [ActiveDir] Is it important to keep correct timezone settings on DC?

2006-05-14 Thread Ulf B. Simon-Weidner
the time, but allow them to adjust the timezone. Gruesse - Sincerely, Ulf B. Simon-Weidner Profile Publications:http://mvp.support.microsoft.com/profile=""> Weblog: http://msmvps.org/UlfBSimonWeidner Website: http://www.windowsserverfaq.org From: [EMAIL PROTECTED] [

RE: [ActiveDir] User Accounts

2006-05-14 Thread Ulf B. Simon-Weidner
be a possibility to reset DNTs programmatically after IFM, however this would need additional code and time after reading the DB and rebooting the DC for the first time. Gruesse - Sincerely, Ulf B. Simon-Weidner Profile Publications: http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489

RE: [ActiveDir] R2 Upgrade or install?

2006-05-14 Thread Ulf B. Simon-Weidner
. Gruesse - Sincerely, Ulf B. Simon-Weidner Profile Publications: http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F2F1214C811 D Weblog: http://msmvps.org/UlfBSimonWeidner Website: http://www.windowsserverfaq.org -Original Message- From: [EMAIL PROTECTED

RE: [ActiveDir] R2 Upgrade or install?

2006-05-01 Thread Ulf B. Simon-Weidner
Also the uninstall-files and all the previous garbage which isn't needed won't install when using a slipstreamed media. Ulf -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Freddy HARTONO Sent: Monday, May 01, 2006 3:23 PM To:

RE: [ActiveDir] logging users out

2006-04-24 Thread Ulf B. Simon-Weidner
Did you try shutdown.exe? The parameters /l /f /t 3600 allow you to time it for an hour after executing it, and to force a logoff. No need to script around using additional timers or scripts. Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book "Windows XP - Die Expertentipps&qu

RE: [ActiveDir] logging users out

2006-04-22 Thread Ulf B. Simon-Weidner
Guess you'll have to do that by yourself, e.g. logon-script shutdown -l -t 3600 Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz Weblog: http://msmvps.org/UlfBSimonWeidner Website: http://www.windowsserverfaq.org Pr

RE: [ActiveDir] Can We configure Romaing Profiles using Script

2006-04-22 Thread Ulf B. Simon-Weidner
- Sincerely, Ulf B. Simon-Weidner MVP-Book Windows XP - Die Expertentipps: http://tinyurl.com/44zcz Weblog: http://msmvps.org/UlfBSimonWeidner Website: http://www.windowsserverfaq.org Profile: http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F2F1214C811 D

RE: [ActiveDir] Can We configure Romaing Profiles using Script

2006-04-22 Thread Ulf B. Simon-Weidner
. You can also combine the dstools: Dsquery user ou=whatever,dc=example,dc=com -limit 0 | dsmod -profile ... This should give you an example how to do this. Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book Windows XP - Die Expertentipps: http://tinyurl.com/44zcz Weblog: http://msmvps.org

RE: [ActiveDir] User Accounts

2006-04-19 Thread Ulf B. Simon-Weidner
- Sincerely, Ulf B. Simon-Weidner MVP-Book Windows XP - Die Expertentipps: http://tinyurl.com/44zcz Weblog: http://msmvps.org/UlfBSimonWeidner Website: http://www.windowsserverfaq.org Profile: http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F2F1214C811 D

RE: [ActiveDir] User Accounts

2006-04-19 Thread Ulf B. Simon-Weidner
| | |-Original Message- |From: [EMAIL PROTECTED] |[mailto:[EMAIL PROTECTED] On Behalf Of Ulf B. |Simon-Weidner |Sent: Tuesday, April 18, 2006 11:40 PM |To: ActiveDir@mail.activedir.org |Subject: RE: [ActiveDir] User Accounts | |* DNTs (to me) are _not_ a component of the directory | |IIRC they are like

RE: [ActiveDir] Anomoly in application of Permissions by adminSDHolder

2006-04-19 Thread Ulf B. Simon-Weidner
or use google, which will bring it up as well. Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book Windows XP - Die Expertentipps: http://tinyurl.com/44zcz Weblog: http://msmvps.org/UlfBSimonWeidner Website: http://www.windowsserverfaq.org Profile: http://mvp.support.microsoft.com/profile

RE: [ActiveDir] Tombstone attributes

2006-04-18 Thread Ulf B. Simon-Weidner
it. Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book Windows XP - Die Expertentipps: http://tinyurl.com/44zcz Weblog: http://msmvps.org/UlfBSimonWeidner Website: http://www.windowsserverfaq.org Profile: http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F2F1214C811 D

RE: [ActiveDir] Tombstone attributes

2006-04-18 Thread Ulf B. Simon-Weidner
AM |To: ActiveDir@mail.activedir.org |Subject: Re: [ActiveDir] Tombstone attributes | |Ulf B. Simon-Weidner wrote: | Unfortunately the passwords is the same attribute for users and | computers. I thought recently to put the password in the |tombstone to | ease computer account reanimation

RE: [ActiveDir] User Accounts

2006-04-17 Thread Ulf B. Simon-Weidner
? Do clue - I'm german - we have our own - can't keep a dictionary of approabriate words in foreign languages in the same brain which is interested in those answers. Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book Windows XP - Die Expertentipps: http://tinyurl.com/44zcz Weblog: http

RE: [ActiveDir] User Accounts

2006-04-17 Thread Ulf B. Simon-Weidner
they use 2B RDNs |... if you're actually dealing with numbers that ballpark into |that area, I'd be curious to hear about your scenario, but I |suspect no one is doing that ... yet. | |Cheers, |-BrettSh | |On Mon, 17 Apr 2006, Ulf B. Simon-Weidner wrote: | | Hi ~eric, | | I don't look very happy

RE: [ActiveDir] User Accounts

2006-04-17 Thread Ulf B. Simon-Weidner
: RE: [ActiveDir] User Accounts | |Never take me to serious | |Seriously? :) | |(Great thread by the way) | |-Original Message- |From: [EMAIL PROTECTED] |[mailto:[EMAIL PROTECTED] On Behalf Of Ulf B. |Simon-Weidner |Sent: Monday, April 17, 2006 6:06 PM |To: ActiveDir@mail.activedir.org

RE: [ActiveDir] User Accounts

2006-04-17 Thread Ulf B. Simon-Weidner
seen large directories in this range. |All of my experience with directories 25M objects was outward facing. |IE, internet portal types, like Brett was talking about. | |~Eric | | |-Original Message- |From: [EMAIL PROTECTED] |[mailto:[EMAIL PROTECTED] On Behalf Of Ulf B. |Simon-Weidner |Sent

RE: [ActiveDir] User Accounts

2006-04-16 Thread Ulf B. Simon-Weidner
troduction of implementing manuall processes for floating roles) And just in case: ;-) Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz Weblog: http://msmvps.org/UlfBSimonWeidner Website: http://www.windowsserver

RE: [ActiveDir] OU's Structure

2006-04-13 Thread Ulf B. Simon-Weidner
Yes - prio 1 is delegation, prio 2 GPOs since you have multiple ways to influence GPOs. Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz Weblog: http://msmvps.org/UlfBSimonWeidner Website: http://www.windowsser

RE: [ActiveDir] Changing a users password

2006-04-12 Thread Ulf B. Simon-Weidner
for this. Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book Windows XP - Die Expertentipps: http://tinyurl.com/44zcz Weblog: http://msmvps.org/UlfBSimonWeidner Website: http://www.windowsserverfaq.org Profile: http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F2F1214C811 D

RE: [ActiveDir] Extending the schema

2006-04-11 Thread Ulf B. Simon-Weidner
Well designed schema updates will not conflict with existing ones - so you shouldn't have any issues - and if you have issues it's most likely another non-MS schema extension. Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book Windows XP - Die Expertentipps: http://tinyurl.com/44zcz

RE: [ActiveDir] default values for net time /querysntp on new systems?

2006-04-11 Thread Ulf B. Simon-Weidner
Actually type NTP or AllSync may use the NTP-Server. AllSync is the reg-setting for w32tm /syncfromflags:MANUAL,DOMHIER (so it's a combination of NTP and NT5DS). If the setting is NoSync or NT5DS the NTP-Server setting is not being used. Ulf |-Original Message- |From: [EMAIL PROTECTED]

RE: [ActiveDir] Server 2003 DNS Admins group permissions

2006-04-06 Thread Ulf B. Simon-Weidner
Might be - you know that you can delegate any eventlog by adjusting the CustomSD Registrykey underneath the specific eventlog in the registry? Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book Windows XP - Die Expertentipps: http://tinyurl.com/44zcz Weblog: http://msmvps.org

RE: [ActiveDir] 2003 DFS/open files

2006-04-05 Thread Ulf B. Simon-Weidner
it, it will inform the user that there's a different version of the file on the server and offer him to reload. But apps which are doing this are pretty rare. Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz Weblog: http://

RE: [ActiveDir] View Delegated Tasks?

2006-04-05 Thread Ulf B. Simon-Weidner
Sounds like http://www.dec2006.com/abstracts.cfm#directorysimonweidner ;-) Ulf From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Dan HolmeSent: Wednesday, March 29, 2006 8:49 AMTo: ActiveDir@mail.activedir.orgSubject: RE: [ActiveDir] View Delegated Tasks?

RE: [ActiveDir] Empty hostname for a Win 2003 server belonging to an AD domain

2006-04-04 Thread Ulf B. Simon-Weidner
How about dsquery * domainroot -Filter ((objectCategory=Computer)(sAMAccountName=computername)) -attr objectSID Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz Weblog: http://msmvps.org/UlfBSimonWeidner Web

RE: [ActiveDir] Finding best way to list servers in AD.

2006-04-03 Thread Ulf B. Simon-Weidner
Why not ((objectCategory=computer)(|(operatingSystem=Windows 2000 Server)(operatingSystem=Windows Server 20003))) This is at least limited to computer objects and should be slightly better. Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book Windows XP - Die Expertentipps: http

RE: [ActiveDir] CNF entries and LDIFDE.

2006-04-02 Thread Ulf B. Simon-Weidner
Excellent writing buddy - hope you are keeping snippets like this for the forth edition ;-) Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz Weblog: http://msmvps.org/UlfBSimonWeidner Website: http://www.windowsser

RE: [ActiveDir] Active Directory Performance for 64-bit Versions of Windows Server 2003

2006-04-02 Thread Ulf B. Simon-Weidner
adjusts on windows depending on the availability of memory. Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz Weblog: http://msmvps.org/UlfBSimonWeidner Website: http://www.windowsserverfaq.org Profile:http://mvp.support.mic

RE: [ActiveDir] display name confusion

2006-04-01 Thread Ulf B. Simon-Weidner
in time) in San Fransisco so I may expect it earliest tonight. Was nice meeting you - and glad you've made it out of the lurking space ;-) Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz Weblog: http://msmvps.org/UlfBSi

RE: [ActiveDir] Thanks to all who came to DEC 2006

2006-04-01 Thread Ulf B. Simon-Weidner
and spent time with us - there were a lot of great discussions between all of the attendees, speakers, MS, and the conference would not be the same without their support physically being there. Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book Windows XP - Die Expertentipps: http

RE: [ActiveDir] Reset Local Admin Passwords

2006-04-01 Thread Ulf B. Simon-Weidner
Sincerely, Ulf B. Simon-Weidner MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz Weblog: http://msmvps.org/UlfBSimonWeidner Website: http://www.windowsserverfaq.org Profile:http://mvp.support.microsoft.com/profile=""> From: [EMAIL PROTE

RE: [ActiveDir] Quiet? DEC? Related?

2006-03-31 Thread Ulf B. Simon-Weidner
Hmm - they figured that one out while under NDA ;-) Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book Windows XP - Die Expertentipps: http://tinyurl.com/44zcz Weblog: http://msmvps.org/UlfBSimonWeidner Website: http://www.windowsserverfaq.org Profile: http://mvp.support.microsoft.com

RE: [ActiveDir] Quiet? DEC? Related?

2006-03-31 Thread Ulf B. Simon-Weidner
Nope, handed out with but not in the bag. Was only 128. It you want me to mail you the content let me know. Easier than writing on the plane ;-) Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book Windows XP - Die Expertentipps: http://tinyurl.com/44zcz Weblog: http://msmvps.org

RE: [ActiveDir] Copying OU permissions

2006-03-24 Thread Ulf B. Simon-Weidner
Title: Message Hi David, my script at http://www.windowsserverfaq.org/faq/CompACLs.aspprovides you with all the parts you need to put your script together. Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz Web

RE: [ActiveDir] AdminSDHolder

2006-03-20 Thread Ulf B. Simon-Weidner
Object inheritance is disabled by default on those protected objects as well. If you enable inheritance on the adminSdHolder the objects will inherit permissions. Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz Weblo

RE: [ActiveDir] Extending AD Schema

2006-03-20 Thread Ulf B. Simon-Weidner
to be unique. For all those Attributes there's no supported way in changing them afterwards. So make sure whatever used is as unique as you are sure no other company ever would consider using the same ones. Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book Windows XP - Die Expertentipps: http

RE: [ActiveDir] AdminSDHolder

2006-03-17 Thread Ulf B. Simon-Weidner
://msmvps.com/blogs/ulfbsimonweidner/archive/2005/05/29/49659.aspx Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz Weblog: http://msmvps.org/UlfBSimonWeidner Website: http://www.windowsserverfaq.org Pr

RE: [ActiveDir] View Delegated Tasks?

2006-03-17 Thread Ulf B. Simon-Weidner
Since it hasn't been mentioned - LDP of R2 and ADAM provides the possiblity to view the ntSecurityDescriptor as well. Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book Windows XP - Die Expertentipps: http://tinyurl.com/44zcz http://tinyurl.com/44zcz Weblog: http://msmvps.org

RE: [ActiveDir] AdminSDHolder

2006-03-17 Thread Ulf B. Simon-Weidner
. AdminSdHolder is a object which has IMHO no specific use, just to hold a securityDescriptor to use as template. Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz Weblog: http://msmvps.org/UlfBSimonWeidner Web

RE: [ActiveDir] Forest Recovery Question

2006-03-12 Thread Ulf B. Simon-Weidner
but some indexes from the domain database. Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz Weblog: http://msmvps.org/UlfBSimonWeidner Website: http://www.windowsserverfaq.org Profile:http://mvp.support.microsoft.c

RE: [ActiveDir] Migrating AD to a lab

2006-03-11 Thread Ulf B. Simon-Weidner
€ Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz Weblog: http://msmvps.org/UlfBSimonWeidner Website: http://www.windowsserverfaq.org Profile:http://mvp.support.microsoft.com/profile=""> From: [EMAI

RE: [ActiveDir] Technet Magazine Active Directory Component Jigsaw

2006-03-08 Thread Ulf B. Simon-Weidner
Hi Todd, this would rock if you are able to scan it (or somebody has contacts to the team to request a printable-file)? Subscriptions are only free for US Residents (shipping costs), and the web-version does not include the picture. Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book

RE: [ActiveDir] Bulk Import

2006-03-08 Thread Ulf B. Simon-Weidner
If you mention google after MSN Search you have to turn off the shamless plug. ;-) From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Al MulnickSent: Thursday, March 09, 2006 3:26 AMTo: ActiveDir@mail.activedir.orgSubject: Re: [ActiveDir] Bulk Import If

RE: [ActiveDir] How Secure is a Domain Controller?

2006-03-06 Thread Ulf B. Simon-Weidner
after a DC has been stolen. Since I'm talking about admin and service-accounts it's not enforceable via GPO - at least not without 3rd party software or a special domain design. Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book "Windows XP - Die Expertentipps": http://tinyurl

RE: [ActiveDir] Dynamic Groups

2006-03-06 Thread Ulf B. Simon-Weidner
And keep in mind that it only works when users are logging off and on (at least for domain groups) so that the token is recreated - so running it multiple times a day is propably not practical. Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book "Windows XP - Die Expertentipps&qu

RE: [ActiveDir] Resolving SIDs

2006-03-06 Thread Ulf B. Simon-Weidner
of the SID without resolving it to the domain. Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz Weblog: http://msmvps.org/UlfBSimonWeidner Website: http://www.windowsserverfaq.org Profile:http://mvp.support.microsoft.c

RE: [ActiveDir] How Secure is a Domain Controller?

2006-03-05 Thread Ulf B. Simon-Weidner
I've written down some related thoughts once: http://msmvps.com/blogs/ulfbsimonweidner/archive/2004/10/24/16568.aspx Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz Weblog: http://msmvps.org/UlfBSimonWeidner Web

RE: [ActiveDir] Active Directory Backup

2006-03-04 Thread Ulf B. Simon-Weidner
not need to boot into directory recovery mode here. However note that you are able to reset the directory recovery mode administrators password as long as you have the domain admin by logging on while AD is active, then use ntdsutil to reset the DSRM Admins password. Gruesse - Sincerely, Ulf B

RE: [ActiveDir] Trouble adding a new server to an AD domain

2006-03-03 Thread Ulf B. Simon-Weidner
Hi Gene, the Infrastructure Master is not the most critical role. However if you have a backup of that system I'd recommend a restore of the Systemstate. If not, I'd seize the Infrastructure Master to another server, clean up the Active Directory from the remainers of the old server

RE: [ActiveDir] AD Lag Sites

2006-03-03 Thread Ulf B. Simon-Weidner
a at least half week old copy of the AD intheone of theLag-Site. And I've even heard fromsomeone using seven lag-sites for every day in the week. Perhaps he's jumping into this thread later ;-) Gruesse - Sincerely, Ulf B. Simon-Weidner MVP-Book "Windows XP - Die Expertentipps": http

  1   2   3   >