available columns in ADUC
In ADUC, from "View" -> add/remove columns I can't see some useful columns
such as mobile number and fax number for user objects. How can I add them to
the available columns list?
many thanks
|
3/11/2010 3:35:02 AM
|
1
|
"tree leafs" <treele...@hotmail.com>
|
|
deleted objects
Can the deleted objects container to made to be visible in ADUC or ADAC? I
tried following this article http://support.microsoft.com/kb/892806 but
without my much help. I have a 20008 R2 with Recycle Bin Enabled. I tried
using LDP and ADSIEDIT, can find it there as well
|
3/11/2010 2:32:09 AM
|
1
|
"Venkat" <Ven...@live.com>
|
sharing permission
Hello,
I created a sharing folder 'test'.
user: user01,user02,user03,user04
group: user_gp1-> user01 and user02
user_gp2 -> user03 and use04
user01 and user02 have full right for test folder.
user03 and user04 have read right for test folder.
I don't have problem about this setiing.
When I chage to
user_gp1 has full right for test folder.
user_gp2 has read right for test folder.
none of users can acces test folder.
anything wrong?
Thanks
|
3/10/2010 7:41:01 PM
|
1
|
=?Utf-8?B?TmV3Ymll?= <New...@discussions.microsoft.com>
|
Win2k3 patches failed - secpol wont let me modify privs
Hi
I am working in an AD win2k3 R2 SP2 domain with a PDCE and a DC.
I just tried to update patches on the DC logged in as a Domain admin and most
of the patches failed. When I checked, it was insufficient privs.
I launched secpol to try to verify permisions for the account I was using and
when I opened 'user rights assignment' there was an info note at the bottom
of the pane that said "this setting is not compatible with computers running
windows 2000" and the option to add users was grayed out. As I mentioned
before, We're running Win2k3 R2 SP2.
This may (or may not) also ti
|
3/10/2010 4:05:08 PM
|
6
|
"kabbott via WinServerKB.com" <u56...@uwe>
|
how to get the Account Disabled Date
How can I read the date a specific account was disabled
eg what else needs to go in here?
>dsquery * dc=mydomain,dc=lab -filter "(&(objectClass=person)(name=nik))
>" -attr displayName givenName sn WhenCreated
|
3/10/2010 2:24:33 PM
|
1
|
"Nik" <test>
|
synchronising domains
Hi,
I have two domains, A and B, both with Windows 2003 server.
Domain A contains several accounts which I want to sync to the other domain B.
Is that possible?
I believe so it was in NT 3.51 (..), simple by trused and trusting domains?
Thanks in advance.
John
|
3/10/2010 2:12:01 PM
|
6
|
=?Utf-8?B?Sm9obg==?= <J...@discussions.microsoft.com>
|
Account Administrator
I want delegate responsibility for one of our OU (Organizational Unit).
Is there a possibility to create Account Administrator only for one OU?
I do not want delegate the Administration of other OU. How to solve such
a small problem?
MarcusB
|
3/10/2010 9:32:16 AM
|
2
|
MarcusB <marc...@llunet.se>
|
domain server releated issue
Hi
I am having three servers one with windows 2003 domain controller,
additional domain controller and last one as fileserver.
when ever there is problem with my primary domain controller server(server
down), users are not able to access the fileserver(share folders), but same
users able to log in domain server, able to access internet authenticated via
additonal domain controller and resolving dns.
I want to know when primary dc is down can i able to access my fileserver i
mean users share folders or i have do any changes.
Need help on this
Regards
Alex
|
3/10/2010 8:01:02 AM
|
3
|
=?Utf-8?B?QWxleHl5?= <Ale...@discussions.microsoft.com>
|
.Net
What is NetFx2-ServerCore? do i need it on my Server Core Domain
Controller??
|
3/9/2010 8:55:37 PM
|
1
|
"Glen" <G...@live.com>
|
ADRB
I see some posts saying that AD Rcycle Bin should be enabled using PS
cmdlets on the Schema Master...Enable-ADOptionalFeature -Identity
<ADOptionalFeature> -Scope <ADOptionalFeatureScope> -Target <ADEntity>
Is that correct, if so what is reasoning behind this?
|
3/9/2010 5:41:21 PM
|
4
|
"Glen" <G...@live.com>
|
Restrict workstation to only allow logon by one user
I have a workstation on our network that should only allow a specific user
or group of users to login there. I can restrict the user to a specific
workstation but I want to restrict a workstation to specific users.
How do I configure that?
|
3/9/2010 5:09:07 PM
|
6
|
"Chegu Tom" <noem...@yahoo.com>
|
Help!!! Migration Problem!
Morning Guys,
We're migrating from one Windows 2003 domain to another (acquisition).
DomainA.lab - Forest Trust 2000, Domain Trust 2003
DomainB.lab - Forest Trust 2003, Domain Trust 2003
Migration from DomainA.lab to DomainB.lab - Trust relationship external,
2-way, Domain Wide Authentication
Side Filtering disabled on both domain and I can also see the SID History
attribute which is correct
Problem:
Users in domainA cant can't access SOME shares on domainB computers. The
SIDHistory attribute in DomainB matches the SID of the group in DomainA, but
still no luck.
Any suggestion
|
3/9/2010 3:38:11 PM
|
14
|
"Nik" <test>
|
Group olicy for Internet Explorer Proxy settings not being applied.
Some of the computers on our domain are not applying the policy for
Internet Explorer Proxy settings
The clients are typically Windows XP with Service pack 2
The domain controllers are Windows 2003 R2 with service pack 2
the Policy has the following settings:
User Configuration (Enabled)
Policies
Windows Settings
Internet Explorer Maintenance
Connection/Proxy Settings
Enable proxy settings
Protocol Server Port
HTTP proxy 8080
Secure proxy 8080
FTP proxy 8080
Gopher proxy 8080
Socks p
|
3/9/2010 3:32:16 PM
|
1
|
yodaqs <yod...@gmail.com>
|
DFSR
I have a Windows 2003 domain controllers and want to upgrade all my DC's to
windows 2008. Now i want to know if after upgrading all my dc's and raising
the domain level to w2k8, will sysvol start replicating using DFSR? or
should we follow the FRS to DFSR migration path?
My understanding is that all new domains that have been started with w2k8/r2
will by default use DFSR?? is that correct? I have noticed that even after
staring the AD forest with a wk28r2 dc, there were no DFS Role Services
installed..is that the default behaviour? should DFS Role Service be
installed after th
|
3/9/2010 2:15:55 PM
|
0
|
"Clot" <c...@live.com>
|
DCDIAG: failed test NCSecDesc
After promoting new server as domain controller and demoting the old
one I get this from DCDIAG on new DC:
Starting test: NCSecDesc
* Security Permissions check for all NC's on DC NEWDC.
The forest is not ready for RODC. Will skip checking ERODC
ACEs.
* Security Permissions Check for
DC=ForestDnsZones,DC=domain,DC=local,DC=hr
(NDNC,Version 3)
Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't
have
Replicating Directory Changes In Filtered Set
access rights for the naming context:
|
3/9/2010 8:14:31 AM
|
1
|
Drazen <delfince...@gmail.com>
|
dsquery -inactive get bad results
Hi!
When running dsquery user -inactive command one of the account displayed is
for example my account and i'm sure that i am not inactive, and using it
everyday
The same thing happens if i run dsquery computer -inactive, all the domain
controllers name appears in the list.
Why this command could get bad results?
|
3/9/2010 1:56:46 AM
|
0
|
"Eduardo Ceh" <eduardo....@yucatan.gob.mx>
|
Export user names as a list?
Hello, is there a way to attain a list of user names from an AD Windows 2003
Server as to where it can be copied/pasted as text? Thanks in advance.
|
3/8/2010 11:03:28 PM
|
1
|
"." <noth...@nothing.com>
|
Is There A Way to Test if Global Catalog Functioning Correctly
Still dealing with some cleanup issues from a DC loss last week. The DC was
a Global Catalog server. However, I *believe* we had another one in place.
At least, there was a checked GC box under the NTDS properties. However, I
was wondering if there is some sort of test to make sure a GC is available
and functioning before I proceed with the metadata cleanup of the dead
domain controller?
Not that it matters much at this point, I suppose. Still, it would be nice
to go into this feeling comfortable about having a GC available.
Thanks
|
3/8/2010 4:59:35 PM
|
5
|
"Mark C" <ma...@askfordomain.ok>
|
finally going native
We FINALLY turned off our last NT 4.0 domain controller a few months back
and are now looking to move our Windows 2003 domain from mixed to native
mode. I KNOW management is going to have a problem with the idea that there
is no rollback plan for this move.
Anyone ever encountered a problem with moving to 2003 Native? We are a
single domain, single site infrastructure. Can't really get more simple.
Thanks,
Phil
|
3/8/2010 4:19:27 PM
|
2
|
"Phil McNeill" <philmcne...@REMOVETEXTINCAPShydroottawa.com>
|
Creating a sub domain
Dear All
I have created one Primary domain and a Secondary domain server in my
local infrastructure already.My primary domain name is EXAMPLE.COM.It
contain only 175 node.Now we going to start a branch office for our
company.So i need to create a sub domain for my primary domain server
like BRANCH.EXAMPLE.COM.It contain 100 node.
Now i wand to know how to create a sub domain.What is the best way to
create it.What I mean that is it i install my sub domain server on my
main office and then ship it into the branch office.Otherwise i will
create sub domain in my branch office through
|
3/8/2010 2:41:22 PM
|
2
|
khan <pnawask...@gmail.com>
|
DCDIAG error, inconsistency in the DS
Suddenly we recieved this errors whenever we run dcdiag in all our Domain
controllers. It is a bit unfriendly error.
Environment is Windows 2003 R2 ent, Forest and Child domain models.
Anyone can assist, shed light what is this error all about?
Domain Controller Diagnosis
Performing initial setup:
***ERROR: There is an inconsistency in the DS, suggest you run dcdiag in a
few moments, perhaps on a different DC.
|
3/8/2010 10:23:01 AM
|
7
|
=?Utf-8?B?QURTYWRtaW5z?= <ADSadm...@discussions.microsoft.com>
|
Applying group policy only to members of a domain local security group
So there is domain ABC.local with various OUs and sub-OUs defined.
There is also domain local security group (placed in ABC\Users)
defined whose members are users from various OUs/subOus. If I wanted
to apply group policy only to that securiy group, how would I do that?
I tried to link group policy object at the ABC.local domain level and
then apply security filtering by removing Authenticated users group
and adding domain local security group containing users from various
OUs.
However the policy did not apply to the users. When I linked group
policy object to OUs where users resi
|
3/6/2010 9:56:22 PM
|
2
|
Drazen <delfince...@gmail.com>
|
WINS question
Hi, i am from Spain, excuse my English
I have a 2003 domain with XP pro SP2 clients
I have two WINS servers but i dont know if WINS servers are necesary in my
enviromment.
What happened if i disable WINS server i my domain ?
Is convenient WINS Servers in my Domain ?
Thanks,
ZIDAC
|
3/6/2010 5:18:03 PM
|
3
|
=?Utf-8?B?WklEQUM=?= <ZI...@discussions.microsoft.com>
|
Answer File
This is a multi-part message in MIME format.
------=_NextPart_000_0006_01CABD5F.8BEFECE0
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
In Windows Server 2008 dcpromo answer file we used =
RebootOnSuccess=3DYes, can the same be still used in Windows Server 2008 =
R2? or do we have to mandatorily use RebootOnCompletion=3DYes instead?
What is the receommended option in both 2008 and 2008 R2?
------=_NextPart_000_0006_01CABD5F.8BEFECE0
Content-Type: text/html;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
<!DOCT
|
3/6/2010 1:32:20 PM
|
5
|
"Dart" <d...@live.com>
|
Software Install via GPO
I have a gpo that is supposed to push the software. I created it, and made
sure that the unc path is appropriate in the gpo but it will not push the
software. What could I be missing? The DC is W2k3 and the settings are pretty
basic. Any ideas?
|
3/5/2010 11:44:10 PM
|
2
|
=?Utf-8?B?Q0s=?= <...@discussions.microsoft.com>
|
2003 AD user looses rights to home directory
I have a single user in my AD2003 that seems to have lost rights to her
home directory.
I have checked her group and user permissions and everything is good. I
have deleted and recreated the home directory. Even tried logging in
from a different PC to eliminate XP profile issues. for some reason she
simply can't write anything to her home folder. she can see it but
doesnt have the ability to put anything in the folder.
If no other solution I may try deleting the user and recreating her. but
Just wanted to check and see if anyone else has run across this type of
issue?
John
|
3/5/2010 7:18:41 PM
|
0
|
jwhite4343 <jwhite4343.47d...@DoNotSpam.com>
|
+++++++ Exclude OUs using LDAP Query ++++++++
Hello ...
I need to import all ACTIVE users profiles in MOSS 2007 from AD using a LDAP
Query and I want to exclude 2 OUs ...which have Resouce Accounts.
I have been looking around and noticed that I cannot exclude OUs?????
Anybody done this successfully ....???
Advise Please.
Thank you
|
3/5/2010 5:21:01 PM
|
1
|
=?Utf-8?B?V2lsZFBhY2tldA==?= <WildPac...@discussions.microsoft.com>
|
Trust Failed
hi all...
two days ago i encountered a trouble...
i have two server in my office (ad writable, same domain)...
everything was fine since when,two days ago, i get the error " the trust
between this workstation and the primary server cannot be established" or
something like that, because error is in italian...
i cannot log on any pc in my office... the only way is to detach the
ethernet and log being disconnected from server, and then plug in the
network again..
once i do that i can access the pc and but can access only one of the two
server...
what does this mean? h
|
3/5/2010 5:10:16 PM
|
6
|
Slepland <slepl...@Italianvampires.it>
|
Default groups and security permissions
When a new Domain Controller is created the Default groups (Domain admins,
Enterprise Admins, Schema admins etc) under the OU users are also created.
if you see the security tab for each of them, specailly Domain admins,
Enterprise Admins you will see that the Administrators groups has the check
mark on all permissions except for Full controll. Isn't this a flaw, let's
say you need to grant permissions to an user to manage the domain
controllers. Any user member of the built-in\administrators can go and
elevate permissions to domain admins, enterprise admins etc.
Has anyone
|
3/5/2010 2:09:01 PM
|
7
|
=?Utf-8?B?WGF2aWVy?= <Xav...@discussions.microsoft.com>
|
Locked Out User
I have one user who keeps getting locked out. As soon as we unlock the
account and he logs in his account locks again. We removed/added his computer
to the domain, deleted and recreated his user account and it just won't go
away. Any ideas? Anyone see this before? Any troubleshooting ideas?
|
3/5/2010 1:47:02 PM
|
5
|
=?Utf-8?B?dGt1dGls?= <tku...@discussions.microsoft.com>
|
Licensing
What are the licensing requirements for upgrading Windows server 2003 to
windows server 2008 or 2008 r2??
|
3/5/2010 1:08:53 PM
|
2
|
"Dart" <d...@live.com>
|
Delagate account operator resposibility
I need simple script for our secretary for resetting password, account
expiration.
She do not belong to account operator group therefore I need that script
will be run as another user with rights to change user password etc.
User and passwor dcould be encoded in script.
Is there any ready script? It will be nice if script will check if
account exist and will allow reset password by writing it two
times(avoid mistakes)
Doeas any of you have already such vbs script?
Regards
Raff
|
3/5/2010 11:40:08 AM
|
1
|
MarcusB <marc...@llunet.se>
|
Unable to install AD FS 2.0 on windows server 2008 sp2
Hi,
I am not able to install AD FS 2.0 on Windows server 2008 sp2, getting
error "AD FS 2.0 installation requires Windows server 2008 sp2". I Just
installed all the items listed in the below webpage as a pre-requisite
for AD FS 2.0 but still not able to proceed further.
http://technet.microsoft.com/en-us/library/dd807096(WS.10).aspx
Any help will be appreciated.
Thanks,
--
Msreddy
------------------------------------------------------------------------
Msreddy's Profile: http://forums.techarena.in/members/191069.htm
View this thread: http://forums.techarena.in/active-
|
3/5/2010 5:43:20 AM
|
0
|
Msreddy <Msreddy.47c...@DoNotSpam.com>
|
Remote Desktop Users
Is it possible to restrict RDP users to a Windows 2008 R2 DC?
By default all Domain Admins are allowed.
Want to just allow some admin users, not all Domain Admins.
Jordan
|
3/5/2010 12:07:51 AM
|
3
|
Jordan
|
Reintegrating a failed FSMO server into Active Directory
Hello everyone,
I have a Windows Server 2003 FSMO that failed approximately 30 days ago.
We were waiting on a replacement component to arrive.
This part has now arrived, and I'm curious as to what steps I need to take
to reintegrate this server back into our Active Directory.
The server was NOT removed from Active Directory.
Since January 27th, the domain has been running on a secondary domain
controller (Windows 2000), there have been quite a few changes (new
accounts, password changes, groups, etc).
Is the procedure to simply turn the repaired domain controller back o
|
3/4/2010 7:25:14 PM
|
7
|
"Glen Miller" <glen1...@kawarthacomputing.com>
|
Managed Service Account
This is a multi-part message in MIME format.
------=_NextPart_000_0009_01CABBFD.9060E670
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
I do not see an option to create a Managed service Account using =
ADCU/ADAC, how can this be enabled? While i understand using powershell =
is the recommended way to create Managed Service Accounts, i would like =
to know what is the difference in an MSA object that is created using =
GUI and PS.
------=_NextPart_000_0009_01CABBFD.9060E670
Content-Type: text/html;
charset="iso-8859-1"
Content-Tran
|
3/4/2010 7:18:25 PM
|
2
|
"Quar" <Q...@live.com>
|
In-Place upgrade
We are planning to perform an in-place upgrade of our domain controllers, is
there any recommended order in which the domain controllers have to be
upgraded? e.g. start with Schema Master, PDCE, of the forest root domain and
then migrate DNM, IM, RID, Bridgehead Servers etc..
|
3/4/2010 7:14:31 PM
|
3
|
"Gab" <...@live.com>
|
How to list all acess given to a security group
How do I list all the access grants given to a security group in a
domain? I have a security group that I want to know every access it
has been granted on every server in the domain. I have examined
several utilities and commands but none of them provide the
information I need. The utlities and commands I have tried include
AccessEnum
ShareEnum
Net Group
I have not found any utility in the Windows 2003 Server Resource kit
that can do the task. I did find a command line utility -- PERMS that
was used with NT, but it is not available/usable with Win 2003.
Thanks in advance
|
3/4/2010 6:11:04 PM
|
0
|
Rob <whitew...@gmail.com>
|
Enterprise Subordinate CA & DC Demotion
hi,
what if i demote a DC which is also an Enterprise subordinate CA ?
will it affect the CA service ? (Root CA is stand alone)
from MS docs the only thing i could read is "dont change the hostname
and/or domain membership" not talking anything about DC role
appreciate a early response
rgds
|
3/4/2010 3:45:03 PM
|
2
|
Biju <bijuba...@gmail.com>
|
Hand blender
I neede parts for CBS-77 hand blender
|
3/4/2010 12:42:56 AM
|
4
|
Manuel Oliveira <moliv89...@aol.com>
|
Account lock out threshold
Hello all
I am running in a native 2003 DFL and FFL, all DC's are DNS servers and are
also all running windows 2008 sp1. We have 4 AD sites there are two DC's in
each site. We recently implemented an account lockout policy for the domain,
and we set the threshold to 5 failed log on attempts would lock the account
out. We noticed that a lot of accounts were getting locked out, more than
would appear to be normal. On average we would see roughly 10 user accounts
getting locked out per day, we have roughly 600 users. This to me sounds
high. As a test I raised the account lockout
|
3/3/2010 4:56:09 PM
|
4
|
"sawyer" <occomp...@cox.net>
|
DSMOD from batch and text file
I am trying to run a batch file that will disable user accounts using a text
file.
--Batch file--
@echo off
if {%1}=={} @echo Syntax: disableDNs FileName&goto :EOF
if not exist %1 @echo Syntax: disableDNs %1 not found.&goto :EOF
setlocal ENABLEDELAYEDEXPANSION
set file=%1
@echo.
for /f "Tokens=*" %%u in ('type %file%') do (
set user=%%u
set user="!user:"=!"
@echo DSMOD USER !user! -desc Disabled -disabled yes
DSMOD USER !user! -desc Disabled -disabled yes
@echo.
)
endlocal
--text file--
"CN=Lastname,CN=Firstname,CN=Users,DC=test,DC=com"
"CN=Madeup,CN=Nam
|
3/3/2010 3:11:01 PM
|
3
|
=?Utf-8?B?UGV0ZSBKb25lcw==?= <PeteJo...@discussions.microsoft.com>
|
Create Batch file for laptops to copy templates
Hi Everyone,
I am new to batch file programming and need an expert help to find out
something. I want to create a batch file that runs at login and compares a
local copy of the templates to what we have on the network. We have templates
on a mapped network drive in h:\clients\templates, and on the laptop in
c:\apps\data\clients\templates. When the laptop is offline it substitutes
c:\apps\data to appear as h: drive, that way the files appear to be in
h:\clients\templates. Here’s the basic steps what I need the batch file for:
1. first it checks to see if the computer is on th
|
3/2/2010 8:36:01 PM
|
1
|
=?Utf-8?B?SGVtYWw=?= <He...@discussions.microsoft.com>
|
How To Recover Domain Controller
Hello,
We just lost a domain controller. I have found what looks like some pretty
good documentation on recovery, and I'm about to give it a shot. However, I
know there are often times when real-world experience is often more helpful
than a KB article, so I thought I'd solicit any advice anyone might have.
We lost DC1, one of three DCs in our domain. All DCs are Windows 2003 SP2.
DC1 was on very old hardware that probably cannot be replaced.
DC1 was our primary DNS, Schema Master, and Domain Naming Master. It was
not a Global Catalog server.
DC2 is our secondary DNS, and
|
3/2/2010 4:52:12 PM
|
5
|
"Mark C" <ma...@askfordomain.ok>
|
Setting up Time in an AD domain
We currently have an AD topology in which we have one forest a root domain
and another domain in the forest. It is a placeholder domain topology. In
order to set up time synchronization we have enabled the PDC emulator in the
root domain to synchronize time with an outside time source. Is that all we
have to do or do we need to set the PDC emulator in the placeholder domain to
synchronize outside as well?
|
3/2/2010 2:41:01 PM
|
6
|
=?Utf-8?B?anNrYWxpY2t5?= <jskali...@discussions.microsoft.com>
|
DHCP permissions
Hi.
I have a number of dhcp servers installed on DCs in various offices. I need
to assign a local admin in one of the remote offices permission to manage
the dhcp server in his site not all dhcp servers. If I add admin to the
default local dhcp administrator group in ADUC I believe he will have access
to all dhcp servers in the domain. I need to assign permissions to just one
dhcp server....
Thanks
|
3/2/2010 12:04:48 PM
|
4
|
"southpaw" <nos...@somewhere.com>
|
DHCP Issues
Not sure if this is the proper group for this but here goes...
Our DHCP server has been experiencing problems in the past few weeks and up
until then has been rock solid. The server is also the AD & DNS. The DHCP
will lose all of it's scopes and the so far I have just be restarting the
server to fix the problem. I thought it might be coinciding with the nightly
restarts of the server. There are no real tell tale errors in the event
viewer. Anyone ever see this before?
|
3/1/2010 5:27:01 PM
|
3
|
=?Utf-8?B?dGt1dGls?= <tku...@discussions.microsoft.com>
|
GPO active desktop wallpaper does not work on windows 7
Maby someone here can help me.
I manage the system for a small business with 2003 server and XP clients.
I use a GPO for the wallpaper (active desktop .htm file).
On XP this runs very fine however I now am testing Windows 7 and I cannot
get the GPO to work.
I have found this article: http://support.microsoft.com/kb/977944 and
installed the hotfix, this did not help.
I also used the workaround registry edit but this also makes no difference.
I keep getting the black desktop and can localy edit everything but with the
same user on an XP machine the GPO wors fine (with correct w
|
3/1/2010 11:57:01 AM
|
3
|
=?Utf-8?B?SGFybWphbiBPbHRob2Zm?= <HarmjanOlth...@discussions.microsoft.com>
|
How to check is child domain support Windows 2008 R2?
Hi!
Is there a way to know if a child domain is ready to have Windows 2008 R2
Domain Controllers?, using ADSIEDIT i checked and the forest schema is at
47, the parent domain already has 200 R2 DCs , but how can i tell if the
child domain is ready?
Tnx
|
3/1/2010 3:24:29 AM
|
3
|
"Eduardo Ceh" <eduardo....@yucatan.gob.mx>
|
Time
When modifying registry to setup logging of Time service on domain
controllers there are three keys that are applied using a script:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Parameters\Log
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Parameters\WriteLog
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Parameters\Servicedll
I would like to know what is the function of servicesdll?
|
2/28/2010 4:56:42 PM
|
1
|
"Kerry" <Ke...@live.com>
|
renaming windows 2003 domain
Hi all,
I have successfully rename my windows 2003 domain using rendom and gpfixup.
There is only 1 dc in my environment. But my clients login still reflect the
old domain during login. I have followed the requirement of restarting my
domain clients for more than 2 times but to no avail. Pls advise. Thks in
advance.
|
2/28/2010 3:03:01 PM
|
5
|
=?Utf-8?B?aW5lbmV3Ymw=?= <inene...@discussions.microsoft.com>
|
ad user to Local group
Hello, I was told that I need to add the user to the DHCP Administrators
local group if I do not want the same user to have control over the
other DHCP servers I have, How can I accomplish this ?
Thank you
--
aconti
------------------------------------------------------------------------
aconti's Profile: http://forums.techarena.in/members/73272.htm
View this thread: http://forums.techarena.in/active-directory/1310820.htm
http://forums.techarena.in
|
2/28/2010 7:21:25 AM
|
0
|
aconti <aconti.473...@DoNotSpam.com>
|
How to promote a secondary server
Hi
I have doubt over setup a primary and secondary server in windows 2003
(or) 2008 new forest in my new office. I promoted one server as a
primary domain. All users are created and it's working fine.I know how
to promote a server to a child domain for primary server. Now I want
to know how i promote another server as a secondary domain. How can I
do it? After promotion how I can conform all my primary data's in
secondary server.
|
2/27/2010 1:22:51 PM
|
5
|
khan <pnawask...@gmail.com>
|
Milenko Kindl Gives an Advice on How to Affair-Proof Your Relationship
Milenko Kindl
Glas Srpske
An affair is one of the most difficult challenges a couple can face,
and nothing destroys a romantic relationship faster than infidelity.
Is it really possible to affair-proof your relationship? The answer
is, "Yes, it's possible." But in order to make that happen, it's
important to know what causes an affair in the first place.
An affair is an extreme symptom of a relationship that has been in
trouble for some time. Affairs do not happen out of the blue and
rarely happen because someone is a bad person. Cheating is caused by
one single factor: "Lack." In
|
2/26/2010 9:28:23 PM
|
4
|
Milenko Kindl <guglgr...@yahoo.com>
|
Problems getting Sysvol to replicate on new Domain Controllers
When adding a new domain controller to the domain, the Sysvol will not
replicate. This error has occurred on three Servers I promoted to test.
Sysvol is replicating fine between the other 8 dc’s (4 in 1 site, each of the
other 4 in their own site).
I have done the following.
Run dcdiag /v
Issues that came up in the log are the failed advertising and sysvol tests
(since no sysvol, this is to be expected). Under the FSMOCheck I noticed the
PDC emulater is not the primary time server…..may not be anything since the
tests passed.
tarting test: FsmoCheck
GC Name: \
|
2/26/2010 5:04:01 PM
|
2
|
=?Utf-8?B?QkgzMzc=?= <BH...@discussions.microsoft.com>
|
Mechanism for applying shared and NTFS permissions
Hello All,
Can someone point me to documentation explaining the mechanism for security
decriptors/attributes when applying permissions via changing group
memberships for users. I do not need to know what file permissions are and
what needs to be set but rather the background mechanism on how it actually
gets applied and when it takes effect. For example, suppose a user is mapped
to a shared drive and has full control on sharing and file system
permissions via group membership. I decide that this person no longer needs
full but rather read access on file/folder, after making th
|
2/26/2010 3:35:22 PM
|
4
|
"Altria" <urbante...@msn.com>
|
Allow users to modify their information
Is there a way to allow users to modify, update their AD information.
Server 2008 SP1, Exchange 2007
|
2/26/2010 11:04:48 AM
|
3
|
"polilop" <fmatosi...@st.htnet.hr>
|
Event ID 2887
I've been getting this error since we upgraded the domain controllers to
server 2008. After enabling the detailed logging I get event ID 2887
about every 3 minutes from my Mac computers:
The following client performed a SASL (Negotiate/Kerberos/NTLM/Digest)
LDAP bind without requesting signing (integrity verification), or
performed a simple bind over a cleartext (non-SSL/TLS-encrypted) LDAP
connection.
Client IP address:
207.157.74.96:49660
Identity the client attempted to authenticate as:
NSSTC-UAH\christymac$
We've tried forcing them to digitally sign their LDAP requests
|
2/25/2010 9:18:32 PM
|
0
|
smithse79 <smithse79.46y...@DoNotSpam.com>
|
Maximum password age question
Group Policy question:
We currently have maximum password age set to 90 days and plan to modify
the setting to 45 days. My question is, what happens to users who have
passwords that are older than 45 days? Are they automatically locked
out or will they be prompted to change their password? I've searched
various forums but didn't find an answer.
Thanks in advance for you help!
--
t3ch13
------------------------------------------------------------------------
t3ch13's Profile: http://forums.techarena.in/members/188710.htm
View this thread: http://forums.techarena.in/acti
|
2/25/2010 6:54:04 PM
|
0
|
t3ch13 <t3ch13.46y...@DoNotSpam.com>
|
AD Recycle Bin - Multiple Domains
Hi group,
I am looking for some more information as to how the recycle bin
operates when you have multiple domains.
We have the following structure:
ad.domain.com = forest
sales.ad.domain.com = domain in ad forest
support.ad.domain.com = domain in ad forest
I enabled the recycle bin with the following command:
> Enable-ADOptionalFeature 'Recycle Bin Feature' -Scope ForestOrConfigurationSet -Target 'ad.domain.com' -server pfrdc-01
Now the recycle bin is working fine for any items deleted in the
ad.domain.com domain, but removing items from either the sales or
support domain
|
2/25/2010 9:26:00 AM
|
6
|
Steven Carr <sjc...@gmail.com>
|
Permissions on msIIS-FTPDir and msIIS-FTPRoot AD user attributes
We have to give the permission to read/write msIIS-FTPDir and msIIS-
FTPRoot AD user attributes for all users under an OU (or to all users
belonging in a security group) to a particular AD user. How can this
be accomplished?
I must point that Delegation wizard does not help. The properties I
mentioned are not exposed and therefore cannot be given permissions
onto.
Regards,
Drazen
|
2/25/2010 7:45:49 AM
|
1
|
Drazen <delfince...@gmail.com>
|
Password lists
I came into an office of about 40 users where they keep all passwords in an
xlsx. I had never kept passwords before- never needed to- . Is this a
common practice?
-- Carly
|
2/25/2010 2:42:33 AM
|
2
|
"News" <...@no.com>
|
Change expired passwords with LDAP
We created a web form which allows users to change their password. We
used the information in this KB article [1]. Usually it works, but when
the userpassword is expired we get this error message.:
> [LDAP: error code 49 - 80090308: LdapErr: DSID-0C090334, comment:
AcceptSecurityContext error, data 532,
We do not want to use an administrative user to set a password. What do
we need to change in our web form, so the user can change the password
himself? Why can a user change an expired password on a desktop?
Patrick
"How To Change a Windows 2000 User's Password Through
|
2/24/2010 9:45:18 AM
|
1
|
Patrick Cervicek <patr...@expires201004.spam.hs-esslingen.de>
|
Service Account
Are there any known repurcussions of either moving or deleting the Managed
Service Accounts Container in a Windows Server 2008 R2 domain?
|
2/24/2010 9:07:12 AM
|
1
|
"Charle" <Cha...@live.com>
|
LSASS Memory Leak in 2003 with Service Pack 1 and 2 installed
There is a similar post to this back in 2007, but it never got answered.
Every few days, right around 5:30 after everyone has logged out, all of a
sudden there is a spike in the non alloc memory usage and all services start
to drop out like dns, login ability, etc. At times it can clear itself up
after about 45 minutes, other times it requires a reboot for the server.
I started running System Monitor last night and right before it cut out too,
it appears that it was lsass that started to drastically climb.
I have seen several entries about lsass memory leaks but they all are
|
2/23/2010 6:04:01 PM
|
1
|
=?Utf-8?B?Y3doaWNrcw==?= <cwhi...@discussions.microsoft.com>
|
GPO & Mandatory Profile
I am configuring a kiosk profile for a timeclock application on a pc. I can
really lock the desktop down and autoadmin login with the user and the
program to start at login, but the user can close the program. My thought was
to place the program shortcut on the desktop in case that happens so the
users can start the program. However, if I enable "Hide and disable all items
on the desktop" the desktop icon from my manadatory profile disappears. If I
disable that setting the desktop is vulnerable.
What other solutions do I have to allow the user to launch just one program
if need
|
2/23/2010 4:22:01 PM
|
1
|
=?Utf-8?B?dGt1dGls?= <tku...@discussions.microsoft.com>
|
msi packages of flash, adobe reader and java runtime?
Hello,
As you guys know, flash, adobe reader and the java runtime need to be
installed in most office environments on every PC. So, where can I
find msi packages for those?
And especially the updates - how can I deactivate the automatic update
functions for them globally, so that only the AD administrator can
provide updates (and where to get the update msi's?)
Is there a site that specialized on that topic?
I guess many system administrators have to deal with this problem, I
would be grateful for any hints.
|
2/23/2010 2:20:17 PM
|
4
|
Peter Siegmann <PSiegm...@mail.nu>
|
LDAP query statistics from the server?
OpenLDAP has an optional "monitor" backend, which exports server performance
stats as a separate tree. ie: cn=Searches,cn=Statistics,cn=monitor has
an attribute containing the number of completed searches done against the
server as a steadily increasing number, and another attribute for the
number currently executing, and so on. It's very handy as a rough monitor
of the usage.
Does AD have anything similar, preferably accessible via plain LDAP calls?
I've read about the STATS control, but that seems to be geared toward
getting stats only about the query it's attached to.
If not
|
2/23/2010 1:54:33 PM
|
3
|
hume.spamfil...@bofh.ca
|
AD 8606 error
Hi there:
I'm maintaining 1 forest root and 6 child domains in a hub and spoke
environmen, all Windows 2003 R2.
I run a repadmin /showrepl in my bridge head server (core-dc1) located in
my forest/root and I have so many of these entries in the log, about 15...
branch1-DRDC\branch1-DRDC via RPC
DC object GUID: 8a683258-7994-4813-80cf-fe1a4866383f
Last attempt @ 2010-02-22 16:25:36 failed, result 8606 (0x219e):
Insufficient attributes were given to create an object. This object
may not exist because it may have been deleted and already garbage coll
|
2/23/2010 10:42:01 AM
|
2
|
=?Utf-8?B?QURTYWRtaW5z?= <ADSadm...@discussions.microsoft.com>
|
Unable to access the active directory
I want to start by saying that I am new to the Windows Server platform. I am
setting up a small local server network with a router that is the gateway and
firewall at 10.10.7.1. A 2003 domain controller with forward and reverse
looking DNS server at 10.10.7.2. And a 2003 small business server at
10.10.7.3.
I think that I have the DNS server setup properly. The small business
server is able to find and join the domain. When I try to complete the
setup, I get the error “Unable to access the active directory”. When I look
at the DNS settings the forward lookup zones show what
|
2/23/2010 5:36:01 AM
|
1
|
=?Utf-8?B?UGhvZW5peGZpZg==?= <Phoenix...@discussions.microsoft.com>
|
Partial Merge
What is the Partial Merge feature in Windows Server 2008 r2?
|
2/22/2010 4:41:08 PM
|
3
|
"Charle" <Cha...@live.com>
|
Lingering Objects -tips?
I'm new in my job and inherited so many issues in our AD..
I have been pulling my hair regarding "lingering objects" issue in my
forest. there are so many DCs that are no longer replicating since they have
been disconnecting for more than 60 days.. ==tombstone state =
Can you give me a tip on how to fix this lingering objects? I have so many
of these errors below.. and I have no idea where to start....
If I have to demote/repromote those DCs not replicating, there are quite a
lot about 15!, will it fix the problem?
************ Errors*****
Internal event: Active Di
|
2/22/2010 4:25:01 PM
|
3
|
=?Utf-8?B?QURTYWRtaW5z?= <ADSadm...@discussions.microsoft.com>
|
Can I change the SID for users in 2008 R2?
Hello,
For reasons I won't waste your time with, I don't want to migrate the
existing AD structure of a relatively small company that is currently on
2003. However the Apple people are using the SID for users for their
profile on their computers. The Apple engineer asked if I could copy the
SID of users on the 2003 system to the 2008 R2 system once I have their
account set up. I have no idea how to do this in ADSIEDIT or if I should
do it at all. He says it will be a few hours of work for him on each APPLE
if I don't do this. I'm happy to oblige him - just not sur
|
2/22/2010 2:37:56 PM
|
3
|
"boe" <bo...@nospammyhotmail.com>
|
LDAP error
Hi,
I'm testing a LDAP connection to my companies Active directory server and
I'm getting the "An invalid dn syntax has been specified." error all the time.
Here is my code:
Dim entry As New DirectoryEntry()
entry.Path = "LDAP://xxxxxx.company.se:389"
entry.Username = "uid=MYAPP,ou=users,ou=internal,o=company"
entry.Password = "yyyyyyyyy"
entry.AuthenticationType = AuthenticationTypes.Secure
Dim search As New DirectorySearcher(entry)
search.ExtendedDN = ExtendedDN.Standard
search.Filter = "(&(ou=ENN)(eriIsManager=Y))"
search.PropertiesTo
|
2/22/2010 1:06:01 PM
|
5
|
=?Utf-8?B?RXJpYw==?= <E...@discussions.microsoft.com>
|
Windows 2008 domain and XP not seeing all servers
We recently upgraded to Windows 2008 domain servers. My XP computer now can
not view any of the servers in Active Directory. Is there a registry setting
to make them visibile again?
|
2/22/2010 1:04:01 PM
|
2
|
=?Utf-8?B?UGVhcmw=?= <Pe...@discussions.microsoft.com>
|
AD CS PEM certificate
Hi everyone;
I've installer ActiveDirectory CS.
I've already try to request PEM certificate, but i cannot request it from
web enrollment...
Is possible to request PEM certificate?
thanks...
|
2/22/2010 12:29:15 PM
|
1
|
"icse" <i...@domain.local>
|
Giving access to AD user attribute read/write
Hi,
We have to give the permission to read/write msIIS-FTPDir and msIIS-
FTPRoot AD user attributes for all users under an OU (or to all users
belonging in a security group) to a particular AD user.
How can this be accomplished?
Regards,
Drazen
|
2/21/2010 12:20:36 PM
|
4
|
Drazen <delfince...@gmail.com>
|
AD REPLICATION
Hello,
I have 2 servers windows 2003. On one of them, Exhange 2003 is installed.
The 2 servers are DC
Exchange Serveur was destroyed and I restored an image (acronis) since 2
days.
Restore succefully with none problem.
BUT in Exchange some users don't receive their emails, they remain in the
queue.
After many research, the probleme comes from AD replication.
When i use REPADMIN /SHOWREPL i have : "The server destination
reject currently replications requests" 2709 consecutives
failures Last success @ 2010-02-13 19:49:11", the day and the time are
exactly the same
t
|
2/21/2010 2:09:17 AM
|
3
|
"R�da" <redtil2...@yahoo.fr>
|
marvendas@gmail.com Kit completo de Solenoides ( solenoid ) + chicote Para Cambio automatico 01M hidramatico Audi A3 Vw Golf gti turbo 40462
Contato: marvendas@gmail.com
marvendas @ gmail.com
marvendas no gmail.com
Kit completo de solenoides para Volkswagem e Audi.
O kit contem:
5 solenoides
2 Epc ( solenoides de pressao )
1 Chicote
Serve para qualquer modelo VW ou Audi fabricados de 1995 ate hoje com o cambio automatico de 4 marchas � 01M
Pre�o: R$ 1900.00
Temos outras tipos de solenoides e artigos importados, nao deixe de fazer uma consulta antes de comprar!
Audi a3 automatico
Audi a3 1.8 t automatico
Audi a3 1.8 turbo automatico
VW Golf gti automatico
VW Golf 2.0 automatico
VW Golf 1.8 turbo auto
|
2/20/2010 3:31:49 AM
|
0
|
kit solenoites audi solenoid.chicote<kit.solenoites.a...@solenoid.chicote.com>
|
Users appear dithered in Global Group, 2003 Fun level
I have an odd situation. I'm troubleshooting a permission issue with our
provisioning team, they are unable to unlock accounts in AD. They are nested
members of the account operators group which technically should give them
this access, however, we have about 250 members in the provisioning team
group and they appear dithered- they are a different color, much lighter than
the usual user icon in AD 2003 Functional domain/forest. The technical
library mentions the group limit being in the millions.
I've never seen this before- any ideas?
--
-Chris
|
2/19/2010 10:19:01 PM
|
4
|
=?Utf-8?B?ZG9jX2tpbmc=?= <dock...@discussions.microsoft.com>
|
AD replication issue!!!
Help!!!
We have an SBS 2000 server and another win2k3 domain controller in our
environment. The two were replicating and have been for many years now.
Last week our SBS server crashed and I had to rebuild it. The last step was
to restore the system state - which restores AD among other things.
As soon as the machine came back up, I started testing to see if it was
actually fully functional again. Right away I noticed that I could not
access ANY shares - not even administrative shares using the server name
(\\server\share). I could only access them by specifying the ip addres
|
2/19/2010 4:58:56 PM
|
50
|
"Brad Pears" <br...@truenorthloghomes.com>
|
pwdlastset View in AD
We changed our passwords every 90 days. Users love to call us and tell us
that they cannot log in. We look in AD at their Account Properties and it is
not locked out. We run a script and find that their password has not changed
for over 90 days. However, Help Desk can not run the script to see this date.
(obviously Help desk would not run a script.)
Is their any way to view Password Last Changes or Password Expire in the AD
Proerties of the account much like we see the other attributes like Account
lock out, Address, Profile...etc.. We have 2003 AD Native
|
2/19/2010 4:34:01 PM
|
2
|
=?Utf-8?B?cG9ib3lfbi5vX3N0eWxl?= <gryphon...@hotmail.com>
|
General Users Container Question
I just happened to read the thread created on 11th Feb 2010, and it got me
thinking.
Whenever I create a security or distribution group, I tend to simply leave
it in the Users container. My domain is kept rather simple, with one site
and domain etc, and just a few of the usual OUs like Sales, Accounts,
Warehouse etc.
Can anyone think of any real obvious advantages of having for example, a
distribution group containing a load of sales people and putting it in
Sales_OU?
Cheers.
|
2/19/2010 3:47:03 PM
|
11
|
"Phil Angus" <ph...@hammerplc.com>
|
Set AD account to never lock out?
Hi,
Is it possible to make an AD account never lock out like the admin user
account?
Thanks
|
2/19/2010 12:00:42 PM
|
8
|
"Whiteford" <...@no.com>
|
Group Policy for Registry Permissions yielding Red X Icon on RSOP
Greetings,
I'm trying to include registry permissions in my policies to lock down
certain keys. Every single key I select I get a "Red X Icon" on the
registry key and the error message says the following:
"The policy xxxxx resulted in the following error Unknown error. Ofr more
information, see %windir%\security\logs\winlogon.log on the target machine."
Well winlogon.log looks perfectly fine, it isn't complaining about anything.
Further, the permissions on the key did apply successfully.
What gives?
|
2/18/2010 9:57:49 PM
|
2
|
<->
|
Pre-authentication failures explained?
Howdy-
In some of our DCs, we see an inordinate amount of Event ID 675s in the Security Log; they
appear to be originating primarily from Macintosh clients that are bound to AD. Is there
anything that can be done (server-side or client-side) to eliminate these specific errors?
Pre-authentication failed:
User Name: machine$
User ID: DOMAIN\machine$
Service Name: krbtgt/DOMAIN.COM.EDU
Pre-Authentication Type: 0x0
Failure Code: 0x19
Client Address: 10.10.10.55 (IP address)
TIA,
BM
|
2/18/2010 7:04:26 PM
|
1
|
Brian MXP <br...@nospam.mit.edu>
|
2008/2008R2??
I like have some assitance in deciding wheather i hv to upgrade my DC's to
2008/2008R2. Can you provide me some link which contains information which
might provide some fatctors that have to be considered in order for me to
take that decision.
|
2/18/2010 5:14:48 PM
|
2
|
"Charle" <Cha...@live.com>
|
Netlogon issues
Hello Guys,
I have a very starnge issue, last night we had to re-ip one of out
windows 2003 DC's so i first Dcprom'ed it down chaged the computer name
and then re-ip'ed the server.
After that I dcpromo'ed the server up and made it a GC and associated
the new Subnet with the site and restarted the netlogon service.
Now When i log on to the DC i get a strange netlogon warining which
says
====================================
Event Type: Warning
Event Source: NETLOGON
Event Category: None
Event ID: 5802
Date: 2/18/2010
Time: 10:18:03 AM
User: N/A
Computer: Server A
Descri
|
2/18/2010 7:25:24 AM
|
0
|
alstar <alstar.46k...@DoNotSpam.com>
|
Import several hunder users
I need to import several hundred users into a new Active Directory domain. I
will receive a spreadsheet with basic information like first and last name
and department. What is the easiet way to import these users into a windows
2008 r2 Active Directory domain. I need a quick how toThanks
|
2/18/2010 12:00:01 AM
|
2
|
=?Utf-8?B?RWRkaWU=?= <Ed...@discussions.microsoft.com>
|
External Trusts and Forest Functional Level
Our domain is at Windows Server 2003 functional level and our Forest is at
Windows Server 2000 functional level. We also have 4 external trusts with
domains in a variety of modes. DomainB is running in 2000 Mixed Mode domain
level and 2000 forest mode. We'd like to move our forest functional level to
2003, but our concerned that this may effect / break the external trusts.
Does anyone have any first hand experience?
|
2/17/2010 10:23:01 PM
|
2
|
=?Utf-8?B?TVN0ZWZhbmk=?= <MStef...@discussions.microsoft.com>
|
AD Domain Controller and RODC
Hi,
Ive got a Domain Controller and a Read Only Domain Controller (RODC).
However, i want to install a printer and save a few folders on the RODC.
Could anyone tell me how to do this, would be very greatful
--
Sem3421
------------------------------------------------------------------------
Sem3421's Profile: http://forums.techarena.in/members/185214.htm
View this thread: http://forums.techarena.in/active-directory/1306919.htm
http://forums.techarena.in
|
2/17/2010 6:29:08 PM
|
0
|
Sem3421 <Sem3421.46j...@DoNotSpam.com>
|
windows 2008 R2 DC questions
Hi all,
We have 3 windows 2003 32bit Domain controllers. we are going to introduce
new windows 2008 domain controllers for around 800 users. Currently, our
windows 2003 DC is configured to use two disk RAID1 for OS, RAID 5 for
database and log. (the database dit is about 120MB). Can we use th same
RAID 1 for OS and RAID 5 for DIT and log? or just use two disk RAID 1 for
everything? Which one is better? any other recommendation?
BTW, will it affect our exchange 2003 and windows XP clients, group policy?
Thank you.
|
2/17/2010 5:46:02 PM
|
4
|
=?Utf-8?B?ZWQ=?= <...@discussions.microsoft.com>
|
Export Certificate with Private Key from CA Management MMC
Hello,
We have an Enterprise Certificate Authority installed in our Windows
2003 Domain. I have minted some Client Authentication certificates,
and I have marked the private keys as exportable.
I am able to install the certs using the web certificate service
(https://CA/certsrv), and I am able to export the certificate and
private key from my computer's local certificate store.
However, I am trying to mint the cert for someone else, as an
administrator, and I want to be able to export the certificate and
private key directly from the CA, rather than installing the
certificates lo
|
2/17/2010 5:28:57 PM
|
3
|
"AlanW." <adwe...@gmail.com>
|
Change User Default Keyboard language using GPO
Hello,
It is possible to Change User Default Keyboard language using GPO ?
I try to create an Adm files which can change the language for one user,
it's work fine, but on the logon screen the language is always by default.
In other word i would like chnage by GPO what i do when i manuelly change
this register key on a locale machine.
HKEY_CURRENT_USER\Keyboard Layout\Preload\1 with the right value according
the language selected.
Can you help me ?
Ty,
|
2/17/2010 4:09:01 PM
|
2
|
=?Utf-8?B?SmF5wrI=?= <...@discussions.microsoft.com>
|
NT 4 and Windows 2008 Upgrade - HELP!!
I have NT 4 domain and a seperate 2003 AD domain, with trusts between, both
ways. I am upgrading my DC's to 2008 presently but I get a message about
breaking NT trusts when running dcpromo - and am afraid to continue. Can
someone tell me for sure what I need to do to ensure that it works after I'm
done? I've read http://support.microsoft.com/kb/942564 and it seems like
this would work, and also http://support.microsoft.com/?id=889030 which again
should work, but I need a definitive answer so I'm hoping one of the MVP's
can assist! I know someone knows the answer - it's just n
|
2/17/2010 2:17:02 PM
|
1
|
=?Utf-8?B?TWFyaw==?= <M...@discussions.microsoft.com>
|
Why AD objects created always have the "domain admins" as owner ?
Hello,
my account is member of the domain admins.
Every time that I create an object, the owner displayed is the Domain
Admins and not my user account.
I know that there is a GPO for files and folders created by an admin to
specify that the user who created the object is the owner (and not the
admin if the user is an admin too) but is it possible to do the same
with an AD object (and so let a user the user as the owner of an
object even if it is member of the domain admins groups)?
thank you
--
Eric
|
2/17/2010 12:21:28 PM
|
1
|
Eric <Eri...@nospam.hotmail.com>
|
Joing old domain and new domain.
Hi,
I have a Windows 2003 domain, seperate Exchange 2003 server which is quite
flaky and I am in the process of designing and building a new Windows 2008
domain, Exchange 2010. The two will act in the begining as seperate domains
but will have to interact for data transfer and more importantly moving
Exchange mailboxes.
What is the best way to achieve this with the idea of dissolving the 2003
domain eventually and running only on the 2008 one. Will I have to do an
adprep? is a trust relationship the best way of doing it? These are the type
of things I need to know.
Any
|
2/17/2010 10:17:02 AM
|
7
|
=?Utf-8?B?RGF2ZQ==?= <D...@discussions.microsoft.com>
|
NT4 to 2003 upgrade - client setup
I am performing an upgrade from NT4 to 2003 and have done a bit of testing
but I am still unsure of the behavior of workstations and servers when they
suddenly find themselves on an upgraded domain.
Currently, the plan is this:
1. Take a NT4 BDC on a virtual machine and upgrade it to 2003. Add
NT4Emulator key.
2. Configure DNS, etc. Verify everything transferred over. Remove
NT4Emulator key.
3. Reboot.
4. Configure clients to use new DNS server.
5. Shutdown all other NT4 BDCs.
Im uncertain at what happens between steps 3 and 4. Will the workstations
continue to be able to a
|
2/16/2010 10:47:02 PM
|
1
|
=?Utf-8?B?ZHJ6YWl1czIwMDA=?= <drzaius2...@discussions.microsoft.com>
|
pcnetsecurity@gmail.com =?UTF-8?B?QXNzaXN0w6puY2lhIFTDqWM=?= =?UTF-8?B?bmljYSAgbWFudXRlbsOnw6M=?= =?UTF-8?B?byBkZSBjb21wdXRhZG9y?= =?UTF-8?B?ZXMgaW5mb3JtYXRpY2Eg?= =?UTF-8?B?Vml0w7NyaWEtZXMgMzEwMjA=?=
Contato: pcnetsecurity@gmail.com
Contato: pcnetsecurity @ gmail.com
Planos a partir de R$ 250,00 .
Assist�ncia T�cnica
Prestamos assist�ncia t�cnica nos computadores de sua empresa ou resid�ncia, e tamb�m possu�mos uma equipe qualificada para fazer a manuten��o no pr�prio local.
- Contratos de Suporte e Manuten��o
Reduza os custos de sua empresa com solicita��es de visitas t�cnicas para seus computadores, elaboramos um contrato de manuten��o integrado para sua empresa onde disponibilizamos: t�cnicos, equipamentos de suporte e substitui��o, e atendimento no hor�rio comercial ou
|
2/16/2010 5:23:11 PM
|
0
|
Assitencia manutencao remocao de virus computador pc<manutencao.assiten...@computador.pc.com>
|
Applock
This is a multi-part message in MIME format.
------=_NextPart_000_0006_01CAAF54.BC57BA20
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
Can applock group policy be hosted on Windows 2003/2008 domain =
controllers?
------=_NextPart_000_0006_01CAAF54.BC57BA20
Content-Type: text/html;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META content=3D"text/html; charset=3Diso-8859-1" =
http-equiv=3DContent-Type>
<META name=3DGENERATOR content
|
2/16/2010 4:39:40 PM
|
2
|
"Grace" <Gr...@live.com>
|