Hi All, I know this might sound a bit crazy but is it possible to turn off the limitation of 20 character limit for the samAccountName attribute. I understand the 20 character limit for downlevel clients authentication but I will never have downlevel clients authenticating against AD 2003. I looked in the schema master and the attribute max length is 256. When I dcpromo'd the domain I didn't choose pre-compat mode because windows 2000 and above machines are going to be in the domain.
-- Thank you, Steve Schofield Microsoft MVP - ASP/ASP.NET ASPInsider Member - MCP http://www.orcsweb.com/ Powerful Web Hosting Solutions #1 in Service and Support List info : http://www.activedir.org/List.aspx List FAQ : http://www.activedir.org/ListFAQ.aspx List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/