On Thursday 14 October 2004 08:49 pm, Quanah Gibson-Mount wrote: > --On Thursday, October 14, 2004 8:46 PM -0700 Jon LeCroy > > <[EMAIL PROTECTED]> wrote: > > Can you post your script? > > It was in his initial post. > > --Quanah > > --
Apologies. This is a DS side configuration problem. If the bind was failing the domain admins group sid would not be added to your AD side access token and in either context (DA or not) your initial search would then fail. If the AD admins can grant you additional rights (DA) and your code then works unchanged it's up to them to investigate the object ACL to more specifically grant you access without using the blanket DA group. Jon
