[ActiveDir] OT (sort of) ADC entry in Active Directory

2005-03-25 Thread Burkes, Jeremy [Contractor]
Title: OT (sort of) ADC entry in Active Directory Everyone,     We recently switched over to Exchange 2000 Native mode (successfully) making sure to remove config_ca, srs databases, and then uninstalling the Active Directory Connector from all the servers within our organization.  Switch

Re: [ActiveDir] Logging changes made to GPOs

2005-03-25 Thread Jason B
Anyone have the general price-range on these products?  Web sites don't seem to list it, and after contacting sales, they want all kinds of info just to get a price.  I am just looking for a GENERAL price.  I don't know if they are $99, $99 per client, $1000 or $10,000. - Original Mes

RE: [ActiveDir] OT (sort of) ADC entry in Active Directory

2005-03-25 Thread joe
Title: OT (sort of) ADC entry in Active Directory Not sure if you can delete it or not, however a raw forest with Exchange loaded without ever using ADC will have the Active Directory Connections container.      joe From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Burkes, Jere

RE: [ActiveDir] DHCP Authorization Issue

2005-03-25 Thread Carerros, Charles
I have verified this as well as what Al suggested in his comment and all seems to be fine. I was able to do this two weeks ago at another one of my sites, so I wondering is someone was fiddling with the security on the root domain. I think I'm going to send those administrators some e-mail to veri

RE: [ActiveDir] AD Database size questions.

2005-03-25 Thread Marcus.Oh
Also, I believe in 2003, they've raised the TSL to 120 days as a default. marcus c. oh .\core technologies\cox communications, inc. .\mvp\windows server systems\management [v] 404.847.6117 [c] 404.391.7097 -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf

RE: [ActiveDir] IP Relay Restrictions Attribute format

2005-03-25 Thread joe
Not only is it not documented, it is specified in the schema listing for that attribute that you shouldn't modify it. While I have no doubt it could be worked out, be careful how you use it as you never know if MS decides to change the format.     joe From: [EMAIL PROTECTED] [mailto:[EMAI

RE: [ActiveDir] AD Database size questions.

2005-03-25 Thread Eric Fleischman
> Also, I believe in 2003, they've raised the TSL to 120 days > as a default. Sorry, but no, we did not. ~Eric -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of [EMAIL PROTECTED] Sent: Friday, March 25, 2005 8:36 AM To: ActiveDir@mail.activedir.org Subjec

RE: [ActiveDir] OT (sort of) ADC entry in Active Directory

2005-03-25 Thread Mulnick, Al
There's no point in deleting it either. You could, but why mess with it? In native mode, it won't matter. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of joe Sent: Friday, March 25, 2005 11:04 AM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir]

RE: [ActiveDir] AD Database size questions.

2005-03-25 Thread Gould, Andrew D.
Isn't the TSL being increased in SP1? Andrew Gould -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Eric Fleischman Sent: Friday, March 25, 2005 11:59 AM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] AD Database size questions. > Also, I b

RE: [ActiveDir] LDAP NTLM Authed Channel Encryption Question was LDAPS part 2

2005-03-25 Thread joseph.e.kaplan
Title: Message That is exactly what I saw as well.  Using the IP address kills off the ability to use Kerberos, forcing SNEGO to NTLM, and then the whole connection is encrypted after that even though I did not specific LDAP_OPT_ENCRYPT.   Joe K.   From: [EMAIL PROTECTED] [mailt

RE: [ActiveDir] Site creation and DNZ zones

2005-03-25 Thread Jorge de Almeida Pinto
Hi, The resource records registered by each DC in DNS can also be found in the file NETLOGON.DNS (%WINDIR%\system32\config). The record you say you are missing is: _ldap._tcp.._sites.dc._msdcs.. Check if the this record can be found in the NETLOGON.DNS file on the DCs that should register this re

RE: [ActiveDir] AD Database size questions.

2005-03-25 Thread Jorge de Almeida Pinto
For NEW forests installed with W2K3 SP1 the default is 180 days For UPGRADED forests to W2K3 SP1 the default is 60 days or any value that has been configured manually Jorge -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Gould, Andrew D. Sent: vrijdag 25

RE: [ActiveDir] Logging changes made to GPOs

2005-03-25 Thread Free, Bob
Based on experience purchasing NetIQ, Quest and similar products, I'd say that's because there is such a large range depending on the type if licensing (number of seats/enterprise license/consoles etc) and the support/maintenance contract you negotiate so there really isn't a GENERAL price.

[ActiveDir] AD user account keeps getting locked out

2005-03-25 Thread Pelle, Joe
Hello!   I have a user account that continuously keeps getting locked out.  We’ve reset the user’s password (multiple times), took the computer off of the domain, renamed the computer, put it back on the domain, etc.  This user works primarily out of her home office but is at our headquar

RE: [ActiveDir] AD user account keeps getting locked out

2005-03-25 Thread Lou Vega
Does she either have mapped drives using the old password or any services running under the old password credentials?     From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Pelle, Joe Sent: Friday, March 25, 2005 1:29 PM To: ActiveDir@mail.activedir.org Subject: [Acti

RE: [ActiveDir] OT (sort of) ADC entry in Active Directory

2005-03-25 Thread Burkes, Jeremy [Contractor]
Thanks everyone. I did not know that a raw installation with no ADC installation would have that container. Interesting. Thanks for the information, good thing I did nothing. Jeremy -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Mulnick, Al Sent: Fri

Re: [ActiveDir] AD user account keeps getting locked out

2005-03-25 Thread James_Day
Hi Joe We have seen two causes for this (although there are others). First, we had a service that was started using the user credentials. The password was changed but the service was never updated. Everytime the service attempted to start it would lock the account. The second time we found the

RE: [ActiveDir] AD user account keeps getting locked out

2005-03-25 Thread Sinton, Gary
Sure. Allathutime. Check for RANDEX on your event logs.   From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Pelle, Joe Sent: 25 March 2005 12:29 To: ActiveDir@mail.activedir.org Subject: [ActiveDir] AD user account keeps getting locked out   Hello!   I have a us

RE: [ActiveDir] LDAP NTLM Authed Channel Encryption Question was LDAPS part 2

2005-03-25 Thread joe
Title: Message Exactly. Since I can't find documentation on this anywhere, I feel it should firmly go into the classification of BUG.   From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of [EMAIL PROTECTED]Sent: Friday, March 25, 2005 1:16 PMTo: ActiveDir@mail.activedir.orgSubjec

RE: [ActiveDir] AD user account keeps getting locked out

2005-03-25 Thread Free, Bob
Likely suspects- Applications using cached credentials that are stale. Stale service account passwords cached by the Service Control Manager (SCM). Stale logon credentials cached by Stored User Names and Passwords in Control Panel. Scheduled tasks and persistent drive mappings that have stale c