Re: [ActiveDir] [OT] RAID 5 Best Practice

2006-05-23 Thread ChuckGaff
Exchange ideally should be run on RAID 1+0 if at all possible, even if it starts off with 4 disks although more is better and a SAN is preferable.  Get the Exchange guides from the MS Technet site and start reading ...   Good luck,   Chuck

RE: [ActiveDir] [OT] RAID 5 Best Practice

2006-05-23 Thread Dave Wade
Title: RE: [ActiveDir] [OT] RAID 5 Best Practice Joe,    Well all agree on that, however we are pretty much stuck with the apps in question "as-is" as the software is supplied "from above" (e.g. the stuff from www.ncer.org). These days I copy the database onto a users PC and they run the repo

RE: [ActiveDir] [OT] Service ChangeConf

2006-05-23 Thread Wyatt, David
Title: Message This maybe overkill but you could use a GPO to do this.  You can configure service permissions, one of which is:   Change Template - Change the configuration of a service. This permission is required so that the user can change the startup type     -David     -Original Mes

RE: [ActiveDir] Group audit

2006-05-23 Thread Wyatt, David
Title: Message Good point!  Thanks.   -Original Message-From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of joeSent: 23 May 2006 5:15To: ActiveDir@mail.activedir.orgSubject: RE: [ActiveDir] Group audit I would set the output up for csv output (see -csv) wh

RE: [ActiveDir] Removing ADAM from configuration set

2006-05-23 Thread Bernier, Brandon \(.\)
Title: Removing ADAM from configuration set My lab has changed a bit but the error remains the same. I have two servers running ADAM SP1 and one isn't ADAM SP1, all in the same configiguration set. The one that isn't ADAM SP1 allows me to use DSMGMT to remove any server from the configuratio

RE: [ActiveDir] IIS 6

2006-05-23 Thread James Eaton-Lee
On Tue, 2006-05-23 at 10:59 +1000, Ken Schaefer wrote: > : -Original Message- > : From: [EMAIL PROTECTED] [mailto:ActiveDir- > : [EMAIL PROTECTED] On Behalf Of Za Vue > : Sent: Tuesday, 23 May 2006 10:54 AM > : To: ActiveDir@mail.activedir.org > : Subject: [ActiveDir] IIS 6 > : > :

Re: [ActiveDir] [OT] RAID 5 Best Practice

2006-05-23 Thread Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP]
Depends on the data. These days with identity theft rampant... anything with a PII element would be on a desktop over my dead body. Software suppliers also tell me to run as admin and these days we need to push strongly back on that as well. Access works for a 'small' multi user app.. and

RE: [ActiveDir] Delete only one object in the Tombstone.

2006-05-23 Thread Grillenmeier, Guido
hmm - what would be the reason why you'd want to purge a single deleted object (tombstone) from your AD?  What secret information does the tombstone contain, that you don't wish remains in it?  Realize that there are hardly any attributes that remain in the tombstone by default, unless you'v

RE: [ActiveDir] (OT)Non authenticating DC

2006-05-23 Thread Grillenmeier, Guido
maybe mark meant it as "on topic" :-) I'm also not aware of any such changes, but as the mgmt of Read-Only DCs (e.g. for PW replication or Admin Separation) is also not fully finalized yet, we may see additional GPO options to configure various aspects of the DCs. Who knows - maybe disabling authe

RE : [ActiveDir] Delete only one object in the Tom bstone.

2006-05-23 Thread TIROA YANN
Hi Guido, There is no secret behind the wall :o) This is the full story. I have Active Directory Connectors that permit bidirectionnal replication of all 5.5 mailboxes <-> Active Directory Forest. The pb is that i had an issue where a user object had the ADC-Global-names mapped with multipl

[ActiveDir] Build an AD test lab with schema extension.

2006-05-23 Thread TIROA YANN
Hello all,   I'm working on duplicating my AD env. into a test lab.   I read lots of posts about this and choosed to use the "CreateXMLFromEnvironment.wsf" and "CreateEnvironmentFromXML.wsf" only.   The question is: I did a schema extension on my AD prod and i wondered if the 2 scripts will al

Re: [ActiveDir] (OT)Non authenticating DC

2006-05-23 Thread Mark Parris
Nope - I meant OT at the time as we had just flammed a sarastic post and I was not in the mood for a flaming of my own. Anyway thanks for replying and perhaps "The Canadian" is making notes. Mark -Original Message- From: "Grillenmeier, Guido" <[EMAIL PROTECTED]> Date: Tue, 23 May 2006

[ActiveDir] AD DNS along with Bind

2006-05-23 Thread Adeel Ansari
Team, Is is possible to have AD DCs manage all the dynamic zones i.e. _tcp, _udp, _msdcs etc. and have the rest of the non-AD zones managed by Bind. Has anyone done something like this? There is a MS article (ID:255913) that talks about it however, it doesnt say what DNS should client point to? R

RE: [ActiveDir] [Exchange] Full Mailbox Directory Name holds wrong Administrative Group name

2006-05-23 Thread Victor W.
Thank you both very much for the replies and for the clear explanations.   I think I will leave the legacyExchangeDN alone then. I was thinking about changing it because part of it refers to an object (Administrative Group) that no longer exists. I am still a bit puzzled why it not updates it

RE: [ActiveDir] I try to execute applications in a script of a GPO but close after a few seconds

2006-05-23 Thread Darren Mar-Elia
The only thing that GP will do around script execution is limit the combined time that all scripts will run, to prevent hanging scripts from hanging up a startup or logon process. The default total time for script execution is 10 minutes but you can adjust this using the policy at Computer Conf

RE: [ActiveDir] AD DNS along with Bind

2006-05-23 Thread Thommes, Michael M.
Adeel, Here is a response from our DNS guy. I hope it helps you. Mike Thommes = Here are the steps I took for delegating the AD zones for example.com: 1) In the example.com zone on the BIND server I added these NS records to delegate the zone t

RE: [ActiveDir] AD DNS along with Bind

2006-05-23 Thread Adeel Ansari
Mike, This is very detailed and clearly written. I appreciate it, say my thanks to your DNS guy! Adeel -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Behalf Of Thommes, Michael M. Sent: Tuesday, May 23, 2006 3:38 PM To: ActiveDir@mail.activedir.org Subject: RE: [A

RE: [ActiveDir] IIS 6

2006-05-23 Thread Ken Schaefer
: -Original Message- : From: [EMAIL PROTECTED] [mailto:ActiveDir- : [EMAIL PROTECTED] On Behalf Of James Eaton-Lee : Subject: RE: [ActiveDir] IIS 6 : : On Tue, 2006-05-23 at 10:59 +1000, Ken Schaefer wrote: : > : -Original Message- : > : From: [EMAIL PROTECTED] [mailto:Ac

RE: [ActiveDir] IIS 6

2006-05-23 Thread Brian Desmond
I thought he wanted to access them by name without the DNS entries e.g. for testing or something. Thanks, Brian Desmond [EMAIL PROTECTED] c - 312.731.3132 > -Original Message- > From: [EMAIL PROTECTED] [mailto:ActiveDir- > [EMAIL PROTECTED] On Behalf Of Ken Schaefer > Sent: Tuesday,

Re: [ActiveDir] IIS 6

2006-05-23 Thread Za Vue
Correct. Using a host file only works for one website, which solved part of the problem. The other site will have to used another port. The main site is registered with the external DNS(BIND), but the other sites are registered with internal DNS(AD) server. No forwarding. When in production all

RE: [ActiveDir] IIS 6

2006-05-23 Thread Ken Schaefer
No, what you are stating below is incorrect. You can add three entries to your host file. On your IIS box, configure corresponding Host Header values for your three sites. Then you can access all three sites by name - no need to use alternate ports. However you mentioned accessing sites by IP add

RE: [ActiveDir] [Exchange] Full Mailbox Directory Name holds wrong Administrative Group name

2006-05-23 Thread joe
Even if it updated itself it would still be stamped in the contents of every message that still exists somewhere within the ORG, either in calendars or in mailboxes. That is the address Exchange uses when you try to update a meeting or respond to a message. You need something constant or else

RE: [ActiveDir] [OT] RAID 5 Best Practice

2006-05-23 Thread joe
Yeah small as in the user has multiple personalities... :o) -- O'Reilly Active Directory Third Edition - http://www.joeware.net/win/ad3e.htm -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] Sent: Tuesday,

RE: [ActiveDir] Build an AD test lab with schema extension.

2006-05-23 Thread joe
I just took a quick glimpse at it and I would say no, not that I would have expected it to in the first place.   You may want to look at the adschemaanalyzer which can be found in the ADAM SP1 and ADAM R2 distributions.   -- O'Reilly Active Directory Third Edition - http://www.joeware.net/wi

RE: [ActiveDir][OT] DNS on a DC or NOT

2006-05-23 Thread Rimmerman, Russ
What about DHCP on a DC? We just had an issue where our weekly reboot task to reboot all the DCs failed on one DC and it didn't come back up. Any user at the site who rebooted their PC was down because they couldn't get an IP from DHCP. Our standard is to run DHCP on the DCs at each site. H

RE: [ActiveDir] AD DNS along with Bind

2006-05-23 Thread Freddy HARTONO
Hi Mike, If you are delegating those 6 zones to only 1 DNS server, if that dns server is going through a quick reboot or downtime - then none of your client can find the NS delegation and hence causing a no domain controller found scenario isnt it? Interesting article mentioned below, does it app

RE: [ActiveDir][OT] DNS on a DC or NOT

2006-05-23 Thread Brian Desmond
Why do you have a weekly reboot task? This isn't NT4 anymore... Thanks, Brian Desmond [EMAIL PROTECTED] c - 312.731.3132 > -Original Message- > From: [EMAIL PROTECTED] [mailto:ActiveDir- > [EMAIL PROTECTED] On Behalf Of Rimmerman, Russ > Sent: Tuesday, May 23, 2006 9:27 PM > To: Act