RE: [ActiveDir] Can't access Default Domain Controller Security policy

2003-04-05 Thread Rick Kingslan
estore function which will allow you to restore to another DC - in this case, your DC with the PDC-E role missing the GP. See the GPMC help, if you can get your hands on the tool. It should be avaiable at the same time that Win2k3 is released, but works just fine on Windows 2000. Hope this all helps.

RE: [ActiveDir] Need Help on a Decision

2003-04-04 Thread Rick Kingslan
ne of your DCs and migrate their Exchange B) create a resource network and move both of your Exchanges into the resource network and publish contact objects C) get MMS (or what ever synch tool) and do a Forest to Forest synch.   Rick Kingslan  MCSE, MCSA, MCTMicrosoft MVP - Active DirectoryAsso

RE: [ActiveDir] downlevel client authentication

2003-04-01 Thread Rick Kingslan
affic. Fortunately, this isn't necessary, as authentication is possible at any DC. Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone - www.microsoft.com/windowsxp/expertzone -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PRO

RE: [ActiveDir] Removing sites and servers from AD

2003-04-01 Thread Rick Kingslan
just be determining if the USN for DC A is still what it has recorded.   Rick Kingslan  MCSE, MCSA, MCTMicrosoft MVP - Active DirectoryAssociate ExpertExpert Zone - www.microsoft.com/windowsxp/expertzone  From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Mike NewellSent: Tuesday

RE: [ActiveDir] Mixed to Native and Exchange 2000

2003-03-31 Thread Rick Kingslan
ll clean-up has been done - it's scrubbed and put in place as the next 'clean, pristine' server for the next mailbox move. The porcess continues until you're completed - leaving you with one extra box (usually to be the new box in your Exchange front or back end). Good lu

RE: [ActiveDir] GPO effect on Admin

2003-03-26 Thread Rick Kingslan
If I had a nickle for each time I'd been guilty of same. ;-) Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone - www.microsoft.com/windowsxp/expertzone -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Beha

RE: [ActiveDir] GPO effect on Admin

2003-03-26 Thread Rick Kingslan
ck to determine if there is a way to affect user settings, but this is typicaly used to apply user settings to a computer startup, not computer settings to user logon - by then it's much too late. Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone

RE: [ActiveDir] What Services/Server's can be combined with Activ e Directory.

2003-03-25 Thread Rick Kingslan
have that many left? ;) -- Roger D. Seielstad - MCSE Sr. Systems Administrator Inovis Inc. > -Original Message- > From: Rick Kingslan [mailto:[EMAIL PROTECTED] > Sent: Tuesday, March 25, 2003 9:20 AM > To: [EMAIL PROTECTED] > Subject: RE: [ActiveDir] What Services/Server's c

RE: [ActiveDir] What Services/Server's can be combined with Activ e Directory.

2003-03-25 Thread Rick Kingslan
and DCs to coexist, I'd expect that to be the much more likely scenario. -- Roger D. Seielstad - MCSE Sr. Systems Administrator Inovis Inc. > -Original Message- > From: Rick Kingslan [mailto:[EMAIL PROTECTED] > Sent: Mond

RE: [ActiveDir] changing the Pre-Windows 2000 computer name

2003-03-25 Thread Rick Kingslan
Title: Message Richard,   Could you expand?  Seems to be using a sledge hammer to kill a gnat.  What might I be missing?   Rick Kingslan  MCSE, MCSA, MCTMicrosoft MVP - Active DirectoryAssociate ExpertExpert Zone - www.microsoft.com/windowsxp/expertzone  From: [EMAIL PROTECTED

RE: [ActiveDir] changing the Pre-Windows 2000 computer name

2003-03-25 Thread Rick Kingslan
e the Pre-Windows 2000 name (or, the NetBIOS name) right-click on My Computer -> Properties -> Network Identification -> Properties  The NetBIOS name is the box at the top with your current computer name.  Change at will, click OK a couple of times, restart.   That should do it!  

RE: [ActiveDir] OT Password Policy:

2003-03-24 Thread Rick Kingslan
't bolster to a sufficient level.  And, if they can't get it immediately, they can chip away a little bit at a time until they do in a very quiet and clandestine way.   This is why we change passwords frequently - because you just don't know who is using your user's username

RE: [ActiveDir] What Services/Server's can be combined with Active Directory.

2003-03-24 Thread Rick Kingslan
ill secure - true? Good to have you here! Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone - www.microsoft.com/windowsxp/expertzone -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Missy Koslosky Sent: Monday, Marc

RE: [ActiveDir] Different password policy

2003-03-24 Thread Rick Kingslan
If you want to guarantee true security autonomy, the forest is the model to use. Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone - www.microsoft.com/windowsxp/expertzone -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On

RE: [ActiveDir] changing the Pre-Windows 2000 computer name

2003-03-24 Thread Rick Kingslan
Pardons to all!  I re-read the original message from Mark, and  I may have read WAAAY too much into this.  If you're only looking to change the name of a member server, it's a bit easier - DCs however, are pretty touch to change. Rick Kingslan  MCSE, MCSA, MCTMicrosoft MV

RE: [ActiveDir] Different password policy

2003-03-24 Thread Rick Kingslan
new domain for that new class of user. Hope this helps.... Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone - www.microsoft.com/windowsxp/expertzone -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Ole Thomsen S

RE: [ActiveDir] changing the Pre-Windows 2000 computer name

2003-03-24 Thread Rick Kingslan
).   As to changing the NetBIOS name - that's another story all together.  I've never seen that done, and would be interested in seeing detail from someone who has successfully done it. Rick Kingslan  MCSE, MCSA, MCTMicrosoft MVP - Active DirectoryAssociate ExpertExpert Zone - www.mic

RE: [ActiveDir] Admt 2.0 roaming profile migration

2003-03-24 Thread Rick Kingslan
rship of the profile, or manually join it to the new domain without migrating it. Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone - www.microsoft.com/windowsxp/expertzone -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTE

RE: [ActiveDir] Force password length problem

2003-03-18 Thread Rick Kingslan
at the Domain level - it cannot (except for specific cases which are outside the scope of this discussion) be implemented at Site, OU, or at the Default Domain Contoller policy level.   Rick Kingslan  MCSE, MCSA, MCTMicrosoft MVP - Active DirectoryAssociate Exp

RE: [ActiveDir] Force password length problem

2003-03-18 Thread Rick Kingslan
Default Domain Contoller policy level.   Rick Kingslan  MCSE, MCSA, MCTMicrosoft MVP - Active DirectoryAssociate ExpertExpert Zone - www.microsoft.com/windowsxp/expertzone    From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Gasper, RickSent: Tuesday, March 18, 2003 3:25 PMTo: [EMAIL

RE: [ActiveDir] Kerberos Vulnerability

2003-03-18 Thread Rick Kingslan
Given the high visibility of ANYTHING Microsoft, they have to review these issues - even though there is likely no connection - other than name Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone - www.microsoft.com/windowsxp/expertzone

RE: [ActiveDir] Anybody see Gil's article?

2003-03-18 Thread Rick Kingslan
Title: Message Yep - did see it.   It's not too bad  ;-)  Good job, Gil.   Rick Kingslan  MCSE, MCSA, MCTMicrosoft MVP - Active DirectoryAssociate ExpertExpert Zone - www.microsoft.com/windowsxp/expertzone    From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of B

RE: [ActiveDir] Group Policies Help (Win2k Server)

2003-03-16 Thread Rick Kingslan
seen this problem.  Me, I'm chalking it up to just living right!  ;-)   Thanks for the information!   Rick Kingslan  MCSE, MCSA, MCTMicrosoft MVP - Active DirectoryAssociate ExpertExpert Zone - www.microsoft.com/windowsxp/expertzone    From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On B

RE: [ActiveDir] Group Policies Help (Win2k Server)

2003-03-16 Thread Rick Kingslan
oblem in (goodness - has it REALLY been this long???) 5+ years of working with Windows 2000. Rick Kingslan  MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone - www.microsoft.com/windowsxp/expertzone     -Original Message- From: [EMAIL PROTECTED] [mailto:[

RE: [ActiveDir] Group Policies Help (Win2k Server)

2003-03-16 Thread Rick Kingslan
Jeremy, If you could find and cite that article, I have about 20k workstations that I have to show it to. GP shouldn't be working on them ;-) Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone - www.microsoft.com/windowsxp/exper

RE: [ActiveDir] ADMT 2.0

2003-03-16 Thread Rick Kingslan
Title: Message Windows Server 2003 RC2 is the current one that is available to general public.  That's where it is  Can be gotten from Microsoft (small fee) or from any of the Tech-Net or MSDN events coming to an area near you anytime.   Rick Kingslan  MCSE, MCSA, MCTMicrosof

RE: [ActiveDir] Group Policies Help (Win2k Server)

2003-03-16 Thread Rick Kingslan
;s not going to work. Put the computers in the group and do same. On ocassion, I have seen this fail to affect some users IF they have been using a roaming profile. Deleting the profile from the machine has solved this in those cases. What does GPRESULT show? Does it show the settings are app

RE: [ActiveDir] DC will not demote....

2003-03-15 Thread Rick Kingslan
reason for being there was to implemet our plans for changing that).   So, just as an emphasis that your somewhat lesser known method is very accepted in some situations - I've done it, it works, and life is all good in Huntsville with two DCs and two new FPs.   Rick Kingslan  MCSE, MCSA, M

RE: [ActiveDir] AD users question

2003-03-14 Thread Rick Kingslan
to AD. Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of John Balos Sent: Friday, March 14, 2003 10:34 AM To: [EMAIL PROTECTED] I have two domain controllers. One exchange server which is not a

RE: [ActiveDir] Native Mode Switch

2003-03-14 Thread Rick Kingslan
Title: Message Nope.  Any of them will make it permanent.   ;-)   Rick Kingslan  MCSE, MCSA, MCT Microsoft MVP - Active Directory   From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Don Murawski (Lenox)Sent: Friday, March 14, 2003 7:15 AMTo: [EMAIL PROTECTED] Switching to

RE: [ActiveDir] back the default valeue of password policy

2003-03-13 Thread Rick Kingslan
Typically, password policy is going to be applied at the Domain level. If you are dealing with a server that is a domain controller or a member of a domain, look at the domain GP level. If it's a standalone system, look to the Local Security policy. Rick Kingslan MCSE, MCSA, MCT Microsof

RE: [ActiveDir] TACACS support

2003-03-12 Thread Rick Kingslan
of a deal.  Actually, it was quite straight forward.   Frightening - I know.  This is one implementation that really had a minimal impact on our AD, as it worked as advertised - the FIRST time.   Rick Kingslan  MCSE, MCSA, MCTMicrosoft MVP - Active DirectoryAssociate ExpertExpert Zone

RE: [ActiveDir] DC can't "see" the AD Domain

2003-03-11 Thread Rick Kingslan
Title: Message Oh, and typically on Win2k, no need to restart the servers for a TCP/IP change Rick Kingslan  MCSE, MCSA, MCTMicrosoft MVP - Active DirectoryAssociate ExpertExpert Zone - www.microsoft.com/windowsxp/expertzone     From: [EMAIL PROTECTED] [mailto:[EMAIL

RE: [ActiveDir] DC can't "see" the AD Domain

2003-03-11 Thread Rick Kingslan
Title: Message I'd set it up as follows:   Primary - Other DC DNS Secondary - Self Tertiary - Your DNS server (as I fully don't understand what these are doing, it might be best handled through forwarding as well)   Let Forwarding handle the ISP DNS resolutions.   Rick Kingslan 

RE: [ActiveDir] DNS replication question

2003-03-10 Thread Rick Kingslan
properties appropriately on each side of the transfer.   Rick Kingslan  MCSE, MCSA, MCTMicrosoft MVP - Active DirectoryAssociate ExpertExpert Zone - www.microsoft.com/windowsxp/expertzone     From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Cariglia, DanielSent: Monday

RE: [ActiveDir] AD & DMZ's

2003-03-09 Thread Rick Kingslan
Have you looked into an RPC proxy to help with the number of ephemeral ports and the 'gaping hole'?   Rick Kingslan  MCSE, MCSA, MCTMicrosoft MVP - Active DirectoryAssociate ExpertExpert Zone - www.microsoft.com/windowsxp/expertzone     From: [EMAIL PROTECTED] [mailto:[EMAI

RE: [ActiveDir] AD & DMZ's

2003-03-09 Thread Rick Kingslan
it's not really addressing the larger problems.   Rick Kingslan  MCSE, MCSA, MCTMicrosoft MVP - Active DirectoryAssociate ExpertExpert Zone - www.microsoft.com/windowsxp/expertzone     From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Mark KelsaySent: Sunday, Mar

RE: [ActiveDir] Remove a Local Security Template

2003-03-07 Thread Rick Kingslan
urrent, the current doesn't know anything about them.  The only way to reverse them is to track your changes with a change control procedure.   Rick Kingslan  MCSE, MCSA, MCTMicrosoft MVP - Active DirectoryAssociate ExpertExpert Zone - www.microsoft.com/windowsxp/expertzone     From: [EM

RE: [ActiveDir] AD Design Guidance

2003-03-07 Thread Rick Kingslan
Title: Message >> They'll start to listen to you once they see you're not half baked   Not if they are the arrogant pricks I work with  ;-)   No way to shut them up.  They have upper management absolutely snowed. Rick Kingslan  MCSE, MCSA, MCTMicrosoft MVP - Active Di

RE: [ActiveDir] Remove a Local Security Template

2003-03-07 Thread Rick Kingslan
mplate for your system (basicsv, basicws, basicdc). Rick Kingslan  MCSE, MCSA, MCTMicrosoft MVP - Active DirectoryAssociate ExpertExpert Zone - www.microsoft.com/windowsxp/expertzone     From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of [EMAIL PROTECTED]Sent: Friday, March

RE: [ActiveDir] Domain Names and Netbios

2003-03-07 Thread Rick Kingslan
ou will not be allowed to create it for the NetBIOS name. However, in your example you would for DNS, as the total namespace is different (root to domain). Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone - www.microsoft.com/windowsxp/expertzone > &

RE: [ActiveDir] Site Link Transitivity

2003-03-05 Thread Rick Kingslan
n for environments that are not as large as what is dealt with in those guides, the experience is invaluable. http://www.microsoft.com/technet/treeview/default.asp?url=/technet/prodt echnol/AD/windows2000/deploy/adguide/default.asp Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Dire

RE: [ActiveDir] AD Design Guidance

2003-03-04 Thread Rick Kingslan
nix camp to get anything done about the utilization, as it seems that they have what they need - they aren't griping about speed, apparently.  If they were, the line would likely have been provisioned for upgrade.   Casey, I think you're fighting a partly political battle, too

RE: [ActiveDir] AD Design Guidance

2003-03-03 Thread Rick Kingslan
ly am overlooking it.  With Exchange and other F&P type issues, I think that you're only 'robbing Peter to pay Paul' by moving this machine.    Ultimately, upgrading the line is the reasonable answer.  Rick Kingslan  MCSE, MCSA, MCTMicrosoft MVP - Active DirectoryAsso

RE: [ActiveDir] AD Design Guidance

2003-03-03 Thread Rick Kingslan
that they are missing (not likely) I'll pop in. Rick Kingslan  MCSE, MCSA, MCTMicrosoft MVP - Active DirectoryAssociate ExpertExpert Zone - www.microsoft.com/windowsxp/expertzone     From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Friese, CaseySent: Monday, Marc

RE: [ActiveDir] AD Design Guidance

2003-03-03 Thread Rick Kingslan
andwidth on the WAN line.  The only way to truly know how large is to run some baselines and find the highwater mark - then plan well above that for the upgrade. Rick Kingslan  MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone - www.microsoft.com/windo

RE: [ActiveDir] Grant Permissions to Add a Computer to a Domain

2003-02-28 Thread Rick Kingslan
prodt echnol/windows2000pro/deploy/depopt/ris.asp The last third of the article answers the issue. Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone - www.microsoft.com/windowsxp/expertzone > > > -Original Message- > From:

RE: [ActiveDir] AD Design Guidance

2003-02-28 Thread Rick Kingslan
e updates are never made. Rick Kingslan  MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone - www.microsoft.com/windowsxp/expertzone >  >  > -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED]] On Behalf Of

RE: [ActiveDir] AD Design Guidance

2003-02-28 Thread Rick Kingslan
it is misconfigured. Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone - www.microsoft.com/windowsxp/expertzone > > > -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] On Behalf Of > Chuck Robinson

RE: [ActiveDir] Strange Group Policy Problem

2003-02-28 Thread Rick Kingslan
an access?   I'll leave it at that.....   ;o) Rick Kingslan  MCSE, MCSA, MCTMicrosoft MVP - Active DirectoryAssociate ExpertExpert Zone - www.microsoft.com/windowsxp/expertzone     From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Brad MartinSent: Friday, Februar

RE: [ActiveDir] Dual Administration of partially migrated NT 4 domains

2003-02-27 Thread Rick Kingslan
rs and data starts moving over.   Just keep your head down and keep plugging along.   Hope this helps. Rick Kingslan  MCSE, MCSA, MCTMicrosoft MVP - Active DirectoryAssociate ExpertExpert Zone - www.microsoft.com/windowsxp/expertzone     From: [EMAIL PROTECTED] [mailto:[EMAIL

RE: [ActiveDir] Time stamp format in "your" Active Directory

2003-02-26 Thread Rick Kingslan
  But, that's me!  ;o)   Rick Kingslan  MCSE, MCSA, MCTMicrosoft MVP - Active DirectoryAssociate ExpertExpert Zone - www.microsoft.com/windowsxp/expertzone     From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Isham, Alan ASent: Wednesday, February 26, 2003 5:19 PMTo:

RE: [ActiveDir] Connection Agreement

2003-02-26 Thread Rick Kingslan
Oh, BTW - Your need for High Importance = very Subjective. IOW, doesn't mean it's important or urgent to anyone else. Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone - www.microsoft.com/windowsxp/expertzone > > > --

RE: [ActiveDir] Connection Agreement

2003-02-26 Thread Rick Kingslan
/default.aspx?scid=KB;en-us;q253286 Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone - www.microsoft.com/windowsxp/expertzone > > > -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] On Behalf Of >

RE: [ActiveDir] OT: Cannot send mail to/from e5.5 to/from e2k an d 2way CA

2003-02-24 Thread Rick Kingslan
Title: Message Shout from the peanut gallery, Joe.  Active/ Passive is the way to go.   And, on the "Geee, I WAS labbing it until the Director said, 'Uhhh, no time to lab - customer wants it now!'"  You're living my life, pal.  I feel your pain...  

RE: [ActiveDir] AD Sites and Services Error

2003-02-24 Thread Rick Kingslan
Title: Message Yep - OK - I can understand that then.   Can you install AdminPak on a Win2k Pro or WinXP, and then do the maint from there?  An MMC issue can be very tough to track down, and it sounds like you need to get this done now.   Rick Kingslan  MCSE, MCSA, MCTMicrosoft MVP - Active

RE: [ActiveDir] AD Sites and Services Error

2003-02-24 Thread Rick Kingslan
.  You must create the site, associate subnets and protocols / transports with the site, then move a DC to that site.   As to the issues that you're having with MMC - yes - I've seen it often. Rick Kingslan  MCSE, MCSA, MCTMicrosoft MVP - Active DirectoryAssociate ExpertExpert Zone -

RE: [ActiveDir] security templates

2003-02-23 Thread Rick Kingslan
icrosoft.com/default.aspx?scid=kb;en-us;243330 Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone - www.microsoft.com/windowsxp/expertzone > > > -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] On Behalf O

RE: [ActiveDir] Group Policy

2003-02-21 Thread Rick Kingslan
settings in one GP, disable the processing of the ENTIRE Computer section.  Same goes for the User section.   Hope this helps.   Rick Kingslan  MCSE, MCSA, MCTMicrosoft MVP - Active DirectoryAssociate ExpertExpert Zone - www.microsoft.com/windowsxp/expertzone     From: [EMAIL PROTECTE

RE: [ActiveDir] Group Policy

2003-02-21 Thread Rick Kingslan
Title: Message More in jest, Craig - not being completely serious - about the flaming, at least!   ;o) Rick Kingslan  MCSE, MCSA, MCTMicrosoft MVP - Active DirectoryAssociate ExpertExpert Zone - www.microsoft.com/windowsxp/expertzone     From: [EMAIL PROTECTED] [mailto:[EMAIL

RE: [ActiveDir] SUS?

2003-02-21 Thread Rick Kingslan
. But, then, the only way I was GOING to get everything that I wanted was to write my own. I don't have that kind of time. The problem is a very 'yesterday' thing. But, it's biting me in the butt today. Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Asso

RE: [ActiveDir] Redirect Policy not being updated

2003-02-20 Thread Rick Kingslan
is no longer available, everything gets quite confused. Check this: http://support.microsoft.com/default.aspx?scid=kb;en-us;274789 Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone - www.microsoft.com/windowsxp/expertzone > > > -Or

RE: [ActiveDir] SUS?

2003-02-20 Thread Rick Kingslan
It might be more precise to say SUS 2.0. What is SUS-SA? Software Assurance??? SUS 2.0 I have seen in it's development bits, and it is a huge step forward for the tool to do real patch management. Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert

RE: [ActiveDir] AD Visio Mapping Tool

2003-02-20 Thread Rick Kingslan
David, Maybe you can be a bit more precise as to which of the Sunbelt tools is going to help Gene generate a Visio drawing. I don't see anything there that is going to do what he wants. Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert

RE: [ActiveDir] SUS?

2003-02-20 Thread Rick Kingslan
John, I can't tell you anything more other than the next version should greatly please and satisfy. Look for it Q4. Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone - www.microsoft.com/windowsxp/expertzone > > > -Or

RE: [ActiveDir] MS changes certifications

2003-02-20 Thread Rick Kingslan
Ahhh! But some of us took 1. For free. ;-) Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone - www.microsoft.com/windowsxp/expertzone > > > -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED

RE: [ActiveDir] .net RC2

2003-02-19 Thread Rick Kingslan
None that I've experienced to date. I have a few RC@ servers installed with no problems. Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone - www.microsoft.com/windowsxp/expertzone > -Original Message- > From: [EMAIL PROTECTED]

RE: [ActiveDir] admt v2.0

2003-02-19 Thread Rick Kingslan
lling you stuff you already know Benefit for those that don't) by using a PES (Password Export Server) to 'copy' the password along with the user. I've used ADMT 1 and 2 quite heavily, and it hasn't mattered if the source was a NT 4.0 domain or not. Apparently, YMDV

RE: [ActiveDir] Empty root domain benefits?

2003-02-19 Thread Rick Kingslan
equirement?" Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone - www.microsoft.com/windowsxp/expertzone > -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED]] On Behalf Of Tony Murray > Sent: Wednesday, Feb

RE: [ActiveDir] security templates

2003-02-18 Thread Rick Kingslan
Thanks, Bob! ;-) Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone - www.microsoft.com/windowsxp/expertzone > -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED]] On Behalf Of Free, Bob > Sent: Tuesday,

RE: [ActiveDir] security templates

2003-02-18 Thread Rick Kingslan
e for your Security Configuration guidelines, in conjunction with the SecOps guides. Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone - www.microsoft.com/windowsxp/expertzone > -Original Message- > From: [EMAIL PROTECTED] >

RE: [ActiveDir] DNS Inconsistency

2003-02-17 Thread Rick Kingslan
And, absolutely correct this is. A DC in this group is a known security problem. Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone - www.microsoft.com/windowsxp/expertzone > -Original Message- > From: [EMAIL PROTECTED] > [mail

RE: [ActiveDir] Resolving a GUID

2003-02-16 Thread Rick Kingslan
any meaning in NT 4.0 speak. Like NDS, AD can and does use GUIDs to identify many objects in the ACLs. SIDs, for the greater part, are a legacy throwback - hence the reason that they weill be around in MS products for a while yet. Me, I'd be happy to see them go Rick Kingslan MCSE,

RE: [ActiveDir] Security Priv over Services on a DC

2003-02-15 Thread Rick Kingslan
specific server types, i.e Web Server, File / Print, etc.   Hope this helps.   Rick Kingslan  MCSE, MCSA, MCTMicrosoft MVP - Active DirectoryAssociate ExpertExpert Zone - www.microsoft.com/windowsxp/expertzone -Original Message-From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED

RE: [ActiveDir] OU Limits

2003-02-15 Thread Rick Kingslan
t are applied through Administraative templates, etc. Rick Kingslan  MCSE, MCSA, MCTMicrosoft MVP - Active DirectoryAssociate ExpertExpert Zone - www.microsoft.com/windowsxp/expertzone -Original Message-From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] On Behalf Of Craig Gaine

[ActiveDir] DSAcls /getsddl /setsddl

2003-02-07 Thread Rick Kingslan
n the next project. Can anyone get them to work, as I can find no documentation on these switches at all. Thanks in advance! (If I don't get an answer over the next two days, I'll ask the folks in Redmond personally next week while I'm there. One way or the other - I'm getting an a

RE: [ActiveDir] Decrypt Files from a no longer existing domain

2003-02-03 Thread Rick Kingslan
> > > www.microsoft.com > www.google.com > www.rtfm.com > www.YouAreProbablyNotGoingToGetTheFilesBack.com > www.DontWasteYourTime.org ROTFLMAO! (Not at your predicament, Justin - I feel your pain, but do some research, man!) Rick Kingslan MCSE, MCSA, MCT Microsoft M

RE: [ActiveDir] ADMT v2.0

2003-02-01 Thread Rick Kingslan
Allan, Thanks for your assistance in this, and for the link. Unfortunately, Microsoft included ADMT as a sub-directory in the i386 folder and it is not considered an Admin tool, per se. Thanks again! Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone

RE: [ActiveDir] ADMT v2.0

2003-01-31 Thread Rick Kingslan
Yes - but it's a move, not a migrate. Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone - www.microsoft.com/windowsxp/expertzone > -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED]] On Behalf Of > S

RE: [ActiveDir] ADMT v2.0

2003-01-31 Thread Rick Kingslan
must be in Native Mode 2.  Password key server designated on the source domain - the PDC Emulator is the right choice.  It's really the creation of a 'certificate' to allow migration of the password.   All of this is clearly documented in the ADMT doc's.   Rick Kingslan

RE: [ActiveDir] ADMT v2.0

2003-01-31 Thread Rick Kingslan
Mark, ADMT itself does not have a facility to do this. Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone - www.microsoft.com/windowsxp/expertzone > -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED]] On

RE: [ActiveDir] NT SUPPORT extended

2003-01-30 Thread Rick Kingslan
Title: Message UI think that they did with the announcement.   Rick Kingslan  MCSE, MCSA, MCTMicrosoft MVP - Active DirectoryAssociate ExpertExpert Zone - www.microsoft.com/windowsxp/expertzone -Original Message-From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] On

RE: [ActiveDir] Split Brain DNS and AD Namespace

2003-01-30 Thread Rick Kingslan
cific "look and feel" for their contract. And, we can usually provide those, too. We use probably (right now - it could change today) 60 outward namespaces. But, we currently have 4 internal namespaces that support AD - all registered, but dissimilar from the outside namespace. Rick

RE: [ActiveDir] NT SUPPORT extended

2003-01-30 Thread Rick Kingslan
ause we then become guilty of the same extremes that we accuse Microsoft of.     Rick Kingslan  MCSE, MCSA, MCTMicrosoft MVP - Active DirectoryAssociate ExpertExpert Zone - www.microsoft.com/windowsxp/expertzone -Original Message-From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECT

RE: [ActiveDir] IIS 6

2003-01-29 Thread Rick Kingslan
Title: Message Maybe.  And, I *DO* agree.  I doubt it, though, in this case.   We'll see   ;)   Rick Kingslan  MCSE, MCSA, MCTMicrosoft MVP - Active DirectoryAssociate ExpertExpert Zone - www.microsoft.com/windowsxp/expertzone -Original Message-From: [EMAIL PROT

RE: [ActiveDir] Active Directory Authentication via ras

2003-01-29 Thread Rick Kingslan
Not unless IAS is now expanding the schema. OOB, it doesn't - so this shouldn't be anm issue. Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone - www.microsoft.com/windowsxp/expertzone > -Original Message- > From:

RE: [ActiveDir] IIS 6

2003-01-29 Thread Rick Kingslan
Title: Message Robert,   I think it's likely.  IIS 6.0 would be a great platform for an embedded webserver.  It's a lot harder to compromise firmware..  (though, not impossible... just harder) Rick Kingslan  MCSE, MCSA, MCTMicrosoft MVP - Active DirectoryAssociate ExpertE

RE: [ActiveDir] Replication Failure Reasons

2003-01-29 Thread Rick Kingslan
gs on your client system (even if that happens to be another server). Run NetDiag and DCDiag in verbose. This will typically point you in the right direction. Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone - www.microsoft.com/windowsxp/expertzone >

RE: [ActiveDir] IIS 6

2003-01-29 Thread Rick Kingslan
on Windows Server 2003.  It's not going to allow you to drop it on any OS that you want.   I suspect (reading posts I get a good feel for the rate of absorption for folks) that you know this.  Look at it as if I'm just helping to clear up the possible misconceptions that will spew

RE: [ActiveDir] Replication partners

2003-01-28 Thread Rick Kingslan
Try ReplMon. It'll point out who is the target / source of an update to any of the partitions that a DC can host. Or, RepAdmin if you're more into the command line thing (both are great in the roles...). Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Exp

RE: [ActiveDir] GPO's and AD...

2003-01-28 Thread Rick Kingslan
ity perspective, this seems to be a bit strange, and an oxymoron, at least. Todd - what is your reasoning for wanting to do this? Remember, this is not a criticism - it's a quest for understanding. Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone - www.micro

RE: [ActiveDir] AD 2 AD Migration

2003-01-25 Thread Rick Kingslan
the “Let Everyone permissions apply to anonymous users” right has been enable on that machine, or that the Anonymous Logon user has been added to the Pre-Windows 2000 Compatible Access group. Hope this helps - if not, redirect and I'll answer. Rick Kingslan MCSE, MCSA, MCT Microsoft MVP -

RE: [ActiveDir] Using Active Directory between a firewall

2003-01-24 Thread Rick Kingslan
It might be an idea to give us a bit of a heads-up (relating to Roger's question) as to why - and more importantly, how your DMZ is set up. Do you just have the one DMZ, or do you have a Bastion host with a Public DMZ, then your internal network, or do you have a multi-layered DMZ (Public, Private,

RE: [ActiveDir] E2K and DC

2003-01-23 Thread Rick Kingslan
't get it done until 2004 Calendar / fiscal year - big deal. Support is going to be available. I know that a cottage industry is going to spring up or grow to encompass NT 4.0 transitional support. Be positive - you'll get what you need much easier. Rick Kingslan MCSE, M

RE: [ActiveDir] VNC and Terminal Services

2003-01-21 Thread Rick Kingslan
ay.   IMHO, (given the above caveat) VNC is no more or less secure than PC Anywhere.  It may have a greater advantage in that it seems to be more widely dispersed and more widely accepted, in some regards.  Though, looking at it negatively, this could be the anti-thesis as well.   Rick Kingslan 

RE: [ActiveDir] Other application/uses on DC's. Was: OT: Exchange 2000

2003-01-21 Thread Rick Kingslan
t did as little as 4 months ago. Now, if I can just continue to work on them to listen to us on AD Monitoring and Life Cycle (yes, Gil - NetPro is still very much alive AND desired!) Baby steps..... Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert

RE: [ActiveDir] VNC and Terminal Services

2003-01-21 Thread Rick Kingslan
True. But, Dell sure seems to as an integral piece of their server management and DRAC offerings - and yes, on Windows 2000. FWIW... Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone - www.microsoft.com/windowsxp/expertzone > -Origi

RE: [ActiveDir] NT system policies

2003-01-17 Thread Rick Kingslan
Ack! Completely forgot about this Great catch, Bob. Thanks for the information. Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone - www.microsoft.com/windowsxp/expertzone > -Original Message- > From: [EMAIL PROTECTED] >

RE: [ActiveDir] NT system policies

2003-01-17 Thread Rick Kingslan
spreadsheet that went around a week or two ago that should help you get the GP going. Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone - www.microsoft.com/windowsxp/expertzone > -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL

RE: [ActiveDir] Authentication ?

2003-01-17 Thread Rick Kingslan
#x27;m sure you are doing.   Thanks!   Rick Kingslan  MCSE, MCSA, MCTMicrosoft MVP - Active DirectoryAssociate ExpertExpert Zone - www.microsoft.com/windowsxp/expertzone -Original Message-From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] On Behalf Of Ken CornetetSent: Frid

<    4   5   6   7   8   9   10   11   12   >