RE: [ActiveDir] Overlapping AD Subnet Boundaries

2007-01-26 Thread Thommes, Michael M.
An AD client will try to associate itself with the site that it is most specific for its IP. Mike Thommes From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Brian Cline Sent: Friday, January 26, 2007 3:20 PM To: ActiveDir@mail.activedir.org Subj

RE: [ActiveDir] OT: maintaining "creation date" when copying directories?

2007-01-25 Thread Thommes, Michael M.
85-4308-B4 89-F2F1214C811D> Weblog: http://msmvps.org/UlfBSimonWeidner http://msmvps.org/UlfBSimonWeidner> Website: http://www.windowsserverfaq.org http://www.windowsserverfaq.org/> From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M. Sent: Donnerstag

RE: [ActiveDir] Kerberos Question

2007-01-25 Thread Thommes, Michael M.
I think you are seeing your Kerberos tickets start to reach their expiration time. The kerbtray icon will go from green to red. I think the last 5 or 15 minutes the default configuration will also issue an audible (and very distinctive) sound. The tickets will renew automatically (and the icon w

RE: [ActiveDir] OT: maintaining "creation date" when copying directories?

2007-01-25 Thread Thommes, Michael M.
with the /B-Switch should work. Ulf From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M. Sent: Donnerstag, 25. Januar 2007 13:10 To: ActiveDir@mail.activedir.org Subject: [ActiveDir] OT: maintaining "creation date" when copying directories? Wh

[ActiveDir] OT: maintaining "creation date" when copying directories?

2007-01-25 Thread Thommes, Michael M.
What "move/copy" tools can be used to copy directories/files to another location and still retain the "creation date" value? Robocopy seems to keep creation date on files but directories are given the current date. Am I missing a switch in Robocopy to do this? A backup/restore operation (with ntb

[ActiveDir] moving server local groups to AD?

2007-01-24 Thread Thommes, Michael M.
(I sure hope this doesn't sound like too dumb a question!) We have a server where local security groups were created for local file access. The files on this server are going to be moved to a file server cluster. Can ADMT v3 migrate these security groups up to the AD structure with the hopes of re

RE: [ActiveDir] PHP Module for Windows

2007-01-24 Thread Thommes, Michael M.
Is this what you are looking for? http://www.php.net/downloads.phpI have not used it, however, and can't speak to how well it works but it seems to come from the right place. ;) Mike Thommes From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf

[ActiveDir] release date for W2K3/SP2?

2007-01-19 Thread Thommes, Michael M.
Has anyone heard of a release date for Windows Server 2003/SP2? Thanks. Mike Thommes

RE: [ActiveDir] 1054 Error (Windows cannot contact DC - Group Policy)

2007-01-19 Thread Thommes, Michael M.
You might want to test the network connection. We have a public tester at http://miranda.ctd.anl.gov:7123/ that might detect duplex mismatches or faulty cables. Mike Thommes -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Darren Mar-Elia Sent: Friday, Ja

[ActiveDir] OT: Apache LDAP authentication oddity

2007-01-19 Thread Thommes, Michael M.
We have an application that is using an Apache server to do LDAP authentications against our active directory. (Yeah, I know; if only I were king! LOL!) The application developer tells me that if he tries doing an auth against our root base (dc=yyy,dc=zzz), the auth fails. If he uses a search b

RE: [ActiveDir] Shares with Computer Account Permissions

2007-01-09 Thread Thommes, Michael M.
Hi Laura, That's what I thought of first but that would stop all traffic to the server, not just a particular share. Mike Thommes From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Laura A. Robinson Sent: Tuesday, January 09, 2007 4:19 PM

RE: [ActiveDir] Disabled user + when

2007-01-03 Thread Thommes, Michael M.
If nothing else has been done to the account, I wonder if you could use the "whenChanged" attribute. Mike Thommes From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Parag Nagwekar Sent: Wednesday, January 03, 2007 9:28 AM To: ActiveDir@mail.acti

[ActiveDir] how to get ALL users in "Domain Users"

2007-01-02 Thread Thommes, Michael M.
I am trying to get a list of all of the users in the builtin group "Domain Users". I am using the following commands, but get incomplete results. Can someone tell me why? Thanks! And Happy New Year to everyone! dsquery group -name "domain users" | dsget group -members > c:\temp\domain_users

RE: [ActiveDir] OT: help with running a scheduled job

2006-12-15 Thread Thommes, Michael M.
rvers where we have ordinary users executing "batch" jobs I've setup a local group to grant read and execute. http://support.microsoft.com/kb/867466 Mike From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M. Se

[ActiveDir] OT: help with running a scheduled job

2006-12-15 Thread Thommes, Michael M.
We are trying to get a particular account to run a scheduled backup job on a server. Our results are puzzling. Here are the particulars: 2003 R2 standard server Domain account, non privileged, doesn't belong to "domain users" Added to local "backup operators" group Trying to run a system stat

RE: [ActiveDir] Split pagefile

2006-12-01 Thread Thommes, Michael M.
How about a remote shutdown like "shutdown /m \\computername /r /f" Mike Thommes -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Kevin Brunson Sent: Friday, December 01, 2006 9:51 AM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] Split pagefile

RE: [ActiveDir] dynamic variables within an event log entry?

2006-12-01 Thread Thommes, Michael M.
last sentence even made sense, sorry. I'm sleep deprived. Laura From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M. Sent: Thursday, November 30, 2006 10:40 PM To: ActiveDir@mai

RE: [ActiveDir] dynamic variables within an event log entry?

2006-11-30 Thread Thommes, Michael M.
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M. Sent: Thursday, November 30, 2006 7:33 PM To: ActiveDir@mail.activedir.org Subject: [ActiveDir] dynamic variables within an event log entry? I wonder if someone could explain t

[ActiveDir] dynamic variables within an event log entry?

2006-11-30 Thread Thommes, Michael M.
I wonder if someone could explain to me (or point me at some reference) about what mechanism is used to populate the information in a Windows event log entry. The reason why I ask is that I see in the Security log when a new user account is created by an account which is a member of the Domain Adm

RE: [ActiveDir] AD Security Group Information

2006-10-31 Thread Thommes, Michael M.
adfind -default -f "&(objectclass=group)(groupType=-2147483646)" -tdc whenChanged   hth, Mike Thommes   From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Frank Abagnale Sent: Tuesday, October 31, 2006 2:51 AM To: activedir@mail.activedir.org Subject: [ActiveDir] AD

RE: [ActiveDir] List Groups I'm In?

2006-10-25 Thread Thommes, Michael M.
Hi Deji,     My version of whoami shows the usage as: “whoami /groups”.  Thanks for pointing me at this; I always just used “whoami”.   Mike Thommes   From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Akomolafe, Deji Sent: Wednesday, October 25, 2006 11:58 AM To: A

RE: [ActiveDir] Gather member of query based distribution list thru command line

2006-10-18 Thread Thommes, Michael M.
dsquery group -name _samaccountname_here_ | dsget group -members Mike Thommes -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Irwan Hadi Sent: Wednesday, October 18, 2006 4:14 PM To: ActiveDir@mail.activedir.org Subject: [ActiveDir] Gather member of query

RE: [ActiveDir] The remote computer has ended the connection.

2006-10-18 Thread Thommes, Michael M.
joined from my domain. but i am sure this has nothing to do with any GPO. Also same thing happened for me when i joined this to any other domain. other than the previous one.   Thanks!!! Ravi   From: [EMAIL PROTECTED] on behalf of Thommes, Michael M. S

RE: [ActiveDir] The remote computer has ended the connection.

2006-10-17 Thread Thommes, Michael M.
Hi Susan, I didn't mean to imply that this was just with the last set of patches. I think your note says that you have been seeing this for a while. We have too. One of the guys in my group uses Update Expert to patch and he sees it more often than I do. Of course, he patches a lot more ser

RE: [ActiveDir] The remote computer has ended the connection.

2006-10-17 Thread Thommes, Michael M.
I have also seen where a second reboot is necessary for RDP to work.  I have not determined the cause of this yet.  It does not happen on all servers.   Mike Thommes   From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Vinnie Cardona Sent: Tuesday, October 17, 2006 1

RE: [ActiveDir] Determine disabled computer accounts

2006-10-16 Thread Thommes, Michael M.
Check out "oldcmp" at http://www.joeware.net/win/free/tools/oldcmp.htm Mike Thommes -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Condra, Jerry W Mr HP Sent: Monday, October 16, 2006 12:50 PM To: ActiveDir@mail.activedir.org Subject: [ActiveDir] Determi

RE: [ActiveDir] Discovering LDAPS availability

2006-10-11 Thread Thommes, Michael M.
In this context, would it make sense to write/use a servicePrincipalName value? (maybe even using admod/adfind 8-) ) Mike Thommes -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of joe Sent: Wednesday, October 11, 2006 9:42 AM To: ActiveDir@mail.activedir.

RE: [ActiveDir] problem changing "employeeID" attribute value

2006-10-10 Thread Thommes, Michael M.
: RE: [ActiveDir] problem changing "employeeID" attribute value   Try clicking the 'Clear' button instead of deleting the value.   -Andrew     From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M. Sent: Tuesday, October

[ActiveDir] problem changing "employeeID" attribute value

2006-10-10 Thread Thommes, Michael M.
For an AD user account, we normally populate the attribute “employeeID” with a value.  Circumstances surrounding some accounts requires me to “unpopulate” this value.  In ADSIEdit, however, when I go to this Unicode String valued attribute with the Edit function, I can delete the value but

RE: [ActiveDir] Who keeps creating this folder & files?!

2006-10-05 Thread Thommes, Michael M.
Try FileNotify – freeware at http://www.xtware.com/   Mike Thommes   From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Kurt Falde Sent: Thursday, October 05, 2006 1:19 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] Who keeps creating this folder & file

RE: [ActiveDir] 200 users network. Adding 2 classes to the GC

2006-10-03 Thread Thommes, Michael M.
Hi Rezuma,     I suspect you might run into the same issue I had when I did the R2 forestprep with SFU 3.5 (although you have the earlier SFU 3.0).  If so, see the fixup from Steve Linehan posted to this newsgroup on 8/7/06 (and my comment from 8/12/06).   Mike Thommes   From:

RE: [ActiveDir] different version of R2 available?

2006-09-21 Thread Thommes, Michael M.
, Michael M. Sent: Wednesday, September 20, 2006 5:58 PM To: ActiveDir@mail.activedir.org Subject: [ActiveDir] different version of R2 available?   My officemate and I were discussing whether there are different versions of the R2 CD depending on whether you’re running Server 2003 Standard or Server

[ActiveDir] different version of R2 available?

2006-09-20 Thread Thommes, Michael M.
My officemate and I were discussing whether there are different versions of the R2 CD depending on whether you’re running Server 2003 Standard or Server 2003 Enterprise.  Or is there only one version of R2?  TIA!   Mike Thommes

RE: [ActiveDir] OT: Protecting against Spyware/Adware

2006-09-14 Thread Thommes, Michael M.
Touche’   8-)   Mike Thommes   From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of joe Sent: Thursday, September 14, 2006 5:04 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] OT: Protecting against Spyware/Adware   I run as local admin and have zero i

[ActiveDir] OT: uptime.exe in a 2003/sp1 world - problem

2006-09-07 Thread Thommes, Michael M.
Hi,    I have moved a job that employs uptime.exe (in a loop using the FOR command) from a Windows 2000/SP4 server to a Windows 2003/SP1 server.  Now part way through the job, I get:   Event Type:   Information Event Source:    Application Popup Event Category: None Event ID: 

RE: [ActiveDir] Seperate Administrator password policy

2006-08-31 Thread Thommes, Michael M.
We are still testing PassFiltPro software (http://www.altusnet.com/products/) which supposedly has the ability with one of its versions (MPE) to enforce different password policies based on global groups.  This is mentioned only for information, not endorsement, at this time.   Mike Thomm

[ActiveDir] www.activedir.org MIA?; storing pictures in AD?

2006-08-30 Thread Thommes, Michael M.
Can anyone else get to the archives?  Specifically, I was looking for a thread from, I think, a couple of years ago where there was discussion about storing (not storing?) employee pictures in AD.  I am concerned about how that attribute will grow our DIT.  I seem to recall that maybe just

RE: [ActiveDir] nslookup. AD beginer question

2006-08-29 Thread Thommes, Michael M.
I am guessing, based on the port number, you have a DNS A record for this computer in gc._msdcs.domain.com .   Mike Thommes   From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Ramon Linan Sent: Tuesday, August 29, 2006 10:06 AM To: ActiveDir@mail.activedir.org Subje

RE: [ActiveDir] nslookup. AD beginer question

2006-08-28 Thread Thommes, Michael M.
You should get back your domain controllers’ IP addresses.  Is it possible that your user’s computer has gotten the IP of an old DC?   Mike Thommes   From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Ramon Linan Sent: Monday, August 28, 2006 3:03 PM To: ActiveDir@ma

RE: [ActiveDir] Secure LDAP queries from the outside --> problem solved

2006-08-23 Thread Thommes, Michael M.
from perfect in that regard. joe -- O'Reilly Active Directory Third Edition - http://www.joeware.net/win/ad3e.htm From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M. Sent: Wednesday, August 23, 2006 8:0

RE: [ActiveDir] Secure LDAP queries from the outside --> problem solved

2006-08-23 Thread Thommes, Michael M.
:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M. Sent: Tuesday, August 22, 2006 9:36 AM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] Secure LDAP queries from the outside   Hi Robert,     Yes, the command is *exactly* the same.  We are thinking that our CRL location is not

RE: [ActiveDir] Secure LDAP queries from the outside

2006-08-22 Thread Thommes, Michael M.
get the object returned?   I tried using adfind to connect to my test DC using port 636 and got the exact same error…but I don’t have a cert installed on my DC so I’d expect mine not to work. Robert Williams From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael

[ActiveDir] Secure LDAP queries from the outside

2006-08-22 Thread Thommes, Michael M.
Hi,    We are trying to set up secure LDAP queries from the outside to AD for pulling email addresses but are running into an issue.  Port 636 has been opened up to our DCs but we get a 0x51 error like the one shown below in this example of using “adfind”:   adfind -h dc1.abc.com:636 -u

RE: [ActiveDir] User AutoEnrollment

2006-08-16 Thread Thommes, Michael M.
Maybe the CRL (Certificate Revocation List) location is not available? Mike Thommes -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Za Vue Sent: Wednesday, August 16, 2006 8:17 AM To: ActiveDir@mail.activedir.org Subject: [ActiveDir] User AutoEnrollment

RE: [ActiveDir] Adding the first Win2003 R2 DC

2006-08-15 Thread Thommes, Michael M.
I fixed this issue with ldp and Steve Linehan’s instructions to the list about two weeks ago.  Microsoft supposedly has an “unofficial” patch to fix this issue.  Talk to your TAM.   Mike Thommes   From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of joe Sent: Tuesday,

RE: [ActiveDir] [OT] joe - please say it isn't so!

2006-08-14 Thread Thommes, Michael M.
TECTED] On Behalf Of Thommes, Michael M. Sent: Monday, August 14, 2006 3:28 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] joe - please say it isn't so! So here I went to take a look at Dean’s article, and I find this: http://blog.joeware.net/cat/recipes/ , expecting to find m

RE: [ActiveDir] joe - please say it isn't so!

2006-08-14 Thread Thommes, Michael M.
So here I went to take a look at Dean’s article, and I find this: http://blog.joeware.net/cat/recipes/ , expecting to find more of joe’s great adfind codes.  At first, I thought it got misfiled and should have been filed under “humor” but I suspect this is hardly funny.  Joe, are you pullin

RE: [ActiveDir] OT: Enterprise Terminal Server Licensing Server question

2006-08-06 Thread Thommes, Michael M.
PROTECTED] On Behalf Of Thommes, Michael M. Sent: Saturday, August 05, 2006 5:04 AM To: ActiveDir@mail.activedir.org Subject: [ActiveDir] OT: Enterprise Terminal Server Licensing Server question Hi,     This is not causing any issues that I am aware of, but something does not seem right.  We set

[ActiveDir] OT: Enterprise Terminal Server Licensing Server question

2006-08-04 Thread Thommes, Michael M.
Title: OT: Enterprise Terminal Server Licensing Server question Hi,     This is not causing any issues that I am aware of, but something does not seem right.  We set up two Enterprise Terminal Server Licensing Servers, both DCs.  They are both identified in CN=TS-Enterprise-License-Server,CN

RE: [ActiveDir] root admin account able to be locked out?

2006-07-22 Thread Thommes, Michael M.
Infrastructure Consultant MVP Windows Server - Directory Services   LogicaCMG Nederland B.V. (BU RTINC Eindhoven) ( Tel : +31-(0)40-29.57.777 (    Mobile : +31-(0)6-26.26.62.80 *   E-mail  :   From: [EMAIL PROTECTED] on behalf of Thommes, Michael

[ActiveDir] OT: Microsoft Acquires Winternals Software

2006-07-21 Thread Thommes, Michael M.
Title: OT: Microsoft Acquires Winternals Software You may find this of interest (from today’s WServerNews): Mike Thommes = Microsoft Acquires Winternals Software Mark Russinovich and Bryce Cogswell have been snagged up by Redmond. And th

[ActiveDir] root admin account able to be locked out?

2006-07-18 Thread Thommes, Michael M.
Title: root admin account able to be locked out? Hi AD Gurus!   We have penetration testing going on and I saw a security event log entry that showed our root admin account getting locked out.  I was surprised because I thought this account could never get locked out.  In addition, we ha

RE: [ActiveDir] Account Password Expiration Tool

2006-07-11 Thread Thommes, Michael M.
joe's tools again ( 8-) ): adfind -b ou=Employees,dc=xyz,dc=com -bit -f "&((objectcategory=person)(useraccountcontrol:AND:=65536))" samaccountname > c:\temp\pw_never_expires.txt Mike Thommes -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Alex Alborzfar

[ActiveDir] importance of "gc._msdcs..com" A records?

2006-06-29 Thread Thommes, Michael M.
Title: importance of "gc._msdcs..com" A records? What is the importance of the “gc._msdcs..com” A records?  Environment: 1) Split DNS – Unix Bind and AD integrated DNS 2) DCs use: [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters] "RegisterDnsARecords"=dw

RE: [ActiveDir] Ammunition, please!

2006-06-28 Thread Thommes, Michael M.
Hi Larry, You might want to check this reference which was posted to this group a few days ago: http://iase.disa.mil/stigs/checklist/AD_Checklist_V1R11_20060607.pdf It discusses physical security and not running other services on DCs, among other things. Mike Thommes -Original Message--

RE: [ActiveDir] [OT] DC Configuration

2006-06-22 Thread Thommes, Michael M.
I know, I know...how about the AD Party? We're ethical, right? joe's probably the most ethical guy around. And he gives stuff away for free. When was the last time you saw a politician do that? I nominate him for President! ;-) Mike Thommes -Original Message- From: [EMAIL PROTECTED]

[ActiveDir] can I exclude a particular user account from "authenticated users"?

2006-06-19 Thread Thommes, Michael M.
Title: can I exclude a particular user account from "authenticated users"? This may sound like an off the wall question, but I would like to exclude a particular user account from the built-in security principal “Authenticated Users”.  Is there any way to do this? TIA! Mike Thommes

RE: [ActiveDir] PCs hang at "Applying computer settings" after upgradingDCs to 2K3 SP1

2006-06-02 Thread Thommes, Michael M.
This is the same issue I posted to this group on 5/25/06.  We never did figure out the cause.  The local admins were rebuilding the workstation in question yesterday since that seemed to be the most expedient thing to do.  I will be interested in future postings to this thread.   Mike Tho

RE: [ActiveDir] OT: srvinfo output incomplete --> solution!

2006-06-02 Thread Thommes, Michael M.
m: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M. Sent: Thursday, June 01, 2006 8:55 AM To: ActiveDir@mail.activedir.org Subject: [ActiveDir] OT: srvinfo output incomplete Situation: running "srvinfo \\computer_name " with domain admin credentials from a

[ActiveDir] OT: srvinfo output incomplete

2006-06-01 Thread Thommes, Michael M.
Title: OT: srvinfo output incomplete Situation: running “srvinfo \\computer_name” with domain admin credentials from a remote computer.  One w2k3/sp1 server target returns the full complement of information, including CPU, BIOS info, hotfixes, network card info, uptime.  Another w2k3sp1 serve

RE: [ActiveDir] MSC pointing at untrusted domain?

2006-05-31 Thread Thommes, Michael M.
Sorry for the last incorrect answer. Try this: runas /netonly /user:domain_or_target_computer\username "mmc.exe eventvwr.msc /computer=target_computer" Mike Thommes -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of AdamT Sent: Wednesday, May 31, 2006 11:3

RE: [ActiveDir] MSC pointing at untrusted domain?

2006-05-31 Thread Thommes, Michael M.
How about: Runas /netonly /user:target_computer\username "eventvwr.exe /auxsource=target_computer" Mike Thommes -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of AdamT Sent: Wednesday, May 31, 2006 11:39 AM To: ActiveDir@mail.activedir.org Subject: [Active

RE: [ActiveDir] OT: stuck processing policy

2006-05-26 Thread Thommes, Michael M.
rrors. Everything described to this point could easily be related to network issues (especially at the NIC/Router) as well.   Al   On 5/26/06, Thommes, Michael M. <[EMAIL PROTECTED]> wrote: Hi Shariff (and Darren too!),    Yeah, I saw some entries in WINS that I didn

RE: [ActiveDir] OT: stuck processing policy

2006-05-26 Thread Thommes, Michael M.
, check the system event log on the client to ensure there are no errors related to authentication, etc.   Darren   From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M. Sent: Thursday, May 25, 2006 2:12 PM To: ActiveDir@mail.activedir.org Subject: RE: [Acti

RE: [ActiveDir] OT: stuck processing policy

2006-05-25 Thread Thommes, Michael M.
Sent: Thursday, May 25, 2006 4:07 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] OT: stuck processing policy   Hi Mike. Can you post the lines of userenv right around that GetUserNameEx error?   From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M

[ActiveDir] OT: stuck processing policy

2006-05-25 Thread Thommes, Michael M.
Title: OT: stuck processing policy I have a user on a computer that takes forever to log in.  She can go to any other computer and log in quickly.  Anyone else can go to the computer in question and log in quickly.  It is only THIS user on the THIS computer.  We have renamed her local profile

RE: [ActiveDir] AD DNS along with Bind

2006-05-25 Thread Thommes, Michael M.
. Could just be a personal preference I suppose... Aric -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M. Sent: Wednesday, May 24, 2006 12:47 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] AD DNS along with Bind Hi Freddy

RE: [ActiveDir] Naming conventions (quasi-OT)

2006-05-24 Thread Thommes, Michael M.
Title: Naming conventions (quasi-OT) Following this thread, I want to comment that we name workstations with their local serial numbers.  In addition, we have a process to look through the local security log to see who is the most common user of the workstation and put their name in the des

RE: [ActiveDir] AD DNS along with Bind

2006-05-24 Thread Thommes, Michael M.
Support Engineer InternationalSOS Pte Ltd mail: [EMAIL PROTECTED] phone: (+65) 6330-9785 -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M. Sent: Wednesday, May 24, 2006 4:38 AM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir

RE: [ActiveDir] view only rights on ADI DNS Zone

2006-05-24 Thread Thommes, Michael M.
The Microsoft link at the bottom of an event log entry has gotten much better.   Mike Thommes   From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Myrick, Todd (NIH/CC/DNA) [E] Sent: Wednesday, May 24, 2006 10:21 AM To: ActiveDir@mail.activedir.org Subject: RE: [Acti

RE: [ActiveDir] AD DNS along with Bind

2006-05-23 Thread Thommes, Michael M.
Adeel, Here is a response from our DNS guy. I hope it helps you. Mike Thommes = Here are the steps I took for delegating the AD zones for example.com: 1) In the example.com zone on the BIND server I added these NS records to delegate the zone t

RE: [ActiveDir] how to find DNS servers in a forest?

2006-05-17 Thread Thommes, Michael M.
Hi Deji, I was thinking about the following but the results are wrong (and I don't understand why!): For /F %a IN ('dsquery server -o rdn -forest') do srvinfo \\%a |find /i "DNS Server" Can anyone tell me what I am doing wrong? Thanks! Mike Thommes -Original Message- From: [EMAIL P

RE: [ActiveDir] Schema extension

2006-05-09 Thread Thommes, Michael M.
"DefaultHidingValue"?   defaultHidingValue A Boolean value that specifies the default setting of the showInAdvancedViewOnly property of new instances of this class. Many directory objects are not interesting to end users. To keep these objects from cluttering the UI,

RE: [ActiveDir] Test Windows 23K Firewall

2006-05-09 Thread Thommes, Michael M.
telnet or portqry? telnet [-a][-e escape char][-f log file][-l user][-t term][host [port]] -a Attempt automatic logon. Same as -l option except uses the currently logged on user's name. -e Escape character to enter telnet client prompt. -f File name for client side loggi

RE: [ActiveDir] which GC answers?

2006-05-03 Thread Thommes, Michael M.
Hi Jorge,     I don’t mean to hijack this thread but I have also been having an issue with lingeringobjects.  I ran your repadmin command shown below on one of the lingering objects I have.  For the lingering object I specified, the output lists a GUID (“Originating DC”) that doesn’t exist

[ActiveDir] dealing with authentication errors after password change?

2006-05-02 Thread Thommes, Michael M.
How do other admins deal with the copious authentication errors a user will generate after the user resets his password with a CNTL+ALT+DEL and stays logged into the session with his old credentials? Mike Thommes List info : http://www.activedir.org/List.aspx List FAQ: http://www.activedir.o

RE: [ActiveDir] how to get rid of an obsolete DC?

2006-05-02 Thread Thommes, Michael M.
H.so *is* ADSIEdit a valid tool to use?  I can see the object I want to delete in ADSIEdit.  (Would I be talking to myself if I reply to my own post?)   Mike Thommes   -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M

RE: [ActiveDir] how to get rid of an obsolete DC?

2006-05-02 Thread Thommes, Michael M.
CTED] [mailto:[EMAIL PROTECTED] On Behalf Of Hutchins, Mike Sent: Tuesday, May 02, 2006 3:06 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] how to get rid of an obsolete DC? ntdsutil -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M

[ActiveDir] how to get rid of an obsolete DC?

2006-05-02 Thread Thommes, Michael M.
In a child domain I have what I believe is the remnants of an old NT4 DC. Using ADUC, it shows up in the child domain's "Domain Controllers" OU. When I try to delete it, I get "The DSA object cannot be deleted." When I use ADSIEdit and go to the domain, it only shows me the two functioning DCs an

[ActiveDir] 2003/SP1 TS Licensing Server registry key confusion

2006-05-01 Thread Thommes, Michael M.
Hi, In trying to determine why my TS Licensing Server (located on a W2K3/SP1 DC) is only handing out temporary licenses, although we have successfully entered the license data, I find the registry key for the type of license is spelled differently (an extra space) than what I find in KB834651.

[ActiveDir] anyone using IPV6?

2006-04-27 Thread Thommes, Michael M.
Has anyone tried IPV6 yet? Production? Or just testbed? Any gotchas? What kind of infrastructure (eg, switches) is needed to support it? How does AD play in this sandbox? I am probably out of my league pretty quickly with subject. I've done a little googling but it seems like a pretty big sub

RE: [ActiveDir] Lsasrv error

2006-04-24 Thread Thommes, Michael M.
Maybe this will help.  From eventid.net:   Matthew C. Miller (Last update 11/24/2005): The error in our server (domain controller) System Event Log was: "The Security System detected an authentication error for the server . The failure code from authentication protocol Kerberos was "{Ope

[ActiveDir] any experiences with PassFilt Pro software? (again)

2006-04-24 Thread Thommes, Michael M.
(I didn't get any response to my first query. I thought I would try it again). This software (http://www.altusnet.com/products/pfp/) supposedly enhances the default passflt.dll, allowing an admin to enforce/control password complexity and, at the same time, does a dictionary check. The price app

[ActiveDir] any experiences with PassFilt Pro software?

2006-04-18 Thread Thommes, Michael M.
Anybody out there have any experience with the PassFilt Pro software by Altus Networks Solutions, Inc.? TIA, Mike Thommes List info : http://www.activedir.org/List.aspx List FAQ: http://www.activedir.org/ListFAQ.aspx List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

RE: [ActiveDir] how to report on scheduled jobs?

2006-04-17 Thread Thommes, Michael M.
Excellent!  Just what I was looking for!  Thanks, Jef!   Mike Thommes   From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Jef Kazimer Sent: Monday, April 17, 2006 3:15 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] how to report on scheduled jobs?  

[ActiveDir] how to report on scheduled jobs?

2006-04-17 Thread Thommes, Michael M.
Is there a script to output scheduled job information? Maybe something I could call in a "for" loop driven by a list of servers. Ideally, I would like to see the job and who's credentials it is running under, with maybe the schedule. Mike Thommes List info : http://www.activedir.org/List.aspx

[ActiveDir] how to display DC services on a single line?

2006-04-13 Thread Thommes, Michael M.
There is a command that shows on a single line what services are running on a DC. The output is something like DS::GC::Time::LDAP:: Can someone help this poor, tired brain out? Thanks! Mike Thommes List info : http://www.activedir.org/List.aspx List FAQ: http://www.activedir.

RE: [ActiveDir] issue with R2 upgrade; SFU confusion?

2006-04-13 Thread Thommes, Michael M.
> Subject: RE: [ActiveDir] issue with R2 upgrade; SFU confusion? > > Ask him/her what the article number is if this is a known issue. If > he/she says there isn't one then say it sure isn't known very well > then. > > > -- > O'Reilly Active Directory T

[ActiveDir] default values for "net time /querysntp" on new systems?

2006-04-11 Thread Thommes, Michael M.
Hi, I've noticed in our Active Directory environment default settings on Windows XP and Server 2003 computers for "net time /querysntp" to be one of two values: net time /querysntp The current SNTP value is: time.windows.com,0x1 net time /querysntp This computer is not currently configured to

RE: [ActiveDir] Server 2003 "DNS Admins" group permissions

2006-04-06 Thread Thommes, Michael M.
|-Original Message- |From: [EMAIL PROTECTED] |[mailto:[EMAIL PROTECTED] On Behalf Of |Thommes, Michael M. |Sent: Thursday, April 06, 2006 5:54 PM |To: ActiveDir@mail.activedir.org |Subject: [ActiveDir] Server 2003 "DNS Admins" group permissions | |The default "DNS Ad

RE: [ActiveDir] 2003 DFS/open files

2006-04-06 Thread Thommes, Michael M.
Gott       From: [EMAIL PROTECTED] on behalf of Thommes, Michael M. Sent: Wed 4/5/2006 7:25 AM To: ActiveDir@mail.activedir.org Subject: [ActiveDir] 2003 DFS/open files Can someone tell me what happens with DFS/replication when a file is updated on one DFS server and a client has

[ActiveDir] Server 2003 "DNS Admins" group permissions

2006-04-06 Thread Thommes, Michael M.
The default "DNS Admins" group has permission to use the DNS GUI (dnsmgmt.msc) and to make changes in it but does not have permission to view the DNS event log (DnsEvent.Evt). Would this just be an oversight on Microsoft's part? TIA, Mike Thommes List info : http://www.activedir.org/List.aspx L

[ActiveDir] 2003 DFS/open files

2006-04-05 Thread Thommes, Michael M.
Can someone tell me what happens with DFS/replication when a file is updated on one DFS server and a client has that same file open on another DFS server? TIA! Mike Thommes List info : http://www.activedir.org/List.aspx List FAQ: http://www.activedir.org/ListFAQ.aspx List archive: http://www

RE: [ActiveDir] Empty hostname for a Win 2003 server belonging to an AD domain

2006-04-04 Thread Thommes, Michael M.
How about: dsquery computer -samid   | dsget computer –sid   Mike Thommes   From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of matheesha weerasinghe Sent: Tuesday, April 04, 2006 10:56 AM To: ActiveDir@mail.activedir.org Subject: Re: [ActiveDir] Empty hostname for a

RE: [ActiveDir] Lingering Objects

2006-04-03 Thread Thommes, Michael M.
Hi joe,     Two questions:   -  Are “lingering objects” the same as “phantom objects”? -  The help for repadmin on my 2003/SP1 DCs doesn’t indicate a “/removelingeringobjects” option.  What version do you have that lets you do this?   Thanks!   Mike Thommes   Ps. 

RE: [ActiveDir] Mass AD Full Name & Display Name Changes - Last name, first name

2006-03-01 Thread Thommes, Michael M.
These may be of interest to you: http://support.microsoft.com/kb/277717/en-us http://support.microsoft.com/?kbid=300427 Mike Thommes -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Danny Sent: Wednesday, March 01, 2006 1:42 PM To: ActiveDir@mail.activedi

RE: [ActiveDir] repadmin info oddity

2006-02-21 Thread Thommes, Michael M.
Adfind (http://www.joeware.net/win/free/tools/adfind.htm) to the rescue! I recently had to do this and got it accomplished with the following syntax (with a little help from joe :) ): adfind -default -binenc -f objectGUID={{GUID:0B3F5BC4-5713-4611-8F6A-752A3B0DE664}} dn ("adfind /???" For lots o

RE: [ActiveDir] issue with R2 upgrade; SFU confusion?

2006-02-17 Thread Thommes, Michael M.
Our MS TAM has indicated this is a known bug! I will keep the group posted as I learn more details. Mike Thommes -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M. Sent: Friday, February 17, 2006 10:52 AM To: ActiveDir

RE: [ActiveDir] issue with R2 upgrade; SFU confusion?

2006-02-17 Thread Thommes, Michael M.
nment where SFU 3.5 had been installed. Thanks! Mike Thommes -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M. Sent: Thursday, February 16, 2006 9:07 AM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] issue with R2 upgrade; SFU conf

[ActiveDir] ability to create container objects not in ADUC

2006-02-16 Thread Thommes, Michael M.
Is there a technical reason why the ability to create a new container is not available in the Active Directory Users and Computers (ADUC) mmc? (Sorry if this is a dumb question.) Mike Thommes List info : http://www.activedir.org/List.aspx List FAQ: http://www.activedir.org/ListFAQ.aspx List

  1   2   3   4   >