RE: [ActiveDir] Anti-virus protection in domain enviroment

2005-10-04 Thread Tim Vander Kooi
We use NOD32 on DCs with no ill effects what so ever. I agree that right now it is the best anti-virus solution available. We use is for both servers and workstations using the enterprise edition with Remote Management console. I love it. We do not use NOD's Exchange product, not because it isn't g

RE: [ActiveDir] Anti-virus protection in domain enviroment

2005-10-04 Thread Tim Vander Kooi
NOD has an admin console very similar to ePO and the others. (does anyone NOT have a console now days?) Works very nicely to see everything that is happening throughout your LAN and WAN virus-wise. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Susan Bra

RE: [ActiveDir] Anti-virus protection in domain enviroment

2005-10-05 Thread Tim Vander Kooi
I've only been on the list a short time, but I must have missed the mandatory Trend Micro brainwashing. :-) So far from what I have noticed there seems to be a set answer to all AV questions. Question: I'm curious about the capabilities of NOD32. Answers (en mass): You should use Trend Micro. Quest

RE: [ActiveDir] GPO Permissions with .vbs

2005-10-05 Thread Tim Vander Kooi
What is your OS? Is it a user specific task or a computer based task? If it is a task scheduled to run after the user logs on I'm sure it is permissions, or lack there of. Tim Vander Kooi Microsoft Systems Administrator Explorer Pipeline From: [EMAIL PROTECTED] [mailto:[EMAIL PROT

RE: [ActiveDir] Anti-virus protection in domain enviroment

2005-10-05 Thread Tim Vander Kooi
ry. Real geeks don't use A/V anyway. [you should have seen the thread on whether to stick a/v on a web server on the focus on ms listserve... if you set up a server for a select job, lock it down only serve up static pages.. why 'does' it need to be covered by A/V was the top

RE: [ActiveDir] Anti-virus protection in domain enviroment

2005-10-06 Thread Tim Vander Kooi
riginal Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Tim Vander Kooi Sent: Wednesday, October 05, 2005 4:12 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] Anti-virus protection in domain enviroment I agree that most all AV vendors are alike, as are most of

RE: [ActiveDir] Anti-virus protection in domain enviroment

2005-10-06 Thread Tim Vander Kooi
you have to ftp it (you can script/schedule it). -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Tim Vander Kooi Sent: Wednesday, October 05, 2005 4:12 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] Anti-virus protection in domain enviroment I ag

RE: [ActiveDir] Active Directory wish list

2005-10-06 Thread Tim Vander Kooi
I think the biggest problem is cultural. And we as developers and administrators make the situation worse by giving in to pressure from business leaders. The average user when you tell them that they now have to have a password that is at least 15 characters long including special characters and

RE: [ActiveDir] Active Directory wish list

2005-10-07 Thread Tim Vander Kooi
reconnect to an existing session with that user context I see That pukes out around 14 characters. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Tim Vander Kooi Sent: Thursday, October 06, 2005 11:09 AM To: ActiveDir@mail.activedir.org Subject: RE

RE: [ActiveDir] Schema Updates

2005-10-07 Thread Tim Vander Kooi
Title: Schema Updates I just did this last week to install Cisco Unity and I still had to enable schema updates in Windows 2003 even though the user was in Schema Admins. I was under the same impression as Travis, but after enabling updating in the registry it worked fine. From: [EMAIL PROT

RE: [ActiveDir] Schema Updates

2005-10-07 Thread Tim Vander Kooi
Title: Schema Updates Upgraded. From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of [EMAIL PROTECTED]Sent: Friday, October 07, 2005 9:38 AMTo: ActiveDir@mail.activedir.orgSubject: RE: [ActiveDir] Schema Updates Upgraded to 2003 or fresh install?   :m:dsm:cci:mvp marcusoh.bl

RE: [ActiveDir] Schema Updates

2005-10-10 Thread Tim Vander Kooi
Title: Schema Updates Not sure why you don't like Unity, it's the best unified messaging app there is right now. Actually has been for over 5 years. I believe that the reason it;s as good as it is, is that it was not created or even modified much by Cisco, they simply bought a really good pro

RE: [ActiveDir] Schema Updates

2005-10-10 Thread Tim Vander Kooi
Title: Schema Updates And I will never run Windows because 3.11 just wasn't that great at networking. ;-) From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of joeSent: Monday, October 10, 2005 9:42 AMTo: ActiveDir@mail.activedir.orgSubject: RE: [ActiveDir] Schema Updates Being

RE: [ActiveDir] Schema Updates

2005-10-10 Thread Tim Vander Kooi
Title: Schema Updates I understand your point of view completely, I have the same hang up about anything made by CA. (Not on my network.) Unity really depends on your use. The things that Cisco has changed make it awesome to use if you have an AD environment and a Cisco VOIP system. Pricey to

RE: [ActiveDir] Schema Updates

2005-10-10 Thread Tim Vander Kooi
Title: Schema Updates The price tag will definitely drop as soon as Microsoft releases Exchange 12 with UM built in. But, it's not THAT expensive today, and there are some great business pluses to it. We had no problems showing ROI on VOIP or UM. From: [EMAIL PROTECTED] [mailto:[EMAIL PROT

RE: [ActiveDir] Schema Updates

2005-10-11 Thread Tim Vander Kooi
Title: Schema Updates I agree completely that the strength, or weakness, of your implementation depends 100% on the abilities of the partner doing your install and your admins on staff. I've been working with Unity since it was the voicemail system for NEC PBXs back in the 90's so it's never

RE: [ActiveDir] .msp & GPOs

2005-10-11 Thread Tim Vander Kooi
Reinstall the msi using the new msp. From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Harding, DevonSent: Tuesday, October 11, 2005 11:56 AMTo: ActiveDir@mail.activedir.orgSubject: [ActiveDir] .msp & GPOs How can I deploy a Symantec patch file (SAV_Corporate_Edition_10

RE: [ActiveDir] .msp & GPOs

2005-10-12 Thread Tim Vander Kooi
Sorry, but redeploying the app is reinstalling. From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Brian DesmondSent: Tuesday, October 11, 2005 5:06 PMTo: ActiveDir@mail.activedir.orgSubject: RE: [ActiveDir] .msp & GPOs Why would he do that? The MSI is on the share for the

RE: [ActiveDir] OT: Are MS Sharepoint CAL's good for multiple portals?

2005-10-25 Thread Tim Vander Kooi
For your described situation a CAL would not cover both portals. Then again, if you are using it for an Extranet with CALs you are incorrectly licensed as is. An Extranet setup would require an External Connector license, as the people connecting to it are not employees of your company. Usin

RE: [ActiveDir] OT: Are MS Sharepoint CAL's good for multiple portals?

2005-10-26 Thread Tim Vander Kooi
thout buying more CAL's, can we run an intranet portal for our employees using that Sharepoint server?   Thanks! ----- Original Message - From: Tim Vander Kooi To: ActiveDir@mail.activedir.org Sent: Tuesday, October 25, 2005 3:27 PM Subject: RE:

RE: [ActiveDir] OT: Are MS Sharepoint CAL's good for multiple portals?

2005-10-26 Thread Tim Vander Kooi
ubject: Re: [ActiveDir] OT: Are MS Sharepoint CAL's good for multiple portals? For the few extranet users we have, they do have login accounts in an AD domain on our network.   I appreciate all the info so far. - Original Message ----- From: Tim Vander Kooi To: ActiveDir@mai

RE: [ActiveDir] OT: Are MS Sharepoint CAL's good for multiple portals?

2005-10-26 Thread Tim Vander Kooi
riginal Message ----- From: Tim Vander Kooi To: ActiveDir@mail.activedir.org Sent: Wednesday, October 26, 2005 9:56 AM Subject: RE: [ActiveDir] OT: Are MS Sharepoint CAL's good for multiple portals? In that case, you are really just running 2 different intranets,

RE: [ActiveDir] Change Auditor tools

2005-11-08 Thread Tim Vander Kooi
I use Active Administrator and love it, almost as much as our auditors do. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Olegario, Alan Sent: Tuesday, November 08, 2005 8:21 AM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] Change Auditor too

RE: [ActiveDir] Change Auditor tools

2005-11-10 Thread Tim Vander Kooi
I have both InTrust by Quest and Active Administrator by ScriptLogic on my network now. I can tell you from real world side by side comparisons that Active Administrator is MUCH easier to set up and get running out of the box. It is also much easier to configure with regards to emailing alerts and

RE: [ActiveDir] OT: Enterasys vs Cisco

2005-11-21 Thread Tim Vander Kooi
What are you looking at using them for? I've used their outdoors wireless solutions for shots of a couple miles between buildings with very good success. From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Noah EigerSent: Monday, November 21, 2005 1:17 PMTo: ActiveDir@mail.acti

RE: [ActiveDir] Assigning Software Via GPO

2006-06-02 Thread Tim Vander Kooi
Title: Assigning Software Via GPO Assign the package to the machine not the user. This causes the software to be installed under the System account which has permissions. Just be sure to add Local Computers to the Security list or the install will fail. Tim   From: [EMAIL PROTECTED]

RE: [ActiveDir] Ammunition, please!

2006-06-28 Thread Tim Vander Kooi
Have you looked into the RODC capability coming with Longhorn? It’s really not that far off, and it solves most of the security issues you are worried about. I was able to use the promise of RODC to get management here to back off of DCs at all branch locations until next year. If they st

[ActiveDir] RE: [ActiveDir] Read-Only Domain Controller and Server Core

2006-07-28 Thread Tim Vander Kooi
I’m not sure why you say it doesn’t store anything??? It stores EVERYTHING, it simply doesn’t get the rights to write anything new back to your core DCs. This is a HUGE breakthrough for those of us with smaller branch offices that today can’t cost justify putting an entire server

[ActiveDir] RE: [ActiveDir] Exchange attributes..

2006-08-03 Thread Tim Vander Kooi
You need to load the ESM on your DCs and/or your XP machine to see the Exchange tabs. You can load it from your Exchange CD.   From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of HBooGz Sent: Thursday, August 03, 2006 10:26 AM To: ActiveDir@mail.activedir.o

RE: [ActiveDir] OT: Management Solutions

2006-09-12 Thread Tim Vander Kooi
Have you looked at the beta for System Center Essentials from Microsoft? I think it would do a lot of what you are looking at. And for far less money than Altiris. Altiris  makes a great product, but it is very much on the high end price-wise. Another product I would recommend looking at wo

RE: [ActiveDir] OT: Why 64 for Exchange

2005-12-29 Thread Tim Vander Kooi
Just about everyone using SQL Server prior to the release of 2005 was wanting Outlook on their server to enable SQL Mail. Now why anyone would have Exchange and SQL on the same box is beyond me. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Susan Bradle

RE: [ActiveDir] OT: Why 64 for Exchange

2005-12-29 Thread Tim Vander Kooi
med like 5 minutes at the request. They figured something else out and got email notifications from the server just fine. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Tim Vander Kooi Sent: Thursday, December 29, 2005 2:28 PM To: ActiveDir@mail.act

RE: [ActiveDir] Windows 2003 Server

2006-01-05 Thread Tim Vander Kooi
I've had this happen before and have always been able to remove all permissions to the file in question with the exception of Domain Admins or my personal log in, depending on the situation. Usually it is removing the System permissions that does the trick though. From: [EMAIL PROTECTED] [

RE: [ActiveDir] Windows update out of control??? [signed]

2006-01-10 Thread Tim Vander Kooi
That is usually a result of GPO being set to restrict (or direct) use of Auto Update. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Chris Neves [c] Sent: Tuesday, January 10, 2006 8:59 AM To: ActiveDir@mail.activedir.org Subject: [ActiveDir] Windows upd

RE: [ActiveDir] Local admin priviledges

2006-02-14 Thread Tim Vander Kooi
Being a local admin on a PC does not give them the ability to see another machine's C$ share. This would occur if you added a group (local admins) to the administrators group on all PCs and then added users to that group instead of doing it on a user by user basis. That said, I would look fo

RE: [ActiveDir] How Secure is a Domain Controller?

2006-03-06 Thread Tim Vander Kooi
Based on the subject of this discussion: if you have those regular users, who can't comprehend or remember a password over 7 characters, signing on to your domain controllers I would say that your domain controllers are VERY not secure. Secondly, if your domain administrators are so lazy as t

RE: [ActiveDir] How Secure is a Domain Controller?

2006-03-06 Thread Tim Vander Kooi
I understand/stood what you were saying, just was hoping to bring out a clearer answer for some of the lurker/newbies on the list (of which there are many). And you provided exactly that clarification which was excellent. Thank you. I still personally believe in the statement that if I can t

RE: [ActiveDir] 2003 DFS/open files

2006-04-05 Thread Tim Vander Kooi
If running DFS on R2 the last write wins, but the first write is put into the Conflict and Deleted folder on the server, so that it can be retrieved if necessary, depending on available space, quotas, etc. HTH, Tim From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of mike klineS

RE: [ActiveDir] GC Promotion

2006-04-28 Thread Tim Vander Kooi
It means if you kiss...You don't tell. :~) From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Mark ParrisSent: Friday, April 28, 2006 1:11 PMTo: ActiveDir@mail.activedir.orgSubject: RE: [ActiveDir] GC Promotion Anyone know what constitutes domain controller discretion?  

RE: [ActiveDir] R2 Upgrade or install?

2006-04-28 Thread Tim Vander Kooi
If you are asking if there is anything "special" about Disk 1 of the R2 install set, then the answer is no. Whether you install Windows 2003 Server SP1 from the R2 set or you have 2003 SP1 already installed, it makes no difference. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL

[ActiveDir] RE: [ActiveDir] Major screwup on AD for my company - Can't install AD on remote server now

2006-10-06 Thread Tim Vander Kooi
It's not speed or resources that scare most of us when it comes to sharing DC space with other apps, it's security. With SBS Microsoft has (at least in theory) covered most of those security bases for the admin. The last time I allowed another admin to install FTP on a server he inadvertently put n

[ActiveDir] RE: [ActiveDir] OT: wikis

2006-10-11 Thread Tim Vander Kooi
Richard Nixon? -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Steve Egan (Temp) Sent: Wednesday, October 11, 2006 6:43 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] OT: wikis Ummm, what's 6 X 9 ?? Steve Egan Purcell Systems System/Network

RE: [ActiveDir] OT: TechED 2007

2006-10-19 Thread Tim Vander Kooi
It was beautiful weather there for TechEd 2000. I had thought that the transportation was less than great, but after Boston this year it wasn’t bad at all in retrospect.   From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Akomolafe, Deji Sent: Thursda

RE: [ActiveDir] OT: TechED 2007

2006-10-19 Thread Tim Vander Kooi
@mail.activedir.org Subject: Re: [ActiveDir] OT: TechED 2007 With or without the police escorts? ;-) Tim Vander Kooi wrote: > > It was beautiful weather there for TechEd 2000. I had thought that the > transportation was less than great, but after Boston this year it > wasn’t bad at all i

RE: [ActiveDir] OT: TechED 2007

2006-10-20 Thread Tim Vander Kooi
_ From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Tim Vander Kooi Sent: 19 October 2006 22:40 To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] OT: TechED 2007

RE: [ActiveDir] OT: Vista Activation and KMS

2006-12-04 Thread Tim Vander Kooi
You need to go to Control Panel > System then at the bottom select Change Product Key. This will allow you to enter your VL key which will result in Vista activating via the web. Definitely not well documented unfortunately. From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Brian C

RE: [ActiveDir] OT: Vista Activation and KMS

2006-12-04 Thread Tim Vander Kooi
Activation and KMS But the MVLS admin has to request the MAK keys... on mine the KMS were default and I had to request MAK (like Brian said) Tim Vander Kooi wrote: > > You need to go to Control Panel > System then at the bottom select > Change Product Key. This will allow you to enter

RE: [ActiveDir] OT: Vista Activation and KMS

2006-12-05 Thread Tim Vander Kooi
While Laura and yourself make valid points, you are both talking about solutions that do not exist today. I'm just trying to help the OP with the problem he is having right now. Getting into the full licensing overhead of Vista, not to mention LH, could, and undoubtedly will, take weeks and/or mont

RE: [ActiveDir] Vista GPO

2006-12-15 Thread Tim Vander Kooi
They won't do it if Microsoft makes it so they CAN'T do it. I feel Microsoft should be applauded for forcing admins to do their jobs correctly for a change, instead of giving in to the lazy or uninformed amongst us. Just my opinion, Tim From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Beh

RE: [ActiveDir] Vista GPO

2006-12-15 Thread Tim Vander Kooi
Well said. But while you're at it, could you let someone know that I very upset that I can't manage my Vista GPOs from my Windows ME PC. Thanks much. ;-) From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Laura A. Robinson Sent: Friday, December 15, 2006 1:26 PM To: ActiveDir@mail

RE: [ActiveDir] Vista GPO

2006-12-15 Thread Tim Vander Kooi
n. But I won't. Sincerely, _ (, / | /) /) /) /---| (/_ __ ___// _ // _ ) /|_/(__(_) // (_(_)(/_(_(_/(__(/_ (_/ /) (/ Microsoft MVP - Directory Services www.akomolafe.com - we know IT -5.75, -3.23 Do you now realize that Today is the Tomorrow you were worried about Yesterday? -anon _______

RE: [ActiveDir] Vista GPO

2006-12-15 Thread Tim Vander Kooi
on the server with your admin ID and do user stuff on your workstation with your workstation ID, so doing GP editing on the workstation isn't best practice, but that's my point of view =) Thanks, Andrew Fidel Tim Vander Kooi <[EMAIL PROTECTED]> Sent by: [EMAIL PROTEC

RE: [ActiveDir] Vista GPO

2006-12-15 Thread Tim Vander Kooi
same time that we release them for Microsoft Bob, IIRC. ;-) Laura From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Tim Vander Kooi Sent: Friday, December 15, 2006 3:49 PM To: ActiveDir@mail.activedir.org S

RE: [ActiveDir] Vista GPO

2006-12-18 Thread Tim Vander Kooi
I've got it out in production now. Not enterprise wide, but in production on a decent number of machines. Granted, I don't run ISA and I don't use Trend. I run NOD and they have a Vista ready version of their AV product out. We rolled Vista to all of our tablet PCs almost immediately upon release a

RE: [ActiveDir] [OT]MOM mailing list

2007-01-03 Thread Tim Vander Kooi
I could give you mine...but my mom doesn't talk to strangers. Sorry. From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of WATSON, BEN Sent: Wednesday, January 03, 2007 4:26 PM To: ActiveDir@mail.activedir.org Subject: [ActiveDir] [OT]MOM mailing list Anyone have a recommendation o