[ActiveDir] Cross forest policies - boxes in Win2k domain, users in win2k3 s ingle domain forest

2004-03-31 Thread Wilkinson, Stephen
Title: Cross forest policies - boxes in Win2k domain, users in win2k3 single domain forest Hello all, Having moved all of our users from an NT4 account domain to a Windows 2003 domain, we have a requirement to set policies on our citrix servers which sit in a separate windows 2000 forest,

[ActiveDir] Best practice for default domain controller policy

2004-03-12 Thread Wilkinson, Stephen
Title: Best practice for default domain controller policy Hi All, When we were designing our Win 2003 AD about this time last year, we were advised by our MCS consultant to copy the default domain and default domain controller policies, and then customise, rather than customising the

RE: [ActiveDir] Migration Tool

2003-11-14 Thread Wilkinson, Stephen
We are using the Quest Fastlane Migrator 6.0.2 and are very happy with it. Only real drawback is the ability to re-migrate groups is missing. i.e. you cannot do a big bang migration of groups and then when you wish to update the groups (as membership may have changed) it will only re-create the

[ActiveDir] Terminal Services and domain credentials Win2k3-Win2k

2003-08-27 Thread Wilkinson, Stephen
Title: Terminal Services and domain credentials Win2k3-Win2k This maybe slightly off-topic but we are seeing something odd in our environment where when we try to connect via terminal service (any client) to a host in a Windows 2000 (SP4) Active Directory domain with an account from a W2003

[ActiveDir] How to delegate the extended right to migrate sIDHistory

2003-08-14 Thread Wilkinson, Stephen
Title: How to delegate the extended right to migrate sIDHistory In order to allow test migrations from out NT4 world to 2003 AD, we currently have many regional and departmental admins as Domain Admins in or test 2003 AD so we can migrate and utilise sIDHistory. I would prefer it if we could

RE: [ActiveDir] Do you allow users to add computers to AD themselves?

2003-07-29 Thread Wilkinson, Stephen
Guys, You have managed to confuse me! Why don't you just delegate the permission on the computers to container to your Technical Services and Lan Admin groups - so they can create computer objects and are not bound by the quota, as it does not apply if you have the create computer object

RE: [ActiveDir] admt 2.0 - nt4 computer migration

2003-07-09 Thread Wilkinson, Stephen
I think Larry's first response could be it Graham. We saw exactly this in our testing with the Quest Migrator product. You must make sure there is no computer account with the same name already in the AD - hiding in an OU you least expect it! (ours got there during testing by manually moving

[ActiveDir] OT perhaps.. Connecting non-admin to remote console in Win2k3 DCs

2003-07-02 Thread Wilkinson, Stephen (DrKW)
We are having trouble connecting non-admin users to the remote console session on our DCs. They have the correct logon locally privilege and we have permissioned the RDP session int Terminal Services ok so non-admins (if they are in the relevant group) can connect to the DC via a terminal session

RE: [ActiveDir] OT perhaps.. Connecting non-admin to remote conso lein Win2k3 DCs

2003-07-02 Thread Wilkinson, Stephen (DrKW)
? -Original Message- From: Wilkinson, Stephen (DrKW) [mailto:[EMAIL PROTECTED] Sent: Wednesday, July 02, 2003 6:25 AM To: '[EMAIL PROTECTED]' Subject: [ActiveDir] OT perhaps.. Connecting non-admin to remote console in Win2k3 DCs We are having trouble connecting non-admin users to the remote

RE: [ActiveDir] OT perhaps.. Connecting non-admin to remote conso lein Win2k3 DCs

2003-07-02 Thread Wilkinson, Stephen (DrKW)
Yes we have successfully logged in at the console and through the iLo RIB and it works ok with our non-admin test user Stephen WilkinsonTel +44(0)207 4759276Mobile+44(0)7973 143970E-Mail: [EMAIL PROTECTED] From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Sent: 02 July 2003

RE: [ActiveDir] Object level restore

2003-07-02 Thread Wilkinson, Stephen (DrKW)
Stuart [This posting is provided "AS IS" with no warranties, and confers no rights.] From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Wilkinson, Stephen (DrKW)Sent: Tuesday, May 20, 2003 6:17 AMTo: '[EMAIL PROT

RE: [ActiveDir] Single sign-on

2003-06-06 Thread Wilkinson, Stephen (DrKW)
Just a fyi - On a MS sponsored Windows Server 2003 Readiness course last week our guys were told that MMS 3.0 would cost £25,000 (may have been $s) per processor. Which is a stunning amount of money - in either currency Stephen Wilkinson Tel: +44(0)207 4759276 Mobile: +44(0)7973 143970

RE: [ActiveDir] w2k / nt4 trust

2003-05-30 Thread Wilkinson, Stephen (DrKW)
Graham, You will be pleased to know that we are currently experiencing exactly the same issues and are now stepping through resetting the polices we had applied on the AD DCS to the reverse and stepping through w2k3 version of the doc you referenced (PSS 325874). There is a PSS article