RE: [ActiveDir] automatic account disable

2006-04-19 Thread deji
Third-party. Sincerely, _ (, / | /) /) /) /---| (/_ __ ___// _ // _ ) /|_/(__(_) // (_(_)(/_(_(_/(__(/_ (_/ /) (/ Microsoft MVP - Directory

RE: [ActiveDir] NT 3.51 trust verification lies

2006-04-18 Thread deji
Man, you sure are brave :) Anywhoo, I was going to suggest that you whip out the trusty lmhosts magic file and see if that helps you. That used to solve a lot of trust and resolution issues for us in those days. But then I read that DomainB has no beef with the 3.51. So, I don't know what to tell

RE: [ActiveDir] NT 3.51 trust verification lies

2006-04-18 Thread deji
You are kidding, right? Please say yes. 3.51 You work in a museum or something? :) Sincerely, _ (, / | /) /) /) /---| (/_ __ ___// _ // _ ) /|_/(__(_) // (_(_)(/_(_(_/(__(/_ (_/ /

RE: [ActiveDir] lockout account

2006-04-18 Thread deji
This helps for background info? http://support.microsoft.com/?kbid=250873 Sincerely, _ (, / | /) /) /) /---| (/_ __ ___// _ // _ ) /|_/(__(_) // (_(_)(/_(_(_/(__(/_ (_/ /)

RE: [ActiveDir] "No Terminal License Server available"

2006-04-13 Thread deji
I don't see the "change". What you quoted is describing what I said. Sincerely, _ (, / | /) /) /) /---| (/_ __ ___// _ // _ ) /|_/(__(_) // (_(_)(/_(_(_/(__(/_ (_/ /)

RE: [ActiveDir] "No Terminal License Server available"

2006-04-12 Thread deji
Let me guess because the DC you demoted is your Terminal Service License server in the domain? It's been a while since I last baby-sat a TS issue, but I believe that if the Site license service is not installed on a DC, then you will have to manually tell EACH TS in your environment how to lo

RE: [ActiveDir] OU's Structure

2006-04-12 Thread deji
The consultant may have been referring to the number of GPOs that you are attaching to the OUs. The more GPOs that have to be processed, the longer the login time. OU design is really a matter or preferences, IMO. Sincerely, _ (, / | /)

RE: [ActiveDir] Domain System Volume

2006-04-12 Thread deji
Go ahead and delete it. Delete it in Sites and Services as well as in the Domain Controllers OU if it's still there. Then look for traces of it in your DNS zone and nuke any reference to it. Sincerely, _ (, / | /) /) /) /---| (

RE: [ActiveDir] Changing a users password

2006-04-12 Thread deji
Function generatePassword( allowNumbers ) NUMLOWER= 48 ' 48 = 0 NUMUPPER= 57 ' 57 = 9 LOWERBOUND = 65 ' 65 = A UPPERBOUND = 90 ' 90 = Z LOWERBOUND1 = 97 ' 97 = a UPPERBOUND1 = 122 ' 122 = z PASSWORD_LENGTH = 10 ' initialize the random number generator Randomize() UserPass =

RE: [ActiveDir] Changing a users password

2006-04-12 Thread deji
Delegate the ability to reset password to your helpdesk lady. Then grab http://www.rlmueller.net/Programs/ResetPassword.txt Clean that up, put it behind an asp page that requires authentication. Give your helpdesk lady access to the page and show her how to use it. Sincerely, _

[ActiveDir] Is this thing working?

2006-04-11 Thread deji
Please ignore. Sincerely, _ (, / | /) /) /) /---| (/_ __ ___// _ // _ ) /|_/(__(_) // (_(_)(/_(_(_/(__(/_ (_/ /) (/ Microsoft MVP - Directo

RE: [ActiveDir][OT] Documentation regarding ADLB

2006-04-06 Thread deji
If you say so ;) Sincerely, _ (, / | /) /) /) /---| (/_ __ ___// _ // _ ) /|_/(__(_) // (_(_)(/_(_(_/(__(/_ (_/ /) (/ Microsoft MVP - Direc

RE: [ActiveDir] Documentation regarding ADLB

2006-04-06 Thread deji
Hehe. You are terrible :O) Sincerely, _ (, / | /) /) /) /---| (/_ __ ___// _ // _ ) /|_/(__(_) // (_(_)(/_(_(_/(__(/_ (_/ /) (/ Microsoft M

RE: [ActiveDir] Documentation regarding ADLB

2006-04-06 Thread deji
The 2 docs I referenced are in the original. I don't believe that the R2 one has adlb materials. Sincerely, _ (, / | /) /) /) /---| (/_ __ ___// _ // _ ) /|_/(__(_) // (_(_)(/_(_(_/(__(/_ (_/

RE: [ActiveDir] Documentation regarding ADLB

2006-04-06 Thread deji
Neil, I don't know which doc you are looking at, but the BOIS docs do a good job on this topic IMO. If we are looking at the same docs, are you saying 04_Deploy_BuildBranch.doc and 06_Plan_Monitoring.doc are not enough to get you started? Sincerely, _ (,

RE: [ActiveDir] DNS errors

2006-04-04 Thread deji
If you'd just copy and paste the output into the body of your email, I may be able to see it. I have a very aggressive spam/attachment filter here. Sincerely, _ (, / | /) /) /) /---| (/_ __ ___// _ // _ ) /|_/(_

RE: [ActiveDir] DNS errors

2006-04-04 Thread deji
Let's see the output of "ipconfig /all" from the affected server. Sincerely, _ (, / | /) /) /) /---| (/_ __ ___// _ // _ ) /|_/(__(_) // (_(_)(/_(_(_/(__(/_ (_/ /)

RE: [ActiveDir] Is there a work around to get all groups (number of groups is mo re than MaxPageSize)?

2006-04-03 Thread deji
You need to page the result using "Page Size" property and specify how much you want your query to return at a time. The MaxPageSize can be increased also, but the more efficient option is to just use the paging method. Here's a link that talks about this briefly - http://msdn.microsoft.com/libra

RE: [ActiveDir] Where's Deji.. (was Quiet? DEC? Related?)

2006-04-03 Thread deji
m> Do you now realize that Today is the Tomorrow you were worried about Yesterday? -anon From: [EMAIL PROTECTED] on behalf of Gil Kirkpatrick Sent: Sun 4/2/2006 1:52 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] Where's Deji.. (was Qu

RE: [ActiveDir] Script not working thru GPO

2006-03-27 Thread deji
Try accessing \\fileserver\serverlist.txt from the problem machine and see what you get. Sincerely, _ (, / | /) /) /) /---| (/_ __ ___// _ // _ ) /|_/(__(_) // (_(_)(/_(_(_/(__(/_ (_/

RE: [ActiveDir] ldifde question

2006-03-24 Thread deji
Assuming that the structures are now the same, then if you modify your query as follows: -l "cn,objectclass,ou,member", you should get an output that includes the DN of the members of each group. Then you should be able to import the output into your target AD. If the structures are not the same, t

RE: [ActiveDir] hosts file on AD DNS server

2006-03-22 Thread deji
>>>I want to know if I can move that hosts file to our local DNS server and have it resolve for us. You wish. Hosts files are not meant to be used this way. Local hosts files is needed on the workstations you are doing the administration from. If they change that frequently, script a period ro

RE: [ActiveDir] Weird AD problem

2006-03-22 Thread deji
Just re-demote it and disjoin it from the domain. Clean up DNS. Delete the account manually in ADUC (there is probably a dupe already). Then rejoin and repromote. Sincerely, _ (, / | /) /) /) /---| (/_ __ ___// _ // _

RE: [ActiveDir] hosts file on AD DNS server

2006-03-22 Thread deji
Yes Sincerely, _ (, / | /) /) /) /---| (/_ __ ___// _ // _ ) /|_/(__(_) // (_(_)(/_(_(_/(__(/_ (_/ /) (/ Microsoft MVP - Directory Services

RE: [ActiveDir] When and how often are EA rights needed?

2006-03-14 Thread deji
>>>IMHO, if you have rights to do all the above, you are an EA equivalent any way :) These rights do not even come close to equaling EA in any sense. Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now re

RE: [ActiveDir] When and how often are EA rights needed?

2006-03-14 Thread deji
No, it doesn't. These are rights that can be delegated even at site object level. Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried about Yesterday? -

RE: [ActiveDir] What do you do when ooops won't work?

2006-03-09 Thread deji
ssage- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Grillenmeier, Guido Sent: Thursday, March 09, 2006 3:09 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] What do you do when ooops won't work? come on Deji - forget whoever you've had in your contact li

RE: [ActiveDir] What do you do when ooops won't work?

2006-03-09 Thread deji
x27;m not sure what those pocket PC's do when they sync their nothingness, but they definitely don't mark the items as deleted. I've run into the same situation with users and PocketPC's and haven't found an acceptable solution... Deji: Do you by chance have an Outlook

RE: [ActiveDir] What do you do when ooops won't work?

2006-03-09 Thread deji
On MY Exchange servers, yes. On the CORPORATE Exchange servers? What was the question again? Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried about

RE: [ActiveDir] What do you do when ooops won't work?

2006-03-09 Thread deji
if the items were marked as deleted. I'm not sure what those pocket PC's do when they sync their nothingness, but they definitely don't mark the items as deleted. I've run into the same situation with users and PocketPC's and haven't found an acceptable solution..

RE: [ActiveDir] What do you do when ooops won't work?

2006-03-09 Thread deji
What's your favorite kingdom? I'll get myself a crown, then maybe (just maybe) the chances of a restore happening will be greatly enhanced :) Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize tha

RE: [ActiveDir] What do you do when ooops won't work?

2006-03-09 Thread deji
Right. I was . errr meaning to do that :) Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried about Yesterday? -anon __

RE: [ActiveDir] What do you do when ooops won't work?

2006-03-09 Thread deji
Wouldn't that be just wonderful? Only if the admin were human :) Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried about Yesterday? -anon ___

[ActiveDir] What do you do when ooops won't work?

2006-03-09 Thread deji
I just f-fingered a synch between my PDA and Outlook. Short story, all my contacts (painfully built over several years) just took a road-trip to neverland on a one-way ticket. Local backup? I was meaning to do it tomorrow. Really ;) Server backup restore? Yeah. I have a greater chance of be

RE: [ActiveDir] ADMT v3 implementation questions

2006-03-08 Thread deji
For #1, you are apparently not migrating with SIDHistory. If you have a problem with SIDHistory and don't want to use it, then you will have to wait until you have migrated everything and repermissioned the resources before you can access resources. For #2, try http://www.akomolafe.com/TechStuff

RE: [ActiveDir] Bulk Import

2006-03-08 Thread deji
What is your input? Where are you getting the input from, and what format is it in? Al mentioned some script laying around. I may have one stuck in one of my couches here :) Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akom

RE: [ActiveDir] Cleaning Up AD

2006-03-08 Thread deji
> What resources (utils, whitepapers etc) have people been using to clean up an AD infrastructure? It depends. If I am in a hurry, I just put it in my trunk and go to the nearest drive-through car wash. If I have time on my hand, I drive it to the friendly neighborhood Laundromat. Either way, it co

RE: [ActiveDir] Automatically generated replication links

2006-03-08 Thread deji
Russ, you are making a big deal out of nothing. Stop worrying yourself sick. IF KCC built a CO for this DC, KCC thinks that's the most optimal CO possible at that point. It is not mandatory that the CO should be reciprocal. If you are not please with what KCC did, then delete its work and create

RE: [ActiveDir] There must be an easier way...

2006-03-07 Thread deji
You will then need to look in DNS and delete every reference to any of the DCs in any zone or sub-zone. You will then go into ADUC, Domain Controller OU, and manually delete the DCs from there. Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Directory Services www.readymaids.com -

RE: [ActiveDir] Domain rename and third party tool

2006-03-06 Thread deji
Honestly? All the products I know of require some investments in time, planning, tests and efforts to get used to them. They are not really like "deploy-and-go" type of solutions. I mentioned that because you appear to be in a dire emergency, and it is usually emergencies like this that tend to c

RE: [ActiveDir] There must be an easier way...

2006-03-06 Thread deji
The OP implied ownership of the Forest by stating: >>> we had set up as a site within our domain with its own pair of DC's has decided to break off from us So, apparently, they only need metadata, DNS and connection objects cleanup as far as mop-up is concerned. Sincerely, Dèjì Akómöláfé,

RE: [ActiveDir] OT : Query DNS using wildcards?

2006-03-06 Thread deji
>>>Extracting the zones to a .txt file which a script can loop through searching for certain strings. Ideal solution would be to look for * records and delete them as they are being found. But as already indicated by other people, this is not available.. Why not? If it's a standard zone, you

RE: [ActiveDir] Can I upgrade/Install IIS6 on windows 2000 advace server.

2006-03-06 Thread deji
No. Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried about Yesterday? -anon From: [EMAIL PROTECTED] on behalf of M

RE: [ActiveDir] AD Lag Sites

2006-03-06 Thread deji
He does NOT "have to save the company money", he says. That's MY money you are talking about there, bucko! :) Seriously, Todd, you do have to understand that a vast majority of IT shops don't have budget for their IT folks to be as productive as they desire to be. This is why people tend to be

RE: [ActiveDir] How Secure is a Domain Controller?

2006-03-04 Thread deji
See: http://www.cisecurity.org/tools2/win2000/CIS_Win2003_DC_Benchmark_v1.2.pdf Happy reading. Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried abou

RE: [ActiveDir] Disabled Accounts/Mail accepted

2006-03-04 Thread deji
The problem with using NoMAS is that you are always chasing your tails. You have to remember to run it often, and in the meantime, your exchange server is being crippled by eventid 9548 . The "fix" for this "issue" is more process than technical. You need to work out a termination process with yo

RE: [ActiveDir] (OT) How to find a computer on same segment but different ip subnet

2006-03-02 Thread deji
.activedir.org Subject: RE: [ActiveDir] (OT) How to find a computer on same segment but different ip subnet Hey Deji... Old computer is alive. It is NT4. The new computer has been installed with an image of XP, and it is replacing the old computer. we'll bring the new one up, grab data and c

RE: [ActiveDir] Password Migration Problem

2006-03-02 Thread deji
This was asked and answered in the past month. Check the archives for "cusrmgr" Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried about Yesterday? -an

RE: [ActiveDir] (OT) How to find a computer on same segment but different ip subnet

2006-03-02 Thread deji
I know that it all made sense to you when you wrote all that. However, I am very slow and still on my first cup of coffee. So, in slooow motion: Is the "old computer" dead or alive? If dead, is it dead as in just turned off, or dead as in re-imaged? why is it important that you know its IP ad

RE: [ActiveDir] Auto move computer

2006-02-27 Thread deji
Pre-create is the key word. I already told you one way to achieve this, and Phil is telling you another. So, now you have more than one way to skin the cat - I am against abusive cat-skinning, mind you. Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Directory Services www.readyma

RE: [ActiveDir] Auto move computer

2006-02-27 Thread deji
You are misaligning priorities here. Start putting something in place to create computers in the correct OU the first time. For all things already created up to this time, try moving them all to the correct OU in one exercise. Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Direct

RE: [ActiveDir] External vs Forest Trust

2006-02-27 Thread deji
Answer: In the first case, ONLY those 2 domains will trust each other. In the second case, EVERY DOMAIN in BOTH FORESTS will trust one another Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize th

RE: [ActiveDir] Auto move computer

2006-02-24 Thread deji
What would? You mean you only plan to move servers and not workstations? Or do you mean that the script would only move servers and not workstation? If you are talking about the script, I don't see why it would not move anything you tell it to move. This here http://www.akomolafe.com/Portals/1/Mo

RE: [ActiveDir] Auto move computer

2006-02-24 Thread deji
This is where a provisioning system is much needed. Put a few lines of vbscript together and use it to "pre-create" the computer account BEFORE you manually join it to the domain. Put a logic in the vbscript that creates the computer account in the desired OU. When that computer is then manually jo

RE: [ActiveDir] MAC Address

2006-02-23 Thread deji
Something like this: wmic NICCONFIG get MACAddress Or a vbscript like this: strComputer = "." Set objWMIService = GetObject("winmgmts:" & "!\\" & strComputer & "\root\cimv2") If Err.number <> 0 Then Else Set colAdapters = objWMIService.ExecQuery _ ("Select * from Win32_NetworkAdapterConfigu

RE: [ActiveDir] IIS 6.0 LDAP Auth

2006-02-23 Thread deji
Ah! That was over my head, sorry. Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried about Yesterday? -anon From: [E

RE: [ActiveDir] Windows 2000 profile migration

2006-02-23 Thread deji
It's called User State Migration Tool (USMT) http://www.microsoft.com/downloads/details.aspx?FamilyID=4af2d2c9-f16c-4c52-a 203-8daf944dd555&DisplayLang=en Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you

RE: [ActiveDir] IIS 6.0 LDAP Auth

2006-02-23 Thread deji
What exactly does that mean? Are you looking for info on FTP auth using AD? Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried about Yesterday? -anon

RE: [ActiveDir] Service Pack Level

2006-02-22 Thread deji
For /F %i in ('dsquery server -o rdn') DO srvinfo \\%i|find /i "Build:" or For /F %i in ('dsquery server -o rdn') DO srvinfo \\%i|find /i "service pack:" Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now

RE: [ActiveDir] SPN issue

2006-02-22 Thread deji
Somewhere on this thread, you indicated that you were watching the packets as you attempted the "net use". If you were watching closely, you will also notice that the transaction does not just include your user credentials, it also include your machine name. Because that machine name existed in the

RE: [ActiveDir] SPN issue

2006-02-22 Thread deji
>>>What if I delete the computer account in the source Forest? 10 cents says there would be no errors then. Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were

RE: [ActiveDir] SPN issue

2006-02-22 Thread deji
Quick question: are the source and target accounts' passwords the same in all cases? If so, try setting different passwords and do your tests again. Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now real

RE: [ActiveDir] SPN issue

2006-02-22 Thread deji
>>> If i'm on a migrated box in the target and the source "copy" of that box had its password expire in the source Forest, would that affect me? It will affect you when you try to connect to the source forest. >>>Then I wouldn't be able to log in at all. Why not? You are logging into the target

RE: [ActiveDir] SPN issue

2006-02-22 Thread deji
Let me see if I understand this: you've migrated the users and computers from source to target. Now you are trying to log into source from an already migrated computer. Right? Could your problem be because the computer's password has expired on the source domain? I'm assuming that you did an inter-

RE: [ActiveDir] SPN issue

2006-02-21 Thread deji
Something is dorked over there. I know you said nothing has changed. It appears to me that netdom is your next option. If "netdom reset" does not work (after a reboot) or "netdom verify" keels over, then I'm afraid you are looking at a painful "netdom join" exercise. Sincerely, Dèjì Akómöláf

RE: [ActiveDir] SPN issue

2006-02-21 Thread deji
In your case, it'll be: setspn /A host/OP5080570765 OP5080570765 setspn /A host/OP5080570765.corp.oproot.opco.com OP5080570765 HTH Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is

RE: [ActiveDir] SPN issue

2006-02-21 Thread deji
Try the /A option. btw, try munging your resource/domain names when you post to a forum such as this. Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worri

RE: [ActiveDir] SPN issue

2006-02-21 Thread deji
Try manually resetting or adding the SPN for one of the computers and see if that takes care of your problem. If it does, the I'd do the same for the rest or just disjoin and rejoin them to the domain if there are not too many of them. you can use setspn to do this. Like so: setspn /R the_comp

RE: [ActiveDir] (off topi) Sound problem

2006-02-20 Thread deji
Before triggering SounDProp, I think we first need to establish the Forest Functional Level and how many Sites and GCs are in this environment. It appears that that attrib is multivalue and has the potential to engender excessive replication that may fire KCC and saturate the WAN link in the proces

RE: [ActiveDir] Computer Policies based on User Logon?

2006-02-10 Thread deji
define your policies in the "User Configuration" and deny this user access to the policies. Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried about Yes

RE: [ActiveDir] Hiding in the Directory

2006-02-10 Thread deji
w realize that Today is the Tomorrow you were worried about Yesterday? -anon From: [EMAIL PROTECTED] on behalf of Noah Eiger Sent: Fri 2/10/2006 12:26 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir

RE: [ActiveDir] OT: DR strategy question

2006-02-10 Thread deji
I read "pils", as in pilsner :) Pills? Been sniffing more than traffic packets, eh? :-D Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried about Yesterd

RE: [ActiveDir] Hiding in the Directory

2006-02-10 Thread deji
ay? -anon From: [EMAIL PROTECTED] on behalf of Noah Eiger Sent: Fri 2/10/2006 12:26 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] Hiding in the Directory Deji- I have actually implemented the dual-login scenario with these folks. In general, I am trying to keep th

RE: [ActiveDir] Hiding in the Directory

2006-02-10 Thread deji
>>>Its very easy to ask an admin "can you log into this ... and see whats going on?" Funny :) This is why I always recommend that admins must have 2 accounts - one plain-vanilla, regular account that will be used for daily tasks and one with admin privileges that they only use for admin tasks. D

RE: [ActiveDir] Lost perfmon counters(OT)

2006-02-10 Thread deji
I just pulled the response from my "lessons learned" archives. Someone on this list with more current experience and knowledge will come along and straighten out, I'm sure. Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akom

RE: [ActiveDir] Lost perfmon counters(OT)

2006-02-10 Thread deji
Had a similar situation way back when. A repair was the only way I was able to get them back. Things may have changed since then :) Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is

RE: [ActiveDir] SSL to ADAM with a vanity URL

2006-02-10 Thread deji
m: [EMAIL PROTECTED] on behalf of Deji Akomolafe Sent: Fri 2/10/2006 10:24 AM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] SSL to ADAM with a vanity URL It is the SUBJECT_ALT_NAME The SUBJECT name will be the "vanity url" Mr. Oteece mentioned, and the SUBJECT_ALT_NAME will

RE: [ActiveDir] SSL to ADAM with a vanity URL

2006-02-10 Thread deji
It is the SUBJECT_ALT_NAME The SUBJECT name will be the "vanity url" Mr. Oteece mentioned, and the SUBJECT_ALT_NAME will be the FQDN of the 2 servers involved. I just did a quick "SUBJECT_ALT_NAME site:microsoft.com" google query and came up empty. That's surprising because I think that this is

RE: [ActiveDir] Hiding in the Directory

2006-02-10 Thread deji
Service accounts. Especially ones with domain-level scope. Resetting the passwords for all known service accounts (including the administrators' account) should be your first course of action - just slightly ahead of the actual group purge. Scripts. Examine all scripts in use, especially login sc

RE: [ActiveDir] Nesting groups

2006-02-06 Thread deji
Joe, What would be the point of B? Deji -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of joe Sent: Monday, February 06, 2006 5:35 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] Nesting groups No limits that I am aware of, I swear I have

RE: [ActiveDir] Script to determine a machine's site

2006-02-06 Thread deji
TECTED] Sent: Monday, February 06, 2006 9:48 AM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] Script to determine a machine's site Thanks for the feedback, Deji, Guido, joe et al. The one piece of code I'm missing now is one that can determine a machine's IP address. Any sugg

RE: [ActiveDir] Script to determine a machine's site

2006-02-03 Thread deji
I don't have the script I wrote for this handy, but the logic I used is this: Get host's IP Address Split it into whatever subnet mask use in your subnet/site configurations. Do a CaseCase Else looking for a match. If you get a match, that computer is in that site. e.g. IP is 192.168.100.2

RE: [ActiveDir] Problem in assigning permissions to the user in parent domain over the shared folder in child domain

2006-02-03 Thread deji
Dean, I hope you don't mind me asking you this. If you do, please forgive me. I'll ask anyway :-p Considering that I work for a Microsoft Gold Partner (Unisys), what do I need to do to get into one of the "internal" trainings you do for MS folks? I know that MS was thinking about introducing an

RE: [ActiveDir] OT: Change Tracking Database

2006-01-30 Thread deji
In my previous life, I cooked something based on Liberum (http://www.liberum.org/) and adapted it to do something similar to what you are describing in your second email. It does not "track" or "log". You can use it to "track" or keep a "log". Subtle diff, I know. Sincerely, Dèjì Akómöláfé, M

RE: [ActiveDir] OT: WMI to retrieve DHCP leases

2006-01-26 Thread deji
Title: RE: [ActiveDir] OT: WMI to retrieve DHCP leases You have a point. Except that if your DNS scavenging and lease duration are not in synch, then you get a highly skewed report. I understand your point about non-domain-members.   Deji   From: [EMAIL PROTECTED] [mailto

RE: [ActiveDir] OT: WMI to retrieve DHCP leases

2006-01-26 Thread deji
DHCP is NOT the authoritative source for "how many computers are out there" If you could, grab Joe's oldcomp tool and just run it against your domain. You should get something close to accurate from there. Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Directory Services www.re

RE: [ActiveDir] OT - Clear IE Cache on Remote machines

2006-01-26 Thread deji
Why not just take the option to not keep the cache at all? Just make sure that the cache gets deleted on system rebooted. Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomor

RE: [ActiveDir] OT - Clear IE Cache on Remote machines

2006-01-26 Thread deji
In a batch file, looping through an input file containing all the computers to work on (\\computername, one per line): FOR /F %%i IN (computer-list.txt) DO echo Working on %%i...& set v1=%%i& call :DoIt goto :EOF :Doit reg add "%v1%\HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settin

RE: [ActiveDir] OT: WMI to retrieve DHCP leases

2006-01-25 Thread deji
To the OP: Would you be happy with pulling the info on the client side? You could use Win32_NetworkAdapterConfiguration and retrieve the DHCPLeaseObtained or DHCPLeaseExpire values. Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Directory Services www.readymaids.com - we know

RE: [ActiveDir] WebAdmin Tool Setup

2006-01-15 Thread deji
Let's see main.asp Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried about Yesterday? -anon From: [EMAIL PROTECTED]

RE: [ActiveDir] LDAPS SRV Records?

2006-01-15 Thread deji
>>> If you "look" at netlogon.dll with hahaha! You make me laugh :) FYI, when *I* can't sleep, I turn to a warm body. OKOK...TMI. I was just trying to say I don't go looking inside any f-ing dll just cause I'm bored or can't sleep :) Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT M

RE: [ActiveDir] LDAPS SRV Records?

2006-01-15 Thread deji
So, which API are you relying on? Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried about Yesterday? -anon From: [E

RE: [ActiveDir] LDAPS SRV Records?

2006-01-13 Thread deji
Jorge, I think he is looking to write his own wrapper. So, he is looking for the bits where the functions are exposed. Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorr

RE: [ActiveDir] Congrat Jorge !!!!!

2006-01-13 Thread deji
I don't think Gil is allowed to say :) NDA, you know ;) Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried about Yesterday? -anon

RE: [ActiveDir] OT: DEC 2006 (way OT ...)

2006-01-13 Thread deji
Not the same thing. Not elegant, given its many problems on DCs. And not local like VMS will give you. Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worrie

RE: [ActiveDir] LDAPS SRV Records?

2006-01-13 Thread deji
I think the functions are exposed in WinAPI and/or DNSAPI - I am NOT a programmer :) There are very likely where you'd start: http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dns/dns/dns_ srv_data.asp http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dns/dns/dns_

RE: [ActiveDir] OT: Prob not relevant here ...but -implement system policies in non AD

2006-01-11 Thread deji
Ahem . I think you forgot Windows. :) Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried about Yesterday? -anon

RE: [ActiveDir] NT and AD Permissions

2006-01-11 Thread deji
avior Deji!! i didn't knew that cusrmgr.exe can be used for adding user...i knew it as only used for password reset... But one last question...does the cusrmgr need to be local to all servers or can i call it from my laptop?? Regards, Chandra -Original Message- Fr

RE: [ActiveDir] NT and AD Permissions

2006-01-11 Thread deji
Me, I just add the appropriate group/user (from the target) to the local administrators' group of every computer (in the source) by script. on the PDC: net view /Domain:NT4Domain >c:\computer-list.txt then, in a batch file: FOR /F %%i IN (computer-list.txt) DO echo Working on %%i...& set v1=%%

RE: [ActiveDir] OT: Scripting Issue.

2006-01-10 Thread deji
You are welcome, Erik :) Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCT Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried about Yesterday? -anon From: [EMAIL PROT

<    1   2   3   4   5   6   7   8   9   10   >