Welcome to Dirteam.com/ActiveDir.org Blogs Sign in | Join | Help

November 2005 - Posts

Imagine this... You are sick at home (because of a heavy cold and almost fever)... It's friday morning...sleeping like a baby... suddendly your girlfriend wakes you and you THINK as shitty as you feel that moment "WTF &*^&*%&*%&* are you Read More...
In this case you need to change the IP of a DC and move it to another AD site --> Assuming it only has the DC/GC role.... <-- (steps with a @ are not mandatory but is just a safe measure as I have seen some occasions where those steps were needed...) Read More...
If account management is enabled and set for success, when changing a password you can look for event IDs 627, 628 or 642. The DC that registers on or more of these event IDs for a certain account is the DC where the change occured. Event ID 627 with Read More...
Tomek has written some interesting information about confidential attributes... Check it out at: http://blogs.dirteam.com/blogs/tomek/archive/2005/11/21/confidential_bit.aspx Cheers Jorge Read More...
For distributing scopes among multiple DHCP servers two well known rules are available. Google for (only the text before the =): 50/50 dhcp = (central setup) and 80/20 dhcp = (local and remote setup) You should make sure only one DHCP servers leases a Read More...
DCs protect themselves against Lingering Objects in 2 ways: (1) By implementing strict replication (2) By isolating DCs that have NOT replicated with other DCs for more than the tombstone lifetime AD (1) When an object is created on some DC that object Read More...
Check out LimitLogon from MS. It only works in a W2K3 AD as it needs a separate app partition for its data. It also extends the schema and as the Resource Kit tools it is not supported by MS For more info see: http://www.thincomputing.net/newsitem296.html Read More...
With the GPMC you can backup and restore GPOs. Don't forget if you restore a GPO it still needs to get replicated to the other DCs. To reset the Default Domain GPO and/or the Default Domain Controllers GPO tooling is available for windows 2000 and windows Read More...
Go to www.joeware.net and download ADFIND (=free) To find users within a certain OU that have dial-in = allowed run: AdFind.exe -b "OU=<yourOU>,OU=<yourOU>,DC=<domain>,DC=<tld>" -f "(&(objectCategory=person)(objectClass=user)(msNPAllowDialin=TRUE))" Read More...
For starters, a domain rename is only possible when your forest is at Forest Functional Level Windows Server 2003 and if it contains Exchange, only Exchange 2003 server WITH SP1 are supported! All other situations do not allow or support domain rename! Read More...
As many of you already have done it, or are doing it right now, or better yet are still thinking about it! What? Well, migrating to Windows Server 2003 with AD. When planning migration, on of the important is topics is thinking about the test environment Read More...
The time service on the forest root domain PDC emulator FSMO holder can be configured to point to an external NTP time source or it can be configured to use its own internal hardware clock. (1) configuring the forest root domain PDC FSMO to use an another Read More...
When using the Associated External Account (AEA) in an account forest and resource forest scenario the account in the resource forest that is mailbox enabled is AD disabled and the account in the account forest is assigned the AEA right on the mailbox. Read More...
When you are part of an AD forest and being in one of the child domains, it may also be important you keep track of forest wide update made by the forest root domain owners/admins. For this to work those owners/admins should notify you when changes occur Read More...
The following articles will helps you in your migration from W2K/E2K to W2K3 (R2)/E2K3 and especially when doing an in-place upgrade of the domain: * MS-KBQ314649_W2K3 ADPREP Command Causes Mangled Attributes in W2K Forests That Contain E2K Servers ( Read More...
As you may know with W2K it was not possible to rename a DC, besides demoting the DC, renaming the server and promoting it back to a DC. With W2K3 it is possible to rename a DC and two different options exist: (1) In all DFLs: you can use the Control Read More...
When thinking about a testlab using a virtual environment you might be bitten by 2 different issues: (1) USN rollbacks (2) Time between replication cycle before the snapshot and the replication cycle after starting the VMs again (1) USN rollbacks.... Read More...
With R2 Microsoft introduces, amongst others, the File Server Resource Manager (FSRM). With that MMC you define, configure and manage quotas and file screens. On a R2 server with the FSRM installed you can configure the following: * FSRM Global Options Read More...
I have seen several questions regarding setting the inheritance flag on AD objects. Possible reasons were: * Inheritance was disabled on sub OUs for some reason * Inheritance was disabled on CUSTOM users or groups that previously were members of default Read More...
The Microsoft Product Licensing Advisor (MPLA) is an easy-to-use online tool that helps you find and select Microsoft products, find the right Volume Licensing program, and determine estimated retail pricing (ERP) based on your software needs. Read more Read More...
Most servers bought at this moment have two NICs. With that you have three possibilities of configuration and use: (1) Configure the NICs on the server as a "load balanced" team This is used to distribute network traffic accross NICs to acchieve maximum Read More...
Have you ever been in the situation where you had to make a choice which Virtual Software to use for your own Infrastructure? I can imagine yes, because at this moment you can choose between a Microsoft solution and an EMC VMware solution. One of the Read More...
Hello Everyone! Well... as you can see I have started my own blog and this is the first post on it. Interested how this started? (Actually.. the first post was a TEST message to see how it looks, but Carlos wasn't happy with that...[<:o)]) After "meeting" Read More...