Francois Lafont0/11 28 Apr 2010
Hi everybody, If I have a little local network with just one "old" DC (DC = domain controller) "Windows 2003 server" with theses features : - DNS name of the domain : yourcenar.local - DNS name of the DC : srv.yourcenar.local - NetBios name of the domain : YOURCENAR - IP : 172.20.0.2 Let's suppose I want to install "new" DC in a new computer with exactly the same features (the
Meinolf@UNKNOWN...0/7 28 Apr 2010
Hi all, this is my first post so hopefully someone can help me. I'm having some problems with my users complaining of Windows taking a very long time to load. I experience the same issues on my Windows 7 laptop, we have various users using Win 7 and XP, i've noticed the same issue on some of the XP machines. I enable the gpo debut on my windows 7 and there is a one minute + delay at one
kj [SBS MVP]0/2 28 Apr 2010
Can Multiple Local Group Policy Objects be applied to a computer which is a member of the domain? or is it applicable on to computers in a workgroup/stand alone?? If they can be applied to computers in a domain, what will be the processing order? Domain Policy and then MLGPO??
ITIntern0/1 28 Apr 2010
Bruce, I have followed your steps but unfortunately it did not work for me. I am trying to accomplish the same problem. I want to create users in Active Directory and when they sign on their local computers, I want them to be automatically Powers Users rather than Users. I created a group named Test added the user in there, went to Restricted Group added the group Test then wrote Power Users
Meinolf@UNKNOWN...0/5 28 Apr 2010
Here is our environment: 5 Windows 2003 R2 SP2 Domain Controllers (4 of which also do File/Print/DNS and 1 is running DHCP) spread across multiple VLANs (multiple NICs mapped to different VLANs in each)
Paul Bergson [M...0/3 28 Apr 2010
Hi, I'm wondering if there is a way to use GP to apply a setting depending on whether a user is logged on at the office or out of office. The setting I had in mind is enable/disable using a proxy found in Internet Options. Enable it if the user is in the office and disable it when out of the office. Is there a way to do this? Any ideas would be great. Many thanks. Mehds
Paul Bergson [M...0/3 28 Apr 2010
Hello, are there any known issues renaming a Windows Server 2008 R2? Thank you Micha
Lee Flight0/8 28 Apr 2010
I have searched around and I cannot find anything that helps me. I am trying to update the schema on ADAM but i continue to receive this error, which I have discovered is pretty common: Add error on line 1049: No Such Attribute The server side error is: 0x57 The parameter is incorrect. The extended server error is: 00000057: LdapErr: DSID-0C090B3D, comment: Error in attribute conversion
Bart Timmermans0/1 27 Apr 2010
Hi all, I am currently responsible for the migration of AD user accounts to a new domain. I have installed ADMT on a server. I have Password Export Server installed on a domain controller within the source domain. I have tested the migration using ADMT with both the password and the SID (SID filtering is off). The test worked like a charm. Currently I am selecting all users within
Hadi El Arawi0/5 27 Apr 2010
Windows 2003 Server, Active Directory. How to find out who and when logon/logout from AD? How to force disconnect a user from AD?
it.toonz0/1 27 Apr 2010
summerized from different sources..*How to enable SNMP service in a Windows XP workstation in a Windows 2003 Domain.* -Basically what is being done is, SNMP is being enabled using SYSOCMGR.EXE already available in Windows XP, through startup script using Group Policy.- Create a txt file with the following [NETOPTIONALCOMPONENTS] SNMP=1 give an obvious name. eg. snmpinstall.txt
Chris Dent0/6 27 Apr 2010
Hi guys, I'm trying to open some 5000 computer objects in a loop. Anyway, at some point (say on 1500-ish iteration of the loop) ADsOpenObject() returns 0x8007203A (The server is not operational). But when I put a delay before each call (say, Sleep(20)), nothing similar happens. Any ideas why frequent calls to ADsOpenObject() may result in 0x8007203A? Martin
ZIDAC0/8 26 Apr 2010
Hi, I have a 2003 domain with DFS root The XP client access with no problem but the Windows 7 clients no access Can anybody help me ? Thanks and excuse my bad Inglish ZIDAC
Meinolf@UNKNOWN...0/2 25 Apr 2010
Hello. I want to configure a NLB (Network Load Balancing) on Windows 2003 but I want to do so as per Microsoft Best Practices which indicate that the best solution should be multiple NICs (2). http://technet.microsoft.com/en-us/library/cc740265%28WS.10%29.aspx The problem is that I couldn't find no even one example of this configuration in the web, the closest are these two articles :
Meinolf@UNKNOWN...0/4 24 Apr 2010
I'm having trouble with one domain controller that has all of the FSMO roles (I have 6 Domain controllers in total running server 2003) I updated my schema to version 47 (Windows server 2008 RC2) and would like to add a new physical server with W2K8 R2 on it and transfer all of the FSMO roles on it. I don't want to upgrade all DC's yet to 2008 R2 yet, so the domain functional level
Meinolf@UNKNOWN...0/7 24 Apr 2010
Can someone please state what FSMO role is involved in AD trusts? The reason I ask this question, is that I moved the 3 domain FSMO roles off the forest root DC to another DC and then took down the forest root DC for hardware maintenance. During this period, users were unable to log onto apps across the trust, but when the forest root DC came back online, the users could then log
Meinolf@UNKNOWN...0/4 24 Apr 2010
It has been a while. How do I limit user access (login) to only one client machine in AD in Windows 2003 server? Thanks,
Meinolf@UNKNOWN...0/4 24 Apr 2010
We are planning to upgrade our AD schema to the 2008 R2 version (we are currently on the 2008 version), all our DC's are 2003 and we are at 2003 domain and forest functional level. Will this have any problems with exchange 2003 or our last remaining NT server (once the NT server has gone we plan to upgrade all our DC's from 2003 to 2008).
Meinolf@UNKNOWN...0/3 24 Apr 2010
Hi, i buy 200 PC with Windows 7 for my company In the past i use Ghost whit my XP clients. How can i clon Windows 7 for deployement my 200 PC ? Thanks
tdors0/5 23 Apr 2010
Hi everyone, here is the scenario that I am having problems with: There are two seperate forests with domains, coffee (internal) and cola (external). I can set cola up with a one way outgoing trust so that the coffee people can access all the cola files that I grant them rights to (which is perfect) and cola doesn't seem to be able to get out into coffee (so that seems to be
Phillip Windell0/11 23 Apr 2010
Hi, A client called me to restore access to their Windows 2003 Server acting as a DC whose Administrators' passwords have been lost. Nobody can now log into the server. I understand that resetting the local Administrator password on non-Active Directory Win 2003 machines is pretty easy. There are lots of utilities that you can download and run from a bootable CD and clear out the
DaveMo0/3 23 Apr 2010
i've win2k3 domain and i need to create a web page for self password reset..Are there any options available to do so.Or if there are any low cost solutions available. Can anyone help
drm0/3 23 Apr 2010
Is there any way to change ADAM so that the Locality-Name, Postal- Code, State-Or-Province-Name and Street-Address attributes are multi- valued on a new build? Our CTO wants us to create a customer ODS using ADAM and some of our customers have more than one address. He wants us to use x.500 attributes as much as possible. Based on what I have seen regarding this standard, these are the
Lee Flight0/2 23 Apr 2010
On Mar 19,
Striker77s0/1 22 Apr 2010
I'm having some baffling behavior on a computer and I need some help. I have a new computer that I setup that is acting strange. Every time I try write files to a network drive while logged into my domain it begins to copy and then fails. If I copy a group of small files several files will successfully write and then it fails at a random file. If I copy a large file it will begin and
Cosmo0/4 22 Apr 2010
Can someone please direct me to a definitive URL (preferably MS) that states what rights are required to delegate AD control to a Windows group to be able to move computer objects between OU's. I’ve found a few myself, but they all mention different rights. Cheers, Cosmo
Bob Dorn0/8 22 Apr 2010
hello everyone, i have a doamin controller with windows 2003 standard edition SP1, I want manage the access to shares folders with membership to group of domain controller, but I don't rebember the syntax of the command. Can yuo help please? thanks
Bob Dorn0/3 22 Apr 2010
member server 2003 sp2, was in old 2000 domain. removed from that domain into a workgroup. changed dns to reflect new domain. now trying to add to 2008 domain and I get a message of "The service cannot accept control messages at this time". Of course it doesnt join the domain either. I had another member server that i pulled out of the same domain and added it with no issue. So
hibenias600/1 22 Apr 2010
I will show you how to successfully reset to Windows server 2008. The solution is a two stage process. The first stage is preparation and requires the use of PING (Partimage is not ghost) which is a linux environment that can run off of a disc. You need to download the PING image and burn it to a disc before continuing. For the second stage, we need to wait until Windows has booted and
Ace Fekay [MVP ...0/3 21 Apr 2010
Hi, I have IIS7 setup with a directory secured using BASIC Authentication only. The directory is on a network share but only two Active Directory usernames have NTFS permissions to this folder. One username is for the IIS entry to have permission to the share. The second username is to be used externally/publically when visiting the website. It works great. The username can login
Paul Bergson [M...0/6 21 Apr 2010
Hi, we are planning on upgrading our Win Server 2003 primary DC to Windows Server 2008. I have a few questions that I need to clear up and hope anyone out there can shed some light on them. -Firstly, will upgrading the PDC to Win2008 mean that secondary DC's need to be upgraded to Win Server 2008 also? -If the answer to the above is 'no', are there any disadvantages to not
Ace Fekay [MVP ...0/16 20 Apr 2010
Does anyone know what to do or a link to help me troubleshoot this problem? C:\Documents and Settings\drservice>repadmin /replicate DC2.DNS DC1.DNS DC=DRS44,DC=drs Sync from DRS-44-9A.drs44.drs to DRS-44-9B.drs44.drs completed successfully. C:\Documents and Settings\drservice>repadmin /replicate DC1.DNS DC2.DNS DC=DRS44,DC=drs DsReplicaSync() failed with status 1127 (0x467):
Ace Fekay [MVP ...0/7 20 Apr 2010
I recently had to remove a child domain using ntdsutil and metadata cleanup since the last domain controller in the domain crashed. That process went smooth Every reference that I can think of (AD users/computers, sites/services, dns) of the old domain and domain controller have been removed. However... when I join a new computer to the parent domain the old child domain that I
Ace Fekay [MVP ...0/6 20 Apr 2010
Hi all, We have windows 2003 SP2 32bit Domain controller with windows 2003 functional level. I need to run exchange 2010 prep on the 32 bit schema master, can I run it since the exchange 2010 i only have 64bit? Is there a way to get around? thank you.
Ace Fekay [MVP ...0/4 20 Apr 2010
We are working on deploying ADFS to provide single sign-on functionality for externally hosted applications. This works fine for multi-tiered environments in which the IIS web server is not a domain controller. However, we have one (test) environment in which the IIS web server is also a domain controller. In that scenario, our .NET application generates the following error when using
Laljeev M0/13 20 Apr 2010
Hi For past 2-3 months we are facing issues with editing GPOs applied at domain level including Default Domain Policy (at the same time Default Domain Controller Policy is fine). Finally we found there are many permanent sessions to Gpttmpl.ini from Windows Vista machines. Most of the machines having SP1 and some are SP2. If we stopr these sessions then we can able to edit sall
Pete Jones0/1 20 Apr 2010
Hopefully a fairly simple one this. I am using a script to automate disabling old unused accounts. @echo off if {%1}=={} @echo Syntax: disableDNs FileName&goto :EOF if not exist %1 @echo Syntax: disableDNs %1 not found.&goto :EOF setlocal ENABLEDELAYEDEXPANSION set file=%1 @echo. for /f "Tokens=*" %%u in ('type %file%') do ( set user=%%u rem set user="!user:"=!" @echo
Andy@UNKNOWN, U...0/1 19 Apr 2010
Hello. You may find this useful. I had a very similar issue and this is how I fixed it. http://www.andymcdonald.co.uk/2010/04/19/dcdiag-fsmocheck-error-1355/ Zalew wrote: NetDiag Default Gateway Error -->DcDiag Advertising Error 22-Nov-08 Hi Guys, I'm having problems with time sync in my AD. Server which should be time server for my domain doesn't advertise himself. After
Ace Fekay [MVP ...0/3 19 Apr 2010
Hi Gereth, Did you get have any solution for same , we are also facing the same challenge... REgards Shailesh garet wrote: Password Policy - minimum age 18-Jan-08 Hi Folks, I'd like clarification on an issue relating to the minimum password age. When the minimum password change period is set to ,say, seven days, does this apply when an administrator has changed a users
Paul Bergson [M...0/6 19 Apr 2010
Hi We have a lab environment that we use to test 2008 server.We had an 2003 native mode forest.There is a single domain.We have 3 sites each containing DCs on them.On the site that represents a branch office we installed an RODC. We run adprep /rodcprep and complete the installation using DCPROMO.The nearest site to the site hosting RODC only has an 2003 DC and there is also a 2008
Meinolf@UNKNOWN...0/2 18 Apr 2010
I have got following error a few times when trying to connect to w2k8 servers. the security database on the server does not have a computer for this workstation trust relationship If I wait for 10-15 minutes then I can logon no problem. I happened to several w2k8 servers. I think I got such error only after added two w2k8 R2 DCs into the existing domain. I still have my w2k3 DCs.
Hank Arnold0/9 17 Apr 2010
Hi all, We are going to introduce the new windows 2008 R2 DC to our windows 2003 32bit DCs with windows 2003 functional level. I need to run forestprep and domainprep in the windows 2003 schema master. Can I run the R2 64bit forestprep and domainprep on the windows 2003 32bit domain controllers? Thank you!
SHADYNET0/1 16 Apr 2010
How Do I Install Printers To Users By Userid I.e User Joy Needs For Printers Installed And Needs 1 To Be His Default Printer -- SHADYNET ------------------------------------------------------------------------ SHADYNET's Profile: http://forums.techarena.in/members/209335.htm View this thread: http://forums.techarena.in/active-directory/713672.htm http://forums.techarena.
Ace Fekay [MVP-...0/13 16 Apr 2010
We have a single 2003 forest/domain env't. We'll have 2 sites (currently only 1). The HQ site has a few DCs (also a GC) and an Exchange mail server. The remote site will have a dedicated DC for the users there to authenticate against (configured in ADSS for their subnet). Does this DC at this remote site need to be a GC as well to handle user authentication in case they lose a
Ace Fekay [MVP-...0/5 16 Apr 2010
We are finding some duplicate computer objects in AD. Some have $Duplicate-... in the pre-Windows 2000 attirbute. Can someone point me to material that explains why/how these are created and if we can get rid of them? I have tried searches on the subject, but search engines don't seem to like that search phrase. Thanks, Dan
Bob Smith0/6 15 Apr 2010
Hello. I have a server running Windows Server 2008 and need to have a security policy to ask for the password change users every 3 months, how I can do? and How does affect the Administrator user? Thank you.
Baris DOGAN0/4 15 Apr 2010
Hello, One of my DC was disconnected from the network for quite a long time and cannot be synchronized with AD anymore. I have been trying to apply the http://support.microsoft.com/kb/325850/en-us procedure to reset the machine account password. After launching the command "netdom resetpwd /S: ....." I've got the following error message : "The machine account password for the local
trigont@gmail.c...0/1 15 Apr 2010
Let me preface this by saying - I am a SQL Server DBA, so AD and dquery is way out of my league. I am performing a clean up of some old service accounts use to start SQL. I have a few service accounts that were never marked for non-interactive logon. Can I query AD to see when was the last time (if any) someone logged on interactively? And if so, what ip address did that
Ace Fekay [MVP-...0/16 15 Apr 2010
Good point, don't feel like you are interferring. -- Paul Bergson MVP - Directory Services MCITP - Enterprise Administrator MCTS, MCT, MCSE, MCSA, MCP, Security +, BS CSci 2008, Vista, 2003, 2000 (Early Achiever), NT4 Microsoft's Thrive IT Pro of the Month - June 2009 http://www.pbbergs.com Please no e-mails, any questions should be posted in the NewGroups. This posting is
Nik0/4 15 Apr 2010
Guys, I have a list of users in a .csv file. The users are listed via firstName, lastName Is there anyway I can use dsquery or any other tools to grab the user's login id after it's compared to the name? Normally for a single name I would do something like dsquery user -name "Nik Test" | dsget user -samid Win2003 sp2 Thanks