Moving File Server Into New Domain
Good Afternoon Everyone,
Iâ??m going through a domain migration and Iâ??ve done users, workstations,
Exchange, and now its time for the file servers.
I have a trust between Domain OLD and Domain NEW.
For the file servers Iâ??ve replicated user permissions on each folder so that
any folder with an entry for dOLD\user now also has an entry for dNEW\user.
This has worked great but since my goal is to retire Domain OLD I want to
move the file sever into the new domain.
My question is this:
If I move the file server from Domain OLD to Domain NEW will my permission
erase?
TIA,
Ray Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128268
dcgpofix doesn't work
Hi All-
I have a corrupted domain gpo and so i ran dcgpofix as a method of disaster
recovery (i don't have a backup - that's a different story).
I ran the following command:
dcgpofix /ignoreschema /target:domain
I get an error that says the following:
Unable to read EFS certificate from registry.pol
Does anyone have any ideas on what to do next?
I'm seeing that the domain policy is no longer being applied to any of the
computers in the domain.
Thanks. Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128260
Quesiton on Group Policy Loopback Processing
Hi all,
I am new to GPOs and I have a problem with Group Policy Loopback Processing.
I am dealing with two OUs, one called LAB101 (which only has computer
accounts in it) and one called STAFF (which houses all of my users).
For the STAFF OU I added a GPO called "STAFF GPO" but I have not configured
anything in it. For the LAB101 OU I added a GPO called "LAB101 GPO". In the
LAB101 GPO I enabled Group Policy Loopback Processing (mode = replace). I
did this because I want a User logon script to run whenever a user logs into
the machine. So, I also added a logon script in the user configuration of
the LAB101 GPO.
However, when I log into a LAB101 machine, the script never runs. Am I
missing a step?
Any help is appreciated, thanks. Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128257
Accounts randomly loosing membership to a group in DL's security
Hi,
We have a Windows 2003 shop. We have two servers where one user looses his
membership to a Security Group that we have setup under DLs Security. Why is
this happening? The PC's in question are different operating systems (2000
and Vista) so I highly doubt that that has anything to do with it. Both
servers are 2003 Standard R2. Thoughts? Thank you.
-Rachel Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128255
Dfs problem
Hi all,
I have 2 domain controllers in my network (hq.company.srh,
fsv.company.srh) . Operations master role (RID,PDC,Infrastructure)
belongs to only one domain controller-hq.company.srh.
I am creating a DFS root on hq.company.srh something like company. I
can log in to the domain using my domain account from a computer which
is not a domain computer without problems but when I try to enter the
directory of DFS I get an error saying "Configuration information
cannot be read from the domain controller either because the machine
is unavailable or access has been denied"
Normally if I wrote \\company.srh to open up the dfs root. Instead of
hq.company.srh comes up fsv.company.srh.
I have tried to create dfs root on fsv.company.srh. I can log on from
the client computer with no problems
What do you think the problem is?
Thank you. Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128254
DHCP dynamically updating internal DNS servers instead of authoritative?
Hi there.
Say you have a domain: domain.com which is out there on the Internet
doing its thing, et cetera but you also use that domain internally for your
active directory (which is probably not ideal).
Domain.com is hosted on your cluster of authoritative nameservers and has
records related to your online presence such as MX records, A records for
your website and other public services, et cetera.
Lets say that you're running DHCP/DNS in your active directory and you would
like new registrations to only be added to the 'local' version of domain.com
and not the Internet version of domain.com, I realize that the DHCP server
(and perhaps windows in general) sends dynamic updates to the authoritative
nameservers, but I would rather not for reasons of security through
obscurity publish our internal DNS to the Internet. I realize the right way
to do this would've probably been to use a subdomain such as
internal.domain.com or corp.domain.com but this was all established 10 years
ago.
So the question is, is it possible to have the DHCP server send updates to
the local DNS servers rather than the actual authoritative DNS servers?
thanks,
Andy Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128247
GPO Queston
Hi all,
I have a batch script that I need to run that sets the default printer, it
contains the following line:
rundll32 printui.dll,PrintUIEntry /y /n "115 Lab 4200"
My thinking is that I would make an OU for the Room 115 lab and put all of
the machines in that lab in the OU. I then made a GPO for that OU and added
the script to User Configuration -> logon Scripts, hoping it would execute
this script along with the logon script set in the properties of the users.
However, it does not. What am I doing wrong?
Any help is appreciated, thanks. Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128246
script for disabling accounts
i have created app. 1200 users with default password
and some of them have logged rest of them have not just logged in since 1
month.
I have created a list which users have not logged in with a lastlogon script.
I want a script or any key information about how to i write a script to
disable which i give the usernames.
Thanks Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128244
Password policy expiration
Win2003 sp2 domain. Is there a way to setup a password expiration prompt for
a specific set of users who are remote and do not always login?
Or does default domain policy make this a useless option?
thnx
--
la Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128242
Connectivity problems between child member-server and root domain controllers
Hi Support
I have a forest with one root domain (root.local) and a child domain
(child.root.local) in a single AD forest.
The root domain and the child domain are seperated by a ISA server 2006
firewall.
I have open for communikation between all of the domains controller in the
root and the child domain.
All of the domain controllere in both domains are Global Catalog servere.
Everything is working fine, replication, DNS, GC without any errors.
The root domain controllers hosts the root DNS zone (root.local)
The child domain controllers hosts the child DNS zone (child.root.local)
I have forwarders on the child domain controllers
DNS works fine
Replication Works fine
My issue is:
When I am on a member server i the child domain and want to assign NTFS
permissions on a folder, the dialog boxes hangs for a long period of time.
(Could be any member server in the child domain)
I have looket at the ISA server logs and can see that this child member
sever tries to access the root domain controllere while it hangs. I first
to connect to the rootdcs using "PING", "Microsoft CIFS" and last "Session"
If i open PING and CIFS in the firewall between the child member server and
the root domain controllers it works fine, but i dont not want that
communikation to occur.
The communication must be so that the child member-servers only communicate
with the child domain controllers.
I have specific sites defined for the ROOT domain and the CHILD domain
Hope you have som good idears so we can this fixed
Best regards
Jesper vedholm
Systemtech A/S Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128241
Endpoint mapper error when joining a computer to domain
We are getting endpoint mapper error when trying to join domain. in the
netsetup log we are getting the following:
05/07 07:32:49 NetpChangeMachineName: from 'D630CLONE' to 'A24929' using
'OURDOMAIN\itsetup' [0x2]
05/07 07:32:49 NetpDsGetDcName: trying to find DC in domain 'OURDOMAIN',
flags: 0x1020
05/07 07:32:49 NetpDsGetDcName: found DC '\\DC1' in the specified domain
05/07 07:32:49 NetpChangeMachineName: status of connecting to dc '\\DC1': 0x0
05/07 07:32:49 NetpGetLsaPrimaryDomain: status: 0x0
05/07 07:32:49 NetpManageMachineAccountWithSid: status of NetUserSetInfo on
'\\DC1' for 'D630CLONE$': 0x0
05/07 07:32:49 NetpGetLsaPrimaryDomain: status: 0x0
05/07 07:32:49 NetpGetDnsHostName: PrimaryDnsSuffix defaulted to DNS domain
name: OURDOMAIN.com
05/07 07:33:11 NetpGetComputerObjectDn: Unable to bind to DS on '\\DC1': 0x6d9
05/07 07:33:11 NetpSetDnsHostNameAndSpn: NetpGetComputerObjectDn failed: 0x6d9
05/07 07:33:11 ldap_unbind status: 0x0
05/07 07:33:11 NetpChangeMachineName: status of setting DnsHostName and SPN:
0x6d9
ANY hints or suggestions? I verified that the WF/ICS is turned off on this
particular DC. We do not get the endpoint mapper problem every time we join
the domain but it is frequent enough to rule out a random error.
thanks,
James Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128240
AD system state backup on Windows 2008, disk size increasing
Hello everyone,
I've been working lately with Windows Server 2008 RTM version, and I
promoted one server (virtual machine) as a DC. After having some obstacles
configuring the AD system state backup I finally completed and I had a
schedule backup running periodically.
That backup storage is made on a seconday disk on the DC, but I found out
that the system state backup catalog it's getting real big in a few weeks,
meaning that the VM disk is increasing as well (over 25gb right now).
Is there any way that I can have more control about that? Like accessing
the system state catalog and removing old system state backups? Basically I
don't want to get to the point where I have virtual disks over 200gb :)
Thanks!
--
augusto alvarez | it pro | southworks
http://staff.southworks.net/aalvarez Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128236
MAC and AD
Dear guru,
Is it possible to do so?
1) Can the MAC join our Windows 2003 Native mode AD?
2) Use AD users to login the MAC?
3) Enforce group policy to our MAC (password, lock screen)?
4) Use Integrated Login to Sharepoint through Safari browser?
Do I need additional software to do all these functions?
thanks
Huang Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128233
2 Domains 1 Forest and Fire wall
hi
ive made a quick pic to help describe what i'm trying to acomplish.
http://cisco.truedeviant.com/ad.jpg
the fire wall will only allow the two domain contrrolers to talk to
each other and this can not be modifided.
sites and services are set up ok ad are the trusts
the issue that am haveing is
is when i logon to the clinet machine that is a member of Domain B and
try to logon to Domain A
i can see in wireshark that the client is trying to talk to the Domain
A domain controller but is failing due to the fire wall. with out
enableing routeing and or tunneling on Domains A domain controller is
there any way i can get the client to talk to domain B and get domain
B to authenticated the Domain A users
and alow the user to logon.
cheers
Yale Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128232
User accounts disabled automatically by administrator?!
Hi,
Recently I have faced a strange problem in active directory. Some specified
user accounts disabled automatically by administrator. I feared domain
administrator password leaked so I changed the password and restrict AD
accessibility to only domain administrators , but problem still remains.
Anybody knows about it?
Thanks in anticipation
Bijan Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128224
GPO question after using rendom.exe
I=92m renaming a domain, which is managed by two W2K3 R2 domain
controllers, with the rendom utility.
In Microsoft=92s step by step guide to renaming a domain, it says to
enter this command:
gpfixup /olddns:oas.local /newdns:oas-backup.local /oldnb:oas /
newnb:oas-backup 2>&1 >gpfixup.log
This command fails and the resulting popup window has this error
message:
=93The procedure entry point CryptUnprotectMemory could not be located
in the dynamic link library CRYPT32.dll=94
Also, this is probably related but when I try to run gpmc.msc, I
experience the following trouble:
There is a problem when clicking on either the domain controller
policy or the domain policy. In fact, a window is displayed asking to
change the current domain controller. On this form there is a
combobox, which is greyed out, and it says, =93look in this domain=94.
And the domain reflected in the un-editable control is =93oas.local=94 =96
which is the old domain!!!
Any attempts to select any of the four radio buttons (the domain
control which is the PDC emulator, any domain controller, and
available domain controller running Windows 2003, or specifying a
domain controller) fails.
Just about everything worked using rendom =96 except for being able to
access the GPO for the domain and the domain controllers. Any
suggestions on how to get the gpfixup command or the gpmc.msc working
is greatly appreciated.
Thanks! Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128223
Problem with domain name
I struggled with this one and finally figured it out but I want to
understand what is going on with this network.
Single DC on the network. When I looked at all of the domain members
under computer properties, the domain name only reads "local". I
also
looked under the active directory on the server and the computer
properties of the server and it was listed as "local". I assumed
that
someone prior to me had set this up as a single level DNS domain
name. So I tried to add a member with "local" as the domain name and
it continued to fail.
So eventually I noticed that if I browsed the network on a
workstation
that was already part of the domain the domain name was actually
"DOMAIN". So I tried to add the member with this name and it worked.
But it still displays as simply "local" when viewed under computer
properties, under active directory on the DC, etc.
Why is the FQDN not showing. I expect it to be displayed as
"DOMAIN.local"??
Is there a group policy setting that hides this part of the domain
name.
All is working fine I just wanted to understand why this is
happening? Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128220
Importing a W2k3 Domain Controller into VMWare Stage Manager
I've imported a w2k3 dc into vmware's stage manager beta 1.0. server is in a
fenced network. I had previously shut down the server (vm) then imported
into stage manager. I receive error attempting to open ADUC: "naming
information cannot be located because: the specified domain either does not
exist or could not be contacted. contact your sys admin to verify that your
domain is properly configured and is currently online." any suggestions
appreciated. Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128213
Weird LSAsrv Eventlog message
Hi Everyone,
I wasn't even sure how to google this. Check out this LsaSrv message I'm
getting on my client PCs:
The Security System could not establish a secured connection with the server
ldap/dc.domain.suffix/domain.suffix@domain.suffix. No authentication
protocol was available.
Shouldn't it not look like that at all? Incidentally the dns name of our
domain controller (one of them) is dc.domain.suffix. It seems like the ldap
address is wrong to me. Where would the machines be getting that other
address?
Thank you! Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128212
IDMU ypservers Map Broken?
I am having trouble with my 2003 R2 IDMU Server for NIS. Nothing is
going into my ypservers map but spaces, and it's really hurting my
ability to make a working NIS Slave. Not so good.
Adding more servers just adds more blank lines in "ypcat ypservers".
I see the servers in the map cache file for ypservers, but it's not
actually serving the file out.
Any advice? Thanks! Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128211
password requirement
I have a group policy setup so users have at least 6 characters for there
password. If I change the password requirement from 6 characters to 7
characters, will those users that are logged in with 6 characters not be able
to access resources until they change there password?
Thanks,
Sam Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128206
IP Setting
Hi. We Have Wan As Follow:
Location Max Clients Server IP/mask Client IP From... To
client mask
Main 200 192.168.0.1 /22 192.168.0.2 ...
200 255.255.255.0
Branch1 100 192.168.1.1 /22 192.168.1.2 ...
101 255.255.255.128
Branch2 50 192.168.1.129/22 192.168.1.130 ...
182 255.255.255.192
Branch3 50 192.168.1.193/22 192.168.1.194 ...
224 255.255.255.192
Branch4 20 192.168.2.1 /22 192.168.2.2 ...
122 255.255.255.224
Branch5 20 192.168.2.33 /22 192.168.2.34 ...
54 255.255.255.224
Branch6 20 192.168.2.65 /22 192.168.2.66 ...
86 255.255.255.224
Branch7 20 192.168.2.97 /22 192.168.2.98 ...
118 255.255.255.224
Branch8 20 192.168.2.129 /22
192.168.2.130...150 255.255.255.224
Branch9 20 192.168.2.161 /22
192.168.2.162...182 255.255.255.224
Branch10 20 192.168.2.193 /22 192.168.2.194...214
255.255.255.224
Branch11 20 192.168.2.225 /22 192.168.2.226...246
255.255.255.224
I Have Create For Main Office PDC and each Branch Office One Site/DC/
GC/DNS , and All Branch are Connected to Main Office With ADSL 256K.
My Problems:
1) Is My IP Setting On Servers and Clients correct? If Answer is NO.
Why? How ?
2) There are Some Shared Folders On Server At Main Office. How My
Clients At all Branches Access to This Folders? Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128205
AD attribute
I need to add the department field under the organization for all users based
on their department group membership. What utility can be used to extract
the information from department group, then that information will be used to
populate the department field hopefully via script. WE have over 1000 users,
so need a quick fix. Thanks.
--
Dipti Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128202
Question on Printers in AD
Hello all,
We are running a Windows 2003 domain. I was wondering, is it was possible
to set the default printer for a group of computers in AD? That way, no
matter who logs into the machine, their default printer is set to the one on
the server.
Any help is appreciated, thanks. Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128198
Isolating ADAM from AD
Hi,
I'm trying to use ADAM as a development/testing environment. I exported the
AD schema, then objects, using ADSchemaAnalyzer followed by ldifde. Now when
I run my application against the ADAM instance (on my local computer, Windows
XP Pro) and change a property, the real AD is updated with the same change.
Is there a way I can disconnect these? Thanks,
Robert Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128197
Ports Used for ADAM
I am setting up a master and replica ADAM instances on two seperate servers.
Can I use the same port number combination for open and ssl on each instance?
Please advise... Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128194
Error Loading Operating Sytem - Windows 2003- Need to recover AD f
I had some partition problem and was able to fix it. I logged into recovery
console and did fix mbr and alsot fix boot disk. Now when I go to the install
it doens show only the C drive.
I still get Error Loading Operating system. If possible, can I get some
files off the Windows 2003 server to restore my AD? I can access all the
files and copy them off using Windows PE Boot disk Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128193
Windows Server 2008 and 2003 GC's + Exchange 2003
We are thnking about repalcing our core DC's/GC's in our HUb. Our AD design
is a hub and spoke topology where the spokes are all 2003 GC's. We are also
using Exchange 2003 with the thought to upgrade to 2007 but first we would
like to get our core DC's/GC's up to 2008. Can Server 2008 GC's/DC's coexist
with 2003 gc's i this tolopology? Please advise... Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128182
EVT ID 1053 at logon
Dear All
i constantly receive event id 1053 when logging on to my 2003 domain.
Windows cannot determine the user or computer name. (The specified domain
either does not exist or could not be contacted. ). Group Policy processing
aborted.
swiftly followed by ID 1054
Windows cannot obtain the domain controller name for your computer network.
(The specified domain either does not exist or could not be contacted. ).
Group Policy processing aborted.
This results in logon scripts not running. Also if i try to have someone
else log on to my pc they get specified domain could not be contacted..
(i am domain admin and this only appears on my pc as far as i know)
GPupdate from the command line works fine its just at logon...
Anyone have any ideas at all !!! Help please
Kr
Paul Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128173
clear current members of a distrib grp and add new members from a
2003 AD, Native forest and Domain.
XP SP2 clients.
I need to script up a way of clearing all current members for an AD
Distribution Group and then adding back in all the members from a .txt or
.csv file.
The script needs to be able to be run by users that have permissions to the
AD group object.
Any ideas? Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128166
question about domain rename
Hello,
I just finished reading the Step-by-Step Guide to Implementing Domain
Rename publication from Microsoft. Wouldn't it be easier to just
remove the hosts from the domain, demote the domain controllers,
rename the DCs, and re-promote them?
Thanks! Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128157
Delegated account control is getting access denied
Hi everyone,
I'll skip over some of the things I have tried. But basically the situation
is this:
I create a barnd new account and delegate these controls for the account
specifically:-
allow reset account
allow read pwdLastSet
allow write pwdLastSet
Now that user can select and tick the box for 'user must change password at
next logon' for any user in the container that delegation has been set up
for. However once this has been selected and applied that user cannot remove
the tick form the tick box - same object.
You get an error - The following Active Directory error occurred: Access is
denied
But there are no explicit denies for this user and the delegation that has
been set up. Plus if there was surely you would not be able to tick the
option in the first place.
Anyone have experience with this sort of issue? Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128154
deleted group policie still active
hi,
i have a strange problem.
i created a group policie to deploy printers.
after a while i decided to use another strategie and deleted the policie.
strange thing is:
meanwhile i already deleted the gp AND the printers but they still get
deployed to all the workstations.
so it seems that even i can not access the policie anymore, it still ist
active somewhere.
how can i get rid of this.
i have no idea where to look at.
please help!!
regards
nico Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128148
Kerberos NTLM
Is there a reason that IE(IE7) would send NTLM instead of KERBEROS after
setting IE as follows?
Is thee something else i have to lok for?
1. put the requesting site in IE to local-network
2. in the IE extended security option enable Integrated Windows
Authentication
To configure Intranet Authentication:
1. Click the Security tab, click Local intranet, and then click Custom
Level.
2. In the Security Settings dialog box, scroll down to the User
Authentication section of the list.
3. Select Automatic logon only in Intranet zone. This setting prevents users
from having to re-enter logon credentials; a key piece to this solution.
4. Click OK to close the Security Settings dialog box.
In addition to the previous settings, one additional setting is required if
you are running Internet Explorer 6.0.
1. In Internet Explorer, click Tools, and then click Internet Options.
2. Click the Advanced tab.
3. Scroll down to the Security section.
4. Make sure that Enable Integrated Windows Authentication (requires
restart) is checked, and then click OK.
5. If this box was not checked, restart the browser. Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128145
Child domain and DNS
Hello list. In a Windows 2003 R2 forest I've added with dcpromo a child
domain of my root domain.
On the Root's DNS, the child domain appears as a subdomain.
I'd like it to appear as a deleagate zone of the child domain pointed to
the child DC's DNS server.
my idea is
1. create the zone on the child DC's DNS by manually copying all entries
from the root's DNS
2. delete the subdomain on the root DNS
3. create a delegated zone in the root domain for the child zone.
Is it a good solution?
Is there any better solution with a 2003 (native mode) forest?
thank you. Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128141
How to default to using KCC
Hi, we are running into some issues with replication in AD- apparently some
manual entries have been added to our replication topology - we are talking
13 sites all across the US
Is there a way to default to only using the KCC to fix all this manual
stuff? What is the correct procedure.?
any help will be appeciated?
Pierre Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128138
Restricting FTP access via windows Explorer
You guys may have some trick to do this. I use Group policy to restrict
almost everything. I would like to restrict users to stop using FTP access
from their machine. I used GPO to restrict ftp, http, in connection setting.
That restrict the user from internet explorer or other browser. However, user
can still access using windows explorer and type in address bar like
ftp://servername .com. and this will ask username and password and can easily
access. Is ftp client also built in windows explorer ? If I want to restrict
ftp for those particular users in OU how do i do this ?
Thanks
AT Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128131
Error Userenv Netlogon without WINS
Hello,
I have a ADS in Win2k3 Mode.
Computers are correctly registred on DC.
If I log onto a Membercomputer the following Errors appear - even if WINS is
not registred on the NIC.
Netlogon
"Der Computer konnte eine sichere Sitzung mit einem Domänencontroller in der
Domäne TEST aufgrund der folgenden Ursache:
Es sind momentan keine Anmeldeserver zum Verarbeiten der Anmeldeanforderung
verfügbar. nicht einrichten. ..."
Userenv
"Der Benutzer oder der Computername kann nicht ermittelt werden. (Die
angegebene Domäne ist nicht vorhanden, oder es konnte keine Verbindung
hergestellt werden. ). Die Verarbeitung der Gruppenrichtlinie wurde
abgebrochen."
If Wins is activated on the ComputerNIC no Error apears
What's the matter?
Thanks Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128126
AD Sync Problem
Hi, I have a situation. I just got customer who had deployed 2 x 2K3 R2 AD
and
had it sync with each other at the main office. They also deployed exchange
2007 at the main office. However, they split the network between 2 sites and
have moved 1 of the AD to a site office, but these 2 AD have not been
connected for the last 3 months. To access the domain and exchange, they
create the same new user account on the 2 AD server and exhange 2007. So
site office users login in to the site office AD, but access exchange via the
main office AD and exhange.
Question: If they connect the network together now and tried to sync the 2
AD, will the new accounts created on both sites conflict with each other or
will they just sync with each other and the users on both sides would
continue to work as per normal? Thanks.
Gilbert Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128123
The domain name has not been registered with InterNIC
Hi,
We have a single domain with 2 DCs at the Datacentre. No other DC at present.
While running command - "dcdiag" or "netdiag" there are no errors. When i
run "dnslint" command i get the below error. we are using 198.x.x.x range for
our internal users.
############
C:\Documents and Settings\ABC>dnslint /d domain.com
DNSLint will attempt to verify the DNS entries for:
domain.com
This process may take several minutes to complete...................
No match for domain name found
The domain name has not been registered with InterNIC
#############
Please guide.
Thanks.
abc. Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128119
NTDS Automatic Entries
We are just emerging from resolving issues with lingering objects and now
have A/D replicating without errors in replmon.
When I look at Sites and Services under one of my domain controllers, the
NTDS Settings show a few <automatically generated> connections and about six
others that show the server name in both the Name and From Server columns.
I am thinking these are there because we manually moved these connections
during the process of troubleshooting our replication issues (and we had
plenty).
My question is, can I delete these non-automatic entries and have A/D
reconnect everything using the automatically generated type? We have had
solid, reliable replication for about 5 days now and I am confident that all
DCs are communicating properly across my WAN.
Thanks in advance for any thoughts or comments! Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128117
add a trusted domain
Hello,
I have a central local domain, servers W2003, AD, ....
We recently buy a company, equiped with a SBS2003, AD, ...
We are linked to this company via MPLS/SDSL.
But employee located at the company can't access ressource on our local
domain without relogin to our domain.
So, I'm looking to make a trust.
But from my local domain, when I try to add it, it say that the remote
domain can not be contacted.
In my local domain, I added a dns entry like "Name.local" (it's the name of
the remote AD) pointing to the SBS2003.
so, I can't ping name.local.
What should I do more to add this trust ?
Thx Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128116
Linux Users Problems
Ok the basic layout:
We are currently running a Samba 3 based domain, and slowly moving towards a
2003 based AD.
Almost everything is in place and working, except for one thing..
Unix/Linux systems, and getting them on the domain, properly.
The Unix attributes tabs show UP in Users and Computers, and all the options
are there, you can make selections, etc. But the moment you hit the ol apply
and ok, the window closes, and every setting you've made..
vanishes.
No errors, no nothing, but NO changes made on the Unix attributes for
users/group/computers, none of those changes seem to save in anyway. I'm at a
bit of a loss anyone have any background with this? Or have an idea that I've
missed? Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128114
Domain Controller Failover
Hello.
We have 2 DC in our forest.
Today after shutting down the 1st for maintenance, all users were unable to
login.
Are there any whitepapers you can suggest? Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128110
ADAM Service Account
I am trying to install ADAM in our domain on two seperate servers. One will
be the Master and the other will be a replica. I will be using a domain
account for the service. What permissions are necessary for the ADAM service
account in a domain? Do I just need to make it an admin on the local box?
Please advise.... Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128105
What is ADLDS
Hello
I'm wondering what ADLDS (previous named ADAM) can be used for? I can't seem
to find a good document that explains it pro's and con's.
Could anyone please assist?
Regards
Per-Torben Sørensen Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128104
How to know when an AD object has been deleted ?
Hi,
I would like to know which day and approximatively at what time an
object has been deleted.
I think that it is possible with the repadmin command but I dont find
how.
Please could you help me ?
Thank you
--
Pascal Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128103
Removing failed DC from AD Integrated Zones
Hi there,
One of our Windows 2000 domain controllers died last week so we had to
remove it from AD as per the following article ->
http://support.microsoft.com/kb/216498.
The problem is we have approximately 100 Active Directly integrated DNS
zones & the 'old' DC is still listed as a Name Server (NS) in all of them.
Is there a quick & easy to remove this entry or do we need to remove it
manually from all of the zones?
Any suggestions/comments are greatly appreciated.
Regards,
Veets Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128096
HOWTO merge multiple GPO's to one new GPO
Does anyone know a way howto merge multiple GPO's to one new GPO.
I want to merge multiple GPO's with some security, system and administrative
policies to one new GPO.
I also want to merge the multiple "regedit.pol" files that are now part of
individual GPO's into one new GPO.
The GPMC does not provide this function with import. The import overwrites
the whole GPO.
VB scripts are also welcome.
Thanx in advance Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128095
prevent some users to download mp3 and specified files
Hi
how can prevent some users to download mp3 and specified files to desktop
and their home folder.
Thanks Tag: Find easy what you need for windows(98, ME, xp, vista) Tag: 128092
If you need some tools for windows or you have a problem, this is the
right spot ...
http://microsoft-windows-tips.blogspot.com/