11 essential tools for managing Active Directory
|
|
|
- Mark Flynn
- 10 years ago
- Views:
Transcription
1 At a glance: Creating objects at the command line Performing bulk operations within Active Directory Active Directory updates and maintenance 11 essential tools for managing Active Directory Laura E Hunter If you ve ever been handed an Excel spreadsheet listing 200 new employees starting next week, or if your user accounts are configured incorrectly because help desk staff clicked something they shouldn t have, or if you just want an easier way to manage Active Directory besides opening Users and Computers every time, there are a number of free administration tools that can help. Some are built right into the Windows OS, some come in a Resource Kit or the Windows Support Tools, and some are free third-party tools. What are these handy tools and where can you get them? Let s find out. I ll start with the built-in command-line tools in Windows Server 2003 that allow you to create, delete, modify, and search for objects in Active Directory. CSVDE The Comma-Separated Values Data Exchange tool, known as CSVDE, allows you to import new objects into Active Directory using a CSV source file; it also provides you with the ability to export existing objects to a CSV file. CSVDE can t be used to modify existing objects; when you are using this tool in import mode you can only create brand new objects. Exporting a list of existing objects with CSVDE is fairly simple. Here s how you d export your Active Directory objects to a file called ad.csv: csvde f ad.csv The f switch indicates that the name of the output file follows. But you must be aware of the fact that, depending on your environment, this basic syntax could result in a huge and unwieldy output file. To restrict the tool to export 50 To get your FREE copy of TechNet Magazine subscribe at:
2 objects only within a particular organisational unit (OU), you could modify the statement as follows: csvde f UsersOU.csv d ou=users,dc=contoso,dc=com Let s further say that you re only interested in exporting user objects into your CSV file. In that case, you can add the r switch, which allows you to specify a Lightweight Directory Access Protocol (LDAP) filter for the search, and the l switch, which restricts the number of attributes that are exported (note that the following is all on one line): csvde f UsersOnly.csv d ou=users,dc=contoso,dc=com r (&(objectcategory=person)(objectclass=user)) l DN,objectClass,description The i switch allows you to import objects into Active Directory from a source CSV file. However, creating user objects with CSVDE has one critical limitation: you can t set user passwords with it. Because of this, I d avoid using CSVDE to create user objects. LDIFDE Active Directory provides a second built-in tool for bulk user operations, called LDIFDE, and it is more powerful and flexible than CSVDE. In addition to creating new objects, LDIFDE can also modify and delete existing objects and even extend the Active Directory schema. The tradeoff for LDIFDE s flexibility is that the necessary input file, which is referred to as an LDIF file with the extension.ldf, uses a more complex format than the simple CSV file. (With a little work you can also configure user passwords, but I ll get to that in a moment.) Let s start with a simple example, exporting users in an OU to an LDF file (note that the following is all on one line): ldifde -f users.ldf -s DC1.contoso.com -d ou=usersou,dc=contoso,dc=com r (&(objectcategory=person)(objectclass=user)) As with most command-line tools, you can find a full explanation of the LDIFDE switches by running the LDIFDE /? command. Figure 1 describes the ones I ve used here. (Note that the switches are actually the same for both the CSVDE and LDIFDE commands.) The real power of LDIFDE is in creating and manipulating objects. Before doing this, however, you first need to create an input file. The following creates two new user accounts called afuller and rking; to create the input file, enter the text in Notepad (or your favourite plain-text editor) and save it as NewUsers.ldf: Figure 1 LDIFDE switches Switch Description -d Specifies LDAP path that LDIFDE should connect to for the operation. -f Indicates the name of the file to be used, in this case to output the results of the export. -r Specifies the LDAP filter to use for an export. -s Specifies the domain controller (DC) to connect to that will perform the operation; if you leave this out, LDIFDE will connect to the local DC (or the DC that authenticated you if you are running the tool from a workstation). Once you ve finished creating the file, run the following command: ldifde i f NewUsers.ldf s DC1.contoso.com The only new switch here is -i, which, you can probably guess for yourself, denotes that this is an import operation instead of an export. When modifying or deleting existing objects, the syntax for the LDIFDE command doesn t change; instead, you modify the contents of the LDF file. To change the description field of the user accounts, create a text file called ModifyUsers.ldf, such as the one shown in Figure 2. You import the changes by running the same LDIFDE command syntax as before, specifying the new LDF file name after the -f switch. The LDF format for deleting objects is even simpler; to delete the users you ve been working with, create a file called DeleteUsers.ldf and enter the following: dn: CN=afuller OU=UsersOU, DC=contoso, DC=com changetype: delete dn: CN=rking, OU=UsersOU, DC=contoso, DC=com changetype: delete Note that unlike CSVDE, LDIFDE is capable of configuring user passwords. Before you can configure the unicodepwd attribute for a user account, however, you must configure secure sockets layer/transport layer security (SSL/ TLS) encryption on your domain controllers. dn: CN=afuller, OU=UsersOU, DC=contoso, DC=com changetype: add cn: afuller objectclass: user samaccountname: afuller dn: CN=rking, OU=UsersOU, DC=contoso, DC=com changetype: add cn: rking objectclass: user samaccountname: rking Figure 2 The ModifyUsers LDF file TechNet Magazine November
3 Moreover, LDIFDE can create and modify any type of Active Directory object, not just user accounts. The following LDF file, for example, will create a custom schema extension called EmployeeID-example in the schema of the contoso.com forest: dn: cn=employeeid-example,cn=schema, cn=configuration,dc=contoso,dc=com changetype: add admindisplayname: EmployeeID-Example attributeid: attributesyntax: cn: Employee-ID instancetype: 4 issinglevalued: True ldapdisplayname: employeeid-example Because LDIFDE files use the industry-standard LDAP file format, third-party applications that need to modify the LDIFDE can create and modify any type of Active Directory object, not just user accounts Active Directory schema will often supply LDF files you can use to examine and approve the changes before applying them to your production environment. In addition to tools for bulk import and export operations, Windows Server 2003 also includes a built-in toolset that lets you create, delete and modify various Active Directory objects as well as perform queries for objects that meet certain criteria. (Note that these tools, dsadd, dsrm, dsget and dsquery, are not supported under Windows 2000 Active Directory.) Dsadd Dsadd is used to create an instance of an Active Directory object class on a particular directory partition. These classes include users, computers, contacts, groups, organisational units and quotas. Dsadd has a generic syntax that consists of the following: dsadd <ObjectType> <ObjectDistinguishedName> attributes Note that each object type you create takes a specific set of switches corresponding to the attributes available for that type. This command creates a single user object with various attributes populated (note that the following is all on one line): dsadd user cn=afuller,ou=it,dc=contoso,dc=com samid afuller fn Andrew ln Fuller pwd * -memberof cn=it,ou=groups,dc=contoso,dc=com cn=help Desk,ou=Groups, dc=contoso,dc=com desc Marketing Director The memberof switch requires the full distinguished name (DN) of each group the user should be added to; if you want to add the user to multiple groups you can add multiple DNs separated by spaces. If any element contains a space, such as the DN of the Help Desk group, it needs to be enclosed in double quotes. If an element contains a backslash, like an OU called IT\ EMEA, the backslash must be entered twice: IT\\EMEA. (These requirements apply to all of the ds* tools.) When you use the -pwd * switch, you ll be prompted to enter a password for the user at the command line. You can specify the password within the command itself (-pwd P@ssword1), but this will display the password in plain text on the screen or in any text or script file that you ve embedded the command into. Similarly, you can create a group object and an OU using the following two commands: dsadd computer cn=wks1,ou=workstations,dc=contoso,dc=com dsadd ou ou=training OU,dc=contoso,dc=com Dsmod Dsmod is used to modify an existing object, and you work with it much as with dsadd, using different submenus and syntax depending on the type of object you re modifying. The following dsmod statement changes a user s password and modifies his account so he will be prompted to change to a new password on next logon: dsmod user cn=afuller,ou=it,dc=contoso,dc=com pwd P@ssw0rd1 mustchpwd yes To see how similar these switches are, look at the dsadd syntax you would use to create this user with the same attributes configured: dsadd user cn=afuller,ou=it,dc=contoso,dc=com pwd P@ssw0rd1 mustchpwd yes As you can clearly see, if you know the switches to create objects in dsadd, you can use those same switches to modify users with dsmod. Dsrm The converse of dsadd is dsrm; as you might imagine, this tool lets you delete an object from the command line. The basic dsrm syntax is pretty straightforward: simply enter dsrm followed by the distinguished name of the object you want to delete, like so: dsrm cn=wks1,ou=workstations,dc=contoso,dc=com By default, dsrm will prompt Are you sure you want to delete this object? Type Y, then press Enter. You can suppress this prompt using the noprompt switch, but, obviously, you then get no chance to confirm that you ve selected the correct object before deleting it. Two additional switches can be helpful if you are deleting a container object, that is, an organisational unit that could potentially 52 To get your FREE copy of TechNet Magazine subscribe at:
4 TechNet Magazine November
5 Figure 3 Running dsget contain other objects within it. The following command deletes the TrainingOU organisational unit and all objects contained within it: dsrm ou=trainingou,dc=contoso,dc=com subtree This one deletes all child objects contained within TrainingOU but leaves the organisational unit object itself in place: dsrm ou=trainingou,dc=contoso,dc=com subtree exclude Dsmove To move or rename an object in Active Directory, you use the dsmove tool, but note that you should use it to move an object only within a single domain. To migrate objects between domains or forests, use the Active Directory Migration Tool (ADMT), a free download from the Microsoft Web site. Dsmove relies on two switches that can be used separately or in combination. This command gives Steve Conn s account a new last name: dsmove cn=conn, Steve,ou=IT,dc=contoso,dc=com newname Steve Conn This command moves Steve s account from the IT OU to the Training OU: dsmove cn=conn, Steve,ou=IT,dc=contoso,dc=com newparent ou=training,dc=contoso,dc=com You can combine a rename and a move into a single operation by specifying both switches at once, like this: dsmove cn=conn, Steve,ou=IT,dc=contoso,dc=com newname Steve Conn newparent ou=training,dc=contoso,dc=com Dsget and Dsquery The ds* command-line toolset also includes two tools used to query Active Directory for information rather than for creating or modifying objects. Dsget takes an object s DN as input and provides you with the value of the attribute or attributes you specify. Dsget uses the same submenus as dsadd and dsmod user, computer, contact, group, OU and quota. To obtain the SAM Account Name and Security Identifier (SID) of a user account, enter the following command (note that the following is all on one line): dsget user cn=afuller,ou=it,dc=contoso,dc=com samaccountname sid You ll get output such as that in Figure 3. Dsquery returns a list of Active Directory objects that meet criteria you specify. You can specify the following parameters no matter which submenu you re using: dsquery <ObjectType> <StartNode> -s <Search Scope> -o <OutputFormat> For ObjectType, dsquery can use the following submenus, each of which has its own syntax: computer, contact, subnet, group, OU, site, server (note that the server submenu retrieves information about domain controllers, not any member servers in your environment), user, quota and partition. And if one of these query types doesn t fit the bill, you can use the * submenu, which lets you enter a free-form LDAP query. StartNode specifies the location in the Active Directory tree where the search will start. You can use a specific DN such as ou=it,dc=contoso,dc=com, or one of the following shortcut specifiers: domainroot, which begins at the root of a particular domain, or forestroot, which begins at the root of the forest root domain using a Global Catalog server to perform the search. Finally, the Search Scope option specifies how dsquery should search the Active Directory tree. Subtree (the default) queries the specified StartNode and all of its child Dsget takes an object s DN as input and provides you with the value of the attributes you specify objects, onelevel queries only the immediate children of the StartNode, and base queries the StartNode object only. To better understand search scopes, consider an OU that contains both user objects and a child OU that itself contains additional objects. Using the subtree scope will query the OU, all of the user objects contained within it, and the child OU and its contents. The onelevel scope will query only the users contained within the OU and will not query the child OU or its contents. A base query will search only the OU itself without querying any of the objects contained within it. 54 To get your FREE copy of TechNet Magazine subscribe at:
6 Finally, you can use Output Format to control how the results of dsquery are formatted. By default, dsquery returns the distinguished names of any objects that match the query, like this: cn=afuller,ou=training,dc=contoso,dc=com cn=rking,ou=ittraining,ou=training,dc=contoso,dc=com To query for all user objects contained within the IT OU and any child OUs, use the following: dsquery user ou=it,dc=contoso,dc=com You can further refine this query by adding extra switches such as -disabled, which returns only disabled user accounts; -inactive x, which returns only users who haven t logged on in the past x weeks or more; or -stalepwd x, which will return only users who have not changed their passwords in x days or more. Depending on the number of objects in your directory, you may need to specify the -limit x switch when running your query. By default, dsquery will return up to 100 objects that match the specifics of your query; you can specify a larger number such as -limit 500, or use -limit 0 to instruct dsquery to return all matching objects. Because Active Directory is based on LDAP standards, you can query and modify it using any tool that can speak LDAP You can use the other submenus to perform useful queries for other object types as well. Consider the following query, which returns every subnet defined in Active Directory Sites and Services that s in the 10.1.x.x address space: dsquery subnet name 10.1.* Or use the following to return every subnet located in the Corp site: dsquery subnet site Corp With another submenu, you can quickly determine how many domain controllers in your forest are configured as Global Catalog servers: dsquery server forest isgc You can also use this syntax to help you determine which domain controller in your domain hosts the Primary Domain Controller (PDC) Emulator Flexible Single Master Operations (FSMO) role: dsquery server hasfsmo pdc As with the other ds* commands that include submenus, you can view all of the switches available within a particular dsquery submenu by going to the command prompt and typing dsquery user /?, dsquery computer /?, dsquery subnet /?, and so forth. An additional slick trick is to pipe the output of dsquery into another tool such as dsmod using the character (shiftbackslash on US keyboards). For example, let s say your company has renamed a department from Training to Internal Development and now you have to update the description field of each relevant user from the old department name to the new. On a single command line, you can query for user objects that have a description field of Training and then modify that description field in bulk, as follows: dsquery user description Training dsmod -description Internal Development Some third-party gems Because Active Directory is based on LDAP standards, you can query and modify it using any tool that can speak LDAP. Many third-party vendors have released fee-based tools to assist you in administering Active Directory, but sometimes you find a treasure that has been made available to the community at no charge. Such is the case with a collection created by Directory Services MVP Joe Richards, available for download from: joeware.net/freetools. There you ll find numerous tools to serve many different functions. Three that I turn to again and again are adfind, admod and oldcmp. Adfind and Admod Adfind and admod are similar to dsquery and dsmod; adfind is a command-line query tool for Active Directory, and admod can create, delete or modify one or more Active Directory objects. Unlike the ds* tools that have multiple submenus and different switches depending on the type of object, adfind and admod have a consistent syntax regardless of the type of query or modification you re trying to perform. The basic syntax for adfind is: adfind b <Search Base> -s <Search Scope> -f <Search Filter> attributesdesired So a query for the DN and description of all computer objects within your domain would be: adfind b dc=contoso,dc=com s subtree f (objectclass=computer) dn description A query for all user objects would look like this: adfind b dc=contoso,dc=com s subtree f (&(objectcategory=person) (objectclass=user)) dn description Notice that except for the contents of the LDAP query, the syntax has not changed. As you work with adfind, you ll find a number of shortcut operators that can save you a lot of typing. For example, the -default switch can replace -b dc=contoso,dc=com in the TechNet Magazine November
7 previous example and search your entire domain; -gc searches against a Garbage Collection (GC) and returns all users in your Active Directory forest. You can also use the -rb switch to set a relative base for your search; if you want to search the Training OU in the phl.east.us.contoso.com domain, you can save yourself quite a bit of effort by simply specifying default rb ou=training rather than b ou=training, dc=phl,dc=east,dc=us,dc=contoso,dc=com. Adfind can also perform a number of advanced search functions that can t be easily managed at the command line otherwise, including those shown in Figure 4. An example using the asq switch would be Show me the group memberships of the members of the HelpDesk, like this: adfind default rb cn=helpdesk,ou=it asq member memberof Admod, as its name suggests, is used to modify objects within Active Directory. As with adfind, there are no specialised submenus with particular syntaxes to remember; admod uses the same syntax regardless of the type of object you re working with. You can also use admod to add, move, rename, delete and even undelete objects simply by adding the appropriate switch, such as -add, -rm, -move, -undel. And just as with dsquery and dsmod, you can also use the character to pipe the results of an adfind query into admod. Note that performing an undelete with admod simply performs a tombstone reanimation operation, in which most of the object s attributes have been removed. To fully restore an object and all of its attributes, you ll still need to perform an authoritative restore of the object. Oldcmp There s one additional joeware tool I consider an indispensable part of my automation toolkit: oldcmp, which scans your Active Directory database for computer accounts that have not been used in a specified number of weeks and can do the following: Create a report of accounts without taking any action against them Disable the unused computer accounts Move the computer accounts to a different OU that you designate Delete the computer accounts outright Note that because oldcmp has the potential to wreak serious havoc on your directory, it has a number of built-in safety features. It will not delete any account that has not already been disabled (and without manually specifying a No really, I mean it! command-line switch). It will not modify more than 10 objects at a time without a similar No really, I mean it! switch, and it absolutely will not do anything to the computer account for a domain controller. Despite the now misleading name of the tool, Joe has Figure 4 Adfind switches Switch -showdel -bit -asq -dsq Description Queries the Deleted Objects container for tombstone objects. Queries against bitwise operators such as the user- AccountControl attribute. Performs an attribute-scoped query. This function (which can t be replicated in dsquery) can retrieve an attribute of a particular object and then perform a query against it. Pipes the output of an adfind query into dsmod or one of the other ds* tools. updated oldcmp so that it will perform similar functions for user accounts that have not been used for a certain amount of time as well. For a small Active Directory environment or one where you re only working with one or two additions or changes at a time, the GUI tools such as Active Directory Users and Computers might be sufficient for day-to-day administration. But if you re adding and modifying large numbers When modifying large numbers of objects on a daily basis, moving to the command line can greatly speed up the process of objects on a daily basis or simply want a more streamlined solution for your administrative tasks, moving to the command line can greatly speed up the process of creating, modifying and deleting objects within Active Directory. As you ve seen, there are a number of flexible and powerful tools available free of charge, both built right into Windows and downloadable from members of the Active Directory community. Any of these tools has the ability to greatly enhance your productivity as an Active Directory administrator, and together they become even more essential to your daily work life. Laura E Hunter is a four-time recipient of the Microsoft MVP award in the area of Windows Server Networking. She is the author of the Active Directory Cookbook, Second Edition (O Reilly, 2006). A 10-year veteran of the IT industry, Laura currently works as the Active Directory architect for a global engineering firm. She holds multiple industry certifications and is a frequent speaker at user group meetings and industry conferences. 56 To get your FREE copy of TechNet Magazine subscribe at:
Active Directory Commands ( www.ostadbook.com )
CSVDE Script Example: Active Directory Commands ( www.ostadbook.com ) 1 Dn, samaccountname, userprincipalname, department, useraccountcontrol, objectclass "CN=Amir Nosrati,OU=IT,DC=Ostadbook,DC=com",Amir-n,[email protected],MCSE,512,user
Microsoft Virtual Labs. Active Directory New User Interface
Microsoft Virtual Labs Active Directory New User Interface 2 Active Directory New User Interface Table of Contents Active Directory New User Interface... 3 Exercise 1 User Management and Saved Queries...4
Chapter 4: Implementing and Managing Group and Computer Accounts. Objectives
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 4: Implementing and Managing Group and Computer Accounts Objectives Understand the purpose of using group accounts to
Module 4. Managing Groups. Contents: Lesson 1: Overview of Groups 4-3. Lesson 2: Administer Groups 4-24. Lab A: Administer Groups 4-36
Managing Groups 4-1 Module 4 Managing Groups Contents: Lesson 1: Overview of Groups 4-3 Lesson 2: Administer Groups 4-24 Lab A: Administer Groups 4-36 Lesson 3: Best Practices for Group Management 4-41
Step-by-Step Guide to Active Directory Bulk Import and Export
Page 1 of 12 TechNet Home > Windows Server TechCenter > Identity and Directory Services > Active Directory > Step By Step Step-by-Step Guide to Active Directory Bulk Import and Export Published: September
CHAPTER THREE. Managing Groups
3 CHAPTER THREE Managing Groups Objectives This chapter covers the following Microsoft-specified objectives for the Managing Users, Computers, and Groups section of the Managing and Maintaining a Microsoft
Introduction to Auditing Active Directory
Introduction to Auditing Active Directory Prepared and presented by: Tanya Baccam CPA, CITP, CISSP, CISA, CISM, GPPA, GCIH, GSEC, OCP DBA Baccam Consulting LLC [email protected] Objectives Understand
Active Directory. By: Kishor Datar 10/25/2007
Active Directory By: Kishor Datar 10/25/2007 What is a directory service? Directory Collection of related objects Files, Printers, Fax servers etc. Directory Service Information needed to use and manage
Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services
Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services Course Number: 6425B Course Length: 5 Days Course Overview This five-day course provides to teach Active Directory Technology
Module 1: Introduction to Active Directory Infrastructure
Module 1: Introduction to Active Directory Infrastructure Contents Overview 1 Lesson: The Architecture of Active Directory 2 Lesson: How Active Directory Works 10 Lesson: Examining Active Directory 19
Module 4: Implementing User, Group, and Computer Accounts
Module 4: Implementing User, Group, and Computer Accounts Contents Overview 1 Lesson: Introduction to Accounts 2 Lesson: Creating and Managing Multiple Accounts 8 Lesson: Implementing User Principal Name
Creating Organizational Units, Accounts, and Groups. Active Directory Users and Computers (ADUC) 21/05/2013
Creating Organizational Units, Accounts, and Groups Tom Brett Active Directory Users and Computers (ADUC) Active Directory Users and Computers (ADUC) After installing AD DS, the next task is to create
Understanding Active Directory. Heng Sovannarith [email protected]
Understanding Active Directory Heng Sovannarith [email protected] Active Directory Active Directory is a directory service and hierarchical data store that holds information about objects on your
70-640 R4: Configuring Windows Server 2008 Active Directory
70-640 R4: Configuring Windows Server 2008 Active Directory Course Introduction Course Introduction Chapter 01 - Installing the Active Directory Role Lesson: What is IDA? What is Active Directory Identity
Active Directory Disaster Recovery Workshop. Lab Manual Revision 1.7
Active Directory Disaster Recovery Workshop Lab Manual Revision 1.7 Table of Contents LAB 1: Introduction to the Lab Environment... 1 Goals... 1 Introduction... 1 Exercise 1: Inspect the Lab Environment...
Module 3: Implementing an Organizational Unit Structure
Module 3: Implementing an Organizational Unit Structure Contents Overview 1 Lesson: Creating and Managing Organizational Units 2 Lesson: Delegating Administrative Control of Organizational Units 13 Lesson
Step-by-Step Guide to Bulk Import and Export to Active Directory
All Products Support Search microsoft.com Guide Windows 2000 Home Windows 2000 Worldwide Search This Site Go Advanced Search Windows 2000 > Technical Resources > Step-by-Step Guides Step-by-Step Guide
Configuring Windows Server 2008 Active Directory
Configuring Windows Server 2008 Active Directory Course Number: 70-640 Certification Exam This course is preparation for the Microsoft Technical Specialist (TS) exam, Exam 70-640: TS: Windows Server 2008
Administering Computer Accounts and Resources in Active Directory
2 CHAPTER TWO Administering Computer Accounts and Resources in Active Directory Terms you ll need to understand: Domains Domain Trees Domain Forests Computer accounts Run As feature Globally unique identifiers
RSA Authentication Manager 7.1 Microsoft Active Directory Integration Guide
RSA Authentication Manager 7.1 Microsoft Active Directory Integration Guide Contact Information Go to the RSA corporate web site for regional Customer Support telephone and fax numbers: www.rsa.com Trademarks
BlackShield ID. QUICKStart Guide. Integrating Active Directory Lightweight Services
QUICKStart Guide Integrating Active Directory Lightweight Services 2010 CRYPTOCard Corp. All rights reserved. http://www.cryptocard.com Trademarks CRYPTOCard, CRYPTO Server, CRYPTO Web, CRYPTO Kit, CRYPTO
Core Active Directory Administration
Chapter 7 Core Active Directory Administration In this chapter: Tools for Managing Active Directory............................157 Using the Active Directory Users And Computers Tool............162 Managing
Using LDAP Authentication in a PowerCenter Domain
Using LDAP Authentication in a PowerCenter Domain 2008 Informatica Corporation Overview LDAP user accounts can access PowerCenter applications. To provide LDAP user accounts access to the PowerCenter applications,
User Management Resource Administrator. Managing LDAP directory services with UMRA
User Management Resource Administrator Managing LDAP directory services with UMRA Copyright 2005, Tools4Ever B.V. All rights reserved. No part of the contents of this user guide may be reproduced or transmitted
CardAccess 3000 V2.9.x New Features Configuration Guide
CardAccess 3000 V2.9.x New Features Configuration Guide DATE: 11 OCTOBER 2012 DOCUMENT PERTAINS TO: CARDACCESS 3000 V2.9.X NEW FEA- TURES CONFIGURATION GUIDE REVISION: A Continental 2012 CardAccess 3000
Introduction... 1. Installing and Configuring the LDAP Server... 3. Configuring Yealink IP Phones... 30. Using LDAP Phonebook...
Introduction... 1 Installing and Configuring the LDAP Server... 3 OpenLDAP... 3 Installing the OpenLDAP Server... 3 Configuring the OpenLDAP Server... 4 Configuring the LDAPExploreTool2... 8 Microsoft
Lesson Plans LabSim for Microsoft s Implementing a Server 2003 Active Directory Infrastructure
Lesson Plans LabSim for Microsoft s Implementing a Server 2003 Active Directory Infrastructure (Exam 70-294) Table of Contents Course Overview... 2 Section 1.1: Introduction to Active Directory... 3 Section
Active Directory LDAP Quota and Admin account authentication and management
Active Directory LDAP Quota and Admin account authentication and management Version 4.1 Updated July 2014 GoPrint Systems 2014 GoPrint Systems, Inc, All rights reserved. One Annabel Lane, Suite 105 San
The following gives an overview of LDAP from a user's perspective.
LDAP stands for Lightweight Directory Access Protocol, which is a client-server protocol for accessing a directory service. LDAP is a directory service protocol that runs over TCP/IP. The nitty-gritty
Using VBScript to Automate User and Group Administration
Using VBScript to Automate User and Group Administration Exam Objectives in this Chapter: Create and manage groups Create and modify groups by using automation Create and manage user accounts Create and
ILTA 2013 - HAND 6B. Upgrading and Deploying. Windows Server 2012. In the Legal Environment
ILTA 2013 - HAND 6B Upgrading and Deploying Windows Server 2012 In the Legal Environment Table of Contents Purpose of This Lab... 3 Lab Environment... 3 Presenter... 3 Exercise 1 Add Roles and Features...
SchoolBooking LDAP Integration Guide
SchoolBooking LDAP Integration Guide Before you start This guide has been written to help you configure SchoolBooking to connect to your LDAP server. Please treat this document as a reference guide, your
SOFTWARE BEST PRACTICES
1 of 7 Abstract MKS Integrity Server LDAP (Lightweight Directory Access Protocol) implementations vary depending on the environment they are being placed into. The configuration of the corporate LDAP implementation
Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services
Course 6425C: Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services Course Details Course Outline Module 1: Introducing Active Directory Domain Services This module provides
ADMT v3 Migration Guide
ADMT v3 Migration Guide Microsoft Corporation Published: November 2006 Abstract This guide explains how to use the Active Directory Migration Tool version 3 (ADMT v3) to restructure your operating environment.
Introduction to Active Directory Services
Introduction to Active Directory Services Tom Brett A DIRECTORY SERVICE A directory service allow businesses to define manage, access and secure network resources including files, printers, people and
Using LDAP with Sentry Firmware and Sentry Power Manager (SPM)
Using LDAP with Sentry Firmware and Sentry Power Manager (SPM) Table of Contents Purpose LDAP Requirements Using LDAP with Sentry Firmware (GUI) Initiate a Sentry GUI Session Configuring LDAP for Active
Administering Active Directory Administering W2K Server
Administering Active Directory Administering W2K Server (Week 9, Wednesday 3/7/2007) Abdou Illia, Spring 2007 1 Learning Objective Default Domain policies Creating OUs and managing their objects Controlling
PriveonLabs Research. Cisco Security Agent Protection Series:
Cisco Security Agent Protection Series: Enabling LDAP for CSA Management Center SSO Authentication For CSA 5.2 Versions 5.2.0.245 and up Fred Parks Systems Consultant 3/25/2008 2008 Priveon, Inc. www.priveonlabs.com
Configuring and Troubleshooting Windows Server 2008 Active Directory Domain MOC 6425
Configuring and Troubleshooting Windows Server 2008 Active Directory Domain MOC 6425 Course Outline Module 1: Introducing Active Directory Domain Services This module provides an overview of Active Directory
Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services
Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services Course Number: 6425C Course Length: 5 Days Course Overview This five-day course provides in-depth training on implementing,
Integration Guide. SafeNet Authentication Service. Integrating Active Directory Lightweight Services
SafeNet Authentication Service Integration Guide Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013 SafeNet, Inc. All rights reserved. 1 Document Information
Active Directory Infrastructure Design Document
Active Directory Infrastructure Design Document Written By Sainath KEV Microsoft MVP Directory Services Microsoft Author TechNet Magazine, Microsoft Operations Framework Microsoft Speaker - Singapore Document
AD Schema Update IPBrick iportalmais
AD Schema Update IPBrick iportalmais October 2006 2 Copyright c iportalmais All rights reserved. October 2006. The information in this document can be changed without further notice. The declarations,
NE-6425C Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services
NE-6425C Configuring and Troubleshooting Windows Server 2008 Active Domain Services Summary Duration Vendor Audience 5 Days Microsoft IT Professionals Published Level Technology 02 June 2011 200 Windows
Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services
Course 6425B: Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services Length: 5 Days Language(s): English Audience(s): IT Professionals Level: 200 Technology: Windows Server
Course 6425B: Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services
Course 6425B: Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services About this Course This five-day instructor-led course provides to teach Active Directory Technology Specialists
ITCertMaster. http://www.itcertmaster.com. Safe, simple and fast. 100% Pass guarantee! IT Certification Guaranteed, The Easy Way!
ITCertMaster Safe, simple and fast. 100% Pass guarantee! http://www.itcertmaster.com IT Certification Guaranteed, The Easy Way! Exam : 070-640 Title : Windows Server 2008 Active Directory. Configuring
Mailbox Recovery for Microsoft Exchange 2000 Server. Published: August 2000 Updated: July 2002 Applies To: Microsoft Exchange 2000 Server SP3
Mailbox Recovery for Microsoft Exchange 2000 Server Published: August 2000 Updated: July 2002 Applies To: Microsoft Exchange 2000 Server SP3 Copyright The information contained in this document represents
O Reilly Ebooks Your bookshelf on your devices!
O Reilly Ebooks Your bookshelf on your devices! When you buy an ebook through oreilly.com you get lifetime access to the book, and whenever possible we provide it to you in five, DRM-free file formats
Skyward LDAP Launch Kit Table of Contents
04.30.2015 Table of Contents What is LDAP and what is it used for?... 3 Can Cloud Hosted (ISCorp) Customers use LDAP?... 3 What is Advanced LDAP?... 3 Does LDAP support single sign-on?... 4 How do I know
Configuring and Troubleshooting Windows 2008 Active Directory Domain Services
About this Course Configuring and Troubleshooting Windows This five-day instructor-led course provides in-depth training on implementing, configuring, managing and troubleshooting Active Directory Domain
Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services
Active Directory About this Course This five-day instructor-led course provides in-depth training on implementing, configuring, managing and troubleshooting (AD DS) in and R2 environments. It covers core
Automating client deployment
Automating client deployment 1 Copyright Datacastle Corporation 2014. All rights reserved. Datacastle is a registered trademark of Datacastle Corporation. Microsoft Windows is either a registered trademark
MS-6425C - Configuring Windows Server 2008 Active Directory Domain Services
MS-6425C - Configuring Windows Server 2008 Active Directory Domain Services Table of Contents Introduction Audience At Clinic Completion Prerequisites Microsoft Certified Professional Exams Student Materials
TechJam Active Directory Auditing Presenter Matt Warburton Professional Services
TechJam Active Directory Auditing Presenter Matt Warburton Professional Services Objectives Automate Auditing of Active Directory Review an Array of Examples Minimize Security Related Risk Address Compliance
Course 6425C: Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services
www.etidaho.com (208) 327-0768 Course 6425C: Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services 5 Days About this Course This five-day instructor-led course provides in-depth
How To Search For An Active Directory On Goprint Ggprint Goprint.Org (Geoprint) (Georgos4) (Goprint) And Gopprint.Org Gop Print.Org
Active Directory LDAP Configuration TECHNICAL WHITE PAPER OVERVIEW: GS-4 incorporates the LDAP protocol to access, (and import into a GS-4 database) Active Directory user account information, such as a
Administrator s Guide
Administrator s Guide Directory Synchronization Client Websense Cloud Products v1.2 1996 2015, Websense, Inc. All rights reserved. 10900 Stonelake Blvd, 3rd Floor, Austin, TX 78759, USA First published
[MS-FSADSA]: Active Directory Search Authorization Protocol Specification
[MS-FSADSA]: Active Directory Search Authorization Protocol Specification Intellectual Property Rights Notice for Open Specifications Documentation Technical Documentation. Microsoft publishes Open Specifications
6425C - Windows Server 2008 R2 Active Directory Domain Services
Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services Introduction This five-day instructor-led course provides in-depth training on configuring Active Directory Domain Services
Windows Server 2003 Administration Part 1 Lab Manual Presented by
Windows Server 2003 Administration Part 1 Lab Manual Presented by Table of Contents Building and Saving Consoles 3 Installing Terminal Services and Running Remote Administration 4 Using Remote Assistance
Stellar Active Directory Manager
Stellar Active Directory Manager What is the need of Active Directory Manager? Every organization uses Active Directory Services (ADMS) to manage the users working in the organization. This task is mostly
Migrating Active Directory to Windows Server 2012 R2
Migrating Active Directory to Windows Server 2012 R2 Windows Server 2012 R2 Hands-on lab In this lab, you will complete a migration of a Windows Server 2008 R2 domain environment to Windows Server 2012
Documentation. CloudAnywhere. http://www.cloudiway.com. Page 1
Documentation CloudAnywhere http://www.cloudiway.com Page 1 Table of Contents 1 INTRODUCTION 3 2 OVERVIEW 4 2.1 KEY FUNCTIONALITY 4 2.2 PREREQUISITES 5 3 FEATURES 6 3.1 A UNIVERSAL PROVISIONING SOLUTION.
Basic Configuration. Key Operator Tools older products. Program/Change LDAP Server (page 3 of keyop tools) Use LDAP Server must be ON to work
Where to configure: User Tools Basic Configuration Key Operator Tools older products Program/Change LDAP Server (page 3 of keyop tools) Use LDAP Server must be ON to work Administrator Tools newest products
Course 6425C: Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services
Course 6425C: Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services Length: 5 Days Published: June 02, 2011 Language(s): English Audience(s): IT Professionals Level: 200
SonicOS Enhanced 3.2 LDAP Integration with Microsoft Active Directory and Novell edirectory Support
SonicOS Enhanced 3.2 LDAP Integration with Microsoft Active Directory and Novell edirectory Support Document Scope This document describes the integration of SonicOS Enhanced 3.2 with Lightweight Directory
Admin Report Kit for Active Directory
Admin Report Kit for Active Directory Reporting tool for Microsoft Active Directory Enterprise Product Overview Admin Report Kit for Active Directory (ARKAD) is a powerful reporting solution for the Microsoft
Forests, trees, and domains
Active Directory is a directory service used to store information about the network resources across a. An Active Directory (AD) structure is a hierarchical framework of objects. The objects fall into
StarTeam/CaliberRM LDAP QuickStart Manager 2009. Administration Guide
StarTeam/CaliberRM LDAP QuickStart Manager 2009 Administration Guide Borland Software Corporation 8310 N Capital of Texas Bldg 2, Ste 100 Austin, TX 78731 USA http://www.borland.com Borland Software Corporation
ADMT v3.1 Guide: Migrating and Restructuring Active Directory Domains
ADMT v3.1 Guide: Migrating and Restructuring Active Directory Domains Microsoft Corporation Published: July 2008 Authors: Moon Majumdar, Brad Mahugh Editors: Jim Becker, Fran Tooke Abstract This guide
Active Directory Forest Recovery
Active Directory Forest Recovery Contents 1. Introduction 2. Active Directory Components 3. Possible Active Directory Disasters 4. Recovery of User, Group and Organization Unit a. Authoritative Restore
9. Which is the command used to remove active directory from a domain controller? Answer: Dcpromo /forceremoval
1. What is Active Directory schema? Answer: The schema is the Active Directory component that defines all the objects and attributes that the directory service uses to store data. 2. What is global catalog
Restructuring Active Directory Domains Within a Forest
C H A P T E R 1 2 Restructuring Active Directory Domains Within a Forest Restructuring Active Directory directory service domains within a forest with the goal of reducing the number of domains allows
70-640. Microsoft - 70-640 Windows Server 2008 Active Directory, Configuring
Microsoft - 70-640 Windows Server 2008 Active Directory, Configuring 1 QUESTION: 1 You have a single Active Directory domain. All domain controllers run Windows Server 2008 and are configured as DNS servers.
6425C: Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services
6425C: Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services Course Details Course Code: Duration: Notes: 6425C 5 days This course syllabus should be used to determine whether
Windows Server 2003 Active Directory: Perspective
Mary I. Hubley, MaryAnn Richardson Technology Overview 25 September 2003 Windows Server 2003 Active Directory: Perspective Summary The Windows Server 2003 Active Directory lies at the core of the Windows
Address Synchronization Tool Administrator Guide
Address Synchronization Tool Administrator Guide This guide is for systems administrators configuring the Address Synchronization Tool to update the information used by MessageLabs in the provision of
Course 6425C: Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services
Course 6425C: Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services Five Days, Instructor-Led About this course This five-day instructor-led course provides in-depth training
LDAP Directory Integration with Cisco Unity Connection
CHAPTER 6 LDAP Directory Integration with Cisco Unity Connection The Lightweight Directory Access Protocol (LDAP) provides applications like Cisco Unity Connection with a standard method for accessing
Active Directory Objectives
Exam Objectives Active Directory Objectives Exam 70 640: TS: Windows Server 2008 Active Directory, Configuring This certification exam measures your ability to manage Windows Server 2008 Active Directory
Introduction to Directory Services
Introduction to Directory Services Overview This document explains how AirWatch integrates with your organization's existing directory service such as Active Directory, Lotus Domino and Novell e-directory
Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services
Course Code: M6425 Vendor: Microsoft Course Overview Duration: 5 RRP: 2,025 Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services Overview This five-day instructor-led course
Contents Introduction... 3 Introduction to Active Directory Services... 4 Installing and Configuring Active Directory Services...
Contents 1. Introduction... 3 1.1. Setup... 3 2. Introduction to Active Directory Services... 4 3. Installing and Configuring Active Directory Services... 5 3.1. Joining to Domain... 5 3.2. Promoting Member
Windows Server 2012 Directory Partition Containers- A Walk Through
Windows Server 2012 Directory Partition Containers- A Walk Through Introduction: Active Directory Users and Computers form a centralized management console to manage User objects, computer objects, Groups,
Dell KACE K1000 System Management Appliance Version 5.4. Service Desk Administrator Guide
Dell KACE K1000 System Management Appliance Version 5.4 Service Desk Administrator Guide October 2012 2004-2012 Dell Inc. All rights reserved. Reproduction of these materials in any manner whatsoever without
Searching for accepting?
If you have set up a domain controller previously with Windows 2000 Server, or Windows Server 2003, then you would be familiar with the dcpromo.exe command also be used to set up a Domain Controller on
ECAT SWE Exchange Customer Administration Tool Web Interface User Guide Version 6.7
ECAT SWE Exchange Customer Administration Tool SWE - Exchange Customer Administration Tool (ECAT) Table of Contents About this Guide... 3 Audience and Purpose... 3 What is in this Guide?... 3 CA.mail Website...
How To Take Advantage Of Active Directory Support In Groupwise 2014
White Paper Collaboration Taking Advantage of Active Directory Support in GroupWise 2014 Flexibility and interoperability have always been hallmarks for Novell. That s why it should be no surprise that
Troubleshooting Active Directory Server
Proven Practice Troubleshooting Active Directory Server Product(s): IBM Cognos Series 7 Area of Interest: Security Troubleshooting Active Directory Server 2 Copyright Copyright 2008 Cognos ULC (formerly
Lesson Plans LabSim for Microsoft s Managing and Maintaining a Microsoft Windows Server 2003 Environment
Lesson Plans LabSim for Microsoft s Managing and Maintaining a Microsoft Windows Server 2003 Environment (Exam 70-290) Table of Contents Course Overview... 3 Section 0.1: Introduction... 5 Section 0.2:
The. Essential. Guide. to an NDS-to- Active Directory Migration. By David Chernicoff. sponsored by. March 2010 1
Essential The Guide to an NDS-to- Active Directory Migration By David Chernicoff sponsored by March 2010 1 W ith the release of Windows Server 2008 and the latest iteration of Active Directory, many enterprise
Installing Active Directory
Installing Active Directory 119 Installing Active Directory Installing Active Directory is an easy and straightforward process as long as you planned adequately and made the necessary decisions beforehand.
Configuring Sponsor Authentication
CHAPTER 4 Sponsors are the people who use Cisco NAC Guest Server to create guest accounts. Sponsor authentication authenticates sponsor users to the Sponsor interface of the Guest Server. There are five
