<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-25337987</id><updated>2011-11-27T15:49:19.453-08:00</updated><category term='Domain Migration'/><category term='Remove Exchange Properties'/><category term='Global groups'/><category term='logonCount'/><category term='Exchange'/><category term='Schema Extensions'/><category term='mail-box-enabled'/><category term='UPN'/><category term='Group scope'/><category term='Windows 2008 attributes'/><category term='Domain local groups'/><category term='Global Catalogue'/><category term='Active Directory Migration'/><category term='BUILTIN Groups'/><category term='System only'/><category term='Exchange 2007'/><category term='Mailbox Enabled'/><category term='Universal groups'/><category term='Groups'/><category term='lastLogon'/><category term='WADMIgrator'/><category term='Classes'/><category term='Syntax'/><category term='Exchange Schema'/><category term='Attributes'/><category term='User Principle Name'/><category term='userPrincipalName'/><category term='Exchange Attributes'/><category term='Windows 2008'/><category term='Computer2User'/><category term='SIDs'/><title type='text'>Active Directory Attributes</title><subtitle type='html'>Winzero - ADSearch Object Property Attributes For Active Directory.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://adsearch-winzero.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://adsearch-winzero.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Akos</name><uri>http://www.blogger.com/profile/04967051529264150640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_R_ywovcgAHA/SShKj4z6h2I/AAAAAAAAAOA/UAkvQFC6kX4/S220/akos2.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>19</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-25337987.post-9187632752335298843</id><published>2009-02-06T10:26:00.001-08:00</published><updated>2009-02-06T10:28:54.361-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Domain Migration'/><category scheme='http://www.blogger.com/atom/ns#' term='WADMIgrator'/><category scheme='http://www.blogger.com/atom/ns#' term='Active Directory Migration'/><title type='text'>Considering Active Directory Migration?</title><content type='html'>&lt;a href="http://2.bp.blogspot.com/_R_ywovcgAHA/SYyBHJJXynI/AAAAAAAAAQY/8ZXx12ato3o/s1600-h/WADMigrator-95100blk.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 95px; height: 100px;" src="http://2.bp.blogspot.com/_R_ywovcgAHA/SYyBHJJXynI/AAAAAAAAAQY/8ZXx12ato3o/s200/WADMigrator-95100blk.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5299752821222525554" /&gt;&lt;/a&gt;&lt;br /&gt;Whether migrating or restructuring to meet specific economic challenges, undergoing acquisition, mergers or divestitures, Winzero Active Directory Migrator provides the features necessary to meet your evolving needs and budget.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Winzero has released the next solution in Active Directory Migration Challenges - Winzero Active Directory Migrator, ensuring coexistence between migrated and un-migrated users, simplifing the migration processes with automated resource updating and continued support during and after the migration process.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25337987-9187632752335298843?l=adsearch-winzero.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://adsearch-winzero.blogspot.com/feeds/9187632752335298843/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://adsearch-winzero.blogspot.com/2009/02/considering-active-directory-migration.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/9187632752335298843'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/9187632752335298843'/><link rel='alternate' type='text/html' href='http://adsearch-winzero.blogspot.com/2009/02/considering-active-directory-migration.html' title='Considering Active Directory Migration?'/><author><name>Akos</name><uri>http://www.blogger.com/profile/04967051529264150640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_R_ywovcgAHA/SShKj4z6h2I/AAAAAAAAAOA/UAkvQFC6kX4/S220/akos2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_R_ywovcgAHA/SYyBHJJXynI/AAAAAAAAAQY/8ZXx12ato3o/s72-c/WADMigrator-95100blk.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-25337987.post-4760429949311350078</id><published>2008-10-26T09:43:00.000-07:00</published><updated>2008-10-26T09:49:14.856-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Exchange Schema'/><category scheme='http://www.blogger.com/atom/ns#' term='Exchange 2007'/><category scheme='http://www.blogger.com/atom/ns#' term='Exchange'/><category scheme='http://www.blogger.com/atom/ns#' term='Schema Extensions'/><title type='text'>Exchange Server 2007 New Property Sets</title><content type='html'>Property sets in Exchange Server 2007 for attribute grouping enables access control for specific object properties. Property sets use one single Access Control Entry (ACE) instead of an ACE for each individual property.&lt;br /&gt;&lt;br /&gt;Exchange Server 2007 creates two new property sets exclusively for itself and doesn’t use existing Active Directory property sets.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Exchange Server 2007 SP1 Schema Extensions&lt;/strong&gt;&lt;br /&gt;Exchange Server 2007 SP1 comes with a lot of additional Schema extensions: &lt;br /&gt;&lt;br /&gt;ms-Exch-Foreign-Forest-Public-Folder-Admin-USG-Sid,&lt;br /&gt;&lt;SchemaContainerDN&gt; &lt;br /&gt;ms-Exch-Internal-NLB-Bypass-Host-Name,&lt;br /&gt;&lt;SchemaContainerDN&gt; &lt;br /&gt;ms-Exch-Mobile-Additional-Flags,&lt;br /&gt;&lt;SchemaContainerDN&gt; &lt;br /&gt;ms-Exch-Mobile-Allow-Bluetooth,&lt;br /&gt;&lt;SchemaContainerDN&gt; &lt;br /&gt;ms-Exch-Mobile-Allow-SMIME-Encryption-Algorithm-Negotiation,&lt;br /&gt;&lt;SchemaContainerDN&gt; &lt;br /&gt;ms-Exch-Mobile-Approved-Application-List,&lt;br /&gt;&lt;SchemaContainerDN&gt; &lt;br /&gt;ms-Exch-Mobile-Max-Calendar-Age-Filter,&lt;br /&gt;&lt;SchemaContainerDN&gt; &lt;br /&gt;ms-Exch-Mobile-Max-Email-Age-Filter,&lt;br /&gt;&lt;SchemaContainerDN&gt; &lt;br /&gt;ms-Exch-Mobile-Max-Email-Body-Truncation-Size,&lt;br /&gt;&lt;SchemaContainerDN&gt; &lt;br /&gt;ms-Exch-Mobile-Max-Email-HTML-Body-Truncation-Size,&lt;br /&gt;&lt;SchemaContainerDN&gt; &lt;br /&gt;ms-Exch-Mobile-Min-Device-Password-Complex-Characters,&lt;br /&gt;&lt;SchemaContainerDN&gt; &lt;br /&gt;ms-Exch-Mobile-Require-Encryption-SMIME-Algorithm,&lt;br /&gt;&lt;SchemaContainerDN&gt; &lt;br /&gt;ms-Exch-Mobile-Require-Signed-SMIME-Algorithm,&lt;br /&gt;&lt;SchemaContainerDN&gt; &lt;br /&gt;ms-Exch-Mobile-Unapproved-In-ROM-Application-List,&lt;br /&gt;&lt;SchemaContainerDN&gt; &lt;br /&gt;ms-Exch-Standby-Copy-Machines,&lt;br /&gt;&lt;SchemaContainerDN&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25337987-4760429949311350078?l=adsearch-winzero.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://adsearch-winzero.blogspot.com/feeds/4760429949311350078/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://adsearch-winzero.blogspot.com/2008/10/exchange-server-2007-new-property-sets.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/4760429949311350078'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/4760429949311350078'/><link rel='alternate' type='text/html' href='http://adsearch-winzero.blogspot.com/2008/10/exchange-server-2007-new-property-sets.html' title='Exchange Server 2007 New Property Sets'/><author><name>Akos</name><uri>http://www.blogger.com/profile/04967051529264150640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_R_ywovcgAHA/SShKj4z6h2I/AAAAAAAAAOA/UAkvQFC6kX4/S220/akos2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-25337987.post-4117113811682236873</id><published>2008-09-02T13:25:00.000-07:00</published><updated>2008-09-02T13:29:19.263-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Mailbox Enabled'/><category scheme='http://www.blogger.com/atom/ns#' term='Remove Exchange Properties'/><category scheme='http://www.blogger.com/atom/ns#' term='Exchange Attributes'/><category scheme='http://www.blogger.com/atom/ns#' term='Exchange'/><title type='text'>Completely Removing a Mailbox Enabled User's Mailbox</title><content type='html'>If an object is a mailbox enabled user with a valid mailbox, the "Delete Mailbox" option will be available only if there is a mailbox (so a distribution list would have a "Remove email address" option instead). &lt;br /&gt;&lt;br /&gt;The "Remove Exchange Attributes" option is available for ANY type of recipient object, mail enabled or not. This option is extremely useful when there is a need to "clear" the attributes in case that some of them were damaged or not valid for some reason. Let's say there is a mailbox enabled user that had some of his attributes changed by some process, and because of that, you cannot use the "Delete Mailbox" option. You can always run AdSearch and "clear out" the values so you can start fresh with mailbox enabling that user again.&lt;br /&gt;&lt;br /&gt;Remove Exchange Attributes removes the following attributes as long as they actually exist as available attributes of that schema object: &lt;br /&gt;&lt;br /&gt;You can use ADSearch to report the status of each attribute by copying the list below and adding it to the objects attribute properties.&lt;br /&gt;&lt;br /&gt;adminDisplayName &lt;br /&gt;altRecipient &lt;br /&gt;authOrig &lt;br /&gt;autoReplyMessage (ILS Settings) &lt;br /&gt;deletedItemFlags &lt;br /&gt;delivContLength &lt;br /&gt;deliverAndRedirect &lt;br /&gt;displayNamePrintable &lt;br /&gt;dLMemDefault &lt;br /&gt;dLMemRejectPerms &lt;br /&gt;dLMemSubmitPerms &lt;br /&gt;extensionAttribute1 &lt;br /&gt;extensionAttribute10 &lt;br /&gt;extensionAttribute11 &lt;br /&gt;extensionAttribute12 &lt;br /&gt;extensionAttribute13 &lt;br /&gt;extensionAttribute14 &lt;br /&gt;extensionAttribute15 &lt;br /&gt;extensionAttribute2 &lt;br /&gt;extensionAttribute3 &lt;br /&gt;extensionAttribute4 &lt;br /&gt;extensionAttribute5 &lt;br /&gt;extensionAttribute6 &lt;br /&gt;extensionAttribute7 &lt;br /&gt;extensionAttribute8 &lt;br /&gt;extensionAttribute9 &lt;br /&gt;folderPathname (Outlook Web Access Server) &lt;br /&gt;garbageCollPeriod &lt;br /&gt;homeMDB (Exchange Mailbox Store) &lt;br /&gt;homeMTA &lt;br /&gt;internetEncoding &lt;br /&gt;legacyExchangeDN &lt;br /&gt;mail (E-Mail Address) &lt;br /&gt;mailNickname (Alias) &lt;br /&gt;mAPIRecipient &lt;br /&gt;mDBOverHardQuotaLimit &lt;br /&gt;mDBOverQuotaLimit &lt;br /&gt;mDBStorageQuota &lt;br /&gt;mDBUseDefaults &lt;br /&gt;msExchADCGlobalNames &lt;br /&gt;msExchControllingZone &lt;br /&gt;msExchExpansionServerName &lt;br /&gt;msExchFBURL &lt;br /&gt;msExchHideFromAddressLists &lt;br /&gt;msExchHomeServerName (Exchange Home Server) &lt;br /&gt;msExchMailboxGuid &lt;br /&gt;msExchMailboxSecurityDescriptor &lt;br /&gt;msExchPoliciesExcluded &lt;br /&gt;msExchPoliciesIncluded &lt;br /&gt;msExchRecipLimit &lt;br /&gt;msExchResourceGUID &lt;br /&gt;protocolSettings &lt;br /&gt;proxyAddresses (Proxy Addresses) &lt;br /&gt;publicDelegates &lt;br /&gt;securityProtocol &lt;br /&gt;showInAddressBook &lt;br /&gt;submissionContLength &lt;br /&gt;targetAddress &lt;br /&gt;textEncodedORAddress &lt;br /&gt;unauthOrig&lt;br /&gt;&lt;br /&gt;In addition to removing the attributes above, the Delete Mailbox option also removes the mailbox information from the dsaccess cache. Note that this actually leaves the mailbox in place with the expectation that the mailbox cleanup task will take care of it at the appropriate time. So the mailbox is actually NOT deleted (purged) from the Information Store as part of this process. Although it will be purged by the mailbox cleanup task later, or as specified by the "Deletion settings" for mailboxes on the database's Limits tab in ESM.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25337987-4117113811682236873?l=adsearch-winzero.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://adsearch-winzero.blogspot.com/feeds/4117113811682236873/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://adsearch-winzero.blogspot.com/2008/09/completely-removing-mailbox-enabled.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/4117113811682236873'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/4117113811682236873'/><link rel='alternate' type='text/html' href='http://adsearch-winzero.blogspot.com/2008/09/completely-removing-mailbox-enabled.html' title='Completely Removing a Mailbox Enabled User&apos;s Mailbox'/><author><name>Akos</name><uri>http://www.blogger.com/profile/04967051529264150640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_R_ywovcgAHA/SShKj4z6h2I/AAAAAAAAAOA/UAkvQFC6kX4/S220/akos2.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-25337987.post-3213750751400499538</id><published>2008-04-16T14:54:00.000-07:00</published><updated>2008-04-16T15:06:44.004-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Groups'/><category scheme='http://www.blogger.com/atom/ns#' term='SIDs'/><category scheme='http://www.blogger.com/atom/ns#' term='BUILTIN Groups'/><title type='text'>Windows Groups</title><content type='html'>&lt;strong&gt;Account Operators&lt;/strong&gt;&lt;br /&gt;SID: S-1-5-32-548&lt;br /&gt;TYPE: BUILTIN&lt;br /&gt;Exists only on domain controllers. By default, the group has no members. By default, Account Operators have permission to create, modify, and delete accounts for users, groups, and computers in all containers and organizational units (OUs) of Active Directory except the Builtin container and the Domain Controllers OU. Account Operators do not have permission to modify the Administrators and Domain Admins groups, nor do they have permission to modify the accounts for members of those groups. &lt;br /&gt; &lt;br /&gt;&lt;strong&gt;Administrators&lt;/strong&gt;&lt;br /&gt;SID: S-1-5-32-544&lt;br /&gt;TYPE: BUILTIN&lt;br /&gt;After the initial installation of the operating system, the only member of the group is the Administrator account. When a computer joins a domain, the Domain Admins group is added to the Administrators group. When a server becomes a domain controller, the Enterprise Admins group also is added to the Administrators group. The Administrators group has built-in capabilities that give its members full control over the system. The group is the default owner of any object that is created by a member of the group. &lt;br /&gt; &lt;br /&gt;&lt;strong&gt;Authenticated Users&lt;/strong&gt;&lt;br /&gt;SID: S-1-5-11&lt;br /&gt;A group that includes all users whose identities were authenticated when they logged on. Membership is controlled by the operating system. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Backup Operators &lt;/strong&gt;&lt;br /&gt;SID: S-1-5-32-551&lt;br /&gt;TYPE: BUILTIN&lt;br /&gt;By default, the group has no members. Backup Operators can back up and restore all files on a computer, regardless of the permissions that protect those files. Backup Operators also can log on to the computer and shut it down. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Batch&lt;/strong&gt; &lt;br /&gt;SID: S-1-5-3&lt;br /&gt;A group that implicitly includes all users who have logged on through a batch queue facility such as task scheduler jobs. Membership is controlled by the operating system. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Cert Publishers &lt;/strong&gt;&lt;br /&gt;SID: S-1-5-domain-517&lt;br /&gt;TYPE: Global Group&lt;br /&gt;Includes all computers that are running an enterprise certificate authority. Cert Publishers are authorized to publish certificates for User objects in Active Directory. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Cert Requesters&lt;/strong&gt;&lt;br /&gt;SID: S-1-5-domain-517&lt;br /&gt;TYPE: Domain Local Group&lt;br /&gt;Members can request certificates&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Creator Group &lt;/strong&gt;&lt;br /&gt;SID: S-1-3-1&lt;br /&gt;A placeholder in an inheritable ACE. When the ACE is inherited, the system replaces this SID with the SID for the primary group of the object's current owner. The primary group is used only by the POSIX subsystem. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Dialup&lt;/strong&gt;&lt;br /&gt;SID: S-1-5-1&lt;br /&gt;A group that implicitly includes all users who are logged on to the system through a dial-up connection. Membership is controlled by the operating system. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Distributed COM Users&lt;/strong&gt;&lt;br /&gt;SID: S-1-5-32-562&lt;br /&gt;TYPE: BUILTIN&lt;br /&gt;An alias. A group for COM to provide computerwide access controls that govern access to all call, activation, or launch requests on the computer.&lt;br /&gt; &lt;br /&gt;&lt;strong&gt;Domain Admins&lt;/strong&gt;&lt;br /&gt;SID: S-1-5-domain-512&lt;br /&gt;TYPE: Global Group&lt;br /&gt;Members are authorized to administer the domain. By default, the Domain Admins group is a member of the Administrators group on all computers that have joined a domain, including the domain controllers. Domain Admins is the default owner of any object that is created in the domain's Active Directory by any member of the group. If members of the group create other objects, such as files, the default owner is the Administrators group. &lt;br /&gt; &lt;br /&gt;&lt;strong&gt;Domain Computers&lt;/strong&gt;&lt;br /&gt;SID: S-1-5-domain-515&lt;br /&gt;TYPE: Global Group&lt;br /&gt;Includes all computers that have joined the domain, excluding domain controllers. &lt;br /&gt; &lt;br /&gt;&lt;strong&gt;Domain Controllers&lt;/strong&gt;&lt;br /&gt;SID: S-1-5-domain-516&lt;br /&gt;TYPE: Global Group&lt;br /&gt;Includes all domain controllers in the domain. New domain controllers are added to this group automatically. &lt;br /&gt; &lt;br /&gt;&lt;strong&gt;Domain Guests&lt;/strong&gt;&lt;br /&gt;SID: S-1-5-domain-514&lt;br /&gt;TYPE: Global Group&lt;br /&gt;By default, has only one member, the domain's built-in Guest account. &lt;br /&gt; &lt;br /&gt;&lt;strong&gt;Domain Users&lt;/strong&gt;&lt;br /&gt;SID: S-1-5-domain-513&lt;br /&gt;TYPE: Global Group&lt;br /&gt;By default, includes all user accounts in a domain. When you create a user account in a domain, it is added to this group automatically. &lt;br /&gt; &lt;br /&gt;&lt;strong&gt;Enterprise Admins&lt;/strong&gt;&lt;br /&gt;SID: S-1-5-root domain-519&lt;br /&gt;TYPE: Universal Group&lt;br /&gt;A group that exists only in the root domain of an Active Directory forest of domains. It is a universal group if the domain is in native mode, a global group if the domain is in mixed mode. The group is authorized to make forest-wide changes in Active Directory, such as adding child domains. By default, the only member of the group is the Administrator account for the forest root domain. &lt;br /&gt; &lt;br /&gt;&lt;strong&gt;Enterprise Controllers&lt;/strong&gt;&lt;br /&gt;SID: S-1-5-9&lt;br /&gt;A group that includes all domain controllers an Active Directory directory service forest of domains. Membership is controlled by the operating system. &lt;br /&gt; &lt;br /&gt;&lt;strong&gt;Everyone&lt;/strong&gt;&lt;br /&gt;SID: S-1-1-0&lt;br /&gt;A group that includes all users, even anonymous users and guests. Membership is controlled by the operating system.&lt;br /&gt; &lt;br /&gt;&lt;strong&gt;Group Policy Creators Owners &lt;/strong&gt;&lt;br /&gt;SID: S-1-5-domain-520&lt;br /&gt;TYPE: Global Group&lt;br /&gt;Authorized to create new Group Policy objects in Active Directory. By default, the only member of the group is Administrator. The default owner of a new Group Policy object is usually the user who created it. If the user is a member of Administrators or Domain Admins, all objects that are created by the user are owned by the group. Owners have full control of the objects they own. &lt;br /&gt; &lt;br /&gt;&lt;strong&gt;Guests&lt;/strong&gt;&lt;br /&gt;SID: S-1-5-32-546&lt;br /&gt;TYPE BUILTIN&lt;br /&gt;By default, the only member is the Guest account. The Guests group allows occasional or one-time users to log on with limited privileges to a computer's built-in Guest account. &lt;br /&gt; &lt;br /&gt;&lt;strong&gt;HelpServicesGroup&lt;/strong&gt;&lt;br /&gt;Group for the Help and Support Center&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Incoming Forest Trust Builders&lt;/strong&gt;&lt;br /&gt;SID: S-1-5-32-557&lt;br /&gt;TYPE: BUILTIN &lt;br /&gt;An alias. Members of this group can create incoming, one-way trusts to this forest.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Interactive&lt;/strong&gt;&lt;br /&gt;SID: S-1-5-4&lt;br /&gt;A group that includes all users who have logged on interactively. Membership is controlled by the operating system.  &lt;br /&gt; &lt;br /&gt;&lt;strong&gt;Network&lt;/strong&gt;&lt;br /&gt;SID: S-1-5-2&lt;br /&gt;A group that implicitly includes all users who are logged on through a network connection. Membership is controlled by the operating system. &lt;br /&gt; &lt;br /&gt;&lt;strong&gt;Network Configuration Operators&lt;/strong&gt;&lt;br /&gt;SID: S-1-5-32-556&lt;br /&gt;TYPE: BUILTIN &lt;br /&gt;An alias. Members in this group can have some administrative privileges to manage configuration of networking features.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Performance Monitor Users&lt;/strong&gt;&lt;br /&gt;SID: S-1-5-32-558&lt;br /&gt;TYPE: BUILTIN&lt;br /&gt;An alias. Members of this group have remote access to monitor this computer.  &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Performance Log Users&lt;/strong&gt;&lt;br /&gt;SID: S-1-5-32-559&lt;br /&gt;TYPE: BUILTIN&lt;br /&gt;An alias. Members of this group have remote access to schedule logging of performance counters on this computer.  &lt;br /&gt; &lt;br /&gt;&lt;strong&gt;Power Users&lt;/strong&gt;&lt;br /&gt;SID: S-1-5-32-548&lt;br /&gt;TYPE: BUILTIN&lt;br /&gt;By default, the group has no members. This group does not exist on domain controllers. Power Users can create local users and groups; modify and delete accounts that they have created; and remove users from the Power Users, Users, and Guests groups. Power Users also can install most applications; create, manage, and delete local printers; and create and delete file shares.&lt;br /&gt; &lt;br /&gt;&lt;strong&gt;Pre-Windows 2000 Compatible Access&lt;/strong&gt;&lt;br /&gt;SID: S-1-5-32-554&lt;br /&gt;A backward compatibility group which allows read access on all users and groups in the domain&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Principal Self or Self&lt;/strong&gt;&lt;br /&gt;SID: S-1-5-10&lt;br /&gt;A placeholder in an ACE on a user, group, or computer object in Active Directory. When you grant permissions to Principal Self, you grant them to the security principal represented by the object. During an access check, the operating system replaces the SID for Principal Self with the SID for the security principal represented by the object. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Print Operators&lt;/strong&gt;&lt;br /&gt;SID: S-1-5-32-550&lt;br /&gt;TYPE: BUILTIN&lt;br /&gt;Exists only on domain controllers. By default, the only member is the Domain Users group. Print Operators can manage printers and document queues.&lt;br /&gt; &lt;br /&gt;&lt;strong&gt;RAS and IAS Servers&lt;/strong&gt;&lt;br /&gt;SID: S-1-5-domain-533&lt;br /&gt;TYPE: Domain Local Group&lt;br /&gt;By default, this group has no members. Computers that are running the Routing and Remote Access service are added to the group automatically. Members of this group have access to certain properties of User objects, such as Read Account Restrictions, Read Logon Information, and Read Remote Access Information. &lt;br /&gt; &lt;br /&gt;&lt;strong&gt;Remote Desktop Users&lt;/strong&gt;&lt;br /&gt;SID: S-1-5-32-555&lt;br /&gt;Members in this group are granted the right to logon remotely&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Replicators&lt;/strong&gt;&lt;br /&gt;SID: S-1-5-32-552&lt;br /&gt;Windows NT domains, this group is called Replicators and is used by the directory replication service. In 2K/XP the group is present but is not used.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Schema Admins&lt;/strong&gt;&lt;br /&gt;SID: S-1-5-root domain-518&lt;br /&gt;TYPE: Universal Group&lt;br /&gt;A group that exists only in the root domain of an Active Directory forest of domains. It is a universal group if the domain is in native mode , a global group if the domain is in mixed mode . The group is authorized to make schema  changes in Active Directory. By default, the only member of the group is the Administrator account for the forest root domain. &lt;br /&gt; &lt;br /&gt;&lt;strong&gt;Server Operators&lt;/strong&gt;&lt;br /&gt;SID: S-1-5-32-549&lt;br /&gt;TYPE: BUILTIN&lt;br /&gt;Exists only on domain controllers. By default, the group has no members. Server Operators can log on to a server interactively; create and delete network shares; start and stop services; back up and restore files; format the hard disk of the computer; and shut down the computer. &lt;br /&gt; &lt;br /&gt;&lt;strong&gt;Service&lt;/strong&gt;&lt;br /&gt;SID: S-1-5-6&lt;br /&gt;A group that includes all security principals that have logged on as a service. Membership is controlled by the operating system. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Terminal Server License Servers&lt;/strong&gt;&lt;br /&gt;SID: S-1-5-32-561&lt;br /&gt;TYPE: BUILTIN &lt;br /&gt;An alias. A group for Terminal Server License Servers. When Windows Server 2003 Service Pack 1 is installed, a new local group is created.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Terminal Server Users&lt;/strong&gt;&lt;br /&gt;SID: S-1-5-13&lt;br /&gt;TYPE: BUILTIN &lt;br /&gt;A group that includes all users who have logged on to a Terminal Services server. Membership is controlled by the operating system.&lt;br /&gt; &lt;br /&gt;&lt;strong&gt;Users&lt;/strong&gt; &lt;br /&gt;SID: S-1-5-32-545&lt;br /&gt;TYPE: BUILTIN&lt;br /&gt;After the initial installation of the operating system, the only member is the Authenticated Users group. When a computer joins a domain, the Domain Users group is added to the Users group on the computer. Users can perform tasks such as running applications, using local and network printers, shutting down the computer, and locking the computer. Users can install applications that only they are allowed to use if the installation program of the application supports per-user installation.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Windows Authorization Access Group&lt;/strong&gt;&lt;br /&gt;SID: S-1-5-32-560&lt;br /&gt;TYPE: BUILTIN&lt;br /&gt;An alias. Members of this group have access to the computed tokenGroupsGlobalAndUniversal attribute on User objects.&lt;br /&gt;&lt;br /&gt;To better understand, report or manage Windows groups see: &lt;a href="http://www.winzero.ca/GroupManagerPlus.htm"&gt;Winzero GroupManagerPlus&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25337987-3213750751400499538?l=adsearch-winzero.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://adsearch-winzero.blogspot.com/feeds/3213750751400499538/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://adsearch-winzero.blogspot.com/2008/04/windows-groups.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/3213750751400499538'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/3213750751400499538'/><link rel='alternate' type='text/html' href='http://adsearch-winzero.blogspot.com/2008/04/windows-groups.html' title='Windows Groups'/><author><name>Akos</name><uri>http://www.blogger.com/profile/04967051529264150640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_R_ywovcgAHA/SShKj4z6h2I/AAAAAAAAAOA/UAkvQFC6kX4/S220/akos2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-25337987.post-7120547149039218380</id><published>2008-02-25T16:23:00.000-08:00</published><updated>2008-02-25T16:35:23.439-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Windows 2008 attributes'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows 2008'/><category scheme='http://www.blogger.com/atom/ns#' term='Attributes'/><title type='text'>New Attributes in Windows 2008</title><content type='html'>&lt;strong&gt;ms-DS-AuthenticatedAt-DC&lt;/strong&gt;&lt;br /&gt;Forward link for ms-DS-AuthenticatedTo-Accountlist; for a User, identifies which DC a user has authenticated to&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-AuthenticatedTo-Accountlist&lt;/strong&gt;&lt;br /&gt;Back link for ms-DS-AuthenticatedAt-DC; for a Computer, identifies which users have authenticated to this Computer&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Az-Object-Guid&lt;/strong&gt;&lt;br /&gt;The unique and portable identifier of AzMan objects&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Az-Generic-Data&lt;/strong&gt;&lt;br /&gt;AzMan specific generic data&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-isGC&lt;/strong&gt;&lt;br /&gt;For a Directory instance (DSA), Identifies the state of the Global Catalogue on the DSA&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-isRODC&lt;/strong&gt;&lt;br /&gt;For a Directory instance (DSA), Identifies whether the DSA is a Read-Only DSA&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Maximum-Password-Age&lt;/strong&gt;&lt;br /&gt;Maximum password age for user accounts.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Minimum-Password-Age&lt;/strong&gt;&lt;br /&gt;Minimum password age for user accounts.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Minimum-Password-Length&lt;/strong&gt;&lt;br /&gt;Minimum password length for user accounts.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Password-History-Length&lt;/strong&gt;&lt;br /&gt;Password history length for user accounts.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Password-Complexity-Enabled&lt;/strong&gt;&lt;br /&gt;Password complexity status for user accounts.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Password-Reversible-Encryption-Enabled&lt;/strong&gt;&lt;br /&gt;Password reversible encryption status for user accounts.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Lockout-Observation-Window&lt;/strong&gt;&lt;br /&gt;Observation window for lockout of user accounts.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Lockout-Duration&lt;/strong&gt;&lt;br /&gt;Duration of lockout for locked out user accounts.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Lockout-Threshold&lt;/strong&gt;&lt;br /&gt;Lockout threshold for user accounts&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-PSO-Applies-To&lt;/strong&gt;&lt;br /&gt;Links to objects that this password settings object applies to.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-PSO-Applied&lt;/strong&gt;&lt;br /&gt;Password settings object applied to this object.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Resultant-PSO&lt;/strong&gt;&lt;br /&gt;Resultant password settings object applied to this object.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Password-Settings-Precedence&lt;/strong&gt;&lt;br /&gt;Password settings precedence.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-NC-Type&lt;/strong&gt;&lt;br /&gt;A bit field that maintains information about aspects of a NC replica that is relevant to replication.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Phonetic-First-Name&lt;/strong&gt;&lt;br /&gt;Contains the phonetic given name or first name of the person.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Phonetic-Last-Name&lt;/strong&gt;&lt;br /&gt;Contains the phonetic last name of the person.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Phonetic-Department&lt;/strong&gt;&lt;br /&gt;Contains the phonetic department name where the person works.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Phonetic-Company-Name&lt;/strong&gt;&lt;br /&gt;Contains the phonetic company name where the person works.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Phonetic-Display-Name&lt;/strong&gt;&lt;br /&gt;The phonetic display name of an object. In the absence of a phonetic display name the existing display name is used.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-HAB-Seniority-Index&lt;/strong&gt;&lt;br /&gt;Contains the seniority index as applied by the organization where the person works.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Promotion-Settings&lt;/strong&gt;&lt;br /&gt;For a Computer, contains a XML string to be used for delegated DSA promotion&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-SiteName&lt;/strong&gt;&lt;br /&gt;For a Directory instance (DSA), Identifies the site name that contains the DSA&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Supported-Encryption-Types&lt;/strong&gt;&lt;br /&gt;The encryption algorithms supported by user, computer or trust accounts. The KDC uses this information while generating a service ticket for this account. Services/Computers may automatically update this attribute on their respective accounts in Active Directory, and therefore need write access to this attribute.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Principal-Name&lt;/strong&gt;&lt;br /&gt;Account name for the security principal (constructed).&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-NC-RO-Replica-Locations&lt;/strong&gt;&lt;br /&gt;A linked attribute on a cross ref object for a partition. This attribute lists the DSA instances which should host the partition in a read-only manner.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-NC-RO-Replica-Locations-BL&lt;/strong&gt;&lt;br /&gt;Back link attribute for ms-DS-NC-RO-Replica-Locations&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-User-Password-Expiry-Time-Computed&lt;/strong&gt;&lt;br /&gt;Contains the expiry time for the user's current password&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-KrbTgt-Link&lt;/strong&gt;&lt;br /&gt;For a computer, Identifies the user object (krbtgt), acting as the domain or secondary domain master secret. Depends on which domain or secondary domain the computer resides in.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Revealed-Users&lt;/strong&gt;&lt;br /&gt;For a Directory instance (DSA), Identifies the user objects whose secrets have been disclosed to that instance&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Has-Full-Replica-NCs&lt;/strong&gt;&lt;br /&gt;For a Directory instance (DSA), identifies the partitions held as full replicas&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Never-Reveal-Group&lt;/strong&gt;&lt;br /&gt;For a Directory instance (DSA), identifies the security group whose users will never have their secrets disclosed to that instance&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Reveal-OnDemand-Group&lt;/strong&gt;&lt;br /&gt;For a Directory instance (DSA), identifies the security group whose users may have their secrets disclosed to that instance&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Secondary-KrbTgt-Number&lt;/strong&gt;&lt;br /&gt;For a user object (krbtgt), acting as a secondary domain master secret, identifies the protocol identification number associated with the secondary domain.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Revealed-DSAs&lt;/strong&gt;&lt;br /&gt;Back link for ms-DS-Revealed-Users; for a user, identifies which Directory instances (DSA) hold that user's secret&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-KrbTgt-Link-BL&lt;/strong&gt;&lt;br /&gt;Back link for ms-DS-KrbTgt-Link; for a user object (krbtgt) acting as a domain or secondary domain master secret, identifies which computers are in that domain or secondary domain&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Is-Full-Replica-For&lt;/strong&gt;&lt;br /&gt;Back link for ms-Ds-Has-Full-Replica-NCs; for a partition root object, identifies which Directory instances (DSA) hold that partition as a full replica &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Is-Domain-For&lt;/strong&gt;&lt;br /&gt;Back link for ms-DS-Has-Domain-NCs; for a partition root object, identifies which Directory instances (DSA) hold that partition as their primary domain&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Is-Partial-Replica-For&lt;/strong&gt;&lt;br /&gt;Back link for has-Partial-Replica-NCs; for a partition root object, identifies which Directory instances (DSA) hold that partition as a partial replica&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Is-User-Cachable-At-Rodc&lt;/strong&gt;&lt;br /&gt;For a Read-only (RO) directory Instance (DSA) identifies whether the specified user's secrets are cacheable&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Revealed-List&lt;/strong&gt;&lt;br /&gt;For a Directory instance (DSA), Identifies the user objects whose secrets have been disclosed to that instance&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Revealed-List-BL&lt;/strong&gt;&lt;br /&gt;Back link attribute for ms-DS-Revealed-List.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Last-Successful-Interactive-Logon-Time&lt;/strong&gt;&lt;br /&gt;The time that the correct password was presented during a C-A-D logon.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Last-Failed-Interactive-Logon-Time&lt;/strong&gt;&lt;br /&gt;The time that an incorrect password was presented during a C-A-D logon.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Failed-Interactive-Logon-Count&lt;/strong&gt;&lt;br /&gt;The total number of failed interactive logons since this feature was turned on.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Failed-Interactive-Logon-Count-At-Last-Successful-Logon&lt;/strong&gt;&lt;br /&gt;The total number of failed interactive logons up until the last successful C-A-D logon.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DFSR-Priority&lt;/strong&gt;&lt;br /&gt;Priority level&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DFSR-DeletedPath&lt;/strong&gt;&lt;br /&gt;Full path of the Deleted directory&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DFSR-DeletedSizeInMb&lt;/strong&gt;&lt;br /&gt;Size of the Deleted directory in MB&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DFSR-ReadOnly&lt;/strong&gt;&lt;br /&gt;Specify whether the content is read-only or read-write&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DFSR-CachePolicy&lt;/strong&gt;&lt;br /&gt;On-demand cache policy options&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DFSR-MinDurationCacheInMin&lt;/strong&gt;&lt;br /&gt;Minimum time in minutes before truncating files&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DFSR-MaxAgeInCacheInMin&lt;/strong&gt;&lt;br /&gt;Maximum time in minutes to keep files in full form&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-FVE-RecoveryPassword&lt;/strong&gt;&lt;br /&gt;This attribute contains the password required to recover a Full Volume&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-FVE-VolumeGuid&lt;/strong&gt;&lt;br /&gt;This attribute contains the GUID that is associated with the Bit locker-supported volume&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-FVE-KeyPackage&lt;/strong&gt;&lt;br /&gt;This attribute contains a volume's Bit locker encryption key, secured by the corresponding password.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-FVE-RecoveryGuid&lt;/strong&gt;&lt;br /&gt;This attribute contains the GUID associated with a Full Volume Encryption (FVE) recovery password.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-TPM-OwnerInformation&lt;/strong&gt;&lt;br /&gt;This attribute contains the owner information for a particular TPM.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-net-ieee-80211-GP-PolicyGUID&lt;/strong&gt;&lt;br /&gt;This attribute contains a GUID which identifies a specific 802.11 group policy object on the domain.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-net-ieee-80211-GP-PolicyData&lt;/strong&gt;&lt;br /&gt;This attribute contains all of the settings and data which comprise a group policy configuration for 802.11 wireless networks.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-net-ieee-80211-GP-PolicyReserved&lt;/strong&gt;&lt;br /&gt;Reserved for future use&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-net-ieee-8023-GP-PolicyGUID&lt;/strong&gt;&lt;br /&gt;This attribute contains a GUID which identifies a specific 802.3 group policy object on the domain.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-net-ieee-8023-GP-PolicyData&lt;/strong&gt;&lt;br /&gt;This attribute contains all of the settings and data which comprise a group policy configuration for 802.3 wired networks.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-net-ieee-8023-GP-PolicyReserved&lt;/strong&gt;&lt;br /&gt;Reserved for future use&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-PKI-RoamingTimeStamp&lt;/strong&gt;&lt;br /&gt;Time stamp for last change to roaming tokens&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-PKI-DPAPIMasterKeys&lt;/strong&gt;&lt;br /&gt;Storage of encrypted DPAPI Master Keys for user&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-PKI-AccountCredentials&lt;/strong&gt;&lt;br /&gt;Storage of encrypted user credential token blobs for roaming&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-RADIUS-FramedInterfaceId&lt;/strong&gt;&lt;br /&gt;This Attribute indicates the IPv6 interface identifier to be configured for the user.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-RADIUS-SavedFramedInterfaceId&lt;/strong&gt;&lt;br /&gt;This Attribute indicates the IPv6 interface identifier to be configured for the user.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-RADIUS-FramedIpv6Prefix&lt;/strong&gt;&lt;br /&gt;This Attribute indicates an IPv6 prefix (and corresponding route) to be configured for the user.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-RADIUS-SavedFramedIpv6Prefix&lt;/strong&gt;&lt;br /&gt;This Attribute indicates an IPv6 prefix (and corresponding route) to be configured for the user.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-RADIUS-FramedIpv6Route&lt;/strong&gt;&lt;br /&gt;This Attribute provides routing information to be configured for the user on the NAS.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-RADIUS-SavedFramedIpv6Route&lt;/strong&gt;&lt;br /&gt;This Attribute provides routing information to be configured for the user on the NAS.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;SAM-Domain-Updates&lt;/strong&gt;&lt;br /&gt;Contains a bitmask of performed SAM operations on active directory&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-TS-Profile-Path&lt;/strong&gt;&lt;br /&gt;Terminal Services Profile Path specifies a roaming or mandatory profile path to use when the user logs on to the Terminal Server. The profile path is in the following network path format: \\servername\profiles folder name\username&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-TS-Home-Directory&lt;/strong&gt;&lt;br /&gt;Terminal Services Home Directory specifies the Home directory for the user. Each user on a Terminal Server has a unique home directory. This ensures that application information is stored separately for each user in a multi-user environment. To set a home directory on the local computer, specify a local path; for example, C:\Path. To set a home directory in a network environment, you must first set the TerminalServicesHomeDrive property, and then set this property to a UNC path.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-TS-Home-Drive&lt;/strong&gt;&lt;br /&gt;Terminal Services Home Drive specifies a Home drive for the user. In a network environment, this property is a string containing a drive specification (a drive letter followed by a colon) to which the UNC path specified in the TerminalServicesHomeDirectory property is mapped. To set a home directory in a network environment, you must first set this property and then set the TerminalServicesHomeDirectory property.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-TS-Allow-Logon&lt;/strong&gt;&lt;br /&gt;Terminal Services Allow Logon specifies whether the user is allowed to log on to the Terminal Server. The value is 1 if logon is allowed and 0 if logon is not allowed.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-TS-Remote-Control&lt;/strong&gt;&lt;br /&gt;Terminal Services Remote Control specifies the whether to allow remote observation or remote control of the user's Terminal Services session. For a description of these values, see the RemoteControl method of the Win32_TSRemoteControlSetting WMI class. &lt;br /&gt;0 – Disable &lt;br /&gt;1 – EnableInputNotify &lt;br /&gt;2 – EnableInputNoNotify &lt;br /&gt;3 - EnableNoInputNotify &lt;br /&gt;4 - EnableNoInputNoNotify&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-TS-Max-Disconnection-Time&lt;/strong&gt;&lt;br /&gt;Terminal Services Session Maximum Disconnection Time is maximum amount of time, in minutes, that a disconnected Terminal Services session remains active on the Terminal Server. After the specified number of minutes has elapsed, the session is terminated.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-TS-Max-Connection-Time&lt;/strong&gt;&lt;br /&gt;Terminal Services Session maximum Connection Time is Maximum duration, in minutes, of the Terminal Services session. After the specified number of minutes has elapsed, the session can be disconnected or terminated.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-TS-Max-Idle-Time&lt;/strong&gt;&lt;br /&gt;Terminal Services Session Maximum Idle Time is maximum amount of time, in minutes, that the Terminal Services session can remain idle. After the specified number of minutes has elapsed, the session can be disconnected or terminated.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-TS-Reconnection-Action&lt;/strong&gt;&lt;br /&gt;Terminal Services Session Reconnection Action specifies whether to allow reconnection to a disconnected Terminal Services session from any client computer. The value is 1 if reconnection is allowed from the original client computer only and 0 if reconnection from any client computer is allowed.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-TS-Broken-Connection-Action&lt;/strong&gt;&lt;br /&gt;Terminal Services Session Broken Connection Action specifies the action to take when a Terminal Services session limit is reached. The value is 1 if the client session should be terminated and 0 if the client session should be disconnected.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-TS-Connect-Client-Drives&lt;/strong&gt;&lt;br /&gt;Terminal Services Session Connect Client Drives At Logon specifies whether to reconnect to mapped client drives at logon. The value is 1 if reconnection is enabled and 0 if reconnection is disabled.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-TS-Connect-Printer-Drives&lt;/strong&gt;&lt;br /&gt;Terminal Services Session Connect Printer Drives At Logon specifies whether to reconnect to mapped client printers at logon. The value is 1 if reconnection is enabled and 0 if reconnection is disabled.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-TS-Default-To-Main-Printer&lt;/strong&gt;&lt;br /&gt;Terminal Services Default To Main Printer specifies whether to print automatically to the client's default printer. The value is 1 if printing to the client's default printer is enabled and 0 if it is disabled.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-TS-Work-Directory&lt;/strong&gt;&lt;br /&gt;Terminal Services Session Work Directory specifies the working directory path for the user. To set an initial application to start when the user logs on to the Terminal Server, you must first set the TerminalServicesInitialProgram property, and then set this property.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-TS-Initial-Program&lt;/strong&gt;&lt;br /&gt;Terminal Services Session Initial Program specifies the Path and file name of the application that the user wants to start automatically when the user logs on to the Terminal Server. To set an initial application to start when the user logs on, you must first set this property and then set the TerminalServicesWorkDirectory property. If you set only the TerminalServicesInitialProgram property, the application starts in the user's session in the default user directory.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;MS-TS-Property01&lt;/strong&gt;&lt;br /&gt;Placeholder Terminal Server Property&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;MS-TS-Property02&lt;/strong&gt;&lt;br /&gt;Placeholder Terminal Server Property&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;MS-TS-ExpireDate&lt;/strong&gt;&lt;br /&gt;TS Expiration Date&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;MS-TS-ExpireDate2&lt;/strong&gt;&lt;br /&gt;Expiration date of the second TS per user CAL.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;MS-TS-ExpireDate3&lt;/strong&gt;&lt;br /&gt;Expiration date of the third TS per user CAL.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;MS-TS-ExpireDate4&lt;/strong&gt;&lt;br /&gt;Expiration date of the third TS per user CAL.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;MS-TS-LicenseVersion&lt;/strong&gt;&lt;br /&gt;TS License Version&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;MS-TS-LicenseVersion2&lt;/strong&gt;&lt;br /&gt;Version of the second TS per user CAL.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;MS-TS-LicenseVersion3&lt;/strong&gt;&lt;br /&gt;Version of the third TS per user CAL&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;MS-TS-LicenseVersion4&lt;/strong&gt;&lt;br /&gt;Version of the fourth TS per user CAL.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;MS-TS-ManagingLS&lt;/strong&gt;&lt;br /&gt;TS Managing License Server&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;MS-TS-ManagingLS2&lt;/strong&gt;&lt;br /&gt;Issuer name of the second TS per user CAL.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;MS-TS-ManagingLS3&lt;/strong&gt;&lt;br /&gt;Issuer name of the third TS per user CAL.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;MS-TS-ManagingLS4&lt;/strong&gt;&lt;br /&gt;Issuer name of the fourth TS per user CAL.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;MS-TSLS-Property01&lt;/strong&gt;&lt;br /&gt;Placeholder Terminal Server Property 01&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;MS-TSLS-Property02&lt;/strong&gt;&lt;br /&gt;Placeholder Terminal Server Property 01&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DFSR-DisablePacketPrivacy&lt;/strong&gt;&lt;br /&gt;Disable packet privacy on a connection&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DFSR-DefaultCompressionExclusionFilter&lt;/strong&gt;&lt;br /&gt;Filter string containing extensions of file types not to be compressed&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DFSR-OnDemandExclusionFileFilter&lt;/strong&gt;&lt;br /&gt;Filter string applied to on demand replication files&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DFSR-OnDemandExclusionDirectoryFilter&lt;/strong&gt;&lt;br /&gt;Filter string applied to on demand replication directories&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DFSR-Options2&lt;/strong&gt;&lt;br /&gt;Object Options2&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DFSR-CommonStagingPath&lt;/strong&gt;&lt;br /&gt;Full path of the common staging directory&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DFSR-CommonStagingSizeInMb&lt;/strong&gt;&lt;br /&gt;Size of the common staging directory in MB&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DFSR-StagingCleanupTriggerInPercent&lt;/strong&gt;&lt;br /&gt;Staging cleanup trigger in percent of free disk space&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25337987-7120547149039218380?l=adsearch-winzero.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://adsearch-winzero.blogspot.com/feeds/7120547149039218380/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://adsearch-winzero.blogspot.com/2008/02/new-attributes-in-windows-2008.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/7120547149039218380'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/7120547149039218380'/><link rel='alternate' type='text/html' href='http://adsearch-winzero.blogspot.com/2008/02/new-attributes-in-windows-2008.html' title='New Attributes in Windows 2008'/><author><name>Akos</name><uri>http://www.blogger.com/profile/04967051529264150640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_R_ywovcgAHA/SShKj4z6h2I/AAAAAAAAAOA/UAkvQFC6kX4/S220/akos2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-25337987.post-258307577319326241</id><published>2008-02-23T09:51:00.000-08:00</published><updated>2008-02-23T09:55:06.667-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Global Catalogue'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows 2008'/><category scheme='http://www.blogger.com/atom/ns#' term='Classes'/><title type='text'>New Classes in Windows 2008</title><content type='html'>&lt;strong&gt;New Classes in Windows 2008&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;ms-DS-Password-Settings&lt;br /&gt;ms-DS-Password-Settings-Container&lt;br /&gt;NTDS-DSA-RO&lt;br /&gt;ms-net-ieee-80211-GroupPolicy&lt;br /&gt;ms-net-ieee-8023-GroupPolicy&lt;br /&gt;ms-FVE-RecoveryInformation&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;New Inclusions in the GC for Windows 2008&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Last-Logon-Timestamp&lt;/strong&gt;&lt;br /&gt;This is the time that the user last logged into the domain. Whenever a user logs on, the value of this attribute is read from the DC. If the value is older [current_time - msDS-LogonTimeSyncInterval], the value is updated. The initial update after the raise of the domain functional level is calculated as 14 days minus random percentage of 5 days&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;MS-DRM-Identity-Certificate&lt;/strong&gt;&lt;br /&gt;The XrML digital rights management certificates for this user.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Phonetic-First-Name&lt;/strong&gt;&lt;br /&gt;Contains the phonetic given name or first name of the person&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Phonetic-Last-Name&lt;/strong&gt;&lt;br /&gt;Contains the phonetic last name of the person.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Phonetic-Department&lt;/strong&gt;&lt;br /&gt;Contains the phonetic department name where the person works&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Phonetic-Company-Name&lt;/strong&gt;&lt;br /&gt;Contains the phonetic company name where the person works.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-Phonetic-Display-Name&lt;/strong&gt;&lt;br /&gt;The phonetic display name of an object. In the absence of a phonetic display name the existing display name is used.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-DS-HAB-Seniority-Index&lt;/strong&gt;&lt;br /&gt;Contains the seniority index as applied by the organization where the person works.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-FVE-VolumeGuid&lt;/strong&gt;&lt;br /&gt;This attribute contains the GUID that is associated with the Bit locker-supported volume.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ms-FVE-RecoveryGuid&lt;/strong&gt;&lt;br /&gt;This attribute contains the GUID associated with a Full Volume Encryption (FVE) recovery password.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25337987-258307577319326241?l=adsearch-winzero.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://adsearch-winzero.blogspot.com/feeds/258307577319326241/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://adsearch-winzero.blogspot.com/2008/02/new-classes-in-windows-2008.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/258307577319326241'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/258307577319326241'/><link rel='alternate' type='text/html' href='http://adsearch-winzero.blogspot.com/2008/02/new-classes-in-windows-2008.html' title='New Classes in Windows 2008'/><author><name>Akos</name><uri>http://www.blogger.com/profile/04967051529264150640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_R_ywovcgAHA/SShKj4z6h2I/AAAAAAAAAOA/UAkvQFC6kX4/S220/akos2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-25337987.post-764421629146058635</id><published>2007-11-30T13:15:00.001-08:00</published><updated>2007-11-30T13:15:15.574-08:00</updated><title type='text'>Windows tips</title><content type='html'>&lt;div id='_ytplayer_vjVQa1PpcFPEXtGPRXozDdG9FBqHw_QkrqbrBswTC8Q='&gt;&lt;a href='http://www.youtube.com/browse'&gt;Watch the latest videos on YouTube.com&lt;/a&gt;&lt;/div&gt;&lt;script type='text/javascript' src='http://www.youtube.com/cp/vjVQa1PpcFPEXtGPRXozDdG9FBqHw_QkrqbrBswTC8Q='&gt;&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25337987-764421629146058635?l=adsearch-winzero.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://adsearch-winzero.blogspot.com/feeds/764421629146058635/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://adsearch-winzero.blogspot.com/2007/11/windows-tips.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/764421629146058635'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/764421629146058635'/><link rel='alternate' type='text/html' href='http://adsearch-winzero.blogspot.com/2007/11/windows-tips.html' title='Windows tips'/><author><name>Akos</name><uri>http://www.blogger.com/profile/04967051529264150640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_R_ywovcgAHA/SShKj4z6h2I/AAAAAAAAAOA/UAkvQFC6kX4/S220/akos2.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-25337987.post-3497560906948695646</id><published>2007-11-13T18:31:00.000-08:00</published><updated>2007-11-13T18:53:08.884-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='System only'/><title type='text'>How to Change System Only Attributes</title><content type='html'>Using ADSearch allows you to extract object properties, however, not all properties of an object are changable. If you need to change Active Directory object properties that are set as system only there is a registry key setting that will allow you to set these properties.&lt;br /&gt; &lt;br /&gt;&lt;strong&gt;I strongly recommend caution when changing system only properties.&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;By adding a registry key to the PDC Emulator or FSMO DC the registry key will allow you to change system-only attributes.&lt;br /&gt;&lt;br /&gt;Key: HKEY_LOCAL_MACHINE&lt;br /&gt;Path: System\CurrentControlSet\Services\NTDS\Parameters&lt;br /&gt;Value name: Allow System Only Change&lt;br /&gt;Data type: REG_DWORD&lt;br /&gt;Value data: 1&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25337987-3497560906948695646?l=adsearch-winzero.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://adsearch-winzero.blogspot.com/feeds/3497560906948695646/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://adsearch-winzero.blogspot.com/2007/11/how-to-change-system-only-attributes.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/3497560906948695646'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/3497560906948695646'/><link rel='alternate' type='text/html' href='http://adsearch-winzero.blogspot.com/2007/11/how-to-change-system-only-attributes.html' title='How to Change System Only Attributes'/><author><name>Akos</name><uri>http://www.blogger.com/profile/04967051529264150640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_R_ywovcgAHA/SShKj4z6h2I/AAAAAAAAAOA/UAkvQFC6kX4/S220/akos2.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-25337987.post-7561982080631032696</id><published>2007-11-06T10:33:00.000-08:00</published><updated>2007-11-06T10:46:50.335-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Groups'/><category scheme='http://www.blogger.com/atom/ns#' term='Global groups'/><category scheme='http://www.blogger.com/atom/ns#' term='Universal groups'/><category scheme='http://www.blogger.com/atom/ns#' term='Group scope'/><category scheme='http://www.blogger.com/atom/ns#' term='Domain local groups'/><title type='text'>AD Group Scope Basics</title><content type='html'>Security groups or a distribution groups, are characterized by a scope that identifies how they are applied in the domain tree or forest.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;There are three group scopes:&lt;/strong&gt; universal, global, and domain local.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Universal Groups (type - 2147483640)&lt;/strong&gt;&lt;br /&gt;Universal groups can include other groups and accounts from any domain in the domain tree or forest and can be assigned permissions in any domain in the domain tree or forest.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Global Groups (type - 2147483646)&lt;/strong&gt; &lt;br /&gt;Global groups can include other groups and accounts only from the domain in which the group is defined and can be assigned permissions in any domain in the forest.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Domain Local Groups (type - 2147483644)&lt;/strong&gt;&lt;br /&gt;Domain local groups can include other groups and can be assigned permissions only within a domain.&lt;br /&gt; &lt;br /&gt;&lt;strong&gt;Functionality Scope&lt;/strong&gt;&lt;br /&gt;When the domain is set to Windows 2000 native or Windows Server 2003, members of universal groups can include accounts, global groups, and universal groups from any domain.&lt;br /&gt;Global groups can include accounts and global groups from the same domain. Domain local scope can include accounts, global groups, and universal groups from any domain, as well as domain local groups from the same domain.&lt;br /&gt;&lt;br /&gt;Groups can be added to other groups and assigned permissions in any domain. Groups can be added to other domain local groups and assigned permissions only in the same domain.&lt;br /&gt;&lt;br /&gt;Groups can be converted to domain local scope, to global scope, as long as no other universal groups exist as members. Groups can be converted to universal scope, as long as the group is not a member of any other group with global scope. Groups can be converted to universal scope, as long as the group does not have as its member another group with domain local scope.&lt;br /&gt; &lt;br /&gt;When the domain level is set to Windows mixed, security universal groups cannot be created. Global groups can include accounts from the same domain. Domain local groups can include accounts and global groups from any domain. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Domain Local Scope Use&lt;/strong&gt;&lt;br /&gt;Groups with domain local scope help you define and manage access to resources within a single domain. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Global Scope Use&lt;/strong&gt;&lt;br /&gt;Use groups with global scope to manage directory objects that require daily maintenance, such as user and computer accounts because groups with global scope are not replicated outside of their own domain.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Universal Scope Use&lt;/strong&gt;&lt;br /&gt;Use groups with universal scope to consolidate groups that span domains. Add the accounts to groups with global scope and nest these groups within groups having universal scope. Any membership changes in the groups having global scope do not affect the groups with universal scope.&lt;br /&gt;Groups with universal scope should not be changed frequently, since any changes to these group memberships cause the entire membership of the group to be replicated to every global catalog in the forest.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Changing Group Scope&lt;/strong&gt;&lt;br /&gt;&lt;em&gt;Global to universal&lt;/em&gt;. This is only allowed if the group you want to change is not a member of another global scope group. &lt;br /&gt;&lt;em&gt;Domain local to universal&lt;/em&gt;. This is only allowed if the group you want to change does not have another domain local group as a member. &lt;br /&gt;&lt;em&gt;Universal to global&lt;/em&gt;. This is only allowed if the group you want to change does not have another universal group as a member. &lt;br /&gt;&lt;em&gt;Universal to domain local&lt;/em&gt;. No restrictions for this operation.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25337987-7561982080631032696?l=adsearch-winzero.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://adsearch-winzero.blogspot.com/feeds/7561982080631032696/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://adsearch-winzero.blogspot.com/2007/11/ad-group-scope-basics.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/7561982080631032696'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/7561982080631032696'/><link rel='alternate' type='text/html' href='http://adsearch-winzero.blogspot.com/2007/11/ad-group-scope-basics.html' title='AD Group Scope Basics'/><author><name>Akos</name><uri>http://www.blogger.com/profile/04967051529264150640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_R_ywovcgAHA/SShKj4z6h2I/AAAAAAAAAOA/UAkvQFC6kX4/S220/akos2.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-25337987.post-3656200570150164371</id><published>2007-11-02T09:43:00.000-07:00</published><updated>2007-11-02T09:47:45.031-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Computer2User'/><category scheme='http://www.blogger.com/atom/ns#' term='logonCount'/><category scheme='http://www.blogger.com/atom/ns#' term='lastLogon'/><title type='text'>Clean up Active Directory</title><content type='html'>Over time, user and computer accounts become obsolete and need elimination. ADSearch helps identify all inactive or disabled users and computers in Active Directory. Based on your company policy you can delete, disable, enable or move these accounts. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Enhance Active Directory Safety and Performance.&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;You can run Adsearch to search logonCount for users and computers and report only accounts that never logged on to locate inactive user or computer accounts and then disable, delete or move these accounts. &lt;br /&gt;&lt;br /&gt;For detailed reports using Active Directory lastLogon feature, download and use &lt;a href="http://www.winzero.ca/Computer2User.htm"&gt;Winzero Computer2User&lt;/a&gt; to evaluate every DC in your domain for the true last logon time of any user.  &lt;br /&gt; &lt;br /&gt;A reliable Active Directory infrastructure should always ensure that the existing accounts are enabled and obsolete accounts are disabled or deleted, for optimum productivity and security.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25337987-3656200570150164371?l=adsearch-winzero.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://adsearch-winzero.blogspot.com/feeds/3656200570150164371/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://adsearch-winzero.blogspot.com/2007/11/clean-up-active-directory.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/3656200570150164371'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/3656200570150164371'/><link rel='alternate' type='text/html' href='http://adsearch-winzero.blogspot.com/2007/11/clean-up-active-directory.html' title='Clean up Active Directory'/><author><name>Akos</name><uri>http://www.blogger.com/profile/04967051529264150640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_R_ywovcgAHA/SShKj4z6h2I/AAAAAAAAAOA/UAkvQFC6kX4/S220/akos2.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-25337987.post-8873413130656510196</id><published>2007-10-25T20:56:00.000-07:00</published><updated>2007-10-25T21:18:47.733-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='mail-box-enabled'/><category scheme='http://www.blogger.com/atom/ns#' term='Exchange'/><title type='text'>Deleting Mailbox-Enabled Users</title><content type='html'>If you choose to delete a mailbox-enabled user or group, the mailbox in the message store of the Exhange 200x server will not be disabled. To disable the mailbox, you should clear the following attributes in Active Directory before deleting the account:&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Attributes to Clear&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;  homeMDB,&lt;br /&gt;  mail,&lt;br /&gt;  mailNickname,&lt;br /&gt;  homeMTA,&lt;br /&gt;  legacyExchangeDN,&lt;br /&gt;  msExchHomeServerName,&lt;br /&gt;  msExchMailboxGuid,&lt;br /&gt;  msExchPoliciesIncluded,&lt;br /&gt;  proxyAddresses,&lt;br /&gt;  textEncodedORAddress&lt;br /&gt;&lt;br /&gt;By clearing these 9 attributes from the user properties before deleting the user account, Active Directory will notify the Exchange 200x server that mailbox attached to this account should be disabled.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25337987-8873413130656510196?l=adsearch-winzero.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://adsearch-winzero.blogspot.com/feeds/8873413130656510196/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://adsearch-winzero.blogspot.com/2007/10/deleting-mailbox-enabled-users.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/8873413130656510196'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/8873413130656510196'/><link rel='alternate' type='text/html' href='http://adsearch-winzero.blogspot.com/2007/10/deleting-mailbox-enabled-users.html' title='Deleting Mailbox-Enabled Users'/><author><name>Akos</name><uri>http://www.blogger.com/profile/04967051529264150640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_R_ywovcgAHA/SShKj4z6h2I/AAAAAAAAAOA/UAkvQFC6kX4/S220/akos2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-25337987.post-7219011519642297374</id><published>2007-10-17T23:28:00.000-07:00</published><updated>2007-10-17T23:31:27.752-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='UPN'/><category scheme='http://www.blogger.com/atom/ns#' term='User Principle Name'/><category scheme='http://www.blogger.com/atom/ns#' term='userPrincipalName'/><title type='text'>userPrincipalName (User-Principal-Name)</title><content type='html'>The userPrincipalName is a single-valued and indexed property that specifies the user principal name (UPN). The UPN is an Internet-style login name for the user. The UPN is shorter than the distinguished name and easier to remember. The point of the UPN is to consolidate the e-mail and logon namespaces so that the user need only remember a single name.&lt;br /&gt; &lt;br /&gt;&lt;strong&gt;The UPN as the Preferred Logon Name&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Users should use their UPNs to log on to the domain. At logon time, a UPN is validated first by searching the local domain, then the global catalog.&lt;br /&gt;By convention, the UPN should map to the user's e-mail name.&lt;br /&gt;&lt;br /&gt;The UPN can be assigned, but is not required. Once assigned, the UPN is unaffected by changes to other properties of the user object. If a parent domain was renamed or a domain was moved the user can keep the same login name, even if the directory is radically restructured.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;The UPN Name Structure&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;The UPN must be unique among all security principal objects within the directory forest.&lt;br /&gt;The user principal name has two parts: the UPN prefix (the user account name) and the UPN suffix (a DNS domain name). The parts are joined together by the @ (at sign) to complete the UPN. &lt;br /&gt;&lt;br /&gt;The UPN can consist of any name for the user (such as the sAMAccountName) and the domain tree name or an email domain name &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Sample User Principal Name:&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;name@domain.com, Email.Name@emailAddress.com&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25337987-7219011519642297374?l=adsearch-winzero.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://adsearch-winzero.blogspot.com/feeds/7219011519642297374/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://adsearch-winzero.blogspot.com/2007/10/userprincipalname-user-principal-name.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/7219011519642297374'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/7219011519642297374'/><link rel='alternate' type='text/html' href='http://adsearch-winzero.blogspot.com/2007/10/userprincipalname-user-principal-name.html' title='userPrincipalName (User-Principal-Name)'/><author><name>Akos</name><uri>http://www.blogger.com/profile/04967051529264150640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_R_ywovcgAHA/SShKj4z6h2I/AAAAAAAAAOA/UAkvQFC6kX4/S220/akos2.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-25337987.post-8684327645968555346</id><published>2007-10-17T10:43:00.000-07:00</published><updated>2007-10-17T11:52:23.869-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Syntax'/><category scheme='http://www.blogger.com/atom/ns#' term='Attributes'/><title type='text'>Common Active Directory Attributes, Syntaxes, and Meanings</title><content type='html'>The following contains a number of commonly used Active Directory attributes, their meanings, their syntax, and what objects contain them in the default Active Directory schema:&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;accountExpires (user)&lt;/strong&gt;&lt;br /&gt;The date which a user account will expire. This attribute takes the form of a long (64 bit) integer. To convert this value into a textual date use the ADSearch Convert function.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;canonicalName (all objects)&lt;/strong&gt;&lt;br /&gt;A type of name for an object which takes the form of "domain.com/container/container/object". This style of name is very human readable. This attribute takes the form of a string.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;cn (user, group, computer, contact)&lt;/strong&gt;&lt;br /&gt;The uplevel name of an object. It is the leaf part of a distinguishedName (for example, the "cn=joe" of "cn=joe,ou=someou,dc=domain,dc=com".)&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;dc (domainDNS)&lt;/strong&gt;&lt;br /&gt;The uplevel name of a domain. It is the leaf part of the distinguished name of the domain (for example, the "dc=domain" of "dc=domain,dc=com".)&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;distinguishedName (all objects)&lt;/strong&gt;&lt;br /&gt;This is the distinguished name of the object. It represents the full path to an object (without the server and provider) in the directory. This attribute takes the form of a single valued string. If you are searching the active directory, this attribute cannot be used as a key to search on. This is because it is a generated attribute (that is, it is generated everytime it is asked for).&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;isCriticalSystemObject (all objects)&lt;/strong&gt;&lt;br /&gt;This attribute specifies whether an object is critical for the operation of Active Directory. This attribute takes the form of a Boolean value. If its value is true, the object is critical to Active Directory and is not deletable.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;logonHours (user)&lt;/strong&gt;&lt;br /&gt;The times which a user is allowed to log on. This attribute takes the form of an octet string (a sequence of hexadecimal characters with each set of two characters representing one byte.) To convert this binary data into a more meaningful set of data, use the ADSearch Convert function.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;member (group)&lt;/strong&gt;&lt;br /&gt;The objects which are members of the group. This attribute takes the form of a multi-valued string, with each element being the distinguished name of a member. If the member is a Foreign Security Principal, the distinguished name will be in the form "CN=sid", where sid is the SID of the member.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;objectCategory (all objects)&lt;/strong&gt;&lt;br /&gt;Represents the path to the schema class of which an object is an instance. This attribute takes the form of a single valued string. If searching for objects, it is recommended that this be used instead of the objectClass, as it is an indexed attribute and replicated to the Global Catalog. Note that the whole path need not be used to search on this attribute, rather only the cn of the class (for example, person for user and contact, and organizational-unit for OUs.)&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;objectClass (all objects)&lt;/strong&gt;&lt;br /&gt;Represents the inheritance hierarchy of an objects class. This attribute takes the form of a multi-valued string.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;objectGUID (all objects)&lt;/strong&gt;&lt;br /&gt;A GUID which uniquely identifies an object within the directory. This attribute takes the form of a raw binary string, with each set of two characters representing one byte of binary data. To convert the raw binary data that is retrieved from this attribute to a more readable or useful form, use the ADSearch Convert function.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;objectSid (all security principals)&lt;/strong&gt;&lt;br /&gt;Contains the security identifier of an object. This SID can be used to represent an object in various places on the network (Active Directory, File System ACLs, or anywhere else users are added to ACLs.) This attribute takes the form of a raw binary string, with each set of two characters representing one byte of binary data. To convert this binary value into a more useful textual value use the ADSearch Convert function.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;ou (organizationalUnit)&lt;/strong&gt;&lt;br /&gt;The uplevel name of an organizational unit. It is the leaf part of the distinguished name of an organizational unit (for example, the "ou=someou" of "ou=someou,dc=domain,dc=com").&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;sAMAccountName (user, computer, group)&lt;/strong&gt;&lt;br /&gt;The downlevel name of the object. This is the name that will be seen by downlevel administrative tools and other pre-windows 200x tools. This attribute takes the form of a single valued string.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;userAccountControl (user)&lt;/strong&gt;&lt;br /&gt;A set of bit flags defining certain properties of a user. This attribute takes the form of a 32-bit integer. This attribute is a combination of the following bit values:&lt;br /&gt;Value Description&lt;br /&gt;1 The logon script will be executed.&lt;br /&gt;2 The user account is disabled.&lt;br /&gt;8 A home directory is required.&lt;br /&gt;16 The account is locked out.&lt;br /&gt;32 The account does not require a password.&lt;br /&gt;64 Account is not allowed to change password.&lt;br /&gt;512 The account is a typical user account.&lt;br /&gt;65536 The account password never expires.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25337987-8684327645968555346?l=adsearch-winzero.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://adsearch-winzero.blogspot.com/feeds/8684327645968555346/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://adsearch-winzero.blogspot.com/2007/10/common-active-directory-attributes.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/8684327645968555346'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/8684327645968555346'/><link rel='alternate' type='text/html' href='http://adsearch-winzero.blogspot.com/2007/10/common-active-directory-attributes.html' title='Common Active Directory Attributes, Syntaxes, and Meanings'/><author><name>Akos</name><uri>http://www.blogger.com/profile/04967051529264150640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_R_ywovcgAHA/SShKj4z6h2I/AAAAAAAAAOA/UAkvQFC6kX4/S220/akos2.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-25337987.post-7792053446128610743</id><published>2007-10-15T15:03:00.000-07:00</published><updated>2007-10-15T15:07:25.755-07:00</updated><title type='text'>Convert Raw AD Properties</title><content type='html'>Adsearch v3.0x features a conversion tool to convert from raw unreadable active Directory properties to readable properties.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;GUIDRaw&lt;/strong&gt;&lt;br /&gt;Convert the raw form of a GUID to The textual form of a GUID.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;SIDRaw&lt;/strong&gt;&lt;br /&gt;Convert the raw form of a SID to The textual form of a SID.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;LHRaw&lt;/strong&gt;&lt;br /&gt;Convert the raw form of hours representation such as the attribute logonHours to the textual form of hours representation such as logonHours. Example: "1-24&lt;-&gt;&lt;-&gt;8-17&lt;-&gt;...."&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;IRawDate&lt;/strong&gt;&lt;br /&gt;Convert the raw form of a date in integer format such as accountExpires to the textual form of a date.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Quick How To&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Adsearch 3.0x and up allows you to quickly copy and paste the raw information into the conversion tool and convert it to a readable form.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Example:&lt;/strong&gt;&lt;br /&gt;To get the last password reset date and time in a readable format.&lt;br /&gt;&lt;br /&gt;From the menu select &lt;strong&gt;Search Active Directory&lt;/strong&gt;; select the &lt;strong&gt;domain&lt;/strong&gt; and the &lt;strong&gt;bindserver&lt;/strong&gt; to logon to.&lt;br /&gt;Select ObjectType:  &lt;strong&gt;user&lt;/strong&gt;&lt;br /&gt;Select SearchBy:  &lt;strong&gt;name&lt;/strong&gt;&lt;br /&gt;Select SearchResults: &lt;strong&gt;pwdLastSet&lt;/strong&gt;   &lt;br /&gt;Enter &lt;strong&gt;ALL&lt;/strong&gt; for Refine Search&lt;br /&gt;&lt;br /&gt;Once the results for all users are returned and the last password set looks like: 128153342196114592, double click an &lt;strong&gt;account name&lt;/strong&gt;. In the popup Copy to Clipboard Window, select &lt;strong&gt;128153342196114592&lt;/strong&gt;.&lt;br /&gt;&lt;br /&gt;Once this is done, select &lt;strong&gt;ADSearch Tools &lt;/strong&gt;from the menu and choose &lt;strong&gt;Convert Raw Active Directory Data&lt;/strong&gt;.&lt;br /&gt;&lt;br /&gt;Select the &lt;strong&gt;domain&lt;/strong&gt; to convert the information and choose &lt;strong&gt;Convert Raw Date to Textual Date&lt;/strong&gt;&lt;br /&gt;In the Enter Raw Date popup, right click the textbox and paste the raw date from the clipboard.&lt;br /&gt;&lt;br /&gt;The raw date will convert to: 02/07/07@11:03:39&lt;br /&gt;&lt;br /&gt;With ADsearch, you can use this method to convert raw Dates, SIDs, GUIDs and compound Times&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25337987-7792053446128610743?l=adsearch-winzero.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://adsearch-winzero.blogspot.com/feeds/7792053446128610743/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://adsearch-winzero.blogspot.com/2007/10/convert-raw-ad-properties.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/7792053446128610743'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/7792053446128610743'/><link rel='alternate' type='text/html' href='http://adsearch-winzero.blogspot.com/2007/10/convert-raw-ad-properties.html' title='Convert Raw AD Properties'/><author><name>Akos</name><uri>http://www.blogger.com/profile/04967051529264150640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_R_ywovcgAHA/SShKj4z6h2I/AAAAAAAAAOA/UAkvQFC6kX4/S220/akos2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-25337987.post-5364740977533644344</id><published>2007-07-09T15:24:00.000-07:00</published><updated>2007-07-09T15:27:27.230-07:00</updated><title type='text'>lastLogon</title><content type='html'>Because the lastLogon attribute is not replicated in Active Directory, a different value can be stored in the copy of Active Directory on each Domain Controller. The largest value that is retrieved is the true last logon time for that user.&lt;br /&gt;&lt;br /&gt;The lastLogon attribute is stored in Active Directory as Integer8 (8 bytes). This means it is a 64-bit number. This value represents the number of 100 nanosecond intervals since 12:00 AM January 1, 1601. The date represented by this number is in Coordinated Universal Time (UTC). It must be adjusted by the time zone bias in the local machine registry to convert to local time.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;lastLogonTimestamp&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Ok, here is how it works in Windows 2003 for the new last logon attribute.&lt;br /&gt;One of the new attributes in Windows 2003 is lastLogonTimestamp which can be used to retrieve the last logon time for users, good so we have a new attribute to use! Sounds easy, right?&lt;br /&gt;&lt;br /&gt;But the lastLogonTimestamp is not always showing the truth since it is only replicated every 14 days...&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Simplifying Matters&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;So instead of writing VBScripts and performing calculation hurdles, why not download Winzero's Computer2User v3.00 or Winzero Domain Monitor solutions at:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.winzero.ca/downloads.htm"&gt;http://www.winzero.ca/downloads.htm&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;and just use these solutions:&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Computer2User&lt;/strong&gt; version 3.0x will report the last domain logon for all users* from any selected DC, or the last local computer logon for all users by server or workstation.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;DomainMonitor&lt;/strong&gt; version 2.0x will report the last domain logon for all users* from all DCs by collection date.&lt;br /&gt;&lt;br /&gt;*note "users" in Active Directory will return both users accounts and computer accounts because AD sees both as accounts.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25337987-5364740977533644344?l=adsearch-winzero.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://adsearch-winzero.blogspot.com/feeds/5364740977533644344/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://adsearch-winzero.blogspot.com/2007/07/lastlogon.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/5364740977533644344'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/5364740977533644344'/><link rel='alternate' type='text/html' href='http://adsearch-winzero.blogspot.com/2007/07/lastlogon.html' title='lastLogon'/><author><name>Akos</name><uri>http://www.blogger.com/profile/04967051529264150640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_R_ywovcgAHA/SShKj4z6h2I/AAAAAAAAAOA/UAkvQFC6kX4/S220/akos2.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-25337987.post-115594463157508198</id><published>2006-08-18T16:21:00.000-07:00</published><updated>2006-08-18T16:44:40.376-07:00</updated><title type='text'>User Properties and Return Values</title><content type='html'>Adsearch User properties and return values that can be returned for a user. The first indicates the names that are indicated on the MMC GUI Users and Computers and the name associated to Active Directory attribute.&lt;br /&gt;&lt;br /&gt;The value returned may be a string (textual), multistring (list of textual entries), boolean (True or false, 0 or 1) , binary, or a date.&lt;br /&gt;&lt;br /&gt;First name - givenName Single value string&lt;br /&gt;Initials - initials Single value string&lt;br /&gt;Last name - sn Single value string&lt;br /&gt;Display name - displayName Single value string&lt;br /&gt;Description - description Single value string&lt;br /&gt;Office - physicalDeliveryOfficeName Single value string&lt;br /&gt;Telephone number - telephoneNumber Single value string&lt;br /&gt;Other telephone number - otherTelephone Multi value string&lt;br /&gt;Email - mail Single value string&lt;br /&gt;Web page - wWWHomePage Single value string&lt;br /&gt;Other web page url Multi value string&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Address:&lt;br /&gt;&lt;/strong&gt;Street - streetAddress Single value string&lt;br /&gt;P.O. Box - postOfficeBox Single value string&lt;br /&gt;City - l (letter 'L') Single value string&lt;br /&gt;State/province - st Single value string&lt;br /&gt;Zip/Postal Code - postalCode Single value string&lt;br /&gt;Country/region - co Single value string&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Account:&lt;br /&gt;&lt;/strong&gt;User logon name - userPrincipalName Single value string&lt;br /&gt;User logon name (pre W2K) - samAccountName Single value string&lt;br /&gt;Logon Hours - logonHours (see Note 1 below this table) Single value string&lt;br /&gt;Log On To - userWorkstations Multi value string&lt;br /&gt;Account locked out ACT-LockedOut (see Note 2 below this table) "true" or "false"&lt;br /&gt;User must change password at next logon ACT-PassMustChange (see Note 2 below this table) "true" or "false"&lt;br /&gt;User cannot change password ACT-PassNoChange (see Note 2 below this table) "true" or "false"&lt;br /&gt;Password never expires ACT-PassNoExpire (see Note 2 below this table) "true" or "false"&lt;br /&gt;Store password using reversible encryption ACT-ReverseEncrypt (see Note 2 below this table) "true" or "false"&lt;br /&gt;Account is Disabled ACT-AccountDisabled (see Note 2 below this table) "true" or "false"&lt;br /&gt;Smart card is required for interactive logon ACT-SmartCardReq (see Note 2 below this table) "true" or "false"&lt;br /&gt;Account is trusted for delegation ACT-AccountTrusted (see Note 2 below this table) "true" or "false"&lt;br /&gt;Account is sensitive and cannot be delegated ACT-AccountSensitive (see Note 2 below this table) "true" or "false"&lt;br /&gt;Use DES encryption types for this account ACT-UseDES (see Note 2 below this table) "true" or "false"&lt;br /&gt;Do not require Kerberos pre-authentication ACT-KerberosNotReq (see Note 2 below this table) "true" or "false"&lt;br /&gt;&lt;br /&gt;Account expires accountExpires date string&lt;br /&gt;&lt;br /&gt;1. Output for logonHours is in the textual form of hours representing a 7-day period. The string is divided into 7 slots, each slot representing a day and indicating a mix of hour ranges and/or single hours. Example of allowing logon 9am to 6pm, Monday through Friday, and between 1pm and 2pm Saturday: "&lt;-&gt;10-18&lt;-&gt;10-18&lt;-&gt;10-18&lt;-&gt;10-18&lt;-&gt;10-18&lt;-&gt;14", where "&lt;-&gt;" is the delimiter.&lt;br /&gt;&lt;br /&gt;2. Most of the 'ACT' attribute names are stored as bit flags in the Active Directory integer attribute userAccountControl. They are uniquely identified here with artificial names to make it easier to get their values.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Profile:&lt;br /&gt;&lt;/strong&gt;Profile path - profilePath Single value string&lt;br /&gt;Logon script - scriptPath Single value string&lt;br /&gt;Local path - homeDirectory Single value string&lt;br /&gt;Connect - homeDrive Single value string home&lt;br /&gt;Directory (The Connect and To fields created the remote path when applied in MMC Users and Computers) Single value string&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Telephones:&lt;br /&gt;&lt;/strong&gt;Home - homePhone Single value string&lt;br /&gt;Other Home - otherhomePhone Multi value string&lt;br /&gt;Pager - pager Single value string&lt;br /&gt;Other Pager - otherPager Multi value string&lt;br /&gt;Mobile - mobile Single value string&lt;br /&gt;Other Mobile - otherMobile Multi value string&lt;br /&gt;Fax - facsimileTelephoneNumber Single value string&lt;br /&gt;Other Fax - otherfacsimileTelephoneNumber Multi value string&lt;br /&gt;IP Phone - ipPhone Single value string&lt;br /&gt;Other IP Phone - otheripPhone Multi value string Notes info Single value string&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Organizations:&lt;br /&gt;&lt;/strong&gt;Title - title Single value string&lt;br /&gt;Company - company Single value string&lt;br /&gt;Department - department Single value string&lt;br /&gt;Manager - manager Single value string&lt;br /&gt;Direct Reports - directReports Multi value string&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Member Of:&lt;br /&gt;&lt;/strong&gt;Member Of - memberOf Multi value string&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Dial-in:&lt;br /&gt;&lt;/strong&gt;Remote Access Permission msNPAllowDialin "true" or "false"&lt;br /&gt;Callback Options:No Callback/ Set by caller/Always callback to ACT-Callback (see note below this table) "false" means callback is disabled."true" means callback is enabled and the callback number is set by the user."true&lt;delimiter&gt;555-1234" means callback is enabled and the callback number is pre-set.&lt;br /&gt;&lt;br /&gt;The 'ACT-Callback' attribute name above is uniquely identified here with an artificial name to make it easier to retrieve the value.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Object:&lt;br /&gt;&lt;/strong&gt;Fully qualified domain name of object - canonicalName Single value string&lt;br /&gt;Created - whenCreated date string Modified whenChanged date string&lt;br /&gt;Original USN - uSNCreated Single value string&lt;br /&gt;Current USN - uSNChanged Single value string&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Other:&lt;/strong&gt;&lt;br /&gt;SID - objectSID binary (Requies conversion from raw format)&lt;br /&gt;GUID - objectGUID- binary (Requires conversion from raw format)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25337987-115594463157508198?l=adsearch-winzero.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://adsearch-winzero.blogspot.com/feeds/115594463157508198/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://adsearch-winzero.blogspot.com/2006/08/user-properties-and-return-values.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/115594463157508198'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/115594463157508198'/><link rel='alternate' type='text/html' href='http://adsearch-winzero.blogspot.com/2006/08/user-properties-and-return-values.html' title='User Properties and Return Values'/><author><name>Akos</name><uri>http://www.blogger.com/profile/04967051529264150640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_R_ywovcgAHA/SShKj4z6h2I/AAAAAAAAAOA/UAkvQFC6kX4/S220/akos2.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-25337987.post-114444079412027837</id><published>2006-04-07T13:05:00.000-07:00</published><updated>2006-04-07T13:13:14.130-07:00</updated><title type='text'>Object: user ~ MS Exchange Attributes</title><content type='html'>Once the Active Directory schema is extended by Microsoft Exchange 2000 or 2003, the user attribute will contain the following additional properties:&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;homeMDB&lt;/strong&gt;&lt;br /&gt;Here is where you set the MailStore&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;legacyExchangeDN&lt;/strong&gt;&lt;br /&gt;Legacy distinguished name for creating Contacts. In the following example, Guy Thomas is a Contact in the first administrative group of GUYDOMAIN: /o=GUYDOMAIN/ou=first administrative group/cn=Recipients/cn=Guy Thomas&lt;br /&gt; &lt;br /&gt;&lt;strong&gt;mail&lt;/strong&gt;&lt;br /&gt;An easy, but important attribute.  A simple SMTP address is all that is required &lt;a href="mailto:billyn@ourdom.com"&gt;billyn@ourdom.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;mAPIRecipient&lt;/strong&gt;&lt;br /&gt;- FALSE  Indicates that a contact is not a domain user.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;mailNickname&lt;/strong&gt;&lt;br /&gt;Normally this is the same value as the sAMAccountName, but could be different if you wished. Needed for mail enabled contacts.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;mDBUseDefaults&lt;/strong&gt;&lt;br /&gt;Another straightforward field, just the value to:True&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;msExchHomeServer&lt;/strong&gt;&lt;br /&gt;NameExchange needs to know which server to deliver the mail.  Example: /o=YourOrg/ou=First Administrative Group/cn=Configuration/cn=Servers/cn=MailSrv&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;proxyAddresses&lt;/strong&gt;&lt;br /&gt;As the name 'proxy' suggests, it is possible for one recipient to have more than one email address.  Note the plural spelling of proxyAddresses.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;targetAddress&lt;/strong&gt;&lt;br /&gt;SMTP:@ e-mail address.  Note that SMTP is case sensitive.  All capitals means the default address.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;showInAddressBook&lt;/strong&gt;&lt;br /&gt;Displays the contact in the Global Address List.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25337987-114444079412027837?l=adsearch-winzero.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://adsearch-winzero.blogspot.com/feeds/114444079412027837/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://adsearch-winzero.blogspot.com/2006/04/object-user-ms-exchange-attributes.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/114444079412027837'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/114444079412027837'/><link rel='alternate' type='text/html' href='http://adsearch-winzero.blogspot.com/2006/04/object-user-ms-exchange-attributes.html' title='Object: user ~ MS Exchange Attributes'/><author><name>Akos</name><uri>http://www.blogger.com/profile/04967051529264150640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_R_ywovcgAHA/SShKj4z6h2I/AAAAAAAAAOA/UAkvQFC6kX4/S220/akos2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-25337987.post-114412503047718341</id><published>2006-04-03T21:21:00.000-07:00</published><updated>2006-04-03T21:30:30.483-07:00</updated><title type='text'>Object: group ~ Attribute: groupType</title><content type='html'>The groupType attribute returns the type of group. However the returned value is in RAW format. AdSearch conversion tool will convert the groupType result or for further refernence see the possible return values below:&lt;br /&gt;&lt;br /&gt;-2147483646  ~ Global Security Group&lt;br /&gt;-2147483644  ~ Local Security Group&lt;br /&gt;-2147483643  ~ BuiltIn Group&lt;br /&gt;-2147483640  ~ Universal Security Group&lt;br /&gt;&lt;br /&gt;2    ~ Global Distribution Group&lt;br /&gt;4    ~ Local Distribution Group&lt;br /&gt;8    ~ Universal Distribution Group&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25337987-114412503047718341?l=adsearch-winzero.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://adsearch-winzero.blogspot.com/feeds/114412503047718341/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://adsearch-winzero.blogspot.com/2006/04/object-group-attribute-grouptype.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/114412503047718341'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/114412503047718341'/><link rel='alternate' type='text/html' href='http://adsearch-winzero.blogspot.com/2006/04/object-group-attribute-grouptype.html' title='Object: group ~ Attribute: groupType'/><author><name>Akos</name><uri>http://www.blogger.com/profile/04967051529264150640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_R_ywovcgAHA/SShKj4z6h2I/AAAAAAAAAOA/UAkvQFC6kX4/S220/akos2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-25337987.post-114412039318903128</id><published>2006-04-03T20:04:00.000-07:00</published><updated>2006-04-03T20:13:13.190-07:00</updated><title type='text'>ADSearch Objects</title><content type='html'>Winzero ADSearch for Active Dirctory enables IT Professionals using Microsoft Windows 200 and Wndows 2003 to search object property attributes in the Schema for the following objects:&lt;br /&gt;&lt;br /&gt;- Users  (user)&lt;br /&gt;- Groups  (group)&lt;br /&gt;- Domains (domain)&lt;br /&gt;- Organizational Units, OUs (organizationalUnit)&lt;br /&gt;- Computers  (computer)&lt;br /&gt;- Published Printers  (printQueue)&lt;br /&gt;- Published Shares  (volume)&lt;br /&gt;&lt;br /&gt;Search queries and search results are based on ADSI LDAP property names&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25337987-114412039318903128?l=adsearch-winzero.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://adsearch-winzero.blogspot.com/feeds/114412039318903128/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://adsearch-winzero.blogspot.com/2006/04/adsearch-objects.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/114412039318903128'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25337987/posts/default/114412039318903128'/><link rel='alternate' type='text/html' href='http://adsearch-winzero.blogspot.com/2006/04/adsearch-objects.html' title='ADSearch Objects'/><author><name>Akos</name><uri>http://www.blogger.com/profile/04967051529264150640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_R_ywovcgAHA/SShKj4z6h2I/AAAAAAAAAOA/UAkvQFC6kX4/S220/akos2.jpg'/></author><thr:total>0</thr:total></entry></feed>
