<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>RO Windows Administrators Weblog &#187; Active Directory</title>
	<atom:link href="http://www.winadmin.ro/category/active-directory/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.winadmin.ro</link>
	<description>Weblogul adminilor de Windows din Romania.</description>
	<lastBuildDate>Wed, 28 Jul 2010 15:34:54 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>One way to backup and &#8220;restore&#8221; AD DNS zones</title>
		<link>http://www.winadmin.ro/2010/05/27/one-way-to-backup-and-restore-ad-dns-zones/</link>
		<comments>http://www.winadmin.ro/2010/05/27/one-way-to-backup-and-restore-ad-dns-zones/#comments</comments>
		<pubDate>Thu, 27 May 2010 15:23:40 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[DNS]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2010/05/27/one-way-to-backup-and-restore-ad-dns-zones/</guid>
		<description><![CDATA[Prin cautarile mele pe net gasisem o metoda interesanta de a face restore la zona DNS AD integrated ce corespunde domeniului AD si m-am gandit sa o explic putin. Locul in care am gasit aceasta metoda nu il mai retin insa o sa incerc eu sa explic cum se face si de ce eu nu [...]]]></description>
			<content:encoded><![CDATA[<p>Prin cautarile mele pe net gasisem o metoda interesanta de a face restore la zona DNS AD integrated ce corespunde domeniului AD si m-am gandit sa o explic putin. Locul in care am gasit aceasta metoda nu il mai retin insa o sa incerc eu sa explic cum se face si de ce eu nu as face asa <img src='http://www.winadmin.ro/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Dupa cum stiti fiecare domeniu AD are asociata si o zona DNS folosita in special pentru a localiza serviciile si sistemele din domeniu.</p>
<p>In majoritatea cazurilor aceasta zona este de tipul AD Integrated (poate fi si standard) adica zona e stocata in AD, replicata pe toate DC-urile, si incarcata automat la pornirea serviciului DNS. Fiind stocata in AD, backup-ul zonei este integrat in backup-ul de AD (systemstate) si bineinteles ca si restore-ul urmareste aceeasi procedura. Problema cu restore-ul de AD e ca trebuie sa restartezi DC-ul in modul de restore si in unele cazuri poate fi destul de neplacut. Plus ca trebuie sa faci restore la intreg systemstate-ul.</p>
<p>Deci, ce metoda mai buna de restore as avea daca accidental sterg zona sau o parte din ea?</p>
<p>Ideea ar fi sa creez o zona de tip standard secondary pe un alt server Windows:</p>
<p>&#160;</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image121.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb118.png" width="508" height="390" /></a> </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image122.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb119.png" width="506" height="388" /></a> </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image123.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb120.png" width="507" height="390" /></a> </p>
<p>Setez ca serverul sa traga o copie a zonei de pe un DNS server existent (domain controller).</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image124.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb121.png" width="506" height="389" /></a> </p>
<p>Si pe serverul care are deja zona setez “allow zone transfers” sa imi permita transferuri catre noul server.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image125.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb122.png" width="406" height="484" /></a> </p>
<p>La scurt timp pot vedea o copie a zonei pe noul server:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image126.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb123.png" width="644" height="450" /></a> </p>
<p>Zona fiind de tip standard, o gasim aici:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image127.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb124.png" width="644" height="449" /></a> </p>
<p>Iar continutul arata cam asa:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image128.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb125.png" width="644" height="431" /></a> </p>
<p>Acest fisier se updateaza pe baza informatiilor din zona din AD, deci va fi necesar sa ii facem un backup schedulat. Nu o sa mai detaliez procesul pentru ca e banal.</p>
<p>Acum sa explic si in ce ar consta procesul de restore. Considerand ca informatiile din zona din AD au “disparut”, luam fisierul cu numele zonei de pe noul server, il copiem pe un DC unde facem urmatoarele:</p>
<p>-stergem zona existenta</p>
<p>-o recream cu acelasi nume dar de nu AD Integrated. In felul acesta zona va fi stocata in %windir%\system32\dns\</p>
<p>-inlocuim fisierul cu numele zonei folosind fisierul de pe serverul de backup</p>
<p>-schimbam modul de storage din nou ca AD Integrated</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image129.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb126.png" width="644" height="450" /></a> </p>
<p>Nu spun ca e cea mai buna metoda, ci doar un mod de a realiza ceva. Acum daca stau sa ma gandesc as gasi metode chiar mai bune. As putea face backup-ul in felul urmator:</p>
<p>- schimb temporar zona de pe DC in standard primary</p>
<p>- fac backup</p>
<p>- schimb la loc in AD Integrated</p>
<p>Problema care o vad eu cu toate aceste metode, e cu permisiunile pe inregistrari. In momentul in care zona ajunge in AD, fiecare inregistrare de acolo reprezinta un obiect in AD cu ACL-uri la fel ca orice alt obiect. Daca ai apucat sa te folosesti de aceste ACL-uri (iar unele servicii se folosesc automat) atunci toate aceste proceduri iti vor sterge ACL-urile and it sucks!</p>
<p>Tocmai din cauza asta recomand ca restore-ul sa se faca via systemstate pe cat posibil.</p>
<p>Si ar mai fi si alte metode de a face backup/restore la zonele DNS. Dar … data viitoare.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2010/05/27/one-way-to-backup-and-restore-ad-dns-zones/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Group Policy Search Tool</title>
		<link>http://www.winadmin.ro/2010/05/26/group-policy-search-tool/</link>
		<comments>http://www.winadmin.ro/2010/05/26/group-policy-search-tool/#comments</comments>
		<pubDate>Wed, 26 May 2010 04:00:00 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Group Policy]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/?p=1612</guid>
		<description><![CDATA[Iata o aplicatie in nor destul de interesanta: http://gps.cloudapp.net Poate fi folosita ca si referinta pentru majoritatea seterilor din GPO. Si merge adaugata ca si search provider in Internet Explorer. Un must have pentru orice GPO admin.]]></description>
			<content:encoded><![CDATA[<p>Iata o aplicatie in nor destul de interesanta: <a title="http://gps.cloudapp.net" href="http://gps.cloudapp.net">http://gps.cloudapp.net</a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image118.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb115.png" width="625" height="484" /></a></p>
<p>Poate fi folosita ca si referinta pentru majoritatea seterilor din GPO.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image119.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb116.png" width="633" height="484" /></a></p>
<p>Si merge adaugata ca si search provider in Internet Explorer.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image120.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb117.png" width="306" height="484" /></a></p>
<p>Un must have pentru orice GPO admin.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2010/05/26/group-policy-search-tool/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Microsoft IT Environment Health Scanner</title>
		<link>http://www.winadmin.ro/2010/05/13/microsoft-it-environment-health-scanner/</link>
		<comments>http://www.winadmin.ro/2010/05/13/microsoft-it-environment-health-scanner/#comments</comments>
		<pubDate>Thu, 13 May 2010 06:05:27 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Windows Server]]></category>
		<category><![CDATA[EBS]]></category>
		<category><![CDATA[Health Scanner]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2010/05/13/microsoft-it-environment-health-scanner/</guid>
		<description><![CDATA[Microsoft IT Environment Health Scanner e un tool scos de cei din echipa de EBS care permite scanarea unei infrastructuri mici si poate identifica cele mai uzuale probleme. Il gasiti aici. Tineti minte ca poate fi rulat si intr-o infrastructura fara EBS. Singurul scenariu in care nu merge este atunci cand domeniul AD e la [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft IT Environment Health Scanner e un tool scos de cei din echipa de EBS care permite scanarea unei infrastructuri mici si poate identifica cele mai uzuale probleme. Il gasiti <a href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;FamilyID=dd7a00df-1a5b-4fb6-a8a6-657a7968bd11" target="_blank">aici</a>.</p>
<p>Tineti minte ca poate fi rulat si intr-o infrastructura fara EBS. Singurul scenariu in care nu merge este atunci cand domeniul AD e la functional level Windows 2008R2 (dar probabil ca la urmatorul release o sa mearga).</p>
<p>Mai jos aveti cateva imagini cu tool-ul. Comentariile sunt de priosos.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image35.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb35.png" width="644" height="384" /></a>&#160;</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image36.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb36.png" width="644" height="384" /></a> </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image37.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb37.png" width="644" height="383" /></a> </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image38.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb38.png" width="644" height="443" /></a> </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image39.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb39.png" width="644" height="460" /></a> </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image40.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb40.png" width="644" height="457" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2010/05/13/microsoft-it-environment-health-scanner/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Diagnostic pe Group Policy Preferences Mapped Drives</title>
		<link>http://www.winadmin.ro/2010/05/09/diagnostic-pe-group-policy-preferences-mapped-drives/</link>
		<comments>http://www.winadmin.ro/2010/05/09/diagnostic-pe-group-policy-preferences-mapped-drives/#comments</comments>
		<pubDate>Sun, 09 May 2010 20:19:32 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Group Policy Preferences]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/?p=1397</guid>
		<description><![CDATA[GPP (Group Policy Preferences) incepe sa fie din ce in ce mai folosit si inlocuieste multe din logon scripturi. Am fost inspirat sa scriu acest post ca raspuns al unui thread de pe ITBoard pentru a aduce putina lumina in zona de troubleshooting pe GPP. De retinut ca userenv.log nu logheaza actiunile specifice GPP, insa [...]]]></description>
			<content:encoded><![CDATA[<p>GPP (Group Policy Preferences) incepe sa fie din ce in ce mai folosit si inlocuieste multe din logon scripturi. Am fost inspirat sa scriu acest post ca raspuns al unui thread de pe ITBoard pentru a aduce putina lumina in zona de troubleshooting pe GPP.</p>
<p>De retinut ca userenv.log nu logheaza actiunile specifice GPP, insa poate fi folosit si acesta, deoarece GPP se aplica ca si parte a unui GPO.</p>
<p>Pentru a loga actiunile ce fac parte din aplicarea unui GPP e nevoie sa aplicam un GPO peste client care sa activeze tracing-ul peste o anumita componenta din GPO. De retinut ca se poate face tracing separat pentru fiecare componenta. Pot face tracing numai pentru Scheduled Tasks sau numai pentru Drive Mappings.</p>
<p>Toate aceste optiuni le gasim in GPO la rubrica Computer Configuration/Policies/Administrative Templates/System/Group Policy/Logging and Tracing.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image23.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb23.png" width="644" height="457" /></a></p>
<p>In exemplul meu am activat tracing pentru Drive Mappings.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image24.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb24.png" width="530" height="484" /></a></p>
<p>Ca sa functioneze si sa nu aveti probleme e bine sa specificati calea exacta catre locatia in care sa se salveze log-ul.</p>
<p>Dupa ce politica a fost aplicata pe client putem vedea cum arata log-ul pentru GPP-ul facut de test.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image25.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb25.png" width="644" height="459" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image26.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb26.png" width="644" height="460" /></a></p>
<p>Dupa cum vedem GPP-ul nostru sa aplica OK.</p>
<p>2010-05-09 22:52:08.492 [pid=0x144,tid=0x6ec] EVENT : The user &#8216;X:&#8217; preference item in the &#8216;GPP Test {D68144D1-8065-4D0D-9827-D869A6A5323F}&#8217; Group Policy object applied successfully.    <br />2010-05-09 22:52:08.492 [pid=0x144,tid=0x6ec] Completed class &lt;Drive&gt; &#8211; X:.     <br />2010-05-09 22:52:08.492 [pid=0x144,tid=0x6ec] {935D1B74-9CB8-4e3c-9914-7DD559B7A417}     <br />2010-05-09 22:52:08.492 [pid=0x144,tid=0x6ec] Starting class &lt;Drive&gt; &#8211; Y:.     <br />2010-05-09 22:52:08.492 [pid=0x144,tid=0x6ec] Set user security context.     <br />2010-05-09 22:52:08.523 [pid=0x144,tid=0x6ec] Set system security context.     <br />2010-05-09 22:52:08.523 [pid=0x144,tid=0x6ec] Properties handled.     <br />2010-05-09 22:52:08.523 [pid=0x144,tid=0x6ec] Handle Children.     <br />2010-05-09 22:52:08.523 [pid=0x144,tid=0x6ec] EVENT : The user &#8216;Y:&#8217; preference item in the &#8216;GPP Test {D68144D1-8065-4D0D-9827-D869A6A5323F}&#8217; Group Policy object applied successfully.     <br />2010-05-09 22:52:08.523 [pid=0x144,tid=0x6ec] Completed class &lt;Drive&gt; &#8211; Y:.     <br />2010-05-09 22:52:08.523 [pid=0x144,tid=0x6ec] Completed class &lt;Drives&gt;.     <br />2010-05-09 22:52:08.523 [pid=0x144,tid=0x6ec] Completed package execution.     <br />2010-05-09 22:52:08.523 [pid=0x144,tid=0x6ec] Completed execution of apply package.</p>
<p>Pentru un incepator, informatiile din aceste fisiere pot fi foarte criptice, iar in unele cazuri chiar si un avansat o sa aiba probleme in a le citi – in cazul asta apelati la MS Support. Aceste loguri de diagnostic au fost gandite in special pentru cei din support.</p>
<p>&#160;</p>
<p>Ce mai putem observa in fisierul de diagnostic, locul in care sunt stocate informatiile de despre mapped drives se afla in acelasi loc in care se afla GPO-ul, mai exact in cazul nostru in:</p>
<p><a href="//\\winadmin.local\SYSVOL\winadmin.local\Policies\{D68144D1-8065-4D0D-9827-D869A6A5323F}\User\Preferences\Drives">\\winadmin.local\SYSVOL\winadmin.local\Policies\{D68144D1-8065-4D0D-9827-D869A6A5323F}\User\Preferences\Drives</a></p>
<p>Fisierul se numeste drives.xml si arata cam asa:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image27.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb27.png" width="644" height="461" /></a></p>
<p>In cazul unui client care nu primeste maparile verificati daca puteti sa accesati acest fisier. Atentie ca la drive mappings nu conteaza daca ai permisiune pe share sau nu, maparea trebuie sa se faca oricum.</p>
<p>Cam atat deocamdata, pentru ca nu am lucrat suficient incat sa ma lovesc de probleme majore cu GPP.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2010/05/09/diagnostic-pe-group-policy-preferences-mapped-drives/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Account lockout tools &#8211; Acctinfo.dll &amp; Acctinfo2.dll</title>
		<link>http://www.winadmin.ro/2010/05/06/account-lockout-tools-acctinfo-dll-acctinfo2-dll/</link>
		<comments>http://www.winadmin.ro/2010/05/06/account-lockout-tools-acctinfo-dll-acctinfo2-dll/#comments</comments>
		<pubDate>Thu, 06 May 2010 04:00:00 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Account Lockout Tools]]></category>
		<category><![CDATA[ADUC]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/?p=1383</guid>
		<description><![CDATA[Probabil ca ati folosit pana acum Account Lockout Tools sau daca nu, macar ati auzit de ele. Despre gasiti aici: http://technet.microsoft.com/en-us/library/cc738772(WS.10).aspx Si download aici: http://www.microsoft.com/downloads/details.aspx?familyid=7AF2E69C-91F3-4E63-8629-B999ADDE0B9E&#38;displaylang=en Parte din acest packet este si Acctinfo.dll care adauga un nou tab in AD Users and Computers destul de folositor pentru taskurile de administrare. Problema e ca acest dll functioneaza [...]]]></description>
			<content:encoded><![CDATA[<p>Probabil ca ati folosit pana acum Account Lockout Tools sau daca nu, macar ati auzit de ele.</p>
<p>Despre gasiti aici:</p>
<p><a title="http://technet.microsoft.com/en-us/library/cc738772(WS.10).aspx" href="http://technet.microsoft.com/en-us/library/cc738772(WS.10).aspx">http://technet.microsoft.com/en-us/library/cc738772(WS.10).aspx</a></p>
<p>Si download aici:</p>
<p><a title="http://www.microsoft.com/downloads/details.aspx?familyid=7AF2E69C-91F3-4E63-8629-B999ADDE0B9E&amp;displaylang=en" href="http://www.microsoft.com/downloads/details.aspx?familyid=7AF2E69C-91F3-4E63-8629-B999ADDE0B9E&amp;displaylang=en">http://www.microsoft.com/downloads/details.aspx?familyid=7AF2E69C-91F3-4E63-8629-B999ADDE0B9E&amp;displaylang=en</a></p>
<p>Parte din acest packet este si Acctinfo.dll care adauga un nou tab in AD Users and Computers destul de folositor pentru taskurile de administrare.</p>
<p>Problema e ca acest dll functioneaza numai pe Windows x86 si cum W2K8 R2 vine numai in versiune x64 nu o sa mai functioneze. Mai nou umbla pe net si versiunea Acctinfo2.dll care mai avea cateva optiuni in plus dar nu era suportata de MS.</p>
<p>Recent am gasit si versiunea x64 a lui Acctinfo2.dll care merge inclusiv pe W2K8 R2. O gasiti aici <a title="http://www.activedir.org/ACCTINFO2_64BIT.zip" href="http://www.activedir.org/ACCTINFO2_64BIT.zip">http://www.activedir.org/ACCTINFO2_64BIT.zip</a></p>
<p>Pentru prima versiune era nevoie doar sa inregistrezi dll-ul, acum e nevoie de mai multi pasi. Ii gasiti pe toti in documentul din arhiva.</p>
<p>Dupa ce faceti ce scrie acolo tab-ul din ADUC o sa arate cam asa:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image19.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb19.png" width="362" height="484" /></a></p>
<p>Optiunea Most Recent Logon iti arata serverul care a autentificat ultima data acel cont.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image20.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb20.png" width="426" height="161" /></a></p>
<p>Poti vedea si replication metadata pentru acel obiect fara a mai fi nevoie de repadmin.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image21.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb21.png" width="644" height="461" /></a></p>
<p>Si pe baza lui lastlogon poti afla site-ul in care se afla utilizatorul si ii poti schimba parola chiar in acel site.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image22.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb22.png" width="510" height="226" /></a></p>
<p>&#160;</p>
<p>Nota: Acctinfo2.dll nu este suportat de MS. Nu numai ca nu e suportat, MS nu a publicat niciodata oficial acest dll. So use it on your own risk.</p>
<p>&#160;</p>
<p>Spor!</p>
<p>Andrei.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2010/05/06/account-lockout-tools-acctinfo-dll-acctinfo2-dll/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cum delegi dreptul de a face unlock la un user account</title>
		<link>http://www.winadmin.ro/2010/05/05/cum-delegi-dreptul-de-a-face-unlock-la-un-user-account/</link>
		<comments>http://www.winadmin.ro/2010/05/05/cum-delegi-dreptul-de-a-face-unlock-la-un-user-account/#comments</comments>
		<pubDate>Wed, 05 May 2010 04:00:00 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Delegation]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2010/05/05/cum-delegi-dreptul-de-a-face-unlock-la-un-user-account/</guid>
		<description><![CDATA[De multe ori atunci cand delegi permisiuni servicedesk-ului ajungi sa iti pui si problema daca sa delegi dreptul de a face unlock la un cont de utilizator. In general servicedesk-ul primeste dreptul de a reseta parole pentru ca asta e unul din rolurile lor de baza (trist dar adevarat), nu si unlock, probabil pentru ca [...]]]></description>
			<content:encoded><![CDATA[<p>De multe ori atunci cand delegi permisiuni servicedesk-ului ajungi sa iti pui si problema daca sa delegi dreptul de a face unlock la un cont de utilizator.</p>
<p>In general servicedesk-ul primeste dreptul de a reseta parole pentru ca asta e unul din rolurile lor de baza (trist dar adevarat), nu si unlock, probabil pentru ca nu exista un atribut anume pentru a fi delegat.</p>
<p>In cazul asta sa explicam cum se face. Prima data trebuie sa avem un grup pentru utilizatorii din servicedesk (intotdeauna delegati folosind grupuri nu user accounts).</p>
<p>Vom efectua exercitiul folosind consola AD Users &amp; Computers cu toate ca exista si alte metode ceva mai simple, insa nu pentru adminul incepator. Activam Advanced Features:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image7.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb7.png" width="395" height="318" /></a> </p>
<p>Ne ducem pe containerul peste care vrem sa delegam permisiunile:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image8.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb8.png" width="364" height="418" /></a> </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image9.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb9.png" width="406" height="451" /></a> </p>
<p>Click pe Add:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image10.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb10.png" width="629" height="472" /></a> </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image11.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb11.png" width="624" height="472" /></a> </p>
<p>Si de aici incepe delegarea permisiunilor:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image12.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb12.png" width="633" height="484" /></a> </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image13.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb13.png" width="345" height="484" /></a> </p>
<p>Iar acum dam drepturi peste atributul lockoutTime:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image14.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb14.png" width="371" height="471" /></a> </p>
<p>Din acest moment membrii grupului Servicedesk vor avea dreptul sa faca unlock pe conturile aflate in OU-ul peste care am efectuat delegarea.</p>
<p>Simplu, nu? O sa revin si cu alte taskuri din categoria delegari.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2010/05/05/cum-delegi-dreptul-de-a-face-unlock-la-un-user-account/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Group Policy Preferences &#8211; Immediate Tasks</title>
		<link>http://www.winadmin.ro/2010/04/21/group-policy-preferences-immediate-tasks/</link>
		<comments>http://www.winadmin.ro/2010/04/21/group-policy-preferences-immediate-tasks/#comments</comments>
		<pubDate>Wed, 21 Apr 2010 04:00:00 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Windows Server]]></category>
		<category><![CDATA[GPP]]></category>
		<category><![CDATA[Group Policy Preferences]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/?p=1258</guid>
		<description><![CDATA[Tocmai am descoperit o chestie super interesanta in Group Policy Preferences. Si anume posibilitatea de a rula taskuri pe sistemele din retea sub forma “Immediate Task”. In traducere: imediat ce se va aplica GPO-ul, task-ul publicat va rula. Ce e interesant aici fata de publicarea unui task via script distribuit prin GPO, e ca GPP [...]]]></description>
			<content:encoded><![CDATA[<p>Tocmai am descoperit o chestie super interesanta in Group Policy Preferences. Si anume posibilitatea de a rula taskuri pe sistemele din retea sub forma “Immediate Task”. In traducere: imediat ce se va aplica GPO-ul, task-ul publicat va rula.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/04/image7.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/04/image_thumb7.png" width="644" height="460" /></a></p>
<p>Ce e interesant aici fata de publicarea unui task via script distribuit prin GPO, e ca GPP se ocupa automat de operatiunea de cleanup. Task-ul va rula, dupa care va fi sters de pe sistem. In cazul cu simplu GPO era nevoie de mai multi pasi, inlcusiv de un GPO pentru cleanup.</p>
<p>Exemple in care ar merge folosita aceasta optiune ar fi: vrei sa rulezi comenzi gen ipconfig /flushdns pe toate sistemele din retea, vrei sa restartezi un serviciu, sa stergi fisiere temporare, etc</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2010/04/21/group-policy-preferences-immediate-tasks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Probleme cu RODC</title>
		<link>http://www.winadmin.ro/2010/04/18/probleme-cu-rodc/</link>
		<comments>http://www.winadmin.ro/2010/04/18/probleme-cu-rodc/#comments</comments>
		<pubDate>Sun, 18 Apr 2010 19:51:52 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[RODC]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2010/04/18/probleme-cu-rodc/</guid>
		<description><![CDATA[Studiam o problema de autentificare legata de clienti cu RODC (Read Only Domain Controller) in site si am dat peste urmatorul KB: http://support.microsoft.com/kb/944043 KB-ul descrie problemele care pot aparea atunci cand ai un RODC in retea si contine update-uri care trebuie instalate pe Windows 2003, XP si Vista. Deci, de retinut: daca folosesti RODC e [...]]]></description>
			<content:encoded><![CDATA[<p>Studiam o problema de autentificare legata de clienti cu RODC (Read Only Domain Controller) in site si am dat peste urmatorul KB:</p>
<p><a title="http://support.microsoft.com/kb/944043" href="http://support.microsoft.com/kb/944043">http://support.microsoft.com/kb/944043</a></p>
<p>KB-ul descrie problemele care pot aparea atunci cand ai un RODC in retea si contine update-uri care trebuie instalate pe Windows 2003, XP si Vista.</p>
<p>Deci, de retinut: daca folosesti RODC e obligatoriu sa instalezi updateurile de mai sus pe clienti si chiar si pe domain controllerele care mai ruleaza Windows 2003 in domeniu.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2010/04/18/probleme-cu-rodc/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>DCPROMO &#8211; clarificare</title>
		<link>http://www.winadmin.ro/2010/04/01/dcpromo-clarificare/</link>
		<comments>http://www.winadmin.ro/2010/04/01/dcpromo-clarificare/#comments</comments>
		<pubDate>Thu, 01 Apr 2010 10:34:41 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[DCPROMO]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2010/04/01/dcpromo-clarificare/</guid>
		<description><![CDATA[Dupa publicarea articolelor despre instalarea Active Directory am fost asaltat cu un val de intrebari legat de lipsa pasului in care trebuie adaugat rolul AD DS din consola roles. Ca sa fiu clar acum: adaugarea rolului din consola roles nu este necesara. Nici pe 2008 si nici pe 2008R2. Comanda DCPROMO adauga rolul automat (din [...]]]></description>
			<content:encoded><![CDATA[<p>Dupa publicarea articolelor despre instalarea Active Directory am fost asaltat cu un val de intrebari legat de lipsa pasului in care trebuie adaugat rolul AD DS din consola roles.</p>
<p>Ca sa fiu clar acum: adaugarea rolului din consola roles nu este necesara. Nici pe 2008 si nici pe 2008R2. Comanda DCPROMO adauga rolul automat (din cauza asta o sa stea si putin mai mult pana sa prezinte wizardul).</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/04/image.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/04/image_thumb.png" width="391" height="248" /></a> </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/04/image1.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/04/image_thumb1.png" width="507" height="480" /></a> </p>
<p>Daca in acest moment dau Cancel, primesc urmatorul mesaj:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/04/image2.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/04/image_thumb2.png" width="633" height="484" /></a> </p>
<p>Cititi cu atentie ce scrie acolo. Rolul a fost instalat de DCPROMO (mai exact, au fost copiate binarele, si atat, configurarea se face mai departe cu dcpromo).</p>
<p>A fost doar un post explicativ ca sa elimin anumite semne de intrebare.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2010/04/01/dcpromo-clarificare/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Identificarea conturilor inactive din Active Directory folosind Administrative Center</title>
		<link>http://www.winadmin.ro/2010/03/29/identificarea-conturilor-inactive-din-active-directory-folosind-administrative-center/</link>
		<comments>http://www.winadmin.ro/2010/03/29/identificarea-conturilor-inactive-din-active-directory-folosind-administrative-center/#comments</comments>
		<pubDate>Mon, 29 Mar 2010 04:00:06 +0000</pubDate>
		<dc:creator>Sebi22</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Windows Server]]></category>
		<category><![CDATA[cleanup]]></category>
		<category><![CDATA[computers]]></category>
		<category><![CDATA[users]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/?p=1130</guid>
		<description><![CDATA[Active Directory Administrative Center este un nou instrument de administrare a obiectelor din Active Directory, inclus in Windows Server 2008 R2 si disponibil in Windows 7 prin instalarea Remote Server Administration Tools. Folosind aceasta consola putem crea obiecte de tip user, computer, OU, sau le putem administra pe cele existente. De asemenea, putem efectua cautari [...]]]></description>
			<content:encoded><![CDATA[<p>Active Directory Administrative Center este un nou instrument de administrare a obiectelor din Active Directory, inclus in Windows Server 2008 R2 si disponibil in Windows 7 prin instalarea <a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=7D2F6AD7-656B-4313-A005-4E344E43997D&amp;displaylang=en">Remote Server Administration Tools</a>. Folosind aceasta consola putem crea obiecte de tip user, computer, OU, sau le putem administra pe cele existente. De asemenea, putem efectua cautari filtrate dupa diverse criterii. Aceste cautari ne pot ajuta, de exemplu, pentru Active Directory clean up, adica identificarea, dezactivarea si/sau stergerea conturilor de tip user sau computer nefolosite.</p>
<p>Sa vedem cum procedam. Deschidem ADAC ( Active Directory Administrative Center) din Administrative Tools :</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/clip_image0021.jpg"><img style="border-width: 0px" src="http://www.winadmin.ro/wp-content/uploads/2010/03/clip_image002_thumb1.jpg" border="0" alt="clip_image002" width="811" height="596" /></a></p>
<p>Mergem la Global Search si, in partea dreapta, expandam Add criteria. Bifam “Users with enabled accounts who have not logged on for more than a given numbers of days” si dam click pe Add :</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/clip_image0041.jpg"><img style="border-width: 0px" src="http://www.winadmin.ro/wp-content/uploads/2010/03/clip_image004_thumb1.jpg" border="0" alt="clip_image004" width="812" height="391" /></a></p>
<p>Acum putem selecta numar de zile :</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/clip_image0061.jpg"><img style="border-width: 0px" src="http://www.winadmin.ro/wp-content/uploads/2010/03/clip_image006_thumb1.jpg" border="0" alt="clip_image006" width="811" height="280" /></a></p>
<p>Sa zicem 60 de zile. Dupa care dam un click pe Search si avem rezultatul. Acum, ii putem selecta si, cu click dreapta sau din partea dreapta a consolei ( Tasks ), ii putem dezactiva sau sterge din Active Directory :</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/clip_image0081.jpg"><img style="border-width: 0px" src="http://www.winadmin.ro/wp-content/uploads/2010/03/clip_image008_thumb1.jpg" border="0" alt="clip_image008" width="811" height="286" /></a></p>
<p>Traducerea in LDAP a acestei cautari arata cam asa : cautam obiecte de tip user – persoana, enabled (vezi atributul UserAccountControl) inactive in perioada data curenta minus 60 zile, folosindu-ne de atributul lastLogonTimestamp. Valoarea acestuia din urma este updatata implicit la interval de 14 zile asa ca sfatul meu e sa nu folositi intervalul de 15 sau chiar 30 de zile pentru clean up, ca sa nu riscati sa stergeti conturi active. Convertirea valorii in format standard de timp este descrisa <a href="http://support.microsoft.com/kb/555936">aici</a> .</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/clip_image0101.jpg"><img style="border-width: 0px" src="http://www.winadmin.ro/wp-content/uploads/2010/03/clip_image010_thumb1.jpg" border="0" alt="clip_image010" width="813" height="500" /></a></p>
<p>Cum putem cauta computerele inactive timp de 60 de zile? Editam query-ul, inlocuind valoarea “person” a atributului objectCategory cu “computer”. Click pe Apply si gasim si computerele inactive pe care, de asemenea, le putem dezactiva sau sterge:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/clip_image0121.jpg"><img style="border-width: 0px" src="http://www.winadmin.ro/wp-content/uploads/2010/03/clip_image012_thumb1.jpg" border="0" alt="clip_image012" width="812" height="431" /></a></p>
<p>Spuneam ca ADAC a aparut de la Windows Server 2008 R2. Consola poate fi folosita totusi si cu Active Directory 2003 si 2008. Vedeti <a href="http://www.winadmin.ro/2009/12/04/powershell-active-directory-module-si-windows-2003-domain-controllers/">aici</a> conditiile. Sunt valabile si pentru ADAC.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2010/03/29/identificarea-conturilor-inactive-din-active-directory-folosind-administrative-center/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
