<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>RO Windows Administrators Weblog &#187; Active Directory</title>
	<atom:link href="http://www.winadmin.ro/tag/active-directory/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.winadmin.ro</link>
	<description>Weblogul adminilor de Windows din Romania.</description>
	<lastBuildDate>Fri, 03 Feb 2012 19:33:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Active Directory over NAT</title>
		<link>http://www.winadmin.ro/2011/12/02/active-directory-over-nat/</link>
		<comments>http://www.winadmin.ro/2011/12/02/active-directory-over-nat/#comments</comments>
		<pubDate>Fri, 02 Dec 2011 05:00:00 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[NAT]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2011/12/02/active-directory-over-nat/</guid>
		<description><![CDATA[AD peste NAT nu e un scenariu foarte bun insa sunt cazuri cand mai dai de asa ceva. Ce nu stiu multi este ca suportul pentru astfel de scenarii este destul de limitat (undeva intre limitat si deloc). The Microsoft statement regarding Active Directory over NAT is: Active Directory over NAT has not been tested [...]]]></description>
			<content:encoded><![CDATA[<p>AD peste NAT nu e un scenariu foarte bun insa sunt cazuri cand mai dai de asa ceva. Ce nu stiu multi este ca suportul pentru astfel de scenarii este destul de limitat (undeva intre limitat si deloc).</p>
<p><em>The Microsoft statement regarding Active Directory over NAT is: </em></p>
<ul>
<li><em>Active Directory over NAT has not been tested by Microsoft. </em></li>
<li><em>We do not recommend Active Directory over NAT. </em></li>
<li><em>Support for issues related to Active Directory over NAT will be very limited and will reach the bounds of commercially reasonable efforts very quickly. </em></li>
</ul>
<p><em>The only configuration with NAT that was tested by Microsoft is running client on the private side of a NAT and have all servers located on the public side of the NAT. The NAT would also function as a DNS server.</em></p>
<p><a title="http://support.microsoft.com/kb/978772" href="http://support.microsoft.com/kb/978772">http://support.microsoft.com/kb/978772</a></p>
<p><a href="http://support.microsoft.com/kb/186340/en-us">http://support.microsoft.com/kb/186340/en-us</a></p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2011/12/02/active-directory-over-nat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Search Active Directory from Windows 7</title>
		<link>http://www.winadmin.ro/2011/06/10/search-active-directory-from-windows-7/</link>
		<comments>http://www.winadmin.ro/2011/06/10/search-active-directory-from-windows-7/#comments</comments>
		<pubDate>Fri, 10 Jun 2011 04:00:00 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Windows Client]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2011/06/10/search-active-directory-from-windows-7/</guid>
		<description><![CDATA[Utilizatorii mai experimentati ai Windows XP stiau ca din Address Book era si o optiune care deschidea un search LDAP ce putea fi folosit sa faci cautari in AD. In Windows 7 lucrurile s-au schimbat, insa tot se pot efectua cautari in AD. Mai jos gasiti in imagini cum. Sau daca vreti ceva mai scurt, [...]]]></description>
			<content:encoded><![CDATA[<p>Utilizatorii mai experimentati ai Windows XP stiau ca din Address Book era si o optiune care deschidea un search LDAP ce putea fi folosit sa faci cautari in AD.</p>
<p>In Windows 7 lucrurile s-au schimbat, insa tot se pot efectua cautari in AD. Mai jos gasiti in imagini cum.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/06/image13.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/06/image_thumb13.png" width="413" height="167" /></a> </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/06/image14.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/06/image_thumb14.png" width="644" height="99" /></a> </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/06/image15.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/06/image_thumb15.png" width="530" height="322" /></a> </p>
<p>Sau daca vreti ceva mai scurt, iata comanda:</p>
<p><strong>&quot;C:\Windows\System32\rundll32.exe&quot; dsquery.dll,OpenQueryWindow</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2011/06/10/search-active-directory-from-windows-7/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cum poti ascunde Organizational Unit-uri in Active Directory</title>
		<link>http://www.winadmin.ro/2011/06/03/cum-poti-ascunde-organizational-unit-uri-in-active-directory/</link>
		<comments>http://www.winadmin.ro/2011/06/03/cum-poti-ascunde-organizational-unit-uri-in-active-directory/#comments</comments>
		<pubDate>Fri, 03 Jun 2011 11:04:24 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Organizational Unit]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2011/06/03/cum-poti-ascunde-organizational-unit-uri-in-active-directory/</guid>
		<description><![CDATA[Pe vremuri raspundeam la intrebarea asta cu nu se poate, insa pe parcurs am aflat si eu cateva metode prin care ai putea sa faci anumite OU-uri invizibile pentru anumiti administratori. Atentie ca nu ma refer la Domain Admins. By default orice user din AD are drept de Read &#38; List Contents peste toate obiectele [...]]]></description>
			<content:encoded><![CDATA[<p>Pe vremuri raspundeam la intrebarea asta cu nu se poate, insa pe parcurs am aflat si eu cateva metode prin care ai putea sa faci anumite OU-uri invizibile pentru anumiti administratori. Atentie ca nu ma refer la Domain Admins.</p>
<p>By default orice user din AD are drept de Read &amp; List Contents peste toate obiectele din AD, asta fiind motivul pentru care toate obiectele sunt vizibile din ADUC.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/06/image.png"><img style="border-bottom: 0px;border-left: 0px;margin: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/06/image_thumb.png" width="370" height="468" /></a></p>
<p>Dar sa luam cazul in care vrem sa gazduim in AD-ul nostru doua companii iar administratorii delegati peste obiectele din AD nu au voie sa vada decat OU-ul companiei lor. Daca am lasa totul default, lucrurile ar arata asa:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/06/image1.png"><img style="border-bottom: 0px;border-left: 0px;margin: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/06/image_thumb1.png" width="644" height="292" /></a></p>
<p>Iar daca am scoatem Authenticated Users din ACL-ul companiei B si ne conectam cu un user normal:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/06/image2.png"><img style="border-bottom: 0px;border-left: 0px;margin: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/06/image_thumb2.png" width="644" height="326" /></a></p>
<p>Ii blocam cumva accesul user-ului la acel OU insa tot il va vedea, ca Unknown bineinteles pentru ca nu ii poate citi nici macar ACL-ul.</p>
<p>Ca sa facem sa dispara complet acel OU, e nevoie sa activam List Object Mode. Asta se face activand DsHeuristics pe 001 (mai exact al treilea bit trebuie setat pe 1; daca aveti si alti biti setati, lasati-i in pace). </p>
<p>Detalii la <a title="http://technet.microsoft.com/en-us/library/dd346510.aspx" href="http://technet.microsoft.com/en-us/library/dd346510.aspx">http://technet.microsoft.com/en-us/library/dd346510.aspx</a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/06/image3.png"><img style="border-bottom: 0px;border-left: 0px;margin: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/06/image_thumb3.png" width="594" height="484" /></a></p>
<p>Setarea se aplica la nivel de forest. Nu este necesar reboot. </p>
<p>Imediat dupa modificare putem vedea ca in ACL-uri apare si List Object:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/06/image4.png"><img style="border-bottom: 0px;border-left: 0px;margin: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/06/image_thumb4.png" width="368" height="468" /></a></p>
<p>Ca sa facem sa dispara un OU, de exemplu “Company B”, e nevoie sa scoatem List Contents de pe containerul Hosting:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/06/image5.png"><img style="border-bottom: 0px;border-left: 0px;margin: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/06/image_thumb5.png" width="369" height="471" /></a></p>
<p>Iar pe containerul Company B, scoatem si List Contents si List Object (merge si daca scoatem List Object, insa List Contents va bloca si queryurile LDAP):</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/06/image6.png"><img style="border-bottom: 0px;border-left: 0px;margin: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/06/image_thumb6.png" width="364" height="470" /></a></p>
<p>Iar rezultatul este urmatorul:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/06/image7.png"><img style="border-bottom: 0px;border-left: 0px;margin: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/06/image_thumb7.png" width="644" height="256" /></a></p>
<p>Pe scurt: List Contents scos de pe containerul parinte, List Object si List Contents de pe child.</p>
<p>Ce am facut eu pana acum a fost doar sa restrictionez vizibilitatea acestui OU pentru Authenticated Users, mai departe puteti asigna permisiuni de Read/List Contents/List Object pentru userii/grupurile ce vor avea access.</p>
<p><strong>ATENTIE</strong> la grupul Pre-Windows 2000 Compatible Access. Daca aveti activata aceasta optiune, atunci Authenticated Users o sa faca parte din acest grup. Ori dati remove ori modificati permisiunile si pentru Pre-Windows 2000 pentru ca altfel nu o sa mearga.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/06/image8.png"><img style="border-bottom: 0px;border-left: 0px;margin: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/06/image_thumb8.png" width="406" height="469" /></a></p>
<p>Si cam asta e tot, pentru intrebari va astept pe forum.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2011/06/03/cum-poti-ascunde-organizational-unit-uri-in-active-directory/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adaugarea pozelor in AD folosind Exchange Management Shell</title>
		<link>http://www.winadmin.ro/2011/05/31/adaugarea-pozelor-in-ad-folosind-exchange-management-shell/</link>
		<comments>http://www.winadmin.ro/2011/05/31/adaugarea-pozelor-in-ad-folosind-exchange-management-shell/#comments</comments>
		<pubDate>Tue, 31 May 2011 14:24:00 +0000</pubDate>
		<dc:creator>Vitalie Ciobanu</dc:creator>
				<category><![CDATA[Exchange]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Poze]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2011/05/31/adaugarea-pozelor-in-ad-folosind-exchange-management-shell/</guid>
		<description><![CDATA[Ma jucam azi cu un coleg cu Exchange si AD si am ajuns la pasul de import poze pentru useri. Am cerut poze, le-am modificat cum ne trebuie si hai sa facem bulk upload. Pac-pac! Minunat! &#160; Bun, hai sa vedem ce si cum am facut. Pentru inceput, cerinte: modificam schema de AD facem rost [...]]]></description>
			<content:encoded><![CDATA[<p>Ma jucam azi cu un coleg cu Exchange si AD si am ajuns la pasul de import poze pentru useri. Am cerut poze, le-am modificat cum ne trebuie si hai sa facem bulk upload. Pac-pac! Minunat! <img style="border-bottom-style: none;border-left-style: none;border-top-style: none;border-right-style: none" class="wlEmoticon wlEmoticon-smile" alt="Smile" src="http://www.winadmin.ro/wp-content/uploads/2011/05/wlEmoticon-smile.png" /></p>
<p>&#160;</p>
<p>Bun, hai sa vedem ce si cum am facut. Pentru inceput, cerinte:</p>
<ol>
<li>modificam schema de AD </li>
<li>facem rost de poze </li>
<li>cunostinte minime powershell sau Gugl </li>
</ol>
<p>Pentru modificarea schemei de AD rulam urmatoarea comanda intr-un cmd cu Run As Administrator: </p>
<blockquote><p><strong>Regsvr32 schmmgmt.dll</strong></p>
</blockquote>
<p>Facem rost de poze ale utilizatorilor. Le modificam sa fie sub 10 KB, 96&#215;96 px si le salvam ca .JPG</p>
<p>Acum, punem pozele intr-un director (sa zicem C:\Emp_Pictures) si le redenumim in <em>alias.jpg</em> de exemplu. Teoretic, calea catre poza mea va fi C:\Emp_Pictures\vitalie.ciobanu.jpg</p>
<p>Daca vrem sa importam poza pentru un singur utilizator, rulam comanda de mai jos in Exchange Management Shell:</p>
<blockquote><p>Import-RecipientDataProperty -Identity vitalie.ciobanu -Picture -FileData ([Byte[]]$(Get-Content -path C:\Emp_Pictures\vitalie.ciobanu.jpg -Encoding Byte -ReadCount 0))</p>
</blockquote>
<p>Daca vrem sa importam pozele pentru suta de utilizatori, trebuie sa cream un fisier CSV cu datele despre utilizatori si calea catre poza fiecaruia. Fisierul CSV trebuie sa aiba doar doua coloane: alias si calea catre fisier. Mai jos e un exemplu de fisier csv:</p>
<blockquote><p>alias,</td>
<td width="64">cale,</p>
</td>
</tr>
<tr>
<td>vitalie.ciobanu,</td>
<td>C:\Emp_Pictures\vitalie.ciobanu.jpg</p>
<p>prenume.nume,C:\Emp_Pictures\prenume.nume.jpg</p>
</blockquote>
<p>Tip:</p>
<blockquote><p><font>Ca sa nu va chinuiti sa faceti copy/paste la alias in calea catre poza userului, deschideti un excel si in celula B2 scrieti: <strong>=&quot;C:\Emp_Pictures\&quot;&amp;A2&amp;&quot;.jpg&quot;</strong> si copiati formula in jos cat aveti inregistrari (aliasuri) in coloana A. Pentru celula B3, evident, stringul va fi <strong>=&quot;C:\Emp_Pictures\&quot;&amp;A3&amp;&quot;.jpg&quot;</strong> si tot asa mai departe…</font></p>
<p><font>Salvati fisierul excel ca <strong>Emp_Pictures.csv</strong> pe discul C: de exemplu.</font></p>
</blockquote>
<p>Pentru a adauga poze mai multor utilizatori, rulam comanda de mai jos in Exchange Management Shell:</p>
<blockquote><p>Import-CSV C:\Emp_Pictures.csv | % {Import-RecipientDataProperty -Identity $_.alias -Picture -FileData ([Byte[]]$(Get-Content -Path $_.cale -Encoding Byte -ReadCount 0)) }</p>
</blockquote>
<p>Daca vreti sa vedeti ce mai fac si unii MVP (din afara, evident <img style="border-bottom-style: none;border-left-style: none;border-top-style: none;border-right-style: none" class="wlEmoticon wlEmoticon-smile" alt="Smile" src="http://www.winadmin.ro/wp-content/uploads/2011/05/wlEmoticon-smile.png" />), intrati aici <a title="Manage Exchange 2010 Thumbnail Photos with a PowerShell Based GUI" href="http://www.mikepfeiffer.net/2010/05/manage-exchange-2010-thumbnail-photos-with-a-powershell-based-gui/" target="_blank">http://www.mikepfeiffer.net/2010/05/manage-exchange-2010-thumbnail-photos-with-a-powershell-based-gui/</a>&#160;</p>
<p>&#160;</p>
<p><strong>Disclaimer:</strong></p>
<p>This weblog contains my personal opinions, offered in good faith, but also come with no guarantees or warrantees. These opinions does not necessarily reflect those of my employer nor the committees I’m member of.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2011/05/31/adaugarea-pozelor-in-ad-folosind-exchange-management-shell/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Bulk User import cu New-ADUser</title>
		<link>http://www.winadmin.ro/2011/02/14/bulk-user-import-cu-new-aduser/</link>
		<comments>http://www.winadmin.ro/2011/02/14/bulk-user-import-cu-new-aduser/#comments</comments>
		<pubDate>Mon, 14 Feb 2011 05:00:00 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Scripting]]></category>
		<category><![CDATA[Powershell]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2011/02/14/bulk-user-import-cu-new-aduser/</guid>
		<description><![CDATA[Am scris cum se face cu vbs, iar acum e randul variantei Powershell. Cu Powershell poate fi mai simplu sau mai complicat, depinde exact ce vrei sa faci. Obiecte de tip user pot fi create foarte usor cu cmdlet-ul New-ADUser. Nota: pentru a afla care e smecheria cu $Password, vezi mai pe la sfarsitul post-ului. [...]]]></description>
			<content:encoded><![CDATA[<p>Am scris cum se face cu <a href="http://www.winadmin.ro/2011/01/17/create-ad-users-from-csvvbscript-edition/">vbs</a>, iar acum e randul variantei Powershell.</p>
<p>Cu Powershell poate fi mai simplu sau mai complicat, depinde exact ce vrei sa faci. Obiecte de tip user pot fi create foarte usor cu cmdlet-ul New-ADUser.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/02/image18.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/02/image_thumb18.png" width="644" height="157" /></a> </p>
<p>Nota: pentru a afla care e <em>smecheria</em> cu $Password, vezi mai pe la sfarsitul post-ului.</p>
<p>Iar daca vrei sa importi o lista de useri din CSV, poti sa o faci dintr-o singura linie folosind Import-CSV:</p>
<p>Import-CSV users.csv | New-ADUser</p>
<p>Trebuie doar sa fii atent ca primul rand din CSV sa contina numele atributelor asa cum le vrea New-ADUser (vezi in help parametrii ceruti de New-ADUser). Nu e nevoie sa fie in ordine.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/02/image19.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/02/image_thumb19.png" width="452" height="158" /></a> </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/02/image20.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/02/image_thumb20.png" width="438" height="149" /></a> </p>
</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/02/image21.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/02/image_thumb21.png" width="413" height="213" /></a> </p>
<p>Mai complicat e cu Powershell sa ii setezi parola user-ului si sa-l activezi, dar folosind urmatoarea comanda se rezolva:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/02/image22.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/02/image_thumb22.png" width="644" height="98" /></a> </p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/02/image23.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/02/image_thumb23.png" width="404" height="206" /></a> </p>
<p>Pentru a functiona e nevoie sa definiti inainte variabila $Password ca securestring:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/02/image24.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/02/image_thumb24.png" width="644" height="147" /></a></p>
<p>Mai merge si cu readhost – assecurestring:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/02/image25.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/02/image_thumb25.png" width="644" height="117" /></a>&#160;</p>
<p>Aceasta valoare va va deveni parola utilizatorului. Daca doriti sa importati parola din CSV (fiecare user cu parola separata) atunci e mai mult de munca si e nevoie de un script care sa citeasca parola din CSV sa o transforme in securestring si abia apoi sa rulati new-aduser in cadrul scriptului.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2011/02/14/bulk-user-import-cu-new-aduser/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AD Attributes Mapping</title>
		<link>http://www.winadmin.ro/2011/01/19/ad-attributes-mapping/</link>
		<comments>http://www.winadmin.ro/2011/01/19/ad-attributes-mapping/#comments</comments>
		<pubDate>Wed, 19 Jan 2011 05:00:00 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Attributes]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2011/01/19/ad-attributes-mapping/</guid>
		<description><![CDATA[Am mai scris mai demult aici http://www.winadmin.ro/2009/12/15/reference-tables-on-active-directory/ si am dat un link util http://www.kouti.com/tables.htm Totusi zilele astea scormonind prin MSDN am gasit ceva si acolo: http://msdn.microsoft.com/en-us/library/ms677980(v=VS.85).aspx User Object User interface Mapping e organizat pe tab-urile din ADUC si e foarte simplu de gasit atributul corespunzator unui anumit camp. Util atunci cand vrei sa faci rapid [...]]]></description>
			<content:encoded><![CDATA[<p>Am mai scris mai demult aici <a title="http://www.winadmin.ro/2009/12/15/reference-tables-on-active-directory/" href="http://www.winadmin.ro/2009/12/15/reference-tables-on-active-directory/">http://www.winadmin.ro/2009/12/15/reference-tables-on-active-directory/</a> si am dat un link util <a title="http://www.kouti.com/tables.htm" href="http://www.kouti.com/tables.htm">http://www.kouti.com/tables.htm</a></p>
<p>Totusi zilele astea scormonind prin MSDN am gasit ceva si acolo:</p>
<p><a title="http://msdn.microsoft.com/en-us/library/ms677980(v=VS.85).aspx" href="http://msdn.microsoft.com/en-us/library/ms677980(v=VS.85).aspx">http://msdn.microsoft.com/en-us/library/ms677980(v=VS.85).aspx</a></p>
<p>User Object User interface Mapping e organizat pe tab-urile din ADUC si e foarte simplu de gasit atributul corespunzator unui anumit camp.</p>
<p>Util atunci cand vrei sa faci rapid un script pe genunchi.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2011/01/19/ad-attributes-mapping/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cum se aplica Accounts Policy pe Domain Controllere</title>
		<link>http://www.winadmin.ro/2010/11/17/cum-se-aplica-accounts-policy-pe-domain-controllere/</link>
		<comments>http://www.winadmin.ro/2010/11/17/cum-se-aplica-accounts-policy-pe-domain-controllere/#comments</comments>
		<pubDate>Wed, 17 Nov 2010 13:22:47 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Windows Server]]></category>
		<category><![CDATA[Accounts Policy]]></category>
		<category><![CDATA[Default Domain Policy]]></category>
		<category><![CDATA[Group Policy]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2010/11/17/cum-se-aplica-accounts-policy-pe-domain-controllere/</guid>
		<description><![CDATA[Am fost invatati de pe vremea lui Windows 2000, ca putem avea o singura politica de parole la nivel de domeniu, definita in Default Domains Policy. Mai exact vorbim de Accounts Policy nu doar de politica de parole. Incepand cu Windows 2008, lucrurile s-au schimbat si a fost introduse Fine Grained Password Policies dar mai [...]]]></description>
			<content:encoded><![CDATA[<p>Am fost invatati de pe vremea lui Windows 2000, ca putem avea o singura politica de parole la nivel de domeniu, definita in Default Domains Policy. Mai exact vorbim de Accounts Policy nu doar de politica de parole. Incepand cu Windows 2008, lucrurile s-au schimbat si a fost introduse Fine Grained Password Policies dar mai multe intr-un alt post.</p>
<p>In continuare si in Windows 2008, daca nu folosim Fine Grained Password Policies, se aplica setarile din politica de domeniu.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/11/image11.png"><img style="border-bottom: 0px;border-left: 0px;margin: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/11/image_thumb11.png" width="644" height="452" /></a></p>
<p>Nu de putine ori am vazut admini incercand sa seteze Accounts Policy in politica ce se aplica pe containerul Domain Controllers &#8211; Default Domain Controllers Policy. Setarile puse acolo nu au nici un efect. Si o sa explic si de ce.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/11/image12.png"><img style="border-bottom: 0px;border-left: 0px;margin: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/11/image_thumb12.png" width="644" height="326" /></a></p>
<p>Da, stiu, putem seta pe un alt OU care contine computer accounturi, Accounts Policy, dar setarile se vor aplica si vor avea efect doar pentru conturile locale, iar cele de domeniu folosite pe acele masini nu vor fi afectate. Cum domain controllerele nu au conturi locale, mecanismul asta nu se aplica. Domain controllerele citesc Accounts Policy numai din politica de domeniu si ignora orice altceva setat intr-o politica legata de containerul Domain Controllers sau alt OU.</p>
<p>In afara de Accounts Policy se mai citesc din politica de domeniu si urmatoarele aflate Security Settings/Local Policies/Security Options:</p>
<p>Accounts: Administrator account status   <br />Accounts: Guest account status    <br />Accounts: Rename administrator account    <br />Accounts: Rename guest account    <br />Network security: Force logoff when logon hours expire</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/11/image13.png"><img style="border-bottom: 0px;border-left: 0px;margin: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/11/image_thumb13.png" width="644" height="331" /></a></p>
<p>Pentru intrebari va astept pe <a href="http://forum.winadmin.ro">forum</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2010/11/17/cum-se-aplica-accounts-policy-pe-domain-controllere/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Account lockout tools &#8211; Acctinfo.dll &amp; Acctinfo2.dll</title>
		<link>http://www.winadmin.ro/2010/05/06/account-lockout-tools-acctinfo-dll-acctinfo2-dll/</link>
		<comments>http://www.winadmin.ro/2010/05/06/account-lockout-tools-acctinfo-dll-acctinfo2-dll/#comments</comments>
		<pubDate>Thu, 06 May 2010 04:00:00 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Account Lockout Tools]]></category>
		<category><![CDATA[ADUC]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/?p=1383</guid>
		<description><![CDATA[Probabil ca ati folosit pana acum Account Lockout Tools sau daca nu, macar ati auzit de ele. Despre gasiti aici: http://technet.microsoft.com/en-us/library/cc738772(WS.10).aspx Si download aici: http://www.microsoft.com/downloads/details.aspx?familyid=7AF2E69C-91F3-4E63-8629-B999ADDE0B9E&#38;displaylang=en Parte din acest packet este si Acctinfo.dll care adauga un nou tab in AD Users and Computers destul de folositor pentru taskurile de administrare. Problema e ca acest dll functioneaza [...]]]></description>
			<content:encoded><![CDATA[<p>Probabil ca ati folosit pana acum Account Lockout Tools sau daca nu, macar ati auzit de ele.</p>
<p>Despre gasiti aici:</p>
<p><a title="http://technet.microsoft.com/en-us/library/cc738772(WS.10).aspx" href="http://technet.microsoft.com/en-us/library/cc738772(WS.10).aspx">http://technet.microsoft.com/en-us/library/cc738772(WS.10).aspx</a></p>
<p>Si download aici:</p>
<p><a title="http://www.microsoft.com/downloads/details.aspx?familyid=7AF2E69C-91F3-4E63-8629-B999ADDE0B9E&amp;displaylang=en" href="http://www.microsoft.com/downloads/details.aspx?familyid=7AF2E69C-91F3-4E63-8629-B999ADDE0B9E&amp;displaylang=en">http://www.microsoft.com/downloads/details.aspx?familyid=7AF2E69C-91F3-4E63-8629-B999ADDE0B9E&amp;displaylang=en</a></p>
<p>Parte din acest packet este si Acctinfo.dll care adauga un nou tab in AD Users and Computers destul de folositor pentru taskurile de administrare.</p>
<p>Problema e ca acest dll functioneaza numai pe Windows x86 si cum W2K8 R2 vine numai in versiune x64 nu o sa mai functioneze. Mai nou umbla pe net si versiunea Acctinfo2.dll care mai avea cateva optiuni in plus dar nu era suportata de MS.</p>
<p>Recent am gasit si versiunea x64 a lui Acctinfo2.dll care merge inclusiv pe W2K8 R2. O gasiti aici <a title="http://www.activedir.org/ACCTINFO2_64BIT.zip" href="http://www.activedir.org/ACCTINFO2_64BIT.zip">http://www.activedir.org/ACCTINFO2_64BIT.zip</a></p>
<p>Pentru prima versiune era nevoie doar sa inregistrezi dll-ul, acum e nevoie de mai multi pasi. Ii gasiti pe toti in documentul din arhiva.</p>
<p>Dupa ce faceti ce scrie acolo tab-ul din ADUC o sa arate cam asa:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image19.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb19.png" width="362" height="484" /></a></p>
<p>Optiunea Most Recent Logon iti arata serverul care a autentificat ultima data acel cont.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image20.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb20.png" width="426" height="161" /></a></p>
<p>Poti vedea si replication metadata pentru acel obiect fara a mai fi nevoie de repadmin.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image21.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb21.png" width="644" height="461" /></a></p>
<p>Si pe baza lui lastlogon poti afla site-ul in care se afla utilizatorul si ii poti schimba parola chiar in acel site.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/05/image22.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/05/image_thumb22.png" width="510" height="226" /></a></p>
<p>&#160;</p>
<p>Nota: Acctinfo2.dll nu este suportat de MS. Nu numai ca nu e suportat, MS nu a publicat niciodata oficial acest dll. So use it on your own risk.</p>
<p>&#160;</p>
<p>Spor!</p>
<p>Andrei.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2010/05/06/account-lockout-tools-acctinfo-dll-acctinfo2-dll/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Probleme cu RODC</title>
		<link>http://www.winadmin.ro/2010/04/18/probleme-cu-rodc/</link>
		<comments>http://www.winadmin.ro/2010/04/18/probleme-cu-rodc/#comments</comments>
		<pubDate>Sun, 18 Apr 2010 19:51:52 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[RODC]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2010/04/18/probleme-cu-rodc/</guid>
		<description><![CDATA[Studiam o problema de autentificare legata de clienti cu RODC (Read Only Domain Controller) in site si am dat peste urmatorul KB: http://support.microsoft.com/kb/944043 KB-ul descrie problemele care pot aparea atunci cand ai un RODC in retea si contine update-uri care trebuie instalate pe Windows 2003, XP si Vista. Deci, de retinut: daca folosesti RODC e [...]]]></description>
			<content:encoded><![CDATA[<p>Studiam o problema de autentificare legata de clienti cu RODC (Read Only Domain Controller) in site si am dat peste urmatorul KB:</p>
<p><a title="http://support.microsoft.com/kb/944043" href="http://support.microsoft.com/kb/944043">http://support.microsoft.com/kb/944043</a></p>
<p>KB-ul descrie problemele care pot aparea atunci cand ai un RODC in retea si contine update-uri care trebuie instalate pe Windows 2003, XP si Vista.</p>
<p>Deci, de retinut: daca folosesti RODC e obligatoriu sa instalezi updateurile de mai sus pe clienti si chiar si pe domain controllerele care mai ruleaza Windows 2003 in domeniu.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2010/04/18/probleme-cu-rodc/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Identificarea conturilor inactive din Active Directory folosind Administrative Center</title>
		<link>http://www.winadmin.ro/2010/03/29/identificarea-conturilor-inactive-din-active-directory-folosind-administrative-center/</link>
		<comments>http://www.winadmin.ro/2010/03/29/identificarea-conturilor-inactive-din-active-directory-folosind-administrative-center/#comments</comments>
		<pubDate>Mon, 29 Mar 2010 04:00:06 +0000</pubDate>
		<dc:creator>Sebi22</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Windows Server]]></category>
		<category><![CDATA[cleanup]]></category>
		<category><![CDATA[computers]]></category>
		<category><![CDATA[users]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/?p=1130</guid>
		<description><![CDATA[Active Directory Administrative Center este un nou instrument de administrare a obiectelor din Active Directory, inclus in Windows Server 2008 R2 si disponibil in Windows 7 prin instalarea Remote Server Administration Tools. Folosind aceasta consola putem crea obiecte de tip user, computer, OU, sau le putem administra pe cele existente. De asemenea, putem efectua cautari [...]]]></description>
			<content:encoded><![CDATA[<p>Active Directory Administrative Center este un nou instrument de administrare a obiectelor din Active Directory, inclus in Windows Server 2008 R2 si disponibil in Windows 7 prin instalarea <a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=7D2F6AD7-656B-4313-A005-4E344E43997D&amp;displaylang=en">Remote Server Administration Tools</a>. Folosind aceasta consola putem crea obiecte de tip user, computer, OU, sau le putem administra pe cele existente. De asemenea, putem efectua cautari filtrate dupa diverse criterii. Aceste cautari ne pot ajuta, de exemplu, pentru Active Directory clean up, adica identificarea, dezactivarea si/sau stergerea conturilor de tip user sau computer nefolosite.</p>
<p>Sa vedem cum procedam. Deschidem ADAC ( Active Directory Administrative Center) din Administrative Tools :</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/clip_image0021.jpg"><img style="border-width: 0px" src="http://www.winadmin.ro/wp-content/uploads/2010/03/clip_image002_thumb1.jpg" border="0" alt="clip_image002" width="811" height="596" /></a></p>
<p>Mergem la Global Search si, in partea dreapta, expandam Add criteria. Bifam “Users with enabled accounts who have not logged on for more than a given numbers of days” si dam click pe Add :</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/clip_image0041.jpg"><img style="border-width: 0px" src="http://www.winadmin.ro/wp-content/uploads/2010/03/clip_image004_thumb1.jpg" border="0" alt="clip_image004" width="812" height="391" /></a></p>
<p>Acum putem selecta numar de zile :</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/clip_image0061.jpg"><img style="border-width: 0px" src="http://www.winadmin.ro/wp-content/uploads/2010/03/clip_image006_thumb1.jpg" border="0" alt="clip_image006" width="811" height="280" /></a></p>
<p>Sa zicem 60 de zile. Dupa care dam un click pe Search si avem rezultatul. Acum, ii putem selecta si, cu click dreapta sau din partea dreapta a consolei ( Tasks ), ii putem dezactiva sau sterge din Active Directory :</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/clip_image0081.jpg"><img style="border-width: 0px" src="http://www.winadmin.ro/wp-content/uploads/2010/03/clip_image008_thumb1.jpg" border="0" alt="clip_image008" width="811" height="286" /></a></p>
<p>Traducerea in LDAP a acestei cautari arata cam asa : cautam obiecte de tip user – persoana, enabled (vezi atributul UserAccountControl) inactive in perioada data curenta minus 60 zile, folosindu-ne de atributul lastLogonTimestamp. Valoarea acestuia din urma este updatata implicit la interval de 14 zile asa ca sfatul meu e sa nu folositi intervalul de 15 sau chiar 30 de zile pentru clean up, ca sa nu riscati sa stergeti conturi active. Convertirea valorii in format standard de timp este descrisa <a href="http://support.microsoft.com/kb/555936">aici</a> .</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/clip_image0101.jpg"><img style="border-width: 0px" src="http://www.winadmin.ro/wp-content/uploads/2010/03/clip_image010_thumb1.jpg" border="0" alt="clip_image010" width="813" height="500" /></a></p>
<p>Cum putem cauta computerele inactive timp de 60 de zile? Editam query-ul, inlocuind valoarea “person” a atributului objectCategory cu “computer”. Click pe Apply si gasim si computerele inactive pe care, de asemenea, le putem dezactiva sau sterge:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/03/clip_image0121.jpg"><img style="border-width: 0px" src="http://www.winadmin.ro/wp-content/uploads/2010/03/clip_image012_thumb1.jpg" border="0" alt="clip_image012" width="812" height="431" /></a></p>
<p>Spuneam ca ADAC a aparut de la Windows Server 2008 R2. Consola poate fi folosita totusi si cu Active Directory 2003 si 2008. Vedeti <a href="http://www.winadmin.ro/2009/12/04/powershell-active-directory-module-si-windows-2003-domain-controllers/">aici</a> conditiile. Sunt valabile si pentru ADAC.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2010/03/29/identificarea-conturilor-inactive-din-active-directory-folosind-administrative-center/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

