Re: ADC-created Disabled Accounts, what to do?

Tech-Archive recommends: Fix windows errors by optimizing your registry

From: steve simpson (simpsonst3_at_comcast.net)
Date: 05/18/04


Date: Tue, 18 May 2004 23:23:53 GMT

On Tue, 18 May 2004 16:32:16 -0500, "Tyrone Cowart [MSFT]"
<tyronec@online.microsoft.com> wrote:

>OK so the plan is sound and the setup is not complicated.
>You should check the advanced settings on the connection agreement and see
>if it is set to default (create disabled account) the odd thing is that if
>the account already existed in AD it should not have created a disabled
>account.
>
>Is it still making these accounts? If you create a new 5.5 mailbox and
>associate an account to it, does the ADC create a disabled account?

Hi Tyrone, thanks again!

I still have to activate the ADC so I do not have anything created
from the 5.5 Directory into the A.D yet.

My problem is that I have A LOT of instances of mailboxes that report
with the NTDSNoMatch setting in Field 10 when I run NTDSAtrb against
the 5.5 Directory.

The expalanation for this is that for business organization reasons
certain SAM-ACCOUNTs (as they are labelled in the .csv file generated
by NTDSAtrb) are set in 5.5 to have access to multiple mailboxes.

Now, once I really activate the ADC (and map information from the 5.5
Directory onto A.D.) I must be sure (always for business reasons) that
these SAM accounts keep having access rights to all the mailboxes thay
had access to in 5.5, with no downtime.

I do not know what will happen once I activate ADC and this is the
reason for my question.

Let me make an example: in 5.5 I have a SAM-account MYDOMAIN\CHARLIE
mailboxes having the following UIDs: charlie, paul, john (i.e. 3
mailboxes). the lines corresponding to the last 2 mailboxes have been
set with the NTDSNoMatch attribute on Field 10 in the .csv

Now let's say I import the .csv into the 5.5 directory and then
activate the ADC. My understanding is that the ADC would create 2
mail-enabled , deactivated users with names paul and john.

What would it do with the user CHARLIE? (user CHARLIE already exist in
A.D !) Would It disable the user? Would it create another mailbox?

Also I have some recipients in 5.5 that have mutiple accesses set for
multiple users (the Permissions tab). Would these permissions be
retained?

I am very confused.

Thank you!

Steve



Relevant Pages

  • Re: Migration question
    ... be the Primary Windows NT Account on the mailboxes. ... MVP - Exchange ... I have setup ADC agreement between the two Exchange servers. ...
    (microsoft.public.exchange.admin)
  • Re: Migration question
    ... could end up deleting all the Exchange 5.5 mailboxes. ... I did ran the ADC tool first. ... that the AD accounts are associated with the mailboxes. ... should be the Primary Windows NT Account on the mailboxes. ...
    (microsoft.public.exchange.admin)
  • Re: Migration question
    ... I did ran the ADC tool first. ... that the AD accounts are associated with the mailboxes. ... should be the Primary Windows NT Account on the mailboxes. ... I can see exchange tabs in userA disabled account. ...
    (microsoft.public.exchange.admin)
  • Re: ADC Resource Mailbox Wizard Question
    ... ADC should have little to no effect on how these accounts are accessed. ... only copies the directory information about the mailboxes. ... The Resource Mailbox Wizard just ensures that the "primary" account is ...
    (microsoft.public.exchange.setup)
  • Re: MS Exchage 2003 License Question
    ... What I would say is do not contact Microsoft, they won't help you (or just ... > server licence, on top of the O/S licence with a licence for every active ... > directory account also. ... > What if thirty mailboxes aliases were linked to one AD account and thirty ...
    (microsoft.public.exchange.setup)