Re: User account attributes greyed out

From: Joe Richards [MVP] (humorexpress_at_hotmail.com)
Date: 02/19/05


Date: Sat, 19 Feb 2005 12:36:50 -0500

Run the following command against an old account and a new account, let me know
if there is a delta in the output

adfind -default -f samaccountname=username allowedAttributesEffective

You can get adfind on my website, www.joeware.net

   joe

--
Joe Richards Microsoft MVP Windows Server Directory Services
www.joeware.net
Mark Knijnenburg wrote:
> ACLs correct - Domain Admins Full Control. ACLs are 
> identical between older accounts (pre-upgrade) and newly 
> created accounts.
> 
> Mark
> 
> 
>>-----Original Message-----
>>Verify the actual ACLs on the objects.
>>
>> joe
>>
>>--
>>Joe Richards Microsoft MVP Windows Server Directory 
> 
> Services
> 
>>www.joeware.net
>>
>>
>>Mark Knijnenburg wrote:
>>
>>>A client of mine has upgraded their domain from NT4 to 
>>>2000. Accounts that were present in the domain before 
> 
> the 
> 
>>>upgrade can be administered by Domain Admin accounts 
> 
> that 
> 
>>>were also present before the upgrade, but newly 
> 
> created 
> 
>>>Domain Admin accounts cannot change these older 
> 
> accounts 
> 
>>>at all (all attributes greyed out). However, newly 
>>>created domain admin accounts can administer newly 
>>>created user accounts, all attributes can be modified. 
>>>Anyone seen this?
>>
>>.
>>


Relevant Pages

  • Re: Service accounts best practices
    ... > The only people who should have domain admin rights are the exact people ... > domain admin work and it should be a very small group. ... >>>Joe Richards Microsoft MVP Windows Server Directory Services ... >>>>Can someone point me to a guide to securing service accounts? ...
    (microsoft.public.win2000.security)
  • Re: Permissions to unlock Administrator account?
    ... Use delegation for everything else. ... The Administrator accounts should have a very long, complex, password, be ... domain admin, and one for general day to day use. ... leaving only the Administrator account there (I ...
    (microsoft.public.windows.server.active_directory)
  • Re: Changing the domain password policy
    ... You could try to look into your AD event logs and check for Successful logons for the domain admin account. ... While the biggest thing to do is make sure you know your environment and what service accounts are used where, eventually you'll find yourself stuck and you just need to make the change and deal with what breaks. ... Time has come to change the domain admin password. ...
    (Security-Basics)
  • Re: Securing workstations from IT guys
    ... It sounds like you have generic domain admin accounts - I'd change that immediately, and create what are called 99 accounts. ... Change all Local Admin passwords so that even IT helpdesk/other doesn't know them. ... Is there an auditing on PC that can be enabled to track/log incoming connections to C$ and pop up and alert whenever someone tries it out from a remote machine. ...
    (Security-Basics)
  • Re: NT4 to Windows 2003 AD Migration Question
    ... You want something that can map the accounts from the source to the ... > I have around 1500 workstations, a couple hundred servers. ... > seems most tools want domain admin on the AD side as well. ... We are tasked with building the OU from scratch, so SID history ...
    (microsoft.public.windows.server.active_directory)