Re: New accounts replicate disabled.

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Then the accounts are disabled on both. An account doesn't get created enabled and replicate to another DC and disable. In actual fact, when you get down to the nuts and bolts, accounts are created disabled by all scripts and MSFT tools, then later in the script or tool the account is enabled. Accounts CAN be created enabled, but there aren't many tools that do it properly.

--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm



chewbacca wrote:
Actually it doesn't matter which of the two servers I create the account on. When the account replicates to the other server it's disabled. If I enable it everyone's happy.

"Joe Richards [MVP]" wrote:

Are you saying the account isn't disabled on your secondary DC but is on your primary DC? Are you positive? I mean really positive?

--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm



chewbacca wrote:
Using Win2K server. When I create an account on our secondary DC in AD it replicates to our primary server but is disabled. Am I missing a setting somewhere that will allow the account to replicate enabled?

Thanks
.



Relevant Pages

  • Re: Field greyed out when account ops try to unlock account
    ... Joe Richards Microsoft MVP Windows Server Directory Services ... Tried on several different account with same result. ...
    (microsoft.public.windows.server.active_directory)
  • Re: How to prohibit an interactive logon and authorize an Ldap access
    ... Joe Richards Microsoft MVP Windows Server Directory Services ... place of ADS_UF_NORMAL_ACCOUNT when creating the account. ...
    (microsoft.public.windows.server.active_directory)
  • Re: How to limit domain account to be used for Service account Only
    ... Joe Richards Microsoft MVP Windows Server Directory Services ... >>>Local administrators account for all my 70 Servers. ...
    (microsoft.public.win2000.active_directory)
  • Re: Everyone can change password in 2003
    ... This allows anyone with the old password for an account to change it to something new. ... Joe Richards Microsoft MVP Windows Server Directory Services ... I noticed that the Everyone group has permission to change the password of every user and computer account in our organization. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Account Locked-Displays Weird
    ... Adding to Richards answer, make sure that you have properly configured DNS, and Sites and Subnets. ... it displays the account IS locked ... An account is locked out when the date/time corresponding to the value of the user lockoutTime attribute plus the domain lockoutDuration is in the future. ... The lockoutTime attribute may take a few minutes to replicate. ...
    (microsoft.public.windows.server.active_directory)