Location: Articles

Articles

Articles

Articles from Tips and Tricks

Considerations when using a domain-based service account with AD LDS

Author: Tony Murray :: Monday, April 13, 2009 9:39 PM

When creating an AD LDS instance you are prompted to specify an account to use as the service account. At this point you can specify either the Network Service account or another account. Unless you have a particular need, you should choose the built-in Network Service account. If you opt for a domain-based service account you have to jump through a whole lot of hoops to get things working. Also, you typically end up giving your domain-based service account more permissions than are strictly necessary (as described later in this article). The Network Service account on the other hand provides an easy set up option and is a good choice from a security perspective given that the account has limited access to the local computer.

 
 
 
So why bother to use a domain-based service account at all? Well, if you have a number of services on your server all running under the context of the Network Service account there is potential for security compromise. In this scenario you may want to consider isolating the services from each other using dedicated service accounts.
 
What follows is a discussion of the steps required to configure AD LDS to use a domain-based service account.

Read More..

3232 Views :: 2 Comments :: :: Categories: Active Directory, Tips and Tricks, Windows Server

LDAP tips #3: Searching for Computers

Author: Tony Murray :: Thursday, September 25, 2008 10:57 PM

This article is the third in a series providing tips for common LDAP searches.

Read More..

4165 Views :: 1 Comments :: :: Categories: Active Directory, Tips and Tricks

Problem: Your user accounts in Active Directory do not have an email address associated with them, you have a lot of user accounts, and you must get an SMTP address associated with the accounts immediately. This script will perform the AD Voodoo for you, automagically.

Read More..

3795 Views :: 2 Comments :: :: Categories: Tips and Tricks

Managing and updating the UserAccountControl AD attribute to fix problem AD accounts through admin scripting

Read More..

2954 Views :: 0 Comments :: :: Categories: Tips and Tricks

Fast, simple mass creation of domain user objects with SMTP mailbox addresses using DSADD.

Read More..

1676 Views :: 0 Comments :: :: Categories: Tips and Tricks

LDAP tips #2: Searching for Groups

Author: Tony Murray :: Wednesday, November 28, 2007 5:10 PM

This article is the second in a series providing tips for common LDAP searches.

Read More..

4311 Views :: 1 Comments :: :: Categories: Tips and Tricks

Where to get the latest Group Policy ADM files

Author: :: Wednesday, November 28, 2007 5:04 PM

Have you ever been concerned that you might not have the very latest Group Policy ADM files?

Read More..

2109 Views :: 0 Comments :: :: Categories: Tips and Tricks

LDAP tips #1: Searching for Users

Author: :: Wednesday, November 28, 2007 5:04 PM

This article is the first in a series providing tips for common LDAP searches.

Read More..

5190 Views :: 1 Comments :: :: Categories: Tips and Tricks

Use the FreesCO router in your virtual environment

Author: :: Wednesday, November 28, 2007 5:01 PM

Provides an overview of a great little router that you can easily run in your VMWare environment.

Read More..

3837 Views :: 0 Comments :: :: Categories: Tips and Tricks

Outlook 2007 Permissions Issue

Author: :: Wednesday, November 28, 2007 4:54 PM

This article describes a permissions issue experienced with Outlook 2007. Outlook clients were unable to view messages when in on-line mode, with the following error displayed: "Cannot display the folder. You do not have sufficient permission to perform this operation on this object. See the folder contact or your system administrator." The error was related to permissions on the Exchange Organization object in Active Directory. Permissions assigned to the Everyone group had been removed. Restoring the permissions to the defaul resolved the issue. The article describes how the problem was identified and the resolution steps required.

Read More..

5933 Views :: 0 Comments :: :: Categories: Tips and Tricks, General

Copyright 2009 ActiveDir.org
Terms Of Use