Index (1st Edition, AD2000)
' (apostrophe), 717, 894
* (asterisk), 458, 485, 719
\ (backslash), 483
: (colon), 499
, (comma), 718
. (decimal point), 718
. (dot), 452
" (double quotes), 718, 724
= (equal sign), 499
/ (forward slash), 499
- (hyphen), 500
< (less-than sign), 499
+ (plus sign), 499, 719
# (pound sign), 499
; (semicolon), 617
[] (square brackets), 237
_ (underscore), 719
169.254.xx, 87
A
Abandon operation of LDAP, 52
Abstract schema objects, 801806. See
also Subschema object
Access (Microsoft), 53
Access control. See also ACEs (access
control entries); ACLs (access control
lists)
architecture, 280296
background for, 206212
basic description of, 3637
delegation and, 282283
impersonation and, 282283
security principals and, 207212
Access tokens
basic description of, 175176,
287288
universal groups and, 196
Account(s)
basic description of, 123
disabling, 163, 172
Group Policies and, 511
options, listing, 784788
policies, 511
resetting, 172173
Account Operators group, 129
Account Restrictions property set, 235
Account tab, 144, 149154, 232
ACEs (access control entries), 36,
214. See also Access control; ACLs (access
control lists)
adding, 39, 848856
basic description of, 219, 288289
contents of, 289292
fields of, 290291
Group Policies and, 554
inheritance and, 240, 851
listing, 834837, 839846
order of, 850851
schema and, 617618
ACL Editor. See also ACLs (access
control lists)
basic description of, 212
dialog boxes, anatomy of, 215222
DSSec.Dat and, 237, 239
procedures for using, 213
setting permissions with, 222251
SIDs and, 286
viewing permissions with, 260
ACLDiag, 250
ACLs (access control lists). See also
Access control; ACEs (access control
entries); ACL Editor; DACL (discretionary
access control list)
administration scripts and,
832856
default, changing, 267
ACPI (Advanced Configuration and Power
Interface)
installation and, 74, 110
problems with, 110
Active Directory
brief description of, 46
building blocks of, 1626
current limitations of, 61
directory face of, 4
enterprise services face of, 4
first look at, 78
history of, 78
installation of, 67, 93105,
109111
introduction to, 416
as a loosely-consistent database,
308310
NDS and, comparison of, 1315, 63
next version of, 6465
requirements/recommendations,
9394
Restore Mode, 97
three faces of, 56
uninstalling, 113, 115117
what data to put in, 645646
Windows NT and, comparison of,
1113
Windows NT face of, 4
ADC (Active Directory Connector), 310
Add ACEs to a Folder.vbs, 854856
Add ACEs.vbs, 846854
Add Members to a Group option, 192
Add operation of LDAPv3, 52
Add/Remove applet, 85, 102, 558, 560
Address Book, 9, 425, 635
Address tab, 144
Administration. See also
Administration scripts
delegation of, 12, 19, 39, 141,
268, 269276
duplicate, as a cost of adding
additional domains,
437
units of, using multiple domains
because of, 434435
Administration script(s)
as command-line tools, 706708,
884887
concepts, 697758
configuration information and,
822832
debugging, 755759
development environment for,
712715
examples of, 761794, 804805
execution environment for, 698703
file types, 703
help files and, 713714
killing, 710711
property caches and, 730750,
767772
schema and, 801822
settings, 708710
testing, 704705
Administrative groups. See also Groups
in forests, 466467
predefined, 128133, 466467
Administrative templates, 515519
Administrative view to a forest, 446
Administrator account, 126, 259,
261263
Administrators group
AdminSDHolder object and, 251
basic description of, 129
ownership and, 243244
AdminSDHolder object, 251
ADMT (Microsoft Active Directory
Migration Tool), 463
ADO (Microsoft ActiveX Data Objects)
administration scripts and, 699,
700, 703, 888, 904
ADSI and, 5556, 888890
basic description of, 888
Basic Example.vbs, 893896
Basic Example with SQL.vbs,
896897
concepts, 888
mechanics, 890891
using, 888903
ADsFMO component, 754, 830831
ADSI (Active Directory Service
Interfaces), 5456, 123, 888890
without the Active Directory,
862870
administration scripts and, 700,
713714
concepts, 721752
examples, 724725, 761763
help files, 713714
interface, 702703, 736839
operations, 724
paths, 725726
properties and, 735736
Resource Kit, 754
syntax, 749753
ADSI Edit, 174, 201202
basic description of, 488489
creating new attributes with,
669670
inspecting schema with, 588591
renaming objects and, 239
ADSizer (Active Directory Sizer), 420
ADsSecurity component, 754, 830831
Aggregate object, 596
Aliases (built-in local security
groups), 286
Alias objects, 63
Allchin, Jim, 10
ANR (Ambiguous Name Resolution), 226,
635637, 639, 642, 654, 655, 813
ANSI (American National Standards
Institute),
606, 607
Answer files, 106107
APIPA (Automatic Private Internet
Protocol Addressing), 87
APIs (application program interfaces)
ADSI (Active Directory Service
Interfaces) API,
5456
GetGPOList API, 538539
LDAP C API, 425, 490, 702
user rights and, 297
Win32 API, 755
APM (Advanced Power Management), 74
Application(s). See also Software
data, storing, 59
deployment, 508509
patching, 561
permissions in, 240243
published versus assigned, 560
removing, 509, 562
self-repairing, 558
upgrading, 561
Application tab, 711
Architecture
access control, 280296
ADSI and, 5456
basic description of, 4158
container objects and, 4344
data models and, 4142
LDAP and, 4952
objects and, 4347
partitions and, 4445
physical, 5154
schema and, 4243
X.500 standard and, 4749
Arguments
basic description of, 718719
command-line arguments (options)
in scripts,
754, 805
optional, 719
ASCII (American Standard Code for
Information Interchange), 483, 687
ASN.1 (Abstract Syntax Notation One),
606
ASP (Microsoft Active Server Pages),
701, 756
ATTRIB command, 114
Attribute(s). See also Properties
ANR, 813814
basic description of, 622631
bit-field, 635
constructed, 599, 813814
creating, 652655, 661, 664666,
669670,
818823
deactivating, 656659
inspecting, 589590
linked, 627629
listing, 805807
mandatory, 42, 582, 583, 612, 803
miscellaneous characteristics for,
637
modifying, 655656, 664666
multivalued, 582, 634
names, 591592
nonreplicated, 813814
optional, 42, 582, 583, 612, 803
permissions for, 677, 696
planning new, 660
reactivating, 659
schema and, 582583
searching on new, 694696
single-valued, 582
syntax, 583
tombstone, 401402
use of the term, 41
values, managing, 693694
attributeSchema objects, 585, 622637,
637639, 817818
Attributes tab, 621622
Auditing
basic description of, 204, 276280
entries, adding, 276278
Group Policies and, 512513
records, viewing, 279280
turning on, 278279
Authentication
basic description of, 204
cross-forest, 65
Kerberos and, 56
mutual, 56
Automatic Certificate Request
settings, 514
B
Backup Operators group
basic description of, 129
user rights and, 296
Base
DNs, 494
objects, 469, 479
schema, 582, 584, 635636
Base64 encoding, 499
BATCH command, 114
Batch files
administration scripts and, 701,
793794
creating, 687688
creating users with, 793794
testing, 687688
BDCs (backup domain controllers)
domain modes and, 133
PDC emulator and, 406, 411
replication and, 25, 310
Binary GUIDs, 837839. See also GUIDs
(globally unique identifiers)
BIND (Berkeley Internet Name Domain),
34, 94
Bindery (of Netware 3), 9, 723
Binding
with credentials, 870872
early, 721
to the GC, 876877
late, 721
strings, 726727
with WKGUIDs, 872876
Bind operation of LDAPv3, 52
BindView bv-Admin, 463
BIOS (Basic Input/Output System), 74,
83, 109
Bit(s)
ACE AccessMask, 290291
ACE AceType, 292, 293
ACE Flags, 292
connection object, 385
-fields, 290291, 635
least-significant, 291
site link, 385
Bitwise AND, 485
Bitwise OR, 485
Blackcomb, 65
Boolean values, 483
Bootable CDs, 108109
BOOTDISK folder, 76
Boot partition, 69
Breakpoints, 759
Bridgehead servers, 315, 371374
Browser service, 406, 518, 519
Browsers, encryption for, 57
Building Enterprise Active Directory
ServicesNotes from the Field, 420
Builtin container, 124, 126130
C
C (high-level language), 54, 680
administration scripts and, 701,
702
compilers, 701
C++ (high-level language), 54, 680
administration scripts and, 701,
702
compilers, 701
CA Unicenter, 509
Cache
property. See Property cache.
schema. See Schema cache.
CACLS command, 793, 794, 795, 796, 797
Cairo, 1011
CAL (client access license), 70
Canonical names, 46
Carriage return/linefeed character
pair, 719720
CAs (certificate authorities), 5758,
92
Group Policies and, 514
SMTP replication and, 386
Case-sensitivity, 718
Catalog Services, 26
CCM (Change and Configuration
Management), 503
CD/CHDIR command, 114
CDO (Collaborative Data Objects), 700
CDs (compact discs), bootable, 108109
Certificate Export Wizard, 116
Certificates, exporting, 116
Change notification, 320, 384385
Channels, secure, 457
Characters
ASCII, 483, 687
carriage return/linefeed, 719720
number of, in passwords, 530
Unicode, 34, 483, 516
unsafe, 499
CHKDSK command, 114
Class(es)
ADSI and, 5446
attributes of, inspecting, 589590
basic description of, 599622
categories of, 612
creating, 647650, 661, 666669
deactivating, 656659
derived, 610
extended rights for, 227229
identifiers, 600, 603
identifiers (CLSIDs), 682, 683,
684, 709
miscellaneous characteristics of,
612618
modifying, 650652, 666669
names, 600, 603
objects of specific,
creating/deleting, 229
planning new, 660
reactivating, 659
schema and, 582583
classSchema objects, 585, 599622,
815817
Clean Install option, 80
Client(s)
access license (CAL), 70
access tokens, 287
extensions, 512
LDAP referrals to, 469
-server applications, connection
points for, 59
-side extensions (CSEs), 504, 538,
571573, 575
slow link detection and, 576578
traffic, 420421, 425
ClonePrincipal tool, 463
CLS command, 114
CLSIDs. See Class(es)identifiers (CLSIDs)
CMDTOOL.vbs, 885887
CNs (common names)
basic description of, 46
renaming objects and, 239
Collisions, 398401
COM (Component Object Model), 5456,
699
basic description of, 728730
components, using, 753755
connection points and, 59
files, registering, 559
COM+, 559
Comdex, 10
Command-line
CScript options, 706708
parameters, 465. See also
Arguments
redirection of output, 707, 773,
799800
tools, 111, 112, 173, 250, 353,
355356, 458, 462, 498, 550, 762, 794,
884887
Compare operation of LDAPv3, 52
Compilers, 701
Complete trust areas, 441443
Components
COM, 755757
homemade, 753
installation of, 8587
using, 753755
Computer(s). See also Computer
accounts; Computer objects
licensing, 351352
locating, 35
managing, 173, 856858
objects, predefined, 133
registering, 91
renaming, 173174
Computer accounts
disabling, 172
resetting, 172173
Computer object(s)
administering, 164174
creating, 166168
creating with a script, 861864
deleting, 172
Group Policies and, 507508
moving, 172
properties, 168171
Computers container, 124
Concurrency control, 661, 675
Configuration
information, handling, 59, 822832
partition, 44, 311, 313, 362
Connection object(s)
creating/managing, 380384
explanation of, 326, 327331,
358359
properties, 899
replication and, 358359
Consistency checks, 650
Constant(s)
administration scripts and,
718719
basic description of, 718
definitions, 758
intrinsic, 719
names, 718
Contact(s)
administering, 142164
creating, 148
deleting, 162163
home pages of, opening, 164
moving, 162
properties, setting, 148157
renaming, 162
sending e-mail to, 164
Container(s)
basic description of, 123125
classes, 583585
objects, 4344, 583585
predefined, 123125
Containment rules (of schema classes),
607610
Context menus, adding scripts to,
693694
Continuation references in LDAP,
487488
Control Panel, 85, 558. See also
Add/Remove applet
Controls dialog box, 497
Control statements, 719
Convergence of Active Directory
information, 309
COPY command, 114
Create a Computer Object.vbs, 859862
Create a Group.vbs, 858
Create a Home Folder for a User - Ver
1.vbs, 794796
Create a Home Folder for a User - Ver
2.vbs, 796797
Create a Share.vbs, 867
Create a User in a Workstation.vbs,
869870
Create a User with a Batch File.bat,
793794
Create a User with Minimum
Attributes.vbs, 788790
Create a User with More Attributes.vbs,
790793
Create Object dialog box, 677678
Credentials, binding with, 870872
Cross-reference(s)
basic description of, 469473
external, creating, 470473
objects, 469470
CScript, 690, 703705, 711
CSEs (client-side extensions), 504,
538, 571573, 575
CSVDE, 202, 662, 663, 674
CTLs (certificate trust lists), 514
Current context, 63
D
DACL (discretionary access control
list), 36, 214, 288289, 290. See also ACLs
(access control lists)
Dampening, propagation, 388
DAP (Directory Access Protocol), 4849
Data model, 4142
Data types
administration scripts and,
734735
handling special, 734735
Date and time settings, 87. See also
time
DB layer, 5253
DCDiag, 458459
DCE (Distributed Computing
Environment), 452
DCOM, 559
DCPromo, 1617, 352, 354, 473,
476477, 586, 673
command, 93, 115
Deactivation, of classes, 656659
DEAs (directory-enabled applications),
5, 43, 59, 642, 659662
Debugging
administration scripts, 755759
with extra output commands,
755756
mode, 112
Default Domain Controllers Policy, 511
Default permissions. See also
Permissions
basic description of, 258267
listing, 260265
sources of, 259
DEL/DELETE command, 114
Delegating
basic description of, 19, 39,
269270
domain controller installation,
476478
domain installation, 473478
management of GPOs, 554557
Delegation (relating to
authentication), 282284
Delegation of Control Wizard, 39, 212
basic description of, 251258
common tasks completed with,
252256
custom tasks completed with,
256258
customizing list of common tasks,
254256
support tools and, 250
DelegWiz.Inf, 254256
Delete operation of LDAPv3, 52
Deleted objects, listing, 495497
Deleting
contacts, 162163
GPOs, 552553
groups, 194, 861
objects, 172, 229, 857
OUs, 857
users, 162163
DEN (directory-enabled networking), 5
Deploying software, with Group
Policies, 559561
Description property, 140
Device Manager, 110
Devices
incompatible, 110
incorrectly detected, 110
DFS (Windows 2000 Distributed File
System), 23, 315316, 341, 559561
DHCP (Dynamic Host Configuration
Protocol)
DNS updates and, 3536
Group Policies and, 538
installation and, 70, 87, 90
RIS and, 520
Dial-in tab, 144, 155156
DIR command, 114
Directories
history of, 9
information about, determining the
placement of, 426432
Directory-enabled applications (DEAs),
5, 43, 59, 642, 659662
Directory-enabled networking (DEN), 5
Directory service, 4, 9, 11, 42, 47,
142, 310, 585, 723724
Directory Services Restore Mode
option, 112
DISABLE command, 114
Disk images, duplicating, 107108
DISKPART command, 114
DISP (Directory Information Shadowing
Protocol), 48
Display name property, 147
Display specifiers, 682685
Distributed Systems Guide, 354355
Distribution groups, 174. See also
Groups
DLLs (Dynamic Link Libraries), 557,
573, 684, 898
DMZ (demilitarized zone), 6061
DNs (distinguished names), 407, 466
base, 494
basic description of, 4547
features recommended for, 94
LDAP and, 46, 485, 494
LDIF and, 498, 501
DNS (Domain Name Service). See also
Domain names
Group Policies and, 550
host names, 84
host records, 476
installation and, 70, 8490,
93105, 110111, 117
integration, 3436
namespaces, 17, 31, 3233
-related tasks, after
installation, 102105
RIS and, 520
root domain, removing, 102
servers, requesting IP addresses
from, 35
updates, dynamic, 3536
virtual containers and, 58
zones, 61
DnsAdmins group, 132
DnsUpdateProxy group, 132
DNS Zones, 34, 6061, 94, 102105,
117, 425, 450
Domain(s). See also Domain
controllers; Domain names
adding workstations to, 302
basic description of, 17, 62
choosing, 200
cost of additional, 437438
creating, 9495
designing, 432452
forest root, 95, 448452
installation, delegation of,
473478
local groups, 2122
looking at single, 429430
managing, 452478
master browser, 406
mode, changing, 133135
placement of directory information
and, 426432
single, OU trees in, 2930
single, with no OU structure,
2728
trees, 3033
using multiple, 433438
using single, advantages of,
433438
Domain Admins group, 131, 243244,
251, 261264
Domain Computers group, 131
Domain controller(s). See also Domains
additional, cost of, 437
basic description of, 6, 1617
choosing, 200
default assignments for, 299302
installing, 65, 476478
logon rights and, 298
operations master (OMDCs), 408,
410411, 413414, 415
originating, 390
placement of, 419502
placement of directory information
and, 426432
privileges and, 28
promoting, to be GC servers,
346347
removing, 352354
targeting, for Group Policy
operations, 547548
USNs and, 390
Domain Controllers container, 124
Domain Controllers group, 131
Domain Guests group, 131
Domain names. See also Domains
basic description of, 3132
Domain naming master, 405
Domain Password & Lockout Policies
property set, 231
Domains and Trusts snap-in, 454
Domain Users group, 131, 134
DOS (Disk Operating System), 77, 78.
See also MS-DOS
DOSNET.INF, 106
Drivers, installation using alternate,
8183
DSAs (Directory System Agents), 49,
51, 53
DSClient (Directory Service Client),
702
DSP (Directory System Protocol), 48
DSSec.Dat, 237239, 257, 677
Dual booting, 7073
Dynamic disks, 92
Dynamic DNS, 3536
Dynamic updates, enabling, 102103.
See also Updates
E
ECMAScript, 702
EditPlus, 712, 713, 763
EFS (Encrypting File System), 47, 514.
See also Encryption
E-mail
encryption, 57
sending, to groups, 194
sending, to users and contacts,
164
systems, history of, 9
Empty lines, 718
Enable Boot Logging option, 112
ENABLE command, 114
Enable VGA Mode option, 112
Encryption. See also EFS (Encrypting
File System)
e-mail, 57
installation and, 92
TCP/IP traffic, 57
Web browser traffic, 57
Enterprise Admins group, 98, 131, 259,
261
Error(s)
categories, 880
checking, 879884
levels, 765
mechanics, 879880
Error Checking.vbs, 879884
Escape sequences, 483
ESE (Extensible Storage Engine), 5253
ESENT.DLL, 51
Event(s)
Group Policies and, 562565
logs, 513, 562565
Excel (Microsoft)
ACEs and, 834837
administration scripts and, 701,
766767, 797798, 807809, 815818
importing text files into, 595596
table of default permissions, 260
Exchange (Microsoft), 9, 43, 53, 142,
143, 310, 431, 444, 605, 723
EXIT command, 114
Extended operation of LDAPv3, 52
Extended rights, adding, 293294
Extensible matching rules, 485
EXTRACT command, 114
F
FastLane Developers, 701
FastLane Migrator, 463
FAT (file allocation table), 71, 73,
81
FAT32, 71, 81
Fault tolerance, 308
FAZAM 2000 RFV (Reduced Functionality
Version) tool, 551, 554, 570
File system(s). See also NTFS (Windows
NT File System)
DFS (Windows 2000 Distributed File
System), 23, 315316, 341, 559561
EFS (Encrypting File System), 47,
514
policies, 514
supported by Windows 2000, 7273
Filters, 200201, 592, 616, 889,
901903
Find command, 762
Find dialog box, 488, 695
FindStr command, 762
Firewalls, 60
First name property, 147
FIXBOOT command, 114
FIXMBR command, 71, 114
flatName property, 453
Folder(s)
adding ACEs to, 854856
creating, 794797
home, 794797
redirection policies, 520
Foreign security principals, 124, 462
ForeignSecurityPrincipals container,
124, 462
Forest(s). See also Forest root
domains
authentication and, 65
changes to, 62
configurations, number of, 440
creating, 9495
designing, 432452
managing, 452478
managing groups and permissions
in, 466469
moving groups in, 464465
moving objects in, 462466
permission assignments in, 468469
planning considerations for,
445452
predefined administrative groups
in, 466467
testing schema modifications in,
660, 685690
three faces of, 445446
trusts, 65, 441443
using multiple, 433444
using single, 438445
Forest root domains, 95, 448452. See also Forests
empty, 449450
nonempty, 450451
FORMAT command, 114
Forwarding addresses, configuring, 102
Forward lookup zones, creating,
102103
FRS (Windows 2000 File Replication
System), 23, 53, 315
FSMOs (flexible single-master
operations), 25, 324, 404. See also Operations
master(s)
FullArmor.com, 570
Full Control permission, 273
Full name property, 147
Function(s)
basic description of, 718719
conversion, 719
G
Garbage collector, 402
Gates, Bill, 10
GCs. See Global Catalogs
General Information property set,
231232, 483
General tab, 144, 170, 195, 232
GetGPOList API, 538539
GetSID, 286287
Global Catalogs, 64, 115, 196
attributes and, 814815
basic description of, 26
binding to, 876877
indexing and, 585
LDAP searches and, 486
multipartition queries and, 899
number of, 440441
replication and, 323, 364, 375378
servers for, placement of, 431432
servers for, promoting domain
controllers to,
346347
Global groups, 2122. See also groups
GPC (Group Policy container), 523524,
567
GPOs (Group Policy Objects)
assigning, 4041, 124
basic description of, 40, 522528
creating, 548550
default permissions for, 575576
delegated, creating MMC consoles
for, 555556
deleting, 552553
editing, 550551
listing, 827828
management of, delegating, 554557
GPT (Group Policy templates), 524,
525, 567
GPT.INI, 524, 525
Group(s)
administering, 174200
built-in, 128130, 184
creating, 186187
deleting, 194, 861
distribution of, 20, 174
filtering Group Policies with,
532534
global, 2122
listing, 865
local, 128130, 184
managing, 121202, 466469,
856859
membership, 64, 188192, 468469
moving, 194, 464465
nesting, 2122
planning, 194200
predefined, 127133
primary, for users, 192193
properties of, setting, 193194
renaming, 194
restricted, 513
scope, 2122, 177184, 187188
security, 21, 174
sending e-mail to, 194
strategies for, 197200
types of, 174177, 187188
universal, 196197
usage, example of, 180181
in the Users container, 130133
Group Policies
administrative templates and,
515519
administration of, delegating,
272273
advanced topics, 571578
backing up, 553554
basic description of, 3941, 204,
503578
concepts for, 503507
CSEs and, 504, 571573
deploying software with, 559561
effective, determining, 539546
event logs and, 513, 562565
filtering, with groups, 532534
folder redirection and, 520
forcing, 532
inheritance, 529, 534
links to, 528529
local, 511513
loopback processing, 536537
managing, 546557
operations for, targeting domain
controllers for, 547548
permissions and, 272273
preference, 517518
processing, 534546
redeploying, 509
registry settings for, 573575
Resource Kit tools for, 566571
restricted groups and, 513
RIS and, 520521
security settings and, 510
slow link detection algorithm and,
576578
software management with, 557562
troubleshooting, 562571
version number for, 524526
Windows NT 4 system policy and,
comparison of, 505506
Group Policy dialog box, 528529,
546548, 551552
Group Policy Migration tool, 566,
569570
Group Policy Reference, 570
Group Policy Results tool, 539,
566567
Group Policy Scenarios tool, 571
Group Policy tab, 522, 525, 549, 553,
555
Group Policy Verification tool,
567569
Guests group, 129, 259
GUIDGen, 648, 653, 679
GUIDs (globally unique identifiers),
167168, 407
ACEs and, 292293, 295
basic description of, 292293
binary, 837839
cloning objects between forests
and, 444
converting, with regular
expressions, 845846
database, 389, 394395, 398
Group Policies and, 504, 522, 525,
527
listing, 824828, 837, 839
replication and, 357358, 375, 389
schema and, 648, 653, 679680
server, 389, 395
H
Hardware
abstraction layer (HAL), 83
compatibility, with Windows 2000
Server, 7475
HCL (Hardware Compatibility List), 74
Hello.vbs, 704
HELP command, 114
Help files, 713714
Hierarchies, 2734
High encryption pack, 92
High-watermark vectors, 394395
Home
folders, creating, 794797
pages, opening, 164
HTML (HyperText Markup Language), 757
I
IADsContainer interface, 741743
IADsGroup interface, 748749
IADS interface, 739742
IADsTools, 754
IADsUser interface, 743748
IBM (International Business Machines),
89
ICANN (Internet Corporation for
Assigned Names and Numbers), 61, 605, 607
IDE (integrated development
environment), 700
IEAK (Internet Explorer Administration
Kit), 517, 521. See also Internet Explorer
browser (Microsoft)
IIS (Microsoft Internet Information
Server), 85, 86, 93
administration scripts and, 701,
756
ADSI and, 54
debugging and, 756
replication and, 387
Impersonation
basic description of, 56, 282283
Kerberos and, 56
tokens, 287
InetOrgPerson class, 65
Infinite loops, 710711
Informational properties of users and
contacts,
156158
Infrastructure master, 25, 229, 324,
334, 407408, 829. See also Operations
masters
Inheritance, 600, 602, 610612
basic description of, 3738
blocking, 531533
Delegation of Control Wizard and,
252
dynamic, 240243
Group Policies and, 529534
static, 3738, 240243
Installation
Active Directory, 6768, 93105,
109111, 122135
answer files and, 106107
automating, 105109
from CDs, 80
Clean Install option for, 80
configuring forwarding addresses
after, 102
creating domains, trees, and
forests during,
9495
creating forward lookup zones
after, 102103
creating reverse lookup zones
after, 104
decisions to make before, 6876,
9495
defining date and time settings
during, 87
disk duplication and, 107108
domain controller, 65, 476478
dual booting, 7073
enabling dynamic updates after,
102103
EXE files for, schema and, 674675
finalizing, 89
from networks, 8081
partitions, selecting, 83
preparation for, 7476
recovery options and, 111113
removing DNS root domains after,
102
reversing, 113117
starting, 7679
steps to take after, 9092,
100101
troubleshooting, 110113
using alternative drivers, 8183
verifying, 100101
Windows 2000 Server, 6893
InstallShield, 559
Instantiation, of classes, 582
Integers, 483, 485, 486
Integrity, referential, 629
IntelliMirror (Microsoft), 503
Interdomain communications, cost of,
437
Internet
connecting to, 5961
directories, 9
routers, 60
Internet Explorer browser (Microsoft)
Administration Kit (IEAK), 517,
521
debugging and, 756
Group Policies and, 521
IP (Internet Protocol), 35, 605. See also IPSec (IP Security)
Group Policies and, 514515
installation and, 70, 87, 88, 90
replication and, 368, 378, 387
IPSec (IP Security), 387, 514515. See also IP (Internet Protocol)
IRQ (Interrupt) settings, 110
ISAM (Indexed Sequential Access
Method), 53
ISDN (Integrated Services Digital
Network), 370
ISM (Intersite Messaging) service, 25,
387
ISO (International Organization for
Standardization), 4749, 605606
ISTG (inter-site topology generator),
366367, 370374, 380381
ITU (International Telecommunications
Union), 4749, 605606
J
JScript, 509
K
KCC (Knowledge Consistency Checker),
314, 327, 330, 343, 347, 353, 357365
KDCs (key distribution centers), 56
Kerberos, 5657, 420, 435, 437438,
444
Cairo and, 10
Group Policies and, 511, 539
synchronization services and, 25
trusts and, 452
Keyboard settings, 81
Knowledge Base. See Microsoft
Knowledge Base
Kouti.com, 260, 714, 759
L
Language Options dialog box, 81
Language settings, during
installation, 81, 84
LAN Manager, 89, 512, 732
access tokens and, 287
NET commands and, 202
LANs (local area networks)
loose consistency and, 6
replication and, 309, 315, 317
schema and, 655
as sites, 23
Last Known Good Configuration option,
111, 112
Latency, 309, 342
LAYOUT.INF, 106
LDAP (Lightweight Directory Access
Protocol)
ADSI and, 54
ANR and, 635
Base64 encoding and, 499
basic description of, 6, 4952
binding strings, 725726
C API, 425, 490, 702
Cairo and, 11
client traffic, 425
continuation references and,
487488
controls, extended, 495497
Data Interchange Format (LDIF),
498501
data model, 581585
domain names and, 31
Group Policies and, 564
the history of directories and, 10
NCs and, 308
property lists and, 480481
referrals, to clients, 469
schema and, 611, 616, 622626,
645646, 652
searches, 473501, 893894
setting properties for OUs and,
139140
version 3 operations, 5152
LDIF (LDAP Data Interchange Format),
498501. See also LDIFDE (LDIF Directory
Exchange)
LDIFDE (LDIF Directory Exchange), 202,
489, 498499, 598, 660
creating/modifying objects with,
670674
schema and, 662, 663, 664, 670674
LDP tool, 490494
Leaf
classes, 583585
objects, 4344, 583585
Least-significant bit, 291
LGPO (Local GPO), 504, 527528, 557
Linear regression analysis, 422
Lines
cutting long, 719
including, from another file,
758759
indenting, 719
Link(s)
bridges, 321, 378380
costs of, 369371
creating/managing,
348351
disabling parts of, 551552
replication topology and, 367369
tables, 53
WANs as, 23
Linked attributes, 627629
Linux, 472473
List ACEsLong.vbs, 839846
List ACEsShort.vbs, 834
List ACEs to Excel - Short.vbs,
834837
List ADSystemInfo.vbs, 831833
List All Abstract Schema Objects.vbs,
806
List All attributeSchemas to
Excel.vbs, 817818
List All Real Schema Objects.vbs,
811812
List Attribute Display Names.vbs,
823824
List Binary GUIDs.vbs, 837839
List Indexed Attributes.vbs, 812813
List Global Catalog Attributes.vbs,
814815
List Objects That Have Blocked ACL
Inheritance.vbs, 901903
List Services.vbs, 863865
List Shares.vbs, 865867
LISTSVC command, 114
List the Account Options of a
User.vbs, 784788
List the DC GUIDs.vbs, 824826
List the GPO GUIDs.vbs, 827828
List the Member Attributes of a Given
Class to Excel.vbs, 805807
List the Member Attributes of a Given
Class.vbs,
805806
List the Operations Masters.vbs,
828830
List the Operations Masters with
ADsFSMO.vbs,
830831
List the Property Cache Contents.vbs,
767772
List the rootDSE Property Cache.vbs,
826827
List the Supported Namespaces.vbs,
822823
List the Users of One Container to
Excel.vbs, 766767
List the Users of One Container.vbs,
764766
List User Properties with Get.vbs,
772779
List User Properties with Methods.vbs,
779784
List WinNT Properties of User
Class.vbs, 868869
Load balancing, 308
Local GPO, 504, 527528
Local policies, 511513
LocalSystem account, 211, 282, 283,
284
Location tab, 171
Logging. See also Auditing
events, 562565
detailed, 564565
Logoff scripts, 509
Logon. See also Access control;
Authentication
GCs and, 64
Group Policies and, 509510
Information property set, 235
rights, 297298
smart card, 440, 661
traffic, 420421
Loopback Adapter (Microsoft), 94
Loopback processing, 536539
Loops, 710711
Loose consistency, 6, 308310
LSA (Local Security Authority), 51,
322
M
MAKEBOOT command, 76
Managed By property, 140
Managed By tab, 195
Manual refresh, of Group Policies, 536
MAP command, 114
MBR (master boot record), 71
MD/MKDIR
command, 114
Member Of tab, 144, 149, 188, 192, 232
Member servers
basic description of, 88
modifying user rights for, 305306
Members tab, 188, 190191
Menu(s)
adding scripts to, 693694
definitions, adding, 686687
Merge mode, 536537
Metadata replication, 391394
MicroHouse ImageCast, 108
Microsoft Access, 53
Microsoft Active Directory. See Active
Directory
Microsoft Active Directory Migration
Tool (ADMT), 463
Microsoft Active Server Pages (ASP),
701, 756
Microsoft ActiveX Data Objects (ADO).
See ADO
Microsoft Excel
ACEs and, 832837
administration scripts and, 701,
766767, 797798, 807809, 815818
importing text files into, 595596
table of default permissions, 260
Microsoft Exchange, 53
Microsoft IntelliMirror, 503
Microsoft Internet Explorer browser.
See Internet Explorer browser (Microsoft)
Microsoft Internet Information Server
(IIS). See IIS (Microsoft Internet
Information Server)
Microsoft Knowledge Base, 249, 353,
380, 501, 511
Microsoft Loopback Adapter, 94
Microsoft Management Console (MMC),
504505, 547548, 550551, 555556
Microsoft Metadirectory Services
(MMS), 310
Microsoft Office, 754
Microsoft Platform SDK (Software
Development Kit), 617
Microsoft Script Debugger, 85, 86,
756757
Microsoft Software Installer (MSI),
557, 559
Microsoft System Management Server,
509
Microsoft Visual Basic for
Applications (VBA), 701
Microsoft Visual Basic Scripting
Edition (VBScript)
ADSI and, 54
basic description of, 698, 702,
715721
COM components and, 753754
Editor, 713
Group Policies and, 509
schema and, 663
scripts, creating/testing, 688690
scripts, sample, 716721
Microsoft Visual Studio Installer, 559
Microsoft Windows Internet Naming
Service (WINS), 36, 53, 70, 88
Microsoft Windows NT
Active Directory and, comparison
of, 1113
Cairo and, 1011
domains, using multiple domains
because of, 436
history of, 89
properties, listing, 870871
system policy, 505506
Microsoft Windows NT Directory Service
(NTDS), 257, 327, 330332, 341347,
353354, 380381, 411, 415
Microsoft Windows NT File System
(NTFS). See NTFS (Microsoft Windows NT File
System)
Microsoft Windows NT LAN Manager
(NTLM), 56, 512
Microsoft Windows 2000 Server
answer files and, 106107
components, installation of, 8587
dual booting, 7073
hardware compatibility with, 7475
history of, 1011
installation, 6876, 8092,
105107
Professional, 9293
requirements/recommendations, 74
Resource Kit, 255, 566571
server upgrades, 83790
uninstalling, 113117
Microsoft Windows Update Corporate Web
site, 91
Mixed mode, 133135, 177180
MMC (Microsoft Management Console),
593, 504505, 547548, 550551,
555556
MMC Group Policy extension, 547548
MMC Group Policy snap-in, 504505
MMS (Microsoft Metadirectory
Services), 310
Modify DN operation of LDAPv3, 52
Modifying Objects.vbs, 897898
ModifyLDAP.vbs, 344
Modify operation of LDAPv3, 52
MORE command, 114
MoveTree tool
basic description of, 462466
moving groups and, 464465
options, 465466
MS-DOS, 8, 8081. See also DOS (Disk
Operating System)
MSI (Microsoft Software Installer),
557, 559
Multilanguage version, 84
My Network Places, 8, 518
N
Namespaces, listing, 822823
Namespace view to a forest, 446
NAT (network address translation), 102
Native mode, 133135, 181184
NCs (naming contexts), 308
NDS (Novell Directory Services)
Active Directory and, comparison
of, 1315, 63
dynamic inheritance and, 38
the history of directories and, 9
introduction of, 11
partitions and, 62
NetBIOS
Browser service, 518
installation and, 84, 95, 100
names, 36, 5960, 84, 95
ports, 5960
trusts and, 453, 455
NET commands, 202
NetDom tool, 173, 454, 456, 458, 464
NetIQ Domain Migration Administrator,
463
Netlogon service, 102
NET TIME, 403404
NetWare (Novell)
Active Directory and, comparison
of, 1315, 63
ADSI and, 54
Catalog Services, 26
the history of directories and, 9
Network(s)
installing/configuring,
8788
installing Windows 2000 Server
from, 8081
operating systems, previous
Microsoft, 89
traffic, measuring, 420425
Network Identification tab, 173
Network Monitor, 85, 474
NLTest tool, 173, 454, 456, 458459
No Override option, 532
Nortel Networks, 11
Northern Telecom. See Nortel Networks
Norton Ghost, 108
Notepad, 54, 109, 510, 545, 687, 704,
713
Notification, change, 320, 384385
Novell NetWare. See NetWare (Novell)
NTDS (Microsoft Windows NT Directory
Service), 257, 327, 330332, 341347,
353354, 380381, 411, 415
NTDSA.DLL, 51
NTDSUtil tool, 344, 412, 473475
NTFS (Microsoft Windows NT File
System)
folder redirection and, 520
Group Policies and, 557
installation and, 6869, 7173,
81, 83, 8990, 93, 97
permissions and, 3637, 214
SIDs and, 284
NTLM (Microsoft Windows NT LAN
Manager), 56, 512
NTRights command, 304306
NtSecurityDescriptor property,
206207, 289
Null sessions, 210
O
Object(s)
administering, 164174
base, 469, 479
basic description of, 4
that block ACL Inheritance.vbs,
901903
creating, 166168, 229, 680681
deleting, 172, 229, 859
displaying, 680681
extended rights for, 227229
finding, 200
listing, 495497, 805, 811812,
901903
moving, 172
names, 4547, 238239, 626629
predefined, 133
properties of, setting, 149157,
168171
renaming, 238239
schema and, 582583, 626629,
676690
tables, 5253
where to place new, 676690
Object tab, 143
ObjectType field, 292293, 294
Octet strings, 483
OIDGEN tool, 606607
OIDs (object identifiers), 485, 486
base, 606607
basic description of, 603607
obtaining, 606607, 660
schema and, 603, 660661, 691
OLE automation
data types, 749752
explanation of, 723
OMDCs (operations master domain
controllers), 408, 410411, 413414, 415
Open Group, 452, 629
Operating System tab, 170
Operations master(s), 26, 324
changing, 829830
failures, 413414
listing, 828831
managing, 404416
placement of, 408411
roles, transferring, 411412
Oracle, 55
Organizational units (OUs), 2734,
135142
adding users of, to a Group.vbs,
859
administration scripts and,
856857, 859
basic description of, 1920
creating, 138, 857
deleting, 140141, 857
features of, 136137
managing, 121202, 856857
moving, 140141
planning, 141142
predefined, 123125
properties for, setting, 138140
renaming, 140141
Organization tab, 144
Originating updates, 388. See also
Updates
Orphan containers, 463
OS/2 (IBM), 89
OSI (Open Systems Interconnection)
directory services, 4849
OUs (organizational units). See
Organizational units (OUs); OU trees
OU trees. See also Organizational
units (OUs)
delegating, without blocking, 272
delegating, with possible
blocking, 270271
permissions and, 270272
roots of, 452
in single domains, 3940
Ownership, 243245
P
Packages
customizable installation, 558
non-MSI, deploying, 560561
patches for, 509
upgrades for, 509
Parameters, ADO command object,
899901
Parent domains
basic description of, 30
domain trees and, 3031
Partition(s)
administration scripts and,
896899
basic description of, 4445
configuration, 310311
creating, 62
enterprise, 310311
installation and, 81, 83
merging, 62
replication and, 310312, 362363,
374375
schema and, 310311
selecting, 83
topologies of several, 374375
types, 311
Whistler and, 65
Passfilt.dll, 511
Passprop.exe, 511
Password(s)
administrator, 97
age, maximum, 530
creating users and, 145
forcing complex, 511
installation and, 97
minimum number of characters in,
530
policies, 435
resetting, 164
Patches, 509
Paths, to abstract schema objects,
retrieving, 803804
PDC emulator, 406407. See also PDCs
(Primary Domain Controllers)
PDCs (Primary Domain Controllers). See also PDC emulator
installation and, 837
replication and, 25, 310
time convergence and, 403
Permission(s)
accumulation of, 245246
administration scripts and,
852854
in applications, 240243
attribute, 677, 696
basic description of, 3637
concepts, 213215
cross-object, 274275
default, 212, 258267, 575576
delegation scenarios for, 269275
denying, 246249
entries, ordering of, 246249
in forests, 466469
general practices using, 268269
generic, 854856
handling, with the ACL Editor,
212, 215229
inheritance and, 214, 240243, 259
list object, 224227
managing, 212251, 466469,
677679
object, 214, 222239
ownership and, 243245
performance and, 249250
property, 214, 229239
property set, 230236
replication and, 356
security principals and, 265267
special, 36, 213, 222229
standard, 36, 213, 222229
usage scenarios for, 267276
using, instead of rights, 301302
Personal Information property set,
232233
Phantoms, 407, 408, 409
Phone and Mail Options property set,
231
Physical structure. See also Physical
architecture
concepts, 308324
diagnosing, 354356
managing, 325356
monitoring, 354356
Physical architecture, 5154. See also
Physical structure
PINs (personal identification
numbers), 58
PKI (public key infrastructure),
4748, 5758, 204, 442, 514
Plug and Play, 83
Policies. See Group Policies
PowerQuest
Drive Image, 108
Partition Magic, 69, 115
Pre-Windows 2000 Compatible Access
group, 97, 130, 260
Preference, use of the term, 517
Primalscript, 713
Primary access tokens, 287. See also
Access tokens
Print Operators group, 129
Print queues, listing, 865
Processes tab, 711
Processing
loopback, 536539
Group Policies, 534546
periodic, 535
slow link, 536
Profile tab, 144, 154155
Propagation dampening, 388
Properties. See also Attributes;
Property cache; Property sets
delegating administration of
informational, 275276
informational, 142144, 164, 791
listing, 772784, 868869
mandatory, 41
multivalued, 41, 737738
nonreplicating, 322323
optional, 41
significant, 142144, 164, 791
single-valued, 41, 737738
syntax of, 41
Property cache
administration scripts and,
730736, 767772
contents of, listing, 770772
interfaces, 669770
special data types and, 734735
ways to read and write, 732733
Property lists, 480481
Property pages of schema objects,
618622, 637639
Property sets, 230236, 294296,
677679
Protocols (listed by name). See also
LDAP (Lightweight Directory Access Protocol); SMTP (Simple Mail Transfer
Protocol)
DAP (Directory Access Protocol),
4849
DHCP (Dynamic Host Configuration
Protocol), 3536, 70, 87, 90, 520, 538
DISP (Directory Information
Shadowing Protocol), 48
DSP (Directory System Protocol),
48
IP (Internet Protocol), 35, 70,
87, 88, 90, 368, 378, 387, 514515, 605
SNTP (Simple Network Time
Protocol), 403
TCP (Transmission Control
Protocol), 490
TCP/IP (Transmission Control
Protocol/Internet Protocol), 23, 57, 59, 70, 87,
9394, 97
Public Information property set, 232
Published Certificates tab, 142, 144
Publishing, basic description of,
5859
Q
QGrep command, 762
Queries, multipartition, 896899
R
RAID drivers, 81
RAM (random-access memory). See also
Caches
access tokens and, 175
administration scripts and, 700
installation and, 75, 81, 93
loading DLLs in, 51
schema cache and, 597599
RAS and IAS Servers group, 132
RCP, 59, 287
RCP Server, 287
RDNs (relative distinguished names)
basic description of, 4647
renaming objects and, 238239
NDS and, 63
RD/RMDIR
command, 115
Read User Information from Excel.xls,
797798
Read User Information from Standard
Input.vbs, 799801
Recovery Console
basic description of, 112113
FIXMBR command, 71
starting, 113
using, 113
Recovery options
basic description of, 111113
Safe Mode and, 111112
RepAdmin command, 355, 391, 398, 416,
746, 768
References
continuation, 487488
cross-, 469473
Referential integrity, 629
Referrals, 469473, 486, 898899
RegEdit, 562
RegEdt32, 562565, 662
Regional settings, 84
Registry
administration scripts and,
704705, 708710
Group Policies and, 514, 538, 543,
562565, 571, 573575
schema and, 662
tattooing, 506
Regular expressions, converting GUIDs
with,
845846
Relationship tab, 620
Remote Administration mode, 85
Remote Install tab, 171
REN/RENAME command, 115
RepAdmin command, 398
Replace mode, 536537
Replicas. See also Replication
basic description of, 44, 310312
partial, 364
partitions and, 310312
Replicated updates, 388
Replication. See also Replicas
Active Directory objects for,
325331
advanced topics, 357364
basic description of, 2426,
307419
change notification and, 320,
384385
collisions and, 398401
connection objects and, 358359
global catalogs and, 323
Group Policies and, 547
high-watermark vectors and,
394395
intersite, 319321, 364386
intrasite, 319321, 357364
latency, 309, 342
managing the physical structure
with, 325356
metadata, 391394
multimaster, 25, 309
nature of, 308310
nonreplicating properties and,
322323
operation masters and, 324,
404416
partitions and, 310312, 362363,
374375
PDC emulator and, 406407
permissions and, 356
reasons to use, 308
reciprocal, 384
removing domain controllers and,
352354
rings, 357361
scheduled, 320321
schema and, 662, 675
server objects and, 341343
single-master, 25, 310
site link bridges and, 321
SMTP, configuring, 386387
subnet objects and, 339340
test environments, 332333
time synchronization and, 402404
tombstones and, 401402
topologies, 314315
traffic, 421425
transitive nature of, 319
units of, 17, 435436
up-to-date vectors and, 395398
urgent, 321322
Replication Monitor tool, 569
Replicator group, 130
Reverse lookup zones, 104
RFCs (requests for comments)
downloading RFC documents, 35
RFC 977, 35
RFCs 10341036, 95
RFC 1278, 633
RFC 1487, 10, 49
RFC 1510, 56
RFC 1769, 403
RFC 1777, 10, 49
RFC 1995, 94
RFC 2052, 95
RFC 2078, 104
RFC 2136, 35, 94
RFC 2137, 104
RFC 2251, 10, 49, 488
RFC 2798, 65
RFC 2849, 489, 498, 501, 876
RFCs related to LDAPv3, 5051
RID MASTER, 405406
RIDs (relative IDs), 285, 324,
405406, 413414
Rights
extending, 227229
using permissions instead of,
301302
RIS (Remote Installation Services),
39, 503
creating computer objects and,
166168
Group Policies and, 520521, 573
Root domains
basic description of, 30
domain trees and, 3031
forest, 95, 448452
removing, 102
RootDSE, 451, 495, 598, 727728,
826827
Root object, 479
RPC (remote procedure call), 348, 378,
383
domain controller placement and,
423
replication and, 24
S
SACLs (system access control lists)
basic description of, 36, 288289
Group Policies and, 512, 513
Safe Mode, 111112
Safe Mode with Command Prompt option,
112
Safe Mode with Networking option, 112
Schema
administration scripts and,
801822
ADSI and, 54
basic description of, 4244,
581640
cache, 597599
containment rules, 607610
content rules, 629634
disabling modifications to, 661
dumping, to spreadsheets, 594596
extending, 43, 641696
GC and, 585
inspecting, 588594
location of, 585592
masters, 405, 660662
modification of, 642659
number of, 438
objects, 616617
permissions and, 677679
physical location of, 586
replication, 675
role of, 585
searches and, 634637
structure rules, 607610
sub-, subentries, 596597
syntax, 622631
updates, forcing, 662
Schema Admins group, 131, 259, 661
Schema cache
explanation of, 597598
update of, 228, 598599, 661, 662,
672
update with a script, 819, 821
Schema container, 586
Schema Manager snap-in, 592594, 620,
662, 663
basic description of, 664674
creating/modifying attributes
with, 664666
creating/modifying classes with,
666669
Schema master, 405
Script(s)
adding, to context menus, 693694
as command-line tools, 706708,
884887
concepts, 697758
configuration information and,
822832
debugging, 755759
development environment for,
712715
editors, 712713
examples of, 761794, 804805
execution environment for, 699703
file types, 703
Group Policies and, 509510
help files and, 713714
killing, 710711
property caches and, 730750,
767772
schema access, 801822
settings, 708710
testing, 704705
Script Debugger (Microsoft), 85, 86,
756757
Script tab, 709
SCSI (Small Computer Systems
Interface), 81
SDCheck, 250
SDDL (Security Descriptor Definition
Language), 617618
default ACLs and, 267
definition of acronyms in, 255
schema and, 613, 617618
SDs (security descriptors), 36,
288296
Search(es)
with ADO, 891
with LDAP, 52, 473501, 893894
multidomain, 486
on new attributes, 694696
options, as command object
parameters, 899901
schema and, 634637
specifying values for, 484486
strings, 893894
tools, 488494
Search Options dialog box, 497
Secedit command, 510
Security Configuration and Analysis
Snap-in, 510
Security Configuration Toolset, 510
Security tab, 143
Security Templates snap-in, 510511
Server(s)
bridgehead, 315, 371374
GUIDs, 389, 395
member, 88, 305306
objects, moving/managing, 341343
stand-alone, 88
Server Operators group, 129
Service packs, 80
Services, listing, 863865
Session Manager, 287
Session tickets, 56
SET command, 115
Setup. See also Installation
finalizing, 89
Wizard, 9293
Setup Manager Wizard, 106107
Shortcut trusts, 31
ShowInAdvancedViewOnly attribute,
613616
Show Property Properties.vbs, 809810
SIDs (security IDs)
ACEs and, 288292
basic description of, 283287
deleting users and, 162
foreignSecurityPrincipal object
and, 462
installation and, 108
MoveTree tool and, 463
RID master and, 405406
Single sign-on, 204
Site(s). See also Site links
Active Directory objects for,
325331
administering, 337338
basic description of, 23
coverage, 318
Default-First-Site-Name, using,
338339
objects, creating/managing,
340341
placement of directory information
and,
426432
replication and, 307419
setting up multiple, 334337
setting up single, 333334
Site link(s)
bridges, 321, 378380
costs of, 369371
creating/managing, 348351
replication topology and, 367369
WANs as, 23
Sites and Services snap-in, 331333
SLDs (second-level domains), 452
Slow link detection algorithm, 576578
Smart cards, 57, 440, 661
SMARTDRIVE command, 78
SMTP (Simple Mail Transfer Protocol),
326327, 330, 348350, 378, 382383
domain controller placement and,
423
replication and, 2425, 386387,
436
schema and, 601
SNTP (Simple Network Time Protocol),
403
Software. See also Applications
deploying, 559561
managing, 557562
Spreadsheets, 594596
SQL (Structured Query Language),
894895
SQL Server, 52, 55
SRM (security reference monitor), 246
SRV records, 34, 93, 102
Stamps, 391, 398
Stand-alone servers, 88
Statistically unique numbers, 285
Strings
binding, 725726
octet, 483
search, 893894
Structure rules (of schema classes),
607610
Subnet objects, creating/managing,
339340
Subschema object. See Abstract schema
objects
SUPPORT folder, 74
Switchboard, 9
Switches, 7879
Synchronization services, 25
Syntax
ADSI, 749752
choices, 629634
highlighting, 712
rules, 629634
SYSOC.INF, 85
SYSOCMGR command, 85
SysPrep (System Preparation Tool), 108
System account, 282. See also
LocalSystem account
System container, 674
System Management Server (Microsoft),
509
System partition, 69
System Policy, 40, 505506
SYSTEMROOT command, 115
System services, 513
System State, 553554
SysVol (System Volume) folder, 6869
T
Task Manager, 704, 711, 756, 864
Task Scheduler, 210, 700, 711
TCO (total cost of ownership), 503
TCP (Transmission Control Protocol),
490. See also TCP/IP (Transmission Control Protocol/Internet Protocol)
TCP/IP
(Transmission Control
Protocol/Internet Protocol). See
also TCP
(Transmission Control Protocol)
connecting to the Internet and, 59
installation and, 70, 87, 9394,
97
site functions and, 23
traffic encryption, 57
Telephones tab, 144
Templates
administrative, 515519
basic description of, 204
Group Policy, 524, 525, 567
security, 41, 204, 510511
Terminal Services, 85, 87, 93, 476
Testing
batch files, 687688
environments, 332333
schema modifications, in forests,
660, 685690
scripts, 688690
TGT (ticket-granting ticket), 56, 435
Time
convergence hierarchy, 403
GMT/UTC, 390, 485, 689
services, controlling, 403404
settings during installation, 87
-stamps, 390
strings, generalized, 485
synchronization, 402404
target, 404
TLDs (top-level domains), 452
Tombstones, 401402
Topologies
intersite, 6465, 364386
intrasite, 357364
replication, 314315, 357386
Transactions, 52
Transitivity, of replication, 319
Tree(s)
creating, 9495
deleting OUs in, 140141
moving OUs in, 140141
renaming OUs in, 140141
root domain, 451
Troubleshooting
Group Policies, 562571
installation, 110113
Trust(s)
basic description of, 1718
bidirectional, 1819, 30, 453,
455, 462
computer, 441443
creating explicit, 460462
managing, 452562
shortcut, 31, 446447
transitive, 1819
tree root, 33
trusted domain objects and,
452454
verifying, 457459
viewing, 454457
TrustAttributes property, 454
TrustDirection property, 453
Trustees, defining, 852
TrustPartner property, 453
Trust view to a forest, 446
TXTSETUP.SIF, 106
TYPE command, 115
U
UDF (Uniqueness Database File), 106
UltraEdit, 713
Unbind operation of LDAPv3, 52
Unicode character set, 34, 483, 516
UNINST.TXT, 117
United Nations, 47
Universal groups, 2122
University of Michigan, 10
UNIX, 3435, 192, 629
Unsolicited Notification operation of
LDAPv3, 52
Updates. See also USNs (update
sequence numbers)
DNS, 3536
dynamic, 3536, 102104
forcing, 662
schema, 662
schema cache, 598599
Upgrades, 8990, 509
UPNs (user principal names)
basic description of, 4647, 440
domain controller placement and,
431
locating user objects via, 440
smart card logons and, 440
suffixes for, 148, 440
UPS (uninterruptible power supply),
74, 92
Up-to-date vectors, 395398
U.S. Department of Defense, 605
User(s)
accounts, disabling, 163
accounts, options for, listing,
784788
administering, 142164
class, extending, 690696
copying, 160161
creating, 145148, 788794,
869870
deleting, 162163
domain modes and, 134
editing multiple, 65
groups, predefined, 468
home pages of, opening, 164
informational properties of,
156157
information, reading, 797801
listing, 764767, 865, 877878
managing, 121202, 764822
moving, 162, 857
objects, properties of, setting,
149157
predefined, 125126
primary groups for, setting,
192193
properties of, listing, 772784
properties of, setting, 148157
renaming, 162
sending e-mail to, 164
User interface
bringing schema extensions to,
676690
creating objects for, 680681
where to place new objects in,
676690
User logon name property, 147
User rights
applying, 303305
assigning, 302
User rights (cont.)
basic description of, 296306
modifying, for domain controllers,
304306
normal privileges, 299300
Users and Computers snap-in, 92, 140,
160, 200202
auditing and, 280
basic description of, 200201, 489
changing group types in, 188
CN=Configuration object and, 586
creating groups with, 186187
creating user objects with, 582
display of editable properties in,
236
installation and, 92
predefined groups in, 130133
user property pages of, 236237
viewing default permissions with,
259
Users container, 124, 126133
U.S. Naval Observatory, 403
USNs (update sequence numbers), 25,
392395. See also Updates
basic description of, 313314,
389391
high-watermark vectors and,
394395
local, 390
originating, 390
timestamps and, 390
up-to-date vectors and, 395398
version numbers and, 390
UUIDGen, 648, 653, 679
V
V.34 modems, 47
Value(s)
attribute, managing, 693694
specifying, for LDAP searches,
484486
string, 718
Variable(s)
administration scripts and, 718
names, 718
VBA (Microsoft Visual Basic for
Applications), 701
VBScript (Microsoft)
ADSI and, 54
basic description of, 698, 702,
715721
COM components and, 753754
Editor, 713
Group Policies and, 509
schema and, 663
scripts, creating/testing, 688690
scripts, sample, 716721
Vectors, 394395
Verbose mode, 489490
VeriSign, 57
Veritas WinInstall2000, 559
VINES, 9
Virtual containers, 58
Virtual private networks (VPNs), 155
Visual Basic, 680, 701, 702
Visual Studio Installer (Microsoft),
559
VMware, 73
VMware Workstation, 73
VPNs (virtual private networks), 155
W
WANs (wide-area networks), 23, 436
bandwidth and, 425
domain controller placement and,
427432
Group Policies and, 547
hierarchies and, 27, 29
installation and, 109
replication and, 24, 308309, 315,
318, 334, 338, 368, 370
schema and, 654, 655
Web Information property set, 235
Well-known security principals,
209212
Whistler, 6465
WhoWhere, 9
Win32 API, 755
Windows Installer, 557562
Windows NT (Microsoft)
Active Directory and, comparison
of, 1113
Cairo and, 1011
domains, using multiple domains
because of, 436
history of, 89
properties, listing, 870871
system policy, 505506
Windows 2000 Server (Microsoft)
answer files and, 106107
components, installation of, 8587
dual booting, 7073
hardware compatibility with, 7475
history of, 1011
installation, 6876, 8092,
105107
requirements/recommendations, 74
Resource Kit, 255, 566571
server upgrades, 83790
uninstalling, 113117
Windows.NET Server, 6465, 231, 347,
539, 643, 655
Windows 2000 Professional, 9293
Windows Update Corporate Web site, 91
Windows XP, 64, 539, 578
WinEdit, 715
WINNT command, 7881
WINNT folder, 6869
WINNT32 command, 78, 80, 81
WINNT32.EXE, 73
WINS (Microsoft Windows Internet
Naming Service), 36, 53, 70, 88
WinSock, 59
Wise for Windows Installer, 559
WKGUIDs, 874878
WMI (Windows Management
Instrumentation),
754755
Workstations, 302, 305306, 869870
World Telecommunication
Standardization Conference, 48
WScript, 680, 703705, 711
WSH (Windows Script Host), 202, 509,
699742
W32Time, 403
W32TM, 403404
X
X.500 standard, 10, 44, 4749, 606,
613, 629
X.509 certificates, 48, 57, 86. See also PKI (public key infrastructure)
XLNT, 703
XML (Extensible Markup Language), 703,
758, 759
XOM (XAPIA X/Open Object Management)
syntax, 629
Y
Yahoo!, 9
Z
Zap files, 560561, 562
Zones. See DNS Zones