Ad Manager Plus Help
Ad Manager Plus Help
Table Of Contents
TECHNOLOGY OVERVIEW.................................................................................... 10
Active Directory Overview.................................................................................................. 11 Active Directory Terminologies .......................................................................................... 13
CSV IMPORT........................................................................................................... 28
Users Creation in Active Directory by Import CSV ............................................................ 29 Modify Active Directory Users Properties/ Attributes by Import CSV................................. 31 Create Contacts in Active Directory................................................................................... 33 Modify Contacts in Active Directory Using CSV ................................................................ 34 Delete Contacts ................................................................................................................. 35 Create Group in Active Directory Using CSV .................................................................... 36 Modify Group in Active Directory ....................................................................................... 37
ZOHO Corp.
ZOHO Corp.
ZOHO Corp.
WEB BASED PEOPLE SEARCH.......................................................................... 171 SEARCHING SECURITY PERMISSIONS............................................................. 172 ACTIVE DIRECTORY EXPLORER ....................................................................... 173 TROUBLESHOOTING TIPS.................................................................................. 174 FAQ........................................................................................................................ 180 KNOWN ISSUES AND LIMITATIONS................................................................... 185 ADMP - ADSSP INTEGRATION............................................................................ 186
ZOHO Corp.
ZOHO Corp.
Searching Security Permissions: Enables searching ACEs to determine the permissions of the security principals. Active Directory Explorer: Enables you to view the Active Directory in the Windows explorer format. Troubleshooting Tips: Helps you to troubleshoot the problems with the product. FAQ: Provides a set of frequently asked questions to clarify your product related queries. Known Issues and Limitations: Provides the limitations and the known issues of ADManager Plus.
ZOHO Corp.
Release Notes
The key features of this release comprise the following: 1. User Management Create Users in different OUs using CSV Import Modify SMTP Address for Users
3. Reports 4. Users not in a Group Members of Domain Users Group Only Users with Change Password at Next Logon IMAP4 Enabled Users POP3 Enabled Users OMA Disabled Users Customize column settings for Scheduled Reports Shares in the Servers Permissions for Folders Folders accessible by Accounts AD Objects accessible by Accounts Subnets accessible by Accounts Servers accessible by Accounts Subnet Permissions Server Permissions
HelpDesk Delegation Restrict Reports viewable by HelpDesk Multiple roles can be Delegated to a Single Technician
5.
Admin Settings Disable Forgot Password Link on Logon Page Create Customized "Offices/Companies" for your Organization
6.
ZOHO Corp.
Web site
www.zohocorp.com ZOHO Corp., Inc. 4900 Hopyard Rd, Suite 310 Pleasanton, CA 94588 USA Phone: +1-925-924-9500 Fax : +1-925-924-9600 E-mail: [email protected] ZOHO Development Centre (I) Private Limited 11 Sarathy Nagar, Vijayanagar, Velachery, Chennai 600 042 INDIA Phone: +91-44-22431115 (10 lines) Fax: +91-44-22435327 E-mail: [email protected]
Sales
To purchase ManageEngine ADManager Plus from any part of the world, you can fill out the Sales Request Form. A sales person will contact you shortly. You can also send us an e-mail at [email protected]. You can also call the ZOHO Corp headquarters at the following numbers: Phone: +1-925-924-9500 Fax: +1-925-924-9600 and request for Sales
Technical Support
One of the value propositions of ZOHO Corp to its customers is excellent support. During the evaluation phase the support program is extended to you free of charge. Please send your technical queries to [email protected]
ZOHO Corp.
Following is the support format to be enclosed, while sending support mails: Edition ( Free or Professional Edition) of the product Operating System version, such as Win 2000, 2003, etc. Browser version, such as Netscape 7.0, IE 5.5, etc. Details of the problem Steps to reproduce the problem.
Alternatively, select the Support tab from the client window. It has the following options that will allow you to reach us: Request Support - Submit your technical queries online. Need Features - Request for new features in ADManager Plus. User Forums - Participate in a discussion with other ADManager Plus users. Contact Us - Speak to our technical team using the toll free number (1-888-7209500)
ZOHO Corp.
Technology Overview
To get started with ManageEngine ADManager Plus it is essential to be familiar with basics of Windows Active Directory and Group Policy. Read the following sections for more details. If you are familiar with the basics, you can skip this section. Active Directory Overview Active Directory Terminologies
ZOHO Corp.
10
ZOHO Corp.
11
object class,such as List contents, Delete Tree, List Object, Write Self, Control Access, Create Child, Delete Child, Read Property, Write Property, and so on. These permissions have to be assigned to the users or groups to restrict or grant access to the Active Directory objects. Each assignment of permissions to users or groups is referred to as Access Control Entry (ACE).
Inherited Permissions
Permissions set on a container (or a parent object) can be applied to its child objects as well. This is referred to as inherited permissions. The Active Directory security model allows you to define explicit permissions or propagate permissions to its child objects. For example, you specify the following conditions for propagation: This object only This object and all child objects Computer objects Group objects Organizational unit objects User objects
Containers can be any Active Directory components like Domain, Organizational Units and only objects within those containers can inherit permissions from the parent. Some commonly used Active Directory terminologies are discussed in the next topic.
ZOHO Corp.
12
ZOHO Corp.
13
Getting Started
The following sections describes how to get started with ADManager Plus. System Requirements Installing ADManager Plus Working with ADManager Plus Installing Service Packs Uninstalling Service Packs Licensing ADManager Plus
ZOHO Corp.
14
System Requirements
Hardware Requirements Software Requirements
Hardware Requirements
Hardware Processor RAM Disk Space Recommended P4 - 1.0 GHz 512 MB 200 MB
Supported Browsers
ManageEngine ADManager Plus requires one of the following browsers to be installed in the system for working with the client. Internet Explorer 5.5 and above Netscape 7.0 and above Mozilla 1.5 and above Firefox 1.5 and above
ZOHO Corp.
15
ZOHO Corp.
16
ZOHO Corp.
17
This will enable SSL and a secure communication by ADManager Plus over the internet is possible. A valid SSL certificate is to be applied for enabling SSL.
Open -up selective Firewall Ports to facilitate access over the Internet :
(i) When ADManager Plus is installed on your local area network with the url accessible across internet : Open the port on which ADManager Plus is running. By default ADManager Plus runs on port 8080 and it is configurable.
ZOHO Corp.
18
(ii) When ADManager Plus is installed in the DMZ, open the following ports in the Firewall: Port "389" to communicate with the LDAP Protocol. Port "135" to communicate with RPC. Refer section: "Find Dynamic Ports" for other dynamic ports that needs to be opened in the Firewall. These will be used for communication between AD and ADManager Plus. |
ZOHO Corp.
19
In case you use different port for RPC, use the Port Number in which your RPC is running by replacing 135 in the above command. Step 3: After executing the above command, open the "resultPorts.txt" from where the command is executed. Step 4: Find for all the "_tcp" in the "resultPorts.txt" (Ex : ncacn_ip_tcp:100.190.1.2[1142]) Step 5 : The value in the Square Brackets[ ] are the ports which needs to be opened. Make a note of these ports. (Ex: in the above result, 1142 is the port that needs to be opened). Step 6: Continue with the search until the file ends and open all the identified ports.
ZOHO Corp.
20
On starting the ADManager Plus, the client is automatically launched in the default browser. When ADManager Plus is started in Windows XP / Windows 2003 machines with firewall enabled, Windows may pop up security alerts asking whether to block or unblock the following programs as shown in the images below: 1. mysqld-nt - Database server 2. Java(TM) 2 Platform Standard Edition binary - Java. You should Unblock these programs to start ADManager Plus.
ZOHO Corp.
21
ZOHO Corp.
22
ZOHO Corp.
23
ZOHO Corp.
24
ZOHO Corp.
25
Dashboard View
The Home tab projects a Dashboard View of the essential and top level information of domains. The Dashboard View projects the following: Vital Help Desk Reports Canned Reports
Vital Help Desk Reports: This section holds a concise list of the essential help desk related reports. The number of Password Expired Users and those whose password is likely to get expired within a week's time is also listed against appropriate headings. Password attributes of users can be modified using the Change password at Next Logon button. Canned Reports: This section contains an auto-generated list of users listed under the most commonly used report types of the User, System and Other Reports categories. These reports get generated everyday at a scheduled time of the day. You can also get an updated list of users with the relevant numbers based on the options you select. The Update Dashboard option allows you to synchronize the Active Directory and ADManager Plus. You can select the category of reports from the Update details of dialog. Meanwhile, if you want to know the latest details of only specific reports, use the Update option adjacent to the report name.
ZOHO Corp.
26
Configuring Domains
During startup, ADManager Plus adds all the domains that could be discovered. If you wish to add more domains or modify the added domains, you can do it from here. Note: The procedure to add domains like Child Domains, Domains from same and different forests are the same. To add more domains, follow the steps below: 1. Click the Domain Settings link from the client to open the Domain Settings page. 2. The domains that are already added are listed here. Click the add new domain link to open the Add Domain Details dialog. 3. Specify the Domain Name. 4. Click on Discover link to locate the domain controllers from the DNS and add. Else, add all the domain controllers manually. The domain controller that appears first in the list is considered as the primary domain controller. Use the up and down arrows to move the added domain controllers in the order of priority. 5. Specify the authentication details of the user as which the domain controller will be contacted. 6. Click ADD to add the domain. You can perform the following actions from here: 1. Default Domain: The domain that is first discovered is considered as default domain. The default domain is shown in bold letters. Delegating security roles can only be done to the security principals of the default domain. If you wish to icon from the action column to make it change the default domain, click the default. 2. Modifying Domain: To modify the domain details, click the the required values and save. 3. Deleting a Domain: To delete a domain, click the icon. icon and change
4. Refreshing the Domain Details: To synchronize the object details with the icon. Active Directory, click the Note: While adding new domains, the user name and password provided will be used for management and report purpose in the product. If the user entered in the domain settings should have the privilege to perform a management operation. Read only privilege is sufficient for a users to view reports. the first domain controller will be contacted first if it turns unsuccessful then the next domain controller in the order will be contacted.
ZOHO Corp.
27
CSV Import
Now you can create and modify users, groups, contacts using CSV import. Create users using CSV Modify users using CSV Create groups using CSV Modify groups using CSV Create contacts using CSV Modify contacts using CSV
ZOHO Corp.
28
Note: The following information conveys the mandatory and useful guide lines for successful creation on users by importing from CSV List of LDAP attributes supported. Sample CSV file. Bulk user creation by CSV To create a user, any one of the following naming attributes is mandatory and enough: givenName or cn or name or samAccountName. To mention the user's OU in the CSV : In case you want to create users under different OUs, mention the user's givenName, followed by the OUName in the CSV file. Example: John, "OU=FinanceOU, DC=abc, DC=com" In case you want to create a user in a child OU, here's a sample of the values that need to be supplied in the CSV file. Example: John, "OU=PayrollOU, OU=FinanceOU, DC=abc, DC=com". In this example, PayrollOU is the child OU and FinanceOU is the parent OU. To have Useraccountcontrol attribute in CSV : Useraccountcontrol should contain the flag value of the user account properties. Example: A flag value 512 indicates that the account is general; and value 514 indicates that the account is disabled. For detailed information, click http://support.microsoft.com/kb/305144 While specifying the password you will be prompted to choose one of the two options: 1. Selecting the option User must change password at next logon will assign a value 0; to pwdLastSet 2. Unselecting the option, User must change password at next logon will assign a value -1 to pwdLastSet To have memberOf attribute in CSV : A user can be a member of more than one group, to support multiple values Distinguished Name (DN) of the groups should be separated by semicolon (;). Example:"CN=Group1,CN=Users,DC=domain,DC=com;CN=Group2,CN=Users,DC=dom ain,DC=com" To have primaryGroupID attribute in CSV For a user in multiple groups only one group is considered as primary; to specify that RID should be assigned. AccountExpires: While specifying the account details, you will be prompted to choose one of the two options: 1. Selecting the option Account Never Expires will assign a value 0 to Accountexpires. 2. To have a expiry date set a date specify the file time. Other values should be in the FileTime format(Contains a 64-bit value representing the number of 100nanosecond intervals since January 1, 1601 (UTC).) To have userWorkstations attribute in CSV To restrict users to specific computers the NEtbios names of computers separated by (,) should be entered and all values should be in
ZOHO Corp.
29
To have 'Country' attribute in CSV 1. The three values c, co, countryCode are mandatory. 2. c - 2 letter country code (eg. US for United states). 3. co - Country Name(Full Country Name). 4. countryCode - 3 digit country code(eg. 840 for United States). To have manager attribute in CSV: CSV should contain the DN of the manager. To have MailBox Enabled Users attribute in CSV: CSV should have 1. Minimum Attributes Needed - mailNickame, homeMDB, msExchHomeServerName. 2. homeMDB - should contain the DN of the mail box store. 3. msExchHomeServerName - value of mail server in legacyExchangeDN Format. To have Mail Enabled Users attribute in CSV: CSV should have 1. Minimum Attributes Needed - mailNickname, targertAddress, msExchAdminGroup 2. targertAddress - value should be something like(SMTP:[email protected]) 3. msExchAdminGroup- value of exchange Admin Group in legacyExchangeDN Format. To have attributes Home Folders and Profile Path, TS Home Folder, ProfilePath in CSV 1. The values can be an absolute path of the folder 2. May contain variables like %userName%, %givenName% etc.. To have Additional email address 1. The user should have the attribute 'proxyAddresses' set to a value. Example - "smtp:[email protected];smtp:[email protected]" To have Additional Attributes Select the 'Additional Attributes' tab to add custom attributes. Enter the exact Attribute name and value. Example: If you wish to have Employee Id Number in user attributes, then enter 'Employee Id Number' as the Attribute name and enter the value. This will add that attribute in to the user account properties and the information can be obtained from Reports.
User creation by Template 1. A user can be created by selecting the predefined templates available in the option "selected Template" 2. By selecting a template, all the properties of the template will be applied to the users being created. 3. By clicking in 'change' you can change the template from mail enabled users to mailbox enabled users etc. 4. A set of users with common properties can be created by using the specific template. Creating user template Example: If your intention is to create user accounts with mailbox for permanent employees, you can select the template 'MailBox Enabled Users' and start creating accounts. All the users created eventually will bare the same properties.
Note: First create a csv with all the updated information and then start the process.
ZOHO Corp.
30
ZOHO Corp.
31
An example entry to modify the "department" and "telephone number" for group of users is given below: givenName,samAccountName,department,telephoneNumber MathewIles,MathewIles,Transportation,01455 882107 Emmanuelsam,Emmanuelsam,Transportation,01455 882108 Strongosky,Strongosky,Transportation,01455 882109
ZOHO Corp.
32
ZOHO Corp.
33
You can modify Active Directory Contacts attributes using CSV import. To perform this operation follow the steps below: 1. Select the AD Mgmt tab. 2. Select Contact Management link on the left pane and open the Contact Management page. 3. Select the Modify Contacts link under CSV Import. 4. Click the Import button. Browse the CSV file to be imported and click OK. 5. Select the contacts for which the details need to be updated in the CSV Import page, 6. Click the Update in AD button. 7. Select the attributes to be modified in the Select Attributes dialog. 8. Click OK. The Contacts' attributes will now hold the values as mentioned in the CSV file that was imported. Note: The Match criteria for Contacts in AD: Show, allows you to specify the LDAP names that should uniquely identify the contacts.
ZOHO Corp.
34
Delete Contacts
Obsolete or unwanted contacts and their accounts can be deleted using this option. To perform the deletion follow the below steps: Select the AD Mgmt tab. Click the Delete contacts link available under General Attributes. This opens the Delete Contact Accounts from Active Directory dialog. Select the domain and search the contacts. You can limit your search to specific OU's of the domain by clicking the Select OU link and selecting the OU's. You can import the list of contacts to be modified from CSV format or select the user from 'show All contacts' list or Type a contact name. From the listed contacts, select the contacts to be deleted. Click on Apply to confirm the deletion.
The change summary and the status of the modification can be verified. Roll over the mouse over the icon to see the attributes in the windows native UI.
ZOHO Corp.
35
ZOHO Corp.
36
ZOHO Corp.
37
ZOHO Corp.
38
ZOHO Corp.
39
Create Users
Active Directory Create Users
ManageEngine ADManager Plus enables you to create multiple user accounts to your windows domain with ease. You have the flexibility to create single users, multiple users either manually or by CSV import. This section guides you in Creating users using ADManager Plus. Follow the links to learn more: Creating a Single User Creating Bulk Users Creating Users Using CSV Additional Attributes
ZOHO Corp.
40
ZOHO Corp.
41
4. A set of users with common properties can be created by using the specific template. Link to template creation Ex: If your intention is to create user accounts with mailbox for permanent employees, you can select the template 'MailBox Enabled Users' and start creating accounts. All the users created eventually will bare the same properties. For details on the user attributes, refer to the Microsoft Documentation here and here. Note: 1. To create Mailbox Enabled Users in Exchange 2007, you would require the Exchange Management Console, failing which the legacy Mailbox will be created. 2. The mandatory parameters for creating a user are the First Name, the Logon Name, SAMaccount Name and the FullName. When the attribute is left blank, the user account will be created with the default values. 3. Changing domain in middle of things will reset all domain specific attributes. 4. OWA - 2 DC Replication. If Mailbox is created in one Domain controller, Out look Web Access contacts other Domain Controller to confirm the mapping, but do not authenticate. The Real Scenario for this is: 1. A Domain May have more than one domain controllers. 2. Users We will be created in the first available domain controller in ADManager Plus. 3. The OWA authenticates a DC for login, if the DC is not the one in which user is created, it will not be recognised about this until it is replicated.
ZOHO Corp.
42
ZOHO Corp.
43
Sample CSV file. Hints: 1. While adding users who have same set of permissions, you can create a user template by specifying the required permissions and create a CSV file containing the names of the users, which can be imported while creating bulk users. 2. If you have to create users with different permissions, you can include the attributes that have different values for different users in the CSV file along with their names and can still have a base template for common attributes. Note: When you use a combination of user template and CSV file, the attribute values specified in the CSV file takes precedence.
ZOHO Corp.
44
Note: The following information conveys the mandatory and useful guide lines for successful creation on users by importing from CSV. List of LDAP attributes supported. Sample CSV file. Bulk user creation by CSV To create a user, any one of the following naming attributes is mandatory and enough: givenName. To have Useraccountcontrol attribute in CSV : Useraccountcontrol should contain the flag value of the user account properties. Example: A flag value 512 indicates that the account is general; and value 514 indicates that the account is disabled. For detailed information, click http://support.microsoft.com/kb/305144 While specifying the password you will be prompted to choose one of the two options: 1. Selecting the option User must change password at next logon will assign a value 0; to pwdLastSet 2. Unselecting the option, User must change password at next logon will assign a value -1 to pwdLastSet To have memberOf attribute in CSV : A user can be a member of more than one group, to support multiple values Distinguished Name (DN) of the groups should be separated by semicolon (;). Example:"CN=Group1,CN=Users,DC=domain,DC=com;CN=Group2,CN=Users,DC=dom ain,DC=com" To have primaryGroupID attribute in CSV For a user in multiple groups only one group is considered as primary; to specify that RID should be assigned. AccountExpires: While specifying the account details, you will be prompted to choose one of the two options: 1. Selecting the option Account Never Expires will assign a value 0 to Accountexpires. 2. To have a expiry date set a date specify the file time. Other values should be in the FileTime format(Contains a 64-bit value representing the number of 100nanosecond intervals since January 1, 1601 (UTC).) To have userWorkstations attribute in CSV To restrict users to specific computers the NetBIOS names of computers separated by (,) should be entered and all values should be in To have 'Country' attribute in CSV 1. The three values c, co, countryCode are mandatory. 2. c - 2 letter country code (eg. US for United states). 3. co - Country Name (Full Country Name). 4. countryCode - 3 digit country code (eg. 840 for United States). To have manager attribute in CSV: CSV should contain the DN of the manager.
ZOHO Corp.
45
To have Password attribute in CSV: CSV should contain the header 'password'. To have MailBox Enabled Users attribute in CSV: CSV should have 1. Minimum Attributes Needed - mailNickame, homeMDB, msExchHomeServerName. 2. homeMDB - should contain the DN of the mail box store. 3. msExchHomeServerName - value of mail server in legacyExchangeDN Format. To have Mail Enabled Users attribute in CSV: CSV should have 1. Minimum Attributes Needed - mailNickname, targertAddress, msExchAdminGroup 2. targertAddress - value should be something like(SMTP:[email protected]) 3. msExchAdminGroup- value of exchange Admin Group in legacy ExchangeDN Format. To have attributes Home Folders and Profile Path, TS Home Folder, ProfilePath in CSV 1. The values can be an absolute path of the folder 2. May contain variables like %userName%, %givenName% etc.. To have Additional email address 1. The user should have the attribute 'proxyAddresses' set to a value. Example - "smtp:[email protected];smtp:[email protected]" To have Additional Attributes Select the 'Custom Attributes' tab to add additional attributes. Enter the exact Attribute name and value. Example: If you wish to have employeeID in user attributes, then enter 'employeeID' as the Attribute name and enter the value. This will add that attribute in to the user account properties and the information can be obtained from Reports.
User creation by Template 1. A user can be created by selecting the predefined templates available in the option "selected Template" 2. By selecting a template, all the properties of the template will be applied to the users being created. 3. By clicking in 'change' you can change the template from mail enabled users to mailbox enabled users etc. 4. A set of users with common properties can be created by using the specific template. Creating user template Example: If your intention is to create user accounts with mailbox for permanent employees, you can select the template 'MailBox Enabled Users' and start creating accounts. All the users created eventually will bare the same properties.
Note: First create a CSV with all the updated information and then start the process.
ZOHO Corp.
46
Native Active Directory supports creation of Custom Attributes in Exchange. The Custom Attributes are predefined by name and the value can be given by you.
ZOHO Corp.
47
Modify Users
Active Directory Modify Users
ManageEngine ADManager Plus enables you to create multiple user accounts to your windows domain with ease. You have the flexibility to create single users, multiple users either manually or by CSV import. This section guides you in Creating users using ADManager Plus. Follow the links to learn more: Modify Users Using CSV Modify Single User Bulk User Modification
ZOHO Corp.
48
ZOHO Corp.
49
An example entry to modify the "department" and "telephone number" for group of users is given below: givenName,samAccountName,department,telephoneNumber MathewIles,MathewIles,Transportation,01455 882107 Emmanuelsam,Emmanuelsam,Transportation,01455 882108 Strongosky,Strongosky,Transportation,01455 882109
ZOHO Corp.
50
ZOHO Corp.
51
ZOHO Corp.
52
ZOHO Corp.
53
Resetting Password
To reset the password for the user(s), follow the steps below: 1. Select the AD Mgmt tab. 2. Click the Reset Password link available under General Attributes. This opens the Modify Password Attributes of the Users dialog. 3. To reset the password, select the Reset Password check box and select any of the options for setting the password. 4. To change the password properties, select the options as required. 5. Select the domain and search the users. You can limit your search to specific OU's of the domain by clicking the Select OU link and selecting the OU's. 6. You can import the list of users to be modified from CSV format or select the user from 'show All Users' list or Type a user name. 7. From the listed users, select the users to reset the password and click Apply.
ZOHO Corp.
54
ZOHO Corp.
55
Enable / Disable users: In most of the reports you find an option to Enable / Disable users. This is an integration of User management into Reports. This feature enables you to modify or manage the user accounts from reports itself. To perform this: 1. Look out for the options Enable / Disable / More actions in the user reports generated. 2. Check in the boxes adjacent to the desired users to select them. 3. Now you can Enable / Disable or perform More actions by clicking on the appropriate tab.
ZOHO Corp.
56
ZOHO Corp.
57
Note: 1. Profile Path need not be specified, if it is a local path. 2. When you specify the Home Folder/Profile Path in a network share, it is advisable to provide permissions only to the specified users to avoid any misuse/discrepancies. 3. Logon Script specified should be located in SYSVOL\<domainName>.com\scripts directory in the Domain Controller.
ZOHO Corp.
58
ZOHO Corp.
59
ZOHO Corp.
60
ZOHO Corp.
61
ZOHO Corp.
62
ZOHO Corp.
63
ZOHO Corp.
64
Note: 1. Changing the Name format will change the name of the existing user account with all the other properties unaltered. 2. Changing the Logon name and SAM account name may cause duplication, if one by the same name exists.
ZOHO Corp.
65
Delete users
Obsolete or unwanted users and their accounts can be deleted using this option. To perform the deletion follow the below steps: Select the AD Mgmt tab. Click the Delete Users link available under General Attributes. This opens the Delete User Accounts from Active Directory dialog. Select the domain and search the users. You can limit your search to specific OU's of the domain by clicking the Select OU link and selecting the OU's. You can import the list of users to be modified from CSV format or select the user from 'show All Users' list or Type a user name. From the listed users, select the users to be deleted. Click the Configure Delete Policy link to specify other user related folders ( Roaming profiles,Remote Home folders, etc) that need to be removed during user deletion. Click on Apply to confirm the deletion.
The change summary and the status of the modification can be verified. Roll over the mouse over the Note: 1. Changing the Name format will change the name of the existing user account with all the other properties unaltered. 2. Changing the Logon name and SAM account name may cause duplication, if one by the same name exists. icon to see the attributes in the windows native UI.
ZOHO Corp.
66
ZOHO Corp.
67
ZOHO Corp.
68
ZOHO Corp.
69
ZOHO Corp.
70
ZOHO Corp.
71
ZOHO Corp.
72
The templates thus created will be available in the bulk user creation wizard from where you can select to apply templates for the users. For details on the user attributes, refer to the Microsoft Documentation here and here. Note: 1. To create Mailbox Enabled Users in Exchange 2007, you would require the Exchange Management Console, failing which the legacy Mailbox will be created. 2. For attributes like Logon Name, Display Name, Email, etc., you can choose any of the formats listed in the combo box. The chosen format will be automatically applied when you add users based on this template. 3. When specifying the Local Path for the Home Folder for the users, you can use any LDAP Attributes in the path, which will be replaced during user creation dynamically. For example, a path can be specified as C:\Documents and Settings\%LogonName%, where, %LogonName% will be replaced by the corresponding Logon Name of the user dynamically.
ZOHO Corp.
73
3. Click on the last icon under Action heading, to set that particular template as the default template. 4. To modify the template click the template name or the icon to open the Modify User Template dialog. 5. Modify the attributes as required and click Save Template. Note: The modification to the attributes will not modify the user attributes of the users created prior to modification of the template. This applies to the users created henceforth using this template. User Creation with Advanced Permissions: While creating User template you can assign advanced permissions and share properties, and eventually all the users created with those template will bear those permissions. You will find these advanced permissions available in the following places: Advanced features in User Creation: For Profile path: Profile path specifies a Uniform Naming Convention (UNC) name, such as \\Server\Prof$\%username%, to be the network folder where the user's roaming profile is stored. This way, user's roaming profile is downloaded to whichever workstation he logs onto and it is uploaded back to the server when he logs off. The dollar sign ($) in the Prof$ sharename makes it invisible so that users don't browse it. Configuring the property "Profile path": 1. "Profile path" attribute can be found in the "Account Details" tab of "Create Template" wizard. 2. While specifying profile path click on 'Permissions' adjacent to it, this will open a window for profile path settings. 3. check in the box to Create Profile Path Directory before user first login 4. you can add more permissions by selecting the tab 'Permissions' to Add More Permissions'. 5. This leads you to set of options where in you can allow a selected user or group or computer, to have permissions like full control, read attributes, delete etc, over folder and its descendants. 6. Click on Add. 7. Check in the Box below to Inherit from parent the permission entries that apply to child objects.
ZOHO Corp.
74
Note: You can also create profile path for Windows Vista users by suffixing it with '.V2'. Example: Let's say the normal profile path looks like 'C: \Documents and settings\Jim', the Vista profile path will look something like 'C: \Documents and settings\Jim.V2'.
For Home folders: Home folders and My Documents make it easier for an administrator to back up user files and manage user accounts by collecting the user's files in one location. If you assign a home folder to a user, you can store the user's data in a central location on a server, and make backup and recovery of data easier and more reliable. ADManager Plus has provided some special features that helps in quickly configuring these properties for the user. Configuring the property "Home Folder": 1. "Home folder" attribute can be found in the "Account Details" tab of "Create Template" wizard. 2. Click "Connect" and specify a drive letter. 3. In the box nearby, type a path. This path can be any of the following types: 1. Network path, for example: \\server\users\tester 2. You can substitute username for the last subfolder in the path, for example: \\server\users\%username% 3. Where server is the name of the file server housing the home folders, and where users is the shared folder.<> 4. The "%username%" will automatically get expanded to the user's name. ADManager Plus also automatically creates a share of the format "\\server\%username%" and allows you to set the desired permissions for this network folder by clicking on the Permissions link. Enable the check box provided across "Create a New Share" below the "home folder" in order to create a new share folder in the network. For Mailbox Rights: Mailbox rights allows to set permissions on users access to mailboxes. In native active directory you can set mailbox rights only after creating users, but with ADManager Plus you can provide the mail box rights while creating users. Perform the following steps: 1. Set Mailbox rights can be found in the 'Exchange server' tab of 'create template' (ADMgmt-->create user Template). This applies to mailbox enabled users. 2. Click on "set Mailbox rights" 3. View the available permissions and Click on "ADD More permissions" to provide more permissions. 4. Select the operation either 'Allow' or 'Delete', select the object, select the permissions from the available list, select the scope of the operation. 5. Click on 'Add', then you will find the added permission. 6. Click OK.
ZOHO Corp.
75
Enable Live Communications/ Office Communication Server 2007 Support : Select the LCS/OCS server. Specify SIP-URI (Session in Protocol -URI) format The SIP-URI format should be of a valid format. Example; sip: [email protected] Also provide Federation Settings Archiving Settings Remote Control Settings
for the users imported from the CSV file in the template by checking in the respective checkboxes provided across them. Native Active Directory supports enabling Live Communication. ADManager Plus facilitates easily enable and configure of Live Communication settings with the help of templates and by avoiding command line tools.
ZOHO Corp.
76
ZOHO Corp.
77
ZOHO Corp.
78
Enable-Disable Computers
You can Enable/Disable Computers using this option. To change the status of computers, 1. Select the AD Mgmt tab. 2. Click the Enable/Disable Computers link available under Bulk computer Modification. This opens the Enable/Disable Computers dialog. 3. Specify the required options. 4. Select the domain and search the users. You can limit your search to specific OU's of the domain by clicking the Select OU link and selecting the OU's. 5. You can import the list of computers to be modified from CSV format or select a computer from 'Show All Computers' list or Type a Computer Name. 6. From the listed computers, select the computers for changing the status and click Apply. The change summary and the status of the modification can be verified.
ZOHO Corp.
79
ZOHO Corp.
80
ZOHO Corp.
81
Move Computers
You can move computers from one Organizational unit to other. 1. Select the AD Mgmt tab. 2. Click the Move computers link available under Bulk computer Modification. This opens the Move computers to another OU dialog. 3. Specify the required options. 4. Select the domain and search the users. You can limit your search to specific OU's of the domain by clicking the Select OU link and selecting the OU's. 5. You can import the list of computers to be modified from CSV format or select a computer from 'Show All Computers' list or Type a Computer Name. 6. From the listed computers, select the computers and the respective container to move and click Apply. The change summary and the status of the modification can be verified.
ZOHO Corp.
82
ZOHO Corp.
83
Single Group Creation 1. Select the AD Mgmt tab. 2. Click the Create Single Group link under Group Management. This opens the Create Distribution List & Security Group Dialog. 3. Select the domain and specify the Group name, Group scope and Group type in the General section. 4. Specify the Email, Description and Notes in the Description section. 5. Import the members list from a CSV file or select the members in the Members section. 6. Specify the Member Of and Managed By details using the appropriate links that appear next to these text boxes. 7. Specify the container in the Container text field. Use the Change link to modify container details. 8. Enable the checkbox below Container text field, to create an exchange email address. 9. Click on Create Group button to save the details and create the new group. Single Group Modification 1. Select the AD Mgmt tab. 2. Click the Single Group Modification link under Group Management. This opens the Modify Distribution List & Security Group Dialog. 3. Select the domain and the group (along with its Scope and Type) to be modified. 4. Click on the Get Existing Members link to view the users in that group. You can add or remove the members from here. 5. Import the members list from a CSV file or select the members. You can also Remove the existing members from the group. Note: To view the existing members in the group, click on the Get Existing Members list. 6. Click on the Advanced Settings link to update the necessary attributes. Make the changes as needed. 7. Click on the Update Group button to save changes in the Active Directory.
ZOHO Corp.
84
Delete Groups You can delete unwanted or obsolete group accounts from your Active Directory using the Delete Groups feature. Follow the steps given below to complete the process. 1. Select the AD Mgmt tab. 2. Click on the Delete Groups link under Group Management. This opens the Delete Group Accounts from Active Directory dialog. 3. Specify the Domain. Use the Add OUs link to select the OUs. 4. Import the group list from a CSV file or search the group accounts. 5. Click on Apply to update the information in Active directory. Modify Organization Attributes Of Group You can change the group address and organization details, such as Title, Department, Manager, etc., from here. To modify the Windows group organization attributes, 1. Select the AD Mgmt tab. 2. Click the Organization Attributes link available under Group Management. This opens the Modify Organization Attributes of the Groups dialog. 3. Enable and Specify the email, description and notes in the Description section. 4. Specify the Member Of and Managed By fields using the add/edit and change options that are avilable. 5. Select the domain. You can limit your search to specific OU's of the domain by clicking the Select OU link and selecting the OU's. 6. You can import the list of groups to be modified via a CSV format file or serach for a particular group name(s). 7. Select the groups and click on Apply button to save changes. The change summary and the status of the modification can be verified. Move Groups You can move groups to another OU using the Move Groups feature of ADManager Plus. Follow the steps given below to perform this operation: 1. Select the AD Mgmt tab. 2. Click the Move Groups link under Group Management. This opens the Move Groups to another OU dialog. 3. Select the container to which the Group(s) need to be moved. 4. Select the domain and search the groups. You can limit your search to specific OU's of the domain by clicking the Select OU link and selecting the OU's.
ZOHO Corp.
85
5. You can import the list of groups to be modified in a CSV format or also search for specific group names. 6. Select the groups from the list and click Apply. The change summary and the status of the modification can be verified. Modify Exchange Attributes of Group 1. Select the AD Mgmt tab. 2. Click the Exchange Attributes link under Group Management. This opens the Modify Exchange Attributes of the Groups dialog. 3. Specify the choices for update in the Delivery Restrictions section. 4. Select the domain and the group to be modified. You can restrict to specify OUs using the Add OUs link. 5. Import the groups list from a CSV file or specify desired groups using search option. 6. Select the groups and click on the Apply button to update information in the Active directory.
ZOHO Corp.
86
Create Groups in Bulk 1. Select the AD Mgmt tab. 2. Click the Create Bulk Groups link under CSV import. This opens the Create Group page. 3. Select the domain in which the new groups need to be added. 4. Import the groups list from a CSV file and click on Next. 5. 6. 7. 8. Select the Group Type & Scope from the dialog and click OK. Select the container. You can also create a new OU using the Create New OU link. Click on Create Groups button to initiate creation of Groups in bulk. The created groups and their status can be verified.
Modify Groups using CSV 1. Select the AD Mgmt tab. 2. Click the Modify Groups Using CSV link under CSV import. This opens the Modify Groups using CSV dialog. 3. Select the domain containing the groups to be modified. 4. Import the group list from a CSV file using the Import button. 5. Select the Groups that need to be modified. You can also Modify Headers using Change Headers option. 6. Click Update in AD button. 7. Select the attributes from the Select Attributes Dialog. You could also make use of the Match criteria link. 8. Click OK to update the information in Active directory. Sample CSV: sAMAccountName Adam John Peter Lisa Freeman Samuel
ZOHO Corp.
87
ZOHO Corp.
88
ZOHO Corp.
89
ZOHO Corp.
90
Address/Organization Attributes
You can change the contacts' address and organization details, such as Title, Department, Manager, etc., from here. To modify the Windows Contact Address/Organization attributes, 1. Click the Contact Management link in the right pane of the Home page. This opens the Contact Management page. 2. Click the Address/Organization Attributes link under Bulk Contact Management. 3. The Modify Address/Organization Attributes of the Contacts page displays various fields like Title, Department, Company, Manager, Street,City, etc., 4. Use the checkbox to enable the required text field. Enter the new values in the text field. 5. Select the domain and search for contacts. You can limit your search to specific OU's of the domain by clicking the Select OU link. 6. You can import a list of contacts to be modified from a CSV format file or select particular contact(s) using the Enter name(s) to search option. 7. From the listed contacts, select those for which the attributes need to be modified. Click the APPLY button. The change summary and the status of the modification can be verified. icon to see the attributes in the windows native UI. Roll over the mouse over the
ZOHO Corp.
91
Naming Attributes
You can change the contacts' naming details with the help of this feature. To modify the Windows Contact Naming Attributes, 1. Select the AD Mgmt tab. 2. Click the Contact Management link in the left pane to open the Contact Management page. 3. Click the Naming Attributes link under Bulk Contact Management to open Modify Naming Attributes of the Contacts page. 4. Select the Display name format from the list. Use Create your own format link to add a new format of your choice. 5. Modify the Full name format by selecting from the given format list. Caution: Modifying the Full Name Format may cause changes to the existing account. 6. Select the domain and search for contacts. You can limit your search to specific OU's of the domain by clicking the Select OU link. 7. You can import a list of contacts to be modified from a CSV format file or select particular contact(s) using the Enter name(s) to search option. 8. From the listed contacts, select those for which the attributes need to be modified. Click the APPLY button. The change summary and the status of the modification can be verified. icon to see the attributes in the windows native UI. Roll over the mouse over the
ZOHO Corp.
92
Contact Attributes
You can change the contacts' contact details, like phone numbers, email, etc., from here. To modify the Windows Contact Contact attributes, 1. Select the AD Mgmt tab. 2. Click the Contact Management link in the left pane to open the Contact Management page. 3. Click the Contact Attributes link under Bulk Contact Management. 4. The Modify Contact Attributes of the Contacts page displays various fields like Telephone number, E-mail, Web page, Description, Office, Mobile, etc., 5. Use the checkbox to enable the required text field. Enter the new values in the text field. 6. Select the domain and search for contacts. You can limit your search to specific OU's of the domain by clicking the Select OU link. 7. You can import a list of contacts to be modified from a CSV format file or select particular contact(s) using the Enter name(s) to search option. 8. From the listed contacts, select those for which the attributes need to be modified. Click the APPLY button. The change summary and the status of the modification can be verified. icon to see the attributes in the windows native UI. Roll over the mouse over the
ZOHO Corp.
93
ZOHO Corp.
94
Delete Contacts
Obsolete or unwanted contacts and their accounts can be deleted using this option. To perform the deletion follow the below steps: Select the AD Mgmt tab. Click the Delete contacts link available under General Attributes. This opens the Delete Contact Accounts from Active Directory dialog. Select the domain and search the contacts. You can limit your search to specific OU's of the domain by clicking the Select OU link and selecting the OU's. You can import the list of contacts to be modified from CSV format or select the user from 'show All contacts' list or Type a contact name. From the listed contacts, select the contacts to be deleted. Click on Apply to confirm the deletion.
The change summary and the status of the modification can be verified. Roll over the mouse over the icon to see the attributes in the windows native UI.
ZOHO Corp.
95
ZOHO Corp.
96
ZOHO Corp.
97
To modify the SMTP address for Mail Enabled Users, 1. Select the AD Mgmt tab. 2. Click the Modify SMTP link available under Exchange Attributes. This opens the Modify Delivery Restrictions of the Users dialog. 3. Select the user category - Mail Enabled Users, for which you want to set additional email address. 4. Specify the Target Address in the corresponding text field. This field will be hidden in the earlier case when Mailbox enabled users was selected. 5. Specify the Proxy email address by clicking on the Add button. The Add Email Address Format dialog box will appear. 6. Specify the additional email address format in the corresponding text field. Ensure you specify SMTP in upper case for setting the email address as Primary. For the email address to be a secondary address, mention smtp in small case in the format. 7. Click on Add More Format link in the dialog to specify/remove additional email address format. 8. Click OK after specifying the required format.
ZOHO Corp.
98
9. Select the domain and search the users. You can limit your search to specific OU's of the domain by clicking the Select OU link and selecting the OU's. 10. From the listed users, select the users for changing the delivery restrictions and click Apply. The change summary and the status of the modification can be verified. Roll over the mouse over the icon to see the attributes in the windows native UI.
ZOHO Corp.
99
Note: If you grant a user both "Send as" and Send on behalf of permissions, the "Send as" permission overrides the "Send on behalf of" permission.
ZOHO Corp.
100
ZOHO Corp.
101
ZOHO Corp.
102
ZOHO Corp.
103
ZOHO Corp.
104
ZOHO Corp.
105
More granular reports are provided for each of the above. All the reports can be exported to HTML, PDF. XLS, CSV and CSVDE formats.
Report Features
Can generate reports for multiple domains. Ability to generate reports for custom inputs for granularity. Customizable columns by using the Edit Column link available in all the reports. Columnar sorting of reports Ability to print the reports. Using this reports you can export Active Directory Bulk Users (Export All users report to desired format).
ZOHO Corp.
106
General Reports
All Users Users with Empty Attributes Users without managers Manager based users Users in more than one Group Recently Deleted Users Recently Created Users Recently Modified Users Dial-in Allow Access Dial-in Deny Access Users with Logon Script Users without Logon Script
All Users
Provides the details of all the users of the selected domain(s). For the domains to be listed here, you should have added all the domains from the Domain Settings page. How it works: The report is generated by querying the LDAP for all users with the attribute 'objectClass' set to 'user' i.e. 'objectClass=user' To view the report, select the domian(s) and click Generate. You can select a specific OU in each domain to view users in it.
ZOHO Corp.
107
ZOHO Corp.
108
ZOHO Corp.
109
Soon-to-expire User Accounts Account never Expiry Users Smart Card Enabled Users Users with Duplicate Attributes
Disabled Users
Provides the details of the user accounts that are disabled. User accounts can be disabled as a security measure to prevent a particular user from logging on, rather than deleting the user account. How it works:The report is generated by querying the LDAP for all users with the attribute "(userAccountControl = ADS_UF_ACCOUNTDISABLE)" This report is auto-generated everyday at 6.00 AM. To view the disabled user accounts of a different domain, select the domain(s) and click Generate.
ZOHO Corp.
110
Provides the details of the user accounts that will expire within the specified number of days. How it works: The report is generated by querying the LDAP for all users with the attribute "(!(accountExpires=0))(!(accountExpires=never))(!(accountExpires<=CurrentTime))(acc ountExpires<=SpecifiedTime)" To view the report, select the domain(s), specify the number of days, and click Generate.
Logon Reports
Inactive Users Recently Logged on Users Logon Hour Based Report Users Never Logged On Enabled Users Real Last Logon
ZOHO Corp.
111
Inactive Users
Provides details of the users who have not logged on for the past 'n' days. The inactive users are determined based on their last logon time. All the configured domain controllers are scanned for the last logon time to ensure accuracy. However, if any of the DC's could not be contacted while report generation, the data may be incomplete. How it works: The report is generated by querying the LDAP for all users with the attribute "(|(&(objectClass=user)(objectCategory=person)(!lastlogon=*))(&(objectClass=user)(ob jectCategory=person)(lastlogon<=SpecifiedTime)))" This report is auto-generated everyday at 6.00 AM. To view the details for a different period, specify the number of days and click Generate. Note: Users logged on through VPN and users who have not logged out for the specified period will be shown as inactive.
ZOHO Corp.
112
How it works: The report is generated by querying the LDAP for all users with the attribute "(&(objectCategory=person)(objectClass=user)(|(lastlogon=0)(!(lastlogon=*))))" To view the report, select the domain(s) and click Generate.
Enabled users
This report generates the list of all the enabled user accounts in desired domain, to see the results for a specific Organizational Unit click ADD OU's. How it works: The report is generated by querying the LDAP for all users with the attribute "(&(objectCategory=person)(objectClass=user)(!(userAccountControl:1.2.840.113556.1. 4.803:=2)))" To view the report select a domain and click Generate .
Nested Reports
Users in Groups Groups for Users Users not in a Group Members only of Domain User Group
Users in Groups
Provides the details of the users of selected groups. How it works: The report is generated by querying all users and checking whether 'memberOf' value is same as specified Group. To view the report, select the domain and the groups and click Generate.
ZOHO Corp.
113
ZOHO Corp.
114
All Contacts Reports This report provides the list of all Contacts in a domain. How it works: The report is generated by querying the domain for Contact Objects. The LDAP Query associated with this operation is (&(objectCategory=person)(objectClass=contact)). To View the reports, Click on All Contacts under AD Reports. Select the domain Select the OU using ADD OUs link. Click on the Generate button.
Mail Enabled Contacts Report This report provides the list of mail enabled contact objects in the domain. How it works: The report is generated by querying the domain for mail enabled contacts. The LDAP Query associated with this operation is (&(objectCategory=person)(objectClass=contact)(mailnickname=*)(targetAddress=*)) To View the report, Click on All Contacts under AD Reports. Select the domain Select the OU using ADD OUs link. Click on the Generate button.
ZOHO Corp.
115
ZOHO Corp.
116
Change Password at Next Logon: This Prompts the selected users to change their password in their next logon. This helps in having Passwords active and secure. More Actions: This will enable you to change the Attributes settings of the selected user. Clicking on this will lead you to AD Management where in you can select the attribute type and define the new settings by Domain wise. Password Expired Users Report This report provides the list of users whose passwords are expired. How it works: The report is generated by querying the users with userAccountControl flag not set to "Password Never Expires" and attributes (!(pwdLastSet=0))(pwdLastSet<=time based on domain password policy). To View the reports Select the domain, enter the number of days and click generate. Soon-to-expire User Passwords Report This report provides the list of users whose passwords will expire in given n days. How it works: The report is generated by querying the users with userAccountControl flag not set to "Password Never Expires" and attributes (!(pwdLastSet<=time based on domain password policy))(pwdLastSet<=specified time). To View the reports Select the domain, enter the number of days and click generate. Recently Password Changed users Report: This report provides the list of users whose passwords are modified in given n days. How it works: The report is generated by querying the LDAP for attributes (&(!(pwdLastSet=0))(!(pwdLastSet>=specified time))). To View the reports Select the domain, enter the number of days and click generate. Recently Password Unchanged users Report This report provides the list of users whose passwords are not modified in given n days. How it works: The report is generated by querying the LDAP for attributes (&(!(pwdLastSet=0))(pwdLastSet>=specified time)). To View the reports Select the domain, enter the number of days and click generate.
ZOHO Corp.
117
General Reports
Groups without Members Top N Big Group All Groups Managed Groups Unmanaged Groups Group Members
All Groups
Provides the details of all the groups of the given domain. How it works: The report is generated by querying the LDAP for all users with the attribute "(objectcategory=group)". To view the report, select the donaim(s) and click Generate.
Managed Groups
Provides the details of the groups that have managers.
ZOHO Corp.
118
How it works: The report is generated by querying the LDAP for all users with the attribute "(&(objectcategory=group)(managedBy=*)". To view the report, select the domain(s) and click Generate.
Unmanaged Group
Provides the details of the groups that do not have managers. How it works: The report is generated by querying the LDAP for all users with the attribute "(&(objectcategory=group)(!managedBy=*)". To view the report, select the domain(s) and click Generate.
Group Members
Provides the details of the users in the selected Group. How it works: The report is generated by querying the LDAP for all users and check 'memberOf' is specifiedGroup. To view the report, select the domain(s) and click Generate.
Security Groups
Provides the details of the security groups available in the selected domain(s). How it works: The report is generated by querying the LDAP for all groups with grouptype set to security enabled. To view the report for a different domain, click the Create New Report link, select the required domains, and click Generate.
ZOHO Corp.
119
How it works: The report is generated by querying the LDAP to specify the group type of that particular group. This information differentiates distribution groups from security groups. To view the report, select the domain(s) and click Generate.
ZOHO Corp.
120
General Reports
Workstation Computers Domain Controllers OS Based Report Computers Trusted for Delegation Recently Modified Computers Recently Created Computers Recently Deleted Computers Managed Computers Unmanaged Computers
Workstation Computers
Provides the details of the workstations in the domain. All the computers except Servers and Domain Controllers are termed as workstations. This report is autogenerated everyday at 6.00 AM. To view the details for a different domain, select the domain(s) and click Generate.
Domain Controllers
Provides the details of the domain controllers in the domain. This report is autogenerated everyday at 6.00 AM. To view the details for a different domain, select the domain(s) and click Generate.
OS Based Report
Provides the details of the computers based on the operating system versions. To view the report, select the domain(s), select the OS version, and click Generate.
ZOHO Corp.
121
Managed Computers
Provides the details of the computer objects that are managed by any of the domain users. To view the report, select the domain(s) and click Generate.
Unmanaged Computers
Provides the details of the computer objects that are not managed by the domain users. To view the report, select the domain(s) and click Generate.
Inactive Computers
ZOHO Corp.
122
Provides the details of the inactive computers for the specified number of days. The inactive computers are determined based on their last logon time. All the configured domain controllers are scanned for the last logon time to ensure accuracy. However, if any of the DCs could not be contacted while report generation, the data may be incomplete. This report is auto-generated everyday at 6.00 AM. To view the details for a different period, specify the number of days and click Generate.
Disabled Computers
Provides the details of the computer objects that are disabled in the domain. Disabling computer account breaks that computer's connection with the domain and that computer will not be able to authenticate to the domain. This report is auto-generated everyday at 6.00 AM. To view the details for a different domain, select the domain(s) and click Generate.
ZOHO Corp.
123
General Reports
Mail-Box Enabled Users Mail Enabled Users Mail Enabled Groups Users with Email Proxy Enabled Groups with Email Proxy Enabled
ZOHO Corp.
124
Distribution Lists
Distribution List Members Non-Distribution List Members
ZOHO Corp.
125
MailBox Size Limits Users Hidden From Exchange Address Lists Accept Messages From Everyone Accept Messages Restricted Users Mail Forwaded To
ZOHO Corp.
126
ZOHO Corp.
127
How it works:ADMP retrieves the value from LDAP attribute unauthOrig and authoring set to a value. To view the report, select the domain(s) and click Generate.
ZOHO Corp.
128
ZOHO Corp.
129
Users with Terminal Services Properties This report provides the list of all users in a domain with their respective terminal services properties. How it works: The report is generated by querying(LDAP) the domain for Users and their assciated Terminal Services properties. To View the reports, Click on Terminal Services Reports under AD Reports. Select the domain. Select the OU using ADD OUs link. Click on the Generate button.
Users with Terminal Server Access This report provides the list of users in a domain, having 'Terminal Server' Access. How it works: The report is generated by querying the domain for users with "allow logon to terminal server access" attribute enabled. To View the report, Click on All Contacts under AD Reports. Select the domain. Select the OU using ADD OUs link. Click on the Generate button.
ZOHO Corp.
130
ZOHO Corp.
131
To view the report, select the domain, enter the number of days and click Generate.
ZOHO Corp.
132
ZOHO Corp.
133
All OU
This provides the list of all Organizational units present in a selected Domain. How it works: The report is generated by querying the LDAP for attribute objectClass set to organizationalUnit i.e. objectClass=organizationalUnit To view the report, select the domain(s) and click Generate.
Empty OU
This provides the list of all empty Organizational units in a selected Domain. How it works: The report is generated by querying the LDAP for all OU's and check for child objects. To view the report, select the domain(s) and click Generate.
Users only OU
This provides the list of all Organizational units that contain only users in a selected Domain. How it works: The report is generated by querying the LDAP for all OU's and check for user objects. To view the report, select the domain(s) and click Generate.
Computers only OU
This provides the list of all Organizational units that contain only computers in a selected Domain. How it works: The report is generated by querying the LDAP for all OU's and check for computer objects.
ZOHO Corp.
134
Recently created OU
This provides the list of all Organizational units that were created in past n days in a selected Domain. How it works: The report is generated by querying the LDAP for attribute createTimeStamp set to greater than equal to specified time i.e. createTimeStamp>=specifiedtime. To view the report, select the domain(s), enter the number of days and click Generate.
Recently modified OU
This provides the list of all Organizational units that are modified in past ‘n’ days in a selected Domain. How it works: The report is generated by querying the LDAP for attribute modifyTimeStamp greater than or equal to specifiedtime i.e. modifyTimeStamp>=specifiedtime. To view the report, select the domain(s), enter the number of days and click Generate.
GPO Linked OU
This provides the list of all Group Policy Objects that are linked to an Organizational unit in a selected Domain. How it works: The report is generated by querying the LDAP for attribute gPo Link set equal to any gPo i.e. gPLink=anygpo. To view the report, select the domain(s) and click Generate.
ZOHO Corp.
135
ZOHO Corp.
136
Non-Inheritable Folders/Files
Provides the list of all folders and files that are restricted to inherit the permissions from their parent objects. To View the Report: 1. Enter the directory path 2. Click on Generate button
ZOHO Corp.
137
AD Objects accessible by Accounts This report is used to view the Active Directory objects that are accessible by Users/Groups specified. To view the report: 1. 2. 3. 4. Select domain. Select OUs if needed. Select the accounts.(More than one account can be selected) Select Access Type Click on Generate button
Non-Inheritable Objects This report is used to view the non-inheritable objects in the selected domain(s). To view the report: 1. Select domain. Add OUs if needed 2. Click on Generate button Subnets accessible by Accounts This report can be used to list all the subnets that can be accessed by the specified Users/Groups. To view the report: 1. Select domain 2. Select Accounts ( You can select more than one Account) 3. Click on Generate button Servers accessible by Accounts Generate this report to list the servers that can be accessed by the specified Users/Groups. To view this report: 1. Select Domain 2. Select Accounts (You can select more than one Account)
ZOHO Corp.
138
Subnet Permissions Generate this report to list the Users/Groups that have access to the given subnets. To view this report: 1. 2. 3. Select Domain Select Subnets (You can choose more than one Subnet) Click on Generate button
Server Permissions Generate this report to list the Users/Groups that have access to the given servers. To view Report: 1. 2. 3. Select Domain Select Computers ( You can select more than one computer) Click on Generate button
ZOHO Corp.
139
Password Policy
Provides the details of the password polices, such as Maximum Password Age, Minimum Password Age, Maximum Password Length, Complexity, and so on, of the selected domain(s). To view the report, select the domain(s) and click Generate.
Printer Reports
Provides the list of Printers for the selected domain(s). To view the report, select the domain(s) and click Generate.
ZOHO Corp.
140
Scheduling Reports
Overview This section would help you to schedule reports and perform effective schedule management. The topics covered are listed below: Scheduling Reports Scheduler Creation Managing Schedules Column Customization in Scheduled Reports
Scheduling Reports You can schedule the reports generation by adhering to the steps mentioned below: Select the AD Reports Tab. Select the Schedule Reports link at the top right corner of the page. Select the Schedule New Reports link at the top right corner to create a new schedule.
Note: You will encounter a Pop up message if the Mail Server is not configured. You can do that using the Configure Mail Server Settings link to proceed further. Specify the Scheduler Name and Description details. Choose the appropriate Domain from the Select Domain list. Click on the Add OUs link, to specify the OUs for the Domain.
Scheduler Creation The Scheduler creation enables you to create a schedule based on the three criteria mentioned below: 1. 2. 3. 4. Select Reports Schedule Duration Select Report Format Email Address to send Reports
1. Select Reports- The Select Reports feature comprises of three sections Click on the Report Type you want to schedule. Select the reports from the Available Reports list. Enter the Input parameter details if asked for. You can view the reports in the Selected Reports list. Use the Remove link to eliminate any report from the selected list.
2. Schedule Duration The time span of report generation can be set based on your requirements. The duration and time can be set with the following options:
ZOHO Corp.
141
Daily-This option is for scheduling a report everyday at a particular time desired by you. Weekly-This option is for scheduling a report at a particular time on a certain day of the week desired by you. Monthly-This option is for scheduling a report on a particular day of the month at a particular time desired by you. Hourly-This option is for scheduling a report generation to be performed on an hourly basis, starting at the specified date and time desired by you.
3. Select the Report Format to be mailed You can select the format in which you would like to have the report mailed. Select the PDF, HTML, CSV, XLS or CSVDE formats, based on your choice. The Storage Path link will enable you to specify the location where you would like the reports to be stored. 4. Email Address to send Reports The email address of the recipient can be mentioned in this field. You can use the Advanced Mail Settings link to receive the Report as an attachement in your email. Select the "Enable Attachment" checkbox to choose amongst the "Send As Files" or "Send as Zip format" options. In case, no choice of format is specified, a report link will be sent in the email, from which the zipped file of the report can be obtained. However, if the "Mail Content: Send link in mail" checkbox is not enabled (left unchecked),the recipient will be inhibited from receiving the link in his mail. The report mails can be sent to Multiple recipients by separating their IDs by comma. Tip: You can use the Send Test Mail option to confirm if the recipient email id is a valid one. Click the SAVE button to add the schedule to the schedule reports list. View Scheduled tasks Click the View Scheduled Tasks link to see the list of tasks you have scheduled.
Enabling/Disabling a Schedule At times, you would require to temporarily stop the generation of a scheduled report and would like to resume it again at some other point of time.
ZOHO Corp.
142
To disable a schedule, Click the AD Reports Tab Click the Schedule Report link to open the Schedule Reports page You will find a list of Scheduled reports on this page. Click on the Enable icon in the Action tab column, appropriate to the Scheduled Report you want to disable. The Enable icon will be replaced by the Disable icon.
To enable a schedule, Click on the Disable icon in the Action tab column, appropriate to the Scheduled Report you want to enable The Disable icon will be replaced by the Enable icon.
Deleting a Schedule When a Schedule is no longer useful, you can delete it from the Schedule Reports list. To delete a schedule, Click the AD Reports Tab Click the Schedule Report link to open the Schedule Reports page You will find a list of Scheduled reports on this page. Click on the Delete icon in the Action tab column, appropriate to the Scheduled Report you want to delete. The deleted Schedule will no longer be listed.
Edit a Schedule You can make changes to the existing schedule as may be required using the Edit option. Follow the steps to edit a schedule: Click the AD Reports Tab Click the Schedule Report link to open the Schedule Reports page You will find a list of Scheduled reports on this page Click on the Edit icon in the Action tab column, appropriate to the Scheduled Report you want update. You can make the changes in the Schedule Reports page. Click on the UPDATE button to save the changes. Click on the View scheduled tasks link to see the updated schedule in the list.
Column Customization in Scheduled Reports(for HelpDesk) HelpDesk Technicians can also schedule report generation depending on the permissions of the HelpDesk Role they belong to. The procedure to schedule report generation is the same as explianed in the previous section. While scheduling the reports, the HelpDesk Technician can also customize the columns that need to appear in the report that is scheduled. So everytime, the schedular runs, the column settings applicable to that particular HelpDesk Technician will be be applied.
ZOHO Corp.
143
Audit Logs
Audit Log is a file/document which records the details of any AD Management task you perform using your AD Manager Plus. The Audit Log is an effective tracking tool which helps in tracing down events like Reset Password, Delete Users, Create/Modify Users, etc., Audit Logs essentially help you to: Identify what accounts are associated with certain tasks. Review chronologically and determine what was happening before and during the AD Management task. Detect problems like investigating casual factors of failed jobs.
Audit Logs can be found under audit-data/audit/technicians/<log folder> of the Program Files of the product. An Audit Log essentially contains the following three basic details of the Task. What When Who
What of the Task Audit Logs store information about the task that was performed while the event got triggered. Details of all those attributes, whose values were updated gets recorded in the Log file for future reference. For example, if a user is moved from one Organizational unit to another using ADManager Plus, the audit log generated will contain the details of the source and destination OUs under the From and To headings respectively. When of the Task Audit files save the Date and Time of Event occurrence. This serves as a useful resource to find out the time of occurrence of a AD Management Task, at a later date. Who of the Task The details of the person who had performed a AD Management task is also tracked in the Audit Log file. If the task was performed by the Administrator, the log is stored in admin under technician folder. For a Help Desk Technician, the logs get stored in a folder named after the Technician and his associated domain. For example, John-ADMP means that this folder contains the logs which got generated while the Help Desk Technician, John initiated AD Management Tasks in the ADMP domain.
ZOHO Corp.
144
ZOHO Corp.
145
10. You can modify Help Desk Role, OUs and also restrict the user to choose from a selected list of templates. 11. Enable Impersonate as Admin option to allocate admin permissions to the user.
ZOHO Corp.
146
Note: 1. The Impersonate as Admin option updates User permissions only in ADMP and retains original settings in AD. 2. You can also set a particular template as Default to allocate roles to the HelpDesk Technicians that are created. The Default template can be selected from the given list under Modify HelpDesk Technician option.
4. Enable the required Domains in the Manageable Domains section 5. You can now assign multiple roles by clicking on choose/change for the corresponding domain. 6. You can modify Help Desk Role, OUs and also restrict the user to choose from a selected list of templates. 7. Enable Impersonate as Admin option to allocate admin permissions to the users. 8. Click Save Changes
ZOHO Corp.
147
2. Select or modify the predefined the help desk roles or create a new help desk role. 3. Define the scope of each operation. Click on the images '+' for granular authorization. 4. All the operations can be restricted to a specific OU. More about OU Restriction
Granular Authorization
Administrator can restrict the help desk technicians function to a specific part of OU or to specific attributes in a function. Example: Help desk technicians can be allowed to modify Group attributes at the same time restricting or avoiding them to any of the sub functions like add to group or remove from group or set primary group.
OU Restriction
All the functions that are being performed by help desk technicians can be restricted to specific OU's. This enhances the security of Active Directory by authorization.
ZOHO Corp.
148
Note:
Select the AD Delegation Tab. Select the Modify User Icon under Action of Help Desk Technicians. This opens the Modify HelpDesk Technician Dialog. Click on Add/Remove buttons adjacent to Included Groups to include the required groups for the HelpDesk Technician. Click on Add/Remove buttons adjacent to Excluded Groups to exclude the required groups for the HelpDesk Technician. Click on Save Changes button to update the changes.
1. If the Included Groups List is alone mentioned, then the HelpDesk Technician permissions only on those mentioned groups. 2. If the Excluded Groups List is alone mentioned, then the HelpDesk Technician will have permissions on all groups except for the ones mentioned. 3. If both Included and Excluded columns contain data, then the ones that are unique with respect to Included List will hold good. 4. In case both the lists are empty, then the groups associated with the delegated OUs will be considered.
ZOHO Corp.
149
4. Select the Active Directory user. Click Browse to select user. The selected user will be eligible to perform the roles defined in next steps. 5. Select the role by clicking on 'choose'. This role will be assigned to the user selected. Be cautious in selecting the role. At a time you can delegate only one role to a user. 6. Select the Organizational Unit. This limits the user's role only to that OU. 7. Save.
ZOHO Corp.
150
The Help Desk Reset Password Console can be used in Web access mode to provide an easy way for Help Desk technicians to provide password resets for individual users. Follow the steps below to Reset Password: Click on the Help Desk Reset Password Console link in the right pane of the Home page to get the Reset Password page. Select the Domain appropriate to the user whose password is to be reset. Enter name of the user in the Search User field and click the GO button. Click RESET PASSWORD button in Action tab, appropriate to the User name. Enter a new Password and also confirm the same. Note: Click User must change the password at next log on check box, if you want the user to change his password when he logs in after the password is reset. Else leave it unchecked. Click on OK button.
Tip:You can filter the viewing options by either selecting the Show All option to view all the users or can simply view the names beginning with a particular alphabet using the Sort By alphabet feature. Click on Help Desk Delegation to know more about this feature.
ZOHO Corp.
151
ZOHO Corp.
152
ZOHO Corp.
153
4. Select the Delegated Roles tab, to view the list of security roles that have been delegated. 5. Select the Non-Delegated Roles tab, to view the list of security roles that have not been delegated.
ZOHO Corp.
154
ZOHO Corp.
155
ZOHO Corp.
156
ZOHO Corp.
157
Admin Settings
Administrator Settings
These settings helps Administrator to customize ADManager Plus to his organizations policies and convenience. You can also configure settings of server, connection and Active Directory Search. The following features are available in Administrator settings: Customize Naming Formats Customize Title & Department Customize Offices & Companies Customize Password Settings Customize LDAP Attributes Customize Delete Policy AD Search Settings Connection Settings Server Settings Mail Server Settings Personalize Settings ServiceDesk Settings
ZOHO Corp.
158
Using this administration can customize the naming template to the organization policies. Follow the following steps: 1. 2. 3. 4. 5. 6. 7. 8. 9. Click on Admin Tab and then on customize naming Format. Click on the +Add New Format. Click on the select data and specify the name with which it should start In the space next to with enter the number of characters you want to choose from name. Click Add to format Continue the process until you arrive at the format value desired. Enable the Select Case checkbox to specify the case (Lower/Upper) in which you want to store the name. Enable the Remove spaces checkbox to avoid unwanted spaces in the name. Save it at the end.
Refer to the following example for a clear understanding. Ex: Suppose a user name is john smith and you want it to be as josmi in directory, for that perform the following steps: Click on the +Add New Format Click on the select data-first name In the space next to with enter 2. Click on the select data-last name In the space next to with enter 3. Click Add to format Save it at the end.
ZOHO Corp.
159
ZOHO Corp.
160
ZOHO Corp.
161
ZOHO Corp.
162
Note: 1.First create a CSV with all the updated information and then start the process. 2.Data Type: Unicode string: Select this data type when the defined attribute or defined by you as a value containing any text like name, role, etc. Integer: Select this data type when the defined attribute or defined by you as a value containing numerical (integer) value with in limits like employee id, phone number, etc. Boolean: Select this data type when the defined attribute or defined by you as a value containing any true or false options values like Dail in Access,Default Storage Limit. Large Integer: Select this data type when the attribute value contains or defined by you as a value containing any lager integer value like last login time,accountExpires etc.
ZOHO Corp.
163
ZOHO Corp.
164
AD Search Settings
You can Configure Active Directory search settings. This Feature enables users search for the information of other users. The operation can be perfomed without user logging into the console. Administrator can configure the People finder more efficiently by appending required information and adding more attributes available in the 'Result column' like phone number, country, address etc. Perform the following steps to configure Search settings. 1. Select the Admin tab. 2. Click the AD search settings. 3. Check in the box configure search. 4. Select the domain. 5. Select the attributes which you want to add to the information of the users. Confirm that the attributes added are reflecting in 'selected attributes' 6. click on 'Save changes'. Note: This feature will be present in the Home page of ADMP console. Users need not login to the console to access to people finder. The user information can be customized to your policy
ZOHO Corp.
165
Connection Settings
You can Change the connection settings using this feature. Perform the following steps 1. Select the Admin tab. 2. Click the Connection settings. 3. Enter the port number 4. Check in the Enable ssl port[https] to enable secure sockets layer and enter the number. Select the session expiry time. 5. Click on save changes.
ZOHO Corp.
166
Server Settings
You can Change Configure ADManager Plus startup & log settings. 1. Select the Admin tab. 2. Click on the Server settings link on the left hand side. 3. Specify the Mail Server, Mail Port and From Address in the corresponding fields. 4. Enable the check boxes based on your personal preferences. 5. Select the Mode for the Current Log Level. 6. Select the Locale Settings of the Computer in which the ADManager Plus needs to be installed.The default working mode is 'Normal' with minimal debugging information. 7. Click on 'Save changes'.
ZOHO Corp.
167
Your Mail Server has been configured and you can now proceed with the Scheduling Reports task.
ZOHO Corp.
168
Personalize Settings
ADManager Plus provides users with the functionality to configure user accounts based on personal priorities and requirements. The Personalize option enables you to change an existing password and a user interface theme.
ZOHO Corp.
169
ServiceDesk Settings
ServiceDesk Plus is a combined HelpDesk & Asset Management software that integrates Trouble Ticketing, Asset Tracking, Purchasing, Contract Management and Knowledge base in one package. ServiceDesk Plus can be installed on any remote machine and can be run from the same machine where ADManager Plus is installed. The below steps will help you configure the server settings and login details to perform the above remote operation. You can Change, update & Configure ServiceDesk Plus settings from here. 1. Select the Admin tab. 2. Click the ServiceDesk settings. 3. Enter the Information. 4. Test connection and save.
ZOHO Corp.
170
ZOHO Corp.
171
ZOHO Corp.
172
ZOHO Corp.
173
Troubleshooting Tips
Domain Settings Active Directory User Management Active Directory Reports Active Directory Delegation
Domain Settings
1. When I start ADManager Plus, none of my domains are discovered. It says "No Domain Configuration available". Why? 2. When I add my domains manually, the Domain Controllers are not resolved. Why? 3. When I add the Domain Controller, I get an error as "The Servers are not operational". What does it mean? 4. When I add the Domain Controller, I get an error as "Unable to get domain DNS / FLAT name". What does it mean? 5. The status column in the domain settings says that the user do not have Admin Privilege? 1. When I start ADManager Plus, none of my domains are discovered. It says "No Domain Configuration available". Why? ADManager Plus, upon starting, discovers the domains from the DNS Server associated with the machine running the product. If no domain details are available in the DNS Server, it shows this message. 2. When I add my domains manually, the Domain Controllers are not resolved. Why? When the DNS associated with the machine running ADManager Plus do not contain the necessary information. You need to add the Domain Controllers manually. 3. When I add the Domain Controller, I get an error as "The Servers are not operational". What does it mean? This error could be due to any of the following reasons: 1. DCs are down. 2. Servers not available. 3. Firewall has been enabled, and port 389 is closed. 4. Busy - try after some time? 4. When I add the Domain Controller, I get an error as "Unable to get domain DNS / FLAT name". What does it mean? This error could be due to any of the following reasons: 1. When the specified user name or the password is invalid. 2. Anonymous login (when no user name and password is provided) 3. When IP Address of the Domain Controller is specified instead of its name.
ZOHO Corp.
174
5. The status column in the domain settings says that the user do not have Admin Privilege? This is a warning message to indicate that the specified user do not have administrator privileges i.e, the user is not a member of Domain Admins Group. Hence permissions applicable to Administrator may not be available to this user.
1. While creating an user, I get the following error "Error in setting the Password. The network path not found - Error Code: 80070035" While setting the password for the user if the target machine could not be contacted, this error is shown. This could happen when the DNS associated with the machine running ADManager Plus does not point to the Domain Controller where the user account has been created (possibly both are in different domains).
ZOHO Corp.
175
2. While creating an user, I get the following error "Error in setting the Password. There is a naming violation - Error Code : 80072037" One possible reason for this error could be creation of a user in an invalid container. 3. While creating/modifying an user, I get the following error "The server is unwilling to process the request - Error Code : 80072035" The possible reasons for this error could be: 1. While setting the password, if the password complexity requirement as defined in the password policy is not met. For example, the password policy might state that the password should be alphanumeric and if the password specified do not comply this, you might get this error. 2. When you try to remove a non-existing user object from a group. 3. When your try to remove a user from his/her primary group. 4. When modifying the SAM Account Name format for multiple users and when more than one user happen to have the same SAM Account Name. 4. While creating an user, I get the following error " Error In Setting Terminal service Properties. The specified user does not exist - Error Code : 525" One possible reason could be that the user or the system account as which the product is run do not have an account in the target domain. Terminal Service properties can only be set if the user account or the system account (applies when ADManager Plus is run as a service) that runs ADManager Plus has an account on the target domain. 5. I have updated the exchange attributes using ADManager Plus, but the properties are not updated in the Exchange Server yet. ADManager Plus modifies the exchange properties in the Active Directory. The changes may not immediately reflect in the Exchange Server. It will get updated after some time. 6. I am not able to set the Terminal Services properties for the user? One possible reason could be that the user or the system as which the product is run do not have an account in that domain. Refer to here for starting ADManager Plus in User or System account. 7. I am getting an error as "The attribute syntax specified to the directory service is invalid - Error Code : 8007200b"? This could happen in the following scenarios: 1. When modifying multiple users, if you try to remove (or making the value as blank) an non-existing attribute 2. When adding a user, if you specify a blank value for an attribute. 8. When I create/modify an user, I get the following error " A device attached to the system is not functioning - Error Code : 8007001f " The possible reasons for this error could be:
ZOHO Corp.
176
1. When creating an user, if the naming attributes, such as Name, Logon Name, SAM Account Name, etc., has some special characters in it. 2. When modifying an user, if an unacceptable format is chosen for the naming attributes. For example, if the format chosen for the Logon Name is LastName.FirstName.Initials and if the user do not have any one of these attributes specified, this error will occur. 9. Email address for user not showing up or not set properly? The possible reason could be: 1. Email may Not be set as per Recipient Policy. check whether all ldap attributes in recipient ploicy query are set to specific value. 2. Check in the user account properties whether you entered the attribute for email. Ex: [email protected]. The company should be entered to the users. 10. Error-The server is unwilling to process the request while setting Password which not maches to password complexity The possible reason could be: You may not have specified or opt for any options in 'Password Complexity' while creating user account. Ex: There will be options for password complexity like length of password, Characters that can be used or number of bad login attempts etc. You need to select any degree of complexity, ignoring so will throw above error. 11. Error code: 8007052e The reason is, the Supplied credentials are invalid. 12. Error code: 80070775 Reason: The referenced account is currently locked out and may not be logged on. 13. Error code: 800708c5 Reason: The password does not meet the password policy requirements. Check the minimum password length, password complexity and password history requirements. 14. 5 -Access is denied (Terminal Service / Folder Creation) Reasons: 1. User does not have rights to create a homefolder. 2. Users do not have access over terminal services. 15.No such user matched. Verify the LDAP attribute in search query Reason: No Users in AD matches with the criteria provided by you.Try choosing the correct matching attributes by checking with the query provided in the "Match criteria for Users in AD",this is obtained by clicking on "Update in AD" button and expanding "Select Attributes" box. 6.Error Code 80072035 : Error In Setting Attributes,The server is unwilling to process the request. Reason: The primary group specfied in User Creation has been moved or deleted.
ZOHO Corp.
177
17.Error Code : 80072030 : Error In Setting Attributes,The server is unwilling to process the request. Reason: The primary group/container specfied in User Template that was selected during User Creation has been moved or deleted. (You are trying create a child object inside an OU, but that parent OU does not exist) 18.Error Code : 80070005 - Access Denied Reason: The User may be trying to access an object to which he has no permissions granted. 19.Error Code : 80072014 - Error In Setting Attributes, The requested operation did not satisfy one or more constraints associated with the class of the object Reason: You may encounter this type of error when the CSV file you are using to import values, does not satisfy the conditions associated with the attribute. 20.Error Code : 80072016 - Error In Setting Attributes, The directory service cannot perform the requested operation on the RDN attribute of an object Reason: You may encounter this type of error if any of the LDAP headers in the CSV file are mentioned inappropriately. 21.Error Code 35 : Error in Creating Terminal Services Home Directory/ Error in Creating Home Directory,The network path was not found. Reason: The remote server path might not be accessible. 22.Error Code: 800704c3 - Error While accessing User in Setting Account Properties. Reason:Multiple connections to a server or shared resource by the same user, using more than one user name, is not allowed. Disconnect all previous connections to the server or shared resource and try again. 23.Error Code b7 : Error in Creating Profile Path Reason: There may be a File/Folder that already exists with the same name.
ZOHO Corp.
178
Domain Controllers in the Domain Settings to enable ADManager Plus to retrieve the data from all the Domain Controllers. 4. When the password policy is not set (i.e., Max Password Age is set to zero), the Password Expired Users report and Soon to Password Expiry users report will not show any data. 5. For time-based reports like inactive users, inactive computers, recently logged on users, etc., the date and time of the machine running ADManager Plus should be in sync with the domain controllers. 2. AD Reports shows an object that do not exist in the Active Directory? This mismatch could occur when the data is not synchronized with the Active Directory. The data synchronization with the Active Directory happens everyday at 1.00 hrs. If ADManager Plus is not running at that time, you can initiate the data synchronization icon of that domain from the Domain Settings. manually by clicking the 3.Error Code : 80070035- Error in getting Shares. The network path was not found Reason - The remote server path might not be accessible.
ZOHO Corp.
179
FAQ
General 1. What is ADManager Plus? 2. What operating systems are supported by ADManager Plus? 3. What is the difference between Free and Professional Editions? 4. ADManager Plus runs in a web browser. Does that mean I can access it from anywhere? 5. How is ADManager Plus licensed? 6. Do I need any prerequisite software to be installed before using ADManager Plus ? 7. Can ADManager Plus work if DCOM is disabled on remote systems? 8. Does ADManager Plus support other than English ? Advanced 1. I want to stop running ADManager Plus during machine boot up, what to do? 2. Can I add Multiple Domains? 3. Can I add domains of different forest? 4. How do i configure child domain details? 5. What does the term default domain mean? 6. How do I change the password of the admin account? 7. What are the advantages of Bulk User Management compared to Active Directory Tools? 8. What is a User Template? What is the advantage of using Template in Bulk User Creation? 9. What are the standards of csv file used for bulk user creation? 10. What are the types of Reports available in ADManager Plus? 11. What is the difference between account disabled users and account locked out users? 12. What is the difference between account disabled users and inactive users? 13. What is the difference between account expired users and password expired users? 14. Is there any customized reports? 15. What is a Security Role? 16. What are the advantages of Delegation through ADManager Plus? 17. What will happen if modify a delegated Security Role? 18. Can I search the ACEs to see what permission is available for a user?
ZOHO Corp.
180
General
1. What is ADManager Plus? ManageEngine AdManager Plus is a 100% web-based product that provides centralized administration and management of Windows Active Directory. You can use ADManager Plus to perform the following: Create bulk user accounts in the Active Directory with the flexibility to import properties from a csv file. Modify the existing user account properties including Exchange Mailbox and Terminal Services properties. Generate and view granular reports of users, computers, groups like Inactive Users, Disabled Users, Users in Nested Groups, Distribution Groups, Security Groups, Inactive Computers, etc. Create and delegate security roles for granting/revoking permissions to security principals. Search ACEs and Active Directory objects.
2. What operating systems are supported by ADManager Plus? ADManager Plus support the following Windows operating systems: Windows 2000. Windows XP. Windows 2003. Windows Vista.
3. What is the difference between Free and Professional Editions? The free edition of ADManager Plus can be used to manage up to 100 objects in a single domain and cannot have more than one domain configured. The professional edition can be used to manage the number of domains and objects for which it is licensed for. The free edition can be upgraded to professional edition at any point of time by obtaining a valid license from ZOHO Corp. 4. ADManager Plus runs in a web browser. Does that mean I can access it from anywhere? Yes, you can connect to the ADManager Plus from any machine on the network through a Web browser. 5. How is ADManager Plus licensed? ADManager Plus is licensed on annual subscription based on the number of Domains t would manage. 6. Do I need any prerequisite software to be installed before using ADManager Plus ? No, ADManager Plus do not require any prerequisite software to be installed.
ZOHO Corp.
181
7. Can ADManager Plus work if DCOM is disabled on remote systems? Yes, ADManager Plus does not use the DCOM service to perform the tasks. 8. Does ADManager Plus support other than English ? No. The support for languages other than English is yet to be added.
Advanced
1. I want to stop running ADManager Plus during machine boot up, what to do? To make ADManager Plus not to start during system bootup, 1. Click the Personalize link from the top right of the ADManager Plus client. 2. Clear the option "Start the product automatically on machine bootup" 3. Click Save Changes. 2. Can I add Multiple Domains? During startup, ADManager Plus adds all the domains that it could resolve. You can also add Domains manually by clicking the Domain Settings link from the client. 3. Can I add domains of different forests? Yes, you can add domains belonging to different forests. 4. How do i configure child domain details? The procedure for adding child domains is no different from adding other domains. Click the Domain Settings link can add the domains. 5. What does the term default domain mean? Default domain is a term used to represent the domain for which the delegation of security roles can be made. If you want to delegate the roles to the security principals of a different domain, you have to make it as default domain and then delegate. 6. How do I change the password of the admin account? To change the password, 1. Click the Personalize link from the top right of the ADManager Plus client. 2. Specify the old and new password. 3. Click Save Changes. 7. What is the advantages of Bulk User Management compared to Active Directory tools? The following are the advantages over Active Directory tools: 1. Can create multiple users simultaneously. 2. Can modify all the properties including Exchange and Terminal Services properties for multiple users.
ZOHO Corp.
182
3. Web-based management. 8. What is a User Template? What is the advantage of using a Template in Bulk User Creation? A user template contains the values of the user attributes defined in it. When you want to create user accounts with similar privileges and permissions, you can create a template with the common attributes and just change the values that differ, say the logon name, display name, etc. This save your time and avoid any possible errors. 9. What are standards of csv file used for bulk user creation? The first line in the csv file should contain the attribute names as defined in the Active Directory. Enter the attribute values for each user in separate lines in the same order. If you do not wish to specify the value for an attribute, just put a comma and proceed. Sample CSV file. 10. What are the types of Reports available in ADManager Plus? There are 100+ different reports about the Active Directory infrastructure components grouped under User, Computer, Groups, and Security Reports. For more details refer to Active Directory Reports. 11. What is the difference between account disabled users and account locked out users? The user accounts that are disabled by the administrator is termed as account disabled users. The account locked out users are those accounts that are locked by the Active Directory based on a policy, for example, three continuous failed login attempts would disable login for certain period. This is a temporary period during which the user will not be able to logon. 12. What is the difference between account disabled users and inactive users? The user accounts that are disabled by the administrator is termed as account disabled users. They do not have login permissions in the domain. Inactive users are those who have login permissions in the domain, but have not logged on to the domain for the specified period. 13. What is the difference between account expired users and password expired users? The account expired users are those whose user account has become invalid. This may happen in cases where a temporary account is created for a specific period beyond which the account expires. The Password expired users are those who are not able to use their account as the password has expired. As a security policy, the users might require to change the password within a specified period after which they may not be able to login using their old password. The password has to be reset for the user to login again. 14. Is there any customized reports? Yes, you can customize the reports based on the criteria available for all the reports. For example, to view the inactive users for a specified period, you can specify the period and generate. Also, you can customize the columns in the report.
ZOHO Corp.
183
15. What is a Security Role? Security roles are those you define for granting/revoking specific permissions. For example, you can define a role to grant permissions for creating a user. This can then be delegated to the security principals for granting the permissions. 16. What are the advantages of Delegation through ADManager Plus? The following are the advantages: 1. Minimises the error when granting/revoking same permissions for different users. 2. Modifying a security role automatically delegates the permissions for the previously delegated objects as well. 3. Can create as many roles as required and can be delegated as and when required. 4. Web-based. 17. What will happen if modify a delegated Security Role? When you modify the delegated security role, it gets automatically delegated for the previously delegated objects. 18. Can I search the ACEs to see what permission is available for a user? Yes, you can search the permissions granted to security principals, such as users, groups, and computers. You can even include the active directory object, security principal, and the permissions in the search criteria to confine your search.
ZOHO Corp.
184
Limitations
1. Inability to delete shared home folders, while deleting Users. 2. Custom Script execution while User Creation is limited to three seconds. 3. Need for a separate Exchange Management Console to create User Mailbox in Exchange 2007. 4. Inability to schedule "Real last logon" , "Logon hour report" and all reports under the Other Reports category.
ZOHO Corp.
185
Thus it helps in a large scale to eliminate a leading source of help desk calls and associated expenses by automating password resets and account unlocks thereby optimizing employee productivity. To know more about ADSelfService Plus, visit our website url: http://www.adselfserviceplus.com
ZOHO Corp.
186