Use-case 23: How To Manage Employee Logon Restriction To Avoid Unrestricted Access To Your Active Directory.
Restricting employee logon access may be trivial. However, to any admin who believes his Active Directory holds a cove of resources, this can go a long way. Some advantages of implementing a business hour based logon are, 1. Primarily, restricting logon during non-business hours as this would prevent unauthorized or unmonitored logon. 2. Less likely chances of expecting an attack as "gaining access" to any resource is out of the question. 3. Ensuring productivity as the employee as they would have
Configuration
Hi, Is it possible to amend the : Inside ADManager Plus ADManager Plus has a stream of tools to manage Active Directory from anywhere. ....that appears on the right side of the Home page? A
displayNamePrintable attribute in User Creation Template
Hello, I need the ability to have the displayNamePrintable attribute in my user creation template. I've added a custom attribute but what I need is for displayNamePrintable to be the same as displayname so ideally I'd like the field type to be 'Naming Format' but the only options I have on the custom attribute when I add it to the template are' Single Line, Editable Dropdown, Dropdown and Date Picker. How can I make the custom attribute displaynamePrintable default to 'First Name Last Name? Thanks
Custom LDAP Attributes
Hi, We have added a custom attribute for proxyAddresses to capture the addtional e-mail addresses for our Distribution groups. For some reason this is only picking up a single entry. We have around 3 proxy addresses for each distribution mailbox group on AD, so do you know why this is only picking up 1 of them ? A
list of groups and their members
Hello all, I need to generate the following reports 1- list of groups and their members. 2- list of users, and what groups are each in. the reports built in, actually mix the whole users selected, as one, and mix them all together.
Recommended methods / practices for updating Title, Department, etc?
i am curious as to what users are doing or developers recommend in terms of updating employees' Titles and departments. How is this best done through ADManager when automating? Would you simply have a csv export from the HR database with employeeNumber and Title? And how can you automate matching the users in AD based on that attribute or based on other attributes in order to update those types of other attributes?
Powershell debugging
Anyone know how to get debug information when running custom script? I have a script to run when a user is disabled that, if they manage and other users, re-assigned those users to the manager of the now disabled user, and then sends the new mamager an email. The user gets disabled OK, the process says the script ran OK, but the manager does not get changed and the email does not get sent. Any ideas? Mark Ashley Weston College
Default Description to Current Date
I am creating a template in ADManager to use when I disable users. In my template I want the value for the Description field to the current date and my initials so I know I disabled this person on this date. Is there a way to put the current date in the the field without having to manually typing it in every time?
Use-case 3: How To Standardize The Format Of Names In Various Active Directory Naming Fields While Provisioning User Accounts
A user provisioning technique that standardizes the format in attributes like sAMAccountName and userPrincipalName throughout the organization can be of help. You can link a naming format with a User Creation Template, that takes inputs from fields like first name, last name, etc. and populate the format for fields like sAMAccountName, userPrincipalName, mail, etc. A simple approach on provisioning users with this technique follows, Step 1: To create a naming format, let say "1st letter of the
O365 Account Creation
Hi I have a separate server that runs Azure AD Connect. With ADManager Plus being on a separate server, how do I configure it when creating accounts to also make sure the user is put into O365? This may not be necessary since their account would be getting sync'd to O365 via Azure AD Connect automatically (usually within a few minutes). But, how is it supposed to work if using Azure AD Management only? You would need Azure AD Connect installed locally on the server, and it would just kick off
Password attribute and best practice question
Hi I noticed %password% for user accounts can be used in areas, such as the new account creation with custom script (passed as an argument). Where does the %password% variable source from? Is there an encrypted database within ADManager where user password are stored? Is it all passwords or just the ones that are created? Also on a different note, what's your recommended ways of communicating the first time sign in AD password to a new-hire in your company? Would you print it out onto paper for
Use-case 17: Securing Employee Accounts In Your Active Directory When They Are On A Holiday
Ah! The bliss of the holidays. The sense of freedom and the time when you ask yourself, "Is it a beach or a mountain?!". But, when you are on a holiday and have no track of your Active Directory account, your account is prone to be cracked and misused. As an IT Admin, the best way to handle employees, that are on vacation, is by disabling the account and sending an out-of-office email. Through the Disable Policy in ADManager Plus, you can disable the account --> move it to an OU (Holiday Employees)
Use-case 16: How To Manage Contract Employees In Your Active Directory
Contract employees are similar to your conventional employees. But what is the big fuss all about?! Your full time employees don't come with an expiry date. So what are the advantages of having an expiry date? 1. Expired account become unusable at a specific time, like a disabled user(the user account is not disabled when the account expires). 2. This is more or less like an automation provided by Microsoft to disable users. 3. Really handy, just in case you forget to disable the account once the
Locked Out Users
Hi, We have setup the AD Manager to report of when users Lockout their Domain accounts, is there any way to find out which PC\Server this lockout was actioned against within AD Manager ? Obviously we could view the logs on the servers but just checking to see if there are any options that don't require buying another product :-) Any ideas would be appreciated. Andrew
Share Permission Enumeration
Enumeration of the share & NTFS permissions on a per server basis Andrew Bray
server share report
how can I run the same report repeatedly if its not available in the schedule report?
Scheduled NTFS reports
Is there a way top run a schedules NTFS report? I am not being able to find the option under Report Type in the Schedule Report screen. Thank you very much. Luis
Company info for templates
I wasn't sure whether to post this under idea or question because I'm not sure if I'm just missing something here or if it's just not possible currently. I work for a mid-sized bank that has around 100 locations. Each location has a teller, CSR, Branch Manager, Asst. BM and loan people. We are having issues with admins creating accounts in AD and inputting things slightly different, for instance one will abbreviate Street while another will type it all out. This causes issues when we try to do
User Modification Templates functionality built into User Creation Templates?
The User Modification Templates are nice, but I would like to see the auto-fill rules available in the User Creation Templates. It seems more appropriate to be in the creation side anyway. I work in a large organization with dozens of different office locations, so it would be nice to setup a new user template, and when a specific office is selected it auto-fills the address information. Otherwise, I have to create a couple dozen different templates, or have my helpdesk copy/paste the info into
Use-case 1: Provisioning User Accounts For New Employees With The Same Department In The Active Directory Easily
Any organization would love to provision user accounts, with a few clicks, for new joinee's in a department. All accounts may differ with name but have a similar value on department, title, company, etc. Through User Creation Templates in ADManager Plus, you can pre-fill AD fields available on the UI and efficiently utilize them during creation. Step 1: Kindly go to AD Mgmt --> User Management --> User templates --> User Creation templates. Step 2: Click on Create New Template. Step 3: Create a new
ADManager Plus rolls out build 6380
ADManager Plus build 6380 (June 2016) We are delighted to announce the release of ADManager Plus 6380 build with PPM. Please find the new feature,enhancements and fixes included in this build, New Features: Move contacts: You can now move contact objects from one container (organizational unit) to another. As per your need, you can: - Move a single contact. - Move multiple contacts at a time. - Use CSV import to move contacts in bulk. Copy schedule: This feature simplifies the creation of
How can we view the custom script result status in ADManager plus.
I have a User modification template which trigger a custom script that is a VBS script. When we click "Update user" the script run and does its job fine(Which in this case is to disabled the user and move it to another OU) . But i have error handling in my script and i want to be able to show the technician a confirmation that everything goes fine or if the script failed in some point if for whatever reason it happen. AD Manager seems to report a failure only when the script does not start at all
How do I delegate distribution list management to HR Role
Hi folks, I'm relatively new to ADManager, and I'd like to be able to delegate distribution list modification to the HR role. How can I go about doing this? Thanks, Adam
Use-case 15: How To Manage Bulk Employee Privilege Allocation During Movement Or Elevation Through Active Directory Groups
Let's say you are planning on a bulk employee move within the organization or an elevation for a good number of users. What are the few question that would be running in your mind? What is the best way to provide these bunch of users permission over an application, resource, etc.? What is the easiest way to send emails to these recipients, rather than sending it individually? What is the best and the easiest way to revoke permissions over an application, resource, etc., and remove recipients from
Integration features for service desk plus
Hi there, Can anyone supply a list/document on all the features available when you integrate AD Manger Plus with ServiceDesk Plus?
Use-case 14: How To Manage Employee Account Changes When Moving To Another Department In Your Active Directory
Do you handle a lot of internal employee movement? Are you looking for pre-defined modification rules based on certain criteria? Do you think templates need to be smarter to dynamically change based on the criteria? You are reading the right post! Through ADManager Plus Modification Rules on templates, you can choose a querying field and add conditions. If the conditions match, the attributes that linked to the conditions change dynamically. Step 1: Kindly go to AD Mgmt --> User Management --> User
Report Automation
Hi, Is there a script that could be used as part of automation to send a report out when an event happens ? I'm trying to figure out if AD Manager can be setup to automatically send a report of all locked out users when any user locks there account as an early warning system...is this possible ? We don't want to automate the unlocking of the account, just to be notified. Any ideas ? A
SIngle/Bulk Modify - match Logon name to E-mail address?
I was wondering if anyone knows how to make it where you can modify users in AD to change their UserPrincipalname to match their Logon name? Would this require a CSV or is there a way to do it built-in or with template?
Is there a report that shows the last user to logon to a computer?
Use-case 13: How Would You Tackle Compromised Employee Account In Your Active Directory
When a crook employee gets hold of crucial employee credentials, your Active Directory can go bogus. Compromised accounts can turn the privileges of your Active Directory upside down and access resources inside out. Identifying compromised accounts is quiet challenging, if you don't have the right tools for the job. Monitoring logon activity, abnormal permission changes and frequent access to key resources can provide some heads-up to trailing a compromised account. With ADAudit Plus, speculating such
Report Share with permission nested groups
Hello, I am new to ADManager Plus. How can I make a report about share (not ntfs) permissions with nested groups (with listed users) AND export that as a CSV document? I always get a list with groups and then I have to click on permissions? Thats not what i want! We need that share report for recertification and audit! So, is there an easy way to perform that with ADManager Plus?
Multiple Google Apps Domains?
I'm looking at purchasing ADManager Plus specifically for the Google Apps account provisioning feature. In our case we have one Active Directory domain (which syncs passwords using ADSelfService Plus) and several Google Apps domains. I want to know if ADManager Plus can provision in multiple Google Apps domains based on the OU where the account is created. For instance... If I create a new user in AD in an OU named "Example A" I want ADManager to provision an account in Google Apps domain ExampleA.com
ADManager Plus + ServiceDesk Plus Tight Integration
Hi all, I've installed ADManager Plus and ServiceDesk Plus and was trying to see what level of integration they had. I've found the location in the admin menu in ADManager Plus to put the server details in for the ServiceDesk Plus and I've checked the box labeled 'Tight integration', put some credentials in, and it reports it was successful. I've also found the ME Other Products tab in SDP and put in the ADManager Plus server info in (they are on the same server - two different ports). Now the hyper
How can I remove multiple Departments in ADManager - Admin - Titles & Departments?
Hello, How can I remove multiple Departments in ADManager - Admin - Titles & Departments? I tried selecting multiple entries but it ends up deleting only one. Please advise. Thanks in advance. Nikhil
Use-case 7: How To Provision Exchange Mailbox, Skype For Business And O365 Accounts While Provisioning The Active Directory User Accounts For Employees
When a new employee joins the organization, you will have to create the user account and possibly other accounts like, a mailbox for the user, a Skype for business account and an O365 account. Now, this is just for one account. Imagine you are on a bulk new employee account provisioning spree. Envision all the tedious work of creating each accounts, separately, in each of those modules, for each of these newbies. Remember about the bulk employee provisioning spree on my earlier lines... huff!! User
Problems and errors gettign full use of the ADMANAGER PLUS app on both iPhone and Droid Phones
I have ADMANAGER Plus installed on my domain and from the web portal it works fine and without issue, However when I try to use the App (either with the internal or external IP address I get only partially function and errors. This is replicable on HTC One M9 (droid) and iPhone 6 and 6s Issue description: Once the installed on the device I can enter either our internal or external address for this function along with the appropriate port and hit save. The server name is verified and it jumps to
Use-case 6: How About Pre-staging Users In Active Directory?!
We all know about pre-staging computers. How about pre-staging users accounts for employees that are likely to join in a while? On the User Creation Templates, you can disable the user account while creating accounts. Once the employee joins, you can enable the user account on will. Step 1: Kindly go to AD Mgmt --> User Management --> User Creation Templates. Step 2: Click on Create New Template. Step 3: Kindly fill the information pertaining to user creation on the templates and also, check "Account
Removing Local Admin Rights
I'm in an environment where a legacy program that required local admin rights has gone away and I'm looking for the best way to remove local admin rights my users have to their pc's. We have close to 300 machine and in lieu of going machine to machine, I was hoping ADManager or another ME tool could assist me.
Use-case 5: How To Provision User Accounts With a Single CSV file For Employees If Your Business Handles Multiple Domains
Is your organization managing multiple domains? Would user provisioning on all the domains, for a single user, take forever? You can create User Creation Templates based on domains, then run a simple CSV file with minimal user information against the templates and provision accounts in all domains with just a few clicks. Steps 1: Kindly create a simple CSV file with minimal information on the employees. Step 2: Go to AD Mgmt --> User Management --> Bulk User Management --> User Creation templates.
Use-case 4: How To Bulk Move Employees To Different Organizational Units In The Active Directory
Is your organization planning on a bulk employee move to other departments? Are you in search of a solution that can help you handle the move with ease? With a simple CSV file that contains the sAMAccountName of the users and their respective destination OU in the distinguished name format, the move is easy as cake. Now, let's move some users to OUs based on their regions, shall we?! Step 1: Kindly create a simple CSV file with two header, sAMAccountName and ouName. "sAMAccountName" list all the
Next Page