<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-2619413889279683124</id><updated>2011-10-11T01:07:08.379-07:00</updated><category term='Windows Server 2003 Administration Tools Pack'/><category term='True Last-Logon Reporting'/><category term='Security Permissions Reports'/><category term='Account Lockout'/><category term='Gold Finger'/><category term='Cmdlets'/><category term='dsac.exe'/><category term='dsrevoke'/><category term='Powershell'/><category term='AD Reporting'/><category term='LDAP Filters'/><category term='MMC'/><category term='ALOInfo.exe'/><category term='Active Directory Reporting'/><category term='permission analyzer'/><category term='Windows PowerShell'/><category term='Active Directory Users and Computers'/><category term='Account Lockout and Management Tools'/><category term='Active Directory Reports'/><category term='LockoutStatus.exe'/><category term='Active Directory Administrative Center'/><category term='active directory resultant permissions'/><category term='ADUC'/><category term='Active Directory Audit'/><category term='Account Lockout Status'/><category term='ALOInfo'/><category term='Free Active Directory Reporting Tools'/><category term='AdFind'/><category term='dsacls'/><category term='Windows 2000 Support Tools'/><category term='Delegation of Control Wizard'/><category term='LDP'/><category term='RSAT'/><category term='Nested Group Memberships'/><category term='DACL'/><category term='security explorer'/><category term='access manager'/><category term='active directory resultant access'/><category term='AD LDS'/><title type='text'>Useful Microsoft Active Directory Tools</title><subtitle type='html'>Helpful Information on Useful Management and Reporting Tools for Microsoft Active Directory</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.ad-active-directory-tools.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2619413889279683124/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://www.ad-active-directory-tools.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>MarcJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>12</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2619413889279683124.post-2369336048725753965</id><published>2011-06-13T19:23:00.000-07:00</published><updated>2011-06-13T23:16:44.234-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security explorer'/><category scheme='http://www.blogger.com/atom/ns#' term='active directory resultant permissions'/><category scheme='http://www.blogger.com/atom/ns#' term='access manager'/><category scheme='http://www.blogger.com/atom/ns#' term='active directory resultant access'/><category scheme='http://www.blogger.com/atom/ns#' term='Active Directory Audit'/><category scheme='http://www.blogger.com/atom/ns#' term='permission analyzer'/><category scheme='http://www.blogger.com/atom/ns#' term='Gold Finger'/><category scheme='http://www.blogger.com/atom/ns#' term='Active Directory Reports'/><title type='text'>Gold Finger 4.0 - A Must-Have for Active Directory</title><content type='html'>&lt;span style="color: #666666;"&gt;A while back I had blogged about the Gold Finger reporting solution for Active Directory. I had also provided some feedback to the vendor and last month, I received an email informing me that my feedback had been incorporated in the latest version, &lt;strong&gt;v4.0&lt;/strong&gt;. I was also invited to review the Pro Edition, so I did, and I have to say that I am very impressed.&lt;/span&gt;&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;Gold Finger 4.0 is a Must-have Tool for Active Directory Reporting and Audit. &lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-9M1QVoxQ7O0/TfaCFYMplmI/AAAAAAAAAD4/_Ex7IPjDDbY/s1600/Gold_Finger_4.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-9M1QVoxQ7O0/TfaCFYMplmI/AAAAAAAAAD4/_Ex7IPjDDbY/s1600/Gold_Finger_4.jpg" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;strong&gt;Gold Finger 4.0&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;strong&gt;Here's why - &lt;/strong&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="color: #990000;"&gt;What is the single most important thing one absolutely needs to know in Active Directory?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;I believe that one thing is the need to know who &lt;strong&gt;really&lt;/strong&gt; has what access in Active Directory, because all accounts, passwords, groups, policies etc. are stored and managed in AD, so we must know &lt;strong&gt;exactly&lt;/strong&gt; who can perform which admin tasks (e.g. &lt;em&gt;Password Resets&lt;/em&gt;) on which objects in Active Directory at all times.&lt;br /&gt;&lt;br /&gt;For instance, at an absolute minimum, I think we all need to know &lt;strong&gt;exactly&lt;/strong&gt; who can - &lt;br /&gt;&lt;ol&gt;&lt;li&gt;Change the membership of the Domain Admins&amp;nbsp;and Enterprise Admins group&lt;/li&gt;&lt;li&gt;Reset the password of the user account of all admin and executive accounts&lt;/li&gt;&lt;li&gt;Delegate administrative tasks in our core OUs to someone else, etc. etc. &lt;/li&gt;&lt;/ol&gt;Of course one also needs to have basic but essential security insight such as - &lt;br /&gt;&lt;ol&gt;&lt;li&gt;How many accounts do we have and in what states (active, disabled, locked, etc.)&lt;/li&gt;&lt;li&gt;How many groups we have and what are their memberships (direct, nested etc.)&lt;/li&gt;&lt;li&gt;How many OUs and containers do we have, what are their contents etc. &lt;/li&gt;&lt;/ol&gt;&lt;span style="color: #990000;"&gt;&lt;strong&gt;But &lt;/strong&gt;the need to know who can do what is far more important, because if say someone could reset a Domain Admin's password, he/she could logon as a Domain Admin and take control of the entire AD!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;strong&gt;Finding out who has REALLY what access in Active Directory - &lt;/strong&gt;&lt;/div&gt;&lt;br /&gt;In that regard, I recently learnt that there is a HUGE difference between determining &lt;em&gt;who has what access &lt;/em&gt;in Active Directory and determining &lt;em&gt;who has what &lt;u&gt;effective/resultant&lt;/u&gt; access&lt;/em&gt;&lt;strong&gt; &lt;/strong&gt;in Active Directory. &lt;br /&gt;&lt;br /&gt;Simply put, it is the difference between finding out where all a user has permissions in AD and finding out what the users' &lt;strong&gt;effective&lt;/strong&gt; permissions are (also known as resultant-set of permissions) in AD.&amp;nbsp; (You may have seen the &lt;em&gt;Effective Permissions Tab&lt;/em&gt; in the ACL Editor, which unfortunately Microsoft has acknowledged to be inaccurate.)&lt;br /&gt;&lt;br /&gt;It turns out that determining a user's &lt;em&gt;&lt;u&gt;effective/resultant&lt;/u&gt; access&lt;/em&gt;&lt;strong&gt; &lt;/strong&gt;in AD is in fact very difficult, because to do so, one needs to consider ALL permissions in an object's ACL&amp;nbsp;just like AD does in a real access check.&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="color: #999999; font-size: x-small;"&gt;For example, all this while I assumed that since I have &lt;em&gt;Write Property &lt;/em&gt;permissions on the &lt;em&gt;member &lt;/em&gt;attribute on the Domain&amp;nbsp;Admins&amp;nbsp;Group, I could change the Domain Admins group membership. It &amp;nbsp;turns out that this is not actually true, because as I learnt recently, if there is even 1 &lt;em&gt;Deny &lt;/em&gt;permission for some group that denies &lt;em&gt;write-property &lt;/em&gt;to the &lt;em&gt;member &lt;/em&gt;property, or blanket write-property, or full-control, and I happen to be a member of that group, directly/indirectly, then I will not be able to actually change the Domain Admins group.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;In short, I discovered that to find out who can really do what in Active Directory,&amp;nbsp;I need to determine resultant-access / resultant-set-of-permissions (RSOP) in Active Directory, and having tried to do so, I can tell you that it is very difficult to do so. &lt;br /&gt;&lt;br /&gt;If you would like to learn more about this, you can Google "&lt;em&gt;Active Directory Resultant Access&lt;/em&gt;".&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;strong&gt;Why I believe Gold Finger is unique - &lt;/strong&gt;&lt;/div&gt;&lt;br /&gt;It is in this regard that Gold Finger 4.0&amp;nbsp;comes&amp;nbsp;in the picture. &lt;br /&gt;&lt;br /&gt;Based on my research, I have found that Gold Finger 4.0 is the only reporting tool for Active Directory that can correctly determine resultant-set-of-permissions (RSOP) in Active Directory, and show me who &lt;strong&gt;really &lt;/strong&gt;has what access in my Active Directory, and in 4.0, show me the &lt;strong&gt;how &lt;/strong&gt;as well.&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;Incidentally,&amp;nbsp;it turns out that Gold Finger is designed by former Microsoft Program Manager for Active Directory Security (author of Microsoft's official delegation white paper) and it is endorsed by Microsoft.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;br /&gt;Here's a demo I happened to find on YouTube - &lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;object style="height: 304px; width: 500px;"&gt;&lt;param name="movie" value="http://www.youtube.com/v/Dg39CUx43H4?version=3"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/Dg39CUx43H4?version=3" type="application/x-shockwave-flash" allowfullscreen="true" allowScriptAccess="always" width="500" height="304"&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="font-size: x-small;"&gt;Here's a direct link to the demo on YouTube - &lt;/span&gt;&lt;a href="http://www.youtube.com/watch?v=Dg39CUx43H4"&gt;&lt;span style="font-size: x-small;"&gt;Active Directory Resultant Access Assessment/Reporting Tool&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: x-small;"&gt;. &lt;/span&gt;&lt;/div&gt;&lt;br /&gt;I did extensive research, checked out many tools, ranging from Microsoft's dsget&amp;nbsp;and dsacls to Quest Software's Access Manager, from ScriptLogic's Security Explorer to Manage Engine's AD Manager+. I even checked out dsrazor, Hyena, adfind, and others and I have not found&amp;nbsp;even&amp;nbsp;one other tool that can determine resultant-access in Active Directory.&lt;br /&gt;&lt;br /&gt;I was led to all these above-mentioned tools because they claim to show you who has what access, but as I have learnt now, &lt;strong&gt;there is a world of a difference &lt;/strong&gt;between &lt;em&gt;who has what access &lt;/em&gt;and &lt;em&gt;who has what resultant access&lt;/em&gt;, and none of the above mentioned tools can determine resultant-access. They merely show you the who has what access part leaving us to do ALL the work ourselves.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Speaking of these tools, I should mention that one of the most misleading named tools out there is a tool called &lt;strong&gt;SolarWinds Permissions Analyzer for Active Directory&lt;/strong&gt;. That tool has absolutely NOTHING to do with determining who can do what in Active Directory or analyzing Active Directory permissions.&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;What I found most valuable - &lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;What's really awesome about the Gold Finger is that not only does it tell you in plain English who can &lt;strong&gt;really &lt;/strong&gt;do what in your Active Directory, it actually also shows &lt;strong&gt;exactly&lt;/strong&gt; you how they can do so. &lt;br /&gt;&lt;br /&gt;For instance, during our eval, it helped me uncover exactly which security permission in the ACL (access control list) on my user account was responsible for one of my co-workers having the ability to reset my password. I have found it to be very useful, because not only can I find out &lt;strong&gt;really &lt;/strong&gt;who has what access, it shows me how that person has this access, and that helps me identify and take away that access that I did not even know he had.&lt;br /&gt;&lt;br /&gt;Here is a summary of some of the&amp;nbsp;reports&amp;nbsp;available in Gold Finger&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;I . 100+ Basic security reports:&lt;/strong&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;50 user account mgmt security reports (e.g. account status, last logons etc.)&lt;/li&gt;&lt;li&gt;20 computer account mgmt security reports (e.g. stale accounts, etc.)&lt;/li&gt;&lt;li&gt;15 group mgmt security reports including&amp;nbsp;nested group memberships etc.&lt;/li&gt;&lt;li&gt;10 OU and container account mgmt security reports&lt;/li&gt;&lt;li&gt;30 Group Policy, Trust, Exchange and Schema mgmt reports&lt;/li&gt;&lt;li&gt;18 AD security permission reports (e.g. who has what permissions where)&lt;/li&gt;&lt;/ul&gt;&amp;nbsp;&lt;strong&gt;&lt;span style="color: #38761d;"&gt;+&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;II . 100+ Unique resultant-access reports &lt;/strong&gt;(fully-automated)&lt;strong&gt; :&lt;/strong&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Who can create/delete user accounts, reset passwords, etc.&lt;/li&gt;&lt;li&gt;Who can create/delete computer accounts, change Kerberos settings etc.&lt;/li&gt;&lt;li&gt;Who can create/delete security groups, change memberships, etc.&lt;/li&gt;&lt;li&gt;Who can create/delete OUs and containers, link and unlink GPOs, etc.&lt;/li&gt;&lt;li&gt;Who can create/delete Service Connection Points, modify keywords, etc.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;One other thing I should mention is that they seem to have made quite a few UI enhancements in 4.0. For instance, the UI is now re-sizable, has two skins, and allows instant CSV exports of all reports. It also lets you instantly generate professional looking reports with custom titles and fields.&lt;br /&gt;&lt;br /&gt;We are still in the midst of evaluating because we need to be able to audit our AD at all times, and from what we seen so far,&amp;nbsp;I can tell you that seems like a must-have tool for Active Directory, because we all absolutely need to know who can do what in our AD. &lt;br /&gt;&lt;br /&gt;I highly recommend checking it out if you have a minute. I believe it is available in 4 editions, and I think consultant versions are also available, but I do not know if they have one for their Pro Edition.&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;strong&gt;In Summary &lt;/strong&gt;&lt;/div&gt;&lt;br /&gt;In summary, based on my extensive research thusfar, I have found that with over 100 security reports (that let you do everything from from True Last Logon reproting to finding out who has what permissions where in AD), to 100+ unique, essential&amp;nbsp;(and fully-automated) resultant-access reports (that show&amp;nbsp;who &lt;strong&gt;really &lt;/strong&gt;has&amp;nbsp;what access in Active Directory, and how), all made as simple as clicking a button, Gold Finger 4.0 has to be one of the best AD tools and a must-have tool for Active Directory.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: #666666;"&gt;&lt;span style="color: #cc0000;"&gt;&lt;strong&gt;Disclaimer&amp;nbsp;- &lt;/strong&gt;&lt;/span&gt;This is merely my opinion. Please do NOT take my word for it but rather try it out for yourself. I believe you can download free 21-day evals from their website.&lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;span style="color: #666666;"&gt;Here is the link to the tool - &lt;a href="http://www.paramountdefenses.com/goldfinger"&gt;http://www.paramountdefenses.com/goldfinger&lt;/a&gt;.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: #666666;"&gt;You can also just Google "&lt;em&gt;Gold Finger for Active Directory&lt;/em&gt;"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: #007700;"&gt;&lt;strong&gt;+Pros&lt;/strong&gt;: Resultant-access analysis, Fully-automated accurate resultant-set-of-permissions (RSOP) based access-reporting, Instant Download, Quick Install, No admin permissions needed, Instant reporting, CSV exports, 200+ valuable reports, Custom report generation&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: #cc0000;"&gt;&lt;strong&gt;-Cons&lt;/strong&gt;: Not all editions seem to be available in a Consultant version.&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2619413889279683124-2369336048725753965?l=www.ad-active-directory-tools.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.ad-active-directory-tools.com/feeds/2369336048725753965/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.ad-active-directory-tools.com/2011/06/gold-finger-40-must-have-for-active.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2619413889279683124/posts/default/2369336048725753965'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2619413889279683124/posts/default/2369336048725753965'/><link rel='alternate' type='text/html' href='http://www.ad-active-directory-tools.com/2011/06/gold-finger-40-must-have-for-active.html' title='Gold Finger 4.0 - A Must-Have for Active Directory'/><author><name>MarcJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-9M1QVoxQ7O0/TfaCFYMplmI/AAAAAAAAAD4/_Ex7IPjDDbY/s72-c/Gold_Finger_4.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2619413889279683124.post-7617786919595968336</id><published>2010-11-13T00:42:00.000-08:00</published><updated>2011-06-13T20:09:19.497-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Free Active Directory Reporting Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Security Permissions Reports'/><category scheme='http://www.blogger.com/atom/ns#' term='Nested Group Memberships'/><category scheme='http://www.blogger.com/atom/ns#' term='True Last-Logon Reporting'/><category scheme='http://www.blogger.com/atom/ns#' term='Active Directory Audit'/><category scheme='http://www.blogger.com/atom/ns#' term='Gold Finger'/><category scheme='http://www.blogger.com/atom/ns#' term='Active Directory Reports'/><title type='text'>Gold Finger Reporting Tool for Active Directory</title><content type='html'>I am updating this blog after a long time, because after a long time I recently came across a really valuable (and I think one of the best) Active Directory Reporting Tools, called &lt;strong&gt;Gold Finger&lt;/strong&gt;. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_NNEF9JTTKro/TN5PrKMVA_I/AAAAAAAAAB4/wupuwjAs6HA/s1600/GoldFinger_v3.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="202" px="true" src="http://1.bp.blogspot.com/_NNEF9JTTKro/TN5PrKMVA_I/AAAAAAAAAB4/wupuwjAs6HA/s320/GoldFinger_v3.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;I happened to come across it by chance as the other day we had a need to clean up stale accounts in our environments, so I was looking for a tool to do free True Last-Logon reporting, and a Google search for “&lt;em&gt;true last logon reports&lt;/em&gt;” led me to this tool.&lt;br /&gt;&lt;br /&gt;It is developed by a company called Paramount Defenses, and as per their website is designed by a former Microsoft Active Directory development team member. Interestingly, although it seems to be designed primarily for determining resultant access in Active Directory, it can also generate almost 400 security reports!&lt;br /&gt;&lt;br /&gt;Thought I'd try it so I downloaded and installed it on my Dell Vostro (which took about a minute.) The install was easy and it seemed fairly straight-forward to use. I could instantly run reports and it was really fast. Surprisingly though I did not need to run it as a Domain Admin.&lt;br /&gt;&lt;br /&gt;What I really liked was that it has virtually every essential Active Directory report one can think of, from account management to security permissions analysis reports! The edition I&amp;nbsp;downloaded had over 50 important accounts reports – enabled accounts, disabled accounts, locked accounts, half a dozen true last-logon reports, expired accounts, deleted accounts, accounts with no passwords etc. &lt;br /&gt;&lt;br /&gt;I did not try all the reports but I believe it can also enumerate nested groups. One other thing I really liked is that it also lets you export the results to CSV format and that has turned out to be quite helpful for us in generating our stale account reports. &lt;br /&gt;&lt;br /&gt;It also had quite a few other reports including group membership, GPO, OU, Microsoft Exchange Mailbox and Schema reports. I did not try all of them (as there were simply too many to try them all) but I did try the security permission reports and it took less than a minute to show me all&amp;nbsp;users in our domain on which I had&amp;nbsp;&lt;strong&gt;Create Child &lt;/strong&gt;permissions.&lt;br /&gt;&lt;br /&gt;One other thing I thought was smart is that in all OU reports, it would automatically display the number of objects in the OU. It also had a cool search utility (oddly called &lt;strong&gt;Target Locator&lt;/strong&gt;) that I could use to perform wildcard searches for accounts, groups OUs etc. One neat search I could do is enter in a SID and find out who it belongs to.&lt;br /&gt;&lt;br /&gt;We've been using it for the last few days now and have come to really like it, especially its speed. Basically, its like have the functionality of many different Active Directory analysis tools into one single fast tool.&lt;br /&gt;&lt;br /&gt;If you need to do any sort of user or computer account, security group, security permissions, Exchange mailbox or OU reporting, you should definitely consider getting your hands on it. You can Google “Active Directory Gold Finger” to find it. I have also provided the link below.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: #007700;"&gt;&lt;strong&gt;+Pros&lt;/strong&gt;: 400 Active Directory Reports, Instant Download, Quick Install, No admin permissions needed, Instant reporting, CSV exports&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: #cc0000;"&gt;&lt;strong&gt;-Cons&lt;/strong&gt;: Not all reports seemed to be exportable to CSV in Free Edition. &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2619413889279683124-7617786919595968336?l=www.ad-active-directory-tools.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.ad-active-directory-tools.com/feeds/7617786919595968336/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.ad-active-directory-tools.com/2010/11/gold-finger-reporting-tool-for-active.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2619413889279683124/posts/default/7617786919595968336'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2619413889279683124/posts/default/7617786919595968336'/><link rel='alternate' type='text/html' href='http://www.ad-active-directory-tools.com/2010/11/gold-finger-reporting-tool-for-active.html' title='Gold Finger Reporting Tool for Active Directory'/><author><name>MarcJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_NNEF9JTTKro/TN5PrKMVA_I/AAAAAAAAAB4/wupuwjAs6HA/s72-c/GoldFinger_v3.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2619413889279683124.post-1113215038740860498</id><published>2010-06-28T15:19:00.000-07:00</published><updated>2011-07-12T11:38:29.022-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Account Lockout Status'/><category scheme='http://www.blogger.com/atom/ns#' term='LockoutStatus.exe'/><category scheme='http://www.blogger.com/atom/ns#' term='Account Lockout'/><title type='text'>Account Lockout Status (LockoutStatus.exe)</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;strong&gt;Account Lockout Status&lt;/strong&gt; (&lt;span class="goog-spellcheck-word"&gt;LockoutStatus&lt;/span&gt;.&lt;span class="goog-spellcheck-word"&gt;exe&lt;/span&gt;) is a free combination command-line and graphical tool provided by Microsoft that can be used to determine vital domain user account lockout related information in an Active Directory domain.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_NNEF9JTTKro/TCkcUbB_4BI/AAAAAAAAABk/TuGynZTUbWc/s1600/LockoutStatus.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" ru="true" src="http://4.bp.blogspot.com/_NNEF9JTTKro/TCkcUbB_4BI/AAAAAAAAABk/TuGynZTUbWc/s320/LockoutStatus.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;This tool can be very helpful in obtaining a list of all domain user accounts that might be locked out, and for all locked accounts, obtaining the specific time when the account got locked out. It is thus not only helpful in determining &lt;strong&gt;account lockout status &lt;/strong&gt;but can also be helpful in identifying an unusual number of bad password attempts on&amp;nbsp;any Active Directory accounts and determining when a user last changed their domain user account's password.&lt;br /&gt;&lt;br /&gt;One nifty feature is that for all bad password attempts, it also shows on which domain controller these bad password attempts occurred, and this information can be useful for security analysis and forensic purposes.&lt;br /&gt;&lt;br /&gt;However, as you might imagine, it can only do account lockout reporting, so its a bit of an overkill to use an entire tool just for a few reports. In that regard, I found the Microsoft-endorsed tool, &lt;a href="http://free-activedir-tools.blogspot.com/2010/11/gold-finger-reporting-tool-for-active.html"&gt;&lt;strong&gt;Gold Finger&lt;/strong&gt;&lt;/a&gt; to be much more useful, because I could not only generate account lockout reports but almost a 100 other useful reports (e.g. true last logon reports, password expiration reports, complete nested group membership lists, detailed security permissions analysis etc.) all from a single tool and UI. &lt;br /&gt;&lt;br /&gt;By the way, here's a helpful illustration of Gold Finger's superior reporting capabilities - &lt;br /&gt;&lt;br /&gt;&lt;div align="center"&gt;&lt;object style="height: 243px; width: 400px;"&gt;&lt;param name="movie" value="http://www.youtube.com/v/PuNM74-0gsg?version=3"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/PuNM74-0gsg?version=3" type="application/x-shockwave-flash" allowfullscreen="true" allowScriptAccess="always" width="400" height="243"&gt;&lt;/object&gt;&lt;/div&gt;&lt;br /&gt;(In case you wish to watch it in full size, here's the direct link to the video on You Tube - &lt;a href="http://www.youtube.com/watch?v=PuNM74-0gsg"&gt;Active Directory Security Reporting/Audit Tool/Solution&lt;/a&gt;)&lt;br /&gt;&lt;br /&gt;All in all, &lt;strong&gt;LockoutStatus &lt;/strong&gt;can certainly help you obtain insight into &lt;strong&gt;account lockout &lt;/strong&gt;information which could help you service account lockouts quickly and in other cases possibly detect and address suspicious activity on your network.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: #007700;"&gt;&lt;strong&gt;+Pros: &lt;/strong&gt;Free, Provided by Microsoft, Combination command-line and GUI, Takes multiple &lt;span class="goog-spellcheck-word"&gt;DCs&lt;/span&gt; into account.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;&lt;strong&gt;-Cons:&lt;/strong&gt; Usage is limited to account lockout specific reporting, no &lt;span class="goog-spellcheck-word"&gt;CSV&lt;/span&gt; generation, no neatly formatted report generation&amp;nbsp;capabilities&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: blue;"&gt;Recommendations - I recommend trying&amp;nbsp; the &lt;a href="http://www.paramountdefenses.com/goldfinger.html"&gt;Gold Finger&lt;/a&gt; tool instead, as it provides a single point of control for anything and everything you need to know about Active Directory security.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2619413889279683124-1113215038740860498?l=www.ad-active-directory-tools.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.ad-active-directory-tools.com/feeds/1113215038740860498/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.ad-active-directory-tools.com/2010/06/account-lockout-status-lockoutstatusexe.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2619413889279683124/posts/default/1113215038740860498'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2619413889279683124/posts/default/1113215038740860498'/><link rel='alternate' type='text/html' href='http://www.ad-active-directory-tools.com/2010/06/account-lockout-status-lockoutstatusexe.html' title='Account Lockout Status (LockoutStatus.exe)'/><author><name>MarcJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_NNEF9JTTKro/TCkcUbB_4BI/AAAAAAAAABk/TuGynZTUbWc/s72-c/LockoutStatus.gif' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2619413889279683124.post-5803432902165198722</id><published>2010-06-18T14:51:00.000-07:00</published><updated>2011-07-12T21:20:09.078-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ALOInfo'/><category scheme='http://www.blogger.com/atom/ns#' term='Account Lockout and Management Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='ALOInfo.exe'/><title type='text'>AloInfo.exe</title><content type='html'>&lt;strong&gt;&lt;span class="goog-spellcheck-word"&gt;AloInfo&lt;/span&gt;.&lt;span class="goog-spellcheck-word"&gt;exe&lt;/span&gt; &lt;/strong&gt;is a free command-line tool provided by Microsoft that can be used to determine the password age of all domain user accounts in an Active Directory domain.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_NNEF9JTTKro/TBvpcqjpONI/AAAAAAAAABU/K6kGSx6KRBk/s1600/AloInfo.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" qu="true" src="http://1.bp.blogspot.com/_NNEF9JTTKro/TBvpcqjpONI/AAAAAAAAABU/K6kGSx6KRBk/s320/AloInfo.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;This can be helpful in situations where you’re trying to obtain a list of all domain user accounts whose password might be about to expire, perhaps to inform them, or to take some other administrative action, or to troubleshoot frequent account lockout issues.&lt;br /&gt;&lt;br /&gt;The tool is rather easy to use, and the following is its usage - &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span class="goog-spellcheck-word"&gt;aloinfo&lt;/span&gt; &lt;/strong&gt;/expires /server:&amp;amp;&lt;span class="goog-spellcheck-word"&gt;lt&lt;/span&gt;;&lt;em&gt;Domain_Controller_Name&amp;gt;&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;Interestingly, one other use of this tool is that it can be used to obtain a list of all local services and &lt;span class="goog-spellcheck-word"&gt;startup&lt;/span&gt; account information for a user who is currently logged on.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;By the way&lt;/strong&gt;, here's a helpful tip. If you ever need insight into when a user's password is scheduled to expire, or when a user last logged on, or when the user's account expires, or what groups a user is a member of, or where all a user has permissions in Active Directory, or the like, then I highly suggest checking out Microsoft-endorsed &lt;a href="http://%3ctable%20border=%221%22%20align=%22center%22%20cellpadding=%2220%22%20bgcolor=%22/#ffffff&amp;quot;&amp;gt;"&gt;Gold Finger&lt;/a&gt; reporting solution. &lt;br /&gt;&lt;br /&gt;In fact, here's a quick video that shows its awesome reporting capabilities - &lt;br /&gt;&lt;br /&gt;&lt;div align="center"&gt;&lt;object style="height: 243px; width: 400px;"&gt;&lt;param name="movie" value="http://www.youtube.com/v/PuNM74-0gsg?version=3"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/PuNM74-0gsg?version=3" type="application/x-shockwave-flash" allowfullscreen="true" allowScriptAccess="always" width="400" height="243"&gt;&lt;/object&gt;&lt;/div&gt;( In case you wish to see the video in its full resolution, here's the link to it on YouTube - &lt;a href="http://www.youtube.com/watch?v=PuNM74-0gsg"&gt;Active Directory Security Reporting/Audit Tool/Solution&lt;/a&gt;. )&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: #007700;"&gt;&lt;strong&gt;+Pros&lt;/strong&gt;: Free, Can be pointed at a specific Domain Controller, Can help identify accounts whose password might be about to expire&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;&lt;strong&gt;-Cons&lt;/strong&gt;: Provides console output, Can’t generate presentable reports, No &lt;span class="goog-spellcheck-word"&gt;CSV&lt;/span&gt; output&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: blue;"&gt;&lt;span style="color: black;"&gt;&lt;strong&gt;Recommendation&lt;/strong&gt;: Checkout the &lt;a href="http://free-activedir-tools.blogspot.com/2010/11/gold-finger-reporting-tool-for-active.html"&gt;Gold Finger&lt;/a&gt;&amp;nbsp;as well. Pretty cool: over 200 security reports (e.g. account mgmt, true last logon, nested group memberships) and access reports etc.&amp;nbsp;+ slick inbuilt AD search utility, in one tool.&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2619413889279683124-5803432902165198722?l=www.ad-active-directory-tools.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.ad-active-directory-tools.com/feeds/5803432902165198722/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.ad-active-directory-tools.com/2010/06/aloinfoexe.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2619413889279683124/posts/default/5803432902165198722'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2619413889279683124/posts/default/5803432902165198722'/><link rel='alternate' type='text/html' href='http://www.ad-active-directory-tools.com/2010/06/aloinfoexe.html' title='AloInfo.exe'/><author><name>MarcJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_NNEF9JTTKro/TBvpcqjpONI/AAAAAAAAABU/K6kGSx6KRBk/s72-c/AloInfo.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2619413889279683124.post-3449528771398870045</id><published>2010-06-08T12:57:00.000-07:00</published><updated>2011-07-12T21:20:38.881-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='RSAT'/><category scheme='http://www.blogger.com/atom/ns#' term='Active Directory Administrative Center'/><category scheme='http://www.blogger.com/atom/ns#' term='dsac.exe'/><category scheme='http://www.blogger.com/atom/ns#' term='AD LDS'/><category scheme='http://www.blogger.com/atom/ns#' term='Powershell'/><title type='text'>Active Directory Administrative Center</title><content type='html'>&lt;strong&gt;Active Directory Administrative Center&lt;/strong&gt; is essentially the new administration interface for Active Directory that provides network administrators with an enhanced Active Directory data management experience and a rich graphical user interface (GUI). &lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_NNEF9JTTKro/TA6YcYE3biI/AAAAAAAAABM/m_YqXuJJ4k8/s1600/Active_Directory_Administration_Center.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" qu="true" src="http://1.bp.blogspot.com/_NNEF9JTTKro/TA6YcYE3biI/AAAAAAAAABM/m_YqXuJJ4k8/s320/Active_Directory_Administration_Center.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;It comes standard with Windows Server 2008 R2 and it can be used to perform common Active Directory object management tasks through both data-driven navigation and task-oriented navigation. It is meant to be the replacement of Active Directory Users and Computer (&lt;span class="goog-spellcheck-word"&gt;ADU&lt;/span&gt;&amp;amp;C) Snap-In and it certainly offers an enhanced management experience for IT administrators.&lt;br /&gt;&lt;br /&gt;It can be used to manage domain user and computer accounts, domain security groups and of course Organizational Units and containers. It can also be used to filter data by using query-building search.&lt;br /&gt;&lt;br /&gt;One of the key benefits of the &lt;strong&gt;Active Directory Administrative Center&lt;/strong&gt; is that it can be used to manage objects across multiple domains, as long as they belong to the same Active Directory forest, or there exists a trust path between the local and the target domain.&lt;br /&gt;&lt;br /&gt;One neat new feature of the &lt;strong&gt;Active Directory Administrative Center&lt;/strong&gt; is the breadcrumb bar, which can be used to directly enter the location of a specific Active Directory object, so that you can directly navigate to that object. &lt;br /&gt;&lt;br /&gt;Another neat feature is that it can be used to query the Active Directory based on richer criteria, such as the to find a list of locked user accounts. It however falls short in providing accurate information on last &lt;span class="goog-spellcheck-word"&gt;logons&lt;/span&gt;, as it does NOT query each DC, but instead relies on the approximation method which is based on the &lt;em&gt;&lt;span class="goog-spellcheck-word"&gt;&lt;a href="http://www.activedirsec.com/last_logon.html"&gt;lastLogonTimeStamp&lt;/a&gt;&lt;/span&gt; &lt;/em&gt;attribute.&lt;br /&gt;&lt;br /&gt;Although &lt;strong&gt;Active Directory Administrative Center&lt;/strong&gt; is not big on reports, I have found that when you compliment it with a dedicated Active Directory reporting tool, such as the Microsoft-endorsed &lt;a href="http://www.ad-active-directory-tools.com/2011/06/gold-finger-40-must-have-for-active.html"&gt;Gold Finger&lt;/a&gt;, you can&amp;nbsp;have a complete (well almost) Active Directory management and reporting solution at your disposal.&lt;br /&gt;&lt;br /&gt;In fact, I have found &lt;a href="http://www.paramountdefenses.com/goldfinger.html"&gt;Gold Finger&lt;/a&gt;&amp;nbsp;to be so helpful that thought I'd share a video with you - awesome reporting capabilities -&lt;br /&gt;&lt;br /&gt;&lt;div align="center"&gt;&lt;object style="height: 243px; width: 400px;"&gt;&lt;param name="movie" value="http://www.youtube.com/v/PuNM74-0gsg?version=3"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/PuNM74-0gsg?version=3" type="application/x-shockwave-flash" allowfullscreen="true" allowScriptAccess="always" width="400" height="243"&gt;&lt;/object&gt; &lt;/div&gt;&lt;br /&gt;( In case you wish to see this on YouTube, here's the link&amp;nbsp;- &lt;a href="http://www.youtube.com/watch?v=PuNM74-0gsg"&gt;Active Directory Security Reporting/Audit Tool/Solution&lt;/a&gt;&amp;nbsp;)&lt;br /&gt;&lt;br /&gt;You can open the &lt;strong&gt;Active Directory Administrative Center&lt;/strong&gt; is one of two ways&amp;nbsp;- you can either click &lt;strong&gt;&lt;em&gt;Start&lt;/em&gt;&lt;/strong&gt;, then select &lt;em&gt;Administrative Tools&lt;/em&gt;, then click on &lt;em&gt;Active Directory Administrative Center&lt;/em&gt;, or you can click &lt;em&gt;Start&lt;/em&gt;, then click &lt;em&gt;Run&lt;/em&gt;, and then type &lt;strong&gt;&lt;span class="goog-spellcheck-word"&gt;dsac&lt;/span&gt;.&lt;span class="goog-spellcheck-word"&gt;exe&lt;/span&gt;&lt;/strong&gt;.&lt;br /&gt;&lt;br /&gt;It however can currently only run on running the &lt;strong&gt;Windows Server 2008 R2 operating system (&lt;/strong&gt;and on Windows 7 clients using (&lt;span class="goog-spellcheck-word"&gt;RSAT&lt;/span&gt;)),&lt;strong&gt; &lt;/strong&gt;and it cannot be used to manage Active Directory Lightweight Directory Services (AD &lt;span class="goog-spellcheck-word"&gt;LDS&lt;/span&gt;) instances and configuration sets. &lt;br /&gt;&lt;br /&gt;It is not without its downsides however in that it cannot be used to generate pretty printed reports which might be needed for security audits and compliance reporting, as the best one can do is perhaps export to &lt;span class="goog-spellcheck-word"&gt;CSV&lt;/span&gt;. Here is another area &lt;strong&gt;Gold Finger &lt;/strong&gt;perfectly compliments the &lt;strong&gt;Active Directory Administrative Center&lt;/strong&gt;.&lt;br /&gt;&lt;br /&gt;Also, because under the hood Active Directory Administrative Center, It is powered by &lt;span class="goog-spellcheck-word"&gt;PowerShell&lt;/span&gt;, and so while it is certainly more powerful than the its predecessor, the Active Directory Users and Computer &lt;span class="goog-spellcheck-word"&gt;MMC&lt;/span&gt; Snap-In, it can be sluggish at time.&lt;br /&gt;&lt;br /&gt;In summary, the &lt;strong&gt;Active Directory Administrative Center &lt;/strong&gt;is the first major revision to the Active Directory data management tools since the initial release of Active Directory way back in 2000.&amp;nbsp;It certainly offers numerous visual and capability enhancements, but is neither intended to and cannot replace the need for dedicated/advanced &lt;a href="http://www.activedir-reporting-tools.com/"&gt;Active Directory reporting tools&lt;/a&gt;.&amp;nbsp; &lt;br /&gt;&amp;nbsp; &lt;br /&gt;&lt;span style="color: #007700;"&gt;+ Pros: Free, Offers Multi-domain Active Directory data management, provides basic Active Directory querying capabilities, enables instant navigation to an Active Directory object, Can generate simple account management type reports&lt;/span&gt; &lt;br /&gt;&lt;span style="color: #6aa84f;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;- Cons: Limited in its ability to generate custom (advanced) IT management and security reports (e.g. True Last &lt;span class="goog-spellcheck-word"&gt;Logons&lt;/span&gt; etc), Currently only runs on Windows Server 2008 R2 and Windows 7 (using &lt;span class="goog-spellcheck-word"&gt;RSAT&lt;/span&gt;), Relies on &lt;span class="goog-spellcheck-word"&gt;PowerShell&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: blue;"&gt;Download Point: Ships along with Windows Server 2008 R2, so will be automatically available when you &lt;span class="goog-spellcheck-word"&gt;DCPROMO&lt;/span&gt; the Windows Server 2008 R2 machine. Alternatively, you can download and install the &lt;/span&gt;&lt;span style="color: blue;"&gt;Remote Server Administration Tools (&lt;span class="goog-spellcheck-word"&gt;RSAT&lt;/span&gt;)&lt;/span&gt; &lt;span style="background-color: white; color: blue;"&gt;on a Windows Server 2008 R2 server or a Windows 7 machine.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: blue;"&gt;&lt;span style="color: black;"&gt;&lt;strong&gt;Recommendation&lt;/strong&gt;: For a well-rounded solution, may wish to consider complimenting the management capabailities of &lt;strong&gt;Active Directory Administrative Center &lt;/strong&gt;with the reporting capabilities of a dedicated&amp;nbsp;Active Directory reporting solution, such as &lt;/span&gt;&lt;a href="http://free-activedir-tools.blogspot.com/2010/11/gold-finger-reporting-tool-for-active.html"&gt;Gold Finger&lt;/a&gt;.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2619413889279683124-3449528771398870045?l=www.ad-active-directory-tools.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.ad-active-directory-tools.com/feeds/3449528771398870045/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.ad-active-directory-tools.com/2010/06/active-directory-administrative-center.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2619413889279683124/posts/default/3449528771398870045'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2619413889279683124/posts/default/3449528771398870045'/><link rel='alternate' type='text/html' href='http://www.ad-active-directory-tools.com/2010/06/active-directory-administrative-center.html' title='Active Directory Administrative Center'/><author><name>MarcJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_NNEF9JTTKro/TA6YcYE3biI/AAAAAAAAABM/m_YqXuJJ4k8/s72-c/Active_Directory_Administration_Center.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2619413889279683124.post-4049479159328680718</id><published>2010-06-04T18:40:00.000-07:00</published><updated>2010-12-10T13:02:30.191-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Active Directory Reporting'/><category scheme='http://www.blogger.com/atom/ns#' term='Free Active Directory Reporting Tools'/><title type='text'>Useful Active Directory Reporting Tools</title><content type='html'>This is a blog on &lt;a href="http://free-activedir-tools.blogspot.com/"&gt;Free as well as useful&amp;nbsp;Active Directory Reporting Tools&lt;/a&gt;. It covers some Active Directory reporting tools that are free and others that are not free but very useful as well. These Active Directory tools can help IT administrators and Network Engineers in day-to-day&amp;nbsp;Active Directory&amp;nbsp;management and reporting.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2619413889279683124-4049479159328680718?l=www.ad-active-directory-tools.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.ad-active-directory-tools.com/feeds/4049479159328680718/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.ad-active-directory-tools.com/2010/06/free-active-directory-reporting-tools.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2619413889279683124/posts/default/4049479159328680718'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2619413889279683124/posts/default/4049479159328680718'/><link rel='alternate' type='text/html' href='http://www.ad-active-directory-tools.com/2010/06/free-active-directory-reporting-tools.html' title='Useful Active Directory Reporting Tools'/><author><name>MarcJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2619413889279683124.post-7807202996357432588</id><published>2010-05-13T15:52:00.001-07:00</published><updated>2011-07-12T22:20:00.204-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='AdFind'/><title type='text'>ADFind</title><content type='html'>&lt;span class="goog-spellcheck-word"&gt;ADFind&lt;/span&gt; is a helpful Active Directory search utility that you can use to query the Active Directory. It is developed by Joe Richards, an IT admin who is also a&amp;nbsp;Microsoft MVP who runs&amp;nbsp;&lt;span class="goog-spellcheck-word"&gt;ActiveDir&lt;/span&gt;.org. &lt;br /&gt;&lt;br /&gt;It can be used to query the Active Directory for user accounts, groups, &lt;span class="goog-spellcheck-word"&gt;OUs&lt;/span&gt;, containers, Schema elements and other resources based on a variety of advanced search criteria. It is a command-line tool and once you have learnt its command line options, it is rather easy to use.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_NNEF9JTTKro/S-xb92jAdNI/AAAAAAAAAAg/lKOcZDCZQJ4/s1600/adfind.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_NNEF9JTTKro/S-xb92jAdNI/AAAAAAAAAAg/lKOcZDCZQJ4/s320/adfind.jpg" wt="true" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span class="goog-spellcheck-word"&gt;ADFind&lt;/span&gt; is a helpful AD search tool and it runs on numerous operating systems ranging from Windows &lt;span class="goog-spellcheck-word"&gt;XP&lt;/span&gt; to Windows Server 2008. Although &lt;span class="goog-spellcheck-word"&gt;LDP&lt;/span&gt;.&lt;span class="goog-spellcheck-word"&gt;exe&lt;/span&gt; can do everything &lt;span class="goog-spellcheck-word"&gt;ADFind&lt;/span&gt; can, the advantage of &lt;span class="goog-spellcheck-word"&gt;AdFind&lt;/span&gt; is that it can be run from the command-line. The only noticeable downside is that it is not supported.&lt;br /&gt;&lt;br /&gt;Personally, I prefer &lt;a href="http://free-activedir-tools.blogspot.com/2010/11/gold-finger-reporting-tool-for-active.html"&gt;Gold Finger&lt;/a&gt; instead, because it is vastly superior and substantially more capable, has so many more (200+) reports (e.g. most account and group mgmt reports, true last logon reports, ACL reports, Exchange reports etc.) in one tool, and because it also has an inbuilt search utility and lets you export both search and report results, all from a clean minimalistic interface.&lt;br /&gt;&lt;br /&gt;By the way, here's a quick helpful video of the Microsoft-endorsed Gold Finger reporting solution for Active Directory&amp;nbsp;- &lt;br /&gt;&lt;br /&gt;&lt;div align="center"&gt;&lt;object style="height: 243px; width: 400px;"&gt;&lt;param name="movie" value="http://www.youtube.com/v/PuNM74-0gsg?version=3"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/PuNM74-0gsg?version=3" type="application/x-shockwave-flash" allowfullscreen="true" allowScriptAccess="always" width="400" height="243"&gt;&lt;/object&gt;&lt;br /&gt;&lt;/div&gt;( Also, in case the video here doesn't work, here's the link to it on YouTube - &lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=PuNM74-0gsg"&gt;Active Directory Security Reporting/Audit Tool/Solution&lt;/a&gt;&amp;nbsp;)&lt;br /&gt;&lt;strong&gt;&lt;span style="color: #007700;"&gt;+ Pros: &lt;/span&gt;&lt;/strong&gt;&lt;span style="color: #007700;"&gt;Free,&amp;nbsp;Command-line, Can be used for most advanced &lt;span class="goog-spellcheck-word"&gt;LDAP&lt;/span&gt;&amp;nbsp;querying and reporting as long as you know &lt;span class="goog-spellcheck-word"&gt;LDAP&lt;/span&gt;, Portable&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;&lt;strong&gt;- Cons:&amp;nbsp;&lt;/strong&gt;&lt;/span&gt;&lt;span style="color: red;"&gt;Unsupported, No advanced reports such as True-Last-Logon etc., Not sure how secure it is, or if it is signed.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2619413889279683124-7807202996357432588?l=www.ad-active-directory-tools.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.ad-active-directory-tools.com/feeds/7807202996357432588/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.ad-active-directory-tools.com/2010/05/adfind.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2619413889279683124/posts/default/7807202996357432588'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2619413889279683124/posts/default/7807202996357432588'/><link rel='alternate' type='text/html' href='http://www.ad-active-directory-tools.com/2010/05/adfind.html' title='ADFind'/><author><name>MarcJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_NNEF9JTTKro/S-xb92jAdNI/AAAAAAAAAAg/lKOcZDCZQJ4/s72-c/adfind.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2619413889279683124.post-477807379310719938</id><published>2010-05-13T15:51:00.001-07:00</published><updated>2010-06-28T15:35:10.699-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Windows PowerShell'/><category scheme='http://www.blogger.com/atom/ns#' term='Cmdlets'/><category scheme='http://www.blogger.com/atom/ns#' term='AD Reporting'/><title type='text'>Windows Powershell</title><content type='html'>The Windows &lt;span class="goog-spellcheck-word"&gt;Powershell&lt;/span&gt; from Microsoft is a free extensible automation engine from Microsoft, consisting of a command-line shell and associated scripting language. &lt;br /&gt;&lt;br /&gt;It is NOT (repeat it is not) a TOOL. &lt;br /&gt;&lt;br /&gt;It is an automation engine that relies on the Microsoft .NET Framework and involves the execution of &lt;span class="goog-spellcheck-word"&gt;cmdlets&lt;/span&gt; which are basically specialized .NET classes which implement specific operations. &lt;br /&gt;&lt;br /&gt;It can however be used to perform a variety of functions on the Windows Platform. It can also be used to query data from Active Directory and to perform common day-to-day aspects of AD management.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_NNEF9JTTKro/S-xg2arr7xI/AAAAAAAAAAo/6Fn14_4uLbg/s1600/ADPowershell.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_NNEF9JTTKro/S-xg2arr7xI/AAAAAAAAAAo/6Fn14_4uLbg/s320/ADPowershell.jpg" wt="true" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;One advantage of using &lt;span class="goog-spellcheck-word"&gt;Powershell&lt;/span&gt; is that it makes it easy for IT admins to derive greater value out of their efforts in scripting so they can automate (at least parts of) common day-to-day IT management and reporting tasks. It also lets IT admins leverage the work of other admins as these scripts can be shared with the community.&lt;br /&gt;&lt;br /&gt;The disadvantage of &lt;span class="goog-spellcheck-word"&gt;PowerShell&lt;/span&gt; is that it relies largely on the development of scripts and even though it makes it easier to derive greater value from scripts, it&amp;nbsp;certainly leaves the possibility of human error. It also takes additional effort to generate reports that are in a presentable fashion and decent enough for submission for any audit or as regulatory compliance evidence.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="color: #007700;"&gt;+ Pros: &lt;/span&gt;&lt;/strong&gt;&lt;span style="color: #007700;"&gt;Free, Can be used to simply day-to-d&lt;span class="goog-spellcheck-word"&gt;ay&lt;/span&gt; IT management tasks and perform basic AD reporting&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;&lt;strong&gt;- Cons:&amp;nbsp;&lt;/strong&gt;&lt;/span&gt;&lt;span style="color: red;"&gt;Limited in its ability to generate custom IT management and security reports (e.g. True Last &lt;span class="goog-spellcheck-word"&gt;Logon&lt;/span&gt;), Relies on scripts which can be prone to human-error, Relies on executing code written by someone else in a trusted environment&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: #0000aa;"&gt;# Download Point: To install &lt;span class="goog-spellcheck-word"&gt;Powershell&lt;/span&gt;, you need to download and install the &lt;a href="http://www.microsoft.com/downloads/details.aspx?familyid=10EE29AF-7C3A-4057-8367-C9C1DAB6E2BF&amp;amp;displaylang=en"&gt;Windows &lt;span class="goog-spellcheck-word"&gt;Powershell&lt;/span&gt; Installation Package&lt;/a&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2619413889279683124-477807379310719938?l=www.ad-active-directory-tools.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.ad-active-directory-tools.com/feeds/477807379310719938/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.ad-active-directory-tools.com/2010/05/windows-powershell_13.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2619413889279683124/posts/default/477807379310719938'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2619413889279683124/posts/default/477807379310719938'/><link rel='alternate' type='text/html' href='http://www.ad-active-directory-tools.com/2010/05/windows-powershell_13.html' title='Windows Powershell'/><author><name>MarcJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_NNEF9JTTKro/S-xg2arr7xI/AAAAAAAAAAo/6Fn14_4uLbg/s72-c/ADPowershell.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2619413889279683124.post-2293491370905450300</id><published>2010-05-13T15:43:00.000-07:00</published><updated>2011-07-12T22:24:01.602-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='dsacls'/><category scheme='http://www.blogger.com/atom/ns#' term='Active Directory Users and Computers'/><category scheme='http://www.blogger.com/atom/ns#' term='DACL'/><title type='text'>dsacls</title><content type='html'>&lt;strong&gt;&lt;span class="goog-spellcheck-word"&gt;DsAcls&lt;/span&gt;&lt;/strong&gt; is a free&amp;nbsp;command-line utility provided by Microsoft that can be used to view and change security permissions on Active Directory objects. &lt;br /&gt;&lt;br /&gt;For all practical purposes, it is the command-line equivalent of the Security tab in the Properties dialog box for an Active Directory object in Active Directory tools, such as Active Directory Users and Computers. &lt;br /&gt;&lt;br /&gt;It can be used to view the &lt;span class="goog-spellcheck-word"&gt;DACL&lt;/span&gt; of any Active Directory object. It can also be used to add a new permission or remove an existing permission from an Active Directory object.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Tip&lt;/strong&gt;: If you are looking for a tool that can help you find out who all has permissions in Active Directory, or where all a user or group has specific permissions in Active Directory, I've found the &lt;a href="http://free-activedir-tools.blogspot.com/2010/11/gold-finger-reporting-tool-for-active.html"&gt;&lt;strong&gt;Gold Finger&lt;/strong&gt;&lt;/a&gt; reporting tool for Active Directory to be the best one by far. We have been using to find out where all our Temp Admin groups have write-property permissions in our AD.&lt;br /&gt;&lt;br /&gt;Here's a quick video of the super helpful Mirosoft-endorsed Gold Finger reporting solution for Active Directory - &lt;br /&gt;&lt;br /&gt;&lt;div align="center"&gt;&lt;object style="height: 243px; width: 400px;"&gt;&lt;param name="movie" value="http://www.youtube.com/v/PuNM74-0gsg?version=3"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/PuNM74-0gsg?version=3" type="application/x-shockwave-flash" allowfullscreen="true" allowScriptAccess="always" width="400" height="243"&gt;&lt;/object&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;In case the video above isn't clear enough,&amp;nbsp; you can watch it on YouTube at - &lt;a href="http://www.youtube.com/watch?v=PuNM74-0gsg"&gt;Active Directory Security Reporting/Audit Tool/Solution&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="color: #007700;"&gt;+ Pros: &lt;/span&gt;&lt;/strong&gt;&lt;span style="color: #007700;"&gt;Free, Can be used to view and modify the security permissions on a single Active Directory object&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;&lt;strong&gt;- Cons:&amp;nbsp;&lt;/strong&gt;&lt;/span&gt;&lt;span style="color: red;"&gt;Cannot be used to identify where all a user/group might have permissions in Active Directory&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2619413889279683124-2293491370905450300?l=www.ad-active-directory-tools.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.ad-active-directory-tools.com/feeds/2293491370905450300/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.ad-active-directory-tools.com/2010/05/dsacls.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2619413889279683124/posts/default/2293491370905450300'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2619413889279683124/posts/default/2293491370905450300'/><link rel='alternate' type='text/html' href='http://www.ad-active-directory-tools.com/2010/05/dsacls.html' title='dsacls'/><author><name>MarcJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2619413889279683124.post-6721178154601705107</id><published>2010-05-13T15:18:00.000-07:00</published><updated>2011-06-13T19:29:36.797-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Delegation of Control Wizard'/><category scheme='http://www.blogger.com/atom/ns#' term='dsrevoke'/><title type='text'>dsrevoke</title><content type='html'>&lt;strong&gt;&lt;span class="goog-spellcheck-word"&gt;Dsrevoke&lt;/span&gt; &lt;/strong&gt;is a command-line tool that can be used to identify the location of all permissions that may be specified for a specific user or group in a domain. It can also be used to remove all permissions specified for a particular user or group on &lt;span class="goog-spellcheck-word"&gt;OU&lt;/span&gt; objects as long as they are explicit in nature.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_NNEF9JTTKro/S-x6tqX1x6I/AAAAAAAAABA/TqY9tTPZU_k/s1600/dsrevoke.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_NNEF9JTTKro/S-x6tqX1x6I/AAAAAAAAABA/TqY9tTPZU_k/s320/dsrevoke.png" wt="true" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;It is was primarily provided by Microsoft to complement the functionality provided by Microsoft's Delegation of Control Wizard, which can be accessed from the Microsoft Active Directory Users and Computers (&lt;span class="goog-spellcheck-word"&gt;ADU&lt;/span&gt;&amp;amp;C) Snap-in and which is used to delegate administrative authority. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span class="goog-spellcheck-word"&gt;dsrevoke&lt;/span&gt; &lt;/strong&gt;complements &lt;span class="goog-spellcheck-word"&gt;ADU&lt;/span&gt;&amp;amp;C by providing the ability to revoke delegated administrative authority. If you are looking to find out where all a user or group has permissions though, you'd be better off using &lt;a href="http://free-activedir-tools.blogspot.com/2010/11/gold-finger-reporting-tool-for-active.html"&gt;Gold Finger&lt;/a&gt; instead as it could help scour your entire domain or any OU for permissions granted to any user/group in no time.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="color: #007700;"&gt;+ Pros: &lt;/span&gt;&lt;/strong&gt;&lt;span style="color: #007700;"&gt;Free, Can be used to find out where all a user or group has permissions specified in AD &lt;span class="goog-spellcheck-word"&gt;OUs&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;&lt;strong&gt;- Cons:&amp;nbsp;&lt;/strong&gt;&lt;/span&gt;&lt;span style="color: red;"&gt;Severely limited in its ability to find out where else a user/group has permissions, and/or identify where&amp;nbsp;all a user/group has&amp;nbsp;what type of permissions &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2619413889279683124-6721178154601705107?l=www.ad-active-directory-tools.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.ad-active-directory-tools.com/feeds/6721178154601705107/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.ad-active-directory-tools.com/2010/05/dsrevoke.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2619413889279683124/posts/default/6721178154601705107'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2619413889279683124/posts/default/6721178154601705107'/><link rel='alternate' type='text/html' href='http://www.ad-active-directory-tools.com/2010/05/dsrevoke.html' title='dsrevoke'/><author><name>MarcJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_NNEF9JTTKro/S-x6tqX1x6I/AAAAAAAAABA/TqY9tTPZU_k/s72-c/dsrevoke.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2619413889279683124.post-3853685711636850053</id><published>2010-05-13T13:04:00.000-07:00</published><updated>2011-06-22T17:22:28.905-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='LDAP Filters'/><category scheme='http://www.blogger.com/atom/ns#' term='LDP'/><category scheme='http://www.blogger.com/atom/ns#' term='AD Reporting'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows 2000 Support Tools'/><title type='text'>LDP.exe for Active Directory</title><content type='html'>Microsoft also provides a free Windows 2000 Support Tools utility&amp;nbsp;called &lt;span class="goog-spellcheck-word"&gt;LDP&lt;/span&gt;.&lt;span class="goog-spellcheck-word"&gt;exe&lt;/span&gt; which can be used to perform Lightweight Directory Access Protocol (&lt;span class="goog-spellcheck-word"&gt;LDAP&lt;/span&gt;) searches against the Active Directory for specific information given specific search criteria.&lt;br /&gt;&lt;br /&gt;&lt;span class="goog-spellcheck-word"&gt;LDP&lt;/span&gt; can be used to perform advanced &lt;span class="goog-spellcheck-word"&gt;LDAP&lt;/span&gt; queries against Active Directory,&amp;nbsp;use a variety of &lt;span class="goog-spellcheck-word"&gt;LDAP&lt;/span&gt; controls, specify&amp;nbsp;advanced connection, binding and search result options and view objects, object meta-data and raw Security Descriptors as well.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_NNEF9JTTKro/S-xbRyHqIJI/AAAAAAAAAAY/zbBAe-5wjDU/s1600/LDP.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="151" src="http://4.bp.blogspot.com/_NNEF9JTTKro/S-xbRyHqIJI/AAAAAAAAAAY/zbBAe-5wjDU/s320/LDP.gif" width="320" wt="true" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;One advantage of &lt;span class="goog-spellcheck-word"&gt;LDP&lt;/span&gt; is that it is a standards-compliant Lightweight Directory Access Protocol (&lt;span class="goog-spellcheck-word"&gt;LDAP&lt;/span&gt;) client that allows users to perform operations (such as connect, bind, search, modify, add, delete) against any &lt;span class="goog-spellcheck-word"&gt;LDAP&lt;/span&gt;-compatible directory, such as Active Directory. &lt;br /&gt;&lt;br /&gt;&lt;span class="goog-spellcheck-word"&gt;LDP&lt;/span&gt; can be used to specify and execute any valid &lt;span class="goog-spellcheck-word"&gt;LDAP&lt;/span&gt; query and thus generate reports which are more advanced than those generated&amp;nbsp;via the standard Administrative &lt;span class="goog-spellcheck-word"&gt;MMC&lt;/span&gt; tools provided by Microsoft Windows Server. It can be used to generate advanced time-based reports as well but it requires you to specify all the technical details in &lt;span class="goog-spellcheck-word"&gt;LDAP&lt;/span&gt; parlance, which can make it a little cumbersome unless you're adept at writing &lt;span class="goog-spellcheck-word"&gt;LDAP&lt;/span&gt; queries and performing 64-bit time value conversions etc.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Tip&lt;/strong&gt;: I first looked for ldp in the hope of being able to find which users have restricted logon hours specified in our AD. Unfortunately, I could not do so with LDP, since analyzing logon-hours takes a bit more work. I however came across the &lt;a href="http://www.paramountdefenses.com/goldfinger.html"&gt;&lt;strong&gt;Gold Finger&lt;/strong&gt;&lt;/a&gt; reporting tool for AD, and finding out who has specific logon-hours specified has been a breeze with it. (Gold Finger is a nifty&amp;nbsp;AD reporting tool with over 200 built-in reports including resultant-set-of-permissions reports.) I would highly recommend trying it out, espcecially if you're pressed for time, and need a quick way to run security reports in AD.&lt;br /&gt;&lt;br /&gt;All in all, its a good tool to have and use if you want to look under the hood of your Active Directory.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="color: #007700;"&gt;+ Pros: &lt;/span&gt;&lt;/strong&gt;&lt;span style="color: #007700;"&gt;Free, Can be used for advanced &lt;span class="goog-spellcheck-word"&gt;LDAP&lt;/span&gt;&amp;nbsp;querying and basic AD reporting&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;&lt;strong&gt;- Cons:&amp;nbsp;&lt;/strong&gt;&lt;/span&gt;&lt;span style="color: red;"&gt;Limited in its ability to generate custom IT management and security reports (e.g. True Last &lt;span class="goog-spellcheck-word"&gt;Logon&lt;/span&gt;)&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2619413889279683124-3853685711636850053?l=www.ad-active-directory-tools.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.ad-active-directory-tools.com/feeds/3853685711636850053/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.ad-active-directory-tools.com/2010/05/ldpexe-for-active-directory.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2619413889279683124/posts/default/3853685711636850053'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2619413889279683124/posts/default/3853685711636850053'/><link rel='alternate' type='text/html' href='http://www.ad-active-directory-tools.com/2010/05/ldpexe-for-active-directory.html' title='LDP.exe for Active Directory'/><author><name>MarcJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_NNEF9JTTKro/S-xbRyHqIJI/AAAAAAAAAAY/zbBAe-5wjDU/s72-c/LDP.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2619413889279683124.post-5590785201892525368</id><published>2010-05-13T12:58:00.000-07:00</published><updated>2010-06-28T15:23:29.171-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Windows Server 2003 Administration Tools Pack'/><category scheme='http://www.blogger.com/atom/ns#' term='ADUC'/><category scheme='http://www.blogger.com/atom/ns#' term='MMC'/><title type='text'>Standard Microsoft Active Directory Management Tools</title><content type='html'>Microsoft Windows Server ships with a standard set of Microsoft Management Console (&lt;span class="goog-spellcheck-word"&gt;MMC&lt;/span&gt;) Snap-Ins that can be used to manage various aspects of Active Directory, including managing your &lt;span class="goog-spellcheck-word"&gt;OU&lt;/span&gt; hierarchy, implement your delegation model, and create, modify and manage the life-cycle of user accounts and security groups.&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&amp;nbsp;&amp;nbsp;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_NNEF9JTTKro/S-xZvAX5hfI/AAAAAAAAAAQ/OMZOjxvJ4TU/s1600/ADUC.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="181" src="http://4.bp.blogspot.com/_NNEF9JTTKro/S-xZvAX5hfI/AAAAAAAAAAQ/OMZOjxvJ4TU/s320/ADUC.png" width="320" wt="true" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;There are four &lt;span class="goog-spellcheck-word"&gt;MMC&lt;/span&gt; Snap-Ins that can help you manage various aspects of AD -&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;strong&gt;Active Directory Users and Computers Snap-In&lt;/strong&gt; - This &lt;span class="goog-spellcheck-word"&gt;MMC&lt;/span&gt; snap-in, also know as &lt;span class="goog-spellcheck-word"&gt;ADU&lt;/span&gt;&amp;amp;C is the main tool used to create and manage your Active Directory hierarchy, create and delete &lt;span class="goog-spellcheck-word"&gt;OUs&lt;/span&gt; and Containers, and create and manager user accounts, security groups and other IT resources. &lt;/li&gt;&lt;li&gt;&lt;strong&gt;&lt;/strong&gt;&amp;nbsp;&lt;strong&gt;Active Directory Domains and Trusts Snap-In&lt;/strong&gt; - This snap-in is used to establish, configure and manage trust relationships between various domains and forests. You can use it to create short-cut trust relationships, external trust relationships, and cross-forest trust-relationships as well. &lt;/li&gt;&lt;li&gt;&lt;strong&gt;&lt;/strong&gt;&amp;nbsp;&lt;strong&gt;Active Directory Sites and Services Snap-In &lt;/strong&gt;- This snap--in is used to define, configure and maintain Active Directory sites, &lt;span class="goog-spellcheck-word"&gt;subnets&lt;/span&gt;, site-to-&lt;span class="goog-spellcheck-word"&gt;subnet&lt;/span&gt; mappings and perform other tasks related to site and &lt;span class="goog-spellcheck-word"&gt;subnet&lt;/span&gt; management. &lt;/li&gt;&lt;li&gt;&lt;strong&gt;&lt;/strong&gt;&amp;nbsp;&lt;strong&gt;&lt;span class="goog-spellcheck-word"&gt;ADSIEdit&lt;/span&gt;.&lt;span class="goog-spellcheck-word"&gt;msc&lt;/span&gt;&lt;/strong&gt; - This is a special and very handy snap-in that can be used to access and edit all attributes of all objects in Active Directory. It is particularly helpful if you wish to make modification to uncommon attributes, and or create a new object of any of the classes defined in the Schema.&lt;/li&gt;&lt;/ol&gt;If you're an IT administrator responsible for AD management, then you probably already know about the common set of administrative tools that ship with Windows Server, but nonetheless, thought of mentioning them here for anyone starting out in AD administration.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="color: #007700;"&gt;+ Pros: &lt;/span&gt;&lt;/strong&gt;&lt;span style="color: #007700;"&gt;Free, Come with Windows, Can be used for AD management, Good for Basic Search and Reporting&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;&lt;strong&gt;- Cons:&amp;nbsp;&lt;/strong&gt;&lt;/span&gt;&lt;span style="color: red;"&gt;Very limited in their ability to generate advanced and/or custom management and security reports&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: #0000aa;"&gt;# Download Point: To install these tools, you need to download and install the &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=c16ae515-c8f4-47ef-a1e4-a8dcbacff8e3&amp;amp;displaylang=en"&gt;Windows Server 2003 Administration Tools Pack&lt;/a&gt; &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2619413889279683124-5590785201892525368?l=www.ad-active-directory-tools.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.ad-active-directory-tools.com/feeds/5590785201892525368/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.ad-active-directory-tools.com/2009/11/hello.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2619413889279683124/posts/default/5590785201892525368'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2619413889279683124/posts/default/5590785201892525368'/><link rel='alternate' type='text/html' href='http://www.ad-active-directory-tools.com/2009/11/hello.html' title='Standard Microsoft Active Directory Management Tools'/><author><name>MarcJ</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_NNEF9JTTKro/S-xZvAX5hfI/AAAAAAAAAAQ/OMZOjxvJ4TU/s72-c/ADUC.png' height='72' width='72'/><thr:total>0</thr:total></entry></feed>
