Active Directory Cookbook Blog

Blog Archived 

I originally created this blog as a marketing tool for Active Directory Cookbook, which went on to become the best selling Active Directory book on the market since its release in 2003. Now that the second edition of the book has been released, I no longer have the the time to keep this blog up to date. I'm going to leave it up for now because it still receives a fair amount of Google traffic, but I will no longer update it moving forward.

Regards,
Robbie Allen

Active Directory Cookbook, 2nd Edition 

The second edition of the best selling Active Directory Cookbook is now available!

Active Directory Cookbook, 2nd edition
If you're among those looking for practical hands-on support, help is here with Active Directory Cookbook, Second Edition, a unique problem-solving guide that offers quick answers for Active Directory and updated for Window Server 2003 SP1 and R2 versions. This best selling book provides solutions to over 300 problems commonly encountered when deploying, administering, and automating Active Directory to manage users in Windows 2000 and Windows Server 2003.

Book Home Page

ISBN 0-596-10202-X
Table of Contents

Publisher O'Reilly Media
Source Code

Published June 2006
Index

Pages 991
Sample Chapter

Author Robbie Allen and Laura Hunter

Buy from Amazon and save over 35%


Centrify Raises $14 Million in Series B Financing 

Looks like Centrify is gaining momentum. I think their AD integration products will only continue to gain importance in this increasingly heterogeneous world.

"Centrify Corporation, a leading provider of solutions that securely integrate non-Microsoft platforms with Microsoft® Active Directory management services, today announced it has raised $14 million in series B financing. INVESCO Private Capital leads this second round with additional investment by existing Centrify investors Mayfield and Accel Partners. As part of this financing round, Michael Patterson of INVESCO will join Centrify's board of directors. Centrify will use the capital to continue the expansion of its sales, marketing and support efforts. To date, Centrify has raised over $20 million in funding."
Continue at source

Article: Red Hat pushes for the middle 

"Szulik also predicted that there will be more products coming out of the Netscape code that Red Hat acquired from AOL last year. The code formed the basis for the Red Hat identity server.

The executive declined to name specific products, saying that he will use the Netscape code where needed to fill in holes in Red Hat's product line-up.

'We are not simply going in and replacing Active Directory or iPlanet,' he said, in a reference to two products that compete with the Red Hat Directory Server.

'This [Netscape] acquisition means that we are going way beyond just print and file servers.'"
Continue at source.

Q&A: Red Hat CEO looks outside U.S. for growth 

"How do you expect to get users to move off Microsoft's Active Directory? You raise a good point. Maybe within the next 12, 18, 36 months, Active Directory in the U.S. won't be the place where the directory's capability is, [where] the certificate management capability happens. Maybe it will happen in Spain. Or maybe it will happen in England. Or maybe it will happen in Poland or Russia. There were $19.5 billion of Linux-related technologies sold in 2004. This is an incredibly large market which we're competing in, and Red Hat's business opportunity is really at such an embryonic stage. To me, it's no longer a question of if. It's just a matter of when."
Continue at source.

Red Hat to open-source Netscape Directory 

There has been a lot of directory news lately. I've been wondering when we'd hear from RedHat and now finely we have:

"Leading Linux vendor, Red Hat, is expected to open source the Netscape Directory technology it acquired last September on the first day of its summit conference in New Orleans on June 1st. As Microsoft Watch reports, Netscape Directory Services (NDS) will be renamed Red Hat Directory Server and the code will be released under the GNU General Public License (GPL). That means anyone will be able to use, modify and redistribute the software. This is good news for organizations running Linux who now will have an alternative to the leading open-source directory software, OpenLDAP."
Continue at source.

Quest acquires Vintela for cross-platform authentication 

Big news: Vintela is acquired by Quest. I wonder if anyone is looking at Centrify now? A related article.

Article: Microsoft Readies Identity Integration Server SP2, 'Gemini' Upgrade 

"As identity management and access take center stage in the software arena, Microsoft is developing a service pack for its Identity Integration Server 2003 and a major upgrade, code-named Gemini, due out in 2007."
Continue at source.

New book: Linux in a Windows World 

"This book is about many of the points where Linux can be strategically placed into your network. Do you need centralized authentication for Windows and Linux machines but don't want to use Windows? This book shows you how. Do you need your Linux machines to authenticate against an Active Directory server? Not a problem? Centralized print services running on a reliable Linux machine? CUPS is your answer. Want a gateway email server to do spam and virus filtering before you email gets to your MS Exchange groupware server? Linux in a Windows World covers that too."
Continue at source.

Article: LDAP at the heart of the secure organisation 

"Single sign-on (SSO) has long been a holy grail for security teams in large complex organisations. But the obstacles in the way of its universal deployment have so far proved to be too great - in particular the challenge of interfacing and synchronising data held in the various directories that larger companies typically deploy.

These proprietary directories have traditionally been built around individual applications, which creates problems for anyone attempting to standardise or centralise user and application credentials. But things are looking up. The accelerating adoption of LDAP (Lightweight Directory Access Protocol) is offering hope to security managers who have been seeking to integrate multiple enterprise directories - and so facilitating SSO."
Continue at source.

Article: Centrify adds Debian support 

"Centrify Corporation announced yesterday that its DirectControl suite -- an application that enables the use of Microsoft Active Directory within a mixed computing environment -- now supports the Debian GNU/Linux operating system."
Continue at source.

Article: Microsoft Ships R2 Public Beta: Should You Bother? 

"Microsoft has released a public beta version of its upcoming Windows Server 2003 interim release, code-named R2. The release is available through the R2 Customer Preview Program. I've been following R2 development and have been working with beta R2 code for several months now. In this week's commentary, I give you some information about what to expect--and perhaps more important, what not to expect--from R2."
Continue at source.

Article: If Only I Remembered The Name Of That Guy In Accounting 

"It's hard enough to remember this month's quality initiative, let alone remember the new head of accounting. Namescape, a Phoenix-based software company, has created rDirectory, a searchable secure employee directory that is based on Microsoft Active Directory."
Continue at source.

Article: Microsoft, Sun agree on sign-on specs 

"Microsoft Corp. and Sun Microsystems Inc. said they have agreed to a single sign-on specification to ease cross-platform identity management and promised to broadly improve the interoperability of their rival .Net and Java Web services platforms."
Continue at source.

PADL Releases XAD Identity Server 

PADL has announced general availability of its identity server, XAD.

"XAD® provides a cross-platform enterprise identity management service on Linux. It is based on open standards and does not require a proprietary server infrastructure. All popular client operating systems and authentication protocols are supported, including Kerberos, LDAP, and Windows logon. XAD is built on proven open source software, including the popular OpenLDAP directory server."
Continue at source.

Article: Extend the Limits of Group Policy 

In this article, Bill Boswell walks through the process of implementing Group Policy extensions.

Article: Join Linux to Active Directory with Winbind 

This article covers the process of joining a Linux workstation to Active Directory using Winbind.

"Samba and winbind provide authentication and identity resolution for Linux hosts that are part of an Active Directory domain, since Active Directory does not deign to provide a method for authenticating them directly. Follow the steps for joining a Samba server to AD. Then comes the hairy part -- if your Linux users require access to network services that require authentication, you'll have to configure PAM (pluggable authentication modules). This can be a bit vexing, but the advantage is it saves users from having to manage multiple logins. And it allows you to control access to services very precisely."
Continue at source.

Article: Tiger Caged by SMB, Active Directory Problems 

"The growing pains for Apple's Mac OS X Tiger continue as reports surface of trouble with SMB networking for Windows servers. Also, compatibility updates are still due for productivity apps."
Continue at source.

Centrify Joins VMware Technology Software Alliance Program to Deliver Active Directory Integration for VMware ESX Server 

"May 9 /PRNewswire/ -- Centrify Corporation, a leading provider of Active Directory-based identity, access and Group Policy management solutions, has joined the VMware® Technology Software Alliance Program. Centrify has optimized its DirectControl suite for VMware ESX Server so that customers can leverage Microsoft® Active Directory® to centralize and control access to their virtual machines and use Microsoft Group Policy to manage configurations. As one of the first VMware partners to provide Active Directory integration for authentication, authorization and group policy, Centrify is committed to delivering optimized support for VMware ESX Server."
Continue at source.

Boston Area Windows Server User Group - May 4th, 2005 

My talk yesterday on Active Directory Hacks to BAWSUG went well. Good group of people. Thanks to Lucien for giving me a ride. They may invite me back in the fall for one of their day-long Active Directory seminars.

It would be nice if RTP had a similar group...unfortunately I don't have the time to organize such an effort at this point.


New download: Ultrasound - Monitoring and Troubleshooting Tool for File Replication Service (FRS) 

Microsoft's Ultrasound tool has been updated:
"Ultrasound is a monitoring and troubleshooting tool for the File Replication service (FRS). FRS is used to replicate files and folders in the SYSVOL file share on domain controllers and files in Distributed File System (DFS) targets. Ultrasound is a powerful tool to measure the health of FRS replica sets by providing health ratings and historical information about replica sets. Ultrasound also allows administrators to monitor the progress of replication and detect problems that can cause replication to become backlogged or stopped."
Continue at source.

New Download: Microsoft Password Change Notification Service 

"The Microsoft Password Change Notification Service enables synchronization of password changes in Active Directory to Microsoft Identity Integration Server Service Pack 1 (MIIS) or the Microsoft Enterprise Single Sign-On (ENTSSO) service. These components simplify password management in organizations with multiple user identity repositories."
Continue at source.

Article: Hooked On Phishing 

This article talks about the identity theft problem and says that "Active Directory Federation Service (ADFS) will become the cornerstone of Microsoft's adoption of Web services security protocols on the Windows platform, supporting authentication and authorization services between disparate systems and across corporate boundaries. It will allow users to 'federate' identities between corporate boundaries. Federation lets an identity credential issued by one company be used for access to a partner's network."

I've talked to several AD MVPs and none know much, if anything, about ADFS. This make me skeptical on the potential for ADFS. I'd rather have the industry say ADFS will be the "cornerstone" than Microsoft. People have been talking about federation for years, but I still don't think sys admins and even IT executives really understand it. Microsoft needs to address this before ADFS will be a success. Heck, MIIS still isn't widely adopted because many people don't understand its value (or don't think the value is great enough to offset the implementation cost).

Article: Novell continues to contribute, commit to Open Source 

Novell is going to make at least part of eDirectory open source according to this article.

New Download: Microsoft Identity Integration Server 2003 Documentation Roadmap 

"This roadmap describes the documentation available for Microsoft® Identity Integration Server (MIIS) 2003 and Identity Integration Feature Pack (IIFP) for Microsoft® Windows Server™ Active Directory. The first section, Common Tasks, allows you to search MIIS 2003 resources for specific information about a task you might want to do. The second section, Documentation Summary, provides a complete list of the MIIS 2003 documentation sets with a brief summary of each document. The documentation summary is divided into five categories: technical reference, design and planning, walkthroughs, operations, and Resource Tool Kit to make it easier to locate specific documentation."Continue at source.

Article: Mapping identities 

This article discusses the evolution of identity management and its importance in organizations today.

Article: Windows Server 2003 'R2' Hits Beta 2 

"Microsoft has issued a second beta of Windows Server 2003 "R2" to testers on its BetaPlace Web site a week after sending out invitations to participate in the program.

The overall R2 feature set includes: Active Directory Application Mode (ADAM); SharePoint version 2.0; Active Directory Federation Services (ADFS), also known as TrustBridge; Branch Office File Replication services (FRS); Common Logging File Systems (CLFS); File Server Migration Toolkit (FSMT); Interix and Network File System (NFS) support; MMC compatibility; Simple SAN support; and Microsoft's Storage Resource Management subsystem code-named "Corral." File and print management enhancements have also been incorporated."
Continue at source.

Past and future meet in Novell OES 

"Novell's OES (Open Enterprise Server) 1.0 is not actually a new product, but a weaving together of existing ones.

OES combines SLES (Suse Linux Enterprise Server) 9.0 and NetWare 6.5, including Virtual Office Services and iPrint, Novell File Services and iFolder, identity management (nSure and eDirectory), Novell iManager Web-based admin, and clustering."
Continue at source.

NetIQ fits FullArmor for security policy automation 

"NetIQ said it will start to market and resell FullArmor's IntelliPolicy for Clients system as part of its Group Policy Suite to help in the standardization of corporate policies across an Active Directory environment."
Continue at source.

Centrify Certifies DirectControl Suite for Red Hat Enterprise Linux 4 

"April 18 -- Centrify Corporation today announced Red Hat Ready certification of DirectControl(TM) which integrates Red Hat Enterprise Linux 4 environments into Microsoft's Active Directory. As a member of the Red Hat Ready Partner program, Centrify has added support for Red Hat Enterprise Linux 4 to its existing product line, which already includes support for Red Hat Enterprise Linux 2.1 and 3 as well as Fedora Core 3. DirectControl is an identity, access and Group Policy management solution that comprehensively extends the capabilities of Microsoft Active Directory for mixed Microsoft Windows, UNIX and Linux environments and Java(TM) and web-based applications."
Continue at source.

NetPro Announces Release of SecurityManager 

"04/19/2005 -- MICROSOFT MANAGEMENT SUMMIT -- NetPro Computing, Inc., a leading provider of distributed services management software, today announced the release of SecurityManager. Building on a foundation of industry security best practices, SecurityManager is a breakthrough solution that monitors Microsoft Active Directory security policies in real-time.

SecurityManager ensures that Active Directory configurations are correctly defined and enforces corporate compliance to government regulations using baked in Security Best Practices from Microsoft and a customizable policy interface. Leveraging NetPro's auditing and configuration solution, ChangeAuditor, SecurityManager provides 24x7notification of Active Directory security vulnerabilities and ensures comprehensive protection against the Active Directory security breaches that put implementations at risk every day. "
Continue at source.

Article: Understanding RFC 2307 and the Windows Server 2003 'R2' default schema 

"With Microsoft Windows Server 2003 'R2', Microsoft has embraced the RFC 2307 standard, and is now including the RFC 2307 attribute definition as part of the default AD schema. This means that when installing R2, support for Unix attribute information is automatically included, and indeed, will form part of the baseline Active Directory schema definition."
Continue at source.

New Download: Windows Server 2003 Access-based Enumeration 

There has been a lot of buzz around this new tool from MS:
"Windows Server 2003 Access-based Enumeration makes visible only those files or folders that the user has the rights to access. When Access-based Enumeration is enabled, Windows will not display files or folders that the user does not have the rights to access. This download provides a GUI and a CLI that enables this feature."
Continue at source.

Article: FullArmor to Ship Updated Group Policy Management Tool 

"FullArmor next week will ship version 2.0 of its GPAnywhere Active Directory Group Policy extender tool for administrators.

The latest version features integration with the Microsoft Group Policy Management Console, a new “Policy Enforcer” capability and integration of FullArmor’s IntelliPolicy for Clients product.

GPAnywhere enables enterprises that have a mix of Active Directory-aware PCs, PCs using earlier network connection technologies and occasionally connected laptops to manage them all through standardized Group Policy settings."
Continue at source.

OctetString Announces Next Version of Virtual Directory Engine 

"April 6, 2005--OctetString today announced version 3.0.2 of their flagship software suite, Virtual Directory Engine (VDE), a virtual directory technology that allows enterprises to connect applications to multiple sources of user identities within the enterprise quickly and easily. This latest version improves support for directory products from Computer Associates and Siemens, while also making identity information accessible via Web services.

In addition to providing underlying Web services framework improvements that simplify connectivity and form the basis for SAML and SPML support in upcoming versions, OctetString has bundled an example Web services adapter. This example communicates with the Amazon Web service, showing how easy it is to expose completely external services via directory protocols such as LDAP and DSML. Web services support within the VDE product can include full read and write access and respect for security and auditing in existing data sources. "
Continue at source.

5 Steps to a Secured Active Directory 

I have a new article in the April edition of Windows IT Pro: 5 Steps to a Secured Active Directory. In it, I cover the fundamental things system administrators must do to ensure a basic level of security with Active Directory. Often people concentrate on more advanced security issues such as defending against root kits, but ignore the basics like providing physical security or implementing secure administrator practices. If you can do the things in this article, you'll be better off than most.

Oracle buys security developer Oblix 

The consolidation train continues full steam ahead...
"MARCH 29, 2005 (IDG NEWS SERVICE) - Oracle Corp. said yesterday that it has acquired Oblix Inc., a privately held identity management technology developer, for an undisclosed sum. Oracle said it will move quickly to integrate Oblix's security products with its own infrastructure software."
Continue at source.

Article: Centrify wades in to market for directory interoperability tools while Vintela bulks up 

Here is an article from Redmond Mag about Tom Kemp and his company, Centrify.

Article: Small shops tackle DR on a budget 

"Jay Wessel, senior director of technology at the Boston Celtics, recently discovered that creating a disaster recovery plan for Microsoft Exchange and Active Directory servers is easier said than done.

Wessel described Exchange as 'great at clustering within a building, but not great at redundancy.' The Celtics discovered that Exchange 2003 does not offer a replication feature. After haranguing Microsoft, they were advised to check out Double-Take replication from NSI Software.

The Celtics have about a terabyte (TB) of data between an Exchange Server and an Active Directory file server to store e-mail, team statistics, financial and ticketing data. The organization had always backed up to tape, but realized that restoring from off-site tapes was taking too long. 'Recovering from tape in the event of a disaster would be a many-day process,' Wessel said."
Continue at source.

Article: When it's time for a change in Active Directory 

"Compliance regulations are bringing new demands for accountability and the need to keep track of changes made by IT administrators.

To that end, Quest Software Inc. this week became the latest software vendor to release a tool that helps IT managers to do real-time change checking and tracking of Microsoft's Active Directory. Quest's Change Manager for Active Directory provides a log that captures before-and-after values, can reverse unwanted changes and does not depend on native auditing."
Continue at source.

Independent Testing Firm VeriTest Confirms Functionality, Reliability and Security of Centrify's Enterprise Identity Management Solution 

"Centrify Corporation, a leading provider of Active Directory-based identity, access and policy management solutions, has announced that DirectControl is the first solution that integrates Unix/Linux environments into Active Directory to successfully complete Microsoft's rigorous, industry-leading 'Certified for Windows' program."
Continue at source.

Centrify announces general availability of DirectControl 

"Centrify Corporation today announced the general availability of DirectControl, an integrated identity, access and policy management solution that comprehensively extends the capabilities of Microsoft Active Directory for mixed Microsoft Windows, UNIX and Linux environments and Java and web-based applications. Using DirectControl software, administrators can reduce the administrative costs associated with user account management, strengthen security throughout their organization and improve user productivity through the streamlined consolidation of multiple user IDs—all via a seamlessly integrated solution that does not require intrusive changes to either a customer’s Active Directory environment or Unix/Linux environment. "
Continue at source.

Quest Adds Active Directory Product 

"Quest Software said this morning that it has added a new product for Microsoft's Active Directory software. The company's new Quest Change Manager monitors and corrects changes in Microsoft Active Directory. The software tracks changes and corrects unwanted changes by logging all Active Directory changes, prevents changes to vital entries, and modifies configuration settings according to policy."
Continue at source.

Article: Novell presses Linux on all fronts 

"Novell this week also unveiled its Application Services Foundation and Identity Services Foundation, two platforms being offered as a set of software development kits that allow developers to build customized identity management and security applications.

Novell faces tough competition in the area of identity management from the likes of Microsoft, Sun and others. But analysts said Novell has a lot of credibility when it comes to the technology, enough to possibly give them an edge.

"[Novell] has been focusing on the directory service problem for 10 years. They started shipping advanced directory services for the NetWare platform in the mid-90s," Iams said. "Microsoft didn't really show up [with Active Directory] until Windows 2000 came out."
Continue at source.

Yeah, but AD was far and away better than Novell's offering.

Article: Novell presses Linux on all fronts 

"Novell this week also unveiled its Application Services Foundation and Identity Services Foundation, two platforms being offered as a set of software development kits that allow developers to build customized identity management and security applications.

Novell faces tough competition in the area of identity management from the likes of Microsoft, Sun and others. But analysts said Novell has a lot of credibility when it comes to the technology, enough to possibly give them an edge.

"[Novell] has been focusing on the directory service problem for 10 years. They started shipping advanced directory services for the NetWare platform in the mid-90s," Iams said. "Microsoft didn't really show up [with Active Directory] until Windows 2000 came out."
Continue at source.

Yeah, but AD was far and away better than Novell's offering.

Article: BMC buys OpenNetwork for $18 million 

"Enterprise management software company BMC Software is continuing its identity-management buying spree. The company is buying OpenNetwork Technologies, a maker of web access management and single sign-on technology, for US$18 million in cash.

The acquisition of privately held OpenNetwork will add technology for securely managing federated user identities and web-based applications to BMC's identity management product suite. The news is the latest evidence that BMC is making Web-based identity and access management a top priority, and comes just two months after BMC said it would purchase Calendra, another identity management vendor.

OpenNetwork makes software for managing user identity over the Web. The company's Universal Identity Platform (Universal IdP) product integrates with existing LDAP (Lightweight Directory Access Protocol) directory services, such as Microsoft Corp.'s Active Directory. It is designed to work with Microsoft's .NET Framework and .NET Web Services, permitting web applications and other resources to be secured and managed without needing to duplicate network policy and user identity information, according to OpenNetwork."
Continue at source.

Q&A: Novell CEO touts Linux, identity products 

"With NetWare usage continuing to decline, Novell Inc. is making Linux and "identity-driven computing" the focal points at this week's annual BrainShare user conference here. In an interview with Computerworld yesterday, CEO Jack Messman talked about his company's strategy, its efforts to court Windows users and recent shake-ups in Novell's executive ranks."
Continue at source.

New Download: Exchange Server Best Practices Analyzer Tool 2.0 

A new version of Microsoft's popular Exchange Server Best Practices Analyzer Tool was recently released.

"The Microsoft Exchange Server Best Practices Analyzer Tool is designed for administrators who want to determine the overall health of their Exchange servers and topology. The tool scans Exchange servers and identifies items that do not conform to Microsoft best practices."

New download: Microsoft LimitLogin 1.0 

"Microsoft is happy to announce the availability of LimitLogin v1.0, an application that adds the ability to limit concurrent interactive user logons in an Active Directory domain. It can also keep track of all logins information in Active Directory domains (without necessarily enforcing logons quotas).

The challenge of limiting concurrent logons in a distributed environment is huge, and although LimitLogin is not a "bullet proof" solution to all the aspects of this challenge, many customers might still find this tool helpful, as this capability has been highly requested by different customers (banks, ISPs, libraries etc) in numerous RFPs etc."
Continue at source.

Article: Identity management: today's business imperative 

This article provides a good summary of identity management and its importance in business.

This page is powered by Blogger. Isn't yours?