Help needed unravelling 2003 Server Security Groups

Hi I have just taken over managing a set of six domains for a care home network.
The domains have previously been managed by different people.
I am not overwhelmed by documentation but most of the AD structures are not that complex; so it’s easy enough to work it out.
There is one site where the admin was part way through a migration from Server 2003 to Server 2008 R2 where there is a little bit more of a challenge.
There are 54 Security Groups for 72 Users!
Most of them are organised in such a way that the membership of a Security Group is comprised of other Security Groups: so to find out who has rights to access what you often have to go through 3 different Security Groups before you get to see any users.
Before I can complete the data migration I need to unravel the Security Group structure and simplify it.  
Does anyone have any suggestions as to how I can easily find details of membership and rights without manually searching through every Security Group? Ideally I’d like to be able to export this to a CSV file or Excel.
Cheers
Micky Mc

Hi Vivian
Due to the aforementioned time issues I only get to spend a couple of hours on site in this place and I didn’t want to install the programme remotely in case it was
too much for the old 2003 Server.
The link to http://www.manageengine.com/products/ad-manager/active_directory_group_reports.html was
a great tip and after a relatively short period of time I was able to get a nice spreadsheet showing me the intricacies of my crazy convoluted security groups. Now all I need to do is sit down with a highlighter pen and fathom it out!!!
Thanks very much for your help
Cheers
Micky Mc

Similar Messages

  • How to change SQL Server security groups name after server rename?

    A Windows 2003 server has been renamed from LAMDAMIRROR1A to LAMDAMIRROR2A and the following
    sql has been run in SQL Server 2008 R2 on the server :
    exec sp_dropserver 'LAMDAMIRROR1A'
    exec sp_addserver 'LAMDAMIRROR2A','local'
    However, although everything appears ok, the 5 Windows 2003 Groups (automatically created by
    the SQL 2008 R2 Install) still contain 'LAMDAMIRROR1A' in their name. Does this matter ? Can the Windows Groups be just renamed (right click , rename) or will this cause problems ?
    The Windows Groups are :
    SQLServer2005SQLBrowserUser$LAMDAMIRROR1A
    SQLServerDTSUser$LAMDAMIRROR1A
    SQLServerMSSQLServerADHelperUser$LAMDAMIRROR1A
    SQLServerMSSQLUser$LAMDAMIRROR1A
    SQLServerSQLAgentUser$LAMDAMIRROR1A
    There are also Registry entries containing the old 'LAMDAMIRROR1A' name. Does this matter ?
    Should this be changed ?
    eg. 
    My Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft SQL Server\100\Machines\OriginalMachineName.
    My Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft SQL Server\Services\Report Server\GroupPrefix.
    My Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\printers\Microsoft XPS
    DocumentWriter\DsSpooler\serverName.
    etc

    Hi,
    If you have executed the sp_dropserver and sp_addserver in SQL Server 2008 R2, we need to verify if you renamed the SQL Server instance successfully. You can select information from @@SERVERNAME or sys.servers to verify if the renaming operation is completely
    successful in SQL Server Management Studio (SSMS). If yes, whether you change the registry entries containing the old 'LAMDAMIRROR1A' name or not, there’s no impact on SQL Server Services. For more details, please review this article: 
    How to: Rename a Computer that Hosts a Stand-Alone Instance of SQL Server.
    In addition, if you must rename the windows groups, you can just right-click the group in Computer Management/System Tools/Local Users and Groups/Groups and rename it, or you can create new groups with new names, for more details, please review this article:
    Manage Local Groups. If there are some issues regards the Windows, you can post the question in the Windows Server forums at
    http://social.technet.microsoft.com/Forums/windowsserver/en-US/home?category=windowsserver . It is appropriate and more experts will assist you.
    Thanks                 
    Lydia Zhang                           

  • Security API help needed / howto list user in group

    Hi there,
    i have tried all example programs of the hyperion security api. hard work to correct the errors in these scripts.
    now i can create native groups an users and can create groups on groups or put users in native groups.
    i have read the java doc / reference for the security api too but its not possible for me to list users of a group (group reference by name).
    is there anybody who can help with a code sample to list users of a group like "testgroup" ?
    something like (...getGroups(context,"testgroup")...) ??
    Best Regards
    Kai

    Please don't cross-post. It is considered very rude to do that here:
    http://forum.java.sun.com/thread.jspa?threadID=5233033&messageID=9953169#9953169

  • Help needed Regarding Project Server - 2013 Workflow

    Hi All,
    I am new to Project server 2013 Workflow, hence please help me regarding this. Pardon me if this question is too trivial. 
    I have created a project type associated with a workflow and my workflow is as follows :
    So I am not doing anything here, I am just testing the workflow as mentioned by technet site : http://technet.microsoft.com/en-us/library/dn458865(v=office.15).aspx
    But it is mentioned that, after a minute or 2, the workflow state will change, also they have mentioned to press the Submit button.
    But in my case, the workflow is not moving to next stage [It just says 'The workflow is still processing - which never changes after hours] or I am getting the submit button (Submit button is disabled on the ribbon). Below is the state of my workflow :
    PS : I have made the user added to Portfolio managers group as well. But still I am having this same issue. 
    The Workflow manager is installed properly, and it is working fine in case of List workflow. I am facing the issue only wrt Site workflow for Project server 2013.
    Please help me to solve this issue.
    Thanks,
    shanky

    Hi Kiran,
    I am now facing issue while assigning a task to a person in the workflow.
    I am having a person named say 'John' , who is included in Project Manager as well as Portfolio Manager.
    And I am using a workflow as :
    Stage : Conceptual
    Assign a task to John (Task outcome to Variable: Outcome5 | Task ID to Variable: TaskID3 )
    Transition to stage
    Go to Approval
    But this is again giving issue as :
    Workflow Internal status : Cancelled
    Details: System.ApplicationException: HTTP 401 {"error":{"code":"-2147024891, System.UnauthorizedAccessException","message":{"lang":"en-US","value":"Access denied. You do not have
    permission to perform this action or access this resource."}}}
    PS : I have used the same Sharepoint admin account for 'Account Name' in ‘User Profile Sync' , Is this causing the issue? Please let me know.
    Thanks,
    Shanky

  • Help need in ADF application security.

    Hi All,
    I need to implement the ADF application with authentication.Iam using jdeveloper 11.1.1.3.0 and Standalone WLS.
    I want to create group in WLS and map the user present in group for authentication.
    Any one please provide the tutorial link or video link so that i can implement the authentication as most of the link is for jdev 10 not for jdev 11.
    Regards,
    Suresh kumar.k

    would this help you:(which is exactly what I suggested in the other place Suresh asked :) )
    Reading the docs is always a good place to start.
    Good luck,
    john

  • Help needed with Mac Server set up

    Hi
    I have purchased a mini mac server, that i want to use as a replacement for my windows home server, for basic back ups & to run a website with possible remote access.
    At the initial configuration screen where if you manually configure your connection via ethernet, after putting the desired internal ip, sub net, router and DNS, it should find my domain on the next page where the server would be named. this does not happen, ( this is where i need the help )
    I have a domain name
    fixed external ip with my it pointing to my domain name
    and a RDNS setup with my ISP
    Any help?
    you can email me directly : [email protected]
    many thanks

    If you're running NAT, well, you have some choices on how you might choose to [set up DNS services|http://labs.hoffmanlabs.com/node/1436]. Once you get that sorted, there's a link there to the set-up for the public-facing (outside your external firewall) network configuration, too.

  • Help needed with streaming server

    hello. i work with a firm that provides hosting. one of our
    clients has asked if it was possible to use a streaming server from
    flash. now, to try it out, i've downloaded the trial version for
    the flash media server 2. i've read through the documentation, but
    i still cannot make it do what i want. as an example, i've
    downloaded the 'dynamic playlist' example. i've set it up
    completely as it's said on the site tutorial, yet i cannot connect
    with the server. before you ask, yes, the server is running and the
    application is loaded. the only thing i've really changed in the
    example is the url of the server inside the xml file. when i test
    the flash in flash pro 8, i get the message
    NetConnection.Connect.Failed, no matter what address i use, be it
    localhost, the internal ip address of the firm, or the external ip
    address for access via the net. admitted, i'm not the most
    knowledgable person on flash, but i still need to get that server
    running.
    obviously, my boss wants that server up and running as soon
    as possible. can someone help me to set it up so i can make a
    connection with the server?
    i can be reached at [email protected] thanks in advance to those
    willing to help.

    Hi,
    please try this sample:
    http://www.adobe.com/devnet/flashcom/articles/broadcast.html
    The simplest sample works like this:
    1. Create a subdirectory in your [FMS_HOME] called "tutorial"
    2. Create a subdirectory in tutorial called "streams"
    3. Create a subdirectoy in streams called "video" (or use
    _definst_)
    4. Create a flv file using Flash Video and save it in your
    "video" directory.
    The server structure should look like this:
    [FMS_HOME]
    |------- applications
    ______|---------- tutorial
    ____________|---------- streams
    ___________________|----------- video
    ___________________________|---- videoToPlay.flv
    Now you can play the stream from within your flash
    application.
    The quickest application is created like this:
    1. Create a video instance (right click in "Library" and
    select "new video", name it "video" and make sure it's action
    script controlled. Then pull it onto the stage and make sure you
    give the instance a name, e.g. "myVideo")
    2. Now you need 5 lines of code.
    // a connection
    nc = new NetConnection();
    nc.connect("rtmp://localhost/tutorial/video"); // Important:
    No / (slash) at the end
    // Create stream onto your connection
    ns = new NetStream(nc);
    // Link your display to the stream
    myVideo.attachVideo(ns);
    // myVideo is the name of your video's instance (see above)
    // play the video
    ns.play("videoToPlay");
    // videoToPlay for videoToPlay.flv
    I hope this helps!

  • RC and Windows 2003 Server Security

    How do I get around the security on my 2003 Terminal Server (MetaFrame)
    where I have Remote Control deployed? It's authenticated but will not
    connect to the workstation. It's like the IP is blocked, but why would
    it care about outbound addresses? I'm logged in as admin on both sides.

    Ncoash,
    It appears that in the past few days you have not received a response to your posting. That concerns us, and has triggered this automated reply.
    Has your problem been resolved? If not, you might try one of the following options:
    - Do a search of our knowledgebase at http://support.novell.com/search/kb_index.jsp
    - Check all of the other support tools and options available at http://support.novell.com in both the "free product support" and "paid product support" drop down boxes.
    - You could also try posting your message again. Make sure it is posted in the correct newsgroup. (http://support.novell.com/forums)
    If this is a reply to a duplicate posting, please ignore and accept our apologies and rest assured we will issue a stern reprimand to our posting bot.
    Good luck!
    Your Novell Product Support Forums Team
    http://support.novell.com/forums/

  • Help Needed with Unresponsive Server

    Hi,
    I have a server at a remote location which is fairly unresponsive. It responds to ping but not much else. I need to restart the server but a psshutdown has done very little.
    I have tried a number of tools but I get RPC Server Unavailable or WMI service unavailable.
    Are there any tools out there that can reboot the server without the use of RPC or WMI?
    We have had a numbe of domain controllers falling over of late due to running out of memory and I believe this could be down to a number of agents we rolled out and a memory leak. Is there a remote processor tool out there I can use to view this? I have
    tried a few but agan they tend to use RPC and WMI.
    Your help with this is much appreciated.

    They can probably help you over here with IDRAC setup.
    http://en.community.dell.com/support-forums/servers/
    Regards, Dave Patrick ....
    Microsoft Certified Professional
    Microsoft MVP [Windows]
    Disclaimer: This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.

  • Help needed with OSX Server 10.5.8

    We're running a headless Xserve (RackMac3,1) with OSX Server 10.5.8 that did its job flawlessly.
    Now we want to update the Perl software from 5.8.6 to 5.20.0 or newer. After downloading the suitable version from CPAN we tried to install, but get the following msg:
    Uh-oh, the C compiler 'cc' doesn't seem to be working.
    You need to find a working C compiler.
    Either (purchase and) install the C compiler supplied by your OS vendor,
    or for a free C compiler try http://gcc.gnu.org/
    I cannot continue any further, aborting.
    Is there a way to install the missing tools remotely via the command line (SSH)? A step-by-step recipe would be most welcome.
    - Harald -

    RackMac3,1 is PPC/G5 processor so you are not going to have an easy time with this. Perl 5.2.20 is bleeding edge (OS X 10.10.3 comes with v5.16.3).
    I would leave Apple's installation of Perl, etc. on the server strictly alone and install MacPorts:
         The MacPorts Project -- Home
    and work from there. You aren't likely to get a step-by-step recipe because its not an exercise a rational person would chose to spend time on.
    Have you considered rewriting whatever features in your code require Perl 5.2.20 than to upgrade your server? Or buy a new server, you could probably pick up a Mini for about $200.
    C.

  • Help need in IntergratedWLS server startup problem.

    Hi All,
    Iam using JDeveloper 11.1.1.3.0 and when iam running my integrated WLS 10.3 server getting the following error.
    <Aug 2, 2011 11:59:25 AM IST> <Notice> <Log Management> <BEA-170019> <The server log file C:\Documents and Settings\krishnss\Application Data\JDeveloper\system11.1.1.3.37.56.60\DefaultDomain\servers\DefaultServer\logs\DefaultServer.log is opened. All server side log events will be written to this file.>
    <Aug 2, 2011 11:59:27 AM IST> <Notice> <Security> <BEA-090082> <Security initializing using security realm myrealm.>
    <Aug 2, 2011 11:59:27 AM IST> <Critical> <Security> <BEA-090404> <User weblogic is not permitted to boot the server; The server policy may have changed in such a way that the user is no longer able to boot the server.Reboot the server with the administrative user account or contact the system administrator to update the server policy definitions.>
    <Aug 2, 2011 11:59:27 AM IST> <Critical> <WebLogicServer> <BEA-000386> <Server subsystem failed. Reason: weblogic.security.SecurityInitializationException: User weblogic is not permitted to boot the server; The server policy may have changed in such a way that the user is no longer able to boot the server.Reboot the server with the administrative user account or contact the system administrator to update the server policy definitions.
    weblogic.security.SecurityInitializationException: User weblogic is not permitted to boot the server; The server policy may have changed in such a way that the user is no longer able to boot the server.Reboot the server with the administrative user account or contact the system administrator to update the server policy definitions.
         at weblogic.security.service.CommonSecurityServiceManagerDelegateImpl.doBootAuthorization(CommonSecurityServiceManagerDelegateImpl.java:1009)
         at weblogic.security.service.CommonSecurityServiceManagerDelegateImpl.initialize(CommonSecurityServiceManagerDelegateImpl.java:1050)
         at weblogic.security.service.SecurityServiceManager.initialize(SecurityServiceManager.java:875)
         at weblogic.security.SecurityService.start(SecurityService.java:141)
         at weblogic.t3.srvr.SubsystemRequest.run(SubsystemRequest.java:64)
         Truncated. see log file for complete stacktrace
    >
    <Aug 2, 2011 11:59:27 AM IST> <Notice> <WebLogicServer> <BEA-000365> <Server state changed to FAILED>
    <Aug 2, 2011 11:59:27 AM IST> <Error> <WebLogicServer> <BEA-000383> <A critical service failed. The server will shut itself down>
    <Aug 2, 2011 11:59:27 AM IST> <Notice> <WebLogicServer> <BEA-000365> <Server state changed to FORCE_SHUTTING_DOWN>
    Process exited.
    Please let me know what the root cause of issue and how to solve it.
    Regards,
    Suresh kumar.k

    "User weblogic is not permitted to boot the server;"
    Looks like you have provided the wrong username/password combination.
    - provide the username/password combination, or
    - edit the boot.properties file (located in the ${DOMAIN_HOME}/servers/<server-name>/security
    The second part of the error: "The server policy may have changed in such a
    way that the user is no longer able to boot the server. Reboot the server with
    the administrative user account or contact the system administrator to update
    the server policy definitions."
    Looks like the security environment is a little damaged.
    What you can try to do is delete the ${DOMAIN_HOME}/servers/<server-name>/data/ldap directory.
    OK. Did not see the post by John, who's solution is much much easier. Just follow that one and forget the cr#p posted above.

  • Licensing help needed for datacenter server with vm running windows server 2012 essentials and ten virtual desktops for remote access

    NPO wants to get windows server 2012 r2 datacenter as the main operating system and then windows server 2012 r2 essentials plus 10 windows 8.1 as virtual desktops.  Each desktop for one remote user running office 2013.  Is there a better configuration?
     In either case what licenses does the NPO need to purchase?
    Bob

    Hi,
    For license related questions we recommend you contact Microsoft licensing specialist.
    http://support.microsoft.com/kb/141850/en-us
    Regards.
    Vivian Wang

  • External display resolution help needed - also posted on SL group

    hi
    I bought a DELL 3007WFP 30" LCD monitor in 2007. It worked perfectly with my old MacBook Pro and Tiger and Leopard and in System Preferences > Display gave me options of 1920 x 1200 pixels or 1440 x 900 pixels as well as 1280 x 800 pixels.
    I have recently moved to a new 17" UniBody MacBook Pro with NVIDIA Geoforce 9600GT and 9400GM graphic cards in it (which is fabulous!!) and also upgraded to Snow Leopard.
    Now when I plug in the DELL I get a maximum resolution option of 1280 x 800.
    Whilst this resolution makes the text nice and big for my 43 year old failing eyesight I find it very un-Mac like for this to happen. I have looked here and found a few suggestions eg have been playing with SwitchResX4 and got the 1440 option back in the list BUT when selected the screen goes black.
    2 questions:
    1) What is that has made this problem appear - is it Snow Leopard or the new MacBook Pro and its hardware?
    2) Should I persevere with SwitchResX4or is there another solution?
    best
    Tommy Banana

    To use the full resolution of your 30" monitor, you need a *mini-Displayport to dual-link DVI* adapter:
    http://store.apple.com/us/product/MB571Z/A?fnode=MTY1NDA5OQ&mco=MTA4MzU1ODY

  • Help needed in DataGrid Server Behavior

    Hi,
    I am an average user.
    I am facing problem with ASP DataGrid function. I have tried
    both ways but
    could not succeed in edit/update function.
    I tried to add additional column with "edit update cancel
    button". Later, I
    tried to add one column with the same functions. But it gives
    the following
    error.
    System.Exception: Unsupported TYPE attribute: Integer
    at DreamweaverCtrls.DataSet.GetDbTypeFromString(String str)
    at DreamweaverCtrls.DataSet.OnDataGridUpdate(Object Src,
    DataGridCommandEventArgs E)
    There is one primary key containing unique value for the
    records. But I am
    not trying to update this anyway.
    Any help is very much appreciated
    Thank you
    p.s.: I have sorted this out with MS visual web developer.
    But I do not want
    to change to it for only one function, no matter how crucial
    it is.

    just go through this :
    http://www.adobe.com/cfusion/communityengine/index.cfm?event=showdetails&productId=2&postI d=7262

  • Help needed to generate new target group for contacts from BP Target Group

    In CRM 5.0, we have a functionality in which say we have created a target group (T1) for 10 BPu2019s (organization) and each of these BPu2019s have one or more contact persons associated to them. Now if I want to create a target group for all these contact persons associated to the 10 BPu2019s, in CRM 5.0 I have the option to right click on the target group (T1) and then I get an option u201C generate new target group from contactsu201D. By doing so another target group for all the contacts associated to those BPu2019s will be generated. I am not able to find out the similar option in CRM 2007 (web UI) where in I can create target group for contacts associated to BPu2019s (organization). There should be some work around for this requirement.
    Please let me know how to achieve this requirement.
    Thanks,
    udaya

    Hi udaya,
    we're also using that functionality in CRM 5.0. I think it would be worth a combined OSS message to get this functionality back in standard if it isn't there.
    Best regards
    Gregor

Maybe you are looking for

  • How to tell if RAID is working

    I'm trying to set up a mirror set on our server. I used Disk Utility to create the array (selected the primary disk, chose the RAID tab, dragged the new disk in). It created a RAID slice and says it's online. HOwever, the "RAID set size" says ZeroKB

  • Ipod cannot synchronise

    Hey, I just bought an iPod 30g and I had nothing but trouble. First I had iTunes 7.0 wich said there was an unknown error (-50) and i could not synchronise (or something). Now I have itunes 7.2 which says: The ipod can not be syncronised, the disk ca

  • Trouble reading XML PDF's created in Acabat Professional

    I am attempting to create a PDF that I can post on a website that the user downloads, fills in info then emails to my general email account. Problem is... I can't figure out how to view xml files with windows Explorer 7.0 on a PC. Is there a better w

  • Error in PO Document

    hi Experts, We are on SRM 7.0 Classic scenario. When I try to view the PO's  its giving me the error message 'EBPCLNT300: Type or Role not assigned to the user' . Any clues to get rid of this issue? Please help. Thanks Pratik

  • Default Mail To value in for apexir_EMAIL_TO and apexir_EMAIL_ADDRESS

    I am trying to set the default "To" email address in the Apex 4.0 interactive reports for Email Download and Subscriptions. I have added the following JavaScript code to the "JavaScript.Function and Global Variable Declaration" section of the page de