ADMGS (Active Directory Management Gateway Service)

There has been some speculation on the web regarding the ADMGS for Server 2008 and 2003, if it would be possible to use it, in an environment without at least one Server 2008 R2.

So I decided to test it, I built a Server 2003 Domain, comprised of a single 2003 R2 Domain Controller, and 1 Windows 7 Enterprise workstation.
I installed Server 2003 into a VM, installed all updates inlcuding SP2, I then ran DCpromo to setup the new domain. When that was complete I downloaded the 2 required patches for 2003, to be able to run ADMGS.
(NDP35SP1-KB969166-x86.exe and 376193_ENU_i386_zip.exe), where the last of the two patches requires registration to download.

When they were installed, I downloaded the ADMGS setup file (Windows5.2-KB968934-x86.exe).
I created a few users, and everything worked fine.

I then built a Windows 7 client, downloaded the RSAT for Win 7 and joined it to the domain. I then ran my Powershell script to enable all RSAT tools on the machine.

The first thing I tried out was the new Active Directory Administrative Center, the new AD manament GUI built on Powershell, it connected to the DC, and I searched for the users I had created, and they showed up **SUCCESS**
I played around with it some more, creating/deleting some users, and everything seemed to work fine, so I tried out the “Active Directory Module for PowerShell”, pulling down some information about users and computers which also worked.

So all in all it seems as if it is not required to have a Server 2008 R2 in you domain/forest in order to use ADWS (Active Directory Web services) in your domain.

So there you have it folks, there are now a full live competitor to the Quest AD cmdlets, which have been around for a while and have let you manage you 2003 AD… Let the fight begin :)

Read More

PowerShell TombStone revival

Our friend Darren Mar-Elia over at SDM software has just released some nice PowerShell cmdlets, to  view Tombstoned objects in AD… You can even revive(or reanimate them as I think the correct AD term is) them as well.. The only requirements are PowerShell (duuh), .Net 2.0 and W2k3 running AD.

I installed it without any problems on a x86 system, but had a few minor problems running it on my 64bit Vista rig, here is what I did to get it working.

Creating an Alias for the .Net installutil, notice the Framework64 here.
[sourcecode lang=”ps”]
set-alias installutil $env:windir\Microsoft.NET\Framework64\v2.0.50727\installutil
[/sourcecode]

I then installed the .dll file manually using the alias I just created above.
[sourcecode lang=”ps”]
installutil -i “C:\Program Files (x86)\SDM Software\SDM Software AD Tombstone Cmdlets\ADTombstones.dll”
[/sourcecode]

Mind you if you are running Vista, the regular user will not have access to “program Files” folder, and you will not be able to register the .dll without running as admin.

I then checked to see if the .dll actually had been loaded

[sourcecode lang=”ps”]
get-pssnapin -registered
[/sourcecode]

I saw that it was succesfully added, I was then ready for the final thing, before I could set out on my revival quest.

[sourcecode lang=”ps”]
add-pssnapin SDMSoftware.PowerShell.AD.Tombstones
[/sourcecode]

Take it for a spin, it is a nice little cmdlet.

Read More