Archive for the 'PeopleSearch & PeopleUpdate' Category

Active Directory management built for MSPs

We have been getting a ton of traffic lately from MSPs that are becoming more and more frustrated with managing data and accounts in Active Directory and the operational costs associated with this menial task. Most of the administrators have been toying with the idea of actually creating their own web applications to delegate out to their customers, but cannot find the time.

The MSPs that do eventually break down and start looking for existing tools find them to be very complicated for their needs and are priced to meet enterprise needs and not theirs (a per-user model).

We have been hit over the head too many times to not make an attempt to satisfy MSP’s needs, so WebAD is now providing tools specific to the MSP market and priced at a low fixed monthly rate.

Call us to learn more about this offering for MSPs and let us show how we can meet the needs of Active Directory account and data management and meet your pricing expectations. You may also ask us how some MSPs are actually turning our tools into a revenue source as well!

Call me at +1 (800)747-3565 or email me at Steve.denney@webactivedirectory.com for more information.

Web Active Directory released new pricing for its Suite of Active Directory Management solutions

If you have been to our website in the last few months, you will have noticed that we started publishing the pricing for our solutions.  Since that time, we have taken many steps towards making it easier for enterprises of all sizes to evaluate, implement and purchase our Active Directory solutions.

In another step toward that goal, we published a new, and much simpler per-user pricing model that includes monthly subscription pricing.  We feel the subscription pricing will enable our small to medium-sized enterprise customers the ability to purchase our award-winning solutions without the large outlay of cash.  In addition to the new subscription pricing, we have added an unlimited site license for enterprises on the other end of the spectrum.  This way very large enterprises can purchase a perpetual license and never have to worry about “truing” up every year on the number of seats, or users they have added or removed.

Very simple and very different.

We would love to hear your feedback on the new pricing model and we look forward to working with you!

For more information contact us at www.webactivedirectory.com, or call us at (+1) 800-747-3565

Top 3 issues with Identity Management and Active Directory

Web Active Directory has been in the identity management business for over 6 years now and the one thing that we have learned in that time is that there are three critical areas that solutions such as ours need to adhere to, they are:

  1. Security
  2. Security
  3. Security

We hear you loud and clear.  That is why we have built our solutions, PeoplePassword and PeopleUpdate to securely delegate repetitive and costly tasks to end users and business owners.  However, we have not stopped there.  Coming soon, is our new and improved role-based access control (RBAC) on a new, robust platform that will enable customized RBAC for searching, updating, and provisioning of Active Directory objects.  Additionally, we have added the powerful Microsoft Windows Workflow 4 and PowerShell 2.0 to completely automate and customize the business process rules around the way you do business.  No longer will you have to conform your business process to the software, but rather make the software work with your business process.  What a concept – eh!

To learn more about the new platform and when it will be available, or to sign up for our beta program, fill out the following form and we will put you on our notification list. 

In the meantime, please visit our website at www.webactivedirectory.com, or call us toll free at +1-800-747-3565

New PeopleUpdate demostration videos – Web-based, Active Directory Management

Our engineers have created a series of demonstration online videos that provide insight into how PeopleUpdate can be used to delegate active directory updates out to the information and business owners within your organization.  Each video provides a different view of PeopleUpdate through the eyes of a typical end-user, a typical HR-user and a typical IT-user.  Here are the links to the online YouTube videos:

Typical end-user view - 

Typical HR-user view –

Typical IT-user view –

Needless to say, there are many other ways you can configure and customize PeopleUpdate to manage your Active Directory information based on your organizations’ needs.  Please take a look at the videos and let us know if you have any questions or comments.  And remember, you can always request a 30-day evaluation of PeopleUpdate on our website or call us toll free at +1-800-747-3565.

When to use OUs in Active Directory

This has been something that has bugged me for quite a while, when I see environments where Active Directory OU’s have been created to reflect the organization structure, whether that be departments or physical locations, I always wonder why someone would choose this model and if they really understand the features and functions in Active Directory.

When you create an Active Directory OU structure that reflects physical location or departments you have doomed yourself to a life of constant object moves for little or no value.  If you want to see which users are in a particular location or department use the attributes in Active Directory that correspond to those things!  Use a product like PeopleUpdate to allow delegated updates to Active Directory and then when you want to see all users in a particular location or department just perform a quick search of Active Directory.

When someone asks me when they should use or create another OU my answer is for Active Directory security delegation.  In limited cases I can buy in to creating OU’s to support Group Policies or at a very high level to separate normal user and computer accounts from IT/service accounts and computers.  One commonly overlooked feature of Group Policy is the ability to use WMI filtering, Active Directory security groups, and Active Directory Sites to filter when or to whom Group Policy is applied to users.

I’d like to hear from you what you think about this topic too, so post a comment or two.  We would love to hear from you.

For more information contact us at www.webactivedirectory.com, or call us at (+1) 800-747-3565

Active Directory Reporting

Web Active Directory LLC has had Active Directory Reports as a part of our core product for a number of years. In a past career Active Directory Reporting was a big component of our IT audit performed by both internal and external auditors (Sarbanes Oxley reporting).  I continue to be amazed by the amount of information you can get out of reporting on Active Directory for auditing purposes or for just getting a quick view of what’s going on in your IT environment.  LDAP filters can be extremely powerful for Active Directory Reporting just the list of reports below.  Are there some Active Directory Reports that you have been asked for or would like to see?

User Reports

  • Accounts who are managers
  • Accounts with no logon script
  • Accounts with hidden mailbox
  • Disabled accounts
  • Accounts with change password at next logon
  • Accounts never logged in
  • Accounts with dial-in permission
  • Accounts without dial-in permission
  • Accounts with password not required
  • Accounts where password is expired
  • Accounts locked out
  • Accounts who are a member of 100+ groups
  • Accounts created in 2007
  • Accounts created in 2008
  • Accounts created in 2009
  • Accounts created in 2010

Group Reports

  • Groups without members
  • Domain Administrators
  • Enterprise Administrators
  • Administrators Accounts
  • Mail enabled groups
  • Mail enabled groups that are hidden
  • Groups with managers
  • Groups without managers
  • Universal distribution gropus
  • Universal security groups
  • All universal groups
  • Global distribution groups
  • Global security groups
  • All global gropus
  • Domain local distribution groups
  • Domain local security groups
  • All domain local groups
  • Groups with more than 4000 members

Computer Reports

  • Computers that have never logged on
  • Disabled computers
  • Computers that are domain controllers
  • Windows 2000 computers
  • Windows 2003 computers
  • Windows XP computers
  • Windows Vista computers
  • Windows 7 computers
  • Windows 2008 computers
  • Windows 2008 R2 computers
  • Servers
  • Workstations
  • Computers created in 2007
  • Computers created in 2008
  • Computers created in 2009
  • Computers created in 2010

PeopleUpdate and PeopleSearch are two Active Directory tools that provide robust reporting as well as many other benefits to help manage and update you Active Directory environment.  Contact us today at www.webactivedirectory.com

Web Active Directory is at the Texas Computer Education Association (TCEA) 2010

We are at booth 206 of the 2010 TCEA show in Austin, Texas.  Please come by and see a demo of PeopleUpdate and PeoplePassword as we show the Texas Educational world that there is an easier way to manage their Active Directory. 

  • Update Active Directory information
  • Self Service Password reset
  • Active Directory reporting
  • Active Directory Group Management

Come see us at booth 206.  We will be here until Friday!

www.webactivedirectory.com

How to ensure fast queries when searching Microsoft Active Directory

Here’s a great article on MSDN that talks about methods to ensure when you search Active Directory that the results are returned as quickly as possible.  It’s something we refer back to quite often with our customers as well as when we ship new Active Directory reports in our products. 

A healthy Active Directory is a makes a happy administrator!

http://msdn.microsoft.com/en-us/library/aa746526(VS.85).aspx

Add photos to Active Directory

Our PeopleSearch and PeopleUpdate product line has long supported showing photos for a user account in Active Directory. Microsoft has created a PowerShell cmdlet to allow users to upload photos to user accounts in Active Directory.  There are some limitations on size though.

http://blogs.technet.com/ilvancri/archive/2009/11/17/upload-picture-in-outlook-2010-using-the-exchange-management-shell-exchange-2010.aspx

We also support linking an Active Directory account to photos stored on a file share so that you don’t bloat the size of your Active Directory.  I’ll write a later article on how we do that!

PeopleSearch and PeopleUpdate provide (and have for many years) their own web interface to display user photos in your intranet, on the internet, etc.  Here’s an example:

LDAP Filter to find accounts not set to expire in Microsoft Active Directory

In order to show accounts that are not set to expire you will need to use the below LDAP filter.

Accounts that don’t expire:

(&(objectCategory=person)(objectClass=user)(|(accountExpires=9223372036854775807)(accountExpires=0)))

 Accounts that have an expiration date:

(&(objectCategory=person)(objectClass=user)(&(!accountExpires=9223372036854775807)(!accountExpires=0)))

About the accountExpires attribute

Account-Expires Attribute

The date when the account expires. This value represents the number of 100 nanosecond intervals since January 1, 1601 (UTC). A value of 0 or 0x7FFFFFFFFFFFFFFF (9223372036854775807) indicates that the account never expires.

http://msdn2.microsoft.com/en-us/library/ms675098(VS.85).aspx

Next Page »


Slipstick Systems Outlook and Exchange Solutions Center
Utilities, how to's and other solutions for Microsoft Outlook and Microsoft Exchange users, administrators and developers

Share this blog

Facebook Twitter More...

Enter your email address to subscribe to WebActiveDirectory blog via email.

Join 243 other followers


Follow

Get every new post delivered to your Inbox.

Join 243 other followers