machine names in ad

  • Thread starter Thread starter John
  • Start date Start date
J

John

back on NT 4 an account had to be created for a machine
and a user. Windows 2k server builds a list of machines.
can someone move a machine account out of the machine
group and log onto the network as if it were a user?
 
Hello John,
Both users and computers are accounts and both can be used for
authentication.

--
Regards
Christoffer Andersson
Microsoft MVP - Directory Services

No email replies please - reply in the newsgroup
 
tell me if I am paranoid. I am seeing a user in the users
folder with a computer's name. the actual computer is in
the domain controllers folder(OU?) so the name is
duplicated. should I be seeing a user and a computer with
the same name? these are not just old NT 4 workstations
that were left over from our upgrade, but windows 2000
server and XP pro machines.

thanks for the help!
 
John,

You are seeing a user account object that resides in the default USERS
container. FYI - you can move any user account object to any Organizational
Unit ( OU ) that you create....By default, all user account objects are
created in this container ( and please notice that I am specifically using
the term 'container' and not OU ). In WIN2000 I am not so sure that you can
change the default location ( please note that there are multiple ways to
create a user account object in another OU....think ldifde or csvde or
scripting, etc. ) but in WIN2003 you can change the default location (
without the need to use ldifde or csvde or scripting, etc ).

Now, you are seeing a computer account object in the Domain Controllers OU
( please note that - out of the box - this is the only OU that you have )
that has the same account name as a user account object? Normally, a
computer account object is appended with the dollar sign ( '$' ) so even if
you have a user account object named 'jsmith' and a computer account object
named 'jsmith' it is really 'jsmith$'. I would be a bit concerned that a
computer account object that is supposed to be a Domain Controller has a
name the remotely resembles that of a user account object. If you open up
the Sites and Services MMC do you see this computer account object listed?
Does it have a sub-folder named NTDS Settings?

HTH,

Cary
 
Back
Top