Windows 2008 DC/AD "Unlock Account" problem
our primary dc/ad 2008 server functionality level 2003, , secondary dc/ad 2003 server used replication only.
on 2008 server, if set "unlock account" true, account still locked. in addition, "unlock account" check box value still set false though set true. question is, @ point 2008 server unlock account? assume when value changed (replicated) on 2003 server. i've experienced 1 minute, 5 - 10 minutes.
based on environment, possible unlock account on 2008 server in real time after 1 attempt?
as far can tell, misinterpreting gui in aduc in windows server 2008/2008 r2 - 1 in windows server 2003 aduc. different design - , 1 in windows server 2008/2008 r2 offers improvement
1) windows server 2008/2008 r2 - "unlock account" checkbox available (regardless of status of account).
if label says "unlock account. account locked out on ad dc" local dc recognizes account locked out (obviously) , have option of unlocking it. replicates subsequently other dcs.
if label "unlock account" means domain controller connected recognizes account unlocked. not mean account not locked on other dcs - however have ability unlock same interface checking checkbox , applying change.
2) windows server 2003 - "account locked out" checkbox can cleared if account locked out on domain controller connected to. means you can not unlock it if it's locked out on domain controller corresponding data has not been replicated yet
hth
marcin
Windows Server > Directory Services
Comments
Post a Comment