Object

Name: AAA 
Path: CN=AAA,OU=Finance,OU=Accounting,DC=adscribe,DC=com 
Created: 12/10/2005 
Modified: 02/10/2007 
Original USN: 28748 
Current USN: 79365 
SID: S-1-5-21-2034109091-298619056-3282043246-1137 
GUID: {88B8FCB1-AE3E-4EB1-89FF-6CB86A6F9DBF} 

General

Disabled:  
Type: Normal 
Display name: DisplayName 
First name: FirstName 
Last name: LastName 
Initials: Init 
Description: Decription 
Office: Office 
Telephone:
Telephone(other): telefonnumber2, telefonnumber1 
E-mail: 1@email.com 
Web-page: www.webpage.com 
Web-page(other): www.otherwebpage2.com, www.otherwebpage.com 

Address

StreetAddress: Street 
P.O.Box: BOX 
City: Cyty 
State/Province: State/province 
Zip/PostalCode: zip/postalcode 
Country/Region: Afghanistan 

Account

User logon name: AAA@adscribe.com 
User logon name (pre-Windows 2000): PRE2000 
Primary Group: Domain Users 
Member Of: Account Operators, Backup Operators 
Log on to: pcq,pc1 
Account is locked out:  
User must change password at next logon??:  
User cannot change password:  
Password never expired:  
Store password using reversible encryption:  
Account is disabled:  
Smart card is required for interactive logon:  
Account is trusted for delegation:  
Account is sensitive and cannot be delegated:  
Use DES encryption types for this account:  
Do not require Kerberos preauthentication:  
Account expires:  
Account expiration date: 29/09/2007 

Logon hours

Day 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24
Sun                                                 
Mon                                                 
Tue                                                 
Wed                                                 
Thu                                                 
Fri                                                 
Sat                                                 

Dial-in

Allowed:  
Verify caller ID:  
Calling station ID(s):  
Callback number: 123 
Static ip address: 0.13.222.209 
Static route: qwqqw, wqwqw, 1111 

Profile

Profile path: profilepath 
Script Path: logonscript 
Local path: \\pc1\conecttofolder 
Connect to: W: 

Telephones

Home: home 
Home(other): home2, home1 
Mobile: mobile 
Mobile(other): mobile2, mobile1 
Fax: fax 
Fax(other): fax2, fax1 
IP phone: ipfone 
IP phone(other): ipfone2, ipfone1 
Notes: st: State/province
title: Organization tittle
description: Decription
postalCode: zip/postalcode
postOfficeBox: BOX
physicalDeliveryOfficeName: Office
telephoneNumber: 1
facsimileTelephoneNumber: fax
givenName: FirstName
initials: Init
distinguishedName: CN=AAA,CN=Users,DC=adscribe,DC=com
instanceType: 4
whenCreated: 10/12/2005 23:15:49
whenChanged: 10/13/2005 07:53:08 

Organisation

Title: Organization tittle 
Department: ord department 
Company: org company 
Manager: Administrator 
Direct reports: Administrator 

Remote control

Enabled:  
Require user permission:  
View user session:  
Interract user session:  

Terminal service

Logon allowed:  
Profile path: c:/terminal service user profile 
Home drive: Z: 
Home directory: //pc1/terminalservicepath 

COM+

Partition set: Current provider does not support returning multiple recordsets from a single execution. 

Enviroment

Initial program:  
Start in:  
Connect client drives at logon:  
Connect client printers at logon:  
Default to main printer:  

Session

End a disconnected session: 10 minutes 
Active session limit: 20 hours  
Idle session limit: 1 day 6 hours 30 minutes 
When a session limit is reached or conection is broken: disconnect from session 
Allow reconnection: from originating client only 

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent:  

Security permissions

Trustee Allow Access Inhereted Children
  NT AUTHORITY\Authenticated Users    Read permissions
List a tree of objects
Read the properties
Enumerate an object 
   
  BUILTIN\Administrators    Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
   
  ADSCRIBE\Enterprise Admins    Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
   
  ADSCRIBE\Domain Admins    Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
   
  NT AUTHORITY\SYSTEM    Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
   
  BUILTIN\Pre-Windows 2000 Compatible Access    Read the properties    Remote Access Information 
  BUILTIN\Pre-Windows 2000 Compatible Access    Read the properties    General Information 
  BUILTIN\Pre-Windows 2000 Compatible Access    Read the properties    Group Membership 
  BUILTIN\Pre-Windows 2000 Compatible Access    Read the properties    Account Restrictions 
  BUILTIN\Pre-Windows 2000 Compatible Access    Read the properties    Logon Information 
  BUILTIN\Pre-Windows 2000 Compatible Access    Read permissions
List a tree of objects
Read the properties
Enumerate an object 
   
  Everyone    Extended access rights    Change Password 
  NT AUTHORITY\SELF    Extended access rights    Change Password 
  ADSCRIBE\Cert Publishers    Write the properties
Read the properties 
  UserCertificate 
  BUILTIN\Pre-Windows 2000 Compatible Access    Read the properties    Remote Access Information 
  BUILTIN\Pre-Windows 2000 Compatible Access    Read the properties    General Information 
  BUILTIN\Pre-Windows 2000 Compatible Access    Read the properties    Group Membership 
  BUILTIN\Pre-Windows 2000 Compatible Access    Read the properties    Account Restrictions 
  BUILTIN\Pre-Windows 2000 Compatible Access    Read the properties    Logon Information 
  BUILTIN\Pre-Windows 2000 Compatible Access    Read permissions
List a tree of objects
Read the properties
Enumerate an object 
   
  BUILTIN\Windows Authorization Access Group    Read the properties    TokenGroupsGlobalAndUniversal 
  BUILTIN\Terminal Server License Servers    Write the properties
Read the properties 
  TerminalServer 
Total: 22 security permission(s)

Audit permissions

Trustee Access Inhereted Children Attribute
  Everyone  Modify owner
Write permissions
Write the properties 
     
  Everyone  Write the properties    OrganizationalUnit  GPLink 
  Everyone  Write the properties    OrganizationalUnit  GPOptions 
Total: 3 audit permission(s)

See Also

List of users