DSRAZOR Updates in 2013

Last Update

Description

2013.05.16

DSRAZOR for Windows

[FIX]
Updated services that use the AutoSamName feature to account for specific CN requirements at the time of user creation when there are special characters required in the naming

[FIX]
AD:AUTO:SAMNAME:Rule 1:(use with Display Service "AD:AUTO:SAMNAME..."
Corrected the Manual Entry Selection for these services to enable the browsing of the schema.

2013.05.10

DSRAZOR for Windows

[NEW]
New Button Service added to disable computer objects in Active Directory.

[NEW]
New Button Service to delete profile directory structure, leaving top level.

[NEW]
New Service to increment numerically the SAMaccountName when using the AUTO:SAMNAME rule.

[NEW]
Added the ability to select themes for how you want your DSRAZOR solutions to look. There are five themes to choose from plus you can select if you want rounded buttons, grid lines in listviews, row highlights in listviews, button hover highlight and you can turn icons off in listviews and treeviews.

2013.02.05

DSRAZOR for eDirectory

[FIX]
When looking at "ndsPredicateStats" objects, the "ndsPredicate" attribute will no longer cause a DSRAZOR error.

[UPDATE]
DSRAZOR can now display the "DNIP:Mac Address" attribute.

DSRAZOR for Windows

[UPDATE]
Added a suppressed selection when searching NTFS permissions across multiple shares/folders for a specific object.

2013.02.01

DSRAZOR for eDirectory

[NEW]
This service will display whether or not the eDirectory object has the selected attribute set. The result will appear as TRUE or FALSE. You can designate the eDirectory attribute to use by typing it in to the "Manual Entry Text" box or using the "Search Manual Entry" button to select it. The service is:
"NDS:Display IF Selected Attribute has a value (you choose the attribute to display, TRUE or FALSE will be displayed)"

[NEW]
This service will display whether or not the eDirectory object has the specified string or phrase in their login script. The result will appear as TRUE or FALSE. You can designate the string or phrase to search for in the login script by typing it in to the "Manual Entry Text" box. The service is:
"NDS:Display IF selected value present in Login Script (TRUE or FALSE will be displayed)"

[NEW]
This service will display whether or not there are user objects in the selected container. The result will appear as TRUE or FALSE. The service is:
"NDS:Display IF there are USER Objects in selected container (TRUE or FALSE will be displayed)"

[NEW]
This service will display a count of how many user objects are in the selected container:
"NDS:Display Count of USER Objects in selected container"

[NEW]
This service will display whether or not the eDirectory object has any explicit eDirectory Trustees with Supervisor, Create, Write, Delete, Rename, or AddSelf eDirectory privileges. The trustee may only have one of those privileges assigned, or they may have a combination of those privileges assigned. The result will appear as TRUE or FALSE. The service is:
"NDS:Display IF Object has Trustees with Supervisor, Create, Write, Delete, Rename or AddSelf privileges in their ACL"

[NEW]
This service will list all eDirectory objects that have Supervisor, Create, Write, Delete, Rename, or AddSelf explicit eDirectory privileges to the selected eDirectory object. The trustee may only have one of those privileges assigned, or they may have a combination of those privileges assigned. The service is:
"NDS:List Object's Trustees with Supervisor, Create, Write, Delete, Rename or AddSelf privileges"

[NEW]
This service will display whether or not a directory has files in it. The result will appear as TRUE or FALSE. It only checks the directory itself for files (not the subdirectories beneath). The service is:
"NW:Display IF there are any files in selected path only (no subdirectories)(will display TRUE or FALSE)"

[NEW]
This service will bring up a dialog box that will allow the modification of the Disk Space Restriction for the selected User:
NW:Modify Selected User's Disk Space Restriction in MB (use with NW:List All Users with Disk Space .Services)

DSRAZOR for Windows

[FIX]
Updated the import service to enable "Never Expires" on user objects via CSV.

[UPDATE]
Added functionality to the DSRAZOR for Windows Zero Privilege service to do mass imports of users 'thumbNailPhoto' attribute.

2013.01.20

DSRAZOR for eDirectory

[NEW]
New display service added that can show whether or not the eDirectory object has the attribute "Login Grace Limit" set. The new service is:
"NDS:Display IF Account has Login Grace Limit"

[NEW]
New display service added that can show whether or not the eDirectory object has the attribute "Password Expiration Time" set. The new service is:
"NDS:Display IF Account has Password Expiration Time"

DSRAZOR for Windows

[NEW]
New service added to display group membership by the "name" attribute.
"AD:List Object's Group Membership (show groups belonged to - show value of 'name' attribute)"

2013.01.09

DSRAZOR for Windows

[FIX]
Corrected an issue with the UTC time stamp on the emails sent time.

[NEW]
Added two services for use during user creates when you need to add the attribute " personaltitle" to a user object's common name:

ADr:Edit User's Personal Title to Create - must be used with Button Service: "AD: Create User + Require EDIT Services..."

ADr:Edit User's(Contact) name to Create|"last, first middle personaltitle" format-must be used with Button Service: "AD:Create User(or Contact) + Require EDIT Services...

2013.01.07

DSRAZOR for eDirectory

[UPDATE]
DSRAZOR imports now work regardless of whether or not there is a leading period at the beginning of the user name in the CSV file. For example, you can use either ".jsmith.ou.org" or "jsmith.ou.org" name format in your CSV file.

DSRAZOR Updates in 2012

Last Update

Description

2012.12.20

DSRAZOR for eDirectory and DSRAZOR for Windows

[FIX]
Corrected a problem where EXE applets created with an older version of the Designer opened slowly when they were run. If you have an EXE that is opening slowly, create a new EXE copy of the applet using this new Designer and use the new EXE applet instead.

2012.12.07

DSRAZOR for eDirectory

[NEW]
This new display service can show eDirectory attributes that are images (such as the attribute "photo"). The new service is:
NDS:Display Selected Attribute as IMAGE (you choose the attribute to display, set the bounding box of this display field to size you want for image display)

[NEW]
This new display service can show disk space restrictions in MB (instead of KB). The new service is:
NW:Display User's Disk Space Limit in MB (use with NW:List All Users with Disk Space.Services)

[NEW]
This new display service can show disk space in use in MB (instead of KB). The new service is:
NW:Display User's Disk Space in Use in MB (use with NW:List All Users with Disk Space.Services)

[NEW]
This new display service can show disk space available in MB (instead of KB). The new service is:
NW:Display User's Disk Space Available in MB (use with NW:List All Users with Disk Space.Services)

DSRAZOR for Windows

[NEW]
Added a service to copy group membership (member attribute) from group to group.
AD:Copy selected Object's 'member' (specified by Display Service - RULE:Canonical Name for copy 'member') to selected Objects

2012.10.31

DSRAZOR for Windows

[UPDATE]
Update to the SMTP emailing feature when running a fully automated report with a static output path in place.

[FIX]
Fix when updating already existing users via csv import, when there is a comma in the CN of the object.

2012.10.24

DSRAZOR for eDirectory

[UPDATE]
When displaying login scripts, DSRAZOR now replaces any quotation marks within the login script with apostrophes in the report (because quotation marks can indicate the beginning of a new field in CSV files).

2012.10.22

DSRAZOR for eDirectory

[NEW SERVICE]
Just a checkbox, automatically DISABLE connected button if not checked, and ENABLE if checked (can use this service multiple times for same button)
This is a static check box that if joined to a button is required to be checked before the button is activated.

DSRAZOR for Windows

[NEW SERVICE]
Just a checkbox, automatically DISABLE connected button if not checked, and ENABLE if checked (can use this service multiple times for same button)
This is a static check box that if joined to a button is required to be checked before the button is activated.

[NEW SERVICE]
EMAIL:Last User Created | using manual entry format "addr@mail.com;Subject;Body"
This service is used to email a confirmation of the User which was created. Set the email details in the manual entry field.

[NEW SERVICE]
EMAIL:AD Path of selected object, Prompt user for 'send to' email address, subject and body.
This service is used to email a confirmation of the User which was created. You will be prompted to enter email configuration at runtime.

[NEW SERVICE]
EMAIL:Last User Created | using manual entry format "addr@mail.com;Subject;Body"
This service is used to email a confirmation of the User which was edited. Set the email details in the manual entry field.

2012.10.18

DSRAZOR for eDirectory/GroupWise

[NEW]
This new display service will show the Last Accessed Date for folders/directories on NetWare servers. It shows the date only (not the time). The service is:
NW:Display Folder's Last Accessed Date

[UPDATE]
The DSRRUN.EXE build date is now made visible on the main DSRAZOR Console.

DSRAZOR for Windows

[UPDATE]
The DSRRUN.EXE build date is now made visible on the main DSRAZOR Console.

2012.10.12

DSRAZOR for eDirectory/GroupWise

[FIX]
Link to the DSRAZOR for Windows console made visible from the DSRAZOR for eDirectory and GroupWise console.

2012.09.25

DSRAZOR for eDirectory

[NEW SERVICE]
This new display service can be used as a rule to limit which items are displayed in a list to only show the specific object referenced in a text service on the same screen. For example, there could be an applet where the first part of the applet lists users and allows you to select one user. Then the second part of the applet shows a list of users who have disk space restrictions and information about their disk space usage and restriction. By using this service as a rule, the second list can be limited to show only the specific user who was selected in the first list (instead of showing all of the users who have space restrictions). The new service is:
NDS:Display IF Object being added to list matches currently selected Object (Dynamically obtain OBJECT name from Display Service-Object's Canonical Name-Rule)

DSRAZOR for Windows

[NEW]
Added a new interactive button service to create and populate the profile path in Active Directory.

[UPDATE]
Update to system services to allow for multiple object selections when passing as a parameter(s)

2012.09.14

DSRAZOR for Windows

[NEW]
New button service to delete the contents under a parent home directory for a selected user. This will leave permissions and the AD attribute in place.
AD:Delete Home Directory structure for selected Users(s), leaving top level directory intact (no files)

[NEW]
Added several new services for terminal services attribute settings for user objects via a mass import.

[NEW]
New service to help in the data masking of attributes.
AD:RULE:Data Entry Mask [FIXED ELEMENTS] - Connect to EDIT control requiring Data Mask - enter mask into Manual Entry window

2012.09.11

DSRAZOR for eDirectory

[NEW SERVICE]
This new display service can include more object classes (in addition to the default "User" object class) for the 01, 02, 03, 04, 05, and 06 searches. For example, perhaps you want to know which Users and which Groups have high level effective eDirectory privileges to other objects. The 03 search service already finds Users who have the privileges. You could use this new service as a rule to also include the "Group" object class. If you want to specify multiple object classes, create one rule per each additional object class that will be included in the search. It is not necessary to set a rule for the "User" object class because Users are always included in the 01, 02, 03, 04, 05, and 06 searches. The new service is:
NDS:RULE:Include selected Object Class + "User" Object Class for all "NDS:SEARCH:NN:List All Users." (rule operator OR is implied regardless of actual value)

[NEW SERVICE]
This new listing service will show the protocols bound to an active LAN board:
NW:List Protocols Bound for selected Active LAN Board at Server

[NEW SERVICE]
This new display service will show the channel number for a multi-port LAN board:
NW:Display Active LAN Board Channel Number (if multi-port)

[NEW SERVICE]
This new display service will show what number the selected LAN board is physically. For multi-port NICs the LAN boards will have the same number. The service is:
NW:Display Active LAN Board Number (indicates physical presence, if multiple LAN Boards have same number the NIC is multi-port)

[UPDATE]
You can now list more servers in an applet for where to look for CVMONE.NLM to be loaded. The previous limit was 10 servers, but now you can list at least 16 servers. The following service was updated:
NDS:Server to interact with to change selected NDS attribute via NLM [Allow Multiple Servers]

[UPDATED APPLETS]
The following three applets in the Examine Servers/Disks section have been updated so that they include the new service that lists the protocols bound to an active LAN Board:
"Enterprise File Server Status (All servers)"
"Enterprise File Server Status (Linux only)"
"Enterprise File Server Status (NetWare only)"

2012.08.30

DSRAZOR for eDirectory

[FIX]
Product update to aid in the ability to 'auto move' eDirectory objects with the Novell Client 2.

[NEW]
Added the ability to send a report via SMTP email by right-clicking when the report results are on screen, or by using the Output to File option. The reports that are emailed can be CSV or TXT reports. The email messages can be SSL, TSL, or unencrypted/unsecured.

DSRAZOR for GroupWise

[NEW]
Added the ability to send a report via SMTP email by right-clicking when the report results are on screen, or by using the Output to File option. The reports that are emailed can be CSV or TXT reports. The email messages can be SSL, TSL, or unencrypted/unsecured.

DSRAZOR for Windows

[NEW]
Added the ability to send a report via SMTP email by right-clicking when the report results are on screen, or by using the Output to File option. The reports that are emailed can be CSV or TXT reports. The email messages can be SSL, TSL, or unencrypted/unsecured.

2012.08.27

DSRAZOR for Windows

[NEW SERVICES]
New functionality to view/update an objects thumbnailPhoto attribute in Active Directory.
AD:Set Object's Picture (Thumbnail Photo)
AD: Display Object's Picture (Thumbnail Photo) set bounding box of this display field to size you want for image display

[NEW SERVICES]
New functionality to document where Permissions originated when documenting an ACE's Effective Trustee permissions.
FS:ACE:List [01] Where Permissions Originated for Effective Trustee (use with "FS:List Users(or Groups) by () EFFECTIVE RIGHTS... service")
FS:ACE::List [02] Group Membership(s) for Effective Trustee (use with FS:ACE:List [01] Where Permissions... Service")

[UPDATE]
Updated the console applets: "Effective NTFS Permissions" / "Update User Details"

2012.08.08

DSRAZOR for eDirectory

[NEW]
You can now scan the Tree and create an Object List file without needing to run one of the searches to look for users who have effective file system rights, or who have effective eDirectory Privileges, or who are Console Operators. Then you could edit the Object List file before running one of those user searches. For example, you could remove certain servers from the Object List if you do not need to check for users who have effective file system rights to those specific servers. Then run the effective file system rights search to check for users who have rights to the servers that still remain in the Object List file. The new listing service is:
NDS:SEARCH:00:Build List of All Objects from Root of selected Tree (must use "NDS:FOR 00:01:02:03 OBJECT SEARCH,AUTO RECALL..." service)

DSRAZOR for Windows

[NEW SEARCH SERVICE]
FS:SEARCH File System from selected object for all File System Objects' Trustees (directories only to specified depth
Permits File System Trustee reports to limit scans of subdirectories to a specified depth

2012.08.03

DSRAZOR for eDirectory

[FIX]
The rule "NDS:Display IF Object is Member / Occupant of indicated Organizational Role" has been fixed so it works correctly when used with the service "NDS:SEARCH:END:List All Users found based on the '01,02,03,nn' services combined - must be last service in Treeview or used in Listview".

[FIX]
The following button service has been fixed so it works with the DirXML-Associations attribute:
"NDS:Edit Selected Multivalued Attribute"

[UPDATED APPLET]
Improvements have been made to the "View Home Directory Sizes" applet in the eDirectory User Maintenance section.

DSRAZOR for Windows

[NEW DISPLAY SERVICE]
AD:Display Logon Hours valid for logon by Day of Week
This Display service shows the day/time the User Account has valid logon hours in a single column for each user account. The day format is Sunday through Saturday if logon hours are configured. If Logon Hours are not changed from the Active Directory default settings then "Can Logon at all times, No Restrictions" will be displayed.

[UPDATE]
Product update to fix mailbox size reporting in exchange.

2012.07.20

DSRAZOR for eDirectory

[UPDATE]
The services that show network addresses have been updated so they can now display network addresses that have a URL format.

[UPDATE]
The /tree_override parameter has been updated so when it is used the applet will only look at the objects within the designated Tree, even if the Primary Server or Primary Tree in the Novell client is set to a different Tree. It is needed for a particular type of custom applet if the user running that applet is logged into multiple Trees.

[UPDATED APPLETS]
The following three applets in the Examine Servers/Disks section have been updated so they have more columns to display more network addresses of the servers:
"Enterprise File Server Status (All servers)"
"Enterprise File Server Status (Linux only)"
"Enterprise File Server Status (NetWare only)"

2012.05.15

DSRAZOR for eDirectory

[NEW]
This new display service shows the GroupWise Domain name for the selected object. It is actually reading the first portion of the eDirectory attribute called NGW: GroupWise ID:
"NDS:Display GroupWise Domain for selected object (parses ID value stored in NDS)"

[UPDATE]
DSRAZOR can now display the values for the eDirectory attributes "NDSPKI:Not Before" and "NDSPKI:Not After" in a simple date format.

[UPDATED APPLET]
The applet called "GroupWise Users and their FIDs" now includes a column showing the GroupWise Domain for each user. It also has been updated so you have the choice of either showing the results on screen or sending the results straight out to a file.

2012.05.15

DSRAZOR for Windows

[NEW BUTTON SERVICE]
AD:Create Contact +Require EDIT Services (AD Attrs) on same page[SHOW SUCCESS POP-UP](will create Exchange Acct if EXCH:Display Admin. Group is on same screen)
This Button service creates a user and populates all of the attributes specified in the required Edit Text fields. If at least one such Edit Text field is not populated, the user will not be created, and a popup message appears, stating that all fields must be populated for a contact to be created.

2012.05.08

DSRAZOR for eDirectory

[NEW]
This new listing service "NDS:SEARCH:06:List All Users w/any permissions except [RF] to any path SYS:* except SYS:LOGIN,SYS:PUBLIC on any NCP Server object in selected Tree(to dir depth)" will find all users who have effective File System Rights to directories on the SYS: volume of any server. It will check directories up to the specified directory depth level. It checks most directories on the SYS: volume to the designated depth, but it excludes the SYS:Login directory structure, the SYS:Public directory structure, the SYS:Network Trash Folder directory, and the SYS:ndps/XFER directory.

2012.05.03

DSRAZOR for Windows

[FIX]
Updated installation files to address reporting on mailbox sizes for exchange 2007-2010.

DSRAZOR for eDirectory

[UPDATED APPLET]

The applet called "Count Servers" in the Examine Servers/Disks section of the DSRAZOR Console has been updated so it will not display an extra line in the results about the trial mode when run with a DSRAZOR evaluation token.

[UPDATED APPLET]
The applet called "Enterprise Volume Space Report" in the Examine Servers/Disks section of the DSRAZOR Console has been updated so it has the option of whether to display the results on screen (can select a specific volume to break the space down by user), or to send the results directly out to a CSV file (faster). The applet now also has the choice of selecting Root to search the whole Tree, or selecting a lower container to only search a portion of the Tree.

DSRAZOR for GroupWise

[NEW APPLET]
The new applet called "J.Disable/Enable GroupWise Logins" in the GroupWise section of the DSRAZOR Console allows you to report on as well as change the GroupWise Login Disabled/Enabled Status for the GroupWise accounts in a selected Domain.

[NEW APPLET]
The new applet called "K.Sample GroupWise Helpdesk Applet" in the GroupWise section of the DSRAZOR Console shows how you can delegate GroupWise-related tasks to your helpdesk or other staff members. The applet is an example of delegating user creation, password management, disabling/enabling GroupWise logins, changing address book visibility, managing Distribution List membership, and moving accounts to a different Post Office. The applet can be modified to your organization's specific helpdesk needs.

[UPDATED APPLETS]
The following four applets in the GroupWise section of the DSRAZOR Console have been updated to display the mailbox sizes in both MB and bytes (previously they only showed bytes):
"8.Direct:Document Disk Space Usage"
"8.Document Disk Space Usage"
"9.Direct:Document Disk Space and Quotas"
"9.Document Disk Space and Quotas"

2012.04.20

DSRAZOR for Windows

[FIX]
Updated product file(s) to resolve an issue when importing new users in mass that included the creation of exchange 2003 mailboxes in the process.

[FIX]
Updated product file(s) to resolve an issue when reporting on Universal Group Membership in a multi-domain/child domain environment.

DSRAZOR for eDirectory - CVMONE.NLM

[FIX]
This new version of CVMONE.NLM (version 1.75.17 or 1.75q) fixes a problem where it could not report the DMI Manufacturer, Model, or Serial Number for some NetWare servers.

DSRAZOR for GroupWise

[NEW SERVICES]
Added two new services, one to set login enabled for a selected GroupWise user and another to set login disabled for a selected GroupWise User.
NWGWC:Set Login Enabled for selected GroupWise Account(s)
NWGWC:Set Login Disabled for selected GroupWise Account(s)

[NEW SERVICE]
This new display service can check GroupWise accounts to find if their GroupWise Login Status is set to Enabled or Disabled. This service requires that the appropriate GroupWise Client be installed and functional on the workstation where applets containing this service are used.
NWGWC: Display selected GroupWise User's Login Enabled/Disabled Status (TRUE=isDisabled)

2012.03.16

DSRAZOR for Windows

[NEW SERVICE]
New Button service to unexpire a user's password. If the user has the setting that forces them to change their password on next logon, using this button service on that user will reverse that setting. They will no longer be required to change their password on next logon.

DSRAZOR for eDirectory

[NEW SERVICE]
This new display service can check servers to find which servers have a Last Modified date for a specified file that is less than a certain number of days ago. The file name/location and then the number of days ago are entered into the Manual Entry Text field of the Rule with a pipe character (|) between them.
"NW:RULE:Display IF defined file on the Selected Server was modified less than X days ago"

[FIX]
Corrected a DSRRUN error that occurred in some environments when running applets that use this high-level effective eDirectory privileges scan service:
"NDS:SEARCH:03:List all Users that have any [Sper;Add;Delete;Rename] Entry perms or [Super;Write;AddSelf] Attr perms to any NDS object in selected Tree"

[FIX]
Corrected an issue with applets that have a rule using this following service:
"NW:RULE:Scan defined file on Selected Server for specified string, use pipe to separate file and search string, returns TRUE if found AT BEGINNING OF NEW LINE"

2012.02.29

DSRAZOR for Windows

[FIX]
Corrects a problem encountered when Exchange Enabling user accounts with Exchange 2007 or Exchange 2010 through Zero Privilege.

DSRAZOR for eDirectory

[NEW]
This display service "NDS:RULE:Include ONLY Named Object Class during NDS:SEARCH:03:Admin User Scan (rule operator OR is implied regardless of actual value)" can be used to include only certain object classes in the high level effective eDirectory privileges scan. For example, perhaps you want to know who has high level effective eDirectory privileges to Groups. In that case, you could use this service to include the Group object class by adding it as a rule to the "NDS:SEARCH:03:List All Users that have any [Super;Add;Delete;Rename] Entry perms or [Super;Write;AddSelf] Attr perms to any NDS object in selected Tree" service.

[NEW]
This new display service can check servers to find which servers have a specified string in a certain file at the beginning of that line in the file. The file name/location and then the string to look for are entered into the Manual Entry Text field of the Rule with a pipe character (|) between them.
"NW:RULE:Scan defined file on Selected Server for specified string, use pipe to separate file and search string, returns TRUE if found AT BEGINNING OF NEW LINE"

[FIX]
DSRAZOR will no longer give an error message when running applets that have the data sent directly out to a TXT file but do not have any data to report.

[UPDATED APPLET]
The applet called "Find Users who are Console Operators of the Servers" in the Assess eDirectory Security section of the DSRAZOR Console has been updated so the third button which looks at effective Console Operators now works correctly.

[UPDATED APPLET]
The applet called "eDirectory Partition Status Report" in the Query and Search eDirectory section of the DSRAZOR Console has been updated so you have the choice of either showing the results on screen (which can be refreshed) or sending the results straight out to a file (which can run faster).

[UPDATE]
Improved support for French characters in directory names.

2012.02.02

DSRAZOR for eDirectory

[UPDATE]
Improved support for French characters in directory names.

2012.02.01

DSRAZOR for Windows

[NEW]
Exchange Enable contact objects in Exchange 2007/2010

[NEW SERVICE]
"EXCH2007-2010:Edit Alias of selected AD Account|Service must be on same scrn"(EXCH2007:List All Exchange 2007 ... Mailbox Databases...)"
New Edit service to modify the Exchange Alias for Contact objects and User objects in Exchange 2007/2010.

[NEW SERVICE]
"AD:Do not show RT7 message timeout prompt when modifying objects - place on first page of applet and it will apply to entire applet"
New Text service that allows you to suppress the "Retry" popup that occurs when bulk importing users and the applet encounters a timeout. This new service will force the applet to try every second for up to 65 seconds until the import operation is successful.

[MODIFY]
Some display services that showed a date and time for Active Directory properties were rounding off the values to the nearest minute. With this update, those services will also display the correct seconds as well.

2012.01.31

DSRAZOR for Windows

[UPDATE]
The DSRAZOR for Windows Zero Privilege Console will now force run as administrator when started from a UAC enabled machine.

[NEW SERVICE]
AD:MODIFY:Disable current AD Account and remove Date appended to CN= | if current CN does not end with "_nnnn" format it will be skipped.

This Display service is typically added as a column in a ListView to automatically disable all Active Directory accounts found in a search and to remove any previously appended date-in MMDDYY or DDMMYY format-to the common name (CN=) of the accounts.

2012.01.11

DSRAZOR for Windows

[NEW]
"AD:List Group's Membership (by displayName - if no displayName defined will show LDAP name)"
This Listing service lists all members of the selected Active Directory group. Members are listed by Display Name. If the user object does not have a value for displayName, it will display the object's Distinguished Name (DN).

DSRAZOR Updates in 2011

Last Update

Description

2011.12.30

DSRAZOR for eDirectory

[FIX]
Corrected an issue when running certain applets with multiple container tokens.

[FIX]
Corrected the service called "NW:SEARCH:List All Directories Only on selected Volume (or beginning in selected directory) to specified Depth" so it will now search the specified number of directory levels beneath the starting directory, instead of beneath the root of the volume.

[UPDATED APPLET]
The applet called "Document Trustees by Directory" in the Query and Search eDirectory section of the DSRAZOR Console has been updated so it can search the specified number of directory levels (in this case the default is 4 levels) beneath the selected starting directory, rather than searching 4 levels beneath the root of the volume.

2011.12.13

DSRAZOR for eDirectory

[NEW]
This new display service "NDS:RULE:Exclude Named Object Class from NDS:SEARCH:03:Admin User Scan (rule operator NOT is implied regardless of actual value)" can be used to exclude a certain object class from the high level effective eDirectory privileges scan. For example, perhaps you want to know who has high level effective eDirectory privileges to other objects in your Tree, but you already know that many people in your Tree have privileges to printers. In that case, you could use this new service to exclude the printer object class by adding it as a rule to the "NDS:SEARCH:03:List All Users that have any [Super;Add;Delete;Rename] Entry perms or [Super;Write;AddSelf] Attr perms to any NDS object in selected Tree" service.

[NEW]
This new display service "NDS:SEARCH:03:STOP PROCESSING at specified DayOfWeek:HHMM (where 0=Sun, 1=Mon .. 5=Fri, and HH is 24 hour time and MM is minutes) (5:1900 = Friday at 7pm)" can be used to indicate a day of the week and time when the eDirectory Privilege scan service will be stopped. Scheduling a planned stop of the scan can be useful in large environments where the applet may take a long time to run, to be sure that the scan stops deliberately and cleanly prior to events that would terminate the scan unexpectedly or suddenly.

[NEW]
This new display service "NDS:SEARCH:03:SKIP AHEAD TO USER # (starts at first user if file C:\_USER.IDX is not present)" is necessary if you want to stop the eDirectory Privileges scan at a designated day and time and then restart it again later. This service keeps track of the number of the last user that was processed in the C:\TREE[TreeName]_USER.IDX file. After a scheduled stop of the applet, as long as you leave C:\TREE[TreeName]_USER.IDX file and the C:\ObjectList.TreeName file intact, you can run the applet again later and the scan will pick up where it left off.

[NEW]
This new listing service "NDS:SEARCH:05:List All Users w/any permissions to any path SYS:* except SYS:LOGIN & SYS:PUBLIC on any NCP Server object in selected Tree (specify dir depth)" will find all users who have effective File System Rights to directories on the SYS: volume of any server. It will check directories up to the specified directory depth level. It checks most directories on the SYS: volume to the designated depth, but it excludes the SYS:Login directory structure, the SYS:Public directory structure, the SYS:Network Trash Folder directory, and the SYS:ndps/XFER directory.

[NEW APPLET]
The new applet called "Find Elevated Users (Sample 2)" in the Assess eDirectory Security section of the DSRAZOR Console is an example of how the new service called "NDS:SEARCH:05:List All Users w/any permissions to any path SYS:* except SYS:LOGIN & SYS:PUBLIC on any NCP Server object in selected Tree (specify dir depth)" can be used in an Elevated Users applet.

[UPDATED APPLET]
The applet called "Who has high level effective eDirectory Privileges to other Objects" in the Assess eDirectory Security section of the DSRAZOR Console has been updated to say that if desired, the applet can now be set to exclude specific object classes and/or specific attributes from the eDirectory Privileges scan.

[UPDATED APPLET]
The applet called "Document Trustees by Directory" in the Query and Search eDirectory section of the DSRAZOR Console has been updated to have separate options for NetWare Servers and SUSE Linux Enterprise Servers. For NetWare, the applet searches up to 4 levels beneath the starting directory you select. For Linux, the applet searches up to 4 levels beneath the root of the volume (even if the starting directory for the search is not at the root level). The applet can be modified to search to a different directory depth level, if you would like it to search more than 4 levels deep or less than 4 levels deep.

DSRAZOR for Windows

[NEW SERVICES]
AD:AUTO:SAMNAME:Auto-populate using Rules 1-5(use with Button Service: "AD:Create User + Require EDIT Services...")
AD:AUTO:SAMNAME:Rule 1:(use with Display Service "AD:AUTO:SAMNAME")
AD:AUTO:SAMNAME:Rule 2:(use with Display Service "AD:AUTO:SAMNAME")
AD:AUTO:SAMNAME:Rule 3:(use with Display Service "AD:AUTO:SAMNAME")
AD:AUTO:SAMNAME:Rule 4:(use with Display Service "AD:AUTO:SAMNAME")
AD:AUTO:SAMNAME:Rule 5:(use with Display Service "AD:AUTO:SAMNAME")
AD:AUTO:ALL Attribute Rules 1-5:Make custom built rule result all UPPERCASE (use with Button Service: "AD:Create Users + Require EDIT Services")
AD:AUTO:ALL Attribute Rules 1-5:Make custom built rule result all lowercase (use with Button Service: "AD:Create Users + Require EDIT Services")

[FIX]
Suppressed a popup error on AD trustee reports when an orphaned SID is encountered as a trustee for an AD object.

2011.11.16

DSRAZOR for eDirectory

[NEW]
This new display service "NDS:RULE:Exclude Named Attribute from NDS:SEARCH:03:Admin User Scan (rule operator NOT is implied regardless of actual value)" can be used to exclude a certain attribute from the high level effective eDirectory privileges scan. For example, perhaps you want to know who has high level effective eDirectory privileges to other objects in your Tree, but you already know that everyone in your Tree has write privilege to the specific attribute zenzfdVersion. In that case, you could use this new service to exclude the zenzfdVersion attribute by adding it as a rule to the "NDS:SEARCH:03:List All Users that have any [Super;Add;Delete;Rename] Entry perms or [Super;Write;AddSelf] Attr perms to any NDS object in selected Tree" service.

2011.11.09

DSRAZOR for Windows

[FIX]
Corrected a problem encountered with not setting home directory permissions + ownership when using the Copy User button service in conjunction with using the Zero Privilege service.

2011.10.06

DSRAZOR for Windows

[FIX]
Corrected a problem encountered when using the Copy User button service in conjunction with the "AD:RULE:Force all AD change operations..." service.

2011.10.04

DSRAZOR for eDirectory

[NEW]
This new display service "NDS:FOR 01:02:03 OBJECT SEARCH, RESTRICT SEARCH TO SELECTED CONTAINER PATH" can limit the scope of the "NDS:SEARCH:NN:List All Users..." searches to a specified container (instead of searching the whole Tree). This can be useful if you only need to look at part of a Tree, starting from a certain container and including the sub-containers beneath. Note that if this optional service is used, the search results will be limited to showing only users within the specified container branch who have rights/privileges/etc. to objects that are also within the specified container branch.

[FIX]
Corrected a problem with the path indicators for the service "NW:Modify Existing File System Trustee Assignments for immediate subdirectories of selected directory". Now the applet called "Set File System Rights of All Subdirectories" in the Assess eDirectory Security section of the DSRAZOR Console will work.

[MODIFIED]
The display service previously called "NDS:SEARCH:NN:RECORD Specific Reason user added to '01,02,03,nn' list to file C:\DSRSECURE.TXT", is now called "NDS:SEARCH:NN:RECORD Specific Reason user added to '01,02,03,nn' list to file C:\Tree[(starting container)]DSRSECURE.TXT". The file name will now include the name of the Tree the applet is reporting about, so that customers who have multiple Trees can easily know which file is for which Tree.

[UPDATED APPLET]
The applet called "eDirectory Partition Status Report" in the Query and Search eDirectory section of the DSRAZOR Console now includes a column to show the Partition State.

[UPDATED APPLET]
The applet called "Change selected Multi-Valued Attributes" in the eDirectory User Maintenance section of the DSRAZOR Console now includes the ability to add/remove descriptions.

[UPDATED APPLET]
The three "Enterprise File Server Status" applets in the Examine Servers/Disks section of the DSRAZOR Console now have options for either displaying the results on screen or sending the results directly out to a CSV file. Sending the results directly to a CSV file can be faster, especially in large Trees. Displaying the results on screen can be good if you want to watch the activity changes for a while (for example, the CPU % In Use data refreshes every second).

2011.08.25

DSRAZOR for Windows

[NEW]
"AD:RULE:Force all AD change operations to named Domain Controller (to specify: user "ComputerName")" Use this text service on the first page of an applet to force it to read and commit changes to the Domain Controller specified in the "Manual Entry Text:" field.

[FIX]
"AD:Display logonHours grid for selected User - Allow changes for one or multiple accounts". Fixed a problem that would cause the applet to close unexpectedly when clicking on a button that uses this service. Problem only occurred for users in specific time zones.

2011.08.22

DSRAZOR for eDirectory

[NEW]
This new listing service will find all users who are explicitly/directly assigned as Console Operators of NCP Servers, plus all users who are security equivalent to the Console Operator users, plus if there are Groups that are assigned as Console Operators it will include the members of those Groups. It works with both NetWare and Linux eDirectory servers:
"NDS:SEARCH:04:List All Users (+Sec.Eq to Me Users & Group Members) that are Console Operators of any NCP Server object from Root of selected Tree"

[NEW]
This new display service creates an optional text file C:\DSRSECURE.TXT of the users found by one or more of the NDS:SEARCH:NN:List All Users. services which provides some details about why each user is listed. For example, when searching for Console Operators, the C:\DSRSECURE.TXT file will indicate which server the user is Console Operator for:
"NDS:SEARCH:NN:RECORD Specific Reason user added to '01,02,03,nn' list to file C:\DSRSECURE.TXT"

[FIX]
This new version of CVMONE.NLM (version 1.75.11 or 1.75k) fixes a problem in some environments where if a user is set to "Password Unique Required", when changing their password via CVMONE you would get a "Password Entered is a DUPLICATE of a previous password. Please enter a different password" error message, even if you were using a password that hadn't been already used previously

[UPDATED APPLET]
The applet called "Find Users who are Console Operators of the Servers" in the Assess eDirectory Security section of the DSRAZOR Console has been updated. In addition to the two previous options in the applet (Console Operators organized by Server, and Explicit Console Operators organized by User), there is now a new third option (Effective Console Operators organized by User). The new third option finds the users who are directly Console Operator, plus Users who are Security Equivalent to them, plus members of any Groups that are Console Operators.

2011.07.25

DSRAZOR for eDirectory

[NEW]
This new listing service will show directories and works with both NetWare and Linux eDirectory servers:
"NW:SEARCH:List All Directories Only on selected Volume (or beginning in selected directory)"

[NEW]
This new listing service will show directories, but only to a specified directory depth (such as showing only 2 directory levels deep) and works with both NetWare and Linux eDirectory servers:
"NW:SEARCH:List All Directories Only on selected Volume (or beginning in selected directory) to specified Depth"

[NEW]
This new listing service will show directories and files, but only to a specified directory depth (such as showing only 2 directory levels deep) and works with both NetWare and Linux eDirectory servers:
"NW:SEARCH:List All Directories and Files on selected Volume (or beginning in selected directory) to specified Depth"

[NEW]
This new listing service will find all users who are explicitly Console Operators of any eDirectory servers:
"NDS:SEARCH:01:List All Users that are Console Operators of any NCP Server object from Root of selected Tree"

[NEW]
This new listing service will find all users who have high level effective File System Rights to a specified directory or a specified file on any server. It scans for users who have any combination of Supervisor, Write, Create, Erase, Modify, and AccessControl effective file system rights to the directory or the file on any server. (It excludes users who only have Read and/or Browse file system rights). An applet can use this service once to search only one specified directory/file on all the servers, or an applet can use multiple instances of this service so you can scan the rights to multiple directories/files in the same applet.
"NDS:SEARCH:02:List All Users that have any [S WCEM A] permissions to specified path on any NCP Server object in selected Tree"

[NEW]
This new listing service will find all users who have high level effective eDirectory Privileges to other objects in the Tree. It scans for users who have any combination of Supervisor, Add(Create), Delete, Rename, Write, or AddSelf privileges to other objects. Users who only have those privileges to their own user object (themselves) are excluded from the list.
"NDS:SEARCH:03:List All Users that have any [Super;Add;Delete;Rename] Entry perms or [Super;Write;AddSelf] Attr perms to any NDS object in selected Tree"

[NEW]
This new listing service is used in a TreeView or ListView to show the results found by the new "NDS:Search01...", "NDS:Search02...", and "NDS:Search03..." services documented above. Although the service title only mentions TreeViews, the service could actually be used in a ListView instead.
"NDS:SEARCH:END:List All Users found based on the '01,02,03' services combined - must be last service in Treeview"

[NEW]
This new display service is used to indicate where to save the Object List file that DSRAZOR creates when doing the scans in the new "NDS:Search01...", "NDS:Search02...", and "NDS:Search03..." services documented above. The extension of the Object List file will be the name of the Tree. Re-using the same Object List file for future runs of the applet will save time. However, re-using the file for future runs of the applet means that any objects that were newly added to the Tree after the Object List file was initially created will NOT be included in subsequent reports. If when you run the applet again in the future you want it to scan ALL objects including any newly added objects (such as new users created recently), be sure to delete any old Object List files before you re-run the applet. If you want DSRAZOR to save the Object List file for future use, be sure to indicate a valid path for the Object List file. If you prefer to NOT save Object List files for future use (so a new up-to-date Object List is created each time you run the applet), simply indicate an invalid path for the Object List file. By specifying a path that does not exist, DSRAZOR will not be able to save the Object List file for future use.
"NDS:FOR 01:02:03 OBJECT SEARCH, AUTO RECALL NDS OBJECT FROM PREDEFINED FILE (WILL AUTO APPEND TREE NAME)"

[NEW]
This new display service can display all of the values of a multi-valued attribute in the same cell/box in a ListView. The data will show a pipe character (|) as a separator between the different values of the attribute.
"NDS:Display all values of selected multi-valued attribute, use pipe (|) symbol as value separator"

[NEW]
This new display service can check servers to find which servers have a specified string in a certain file. The file name/location and then the string to look for are entered into the Manual Entry Text field of the Rule with a pipe character (|) between them.
"NW:RULE:Scan defined file on Selected Server for specified string, use pipe to separate file and search string, returns TRUE if found"

[NEW]
This new display service can check NetWare servers to find which servers have a specific NLM loaded. The name of the NLM to look for is entered into the Manual Entry Text field of the Rule.
"NW:RULE:Display IF selected NLM Name is currently loaded on the Selected server"

[NEW]
This new display service can check servers to find which servers have a Last Modified date for a specified file that is more than a certain number of days ago. The file name/location and then the number of days ago are entered into the Manual Entry Text field of the Rule with a pipe character (|) between them.
"NW:RULE:Display IF defined file on the Selected Server was modified more than X days ago"

[UPDATE]
This listing service has been updated to accept items dragged from a ListView or a TreeView. Because you can now drag them from a ListView, you can select multiple users/groups or all/users groups (instead of previously where users/groups could only be dragged one at a time from a TreeView).
"FILE:List Derivation of Trustee Assignments for Drag and Dropped Users + Directories/Files"

[NEW APPLET]
"Find Elevated Users (sample)" is a new applet in the Assess eDirectory Security section. The applet scans the Tree to find Elevated Users, based on sample criteria. The applet currently finds users who have any combination of the following:
- High Level effective eDirectory Privileges (Supervisor, Create, Rename, Delete, Write, AddSelf) to other objects in the Tree (not themselves)
- High Level effective File System Rights (Supervisor, Write, Create, Erase, Modify, AccessControl) to the SYS:SYSTEM directory or the SYS:APACHE directory, or the SYS:APACHE2 directory
- Explicit assignment of Console Operator of any server If your criteria for determining Elevated Users is different than what is listed above, it may be possible to change the applet accordingly. One example is that if you are not concerned about Console Operators, that part can be removed from the applet completely. Another example is that the applet could check for who has high level effective file system rights to other directories or additional directories (such as SYS:ETC or DATA:FINANCE). Although some of the directories mentioned here are typically found on NetWare Servers, the applet could also be used to look at directories on NSS volumes of SUSE Linux Enterprise Servers.

[NEW APPLET]
"Find Servers that have a Specific NLM Loaded" is a new applet in the Examine Servers/Disks section. The applet checks each NetWare server to see if a specific NLM is currently loaded or not. DSRAZOR's optional CVMONE.NLM is used as an example, but the applet can be modified to look for a different NLM instead.

[NEW APPLET]
"Find Servers where a Specific File was Last Modified more than X Days Ago" is a new applet in the Examine Servers/Disks section. The applet checks each server to see if the SYS:ETC\HOSTS file was modified more than 30 days ago. This is just an example of this type of applet - the applet can be easily changed to check the Last Modified date of a different file and/or to look for a different number of days ago. Although the example file mentioned here is typically found on NetWare Servers, the applet could also be used to look at files on NSS volumes of SUSE Linux Enterprise Servers.

[NEW APPLET]
"Find Users who are Console Operators of the Servers" is a new applet in the Assess eDirectory Security section. The applet has two options for showing explicit Console Operator assignments - one method organizes the report by User, and the other method organizes the report by Server.

[NEW APPLET]
"Objects (all) with NDS S, C or W Rights" is a new applet in the Assess eDirectory Security section. The applet finds all eDirectory objects that have explicit Trustees with Supervisor or Create or Write privileges to other objects in the Tree. It shows the eDirectory privileges assigned and also shows who is security equivalent to the objects that have the Supervisor or Create or Write privileges.

[NEW APPLET]
"Search for a Specific String in a Certain File on All Servers" is a new applet in the Examine Servers/Disks section. The applet checks each server to see if the SYS:SYSTEM\AUTOEXEC.NCF file contains the string "LOAD RCONAG6". This is just an example of this type of applet - the applet can be easily changed to search for a different specific string within a different designated file. Although the example file mentioned here is typically found on NetWare Servers, the applet could also be used to look at files on NSS volumes of SUSE Linux Enterprise Servers.

[NEW APPLET]
"Who has high level effective eDirectory Privileges to other Objects" is a new applet in the Assess eDirectory Security section. The applet scans the Tree to find users who have any combination of the following:
- High Level effective eDirectory Privileges (Supervisor, Create, Rename, Delete, Write, AddSelf) to other objects in the Tree
The applet does not include users who only have privileges to themselves nor users who only have low level (Read, Compare, Browse) privileges to other objects.

[NEW APPLET]
"Who has high level effective File System Rights to a specific Directory" is a new applet in the Assess eDirectory Security section. The applet scans the Tree to find users who have any combination of the following:
- High Level effective File System Rights (Supervisor, Write, Create, Erase, Modify, AccessControl) to the SYS:SYSTEM directory
The SYS:SYSTEM directory is an example, the applet could be changed to look for a different directory. Although the directory mentioned here is typically found on NetWare Servers, the applet could also be used to look at directories on NSS volumes of SUSE Linux Enterprise Servers.

[NEW APPLET]
"User Information Report" is a new applet in the Query and Search eDirectory section. The applet shows users and information about them - full name, department, title, location, email address, last login, eDirectory status, phone numbers, fax numbers, group memberships, security equivalences, and descriptions. If there is more than one value for the attribute, the values are separated by a pipe character (|). This applet gives useful information about users and also illustrates how DSRAZOR can now show multiple values of the same attribute in the same box of a ListView - this particular format is a new option. The applet can be modified to show other eDirectory attributes of the users if you want to see different or additional attributes in the report.

[UPDATED APPLET]
The applet called "Document Effective File System Rights" in the Assess eDirectory Security section has been updated. One change to the applet is that you can drag and drop multiple users/groups or all users/groups in Step 3 (previously you could only drag and drop one user or group at a time). Another change to the applet is that it is now set to search only two directory levels deep for both NetWare servers and SUSE Linux Enterprise Servers. The directory depth can be set to a higher amount if needed, but scanning more directory levels will take the applet longer to run.

[UPDATED APPLET]
The applet called "Who has access to a specific File" in the Assess eDirectory Security section has been updated. It now has two options for looking at effective file system rights for a specific File. the first method will show only the list of users who have HIGH LEVEL effective file system rights (S WCEM A) to the file on any server. The second method will show users who have ANY effective rights (SRWCEMFA) to the file, plus it will also show what rights they have. SYS:SYSTEM\AUTOEXEC.NCF is an example, the applet can be changed to look at rights to a different file instead. Although the example file mentioned here is typically found on NetWare Servers, the applet could also be used to look at files on NSS volumes of SUSE Linux Enterprise Servers.

[UPDATED APPLET]
The applet called "Find Directories with an Inheritance Filter" in the Examine Servers/Disks section has been updated. One change is that there is now just a single applet for both NetWare servers and SUSE Linux Enterprise Servers (previously there were separate applets for different server platforms). Another change to the applet is that it is now set to search only three directory levels deep for both NetWare servers and SUSE Linux Enterprise Servers. The directory depth can be set to a higher amount if needed, but scanning more directory levels will take the applet longer to run.

[UPDATED APPLET]
The applet called "Document Trustees by Directory" in the Query and Search eDirectory section has been updated. The applet is now set to search only four directory levels deep for both NetWare servers and SUSE Linux Enterprise Servers. The directory depth can be set to a higher amount if needed, but scanning more directory levels will take the applet longer to run.

2011.06.24

DSRAZOR for eDirectory - CVMONE.NLM

[NEW]
CVMONE.NLM version 1.75.10 (or higher) can be used to allow helpdesk staff to create new groups without giving the helpdesk staff elevated privileges.

[FIX]
CVMONE.NLM version 1.75.10 now correctly sets values for the following attributes during user creation - Login Grace Limit, Login Maximum Simultaneous, Password Expiration Interval, and Password Minimum Length.

2011.06.15

DSRAZOR for Windows

[FIX]
Corrected an issue with updating existing users to create a "Random Password".

2011.06.02

DSRAZOR for eDirectory

[FIX]
Corrected an issue with container licenses.

2011.05.25

DSRAZOR for Windows

[UPDATE]
Edit fields with pre-defined values now accept values larger than 64 characters.

Increased performance for Active Directory searches.

[NEW]
Added two new button services to search for computers:

"AD:Search for any COMPUTER object by Name beginning at selected Container or DNS Domain Root (auto append '*')"

"AD:Search for any COMPUTER object by Name beginning at selected Container or DNS Domain Root (auto append '*') [Clear Previous Results]"

DSRAZOR for eDirectory

[NEW]
This listing service will show the size of a directory (including subdirectories) by using a Quick Scan method. This new service is faster than DSRAZOR's other more comprehensive directory size services, however, it is less accurate and should only be used if an approximate size value is sufficient for your reporting needs.
"NW:List Size of Directory + all Subdirectories [Quick Scan]"

2011.05.19

DSRAZOR for eDirectory

[FIX]
Corrected an issue with a directory information custom applet so it now completes successfully.

2011.04.27

DSRAZOR

[NEW]
When using DSRAZOR to pass a parameter to an EXE, if your parameter string includes spaces use this new button service:
"RUN: Specific File (EXE or other 'executable file) - Pass as a parameter, the connected display item (separately passes executable and parameters)"

2011.04.22

DSRAZOR for Windows Zero Privilege Help Desk

[FIX]
Corrected a problem in name resolution when running the agent on a 2008, 32-bit server. Zero Privilege enabled applets should no longer give error message "0x8007203B".

DSRAZOR for eDirectory

[UPDATED APPLET]
The "Disk Space in use, Files Owned/Unowned" applet has been updated to replace the "bytes" labels with "KB".

[UPDATED APPLETS]
The following applets have been updated to give you the choice of whether to run them from a specific Container or the whole Tree:
"Enterprise File Server Status (All servers)"
"Enterprise File Server Status (Linux only)"
"Enterprise File Server Status (NetWare only)"

2011.04.19

DSRAZOR for Windows

[FIX]
DSRAZOR for Windows now allows population of Boolean and Integer attributes using pre-defined values field.

[FIX]
Corrected a problem with the Output To File display on the Effective File System Permissions report. The problem only seemed to occur if the file system objects had several orphaned permissions assigned to it.

DSRAZOR for eDirectory

[FIX]
Corrected a problem with the entry stamps for NDPS print jobs were off by one hour with the service:
"NWNDPS:Display Print Job's entry into Queue".

[FIX]
Eliminated token errors from the last part of the "Enterprise Volume Space Report" applet (the view that shows the selected volume's disk space by user).

[FIX]
Corrected a problem where sending to multiple NetWare servers gave a W34 error when using the "Send Commands to Servers without RCONSOLE" applet.

[UPDATED APPLET]
The "Send Commands to Servers without RCONSOLE" applet has been updated to make it easier to select multiple NetWare servers or all of your NetWare servers.

2011.03.15

DSRAZOR for eDirectory

[FIX]
Corrected a directory name issue with the applet "Document Trustees by directory" (TRBYDIR4.DSR) on a Windows 7, 64bit OS.

2011.03.14

DSRAZOR for Windows Zero Privilege Help Desk

[FIX]
Corrected an issue encountered when using the copy user button service through zero privilege without the "Preferred DC" defined. The copy user button service now works fine without a Preferred DC defined.

DSRAZOR for eDirectory

[FIX]
Corrected an issue with the eDirectory Partition Status report when running with Windows 7.

2011.02.21

DSRAZOR for Windows Zero Privilege Help Desk

[FIX]
Corrected an issue with the "Who can use DSRWZP" configuration where allowed groups would stop being allowed to use ZP after a period of time in certain situations.

2011.02.16

DSRAZOR for Windows

[NEW]
Applet "List Local Group membership (OTF)"
[LocalGroupMembership_OTF.dsr]
This applet will document the members of all local groups on selected workstations or servers.

2011.01.25

DSRAZOR for Windows

[NEW]
Button service "AD:Copy selected Object's 'memberOf' (specified by Display Service - RULE:Canonical Name for copy 'memberOf') to selected Objects".
Display service "AD:RULE:Display Object's Distinguished Name (Canonical Name)(Specifies Source Object to copy its 'memberOf' attribute)"
These new services allow you to copy the group membership from one selected Active Directory object to another selected Active Directory object.

[NEW]
Applet "Copy Group Memberships"
[CopyGroupMembership1.dsr]
This new applet demonstrates how to copy group membership from one object to another object. The drilldown method can be simplified and modified to meet individual needs.

[UPDATE]
Applet "User Account Password Reset and Unlock - Helpdesk"
[hd_pwdr2b.dsr]
Renamed button face from "Reset Intruder Lockout" to "Unlock Account".

[UPDATE]
Applet "User Account Password Reset and Unlock - Helpdesk - Specify Containers"
[hd_pwdr3b.dsr]
Renamed button face from "Reset Intruder Lockout" to "Unlock Account".

2011.01.19

DSRAZOR for Windows

[NEW]
"[OTF]RECEIVE Merged items in connected Treeview into single list item - connect to service "Merge items...""
"[OTF]SEND Expanded & Merged items in same Treeview as this service - place this service as last root level item-select number of levels to process:range:1 to 3" These two new services allow you to format the output of a TreeView to look more like a ListView when exporting the data out to file.

[NEW]
Four new import keywords to move home directory contents (folders and files) to new location when updating the home directory path attribute on import from CSV. This will facilitate doing bulk home directory moves.,
These two keywords will move the the home directory data to the new location and delete the files in the old location:
"_Move Home Directory"
"_Move Home Directory SAMNAME"
These two keywords will copy the home directory data to the new location:
"_Move Home Directory NO DELETE"
"_Move Home Directory SAMNAME NO DELETE"

[NEW]
"AD:Edit User's UPN @Domain (will change to be an auto-populated dropdown)"
"AD:Edit User's UPN Logon Name (if @Domain not used will use default)"
These two new edit services for updating existing user objects work similarly to the existing UPN (userPrincipalName) edit services for use when creating new user objects. Previously when you wanted to modify the value for userPrincipalName on an existing user object, you needed to enter the entire value for the attribute in the edit field (such as BSmith@MyCompany.local). These new edit fields break the attribute down into separate prefix and suffix edit fields so that you can modify only a portion of the UPN if you would like.

[NEW]
Local User Reporting and Management We have added several new services to augment our existing local user services to allow additional reporting and management of local user accounts.
-Button Services-
"NT:Change Local User's Password across selected Servers/Workstations (local user manually specified at runtime)"
"NT:Change Local User's Password for selected local user (user selected from list of local users)"
"NT:Delete selected Local User Account(s)"
"NT:Disable selected Local User Account(s)"
"NT:Enable selected Local User Account(s)"
"NT:Unlock selected Local User's Account"
"NT:Remove Member(s) from list of Local Group Membership"
-Display Services-
"NT:Display IF selected Local User's Account is Locked"
"NT:Display User Account's Last Logon"

[NEW]
Applet "Local Account Password Reset - bulk - to all selected computers"
[LocalPasswordResetBulk.dsr]
Change the password for specified local account that exists across several computers. This can be useful for updating the passwords for service accounts that exist locally on several computers.

[NEW]
Applet "List Local User Accounts (alternate formatting) OTF"
[ListLocalUserAccounts_OTF1.dsr]
This applet uses the two new OTF Send and Receive services. It demonstrates formatting TreeView data for multi-valued data into a ListView or tabular format."

[NEW]
Applet "Local User Management"
[LocalUserManagement.dsr]
Manage local computer accounts (change password, unlock, enable, disable, delete, remove members from local groups).

[NEW]
"AD:Remove 'User cannot change password' on selected Active Directory user(s) (users will be able to change password)"
"AD:Set 'User cannot change password' on selected Active Directory user(s) (users will not be able to change password)"
These new services allow you to manage the "User cannot change password" setting on selected Active Directory accounts.

[NEW]
"AD:Set "Password never Expires" for selected Active Directory User Account(s)"
This new button service will set the flag in the userAccountControl attribute so that the "Password never Expires" on selected Active Directory accounts.

[NEW]
Applet "Password Security Settings for User Accounts"
[PasswordSettingsAD.dsr]
Manage password security settings for Active Directory user accounts.

[NEW]
Added 24 new "AD:AUTO..." services for autopopulating attributes on user creation. Previously you could use the set of 6 auto-populate services to populate the value of an attribute based on values that were entered for other attributes. For example, you could set the displayName attribute to [last, first] if the applet user entered the first name and last name on the user creation form. We have added 4 more sets of these services so now you can auto-populate up to 5 attributes when creating a new user.
Below are listed 6 (one set) of the 24 added services.
"AD:AUTO:1:Attribute Name - Auto-populate using Rules 1-5(use with Button Service:
"AD:Create User + Require EDIT Services...")"
"AD:AUTO:1:Rule 1:Attribute Name - (user with Display Service "AD:AUTO:Attribute Name...")
"AD:AUTO:1:Rule 2:Attribute Name - (user with Display Service "AD:AUTO:Attribute Name...")
"AD:AUTO:1:Rule 3:Attribute Name - (user with Display Service "AD:AUTO:Attribute Name...")
"AD:AUTO:1:Rule 4:Attribute Name - (user with Display Service "AD:AUTO:Attribute Name...")
"AD:AUTO:1:Rule 5:Attribute Name - (user with Display Service "AD:AUTO:Attribute Name...")

[NEW]
"AD:Search for any USER object by Name beginning at selected Container or DNS Domain Root (auto append '*')"
"AD:Search for any USER object by Name beginning at selected Container or DNS Domain Root (auto append '*')[Clear Previous Results]"
These two new button services behave similarly to the existing search button services. The difference is that these automatically append an '*' to the end of the search string. With the existing services, if you were searching for "Darin Smith" you might enter "Darin*" into the search field. With the new search button services you could just type "Darin" into the search field.

[NEW]
Import computer objects from CSV file.
Button service "AD:IMPORT:Mass Active Directory OBJECT Create, SPECIFY [Object Class in Manual Entry] - use with "Receive CSV file service" can now accept a value of "computer" for the import object class.
Display service "AD:IMPORT:AUTO_CREATE:Mass Active Directory OBJECT Create, SPECIFY [Object Class in Manual Entry] - use wth a "AUTO_CREATE receive CSV file service" can now accept a value of "computer" in the Manual Entry text field for automatically importing computer objects.

[NEW]
Applet "Import Computers + Attributes from CSV File"
[import_computer.dsr].
Applet "Import Computers + Attributes from CSV File (Automated)"
[import_computer_auto.dsr].
Sample import CSV file [import_computer.csv].
These two new applets allow you to import computer accounts from a CSV file.

[NEW]
"AD:Edit selected Object's Home Directory Path appending CN - use predefined values"
"AD:Edit selected Object's Home Directory Path appending SAMNAME - use predefined values"
These two new edit text services allow you to pre-specify some potential home directory locations in a dropdown list. You can then select the desired value in the dropdown list to edit the home directory location for the selected user. First it will update the homeDirectory attribute for the user in Active Directory. Second, it will create a folder for the user in the new location and set the permissions on the folder for the user. It will leave the files and contents of the old home directory in place, it does not move or copy files. We have found that it is better to use Windows Explorer to move or copy the files because it will allow you to make decisions about what to do with problem files during the move/copy process. You will need to use these new edit text services with an "Apply Changes" button.

[NEW]
"ADr:Create Home Directory Path using CN:for use during Create User + Req'd attr.(specify full UNC path such as "\\FS1\share\path")"
"ADr:Create Home Directory Path using SAMNAME:for use during Create User + Req'd attr.(specify full UNC path such as "\\FS1\share\path")"
These two new edit text services allow you to pre-specify some home directory locations in a dropdown list. You can then select the home directory location when creating a new user. You will need to use these new services with a "Create User" button.

[UPDATE]
"AD:List Group's Membership (by full AD/LDAP name)". This service will now successfully resolve group members that show up as Foreign Security Principals in the current domain because they are users from a trusted domain in another forest. Instead of showing the SID of the member from another forest, it will perform lookups to successfully display the full Distinguished Name of the user.

[UPDATE]
Corrected Output To File so that it would fully expand a multi-level TreeView in a file system permissions report. In a few specific cases it would only expand the TreeView output a few levels deep.

[UPDATE]
Modified how DSRAZOR determines whether an Active Directory account is locked out or not. It will now properly consider accounts that were "effectively" unlocked by a Group Policy Object (GPO), but still had a timestamp value present in the lockoutTime attribute. It will perform a calculation based on the value in the lockoutTime attribute, the current date and time, and the "Account lockout duration" specified in the Group Policy Objects applied to that user to determine if the user has been "effectively" unlocked by the GPO.

[UPDATE]
Removed a benign popup message that occurred when using a button service to view files in a directory. The popup only occurred if you used specific services linked in a very specific way. It was discovered by a customer who created a custom applet that connected services in an unusual way. Since the applet gave the correct results, this update does not change the results, it only removes the popup message.

[UPDATE]
"AD:Move selected Object(s) (Container to move to must be specified with Display Service - Canonical Name for Move Operation)"
We discovered that in certain circumstances, not all selected objects were being moved to the new OU/Container. Only half of the selected objects were being moved (every other one). This update fixes that problem.

[UPDATE]
"NT:Change Local Administrator User Account's Password for selected Servers/Workstations (RID=500)"
This button service will now accept passwords up to 30 characters in length. This has been increased from the previous limit of 14 characters. The increased 30 character limit has also been used in the new local password reset button services that are being released with this new update.

[UPDATE]
When Exchange enabling a contact object or a group object that has already been Exchange enabled; DSRAZOR will now display a popup indicating that the object is already Exchange enabled. (This update applies to Exchange 2000/2003 services)

[UPDATE]
"AD:Expire selected Active Directory user's password (requires users to change password at next logon)"
"AD:Assign Single-User Password for selected Active Directory User Account(s) {Must change password at next logon}"
"AD:Assign Single-User Password for selected Active Directory User Account(s) {Must change password at next logon} + Remove PwdNotRqd/Disable"
Added some "checks" to these button services. DSRAZOR will prevent you from successfully using these button services against a user account if the user is flagged with "User cannot change password". If you try to use one of those button services, DSRAZOR will now display a popup explaining the operation cannot be completed because the account is flagged with "User cannot change password".

[UPDATE]
Updated "User Account Password Reset and Unlock - Helpdesk" applet [hd_pwdr2b.dsr] to use new button search service that automatically appends '*' to the end of the search string.

[UPDATE]
Renamed "User Password and Intruder Lockout Reset Helpdesk" applet to "User Account Password Reset and Unlock - Helpdesk" in the Console.
Renamed "User Password and Intruder Lockout Reset Helpdesk - Specify Containers" applet to "User Account Password Reset and Unlock - Helpdesk - Specify Containers" in the Console.
Renamed "Local Admin Password Reset" applet to "Local Admin Password Reset - bulk - to all selected computers" in the Console.

[UPDATE]
Updated "Accounts with Password problems" applet [adpwdp3.dsr] to include new button service to "Remove 'User cannot change password' setting from selected objects".

[UPDATE]
Updated "AD:Display if selected User's Password is Expired" service to show the password is expired if the setting is present in the userAccountControl attribute or if the pwdLastSet attribute has been cleared. Previously the service relied on the flag in userAccountControl attribute being set.

[UPDATE]
"ADr:Edit New Account's selected Attribute and only allow predefined values to be entered - must be used with Button: "AD:Create User|Contact + Require..."
You can now use this edit text service with pre-defined values to assign a value to the userAccountControl attribute during user creation. This is a bitfield attribute in Active Directory that controls many important settings on user objects. Now you can automatically assign those settings by using a predefined value and setting it as the default value. This was added to fulfill a customer request to automatically set "password never expires" on all new user accounts.

[UPDATE]
Made enhancements to some security options in the Zero Privilege Server Agent configuration. When you specify a group to be "protected" from any changes initiated by Zero Privilege enabled applets, it will now consider nested groups and members of the specified group to be "protected". Also, when you specify a group of authorized users that can use Zero Privilege enabled applets, it will now consider nested groups and members of the specified group.

[FIX]
Modified the OTF alignment when populating group members of a documented group that has permissions

DSRAZOR for eDirectory

[NEW]
New button service allows you to delete whole directory structures, including subdirectories and files:
"NW:Delete Selected Path (all folders and files)"

[NEW]
New button service allows helpdesk staff to delete eDirectory objects via CVMONE.NLM:
"NDS:Delete Object with Prompt via NLM"

[NEW]
Two new button services for changing Directory Space Restrictions in MB (instead of KB):
"NW:Modify Selected Directory's Space Restriction in MB (use with NW:List ALL Selected Volume's Directories from current...)"
"NW:Modify Selected Directory's Space Restriction in MB via NLM (use with NW:List ALL Selected Volume's Directories from current...)"

[NEW]
New display service to show Directory Space Restrictions in MB (instead of KB):
"NW:Display Directory's Space Restriction in MB (use with NW:List ALL Selected Volume's Directories from current...)"

[NEW]
New button service for removing group membership via CVMONE.NLM:
"NDS:Remove User from selected Group via NLM (use when viewing Groups a User belongs to)"
Note: the "NDS:Server to interact with to change selected NDS attribute via NLM" text service must be used on the same screen.

[NEW]
New button service for moving eDirectory objects to a different container:
"NDS:MOVE:Move selected eDir/NDS Account(s) to Container designated by 'MOVE' display service"
Note: the new "NDS:MOVE:Display selected Container - will be used as the destination eDir/NDS account moves" text service must be used on the same screen.

[NEW]
You can now add users into Auxiliary Object Classes and also populate the attributes associated with the Auxiliary Classes when doing a CSV import. The new service for adding the Auxiliary Class is:
"NDS:Receive value from runtime-selected CSV file for the selected NDS Auxiliary Object Class for Mass Create - use manual entry to select"

[NEW]
Now when you delegate management of group membership to others, you could limit their view to see only the groups which they personally own. The new service is:
"NDS:Search for Groups owned by the current user beginning at a predefined container"

[NEW]
Two new services for setting the owner of Home Directories to be the end user:
"NW:HOME DIRECTORY: Set selected NDS Object's Home Directory Owner to be itself - including all subdirectories"
"NW:HOME DIRECTORY: Set selected NDS Object's Home Directory Owner to be itself - including all subdirectories and files"

[NEW]
New button service allows you to pass multiple parameters to an executable file:
"RUN: Specific File (EXE or other 'executable' file) - Pass as parameter(s) each display item in the connected listview (not the first column)"

[NEW]
CVMONE.NLM version 1.75.06 allows four new functions via NLM:
- Delete objects with prompt
- Remove members from groups (when viewing groups user is a member of)
- Modify directory space restrictions in MB
- Edit login time restrictions

[NEW APPLET]
There is a new applet named "Change Directory Space Restrictions via NLM" in the HelpDesk Examples section of the DSRAZOR Console. It allows helpdesk staff to change directory space restrictions on NetWare servers that have CVMONE.NLM loaded.

[NEW APPLET]
There is a new applet named "Move User(s) to a Different Container" in the eDirectory User Maintenance section of the DSRAZOR Console. It allows you to move a user or multiple users to a different container. The applet can be modified if you would like to move other types of objects - groups, containers, templates, workstations, etc.

[UPDATE]
The button service "NW:Delete Selected File" has been updated to "NW:Delete Selected File(s)" so you can delete multiple files at the same time, even if they are in different directories.

[UPDATE]
The button service "NDS:Add ZEN Application to selected User, Group or Container; Add Apps from selected container" has been updated to "NDS:Add ZEN Application to selected User, Group or Container; Add Apps from selected container>append '+' sign at end of path to include subcontainers in search" so that you no longer have to specify each container with a separate button. Now you can search through subcontainers and/or start your search from the Root of the Tree.

[UPDATE]
The service "NDS:List Last User Created" has been updated so it can now be used with the "NW:Copy list of all directories created, connect to NW:Receive list of directories..." service when assigning file system rights to newly created users.

[UPDATE]
The button services "NDS:Edit Login Time Restrictions" and "NDS:Edit Login Time Restrictions [NWADMINSTYLE]" have been updated so they can now be used with CVMONE.NLM. Note: to have the request go through the NLM, the "NDS:Server to interact with to change selected NDS attribute via NLM" text service must be added on the same screen.

[UPDATED APPLET]
The "Find Home Directories with No Trustees" applet in the Query and Search eDirectory section of the DSRAZOR Console has been updated to include an option for deleting the directories.

[UPDATED APPLET]
The "Add/Delete ZEN (NAL) Apps from Users" applet in the ZENworks Maintenance section of the DSRAZOR Console has been updated to search the whole Tree to find ZEN/NAL Applications to associate (so you do not have to edit the applet in the Designer anymore). If you do not want to search the whole Tree for Applications, the applet can be modified to only look in or beneath a specific container for ZEN/NAL Applications.

[UPDATED APPLET]
The "Find Files Ending with MP3 (or other extension)" applet in the Examine Servers/Disks section of the DSRAZOR Console has been updated to include an option for deleting the MP3 files. Also the "bytes" label was changed to "KB".

[UPDATED APPLET]
The "Find Files Greater than 1 MB in Size (or other size)" applet in the Examine Servers/Disks section of the DSRAZOR Console has been updated to include an option for deleting the large files. Also the "bytes" label was changed to "KB".

[UPDATED APPLET]
The "Find Unused for Past 365 Days (or other interval)" applet in the Examine Servers/Disks section of the DSRAZOR Console has been updated to include an option for deleting the unused files. Also the "bytes" label was changed to "KB".

[UPDATED APPLET]
The "View File Details per Directory" applet in the Examine Servers/Disks section of the DSRAZOR Console has been updated to include an option for deleting the files. Also the "bytes" label was changed to "KB".

[UPDATED APPLET]
The "Compressed vs. Uncompressed Directory Sizes" applet in the Examine Servers/Disks section of the DSRAZOR Console has been updated to be able to display and set the Directory Space Restrictions in both KB and MB.

[UPDATED APPLET]
The "Directory Space Restrictions (Linux only)" applet in the Examine Servers/Disks section of the DSRAZOR Console has been updated to be able to display the Directory Space Restrictions in both KB and MB.

[UPDATED APPLET]
The "Directory Space Restrictions (NetWare only)" applet in the Examine Servers/Disks section of the DSRAZOR Console has been updated to be able to display and set the Directory Space Restrictions in both KB and MB.

[UPDATED APPLET]
The "Set User as Owner of their Home Directory" applet in the NDS User Maintenance section of the DSRAZOR Console has been updated to include changing the ownership of the subdirectories and files within the Home Directory.

[UPDATED APPLET]
The "Document Access to Sensitive File System Directory (Linux only)" applet in the Assess eDirectory Security section of the DSRAZOR Console has been updated to accommodate the fix for the Modify and Access Control services

[UPDATED APPLET]
The "Document Access to Sensitive File System Directory (NetWare only)" applet in the Assess eDirectory Security section of the DSRAZOR Console has been updated to accommodate the fix for the Modify and Access Control services.

[FIX]
When running the "Enterprise Volume Space Report" applet in the Examine Servers/Disks section of the DSRAZOR Console, if a particular volume cannot be accessed you will now only see the error after the report completes. The previous error messages for each volume that would pop up while running the applet have been removed.

[FIX]
Setting rules using the "NW:Display File's Size in MB" service now works correctly.

[FIX]
The "NW:Display File's Size in KB" service now lists values in KB (instead of bytes)

[FIX]
Fix for CSV imports that were previously getting DSRRUN errors.

[FIX]
Corrected an issue when Inherited Rights Filters are displayed on the screen.

[FIX]
Corrected an issue with the following two display services:
"NDS:Display if Modify Right Exists (use with NDS:List ALL User/Grp/OU Objects with ANY Rights...)"
"NDS:Display if Access Control Right Exists (use with NDS:List ALL User/Grp/OU Objects with ANY Rights...)"

DSRAZOR Updates in 2010

Last Update

Description

2010.12.28

DSRAZOR for Windows Zero Privilege Help Desk

[NEW]
New import keyword (_Move to new OU) to allow moving user ojects to another OU through CSV import.

[UPDATE]
Reduced permissions required when configuring the Zero Privilege Account:
Zero Privilege Account does not need to be a local administrator when the server agent is installed on a member server. Zero Privilege Account does not need to be a member of the Domain "Administrators" group when the server agent is installed on a Domain Controller (unless User Account Control is enabled on the DC).

[UPDATE]
Added the ability to set a preferred DC - useful for member server installation.

Added "ZP Logon Account not enabled for Local Logon on Host Computer" message if Local Logon right has not been granted to ZP account (for use with non-admin account using delegation to the ZP account)

2010.12.14

DSRAZOR for eDirectory

[NEW]
CVMONE.NLM version 1.75b can now report the following information about NetWare servers: CPU Speed, LAN Board Line Speed, DNS Hostname, Manufacturer, Model, and Serial Number.

[NEW]
The following six new display services can show server information for NetWare 5.x and NetWare 6.x servers that have CVMONE.NLM version 1.75b or higher loaded:
"NW:Display Server's CPU Speed [requires NLM]"
"NW:Display LAN Board X's Line Speed [requires NLM](X = which logical board, first is = 1)(fill in X below in Manual Entry)"
"NW:Display Server's DNS Hostname [requires NLM]"
"NW:Display Server's DMI Manufacturer Name [requires NLM]"
"NW:Display Server's DMI Model Name [requires NLM]"
"NW:Display Server's Serial Number [requires NLM]"

[NEW]
The following two new listing services can show the LAN Boards and the LAN Board Custom Counters for NetWare or Linux servers:
"NW:List Active LAN Boards at Server"
"NW:List Custom Counters for selected Active LAN Board at Server"

[UPDATED APPLET]
The Enterprise File Server Status applet has been expanded to include the eight new server information services mentioned above. There are now slightly different copies of the applet so you can run whichever applet is appropriate for your needs:
"Enterprise File Server Status (All servers)"
"Enterprise File Server Status (Linux only)"
"Enterprise File Server Status (NetWare only)"

[UPDATED APPLET]
A screen has been added to the Directory Space Restrictions + Manage applet to show all users who have space on the volume, even if they do not have a space restriction set.

[UPDATED APPLET]
The Disk Space in use, Files Owned/Unowned applet now has some data sent directly out to a file, instead of on screen. Also the "KB" label was changed to "bytes".

[UPDATED APPLET]
The Find files ending with MP3 (or other extension) applet has been changed to be able to start the search at a selected directory, so you do not necessarily have to search the whole volume. Also the "KB" label was changed to "bytes".

[UPDATED APPLET]
The Find files greater than 1 MB in size applet has been changed to be able to start the search at a selected directory, so you do not necessarily have to search the whole volume. Also the "KB" label was changed to "bytes".

[UPDATED APPLET]
The Find files unused for past 365 days applet has been changed to be able to start the search at a selected directory, so you do not necessarily have to search the whole volume. Also the "KB" label was changed to "bytes".

[UPDATED APPLET]
The View File details per Directory applet has been changed to be able to start the search at a selected directory, so you do not necessarily have to search the whole volume. Also the "KB" label was changed to "bytes".

2010.10.07

DSRAZOR for Windows

[UPDATE BUTTON SERVICE]
Button Service:"AD:Rename Account (CN= component only) for selected Active Directory User Account(s)"
This Button Service has been enhanced to accommodate for commas in the CN name.

2010.10.06

DSRAZOR for Windows

[NEW BUTTON SERVICE]
New Button Service:"AD:Rename Account (CN= component only) for selected Active Directory User Account(s)"
Will rename selected Active Directory Account (CN or Common Name).

[FIX]
Updated some of the applets in the Console that are labeled Exchange 2007/2010 to work properly with Exchange 2010.

2010.09.21

DSRAZOR for eDirectory

[UPDATED APPLET]
New scount9.dsr replaces scount8.dsr. Added column for version of server to show more detail, and changed the way the top "NOT for licensing" button works.

2010.08.19

DSRAZOR for eDirectory

[NEW BUTTON SERVICE]
This new button service will import from a CSV file to update attributes of existing users, without creating any new users:
"Mass Update Existing User Accounts - use with Receive CSV file service (DOES NOT CREATE USERS)"

[NEW BUTTON SERVICE]
This new button service will import from a CSV file via CVMONE.NLM to update attributes of existing users, without creating any new users:
"Mass Update Existing User Accounts via NLM - use with Receive CSV file service (DOES NOT CREATE USERS)"
Note: you must use the text service "NDS:Server to interact with to change selected NDS attribute via NLM" to specify which server CVMONE.NLM is loaded on.

2010.08.09

DSRAZOR for Windows

[NEW BUTTON SERVICE]
"AD:Expire selected Active Directory user's password"
Will force selected users to change their password on next logon.

2010.07.08

DSRAZOR for Windows

[MODIFY]
Button services that copy user objects will now copy the Logon Hours of the source user to the target user. With this update it will also copy the UPN suffix of the source user and create the UPN logon name of the target user [sAMAccountName + UPN Suffix].

2010.06.25

DSRAZOR for eDirectory

[NEW SERVICE]
The following edit service allows changing the password expiration date but does not allow removing the password expiration date: "NDS:Edit Account's Password Expiration Date (No checkbox to remove date)"

2010.05.13

DSRAZOR for Windows

[NEW HELPDESK APPLET]
Helpdesk Dashboard Example applet [HelpdeskDashboard1.dsr]. This sample applet combines many of the daily user administration tasks into an efficient dashboard-style interface. The initial drilldown can be modified for your environment to reduce the number of windows in the applet. This will further increase the efficiency of the applet.

2010.05.10

DSRAZOR for Windows

[NEW SERVICES]
"FS:List All Controlled File System Objects of selected Trustee + Description + Inherited Flag + Apply To (use with "FS:SEARCH File System ..." service)"

"AD:RULE:Display selected Active Directory Container (can be domain root) to enable Document Effective Rights for User"

"AD:RULE:Display selected Active Directory Container (can be domain root) to enable Document Effective Rights for Group"

"AD:RULE:Document Effective Rights for selected object(s) in the connected list"

FS:List Groups by "SAM Account name" & EFFECTIVE RIGHTS to the selected File System Object (use "AD:RULE:Display Starting AD Container for Doc.Eff.")"

FS:List Groups by LDAP name & EFFECTIVE RIGHTS to the selected File System Object (use "AD:RULE:Display Starting AD Container for Doc.Eff.")"

"FS:List users by "display name" & EFFECTIVE RIGHTS to the selected File System Object (use "AD:RULE:Display Starting AD Container for Doc.Eff.")"

"FS:List users by "SAM Account name" & EFFECTIVE RIGHTS to the selected File System Object (use "AD:RULE:Display Starting AD Container for Doc.Eff.")"

"FS:List users by LDAP name & EFFECTIVE RIGHTS to the selected File System Object (use "AD:RULE:Display Starting AD Container for Doc.Eff.")"

[NEW APPLET]
Effective NTFS Permissions - [EffectivePermissions_Directories.dsr]

This applet will calculate effective NTFS permissions for users and groups on directories in the file system.

[UPDATED APPLETS]
Updated the following applets to use the new service, "FS:List All Controlled File System Objects of selected Trustee + Description + Inherited Flag + Apply To (use with "FS:SEARCH File System ..." service)".

The difference between the old service and the new service is the addition of the "Applies To" information in the Access Control Entries (ACE). This means that the applets will now output the "Applies To" data for the Access Control Entries (ACE) in the reports.
[findFStrustee1.dsr]
[findFSdirTrustee1.dsr]
[findFSdirTrustee_OTF1.dsr]
[findFStrustee_OTF1.dsr]
[fsadmn_OTF4.dsr]
[fsadmnu_OTF4.dsr]
[fsadmnSID_OTF4.dsr]
[findFSdirTrustee_OTF1.dsr]
[fsadmnd_OTF4.dsr]
[fsadmndu_OTF4.dsr]
[fsadmndSID_OTF4.dsr]

2010.05.05

DSRAZOR for Windows

[NEW BUTTON SERVICE]
AD:Remove Group Membership for all groups the selected Object belongs to (except primaryGroupID)

Removes selected user (or other object) from all Active Directory groups( except Primary Group)

[NEW BUTTON SERVICE]
EXCH:MODIFY:HIDE selected AD Account(s) From Exchange Address Lists

Hides selected user from Exchange address lists

[NEW BUTTON SERVICE]
EXCH:MODIFY:SHOW selected AD Account(s) so it can be seen by Exchange Address Lists

[NEW EDIT SERVICE]
ADr:Edit User's(Contact) name to Create|"last, first" format-must be used with Button Service: "AD:Create User(or Contact) + Require EDIT Services..."

This service is very similar to the existing "Edit User's name to Create" service. When assigned to a control on a user creation applet, this edit text service will enter the Account Name (a required attribute) when creating a new user. This new service will auto-populate the Account Name using "Last, First" format based on the information entered for First and Last name. You can optionally override the auto-populated text and either modify it or replace it.

DSRAZOR for eDirectory

[UPDATE]
Updated the service "NW:Display Server's current time". This service would sometimes report the time one hour ahead.

[UPDATE]
Modification made to the service "NDS:RULE:When NDS Attribute has no value, display nothing at all instead of the default <None>" so that it will now also omit <Never>.


2010.04.30

DSRAZOR for Windows

[UPDATE]
Added functionality to the Local Admin Password Reset applet that indicates if any computers failed to have their admin password reset.

[UPDATE]
Modification made to the "auto close" service to work with the auto import service. This is to close an applet automatically after 60 seconds upon completion.

2010.04.16

DSRAZOR for eDirectory

[FIX]
Corrected the button service "NDS:Reset Selected Attribute" so it works with the attribute "Password Expiration Interval"

2010.04.07

DSRAZOR for Windows Zero Privilege Help Desk

[FIX]
Corrected an issue with the Zero Privilege Alert Agent where under certain circumstances it did not display the data for the "On Object" column. This update does not affect the logs because the "On Object" data was always correctly displayed in the logs

DSRAZOR for Windows

[NEW]
The following two services have been updated:
"AD:Display logonHours grid for selected User"
"AD:Display logonHours grid for selected User - Allow changes for one or multiple accounts"

They now allow you to set the days of the week and hours of the day that a user account is authorized to authentication to Active Directory. This information is stored in the logonHours attribute.

DSRAZOR for eDirectory

[FIX]
Corrected an issue where Last Login time stamp was ahead one hour for DST in Central European Time

2010.03.30

DSRAZOR for eDirectory - CVMONE.NLM

[FIX]
Corrected an issue with the service "NDS:Assign Grace Logins Remaining via NLM".

2010.03.26

DSRAZOR

[FIX]
Corrected a timezone issue in some reports.

2010.03.23

DSRAZOR for Windows

[FIX]
Removed a popup error with the "AD:Move Home Directory for selected User Account(s) (append SAMname)" button service.

2010.03.10

DSRAZOR - Out to File

[FIX]
With reports that send information directly out to a file, you can now run the same report multiple times in the same session of running the applet.

2010.03.04

DSRAZOR for Windows

[NEW]
The following Service was added to allow rule based query on multi-valued attributes:
"AD:RULE:Search selected Active Directory Multi-Valued Attribute for any values matching Manual Entry value"

2010.03.02

DSRAZOR for Windows

[NEW]
Added a button service similar to existing "copy user" button service. In addition to copying the user this new button service will also create a home directory for the new user in the same parent directory as the source user.

2010.02.26

DSRAZOR for Windows

[NEW]
There are two new services for listing local computer account's Lastpwdset:
"NT:List User Account's Password Last Set"
"NT:Display User Account's Password Last Set"

DSRAZOR for eDirectory

[FIX]
Some search services would display full results on screen, but incomplete results if the data was sent directly out to a file. This has been corrected.

[NEW]
There is a new service for listing items in a container (no sub-containers) with their fully distinguished name:
"NDS:SEARCH:List Objects in Specific Container ONLY (you can specify specific Object Classes to include)_Show Full Name"

2010.01.22

DSRAZOR for eDirectory - CVMONE.NLM

[NEW]
By default CVMONE.NLM does not allow helpdesk staff to modify objects that have "admin" in their name. There is now an optional switch that can be used if you want to allow your helpdesk to change attributes of objects with "admin" in their name (such as changing their group membership), but it still will not allow password changes of objects with "admin" in their name. The syntax is:
LOAD CVMONE /ALLOWA1

2010.01.21

DSRAZOR for Windows Zero Privilege Help Desk

[FIX]
The Single Use Password service now works correctly when using Zero Privilege Help Desk.

2010.01.19

DSRAZOR for eDirectory

[MODIFICATION]
You can now set values in minutes or days when changing the specific attributes Intruder Lockout Reset Interval and/or Intruder Attempt Reset Interval using this service:

"NDS:Change Selected Attributes for "selected" NDS objects only"

(Previously you could only set values in days.)

2010.01.18

DSRAZOR for eDirectory

[FIX]
Corrected the column indentation of the CSV file output of the "Document Effective File System Rights" applet.

DSRAZOR Updates in 2009

Last Update

Description

2009.12.10

DSRAZOR for Windows

[NEW SERVICES]
New Display Service to show if an account is hidden from Exchange Address Lists:
"EXCH:Display if selected AD Account is hidden from Exchange Address Lists"

New Listing Service to show if a Control Panel Service logon account has the ability to interact with the desktop session:
"NT:List IF selected Service can interact with the desktop"

New Button Service and import keywords to allow creating/updating groups from a CSV input file:
"AD:IMPORT:Mass Active Directory GROUP Create, SPECIFY [Group Type in Manual Entry] - use with a "Receive CSV file service""

[NEW APPLET]
New Applet for importing groups from CSV file:
"Import Groups from CSV File" [import_groups.dsr]

[NEW CSV EXAMPLE FILES]
importDistGroup.csv and importSecGroup.csv are sample files for the new import_groups.dsr applet.

[ZERO PRIVILEGE HELP DESK]
Added informational popup when removing the server agent.

DSRAZOR for eDirectory

[NEW SERVICES]
New Button Service added to clear results from a TreeView/ListView:
"TreeView/ListView: Clear List"

[CVMONE.NLM FIX]
Corrected a problem with editing the attribute "Account Balance" with CVMONE.NLM.

DSRAZOR for GroupWise

[FIX]
Corrected a problem with displaying GroupWise mailbox sizes.

2009.11.20

DSRAZOR for Windows

[NEW SERVICES]
EXCH:Display if selected AD Account is hidden from Exchange Address Lists

AD:IMPORT:Mass Active Directory GROUP Create, SPECIFY [Group Type in Manual Entry] - use with a "Receive CSV file service"

2009.11.04

DSRAZOR for GroupWise

[NEW]
New applet: "I.Move GroupWise User(s) to a different Post Office"
(gwmove.dsr) allows you to move one or more GroupWise Users to a different Post Office.

[NEW]
New display service shows how many Resources a GroupWise Account owns:
"NWGWC:Display Count of the number of Resources owned by the selected GroupWise Account"

[NEW]
New display service shows which post office the GroupWise Account will be moved to:
"NWGWC:MOVE:Display selected GroupWise Post Office - will be used as the destination PO for GW account moves"

[NEW]
New button service moves GroupWise Account(s) to a different Post Office:
"NWGWC:MOVE:Move selected GroupWise Account(s) to PO designated by "MOVE" display service"

DSRAZOR for eDirectory

[FIX]
Corrected a problem where this service showed incomplete results in some environments:
"NW: List All Users (plus File Server) Disk Space on the Selected Volume [NSS]"

2009.10.07

DSRAZOR for eDirectory

[FIX]
Corrected a problem with the service "Find and Delete Inactive Accounts" when selecting the "Delete selected GroupWise accounts only".

2009.09.28

DSRAZOR for eDirectory

[NEW]
New button service gives a confirmation after changing eDir/NDS password with a prompt for existing password:
"NDS:Change Account's Password, Prompt for Existing Password (When change is complete, show pop-up message)"

2009.09.25

DSRAZOR for Windows

[FIX]
"AD:RULE:Move current AD Account to designated Container..."
Now accepts Distinguished Names of up to 128 characters.

DSRAZOR for eDirectory

[NEW]
New button service gives a confirmation after changing eDir/NDS password:
"NDS:Change Account's Password (When change is complete, show pop-up message)"

[NEW]
New button service gives a confirmation after unlocking eDir/NDS accounts:
"NDS:Reset Intruder Lockout (When reset is complete, show pop-up message)"

2009.09.21

DSRAZOR for GroupWise

[FIX]
Increased support for larger GWCHECK log files.

2009.09.08

DSRAZOR for Windows

[NEW SERVICE]
"FS:List Servers/Workstations on selected server/workstation Active Directory object"

Allows disk space report to connect to computer object listing in Active Directory rather than relying on a NetBIOS listing of computers in the domain.

[NEW SERVICE]
"FS:List Servers/Workstations in selected Active Directory Container including Shared Disks on selected server/workstation"

Previously you could only select and search a NetBIOS domain name when reporting on disk space usage for computer objects. This new service allows you to select a container with computer objects in it for reporting disk space usage. This allows for quicker results when reporting on a subset of computer objects is desired in larger environments.

[UPDATE]
Updated "Disk Space Report" applet [fssize2.dsr] to use the new services.

DSRAZOR for Windows Zero Privilege Help Desk

[FIX]
Corrected an error message that incorrectly gave a warning message about a licensing problem when using Zero Privilege applets in a specific way.

DSRAZOR for eDirectory

[NEW RULE]
"Username Home Directory Owner"
and
"Attribute Home Directory Owner"

When using a CSV import to create eDir/NDS accounts, if a Home Directory is assigned during account creation the owner of the home directory can be set to be the newly created user. This is done by using either "Username Home Directory Owner" or "Attribute Home Directory Owner" in the import applet.

[NEW DISPLAY SERVICE]
This new Display Service closes the applet after doing a CSV import so that the applet can be fully automated (for example, to run unattended imports with a task scheduler):
"NDS_AUTOCREATE:Automatically exit applet after AUTO Receive CSV file service completes"

[NEW BUTTON SERVICE]
This new Button Service allows you to set the owner of a home directory to be the user that the home directory belongs to:
"NW:HOME DIRECTORY: Set selected NDS Object's Home Directory Owner to be itself"

[NEW APPLET]
Set User as Owner of their Home Directory (homedirowner.dsr):
This applet displays Home Directories and their owners. It also allows you to set the ownership to be the user that the Home Directory belongs to (in case any were set to other owners, such as to the creator of the account).

[UPDATE]
When using the various button services that create eDir/NDS accounts, if a Home Directory is assigned during account creation the owner of the home directory will be the newly created user.

[UPDATE TO CVMONE.NLM]
When using the new version of CVMONE.NLM, if a Home Directory is assigned during account creation the owner of the home directory will be the newly created user.

2009.08.20

DSRAZOR for eDirectory

[NEW]
New Applet:
Document GroupWise Distribution List Membership by User Name

DSRAZOR for GroupWise

[NEW]
New Listing Service:
"NWGWC:List Distribution Lists selected eDirectory User is a member of"

[NEW]
New GroupWise Applet:
H.List eDir/NDS Users and their Distribution List Memberships 

2009.08.18

DSRAZOR for GroupWise

[NEW]
New Display Service:
"NWGWCHK: Display Amount of Disk Space In-Use[MB]for selected GroupWise Account's email"
When displaying the mailbox size of user, you now can display it in MB (instead of Bytes).

2009.08.13

DSRAZOR for Windows

[FIX]
"AD:Include Container of Current User Logon in List"
This service was corrected to work with users whose Common Names contain a comma.

[MODIFY]
Made change to "AD:Create User + Require EDIT Services (AD Attributes) on same page [SHOW SUCCESS POP-UP](use EXCH:CREATE Display Mailbox Store on same screen)" service. The notification popup that indicates a new user has been created will no longer popup when attempting to create a user that previously existed.

DSRAZOR for eDirectory

[NEW]
New Display Services - When displaying directory sizes, you now can display in KB (instead of MB):

"NW:Display Size of Directory Compressed (KB) - Include All Subdirectories(i.e. actual amount of disk space in use)"

"NW:Display Size of Directory Compressed (KB) (i.e. actual amount of disk space in use)"

"NW:Display Size of Directory Uncompressed (KB) - Include All Subdirectories (i.e. amount of disk space in use if all files were uncompressed)"

"NW:Display Size of Directory Uncompressed (KB) (i.e. amount of disk space in use if all files were uncompressed)"


[NEW]
New Display Service - When listing file system trustees, the file system rights can now be displayed on one line:

"FILE:Display trustee assignments on a single line (versus a row for each assignment granted) - works with all trustee services using multiple lines"


2009.07.13

DSRAZOR for Windows

[FIX]
Corrected a problem that occurred when reporting lastLogon under special conditions. This problem typically occurred when running applets on a workstation with the local date incorrectly set.

2009.07.01

DSRAZOR for Windows

[NEW]
New display service:
"FS:Display File System Object's Extension (such as DOC, XLS, DLL)"

New display service was added to display file size in MB:
"FS:Display File System Object's Size (MB)"

DSRAZOR for eDirectory

[NEW]
New display service was added to display file size in MB:
"NW:Display File's Size in MB"

[UPDATE]
The following applets now have better functionality with SUSE Linux Enterprise Servers:

    Connection Stats (Bindery or NDS logins) - srvcon3.dsr
    Document Access to Sensitive Directory - privher6.dsr
    Document Effective File System Rights - doceff7.dsr
    Document Trustees by Directory - trbydir3.dsr
    Directory Space Restrictions - dirpspc4.dsr
    Find Directories with an Inheritance Filter - if4.dsr
    Find Home Directories with No Trustees - hdnotrst1.dsr
    View Home Directory Sizes - homed3.dsr

[FIX]
The following applets now work with DSRAZOR Container Tokens:

    Count Servers - scount8.dsr
    ZEN Remote Control / Remote View (Tab) - zenrcrvt1.dsr
    ZEN Remote Control / Remote View by User - zenrcrvu3.dsr

[UPDATE]
The following applets now display file sizes in both KB and MB:

    Disk Space in use, Files Owned/Unowned - volspc6.dsr
    File Extensions in Use - Count each - file-ex2.dsr
    Find files unused for past 365 days - files365a.dsr
    View File Details per Directory - fileuse1.dsr


2009.06.18

DSRAZOR for Windows

[UPDATE]
This update is more tolerant when creating users on slower DCs. It includes a new display service that allows you to specify a delay period (in seconds) for the applet to keep retrying to create the user.

2009.06.11

Visual Click Software proudly announces the release of DSRAZOR for Windows Zero Privilege Help Desk

Completely eliminate providing change permissions to your helpdesk operator accounts!

  • Does not use or rely on Active Directory Delegation
  • Uses a separate server-based service with full security options
  • Create Active Directory Accounts
  • Change Passwords
  • Change Active Directory Details
  • Create Exchange 2007/2010 Accounts
  • Create Home Directories
  • and much more!

  • Extends your existing DSRAZOR for Windows installation - convert your applets to use Zero Privilege Help Desk by adding a single service!
Zero Privilege Help Desk details

DSRAZOR for Windows now has support for Exchange 2007/2010

  • Add Exchange Mailbox to Existing User Accounts
  • Add Exchange Mailbox to User Accounts during Import
  • Enable Exchange Mailbox for Contact objects
  • Delete Exchange Mailbox from selected User Accounts
  • Smart Delete of User Account, Home Directory Structure and Exchange Mailbox
  • Quick Search to find User Accounts with or without Exchange Mailbox
  • Document Mailbox Statistics:
    • Account Name
    • Alias
    • Primary Email Address
    • Number of Emails in all folders
    • Size of all Emails in all folders
    • Number of Deleted Emails
    • Size of Deleted Emails
    • Storage Limit Status
    • Last Account Logged on (could be service account)
    • Last Logon Time
    • Rule that indicates if last logon was by the account holder
Click here for more details


2009.05.21

DSRAZOR for eDirectory

[FIX]
Corrected a problem with the applet that finds hung Login Scripts.

2009.05.08

DSRAZOR for Windows

[FIX]
Corrected a problem where the date/timestamp for lastLogon was being incorrectly reported.

Changed the way the "AD:Display if selected User cannot change their own password" service works. It no longer looks at the value in the userAccountControl attriibute - it looks at the permissions on the user object.

2009.05.04

DSRAZOR for Windows

[FIX]
Corrected a token/license check error when specific services were combined.

2009.03.04

DSRAZOR for GroupWise

[NEW]
"NWGWC:Delete GroupWise Account for NDS User/GroupWise External Entity"
New button service that deletes GroupWise accounts only, leaving the eDirectory accounts intact. Can be used to delete multiple GroupWise accounts at the same time.

DSRAZOR for eDirectory

[UPDATE]
"NDS:SEARCH:List and Authenticate to all NetWare Servers starting from selected container or [Root] if no container is selected"
This service now includes Linux servers in the search results.

2009.02.26

DSRAZOR for Windows

[UPDATE]
"EXCH:ENABLE:Exchange 2000 (or later) Mailbox for selected Active Directory Account(s) | EXCH:Display Administrative Group must be on same screen"

This button service can now be used to Exchange enable existing Contact objects.

[NEW]
"ADr:Edit Account's Target Email Address to Create - must be used with Button Service: "AD:Create Contact + Require Edit Services...""

New Edit service allows specifying email address when Exchange enabling existing Contact objects. If the "mail" attribute has a value before Exchange enabling the contact, this edit field will use that value. This can save time if someone has already populated email addresses for non-Exchange enabled Contact objects

2009.02.09

DSRAZOR for Windows

[MODIFY]
When displaying group membership - allow resolving Fully Qualified Domain Name of group members when those group members belong to a different forest.

2009.02.02

DSRAZOR for Windows

[UPDATE]
Updated the "FS:Display IF any Access Control Entry (ACE) grants GENERIC_ALL to selected File System Object" service to facilitate filtering on Full Control permissions.

DSRAZOR for Windows Console

AD User Maintenance

[NEW]
Added "Create Contact from a Template" applet to allow Exchange Enabled contact creation from a form. - [ContactTemplate1.dsr]


2009.01.30

DSRAZOR for Windows

[NEW]
The following new services will allow form-based creation of Exchange enabled contacts:

New button service to create contact objects:
"AD:Create Contact + Require EDIT Services (AD Attributes) on same page (will create Exchange Acct if EXCH:Display Administrative Group is on same screen)"

New edit service to be used when creating Exchange enabled contact objects with button service:
"ADr:Edit Account's Target Email Address to Create - must be used with Button Service: "AD:Create Contact + Require EDIT Services..."

2009.01.29

DSRAZOR

[FIX]
TreeViews that use tab labels now have the data indented correctly when sent directly out to a CSV file.

DSRAZOR for GroupWise

[NEW]
Support for GroupWise 8 GWCHECK.

[FIX]
The applets that use GWCHECK can now handle larger log files.

DSRAZOR for eDirectory

[NEW]
"NW:Display Count of Files in selected path only (no subdirectories)" - This new service can be used to show the number of files within a directory (it does not include the files in subdirectories beneath).

[FIX]
"NDS_AUTOCREATE:Receive CSV file, EXCEL STYLE [NO Quotes, Commas ONLY, no trailing comma] for Mass User [or Other Object] Create" - This service now expects the correct Excel CSV format.

[FIX]
The following services about directory details now display data correctly when sent directly out to a CSV file:
   "NW:List Count of Directories in selected path (includes all
    subdirectories)"
   "NW:List Count of Files in selected path (includes all subdirectories)"
   "NW:List Count of Files in selected path - no subdirectories
   included"
   "NW:List File's Owner (Name)"
   "NW:List File's Creation Date/Time"
   "NW:List File's Last Update (Modified) Date/Time"

2009.01.22

DSRAZOR for Windows

[NEW]
The following AD import keywords have been added:
   _Cannot change password
   _Delete Account

2009.01.15

DSRAZOR for Windows Services

[NEW]
"AD:List Trustees (List ACEs) by "displayName" name (where possible) for selected Active Directory Object"

[NEW]
"FS:List Trustees (List ACEs) by "displayName" name (where possible) for selected File System Object"

DSRAZOR Viewer

[UPDATE]
The DSRAZOR Viewer now recognizes applets that have Tab Controls.

DSRAZOR Updates in 2008

Last Update

Description

2008.12.11

DSRAZOR

[NEW]
"Password protect current page, if first page, protects entire applet - enter password in manual entry" - This service can be used to password protect an applet for additional security.

DSRAZOR for eDirectory Services

[NEW]
"NDS:List Department (Show 'empty' if no value)" - This service can be used to list the Department in a TreeView. Including 'empty' when there is no value is useful when saving the data with DSRAZOR's "Export to CSV - Only Entirely Expanded Items" option.

"NDS:List Full Name (Show 'empty' if no value)" - This service can be used to list the Full Name in a TreeView. Including 'empty' when there is no value is useful when saving the data with DSRAZOR's "Export to CSV - Only Entirely Expanded Items" option.

"NDS:List Given Name + Surname + Full Name + Department (Show 'empty' if no value for one or both, include quote and comma for CSV output)" - This service can be used to put the Given Name, Surname, Full Name, and Department all on one line in a TreeView. Including 'empty' when there is no value is useful when saving the data with DSRAZOR's "Export to CSV - Only Entirely Expanded Items" option.

"NW:Delete Selected Directory(s)/Folder(s)" - This button service can be used to delete empty directories. It cannot be used to delete directories that have files and/or subdirectories in them.

"NW:List Maximum Rights Mask for selected Directory (i.e. IF or IRF)" - This service can be used to list the maximum directory rights mask in a TreeView. If you use this as a Rule, please note that "no IRF" is designated by the value of 255. Any directory with a value of less than 255 indicates that an IRF is present.

2008.08.19

DSRAZOR Designer

[NEW]
Added Undo/Redo option in the Designer.

[NEW]
Added a Tab control

DSRAZOR for Windows Console

[NEW]
New applet in the "HelpDesk Examples" section titled "Update User Details (tabbed)". [editud_noml_tab2.dsr]

DSRAZOR for eDirectory Console

[NEW]
New applet in the "eDirectory User Maintenance" section titled "Set UniqueID to be equal to CN". [uniqueid.dsr]

[NEW]
New applet in the "NDS User Maintenance" section titled "Copy Members from one Group to another Group". [copygrpmem.dsr]

[NEW]
New applet in the "NDS User Maintenance" section titled "Change selected Attributes for Users-Mass (Tab)". [masscht.dsr]

[NEW]
New applet in the "Helpdesk Examples" and "ZENworks Maintenance" sections titled "ZEN Remote Control / Remote View (Tab)". [zenrcrvt.dsr]

[NEW]
New applet in the "Helpdesk Examples" section titled "Edit User Information (Tab)". [editusert.dsr]

[NEW]
New applet in the "Helpdesk Examples" section titled "Multi-function Helpdesk (Tab)". [helpdt.dsr]

[NEW]
New applet in the "Helpdesk Examples" section titled "Multi-function Helpdesk (Menu)". [helpdm.dsr]

2008.07.09

DSRAZOR for eDirectory

[FIX]
Removed an unhandled Edit error message.

2008.06.18

DSRAZOR for eDirectory Console

[NEW]
Treewalk style applet for finding GroupWise accounts that do not have an eDirectory/NDS Object, with the option of deleting them. [GWNONDS.DSR]

[NEW]
Direct style applet for finding GroupWise accounts that do not have an eDirectory/NDS Object, with the option of deleting them. [CGWNONDS.DSR]

[NEW]
List the username and the groups they belong to. [USERGM.DSR]

[UPDATED]
The "Find Accounts unused for 30, 90, or X days" applet now has the ability to enter the number of days you want to search for at runtime. Many other DSRAZOR applets can also be modified to allow values of rules to be entered at runtime. [3090D.DSR]

2008.06.12

DSRAZOR for Windows

[UPDATE]
Made improvements to the "AD:IMPORT:Mass User Attribute Update (existing accounts only), use with "receive CSV file service" button service. When encountering an account in the CSV file that does not already exist, an applet using this service will no longer generate popup messages. It will quickly skip the account and log a message in the DSRAZOR audit log indicating "Account not found - no update processed".

2008.06.03

DSRAZOR for Windows

[FIX]
Corrected a problem that sometimes occurred when setting a user account to never expire.

2008.04.24

DSRAZOR for eDirectory

[FIX]
Corrected an issue when editing the surname attribute via an import.

2008.03.28

DSRAZOR for Windows

[FIX]
Corrected a redraw issue with the Console when running on Vista.

2008.03.13

DSRAZOR for Windows

[NEW]
Services help is now available for all of the DSRAZOR for Windows Services. In the Designer, just right click on the service to view the help for that service. Also in the Designer select the menu option "Help/Search for Windows Services" to view help for all the services.

[NEW]
New service is available for reporting share permissions:
FS:ACE:List ACE AccessMask (simple) of Trustee (use with "FS:List Trustees ... service")

This service differs from the NTFS permissions service used previously. It does not show the data mask for the permission and it does not show if the permission was inherited or explicit. Share permissions are always explicit.

[NEW]
New applet for reporting share permissions. [NTSharePerms.dsr] can be accessed by double-clicking "Shares Permissions on Servers and Workstations" in the "Assess AD/NTFS Security" section of the Console.

[UPDATE]
Modified two applets in the Console that report Share permissions. The applets now use a new service to display permissions granted.
[fsListShareACLp3.dsr] and [fsListShareACLp3.dsr]

2008.02.22

DSRAZOR for Windows

[FIX]
Modified Active Directory button search service. Under certain circumstances, the first search performed after opening the applet would return no results, but all subsequent searches would return results. This update resolves that problem.

2008.02.15

DSRAZOR for Windows

[FIX]
Corrected a problem with updating AD attributes.

[FIX]
Search Manual Entry for "AD:Edit selected single-valued Attribute [Clear All Previous Values]" will now list all attributes defined in the schema.

2008.02.07

DSRAZOR for eDirectory

[FIX]
Search by attribute services are now working correctly.

2008.02.05

DSRAZOR for Windows

[UPDATE]
Made enhancements to certain Active Directory connection methods. Connecting to External Forests across a Trust is now more robust. These updates enable connecting to another Forest across an External Trust in certain circumstances where settings were preventing some services from working.

2008.01.25

DSRAZOR for GroupWise

[FIX]
DSRAZOR for GroupWise no longer leaves the "Loading GWCHECK Data" window on screen when complete.

DSRAZOR Updates in 2007

Last Update

Description

2007.12.14

DSRAZOR for Windows

[FIX]
Removed a debug message.

2007.12.13

DSRAZOR for eDirectory

[FIX]
Removed a debug message.

2007.12.11

DSRAZOR for eDirectory

[NEW]
You can remove members from groups by using a CSV import.

[FIX]
Searching by name now works when entering the whole name as the search string.

[FIX]
Searching will no longer use the cache if the previous search was canceled.

2007.10.25

DSRAZOR for Windows

[FIX]
Now correctly reports group membership if the group contains only one member.

2007.10.19

DSRAZOR for GroupWise

[Update]
DSRAZOR for GroupWise applets will now only search the GroupWise Domain you select (instead of searching all Domains before producing results for the selected Domain). This may improve speed of running the applets in environments with multiple GroupWise Domains.

2007.10.03

DSRAZOR for Windows

[Update]
Removed 'AD:Display User's Logon Workstation' service because Microsoft does not populate the 'logonWorkstation' attribute. Alternatively, use the 'AD:List User's Workstations where logon is permitted' service which reports the values in the 'userWorkstation' attribute.

2007.09.28

DSRAZOR for eDirectory

[NEW]
DSRAZOR will now report the associated value for "DirXML-Associations" attribute(s).

2007.09.27

DSRAZOR for Windows

[FIX]
When limiting the listing of directories in a file system tree to a specified depth, you may now add a display column that shows the aggregate size of the files and folders contained within each directory path. This enhancement allows the service "FS:List ALL Directories from current directory (or Root if none specified) by full name to specified directory depth" to work together with the service "FS:Display Size of Files on selected Path (in KB)".

DSRAZOR for eDirectory

[NEW]
You can now enter a partial name when searching for objects with this service: "Search for any object by Name beginning at selected container or [Root] if no container selected [CLEAR RESULTS FIRST]" For example, you could find a workstation called "111ABCworkstation" by just searching for "ABC".

2007.09.26

DSRAZOR for eDirectory

[NEW]
When remote controlling/viewing ZEN workstations via CVMONE.NLM, if you load the NLM with the /L switch you can now see the remote activity in the CVMONE.LOG file.  This requires CVMONE.NLM version 1.72.03 be run on a NetWare 5.x or NetWare 6.x server (this activity is not logged if CVMONE.NLM is on a NetWare 4.x server).

[NEW]
When creating eDirectory/NDS accounts, this service can be used to limit the User ID/Login Name (CN) to a maximum of 8 characters:
"NDS:Edit User's name to Create (8 Characters or less) - must be used with Button Service: NDS:Create User + Require EDIT Service..."

2007.09.21

DSRAZOR for Windows

[FIX]
Corrected an issue where local time was sometimes being reported as UTC time for last login.

DSRAZOR for eDirectory and
DSRAZOR for GroupWise

[NEW]
The following is a new rule that will commit changes in GroupWise once updated in eDirectory:
NWGWC:RULE:Automatically Commit NDS Change to GroupWise for selected GroupWise Account when editing NDS attribute starting "NGW:"

2007.09.20

DSRAZOR for Windows

[New Button Service]
AD:Change User Password - Requires Verification of Existing Password

Allows applet user to reset his or her own password if current password is known.  This service should be connected to a 'AD:Display Who Am I (distinguished name of current user)' service.

2007.09.13

DSRAZOR

[FIX]
Corrected a problem with date sorting introduced in the September 7 build.

2007.09.11

DSRAZOR for Windows

[FIX]
Removed repeated lines from Output To File (OTF) when reporting disk space usage.

2007.09.07

DSRAZOR for Windows

[FIX]
This update resolves a problem displaying group membership.  This is a fix for the oleaut32.dll problem that was introduced with the latest Windows Update (KB921503).

DSRAZOR for eDirectory

[NEW]
You can specify multiple servers to check for CVMONE.NLM by using this new text service:
"NDS:Server to interact with to change selected NDS attribute via NLM [Allow Multiple Servers]"

[NEW]
You can count the number of objects of each object class per container by using this new button service:
"NDS:Add Column for each Object Class and show count of objects found for each NDS container in selected list"

[NEW]
You can list partitions with servers and replica types using this new button service:
"NDS:Add Column for each Server Host with Replica Type for Partitions in selected list"

2007.08.23

DSRAZOR for eDirectory and
DSRAZOR for GroupWise

[NEW]
New service that will update the GroupWise Phone Number at the same time that you update the eDirectory/NDS Phone Number.

New service that will update the GroupWise Given Name at the same time that you update the eDirectory/NDS Given Name.

New service that will update the GroupWise Last Name at the same time that you update the eDirectory/NDS Last Name.

New service that will update the GroupWise Full Name at the same time that you update the eDirectory/NDS Full Name.

New service that will update the GroupWise Title at the same time that you update the eDirectory/NDS Title.

New service that will update the GroupWise Department (OU) at the same time that you update the eDirectory/NDS Department (OU).

New service that will update the GroupWise Facsimile Telephone Number at the same time that you update the eDirectory/NDS Facsimile Telephone Number.

2007.08.21

DSRAZOR for Windows

[FIX]
Updated a licensing issue.

2007.08.13

DSRAZOR for eDirectory

[FIX]
Mass change of "Password Expiration Time" is no longer an hour off.

2007.08.02

DSRAZOR

[NEW]
In the Designer you can now export the Window/Control Map.


DSRAZOR for eDirectory

[NEW]
The new text service "NDS:RULE:When NDS Attribute has no value, display nothing at all instead of the default <None>" can be added to an applet so that attributes with no value will not get "<None>" written in when applying edit changes. 


[FIX]
When creating an EXE version of an applet that needs VCSGW.DLL and SNAPIN32.DLL, the distribution notes will now say that those DLLs are needed. 


[FIX]
When browsing to select an extensionless file, DSRAZOR now shows all files of all types (previously no files were shown). 


2007.07.10

DSRAZOR for Windows

[FIX]
Fixed popup error 800500d that occurs in some environments when reporting lastLogon values using a scan across all domain controllers. 


2007.05.29

DSRAZOR for Windows Services

[NEW]
AD:Include in the List, Home Directory Path for use during Create User + Req'd attr.(specify full UNC path such as "\\FS1\share\path", cn will be appended)

NT:List IF selected Service is running

NT:List Service Comment

NT:List Service File Path and startup options

NT:List Service Logon As

NT:List Service Short Name

NT:List Service Start Option

NT:List Service State

[UPDATES]
AD:RULE:For Edit and Display fields: Do not show <unknown> where value is undefined
This Text Control will now hide {unknown} from applet users when ADr:Edit services have no default value set.

The change log now correctly reports changes to userAccountControl.

The service formerly called "AD:Move Home Directory for selected User Account(s)" has been renamed "AD:Move Home Directory for selected User Account(s) (append CN)" to identify its function more clearly.

AD:List Object's Group Membership (show groups belonged to)
Fixed a problem that caused objects' primary group not to resolve to a distinguished name.

[FIXES]
FS:Remove selected Trustee from selected controlled object(s) (use with "FS:List All Controlled File System Objects of selected Trustee" service)
Corrected a problem that prevented button service from removing trustees.

Corrected a problem with time calculations that reported time one hour off in certain circumstances.

Corrected a problem with tabs and List services that would cause applets to fail on occasion.



DSRAZOR for eDirectory Services

[NEW]
NDS:List Rights in single line format [SRWCEFMA] that User or other Object has to Selected Directory (use with NDS:List ALL User...)

[NEW]
FILE:Display if selected Directory has explicitly assigned trustees

DSRAZOR for eDirectory

[FIX]
The service "NDS:Mass Create NDS OBJECT, SPECIFY [Object Class in
Manual Entry] - use with Receive CSV file service (No error on re-create)"
now works correctly.

[FIX]
The service "NWNDPS:Display Status of selected Printer Agent" no
longer displays ?Unknown? for iPrint printers.

[FIX]
Sending data directly out to a file now includes all of the data that
would have been displayed if the results were displayed on screen

2007.05.15

DSRAZOR

[UPDATE]
Increased the number of controls that are allowed on the opening screen of an applet.

2007.05.10

DSRAZOR for Windows Console

Assess AD/NTFS Security

[NEW]
ACL Documentation per File System Share - [fsListShareACLp1.dsr]
Document share permissions.

Examine Servers and Disks

[NEW]
Document Share Permissions - [fsListShareACLp1EXA.dsr]
Document share permissions.

AD User Maintenance

[UPDATED]
Create Users with Required Attributes - [cura04c.dsr]
Added auto-creation of user's display name based on last name, a comma, and first name.

Create Users with Required Attributes + Exchange Mailbox - [cura04exc.dsr]
Added auto-creation of user's display name based on last name, a comma, and first name.

Edit Single-Valued Attribute for Selected Accounts - [sved_text4.dsr]
Added buttons to prepend or append text to selected accounts' fax numbers.

Create Users from a Template - [UserTemplate1.dsr]
Added home directory path selection and groups to add automatically during template user creation.

DSRAZOR for Windows Services

[FIXES]
FS:List All Controlled File System Objects of selected Trustee + Description + Inherited Flag (use with "FS:SEARCH File System " service)
Corrected a problem that limited display of controlled objects.

AD:Edit Selected Multivalued Attribute
Corrected the display of existing values when editing attribute.

AD:Move selected Object(s) (Container to move to must be specified with Display Service Canonical Name for Move Operation
Corrected a problem with moving objects with commas embedded in the CN.

The following seven services are now properly treated as returning Boolean values:

  • AD:Display if selected Object has Domain Administrator Status (adminCount set to 1)

  • AD:Display if selected Object is critical system object (IsCriticalSystemObject attribute is TRUE)

  • AD:Display Computer's Role: Schema Master Status (whether or not is Schema Master of Forest)

  • AD:Display Computer's Role: Domain Naming Master Status (whether or not is Domain Naming Master of Forest)

  • AD:Display Computer's Role: PDC Emulator Master Status (whether or not is PDC Emulator Master of Domain)

  • AD:Display Computer's Role: RID Master Status (whether or not is RID Master of Domain)

  • AD:Display Computer's Role: Infrastructure Master Status (whether or not is Infrastructure Master of Domain)
AD:FSMO:List FSMO Roles for selected Primary Domain Root including Global Catalog Status of each DC
Corrected a problem in domains where the pre-AD domain name is different than the relative distinguished name of the AD/DNS domain name.

FS:List All Controlled File System Objects of selected Trustee (use with "FS:SEARCH File System from selected object " service)
Corrected a problem with listing file system objects with high-bit-set ASCII characters. Such objects will now be displayed using their DOS-compatible 8.3 name.

Removed error messages when Output to File (OTF) is enabled for TreeViews with multiple services at the same level under a common parent service.

[UPDATES]
The rule service formerly titled "AD:Display Object's Distinguished Name (Canonical Name) (For Move/Copy Operation {Button Service})" has been renamed "AD:RULE:Display Object's Distinguished Name (Canonical Name) (For Move/Copy Operation {Button Service})" to more clearly indicate its function as a helper service for the "AD:Move" and "AD:Copy" button services.

AD:Erase ALL values of selected Attribute for selected Active Directory Object(s), use Manual Entry to select Attribute
Can now link to a 'AD:Display Who Am I (distinguished name of current user)' Text box to select the user. Removed a pop-up message when targeted attribute is already empty.

GC:Display number of USER objects in selected path
Can now select a domain root in the 'Connect Service to:' field, in addition to the container and Organizational Unit options previously available.

[NEW]
AD:Edit:Append value to text-based Attribute This button service will append text to the specified attribute of selected users. The text-based attribute to modify should be specified in the "Manual Entry Text" field in the Designer.

AD:Edit:Prepend value to text-based Attribute This button service will prepend text to the specified attribute of selected users. The text-based attribute to modify should be specified in the "Manual Entry Text" field in the Designer.

AD:Include in the List, Home Directory Path for use during Create User + Req'd attr.(specify full UNC path such as "\\FS1\share\path", SAMname will be appended) Use this service in a Dropdown List or ListView to display selectable home directory paths in a user creation applet. Rules are used to specify the UNC path(s) of the available home directory location(s). Upon user creation the home directory will be created using the SAM Account Name of the user account in the selected parent directory. The user will be granted permissions to create, delete, and change objects within the Home Directory, but will not be able to assign permissions to his or her Home Directory or delete the Home Directory itself.

AD:Include in the List, thisGroupforMembershipaddduringCreateUser+Req'dattr.(specifyfullLDAPname,example:"CN=MediaGroup,DC=Staff,DC=local") This service can be used in a ListView to specify group membership upon user creation with a button service. Groups should be specified by distinguished name (full LDAP name) in the Rules for the service.

AD:RULE:For Edit and Display fields: Do not show '<unknown>' where value is undefined When this service is present in a Text box on a window with edit and display services, they will show an empty field instead of '' when a value has not been defined.

NT:List All Shares including Ownership and Permission Data This list service will display all shares defined on the selected server, and can be followed in a ListView or TreeView with services that document permissions and other data. See the Console applet "ACL Documentation per File System Share" [fslistShareACLp1.dsr] in the "Assess AD/NTFS Security" section for examples of use of this service.

New services have been added to permit the automated building of a specified attribute value from a combination other attribute values, parts of other attribute values, and static text. An example of this feature is in the applet titled "Create Users with Required Attributes" [cura04c.dsr], which can be found in the "AD User Maintenance" section of the Console. This applet constructs the created user's display name from the user's last name, a comma, and the user's first name.

AD:AUTO:Attribute Name Auto-populate using Rules 1-5 (use with Button Service: "AD:Create User + Require EDIT Services")
This display service specifies which attribute will be built by the following five services. It should be used with one or more of the following five services which will allow you to automate the construction of an attribute's value, as specified by the "AD:AUTO:Attribute Name Auto-populate using Rules 1-5 (use with Button Service: "AD:Create User + Require EDIT Services")" service, with the values of other attributes and static text:

  • AD:AUTO:Rule 1:Attribute Name (use with Display Service "AD:AUTO:Attribute Name")
  • AD:AUTO:Rule 2:Attribute Name (use with Display Service "AD:AUTO:Attribute Name")
  • AD:AUTO:Rule 3:Attribute Name (use with Display Service "AD:AUTO:Attribute Name")
  • AD:AUTO:Rule 4:Attribute Name (use with Display Service "AD:AUTO:Attribute Name")
  • AD:AUTO:Rule 5:Attribute Name (use with Display Service "AD:AUTO:Attribute Name")
To insert the entire value of a single-valued attribute, place the name of the attribute in the "Manual Entry Text" box in the Designer.

To insert the first five characters of an attribute, use "*5*<attributeName>" (without the quotes, and substituting an attribute name for <attributeName>).

To insert the last three characters of an attribute, use "<attributeName>*3*" (without the quotes, and substituting an attribute name for <attributeName>).

To insert static text, two asterisks should precede the static text in the "Manual Entry Text" box in the Designer, for example, "**fixed text" (without the quotes).

The rules will be executed in numerical order to build the attribute specified with the ' AD:AUTO:Attribute Name Auto-populate using Rules 1-5 (use with Button Service: "AD:Create User + Require EDIT Services")' service. Each auto rule service may be used only once, and any number of these AD Auto Rule services may be used to build the specified attribute's value.

DSRAZOR for eDirectory

[FIX]
Creating aliases for multiple objects at the same time now works correctly when the applet has the container pre-defined to a specific container.

[FIX]
The Service applet LRGSRCH.DSR no longer reports a file over 2GB in size as a negative value.

2007.04.03

DSRAZOR

[FIX]
Corrected a problem with timezone being one hour off.

2007.03.21

DSRAZOR for Windows Console

Assess AD/NTFS Security

[NEW]
ACL Documentation per File System Share - [fsListShareACLp1.dsr]
Document share permissions.

Examine Servers and Disks

[NEW]
Document Share Permissions - [fsListShareACLp1EXA.dsr]
Document share permissions.

AD User Maintenance

[UPDATED]
Create Users with Required Attributes - [cura04c.dsr]
Added auto-creation of user's display name based on last name, a comma, and first name.

Create Users with Required Attributes + Exchange Mailbox - [cura04exc.dsr]
Added auto-creation of user's display name based on last name, a comma, and first name.

Edit Single-Valued Attribute for Selected Accounts - [sved_text4.dsr]
Added buttons to prepend or append text to selected accounts' fax numbers.

Create Users from a Template - [UserTemplate1.dsr]
Added home directory path selection and groups to add automatically during template user creation.

DSRAZOR for Windows Services

[FIXES]
FS:List All Controlled File System Objects of selected Trustee + Description + Inherited Flag (use with "FS:SEARCH File System " service)
Corrected a problem that limited display of controlled objects.

AD:Edit Selected Multivalued Attribute
Corrected the display of existing values when editing attribute.

AD:Move selected Object(s) (Container to move to must be specified with Display Service Canonical Name for Move Operation
Corrected a problem with moving objects with commas embedded in the CN.

The following seven services are now properly treated as returning Boolean values:

  • AD:Display if selected Object has Domain Administrator Status (adminCount set to 1)

  • AD:Display if selected Object is critical system object (IsCriticalSystemObject attribute is TRUE)

  • AD:Display Computer's Role: Schema Master Status (whether or not is Schema Master of Forest)

  • AD:Display Computer's Role: Domain Naming Master Status (whether or not is Domain Naming Master of Forest)

  • AD:Display Computer's Role: PDC Emulator Master Status (whether or not is PDC Emulator Master of Domain)

  • AD:Display Computer's Role: RID Master Status (whether or not is RID Master of Domain)

  • AD:Display Computer's Role: Infrastructure Master Status (whether or not is Infrastructure Master of Domain)
AD:FSMO:List FSMO Roles for selected Primary Domain Root including Global Catalog Status of each DC
Corrected a problem in domains where the pre-AD domain name is different than the relative distinguished name of the AD/DNS domain name.

FS:List All Controlled File System Objects of selected Trustee (use with "FS:SEARCH File System from selected object " service)
Corrected a problem with listing file system objects with high-bit-set ASCII characters. Such objects will now be displayed using their DOS-compatible 8.3 name.

Removed error messages when Output to File (OTF) is enabled for TreeViews with multiple services at the same level under a common parent service.

[UPDATES]
The rule service formerly titled "AD:Display Object's Distinguished Name (Canonical Name) (For Move/Copy Operation {Button Service})" has been renamed "AD:RULE:Display Object's Distinguished Name (Canonical Name) (For Move/Copy Operation {Button Service})" to more clearly indicate its function as a helper service for the "AD:Move" and "AD:Copy" button services.

AD:Erase ALL values of selected Attribute for selected Active Directory Object(s), use Manual Entry to select Attribute
Can now link to a 'AD:Display Who Am I (distinguished name of current user)' Text box to select the user. Removed a pop-up message when targeted attribute is already empty.

GC:Display number of USER objects in selected path
Can now select a domain root in the 'Connect Service to:' field, in addition to the container and Organizational Unit options previously available.

[NEW]
AD:Edit:Append value to text-based Attribute This button service will append text to the specified attribute of selected users. The text-based attribute to modify should be specified in the "Manual Entry Text" field in the Designer.

AD:Edit:Prepend value to text-based Attribute This button service will prepend text to the specified attribute of selected users. The text-based attribute to modify should be specified in the "Manual Entry Text" field in the Designer.

AD:Include in the List, Home Directory Path for use during Create User + Req'd attr.(specify full UNC path such as "\\FS1\share\path", SAMname will be appended) Use this service in a Dropdown List or ListView to display selectable home directory paths in a user creation applet. Rules are used to specify the UNC path(s) of the available home directory location(s). Upon user creation the home directory will be created using the SAM Account Name of the user account in the selected parent directory. The user will be granted permissions to create, delete, and change objects within the Home Directory, but will not be able to assign permissions to his or her Home Directory or delete the Home Directory itself.

AD:Include in the List, thisGroupforMembershipaddduringCreateUser+Req'dattr.(specifyfullLDAPname,example:"CN=MediaGroup,DC=Staff,DC=local") This service can be used in a ListView to specify group membership upon user creation with a button service. Groups should be specified by distinguished name (full LDAP name) in the Rules for the service.

AD:RULE:For Edit and Display fields: Do not show '<unknown>' where value is undefined When this service is present in a Text box on a window with edit and display services, they will show an empty field instead of '' when a value has not been defined.

NT:List All Shares including Ownership and Permission Data This list service will display all shares defined on the selected server, and can be followed in a ListView or TreeView with services that document permissions and other data. See the Console applet "ACL Documentation per File System Share" [fslistShareACLp1.dsr] in the "Assess AD/NTFS Security" section for examples of use of this service.

New services have been added to permit the automated building of a specified attribute value from a combination other attribute values, parts of other attribute values, and static text. An example of this feature is in the applet titled "Create Users with Required Attributes" [cura04c.dsr], which can be found in the "AD User Maintenance" section of the Console. This applet constructs the created user's display name from the user's last name, a comma, and the user's first name.

AD:AUTO:Attribute Name Auto-populate using Rules 1-5 (use with Button Service: "AD:Create User + Require EDIT Services")
This display service specifies which attribute will be built by the following five services. It should be used with one or more of the following five services which will allow you to automate the construction of an attribute's value, as specified by the "AD:AUTO:Attribute Name Auto-populate using Rules 1-5 (use with Button Service: "AD:Create User + Require EDIT Services")" service, with the values of other attributes and static text:

  • AD:AUTO:Rule 1:Attribute Name (use with Display Service "AD:AUTO:Attribute Name")
  • AD:AUTO:Rule 2:Attribute Name (use with Display Service "AD:AUTO:Attribute Name")
  • AD:AUTO:Rule 3:Attribute Name (use with Display Service "AD:AUTO:Attribute Name")
  • AD:AUTO:Rule 4:Attribute Name (use with Display Service "AD:AUTO:Attribute Name")
  • AD:AUTO:Rule 5:Attribute Name (use with Display Service "AD:AUTO:Attribute Name")
To insert the entire value of a single-valued attribute, place the name of the attribute in the "Manual Entry Text" box in the Designer.

To insert the first five characters of an attribute, use "*5*<attributeName>" (without the quotes, and substituting an attribute name for <attributeName>).

To insert the last three characters of an attribute, use "<attributeName>*3*" (without the quotes, and substituting an attribute name for <attributeName>).

To insert static text, two asterisks should precede the static text in the "Manual Entry Text" box in the Designer, for example, "**fixed text" (without the quotes).

The rules will be executed in numerical order to build the attribute specified with the ' AD:AUTO:Attribute Name Auto-populate using Rules 1-5 (use with Button Service: "AD:Create User + Require EDIT Services")' service. Each auto rule service may be used only once, and any number of these AD Auto Rule services may be used to build the specified attribute's value.

DSRAZOR for eDirectory

[FIX]
Creating aliases for multiple objects at the same time now works correctly when the applet has the container pre-defined to a specific container.

[FIX]
The Service applet LRGSRCH.DSR no longer reports a file over 2GB in size as a negative value.

2007.02.08

DSRAZOR

[UPDATE]
The Out To File in TXT format will now have a more consistent number of records per page.

DSRAZOR for Windows

[FIX]
DSRAZOR will now give a more user friendly error when running Group Membership type applets and it cannot bind to the Global Catalog.

[FIX]
The Service "AD:Display Number of Members for selected Group" will now return the correct value.

Click here to see updates from 2006

 

 

Active Directory Tools for Management and Reporting - Questions? Please call direct: 512 330 0542
Questions?Here's some easy ways to get the answers you need.
Phone
  • (512) 330-0542
  • (877) 902-5425