DSRAZOR Updates in 2012

Last Update

Description

2012.02.01

DSRAZOR for Windows

[NEW]
Exchange Enable contact objects in Exchange 2007/2010

[NEW SERVICE]
"EXCH2007-2010:Edit Alias of selected AD Account|Service must be on same scrn"(EXCH2007:List All Exchange 2007 ... Mailbox Databases...)"
New Edit service to modify the Exchange Alias for Contact objects and User objects in Exchange 2007/2010.

[NEW SERVICE]
"AD:Do not show RT7 message timeout prompt when modifying objects - place on first page of applet and it will apply to entire applet"
New Text service that allows you to suppress the "Retry" popup that occurs when bulk importing users and the applet encounters a timeout. This new service will force the applet to try every second for up to 65 seconds until the import operation is successful.

[MODIFY]
Some display services that showed a date and time for Active Directory properties were rounding off the values to the nearest minute. With this update, those services will also display the correct seconds as well.

2012.01.31

DSRAZOR for Windows

[UPDATE]
The DSRAZOR for Windows Zero Privilege Console will now force run as administrator when started from a UAC enabled machine.

[NEW SERVICE]
AD:MODIFY:Disable current AD Account and remove Date appended to CN= | if current CN does not end with "_nnnn" format it will be skipped.

This Display service is typically added as a column in a ListView to automatically disable all Active Directory accounts found in a search and to remove any previously appended date-in MMDDYY or DDMMYY format-to the common name (CN=) of the accounts.

2012.01.11

DSRAZOR for Windows

[NEW]
"AD:List Group's Membership (by displayName - if no displayName defined will show LDAP name)"
This Listing service lists all members of the selected Active Directory group. Members are listed by Display Name. If the user object does not have a value for displayName, it will display the object's Distinguished Name (DN).

DSRAZOR Updates in 2011

Last Update

Description

2011.12.13

DSRAZOR for Windows

[UPDATE]
When using the "AD:AUTO" services and including the creation of a home directory during user creation the home directory is correctly created with all the characters the "AD:AUTO" services are using.

[NEW SERVICES]
AD:AUTO:SAMNAME:Auto-populate using Rules 1-5(use with Button Service: "AD:Create User + Require EDIT Services...")
AD:AUTO:SAMNAME:Rule 1:(use with Display Service "AD:AUTO:SAMNAME")
AD:AUTO:SAMNAME:Rule 2:(use with Display Service "AD:AUTO:SAMNAME")
AD:AUTO:SAMNAME:Rule 3:(use with Display Service "AD:AUTO:SAMNAME")
AD:AUTO:SAMNAME:Rule 4:(use with Display Service "AD:AUTO:SAMNAME")
AD:AUTO:SAMNAME:Rule 5:(use with Display Service "AD:AUTO:SAMNAME")
AD:AUTO:ALL Attribute Rules 1-5:Make custom built rule result all UPPERCASE (use with Button Service: "AD:Create Users + Require EDIT Services")
AD:AUTO:ALL Attribute Rules 1-5:Make custom built rule result all lowercase (use with Button Service: "AD:Create Users + Require EDIT Services")

[FIX]
Suppressed a popup error on AD trustee reports when an orphaned SID is encountered as a trustee for an AD object.

2011.11.09

DSRAZOR for Windows

[FIX]
Corrected a problem encountered with not setting home directory permissions + ownership when using the Copy User button service in conjunction with using the Zero Privilege service.

2011.10.06

DSRAZOR for Windows

[FIX]
Corrected a problem encountered when using the Copy User button service in conjunction with the "AD:RULE:Force all AD change operations..." service.

2011.08.25

DSRAZOR for Windows

[NEW]
"AD:RULE:Force all AD change operations to named Domain Controller (to specify: user "ComputerName")" Use this text service on the first page of an applet to force it to read and commit changes to the Domain Controller specified in the "Manual Entry Text:" field.

[FIX]
"AD:Display logonHours grid for selected User - Allow changes for one or multiple accounts". Fixed a problem that would cause the applet to close unexpectedly when clicking on a button that uses this service. Problem only occurred for users in specific time zones.

2011.06.15

DSRAZOR for Windows

[FIX]
Corrected an issue with updating existing users to create a "Random Password".

2011.05.25

DSRAZOR for Windows

[UPDATE]
Edit fields with pre-defined values now accept values larger than 64 characters.

Increased performance for Active Directory searches.

[NEW]
Added two new button services to search for computers:

"AD:Search for any COMPUTER object by Name beginning at selected Container or DNS Domain Root (auto append '*')"

"AD:Search for any COMPUTER object by Name beginning at selected Container or DNS Domain Root (auto append '*') [Clear Previous Results]"

2011.04.27

DSRAZOR for Windows

[NEW]
When using DSRAZOR to pass a parameter to an EXE, if your parameter string includes spaces use this new button service:
"RUN: Specific File (EXE or other 'executable file) - Pass as a parameter, the connected display item (separately passes executable and parameters)"

2011.04.22

DSRAZOR for Windows Zero Privilege Help Desk

[FIX]
Corrected a problem in name resolution when running the agent on a 2008, 32-bit server. Zero Privilege enabled applets should no longer give error message "0x8007203B".

2011.04.19

DSRAZOR for Windows

[FIX]
DSRAZOR for Windows now allows population of Boolean and Integer attributes using pre-defined values field.

[FIX]
Corrected a problem with the Output To File display on the Effective File System Permissions report. The problem only seemed to occur if the file system objects had several orphaned permissions assigned to it.

2011.03.14

DSRAZOR for Windows Zero Privilege Help Desk

[FIX]
Corrected an issue encountered when using the copy user button service through zero privilege without the "Preferred DC" defined. The copy user button service now works fine without a Preferred DC defined.

2011.02.21

DSRAZOR for Windows Zero Privilege Help Desk

[FIX]
Corrected an issue with the "Who can use DSRWZP" configuration where allowed groups would stop being allowed to use ZP after a period of time in certain situations.

2011.02.16

DSRAZOR for Windows

[NEW]
Applet "List Local Group membership (OTF)"
[LocalGroupMembership_OTF.dsr]
This applet will document the members of all local groups on selected workstations or servers.

2011.01.25

DSRAZOR for Windows

[NEW]
Button service "AD:Copy selected Object's 'memberOf' (specified by Display Service - RULE:Canonical Name for copy 'memberOf') to selected Objects".
Display service "AD:RULE:Display Object's Distinguished Name (Canonical Name)(Specifies Source Object to copy its 'memberOf' attribute)"
These new services allow you to copy the group membership from one selected Active Directory object to another selected Active Directory object.

[NEW]
Applet "Copy Group Memberships"
[CopyGroupMembership1.dsr]
This new applet demonstrates how to copy group membership from one object to another object. The drilldown method can be simplified and modified to meet individual needs.

[UPDATE]
Applet "User Account Password Reset and Unlock - Helpdesk"
[hd_pwdr2b.dsr]
Renamed button face from "Reset Intruder Lockout" to "Unlock Account".

[UPDATE]
Applet "User Account Password Reset and Unlock - Helpdesk - Specify Containers"
[hd_pwdr3b.dsr]
Renamed button face from "Reset Intruder Lockout" to "Unlock Account".

2011.01.19

DSRAZOR for Windows

[NEW]
"[OTF]RECEIVE Merged items in connected Treeview into single list item - connect to service "Merge items...""
"[OTF]SEND Expanded & Merged items in same Treeview as this service - place this service as last root level item-select number of levels to process:range:1 to 3" These two new services allow you to format the output of a TreeView to look more like a ListView when exporting the data out to file.

[NEW]
Four new import keywords to move home directory contents (folders and files) to new location when updating the home directory path attribute on import from CSV. This will facilitate doing bulk home directory moves.,
These two keywords will move the the home directory data to the new location and delete the files in the old location:
"_Move Home Directory"
"_Move Home Directory SAMNAME"
These two keywords will copy the home directory data to the new location:
"_Move Home Directory NO DELETE"
"_Move Home Directory SAMNAME NO DELETE"

[NEW]
"AD:Edit User's UPN @Domain (will change to be an auto-populated dropdown)"
"AD:Edit User's UPN Logon Name (if @Domain not used will use default)"
These two new edit services for updating existing user objects work similarly to the existing UPN (userPrincipalName) edit services for use when creating new user objects. Previously when you wanted to modify the value for userPrincipalName on an existing user object, you needed to enter the entire value for the attribute in the edit field (such as BSmith@MyCompany.local). These new edit fields break the attribute down into separate prefix and suffix edit fields so that you can modify only a portion of the UPN if you would like.

[NEW]
Local User Reporting and Management We have added several new services to augment our existing local user services to allow additional reporting and management of local user accounts.
-Button Services-
"NT:Change Local User's Password across selected Servers/Workstations (local user manually specified at runtime)"
"NT:Change Local User's Password for selected local user (user selected from list of local users)"
"NT:Delete selected Local User Account(s)"
"NT:Disable selected Local User Account(s)"
"NT:Enable selected Local User Account(s)"
"NT:Unlock selected Local User's Account"
"NT:Remove Member(s) from list of Local Group Membership"
-Display Services-
"NT:Display IF selected Local User's Account is Locked"
"NT:Display User Account's Last Logon"

[NEW]
Applet "Local Account Password Reset - bulk - to all selected computers"
[LocalPasswordResetBulk.dsr]
Change the password for specified local account that exists across several computers. This can be useful for updating the passwords for service accounts that exist locally on several computers.

[NEW]
Applet "List Local User Accounts (alternate formatting) OTF"
[ListLocalUserAccounts_OTF1.dsr]
This applet uses the two new OTF Send and Receive services. It demonstrates formatting TreeView data for multi-valued data into a ListView or tabular format."

[NEW]
Applet "Local User Management"
[LocalUserManagement.dsr]
Manage local computer accounts (change password, unlock, enable, disable, delete, remove members from local groups).

[NEW]
"AD:Remove 'User cannot change password' on selected Active Directory user(s) (users will be able to change password)"
"AD:Set 'User cannot change password' on selected Active Directory user(s) (users will not be able to change password)"
These new services allow you to manage the "User cannot change password" setting on selected Active Directory accounts.

[NEW]
"AD:Set "Password never Expires" for selected Active Directory User Account(s)"
This new button service will set the flag in the userAccountControl attribute so that the "Password never Expires" on selected Active Directory accounts.

[NEW]
Applet "Password Security Settings for User Accounts"
[PasswordSettingsAD.dsr]
Manage password security settings for Active Directory user accounts.

[NEW]
Added 24 new "AD:AUTO..." services for autopopulating attributes on user creation. Previously you could use the set of 6 auto-populate services to populate the value of an attribute based on values that were entered for other attributes. For example, you could set the displayName attribute to [last, first] if the applet user entered the first name and last name on the user creation form. We have added 4 more sets of these services so now you can auto-populate up to 5 attributes when creating a new user.
Below are listed 6 (one set) of the 24 added services.
"AD:AUTO:1:Attribute Name - Auto-populate using Rules 1-5(use with Button Service:
"AD:Create User + Require EDIT Services...")"
"AD:AUTO:1:Rule 1:Attribute Name - (user with Display Service "AD:AUTO:Attribute Name...")
"AD:AUTO:1:Rule 2:Attribute Name - (user with Display Service "AD:AUTO:Attribute Name...")
"AD:AUTO:1:Rule 3:Attribute Name - (user with Display Service "AD:AUTO:Attribute Name...")
"AD:AUTO:1:Rule 4:Attribute Name - (user with Display Service "AD:AUTO:Attribute Name...")
"AD:AUTO:1:Rule 5:Attribute Name - (user with Display Service "AD:AUTO:Attribute Name...")

[NEW]
"AD:Search for any USER object by Name beginning at selected Container or DNS Domain Root (auto append '*')"
"AD:Search for any USER object by Name beginning at selected Container or DNS Domain Root (auto append '*')[Clear Previous Results]"
These two new button services behave similarly to the existing search button services. The difference is that these automatically append an '*' to the end of the search string. With the existing services, if you were searching for "Darin Smith" you might enter "Darin*" into the search field. With the new search button services you could just type "Darin" into the search field.

[NEW]
Import computer objects from CSV file.
Button service "AD:IMPORT:Mass Active Directory OBJECT Create, SPECIFY [Object Class in Manual Entry] - use with "Receive CSV file service" can now accept a value of "computer" for the import object class.
Display service "AD:IMPORT:AUTO_CREATE:Mass Active Directory OBJECT Create, SPECIFY [Object Class in Manual Entry] - use wth a "AUTO_CREATE receive CSV file service" can now accept a value of "computer" in the Manual Entry text field for automatically importing computer objects.

[NEW]
Applet "Import Computers + Attributes from CSV File"
[import_computer.dsr].
Applet "Import Computers + Attributes from CSV File (Automated)"
[import_computer_auto.dsr].
Sample import CSV file [import_computer.csv].
These two new applets allow you to import computer accounts from a CSV file.

[NEW]
"AD:Edit selected Object's Home Directory Path appending CN - use predefined values"
"AD:Edit selected Object's Home Directory Path appending SAMNAME - use predefined values"
These two new edit text services allow you to pre-specify some potential home directory locations in a dropdown list. You can then select the desired value in the dropdown list to edit the home directory location for the selected user. First it will update the homeDirectory attribute for the user in Active Directory. Second, it will create a folder for the user in the new location and set the permissions on the folder for the user. It will leave the files and contents of the old home directory in place, it does not move or copy files. We have found that it is better to use Windows Explorer to move or copy the files because it will allow you to make decisions about what to do with problem files during the move/copy process. You will need to use these new edit text services with an "Apply Changes" button.

[NEW]
"ADr:Create Home Directory Path using CN:for use during Create User + Req'd attr.(specify full UNC path such as "\\FS1\share\path")"
"ADr:Create Home Directory Path using SAMNAME:for use during Create User + Req'd attr.(specify full UNC path such as "\\FS1\share\path")"
These two new edit text services allow you to pre-specify some home directory locations in a dropdown list. You can then select the home directory location when creating a new user. You will need to use these new services with a "Create User" button.

[UPDATE]
"AD:List Group's Membership (by full AD/LDAP name)". This service will now successfully resolve group members that show up as Foreign Security Principals in the current domain because they are users from a trusted domain in another forest. Instead of showing the SID of the member from another forest, it will perform lookups to successfully display the full Distinguished Name of the user.

[UPDATE]
Corrected Output To File so that it would fully expand a multi-level TreeView in a file system permissions report. In a few specific cases it would only expand the TreeView output a few levels deep.

[UPDATE]
Modified how DSRAZOR determines whether an Active Directory account is locked out or not. It will now properly consider accounts that were "effectively" unlocked by a Group Policy Object (GPO), but still had a timestamp value present in the lockoutTime attribute. It will perform a calculation based on the value in the lockoutTime attribute, the current date and time, and the "Account lockout duration" specified in the Group Policy Objects applied to that user to determine if the user has been "effectively" unlocked by the GPO.

[UPDATE]
Removed a benign popup message that occurred when using a button service to view files in a directory. The popup only occurred if you used specific services linked in a very specific way. It was discovered by a customer who created a custom applet that connected services in an unusual way. Since the applet gave the correct results, this update does not change the results, it only removes the popup message.

[UPDATE]
"AD:Move selected Object(s) (Container to move to must be specified with Display Service - Canonical Name for Move Operation)"
We discovered that in certain circumstances, not all selected objects were being moved to the new OU/Container. Only half of the selected objects were being moved (every other one). This update fixes that problem.

[UPDATE]
"NT:Change Local Administrator User Account's Password for selected Servers/Workstations (RID=500)"
This button service will now accept passwords up to 30 characters in length. This has been increased from the previous limit of 14 characters. The increased 30 character limit has also been used in the new local password reset button services that are being released with this new update.

[UPDATE]
When Exchange enabling a contact object or a group object that has already been Exchange enabled; DSRAZOR will now display a popup indicating that the object is already Exchange enabled. (This update applies to Exchange 2000/2003 services)

[UPDATE]
"AD:Expire selected Active Directory user's password (requires users to change password at next logon)"
"AD:Assign Single-User Password for selected Active Directory User Account(s) {Must change password at next logon}"
"AD:Assign Single-User Password for selected Active Directory User Account(s) {Must change password at next logon} + Remove PwdNotRqd/Disable"
Added some "checks" to these button services. DSRAZOR will prevent you from successfully using these button services against a user account if the user is flagged with "User cannot change password". If you try to use one of those button services, DSRAZOR will now display a popup explaining the operation cannot be completed because the account is flagged with "User cannot change password".

[UPDATE]
Updated "User Account Password Reset and Unlock - Helpdesk" applet [hd_pwdr2b.dsr] to use new button search service that automatically appends '*' to the end of the search string.

[UPDATE]
Renamed "User Password and Intruder Lockout Reset Helpdesk" applet to "User Account Password Reset and Unlock - Helpdesk" in the Console.
Renamed "User Password and Intruder Lockout Reset Helpdesk - Specify Containers" applet to "User Account Password Reset and Unlock - Helpdesk - Specify Containers" in the Console.
Renamed "Local Admin Password Reset" applet to "Local Admin Password Reset - bulk - to all selected computers" in the Console.

[UPDATE]
Updated "Accounts with Password problems" applet [adpwdp3.dsr] to include new button service to "Remove 'User cannot change password' setting from selected objects".

[UPDATE]
Updated "AD:Display if selected User's Password is Expired" service to show the password is expired if the setting is present in the userAccountControl attribute or if the pwdLastSet attribute has been cleared. Previously the service relied on the flag in userAccountControl attribute being set.

[UPDATE]
"ADr:Edit New Account's selected Attribute and only allow predefined values to be entered - must be used with Button: "AD:Create User|Contact + Require..."
You can now use this edit text service with pre-defined values to assign a value to the userAccountControl attribute during user creation. This is a bitfield attribute in Active Directory that controls many important settings on user objects. Now you can automatically assign those settings by using a predefined value and setting it as the default value. This was added to fulfill a customer request to automatically set "password never expires" on all new user accounts.

[UPDATE]
Made enhancements to some security options in the Zero Privilege Server Agent configuration. When you specify a group to be "protected" from any changes initiated by Zero Privilege enabled applets, it will now consider nested groups and members of the specified group to be "protected". Also, when you specify a group of authorized users that can use Zero Privilege enabled applets, it will now consider nested groups and members of the specified group.

[FIX]
Modified the OTF alignment when populating group members of a documented group that has permissions

DSRAZOR Updates in 2010

Last Update

Description

2010.12.28

DSRAZOR for Windows Zero Privilege Help Desk

[NEW]
New import keyword (_Move to new OU) to allow moving user ojects to another OU through CSV import.

[UPDATE]
Reduced permissions required when configuring the Zero Privilege Account:
Zero Privilege Account does not need to be a local administrator when the server agent is installed on a member server. Zero Privilege Account does not need to be a member of the Domain "Administrators" group when the server agent is installed on a Domain Controller (unless User Account Control is enabled on the DC).

[UPDATE]
Added the ability to set a preferred DC - useful for member server installation.

Added "ZP Logon Account not enabled for Local Logon on Host Computer" message if Local Logon right has not been granted to ZP account (for use with non-admin account using delegation to the ZP account)

2010.10.07

DSRAZOR for Windows

[UPDATE BUTTON SERVICE]
Button Service:"AD:Rename Account (CN= component only) for selected Active Directory User Account(s)"
This Button Service has been enhanced to accommodate for commas in the CN name.

2010.10.06

DSRAZOR for Windows

[NEW BUTTON SERVICE]
New Button Service:"AD:Rename Account (CN= component only) for selected Active Directory User Account(s)"
Will rename selected Active Directory Account (CN or Common Name).

[FIX]
Updated some of the applets in the Console that are labeled Exchange 2007/2010 to work properly with Exchange 2010.

2010.08.09

DSRAZOR for Windows

[NEW BUTTON SERVICE]
"AD:Expire selected Active Directory user's password"
Will force selected users to change their password on next logon.

2010.07.08

DSRAZOR for Windows

[MODIFY]
Button services that copy user objects will now copy the Logon Hours of the source user to the target user. With this update it will also copy the UPN suffix of the source user and create the UPN logon name of the target user [sAMAccountName + UPN Suffix].

2010.05.13

DSRAZOR for Windows

[NEW HELPDESK APPLET]
Helpdesk Dashboard Example applet [HelpdeskDashboard1.dsr]. This sample applet combines many of the daily user administration tasks into an efficient dashboard-style interface. The initial drilldown can be modified for your environment to reduce the number of windows in the applet. This will further increase the efficiency of the applet.

2010.05.10

DSRAZOR for Windows

[NEW SERVICES]
"FS:List All Controlled File System Objects of selected Trustee + Description + Inherited Flag + Apply To (use with "FS:SEARCH File System ..." service)"

"AD:RULE:Display selected Active Directory Container (can be domain root) to enable Document Effective Rights for User"

"AD:RULE:Display selected Active Directory Container (can be domain root) to enable Document Effective Rights for Group"

"AD:RULE:Document Effective Rights for selected object(s) in the connected list"

FS:List Groups by "SAM Account name" & EFFECTIVE RIGHTS to the selected File System Object (use "AD:RULE:Display Starting AD Container for Doc.Eff.")"

FS:List Groups by LDAP name & EFFECTIVE RIGHTS to the selected File System Object (use "AD:RULE:Display Starting AD Container for Doc.Eff.")"

"FS:List users by "display name" & EFFECTIVE RIGHTS to the selected File System Object (use "AD:RULE:Display Starting AD Container for Doc.Eff.")"

"FS:List users by "SAM Account name" & EFFECTIVE RIGHTS to the selected File System Object (use "AD:RULE:Display Starting AD Container for Doc.Eff.")"

"FS:List users by LDAP name & EFFECTIVE RIGHTS to the selected File System Object (use "AD:RULE:Display Starting AD Container for Doc.Eff.")"

[NEW APPLET]
Effective NTFS Permissions - [EffectivePermissions_Directories.dsr]

This applet will calculate effective NTFS permissions for users and groups on directories in the file system.

[UPDATED APPLETS]
Updated the following applets to use the new service, "FS:List All Controlled File System Objects of selected Trustee + Description + Inherited Flag + Apply To (use with "FS:SEARCH File System ..." service)".

The difference between the old service and the new service is the addition of the "Applies To" information in the Access Control Entries (ACE). This means that the applets will now output the "Applies To" data for the Access Control Entries (ACE) in the reports.
[findFStrustee1.dsr]
[findFSdirTrustee1.dsr]
[findFSdirTrustee_OTF1.dsr]
[findFStrustee_OTF1.dsr]
[fsadmn_OTF4.dsr]
[fsadmnu_OTF4.dsr]
[fsadmnSID_OTF4.dsr]
[findFSdirTrustee_OTF1.dsr]
[fsadmnd_OTF4.dsr]
[fsadmndu_OTF4.dsr]
[fsadmndSID_OTF4.dsr]

2010.05.05

DSRAZOR for Windows

[NEW BUTTON SERVICE]
AD:Remove Group Membership for all groups the selected Object belongs to (except primaryGroupID)

Removes selected user (or other object) from all Active Directory groups( except Primary Group)

[NEW BUTTON SERVICE]
EXCH:MODIFY:HIDE selected AD Account(s) From Exchange Address Lists

Hides selected user from Exchange address lists

[NEW BUTTON SERVICE]
EXCH:MODIFY:SHOW selected AD Account(s) so it can be seen by Exchange Address Lists

[NEW EDIT SERVICE]
ADr:Edit User's(Contact) name to Create|"last, first" format-must be used with Button Service: "AD:Create User(or Contact) + Require EDIT Services..."

This service is very similar to the existing "Edit User's name to Create" service. When assigned to a control on a user creation applet, this edit text service will enter the Account Name (a required attribute) when creating a new user. This new service will auto-populate the Account Name using "Last, First" format based on the information entered for First and Last name. You can optionally override the auto-populated text and either modify it or replace it.


2010.04.30

DSRAZOR for Windows

[UPDATE]
Added functionality to the Local Admin Password Reset applet that indicates if any computers failed to have their admin password reset.

[UPDATE]
Modification made to the "auto close" service to work with the auto import service. This is to close an applet automatically after 60 seconds upon completion.

2010.04.07

DSRAZOR for Windows Zero Privilege Help Desk

[FIX]
Corrected an issue with the Zero Privilege Alert Agent where under certain circumstances it did not display the data for the "On Object" column. This update does not affect the logs because the "On Object" data was always correctly displayed in the logs

DSRAZOR for Windows

[NEW]
The following two services have been updated:
"AD:Display logonHours grid for selected User"
"AD:Display logonHours grid for selected User - Allow changes for one or multiple accounts"

They now allow you to set the days of the week and hours of the day that a user account is authorized to authentication to Active Directory. This information is stored in the logonHours attribute.

2010.03.26

DSRAZOR

[FIX]
Corrected a timezone issue in some reports.

2010.03.23

DSRAZOR for Windows

[FIX]
Removed a popup error with the "AD:Move Home Directory for selected User Account(s) (append SAMname)" button service.

2010.03.10

DSRAZOR - Out to File

[FIX]
With reports that send information directly out to a file, you can now run the same report multiple times in the same session of running the applet.

2010.03.04

DSRAZOR for Windows

[NEW]
The following Service was added to allow rule based query on multi-valued attributes:
"AD:RULE:Search selected Active Directory Multi-Valued Attribute for any values matching Manual Entry value"

2010.03.02

DSRAZOR for Windows

[NEW]
Added a button service similar to existing "copy user" button service. In addition to copying the user this new button service will also create a home directory for the new user in the same parent directory as the source user.

2010.02.26

DSRAZOR for Windows

[NEW]
There are two new services for listing local computer account's Lastpwdset:
"NT:List User Account's Password Last Set"
"NT:Display User Account's Password Last Set"

2010.01.21

DSRAZOR for Windows Zero Privilege Help Desk

[FIX]
The Single Use Password service now works correctly when using Zero Privilege Help Desk.

DSRAZOR Updates in 2009

Last Update

Description

2009.12.10

DSRAZOR for Windows

[NEW SERVICES]
New Display Service to show if an account is hidden from Exchange Address Lists:
"EXCH:Display if selected AD Account is hidden from Exchange Address Lists"

New Listing Service to show if a Control Panel Service logon account has the ability to interact with the desktop session:
"NT:List IF selected Service can interact with the desktop"

New Button Service and import keywords to allow creating/updating groups from a CSV input file:
"AD:IMPORT:Mass Active Directory GROUP Create, SPECIFY [Group Type in Manual Entry] - use with a "Receive CSV file service""

[NEW APPLET]
New Applet for importing groups from CSV file:
"Import Groups from CSV File" [import_groups.dsr]

[NEW CSV EXAMPLE FILES]
importDistGroup.csv and importSecGroup.csv are sample files for the new import_groups.dsr applet.

[ZERO PRIVILEGE HELP DESK]
Added informational popup when removing the server agent.

2009.11.20

DSRAZOR for Windows

[NEW SERVICES]
EXCH:Display if selected AD Account is hidden from Exchange Address Lists

AD:IMPORT:Mass Active Directory GROUP Create, SPECIFY [Group Type in Manual Entry] - use with a "Receive CSV file service"

2009.09.25

DSRAZOR for Windows

[FIX]
"AD:RULE:Move current AD Account to designated Container..."
Now accepts Distinguished Names of up to 128 characters.

2009.09.08

DSRAZOR for Windows

[NEW SERVICE]
"FS:List Servers/Workstations on selected server/workstation Active Directory object"

Allows disk space report to connect to computer object listing in Active Directory rather than relying on a NetBIOS listing of computers in the domain.

[NEW SERVICE]
"FS:List Servers/Workstations in selected Active Directory Container including Shared Disks on selected server/workstation"

Previously you could only select and search a NetBIOS domain name when reporting on disk space usage for computer objects. This new service allows you to select a container with computer objects in it for reporting disk space usage. This allows for quicker results when reporting on a subset of computer objects is desired in larger environments.

[UPDATE]
Updated "Disk Space Report" applet [fssize2.dsr] to use the new services.

DSRAZOR for Windows Zero Privilege Help Desk

[FIX]
Corrected an error message that incorrectly gave a warning message about a licensing problem when using Zero Privilege applets in a specific way.

2009.08.13

DSRAZOR for Windows

[FIX]
"AD:Include Container of Current User Logon in List"
This service was corrected to work with users whose Common Names contain a comma.

[MODIFY]
Made change to "AD:Create User + Require EDIT Services (AD Attributes) on same page [SHOW SUCCESS POP-UP](use EXCH:CREATE Display Mailbox Store on same screen)" service. The notification popup that indicates a new user has been created will no longer popup when attempting to create a user that previously existed.

2009.07.13

DSRAZOR for Windows

[FIX]
Corrected a problem that occurred when reporting lastLogon under special conditions. This problem typically occurred when running applets on a workstation with the local date incorrectly set.

2009.07.01

DSRAZOR for Windows

[NEW]
New display service:
"FS:Display File System Object's Extension (such as DOC, XLS, DLL)"

New display service was added to display file size in MB:
"FS:Display File System Object's Size (MB)"

2009.06.18

DSRAZOR for Windows

[UPDATE]
This update is more tolerant when creating users on slower DCs. It includes a new display service that allows you to specify a delay period (in seconds) for the applet to keep retrying to create the user.

2009.06.11

Visual Click Software proudly announces the release of DSRAZOR for Windows Zero Privilege Help Desk

Completely eliminate providing change permissions to your helpdesk operator accounts!

  • Does not use or rely on Active Directory Delegation
  • Uses a separate server-based service with full security options
  • Create Active Directory Accounts
  • Change Passwords
  • Change Active Directory Details
  • Create Exchange 2007/2010 Accounts
  • Create Home Directories
  • and much more!

  • Extends your existing DSRAZOR for Windows installation - convert your applets to use Zero Privilege Help Desk by adding a single service!
Click here for more details

DSRAZOR for Windows now has support for Exchange 2007/2010

  • Add Exchange Mailbox to Existing User Accounts
  • Add Exchange Mailbox to User Accounts during Import
  • Enable Exchange Mailbox for Contact objects
  • Delete Exchange Mailbox from selected User Accounts
  • Smart Delete of User Account, Home Directory Structure and Exchange Mailbox
  • Quick Search to find User Accounts with or without Exchange Mailbox
  • Document Mailbox Statistics:
    • Account Name
    • Alias
    • Primary Email Address
    • Number of Emails in all folders
    • Size of all Emails in all folders
    • Number of Deleted Emails
    • Size of Deleted Emails
    • Storage Limit Status
    • Last Account Logged on (could be service account)
    • Last Logon Time
    • Rule that indicates if last logon was by the account holder
Click here for more details


2009.05.08

DSRAZOR for Windows

[FIX]
Corrected a problem where the date/timestamp for lastLogon was being incorrectly reported.

Changed the way the "AD:Display if selected User cannot change their own password" service works. It no longer looks at the value in the userAccountControl attriibute - it looks at the permissions on the user object.

2009.05.04

DSRAZOR for Windows

[FIX]
Corrected a token/license check error when specific services were combined.

2009.02.26

DSRAZOR for Windows

[UPDATE]
"EXCH:ENABLE:Exchange 2000 (or later) Mailbox for selected Active Directory Account(s) | EXCH:Display Administrative Group must be on same screen"

This button service can now be used to Exchange enable existing Contact objects.

[NEW]
"ADr:Edit Account's Target Email Address to Create - must be used with Button Service: "AD:Create Contact + Require Edit Services...""

New Edit service allows specifying email address when Exchange enabling existing Contact objects. If the "mail" attribute has a value before Exchange enabling the contact, this edit field will use that value. This can save time if someone has already populated email addresses for non-Exchange enabled Contact objects

2009.02.09

DSRAZOR for Windows

[MODIFY]
When displaying group membership - allow resolving Fully Qualified Domain Name of group members when those group members belong to a different forest.

2009.02.02

DSRAZOR for Windows

[UPDATE]
Updated the "FS:Display IF any Access Control Entry (ACE) grants GENERIC_ALL to selected File System Object" service to facilitate filtering on Full Control permissions.

DSRAZOR for Windows Console

AD User Maintenance

[NEW]
Added "Create Contact from a Template" applet to allow Exchange Enabled contact creation from a form. - [ContactTemplate1.dsr]


2009.01.30

DSRAZOR for Windows

[NEW]
The following new services will allow form-based creation of Exchange enabled contacts:

New button service to create contact objects:
"AD:Create Contact + Require EDIT Services (AD Attributes) on same page (will create Exchange Acct if EXCH:Display Administrative Group is on same screen)"

New edit service to be used when creating Exchange enabled contact objects with button service:
"ADr:Edit Account's Target Email Address to Create - must be used with Button Service: "AD:Create Contact + Require EDIT Services..."

2009.01.29

DSRAZOR

[FIX]
TreeViews that use tab labels now have the data indented correctly when sent directly out to a CSV file.

DSRAZOR for GroupWise

[NEW]
Support for GroupWise 8 GWCHECK.

[FIX]
The applets that use GWCHECK can now handle larger log files.

2009.01.22

DSRAZOR for Windows

[NEW]
The following AD import keywords have been added:
   _Cannot change password
   _Delete Account

2009.01.15

DSRAZOR for Windows Services

[NEW]
"AD:List Trustees (List ACEs) by "displayName" name (where possible) for selected Active Directory Object"

[NEW]
"FS:List Trustees (List ACEs) by "displayName" name (where possible) for selected File System Object"

DSRAZOR Viewer

[UPDATE]
The DSRAZOR Viewer now recognizes applets that have Tab Controls.

DSRAZOR Updates in 2008

Last Update

Description

2008.12.11

DSRAZOR

[NEW]
"Password protect current page, if first page, protects entire applet - enter password in manual entry" - This service can be used to password protect an applet for additional security.

2008.08.19

DSRAZOR Designer

[NEW]
Added Undo/Redo option in the Designer.

[NEW]
Added a Tab control

DSRAZOR for Windows Console

[NEW]
New applet in the "HelpDesk Examples" section titled "Update User Details (tabbed)". [editud_noml_tab2.dsr]

2008.06.12

DSRAZOR for Windows

[UPDATE]
Made improvements to the "AD:IMPORT:Mass User Attribute Update (existing accounts only), use with "receive CSV file service" button service. When encountering an account in the CSV file that does not already exist, an applet using this service will no longer generate popup messages. It will quickly skip the account and log a message in the DSRAZOR audit log indicating "Account not found - no update processed".

2008.06.03

DSRAZOR for Windows

[FIX]
Corrected a problem that sometimes occurred when setting a user account to never expire.

2008.03.28

DSRAZOR for Windows

[FIX]
Corrected a redraw issue with the Console when running on Vista.

2008.03.13

DSRAZOR for Windows

[NEW]
Services help is now available for all of the DSRAZOR for Windows Services. In the Designer, just right click on the service to view the help for that service. Also in the Designer select the menu option "Help/Search for Windows Services" to view help for all the services.

[NEW]
New service is available for reporting share permissions:
FS:ACE:List ACE AccessMask (simple) of Trustee (use with "FS:List Trustees ... service")

This service differs from the NTFS permissions service used previously. It does not show the data mask for the permission and it does not show if the permission was inherited or explicit. Share permissions are always explicit.

[NEW]
New applet for reporting share permissions. [NTSharePerms.dsr] can be accessed by double-clicking "Shares Permissions on Servers and Workstations" in the "Assess AD/NTFS Security" section of the Console.

[UPDATE]
Modified two applets in the Console that report Share permissions. The applets now use a new service to display permissions granted.
[fsListShareACLp3.dsr] and [fsListShareACLp3.dsr]

2008.02.22

DSRAZOR for Windows

[FIX]
Modified Active Directory button search service. Under certain circumstances, the first search performed after opening the applet would return no results, but all subsequent searches would return results. This update resolves that problem.

2008.02.15

DSRAZOR for Windows

[FIX]
Corrected a problem with updating AD attributes.

[FIX]
Search Manual Entry for "AD:Edit selected single-valued Attribute [Clear All Previous Values]" will now list all attributes defined in the schema.

2008.02.05

DSRAZOR for Windows

[UPDATE]
Made enhancements to certain Active Directory connection methods. Connecting to External Forests across a Trust is now more robust. These updates enable connecting to another Forest across an External Trust in certain circumstances where settings were preventing some services from working.

DSRAZOR Updates in 2007

Last Update

Description

2007.12.14

DSRAZOR for Windows

[FIX]
Removed a debug message.

2007.10.25

DSRAZOR for Windows

[FIX]
Now correctly reports group membership if the group contains only one member.

2007.10.03

DSRAZOR for Windows

[Update]
Removed 'AD:Display User's Logon Workstation' service because Microsoft does not populate the 'logonWorkstation' attribute. Alternatively, use the 'AD:List User's Workstations where logon is permitted' service which reports the values in the 'userWorkstation' attribute.

2007.09.27

DSRAZOR for Windows

[FIX]
When limiting the listing of directories in a file system tree to a specified depth, you may now add a display column that shows the aggregate size of the files and folders contained within each directory path. This enhancement allows the service "FS:List ALL Directories from current directory (or Root if none specified) by full name to specified directory depth" to work together with the service "FS:Display Size of Files on selected Path (in KB)".

2007.09.21

DSRAZOR for Windows

[FIX]
Corrected an issue where local time was sometimes being reported as UTC time for last login.

2007.09.20

DSRAZOR for Windows

[New Button Service]
AD:Change User Password - Requires Verification of Existing Password

Allows applet user to reset his or her own password if current password is known.  This service should be connected to a 'AD:Display Who Am I (distinguished name of current user)' service.

2007.09.13

DSRAZOR

[FIX]
Corrected a problem with date sorting introduced in the September 7 build.

2007.09.11

DSRAZOR for Windows

[FIX]
Removed repeated lines from Output To File (OTF) when reporting disk space usage.

2007.09.07

DSRAZOR for Windows

[FIX]
This update resolves a problem displaying group membership.  This is a fix for the oleaut32.dll problem that was introduced with the latest Windows Update (KB921503).

2007.08.21

DSRAZOR for Windows

[FIX]
Updated a licensing issue.

2007.08.02

DSRAZOR

[NEW]
In the Designer you can now export the Window/Control Map.


2007.07.10

DSRAZOR for Windows

[FIX]
Fixed popup error 800500d that occurs in some environments when reporting lastLogon values using a scan across all domain controllers. 


2007.05.29

DSRAZOR for Windows Services

[NEW]
AD:Include in the List, Home Directory Path for use during Create User + Req'd attr.(specify full UNC path such as "\\FS1\share\path", cn will be appended)

NT:List IF selected Service is running

NT:List Service Comment

NT:List Service File Path and startup options

NT:List Service Logon As

NT:List Service Short Name

NT:List Service Start Option

NT:List Service State

[UPDATES]
AD:RULE:For Edit and Display fields: Do not show <unknown> where value is undefined
This Text Control will now hide {unknown} from applet users when ADr:Edit services have no default value set.

The change log now correctly reports changes to userAccountControl.

The service formerly called "AD:Move Home Directory for selected User Account(s)" has been renamed "AD:Move Home Directory for selected User Account(s) (append CN)" to identify its function more clearly.

AD:List Object's Group Membership (show groups belonged to)
Fixed a problem that caused objects' primary group not to resolve to a distinguished name.

[FIXES]
FS:Remove selected Trustee from selected controlled object(s) (use with "FS:List All Controlled File System Objects of selected Trustee" service)
Corrected a problem that prevented button service from removing trustees.

Corrected a problem with time calculations that reported time one hour off in certain circumstances.

Corrected a problem with tabs and List services that would cause applets to fail on occasion.



2007.05.15

DSRAZOR

[UPDATE]
Increased the number of controls that are allowed on the opening screen of an applet.

2007.05.10

DSRAZOR for Windows Console

Assess AD/NTFS Security

[NEW]
ACL Documentation per File System Share - [fsListShareACLp1.dsr]
Document share permissions.

Examine Servers and Disks

[NEW]
Document Share Permissions - [fsListShareACLp1EXA.dsr]
Document share permissions.

AD User Maintenance

[UPDATED]
Create Users with Required Attributes - [cura04c.dsr]
Added auto-creation of user's display name based on last name, a comma, and first name.

Create Users with Required Attributes + Exchange Mailbox - [cura04exc.dsr]
Added auto-creation of user's display name based on last name, a comma, and first name.

Edit Single-Valued Attribute for Selected Accounts - [sved_text4.dsr]
Added buttons to prepend or append text to selected accounts' fax numbers.

Create Users from a Template - [UserTemplate1.dsr]
Added home directory path selection and groups to add automatically during template user creation.

DSRAZOR for Windows Services

[FIXES]
FS:List All Controlled File System Objects of selected Trustee + Description + Inherited Flag (use with "FS:SEARCH File System " service)
Corrected a problem that limited display of controlled objects.

AD:Edit Selected Multivalued Attribute
Corrected the display of existing values when editing attribute.

AD:Move selected Object(s) (Container to move to must be specified with Display Service Canonical Name for Move Operation
Corrected a problem with moving objects with commas embedded in the CN.

The following seven services are now properly treated as returning Boolean values:

  • AD:Display if selected Object has Domain Administrator Status (adminCount set to 1)

  • AD:Display if selected Object is critical system object (IsCriticalSystemObject attribute is TRUE)

  • AD:Display Computer's Role: Schema Master Status (whether or not is Schema Master of Forest)

  • AD:Display Computer's Role: Domain Naming Master Status (whether or not is Domain Naming Master of Forest)

  • AD:Display Computer's Role: PDC Emulator Master Status (whether or not is PDC Emulator Master of Domain)

  • AD:Display Computer's Role: RID Master Status (whether or not is RID Master of Domain)

  • AD:Display Computer's Role: Infrastructure Master Status (whether or not is Infrastructure Master of Domain)
AD:FSMO:List FSMO Roles for selected Primary Domain Root including Global Catalog Status of each DC
Corrected a problem in domains where the pre-AD domain name is different than the relative distinguished name of the AD/DNS domain name.

FS:List All Controlled File System Objects of selected Trustee (use with "FS:SEARCH File System from selected object " service)
Corrected a problem with listing file system objects with high-bit-set ASCII characters. Such objects will now be displayed using their DOS-compatible 8.3 name.

Removed error messages when Output to File (OTF) is enabled for TreeViews with multiple services at the same level under a common parent service.

[UPDATES]
The rule service formerly titled "AD:Display Object's Distinguished Name (Canonical Name) (For Move/Copy Operation {Button Service})" has been renamed "AD:RULE:Display Object's Distinguished Name (Canonical Name) (For Move/Copy Operation {Button Service})" to more clearly indicate its function as a helper service for the "AD:Move" and "AD:Copy" button services.

AD:Erase ALL values of selected Attribute for selected Active Directory Object(s), use Manual Entry to select Attribute
Can now link to a 'AD:Display Who Am I (distinguished name of current user)' Text box to select the user. Removed a pop-up message when targeted attribute is already empty.

GC:Display number of USER objects in selected path
Can now select a domain root in the 'Connect Service to:' field, in addition to the container and Organizational Unit options previously available.

[NEW]
AD:Edit:Append value to text-based Attribute This button service will append text to the specified attribute of selected users. The text-based attribute to modify should be specified in the "Manual Entry Text" field in the Designer.

AD:Edit:Prepend value to text-based Attribute This button service will prepend text to the specified attribute of selected users. The text-based attribute to modify should be specified in the "Manual Entry Text" field in the Designer.

AD:Include in the List, Home Directory Path for use during Create User + Req'd attr.(specify full UNC path such as "\\FS1\share\path", SAMname will be appended) Use this service in a Dropdown List or ListView to display selectable home directory paths in a user creation applet. Rules are used to specify the UNC path(s) of the available home directory location(s). Upon user creation the home directory will be created using the SAM Account Name of the user account in the selected parent directory. The user will be granted permissions to create, delete, and change objects within the Home Directory, but will not be able to assign permissions to his or her Home Directory or delete the Home Directory itself.

AD:Include in the List, thisGroupforMembershipaddduringCreateUser+Req'dattr.(specifyfullLDAPname,example:"CN=MediaGroup,DC=Staff,DC=local") This service can be used in a ListView to specify group membership upon user creation with a button service. Groups should be specified by distinguished name (full LDAP name) in the Rules for the service.

AD:RULE:For Edit and Display fields: Do not show '<unknown>' where value is undefined When this service is present in a Text box on a window with edit and display services, they will show an empty field instead of '' when a value has not been defined.

NT:List All Shares including Ownership and Permission Data This list service will display all shares defined on the selected server, and can be followed in a ListView or TreeView with services that document permissions and other data. See the Console applet "ACL Documentation per File System Share" [fslistShareACLp1.dsr] in the "Assess AD/NTFS Security" section for examples of use of this service.

New services have been added to permit the automated building of a specified attribute value from a combination other attribute values, parts of other attribute values, and static text. An example of this feature is in the applet titled "Create Users with Required Attributes" [cura04c.dsr], which can be found in the "AD User Maintenance" section of the Console. This applet constructs the created user's display name from the user's last name, a comma, and the user's first name.

AD:AUTO:Attribute Name Auto-populate using Rules 1-5 (use with Button Service: "AD:Create User + Require EDIT Services")
This display service specifies which attribute will be built by the following five services. It should be used with one or more of the following five services which will allow you to automate the construction of an attribute's value, as specified by the "AD:AUTO:Attribute Name Auto-populate using Rules 1-5 (use with Button Service: "AD:Create User + Require EDIT Services")" service, with the values of other attributes and static text:

  • AD:AUTO:Rule 1:Attribute Name (use with Display Service "AD:AUTO:Attribute Name")
  • AD:AUTO:Rule 2:Attribute Name (use with Display Service "AD:AUTO:Attribute Name")
  • AD:AUTO:Rule 3:Attribute Name (use with Display Service "AD:AUTO:Attribute Name")
  • AD:AUTO:Rule 4:Attribute Name (use with Display Service "AD:AUTO:Attribute Name")
  • AD:AUTO:Rule 5:Attribute Name (use with Display Service "AD:AUTO:Attribute Name")
To insert the entire value of a single-valued attribute, place the name of the attribute in the "Manual Entry Text" box in the Designer.

To insert the first five characters of an attribute, use "*5*<attributeName>" (without the quotes, and substituting an attribute name for <attributeName>).

To insert the last three characters of an attribute, use "<attributeName>*3*" (without the quotes, and substituting an attribute name for <attributeName>).

To insert static text, two asterisks should precede the static text in the "Manual Entry Text" box in the Designer, for example, "**fixed text" (without the quotes).

The rules will be executed in numerical order to build the attribute specified with the ' AD:AUTO:Attribute Name Auto-populate using Rules 1-5 (use with Button Service: "AD:Create User + Require EDIT Services")' service. Each auto rule service may be used only once, and any number of these AD Auto Rule services may be used to build the specified attribute's value.

2007.04.03

DSRAZOR

[FIX]
Corrected a problem with timezone being one hour off.

2007.03.21

DSRAZOR for Windows Console

Assess AD/NTFS Security

[NEW]
ACL Documentation per File System Share - [fsListShareACLp1.dsr]
Document share permissions.

Examine Servers and Disks

[NEW]
Document Share Permissions - [fsListShareACLp1EXA.dsr]
Document share permissions.

AD User Maintenance

[UPDATED]
Create Users with Required Attributes - [cura04c.dsr]
Added auto-creation of user's display name based on last name, a comma, and first name.

Create Users with Required Attributes + Exchange Mailbox - [cura04exc.dsr]
Added auto-creation of user's display name based on last name, a comma, and first name.

Edit Single-Valued Attribute for Selected Accounts - [sved_text4.dsr]
Added buttons to prepend or append text to selected accounts' fax numbers.

Create Users from a Template - [UserTemplate1.dsr]
Added home directory path selection and groups to add automatically during template user creation.

DSRAZOR for Windows Services

[FIXES]
FS:List All Controlled File System Objects of selected Trustee + Description + Inherited Flag (use with "FS:SEARCH File System " service)
Corrected a problem that limited display of controlled objects.

AD:Edit Selected Multivalued Attribute
Corrected the display of existing values when editing attribute.

AD:Move selected Object(s) (Container to move to must be specified with Display Service Canonical Name for Move Operation
Corrected a problem with moving objects with commas embedded in the CN.

The following seven services are now properly treated as returning Boolean values:

  • AD:Display if selected Object has Domain Administrator Status (adminCount set to 1)

  • AD:Display if selected Object is critical system object (IsCriticalSystemObject attribute is TRUE)

  • AD:Display Computer's Role: Schema Master Status (whether or not is Schema Master of Forest)

  • AD:Display Computer's Role: Domain Naming Master Status (whether or not is Domain Naming Master of Forest)

  • AD:Display Computer's Role: PDC Emulator Master Status (whether or not is PDC Emulator Master of Domain)

  • AD:Display Computer's Role: RID Master Status (whether or not is RID Master of Domain)

  • AD:Display Computer's Role: Infrastructure Master Status (whether or not is Infrastructure Master of Domain)
AD:FSMO:List FSMO Roles for selected Primary Domain Root including Global Catalog Status of each DC
Corrected a problem in domains where the pre-AD domain name is different than the relative distinguished name of the AD/DNS domain name.

FS:List All Controlled File System Objects of selected Trustee (use with "FS:SEARCH File System from selected object " service)
Corrected a problem with listing file system objects with high-bit-set ASCII characters. Such objects will now be displayed using their DOS-compatible 8.3 name.

Removed error messages when Output to File (OTF) is enabled for TreeViews with multiple services at the same level under a common parent service.

[UPDATES]
The rule service formerly titled "AD:Display Object's Distinguished Name (Canonical Name) (For Move/Copy Operation {Button Service})" has been renamed "AD:RULE:Display Object's Distinguished Name (Canonical Name) (For Move/Copy Operation {Button Service})" to more clearly indicate its function as a helper service for the "AD:Move" and "AD:Copy" button services.

AD:Erase ALL values of selected Attribute for selected Active Directory Object(s), use Manual Entry to select Attribute
Can now link to a 'AD:Display Who Am I (distinguished name of current user)' Text box to select the user. Removed a pop-up message when targeted attribute is already empty.

GC:Display number of USER objects in selected path
Can now select a domain root in the 'Connect Service to:' field, in addition to the container and Organizational Unit options previously available.

[NEW]
AD:Edit:Append value to text-based Attribute This button service will append text to the specified attribute of selected users. The text-based attribute to modify should be specified in the "Manual Entry Text" field in the Designer.

AD:Edit:Prepend value to text-based Attribute This button service will prepend text to the specified attribute of selected users. The text-based attribute to modify should be specified in the "Manual Entry Text" field in the Designer.

AD:Include in the List, Home Directory Path for use during Create User + Req'd attr.(specify full UNC path such as "\\FS1\share\path", SAMname will be appended) Use this service in a Dropdown List or ListView to display selectable home directory paths in a user creation applet. Rules are used to specify the UNC path(s) of the available home directory location(s). Upon user creation the home directory will be created using the SAM Account Name of the user account in the selected parent directory. The user will be granted permissions to create, delete, and change objects within the Home Directory, but will not be able to assign permissions to his or her Home Directory or delete the Home Directory itself.

AD:Include in the List, thisGroupforMembershipaddduringCreateUser+Req'dattr.(specifyfullLDAPname,example:"CN=MediaGroup,DC=Staff,DC=local") This service can be used in a ListView to specify group membership upon user creation with a button service. Groups should be specified by distinguished name (full LDAP name) in the Rules for the service.

AD:RULE:For Edit and Display fields: Do not show '<unknown>' where value is undefined When this service is present in a Text box on a window with edit and display services, they will show an empty field instead of '' when a value has not been defined.

NT:List All Shares including Ownership and Permission Data This list service will display all shares defined on the selected server, and can be followed in a ListView or TreeView with services that document permissions and other data. See the Console applet "ACL Documentation per File System Share" [fslistShareACLp1.dsr] in the "Assess AD/NTFS Security" section for examples of use of this service.

New services have been added to permit the automated building of a specified attribute value from a combination other attribute values, parts of other attribute values, and static text. An example of this feature is in the applet titled "Create Users with Required Attributes" [cura04c.dsr], which can be found in the "AD User Maintenance" section of the Console. This applet constructs the created user's display name from the user's last name, a comma, and the user's first name.

AD:AUTO:Attribute Name Auto-populate using Rules 1-5 (use with Button Service: "AD:Create User + Require EDIT Services")
This display service specifies which attribute will be built by the following five services. It should be used with one or more of the following five services which will allow you to automate the construction of an attribute's value, as specified by the "AD:AUTO:Attribute Name Auto-populate using Rules 1-5 (use with Button Service: "AD:Create User + Require EDIT Services")" service, with the values of other attributes and static text:

  • AD:AUTO:Rule 1:Attribute Name (use with Display Service "AD:AUTO:Attribute Name")
  • AD:AUTO:Rule 2:Attribute Name (use with Display Service "AD:AUTO:Attribute Name")
  • AD:AUTO:Rule 3:Attribute Name (use with Display Service "AD:AUTO:Attribute Name")
  • AD:AUTO:Rule 4:Attribute Name (use with Display Service "AD:AUTO:Attribute Name")
  • AD:AUTO:Rule 5:Attribute Name (use with Display Service "AD:AUTO:Attribute Name")
To insert the entire value of a single-valued attribute, place the name of the attribute in the "Manual Entry Text" box in the Designer.

To insert the first five characters of an attribute, use "*5*<attributeName>" (without the quotes, and substituting an attribute name for <attributeName>).

To insert the last three characters of an attribute, use "<attributeName>*3*" (without the quotes, and substituting an attribute name for <attributeName>).

To insert static text, two asterisks should precede the static text in the "Manual Entry Text" box in the Designer, for example, "**fixed text" (without the quotes).

The rules will be executed in numerical order to build the attribute specified with the ' AD:AUTO:Attribute Name Auto-populate using Rules 1-5 (use with Button Service: "AD:Create User + Require EDIT Services")' service. Each auto rule service may be used only once, and any number of these AD Auto Rule services may be used to build the specified attribute's value.

2007.02.08

DSRAZOR

[UPDATE]
The Out To File in TXT format will now have a more consistent number of records per page.

DSRAZOR for Windows

[FIX]
DSRAZOR will now give a more user friendly error when running Group Membership type applets and it cannot bind to the Global Catalog.

[FIX]
The Service "AD:Display Number of Members for selected Group" will now return the correct value.

Click here to see updates from 2006

 

 

Questions? Please call direct: 512 330 0542
Questions?Here's some easy ways to get the answers you need.
Phone
  • (512) 330-0542
  • (877) 902-5425