How does Directory and Resource Administrator enforce SAMAccountName uniqueness across domains? (NETIQKB38376)

  • 7738376
  • 02-Feb-2007
  • 19-Jun-2007

Resolution

goal
How does Directory and Resource Administrator enforce SAMAccountName uniqueness across domains?

fact
Directory and Resource Administrator 6.x

fact
Directory and Resource Administrator 7.x

fix

Directory and Resource Administrator (DRA) enforces SAMAccountName if the built-in $NameUniquenessPolicy is enabled.

The $NameUniquenessPolicy, if enabled enforces SAMAccountName uniqueness across all managed and trusted domains. The policy prevents Assistant Admins from creating new user or group accounts with the same SAMAccountName if that name already exists in any of the managed or trusted domains.  The policy checks the DRA Cache to ensure that no user or group account in any of the managed or trusted domains have the same SAMAccountName.  DRA does not check trusted domains that have been omitted.



Additional Information

Formerly known as NETIQKB38376