Creating User Templates


 

Templates play an important role in maintaining different permissions for different levels of users. You can create as many templates as required to suit your needs, which can then be used in creating user accounts by just specifying the user names. To create a user template follow the steps below:

  1. Click the AD Mgmt tab.

  2. Click the Create User Template link available under Create Template. This opens the Create Template dialog.

  3. Specify a name and description for the template.

  4. Specify the values for User Profile attributes. Note: Selecting the option "Automatically append numbers starting from 2, if there are any duplicate names" will enable to create duplicate names prefixed with numbers. Example: If you try to create a user named 'john' which already exists, ADManager Plus will duplicate the name with 'john2' and so on.

  5. Select the Account Details tab and specify the account properties.

  6. Select the Contact Details tab to specify the contact information about the user.

  7. Select the Exchange Server tab to specify the exchange attributes

  8. Select the Terminal Services and specify the terminal services attributes.

  9. After specifying all the attributes as required, click Save Template.

The templates thus created will be available in the bulk user creation wizard from where you can select to apply templates for the users.

 

For details on the user attributes, refer to the Microsoft Documentation here and here.

 

Note:

  1. For attributes like Logon Name, Display Name, Email, etc., you can choose any of the formats listed in the combo box. The chosen format will be automatically applied when you add users based on this template.

  2. When specifying the Local Path for the Home Folder for the users, you can use any LDAP Attributes in the path, which will be replaced during user creation dynamically. For example, a path can be specified as C:\Documents and Settings\%LogonName%, where, %LogonName% will be replaced by the corresponding Logon Name of the user dynamically.

 

Viewing/Modifying User Templates

 

To view or to modify the user templates,

  1. Click the AD Mgmt tab.

  2. Click the View User Template link available under Create Template. This will list all the templates that were created.

  3. To modify the template click the template name or the icon to open the Modify User Template dialog.

  4. Modify the attributes as required and click Save Template.

Note: The modification to the attributes will not modify the user attributes of the users created prior to modification of the template. This applies to the users created henceforth using this template.

 

User Creation with Advanced Permissions: While creating User template you can assign advanced permissions and share properties, and eventually all the users created with those template will bear those permissions.

 

You will find these advanced permissions available in the following places:

 

 

Advanced features in User Creation:

 

For Profile path:

 

Profile path specifies a Uniform Naming Convention (UNC) name, such as \\Server\Prof$\%username%, to be the network folder where the user's roaming profile is stored. This way, user's roaming profile is downloaded to whichever  workstation he logs onto and it is uploaded back to the server when he logs off. The dollar sign ($) in the Prof$ sharename makes it invisible so that users don't browse it.

 

Configuring the property "Profile path":

  1. "Profile path" attribute can be found in the "Account Details" tab of "Create Template" wizard.

  2. While specifying profile path click on 'Permissions' adjacent to it, this will open a window for profile path settings.

  3. check in the box to Create Profile Path Directory before user first login

  4. you can add more permissions by selecting the tab 'Permissions' to Add More Permissions'.

  5. This leads you to set of options where in you can allow a selected user or group or computer, to have permissions like full control, read attributes, delete etc, over folder and its descendants.

  6. Click on Add.

  7. Check in the Box below to Inherit from parent the permission entries that apply to child objects.

For Home folders:


Home folders and My Documents make it easier for an administrator to back up user files and manage user accounts by collecting the user's files in one location. If you assign a home folder to a user, you can store the user's data in a central location on a server, and make backup and recovery of data easier and more reliable.  ADManager Plus has provided some special features that helps in quickly configuring these properties for the user. 

Configuring the property "Home Folder":

  1. "Home folder" attribute can be found in the "Account Details" tab of "Create Template" wizard.
  2. Click "Connect" and specify a  drive letter.
  3. In the box nearby, type a path. This path can be any of the following types:
    1. Network path, for example: \\server\users\tester
    2. You can substitute username for the last subfolder in the path, for example: \\server\users\%username%
    3. Where server is the name of the file server housing the home folders, and where users is the shared folder.<>
    4. The "%username%" will automatically get expanded to the user's name.
ADManager Plus also automatically creates a share of the format "\\server\%username%" and allows you to set the desired permissions for this network folder by clicking the adjacent "Permissions" link.
 
For Mailbox Rights:
 
Mailbox rights allows to set permissions on users access to mailboxes. In native active directory you can set mailbox rights only after creating users,  but with ADManager Plus you can provide the mail box rights while creating users.
 
Perform the following steps:
 
1. Set Mailbox rights can be found in the 'Exchange server' tab of 'create template' (ADMgmt-->create user Template). This applies to mailbox enabled users.
2. Click on "set Mailbox rights"
3. View the available permissions and Click on "ADD More permissions" to provide more permissions.
4. Select the operation either 'Allow' or 'Delete', select the object, select the permissions from the available list, select the scope of the operation.
5. Click on 'Add', then you will find the added permission.
6. Click OK.   
 
 
 

 
 

 

 

 

 



Copyright © 2007, AdventNet Inc. All Rights Reserved.