Creating User Templates


 

Using ADManager Plus templates, you can configure values for different attributes of users, computer, contacts and groups. Once you apply this template during creation or modification of the Active Directory objects , the objects will automatically take the corresponding attributes that have been configured in the template. One common scenario which manifests the usage of templates is described below:

 

Suppose there are a number of people who are joining the Sales department at the same time. Administrators can handle this very smartly by creating a template and configuring the various attributes for the users based on their requirement. Then, just import apply this template during user creation which will thus fill the attributes of the users automatically.

 

Procedure:

 

You have to enter a suitable name , description and domain in which the template will be created. Then, enter the values for various user attributes which are present under the different tabs and finally save the template.

 

Steps:

  1. Click the AD Mgmt tab.

  2. Click the Create User Template link available under Create Template. This opens the Create Template dialog.

  3. Specify a name and description for the template.

  4. Specify the values for User Profile attributes. Note: Selecting the option "Automatically append numbers starting from 2, if there are any duplicate names" will enable to create duplicate names prefixed with numbers. Example: If you try to create a user named 'john' which already exists, ADManager Plus will duplicate the name with 'john2' and so on.

  5. Select the Account Details tab and specify the account properties.

  6. Select the Contact Details tab to specify the contact information about the user.

  7. Select the Exchange Server tab to specify the exchange attributes

  8. Select the Terminal Services and specify the terminal services attributes.

  9. Select the Custom Attributes link tab and enable the Run Custom Script on the Successful User Creation checkbox, to invoke any customized script immediately after user creation.
  10. After specifying all the attributes as required, click Save Template.

 

 

The templates thus created will be available in the bulk user creation wizard from where you can select to apply templates for the users.

 

For details on the user attributes, refer to the Microsoft Documentation here and here.

 

Note:

  1. You can also apply a created templates by importing CSV file. The LDAP attribute "templateName" is mandatory.

  2. To create Mailbox Enabled Users in Exchange 2007, you would require the Exchange Management Console, failing which the legacy Mailbox will be created.

  3. For attributes like Logon Name, Display Name, Email, etc., you can choose any of the formats listed in the combo box. The chosen format will be automatically applied when you add users based on this template.

  4. When specifying the Local Path for the Home Folder for the users, you can use any LDAP Attributes in the path, which will be replaced during user creation dynamically. For example, a path can be specified as C:\Documents and Settings\%LogonName%, where, %LogonName% will be replaced by the corresponding Logon Name of the user dynamically.

 

Viewing/Modifying User Templates

 

To view or to modify the user templates,

  1. Click the AD Mgmt tab.

  2. Click the View User Template link available under Create Template. This will list all the templates that were created.

    Tip: You can sort the templates in ascending/descending order using the arrow icon near the Template Name heading.
  3. Click on the last icon under Action heading, to set that particular template as the default template.

  4. To modify the template click the template name or the icon to open the Modify User Template dialog.

  5. Modify the attributes as required and click Save Template.

 

Note: The modification to the attributes will not modify the user attributes of the users created prior to modification of the template. This applies to the users created henceforth using this template.

 

User Creation with Advanced Permissions: While creating User template you can assign advanced permissions and share properties, and eventually all the users created with those template will bear those permissions.

 

You will find these advanced permissions available in the following places:

 

 

Advanced features in User Creation:

 

For Profile path:

 

Profile path specifies a Uniform Naming Convention (UNC) name, such as \\Server\Prof$\%username%, to be the network folder where the user's roaming profile is stored. This way, user's roaming profile is downloaded to whichever  workstation he logs onto and it is uploaded back to the server when he logs off. The dollar sign ($) in the Prof$ sharename makes it invisible so that users don't browse it.

 

Configuring the property "Profile path":

  1. "Profile path" attribute can be found in the "Account Details" tab of "Create Template" wizard.

  2. While specifying profile path click on 'Permissions' adjacent to it, this will open a window for profile path settings.

  3. check in the box to Create Profile Path Directory before user first login

  4. you can add more permissions by selecting the tab 'Permissions' to Add More Permissions'.

  5. This leads you to set of options where in you can allow a selected user or group or computer, to have permissions like full control, read attributes, delete etc, over folder and its descendants.

  6. Click on Add.

  7. Check in the Box below to Inherit from parent the permission entries that apply to child objects.

Note: You can also create profile path for Windows Vista users by suffixing it with '.V2'. Example: Let's say the normal profile path looks like 'C: \Documents and settings\Jim', the Vista profile path will look something like 'C: \Documents and settings\Jim.V2'.

 

 

For Home folders:

Home folders and My Documents make it easier for an administrator to back up user files and manage user accounts by collecting the user's files in one location. If you assign a home folder to a user, you can store the user's data in a central location on a server, and make backup and recovery of data easier and more reliable.  ADManager Plus has provided some special features that helps in quickly configuring these properties for the user. 

Configuring the property "Home Folder":

  1. "Home folder" attribute can be found in the "Account Details" tab of "Create Template" wizard.
  2. Click "Connect" and specify a  drive letter.
  3. In the box nearby, type a path. This path can be any of the following types:
    1. Network path, for example: \\server\users\tester
    2. You can substitute username for the last subfolder in the path, for example: \\server\users\%username%
    3. Where server is the name of the file server housing the home folders, and where users is the shared folder.<>
    4. The "%username%" will automatically get expanded to the user's name.
ADManager Plus also automatically creates a share of the format "\\server\%username%" and allows you to set the desired permissions for this network folder by clicking on the Permissions link. Enable the check box provided across "Create a New Share" below the "home folder" in order to create a new share folder in the network.
 
For Mailbox Rights:
 
Mailbox rights allows to set permissions on users access to mailboxes. In native active directory you can set mailbox rights only after creating users,  but with ADManager Plus you can provide the mail box rights while creating users.
 
Perform the following steps:
 
1. Set Mailbox rights can be found in the 'Exchange server' tab of 'create template' (ADMgmt-->create user Template). This applies to mailbox enabled users.
2. Click on "set Mailbox rights"
3. View the available permissions and Click on "ADD More permissions" to provide more permissions.
4. Select the operation either 'Allow' or 'Deny', select the object, select the permissions from the available list, select the scope of the operation.
5. Click on 'Add', then you will find the added permission.
6. Click OK.   
 
 
   
   

Enable Live Communications/ Office Communication Server 2007 Support :

  

Select the LCS/OCS server. Specify SIP-URI (Session in Protocol -URI) format

  

The SIP-URI format should be of a valid format. Example; sip: user@domain.com

  

Also provide

  

  

for the users imported from the CSV file in the template by checking in the respective checkboxes provided across them.

  

Native Active Directory supports enabling Live Communication. ADManager Plus facilitates easily enable and configure of Live Communication settings with the help of templates and by avoiding command line tools.

 

 

 

 



Copyright © 2011, ZOHO Corp.All Rights Reserved.