ManageEngine ADManager Plus Release Notes
ManageEngine ADManager Plus 6.5
Highlights of Build 6510
- Exchange auto-reply settings: ADManager Plus provides a GUI-based capability to configure automatic replies for the emails sent to your users' Exchange mailboxes, which offers options to:
- Enable/ disable automatic replies to senders from your organization.
- Enable/ disable automatic replies to senders from other organizations.
- Send different replies to senders from your organization and to those from other organizations.
- Specify the time period during which automatic replies must be sent.
- Support for custom attributes in computer creation: The existing custom attributes can now be mapped to computer creation as well. Also, new custom attributes can be added while creating computer objects, in single or bulk, using ADManager Plus.
Workflow has been enriched with the following enhancements:
- Requesters now get an option to cancel the requests that they create.
- Email notifications sent to workflow technicians now include a link to access the relevant request instantly.
- Notification settings now include three new macros using which you can add the reviewer, approver, and executor details in the notification message.
- All changes made to the objects in a workflow request will now be audited.
For the users that will be disabled/ deleted using ADManager Plus, the 'disable/ delete policy' includes the following actions as well:
When an AD user account is disabled, you can also:
- Disable the user's Google Apps account.
- Revoke the user's Office 365 license.
When an AD user account is deleted, you can also:
- Delete the user's Google Apps account.
- Delete the user's Office 365 account.
Option to configure the ‘reset password policy' in ADManager Plus database for automatically resetting users’ Office 365 and Google Apps passwords, whenever their AD passwords are reset.
The following issues have been fixed in this release:
Error in setting proxy addresses if givenName contains space(s).
- Inability to assign values for the custom attributes: msExchExtensionCustomAttribute (1-5) and msExchAddressBookPolicyLink.
- During user modification, the changes made to a user's mail alias not being reflected in the email address, when the recipient policy specifies alias as the local part of email address and the option 'automatically update e-mail addresses based on recipient policy' is selected.
Error in user creation with Exchange properties if the user account gets created in one DC and Exchange connects to another DC to configure the Exchange properties, due to a replication issue between the DCs.
Highlights of Build 6500
- Smart card authentication: The use of smart cards/ PKI/ certificates has been enabled as additional options for ADManager Plus login. If you have such an authentication system configured in your organization, ADManager Plus can be configured to authenticate users through it, bypassing other first factor methods.
- Support for Exchange 2016: With this release, ADManager Plus supports management and reporting on Exchange Server 2016 environment as well.
- Google Apps reports: These new reports provide detailed information such as, all users, active users, and suspended users in your Google Apps environment.
- Copy automation: It simplifies the creation of new automations by allowing you to copy the settings of an existing one and eliminating the need to create a new one from scratch. The newly created automation can then be modified, as per requirement.
Automation now includes the following:
- Modify users using templates
- Disable, disconnect, or delete user mailboxes.
- Hide from Exchange address lists.
- Create groups using templates.
- Create contacts using templates.
- Exclude child OUs from the selected OUs, while specifying the scope of a task that should be executed automatically.
'Run now' to instantaneously run any automation from the list of scheduled automations.
- 'User can't change the password' and 'set password never expires', while automating the 'reset password' task.
While creating a user account in Google Apps, its group membership and the organizational unit where it must be located can also be specified.
- While managing a workflow request that was created via automation policy, an option to remove objects either from that particular request, or from all the requests generated by that automation policy, is provided.
- Bulk modify templates option allows modification of more fields such as, Google Apps, Office 365, and Lync attributes.
- Report scheduler now includes an option to exclude the child OUs while specifying the OUs for which the reports have to be generated.
- Using ADManager Plus’ iOS mobile app, you can now:
- - View all the workflow requests that you have created.
- - View all open requests, among the requests assigned to you.
The following issues have been fixed in this release:
Inability to generate 'NTFS permissions for folders' report of a domain when authenticated with its child domain's credentials.
- In help desk audit reports, SID being displayed in place of distinguished name for a cross-forest group member, when listing group management actions performed by technicians.
- inetOrgPerson object class not being supported in 'group members' report.
Issue in starting the product after service pack installation if database has been migrated to MS SQL.
Error in report generation if only multi-valued attributes are selected (in add/ remove columns) to be displayed.
- In user modification templates, issue in applying a modification rule when 'select container' is specified in the conditions field.
Highlights of Build 6380
- Move contacts: You can now move contact objects from one container (organizational unit) to another. As per your need, you can:
- Move a single contact.
- Move multiple contacts at a time.
- Use CSV import to move contacts in bulk.
- Copy schedule: This feature simplifies the creation of new report schedules by allowing you to copy the settings of an existing schedule. The settings can then be modified, as per requirement.
- ADManager Plus mobile apps (v2.0) now support workflow and important user reports: Using the latest version of ADManager Plus iOS and Android apps, you can view and manage workflow requests, and also execute the tasks requested. Furthermore, you can generate the user reports - 'locked out', 'disabled', 'password expired', and 'inactive' - as well as perform the required management actions right from these reports.
- Automation now provides the flexibility to either overwrite or append the values of user attributes while modifying user accounts.
- Report Scheduler now allows you to:
Select multiple inputs while scheduling 'group members', 'users with empty attributes', and 'OS-based computers' reports.
- Schedule ‘shares in the servers’ and ‘permissions for folders’ reports as well.
- User creation templates now offer a new option - Creation Rules. It can be used to specify the attributes that should automatically be updated with predefined values whenever a user account is created. It also offers an option to set up conditions, which on being satisfied, shall auto-populate the specified fields in the user account being created.
- Single user modification also includes Copy User Attributes option.
- 'Shares in the servers' report also displays NTFS and share permissions in the file when it is exported to the desired format.
- Custom attributes can now be used as a filter:
In Report Scheduler, to refine the report results.
In Automation, while specifying the objects to be managed.
- Enhanced UI for selecting values in department, title, company, and office attributes:
- Navigation arrows to view the next thirty entries in the list.
- Predictive Search option to easily locate the desired entry. The search settings can be enabled/disabled from the Admin tab.
- 'Detailed group members' report now also lists cross-forest members.
The following issues have been fixed in this release:
- While modifying an automated task or policy, inability to remove the selected report (that lists the objects on which the automated task or policy has been applied).
- Inability to enable or disable display of well-known security principals while creating a File Server Management help desk role.
- Inability to copy any of the user attributes when memberOf is included in the list of attributes to be copied.
- Issues in the email delivery of 'inactive users' report.
- 'Lync Online' being displayed in place of 'Skype for Business Online' while assigning Office 365 licenses.
Highlights of Build 6371
Room mailbox management: You can now create new room mailboxes in both on-premise Exchange Server as well as cloud-based Office 365, from a single window. This feature also offers the capability to modify room mailboxes in Exchange Server.
Also, to simplify the process of creating and modifying room mailboxes, this feature offers customizable room mailbox creation and modification templates.
Equipment mailbox management: This feature enables you to create new equipment mailboxes in Exchange Server and also Office 365. You can also modify an existing equipment mailbox in Exchange Server using this feature.
This feature also includes configurable equipment mailbox creation and modification templates, to help you fine tune the process of creating and modifying equipment mailboxes exactly as per your needs.
Disable policy allows you to define a set of tasks (deleting home folders, profiles, disabling mailboxes, execute a script, etc.) that must be executed when any user account is disabled. Further, this feature also allows you to create domain-specific disable policies.
Delete Policy now includes new options which allow you to move remote home folders, and also execute a custom script, to perform any specific action, while deleting a user account from Active Directory.
The 'Manager can update members list' option can now be enabled during bulk or CSV-based
creation and also modification of groups.
- The 'protect from accidental deletion' option is now included in both the single and bulk OU creation features.
- The automation feature now allows you to add or remove computers from groups.
The scheduler for detailed group members report now features more options to offer more
flexibility in specifying the report generation time and frequency.
The 'BitLocker recovery keys' report now displays the computer name as well.
Shared mailbox management now includes customizable templates for creating and modifying shared mailboxes.
Issue in disabling users via automation is now fixed.
Issue in removing the objects to be managed from a request that is yet to be executed is fixed.
While creating an account provisioning template or editing an existing one, the read-only fields will now be displayed distinctly, to easily distinguish them from the editable ones.
Highlights of Build 6361
Remote mailbox creation: You can now configure remote mailboxes while creating new accounts for users, individually, as well as, in bulk.
Highlights of Build 6360
Move or delete users' Terminal Services home folders and profile paths: This feature allows you to delete or move the Terminal Services home folders or profile paths for multiple users at once. Also, while moving the terminal services home folders or profile paths, you can choose to retain a copy of them in the original location.
Help desk technicians report: This report lists all available help desk technicians, along with details like their delegated domains and OUs, roles, management and reporting tasks, etc. It also offers filters to view:
The report can also be exported to CSV, PDF, XLSX, and HTML formats.
- the settings of any specific help desk technician. Or,
- all technicians matching a specific criterion (like delegated domains, delegated tasks, etc.).
GUI-based configuration of high availability setup: You can now configure the settings of various components (primary server, backup server, and virtual IP to access the server) required to ensure high availability of ADManager Plus server from the GUI-based console.
Scheduled generation and email delivery of reports is now available for Password Policy, Account Lockout Policy, and Printer Reports also.
Help desk technician audit report can now be exported to CSV, PDF, XLSX, and HTML formats.
- The AD objects (users, groups, etc.) in the member and memberOf attributes will now be displayed in alphabetical order.
In modification templates, issues while applying modification rules when OU is specified as a condition.
Inability to assign templates to workflow requesters by help desk technicians.
OU selection pop-up taking a long time to load child OUs.
In help desk technician audit report, passwords of the user accounts created by the technician not being displayed in the 'details' of the action performed.
Inability to add proxyAddresses as custom attribute during group creation.
In help desk reset password console, need of an 'all domains' option in the domain search field to list users from all the domains configured.
In help desk password reset console, the option 'user must change password at next logon' not being a default selection.
In bulk user modification, error while importing a CSV file containing employeeID attribute.
Highlights of Build 6350
Support for Windows 10: With this release, ADManager Plus extends support for Windows 10 as well.
- Exclude nested groups from Group Members report: You can now choose to generate Group Members report of specific groups with only the members belonging to that particular group, i.e. without nested group members, appearing in the report.
- New time-based filters for reports: While generating time-bound reports like recently created groups, recently expired user accounts, and so forth, you can now easily specify the precise period for which you need the reports using options such as, today/yesterday, on/before/after a specific date, last 'n' days, this week/month, any custom period, etc.
The following issues have been fixed in this release:
- Issues in listing the NTFS permission for folders located in DFS environment.
- Error while modifying a user's Exchange mailbox server and store settings.
- Error while applying retention policy during user creation.
- While creating titles, departments, offices, and companies, duplicate values were being created if spaces were left after an entry.
- Inability to export memberOf attribute from a report to csvde format.
- Issues in provisioning users in Office 365 while creating mail or mailbox enabled users in Active Directory.
- Issues in applying email address policy while creating mail enabled groups.
Highlights of Build 6340
Skype for Business (Lync 2015) Management & Reporting: Besides Lync 2010 and 2013, you can now manage and report on user accounts in Lync 2015 / Skype for Business (SfB) as well. That is, right from ADManager Plus' console, you can now:
- Create SfB/Lync user accounts, along with all relevant settings / policies (Telephony, Conferencing policy, External access policy, etc.)
- Enable/Disable/Delete SfB or Lync user accounts
- Modify the SfB/Lync policies (Conferencing, Archiving, and Telephony) of specific users
- Identify all SfB/Lync enabled or disabled users via pre-defined reports
Manage AD User Photos: This feature enables you to manage the profile pictures of Active Directory users individually, as well as, in bulk, by allowing you to:
- upload new pictures
- crop existing pictures
- replace existing photos with different ones
- delete pictures
- Displaying users' AD attributes in Office 365 reports: Besides users' O365-specific attributes, the Office 365 reports now also display their important AD attributes such as SID, SAM Account Name, OU Name, Object GUID, etc.
- ADManager Plus now uses an upgraded version of Tomcat for enhanced reliability and security.
The following issues have been fixed in this release:
- Issues in adding cross-forest members while creating and modifying groups, in single and in bulk.
- Exporting 'users in groups' report to xlsx results in the downloaded file's name being cluttered with special characters.
- Product crashes while modifying the 'memberOf' attribute of users, if the DN of the group exceeds 260 characters.
- While trying to create Exchange mailbox, legacy mailbox gets created instead, if there are issues in establishing remote PowerShell session.
- Recovery mailbox database appears in Mailbox Store drop down list.
Highlights of Build 6330
Shared Mailbox Creation and Modification features enable you to create and modify shared mailboxes in both, on-premise Exchange Server, as well as cloud-based Office 365, from a single console.
Copy Technician feature allows you to copy all the settings (delegated roles, assigned templates, and the domains/OUs/groups that can be managed) of any help desk technician, and use those copied values to create a new technician; eliminates the need for creating a new one from scratch.
Admin Audit Report helps in auditing all the changes made to a help desk technician or a help desk role's configuration, by listing all actions (creation, modification, and deletion) performed on it, along with details such as, who made the changes, the date and time at which they were performed, etc.
Bulk Management of Help Desk Technicians: The Active Directory (AD) delegation feature now allows you to create and modify help desk technicians in bulk.
Create new Help Desk Technicians in bulk, by delegating the required roles and OUs to all the relevant AD users, at once.
Bulk Edit Technicians allows you to modify multiple help desk technicians (add/remove roles, templates, and OUs assigned to them) in one go, making management of help desk technicians easier and quicker.
Export technicians and roles option allows you to export the details of all existing help desk roles and technicians to html, pdf, and excel formats.
- The issue of Office 365 license count not being shown correctly has been fixed.
- CSV import now supports the creation of computers and contacts in different OUs, as required, using 'ouName' as CSV header. (In previous versions, bulk creation of computers or contacts could only be done in one OU at a time.)
- Issues in bulk deletion of titles, departments, offices, and companies have been sorted.
- In Automation, custom attributes can also be imported via CSV files.
Highlights of Build 6322
Computers not in groups report displays all the computers that do not belong to (not members of) any of the Active Directory groups that you specify.
View common members of the specified groups - The 'detailed group members' report now features an option to list the members who are common (part of) to all the selected Active Directory groups. In other words, this option fetches all the users, groups, computers and contacts which are members of all the specified AD groups.
More options for deleting AD users; you can now locate and delete the desired AD user account using the 'single user modification' and 'AD Explorer' features too.
New values appended to the Title, Department, Office and Company fields in AD directly will be automatically updated in ADManager Plus ( at 0100 hrs everyday), and available for selection in the relevant user management features.
(If you wish to immediately update and use a new value for any of these fields immediately, you can add the desired value manually in ADManager Plus's Admin tab.)
While reviewing, approving or executing the user creation requests, in the workflow, the corresponding technicians can now change the template specified in the request to a different one, as needed.
While assigning managers for AD objects, besides users it is now possible to select a group or a foreign security principal as well as managers.
During bulk creation of new contacts, groups and computers, you can now set the values for their custom attributes as well.
Logo customization option to personalize and rebrand ADManager Plus by replacing its logo with your organization's logo.
The following issues have been fixed in this release:
- Unable to delete users via the delete option in the 'disabled users report'.
- Domain name not being displayed in the 'permission for folder' report while selecting the required shared resource's path.
- Product crashes whenever a management action is performed on users with a lengthy DN (>250 characters).
- Proxy addresses and extension (custom) attributes of users and groups not being displayed in Exchange reports.
- The 'check all' option not working as desired in the 'inactive users report'.
- Issues in 'permissions for folders report': not being able to type the shared folder path, and unable to generate this report for a custom level (number of folder levels).
- Error in adding proxy address in formats other than SMTP, such a X.400, X.500, etc., during creation or modification of AD users, groups and contacts.
- Help desk technicians not being able to configure the delegated fields while creating new contacts via bulk contact creation.
- The necessity to use the same password format for all the users while creating new users via the bulk user creation feature (you can now specify different password formats for different users).
- Error in configuring Google Apps accounts.
Highlights of Build 6310
Grant 'SendAs' permission to Active Directory (AD) users during user creation and modification: You can now set the 'Send As' permission for users right during their onboarding process, in single or in bulk, using the new option added to the single and bulk user creation features; you can configure the 'Send As' permission for existing users too using the single user modification feature.
Flexible CSV-based modification of AD objects:The CSV import feature has been enhanced by adding the following options to offer more flexibility for modifying AD objects:
- - For multi-valued attributes: you can choose to either append the values specified in the CSV file to the attributes' existing values in AD, or overwrite their existing AD values with the values specified in the CSV file.
- - If the value of an attribute in the CSV file is empty, you can now choose to either clear the attribute's existing value in AD, or retain its current value in AD, as per your need.
Bulk modification of user creation templates: This option allows you to make the desired changes to multiple user creation templates at once. For example, consider the case where you wish to standardize the naming format for the logon name in a specific set of templates. Instead of modifying the relevant templates one after the other, you can set the desired naming format in all the relevant templates in a single action, using this option.
The following issues have been fixed in this release:
- Issue in configuring the 'Enhanced Presence' setting for users in LCS/OCS
- Error in exporting report data to XLSX format if the report contains date-related fields
- 'User Forum' link in the Support tab not being visible after enabling SSL
- Error when a help desk technician tries to add AD users/computers to groups
Highlights of Build 6300
OU (organizational unit) Management provides the ability to perform the following tasks via ADManager Plus:
- Create OUs
- Modify OUs
- Move OUs
- Delete OUs
OU management also offers:
- - Bulk creation and management of OUs via CSV import
- - Customizable OU creation templates which allow you to fine tune the OU creation process to exactly meet your organizational demands
- - The ability to create a new parent OU, and then create the required OUs inside it.
Report from CSV: This report helps in viewing the Active Directory information of existing user and computer accounts. You can import the list of desired users and computers from a CSV file into ADManager Plus, which then extracts and displays the Active Directory details of those accounts.
This report also features an option to refine its result based on specific attributes mentioned in the CSV file; you can also customize the report by choosing the specific fields (columns) that you wish to view in the result.
Exchange ActiveSync Policy Management allows you to assign the appropriate ActiveSync policies for users, right while creating new accounts for them in Active Directory and MS Exchange Server. You can apply the ActiveSync policies while creating new user accounts in single and also in bulk.
Exchange Archive (online and on-premise) Management offers the flexibility to create archive mailboxes for users either on the cloud or on premises. Using this feature you can create archive mailboxes for users simultaneously while creating their Active Directory accounts and Exchange mailboxes; you can also enable archiving for those users who already have Exchange mailboxes.
ADManager Plus now automatically synchronizes itself with the details of OUs and contact objects that are created or modified in Active Directory. This synchronization happens periodically throughout the day. Whenever needed, you can also manually synchronize the details of:
- All new and modified OUs and contact objects in Active Directory using the update dashboard (in Dashboard) and update domain objects (in Domain Settings) options.
- Only the modified/updated OUs and contact objects in Active Directory using the refresh option (in Select Container popup window while selecting the OUs for management and reporting).
Active Directory reporting has been enhanced with:
- Addition of: add to group, remove from group and move objects, to the list of management tasks that can be performed from reports, via the 'More Actions' option present in them.
- A revamped UI (layout) in reports for viewing the report results (objects fetched by the report).
- Performance improvements for faster report generation
The report scheduler features a 'Run Now' option to allow ad-hoc execution of any existing report schedule.
- HttpOnly setting has been enabled to fix security vulnerabilities.
- Database cleanup issue is now fixed.
- Issue in applying Exchange mailbox retention policy has been corrected.
- SSL v3 has been disabled to guard against security vulnerabilities.
- Issue in displaying entries under Titles and Departments (located in Admin Tab) in sorted order while adding new entries to the list is now fixed.
- Reports will now be adjusted (resized) to printable format while exporting them.
- Group members report's group selection popup window now allows removal of all the selected groups at once.
Highlights of Build 6290, 6291
Filters in Report Scheduler: ADManager Plus now offers filters using which you can customize the Active Directory reports exactly as per your needs, while scheduling them.
- Intensifies security with fixes for security vulnerabilities by updating its JRE (Java Runtime Environment) to 1.7
- Offers greater flexibility in selecting the objects to be managed via Automation, by adding more attributes/fields to the filters in its report library.
This release includes fixes for the following issues:
- Headers are repeated for every 5000 rows while exporting the reports to CSV format.
- The first sheet has 5000 rows and the subsequent sheets have only 150 rows each while exporting the reports to XLS format.
- While a request is created through Workflow/Automation for bulk user creation via CSV, user details are not displayed in the 'view objects' link in the request if template name is mentioned in the CSV file.
- Helpdesk technicians are not able to unlock user accounts that are locked out.
- ADManager Plus mobile app displays locked out user accounts as not locked (lockout status: false).
Highlights of Build 6280
Office 365 License Management helps you assign, replace or remove the licenses of multiple AD users who are enrolled in Office 365, in one single action. Further, to make it easy for you to specify the users whose licenses have to be modified, this feature provides an option to import the list of users from a CSV file.
Copy AD Group feature allows you to copy the attributes/settings of any group in your Active Directory and use the copied values to create a new:
- Distribution or Security group in AD, or
- Group creation template
This feature also gives you the option of copying either all the attributes or only specific attributes such as the container, group type/scope, memberOf, members, etc., from the desired group.
LDAPS Support which allows you to communicate securely with the Active Directory.
- Reinforced security: This release fortifies the protective mechanism with a fix to guard against the CSRF vulnerability.
- Additional input field types for Custom Attributes: To make it easy to specify the values for custom attributes, you can now pick the most appropriate input field type from the new options such as combo box, editable combo box and date picker.
This release includes fixes for the following issues:
- Not being able to logon using the password obtained through random password generation.
- Helpdesk technicians' description getting replaced with the description mentioned in AD.
- Error in generating the Licensed O365 users report.
- Not being able to view all the configured File Servers in File Server management.
- Error when using %sAMAccountName% as SIP URI format for Lync enabled users.
Highlights of Build 6271
'Reactive' Group Modification Template: These templates help you standardize the process of modifying AD groups and also automatically populate specific attributes during the single group modification process via:
- - Customizable Layout: With simple 'drag-n-drop' actions, you can place only the desired attributes in the templates; you can also make any attribute editable, read-only or hidden during the modification process. With customized templates, you can provide role-based access to helpdesk technicians for modifying AD groups
- - Reactive modification rules: You can configure conditions to be checked whenever an AD group is modified and auto-update specific attributes, if the conditions are satisfied. These rules are triggered in the background whenever a group is modified and the specified fields are automatically populated with appropriate values.
- Cross-domain support in single group creation and modification - you can now add users and also contacts from different domains as members of a group; also, you can now add contacts to groups via single group creation and modification.
- Reset computer accounts feature to help you reset the passwords of computers that cannot connect to the domain as they cannot be authenticated by the domain controller
- Multiple group selection in 'Users not in groups' report: You can now select multiple groups while specifying the ones based on which this report has to be generated; fetches all the users who are not members of any of the specified groups
- Enhanced random password generator: the password policy now offers advanced options like exclude characters, dictionary words, etc. for more efficient and secure password policy generation, in compliance with the organization's password policy
- Users with empty attributes report now brings custom user attributes also under is scope; will now fetch users even if their custom attribute is empty
- Enhanced error indicators for the failed CSV-import operations now offer detailed error messages for greater understanding about the reason for the error.
- While performing single user modification, you can now sort the list of users displayed alphabetically, to locate the desired user without much effort.
- The AD objects search, located inside the product, now lists the objects in the search result in alphabetical order.
This release has fixes for the following issues:
- Not being able to disable and move user accounts via automation.
- Issues in helpdesk technician not being able to reset passwords
- Not displaying the names of requesters (users) who are not helpdesk technicians, while configuring the assigning rules
- Issues in updating the 'Country' attribute of users in AD via bulk user modification
- Product does not start when Java crashes due to 'out of memory'
- 'No Lync server found' message being displayed in the user creation templates randomly
Highlights of Build 6260
Inactive Office 365 users report: This report lists all the Office 365 users who have not accessed their Exchange Online mailboxes during the specified time period.
CSV-based computer modification: This feature helps you modify the attributes of Active Directory computers, in bulk, by importing a CSV file which has the list of computers and their attributes to be modified.
Computers with duplicate attributes report: This report displays all the computers which have duplicate values for the specified attribute.
OS filter in OS-based computers report: While selecting the operating systems to generate the OS-based computers report, you can use this filter to view the list of only the server operating systems or all the operating systems (server as well as client versions) used in the organization.
The following issues have been fixed in this release:
- Issue in setting the Dial-in attribute's value for AD users via single user modification
- Names of objects modified via bulk user modification feature (using a CSV file) not being displayed in helpdesk audit reports
- Issue in selecting the required domains for generating the photo-based users report
Highlights of Build 6250, 6251
Exclude Child OUs filter: For AD management/reporting tasks, this filter allows you to precisely select the particular OUs only in which the specified management/reporting tasks have to be executed, by allowing you to exclude their child OUs from being modified/affected by the task.
'Remove users/computers from all groups' option: For pruning the group membership of user and computer objects, instead of going through the list of each group that they belong to, and then removing them from all the irrelevant groups one by one, you can use this option to remove them from all the groups that they are currently members of, and then add them only to the desired groups.
Copy Help Desk Role: You can use this feature to create a new helpdesk role by just copying the settings of an existing helpdesk role. Instead of creating a new role from the scratch, this feature allows you to use any existing role as a building block for creating a new role.
- In automation, issue in removing a filter criterion when the value contains special characters has been fixed
- Helpdesk technicians not being able to change admin passwords which contain special characters has been fixed
- When applying custom templates, issue in providing a longer user logon name, like a logon name consisting of 20 characters, is now fixed
- Issue of helpdesk technicians, with super-admin privilege, not being able to access the support tab is now rectified
- Custom attributes now support multi-value proxyAddresses in single and bulk user creation as well as single user modification
- Issues in exporting scheduled report to Excel is now fixed
- Issue in denying the 'set as primary group' option during single user creation and single user modification is now fixed
- Issue in automatic selection of mailbox servers is fixed; this option is now available for Exchange Server versions 2010 and later
- Changes to domain name not reflecting in the Exchange tab during single user creation is now fixed
- Performance issues in single user modification have been rectified
Highlights of build 6241
Google Apps User Provisioning: You can now provision Google Apps user accounts, automatically, via ADManager Plus. Along with the existing Office 365 user creation ability, this feature makes it easy to manage the users' identities in the cloud.
BitLocker Recovery Keys Report: This report helps in unlocking or recovering data from the drives, which are protected by BitLocker encryption, by fetching their corresponding volume and recovery GUIDs, recovery passwords and also their Key Packages in downloadable format.
Photo-based User Report: This report helps you identify the Active Directory users who have a profile photo. This report also helps you zero in on the users who don't have a profile photo.
- Issue in displaying the default domain during group management operations has been fixed
- Issue in execution of automation when new files are added to a shared location, which is already being used is fixed now
- Empty reports issue in scheduled generation of audit reports is now fixed
- Issue in generating computer reports from MSSQL database has been fixed
- Issue in removing a distribution group during contact modification is fixed now
Highlights of build 6230
Office 365 Reports:You can now obtain vital details about all the users, groups and licenses of your Office 365 environment using the following new reports:
- All Users: This report gives you the list of all the users in your Office 365 setup.
- License Details: License-specific information such as the list of all licenses, the corresponding number of active units, number of units used, number of units in warning state, suspended units, locked out units, etc. can be obtained via this report.
- Licensed Users: This report lists all the users for whom Office 365 licenses have been assigned, along with the respective list of services assigned to them.
- Unlicensed Users: Using this report you can identify the list of all users who do not have any license assigned to them.
- All Groups: You can fetch the list of all the groups in your Office 365 environment.
- Security Groups: This report helps you identify all the security groups in Office 365 setup along with their last DirSyn time.
- Distribution Groups: This report lists all the distribution groups in your Office 365 setup along with their last DirSync time.
- Issue in opening an exported CSV file, which has Japanese characters, using Japanese version of Excel is fixed.
- Office 365 user attributes have been updated to include the latest changes introduced by Microsoft.
- Issues in applying multiple rules in user modification templates have been fixed.
- Issue in creating a user with more than one proxy address, when Office 365 settings are configured, has been fixed.
- HTML injection vulnerability has been fixed.
- When ADManager Plus is started as a service, the issue of browser process not stopping even after ADManager Plus service is stopped, has been fixed.
- Incorrect account expiry date issue in bulk user modification is corrected.
- Issue in displaying the 'date' field in Excel format has been fixed.
- Issue of 'Reject Message from' value getting changed, when the members attribute of a group is modified, via single group modification, is fixed now.
- Error in saving the user template after deleting the Exchange tab, if Office 365 is enabled in ADManager Plus, has been corrected.
- Issue in selecting OU in 'Real Last Logon' report is now fixed.
Highlights of build 6220, 6221
Copy User: This feature allows you to copy the attributes/settings of any user account in your Active Directory and use the copied values to create a new:
- User account
- User creation template
The advantage of this feature is, instead of copying a user account entirely, this feature also allows you to pick and choose only specific attributes like User Account Control (UAC) attributes, Terminal Services attributes, Custom attributes, etc., that you wish to copy from a user account.
New group-based reports: Active Directory group reporting gets more detailed with the addition of these new reports:
- Recently created groups: fetches all the groups that were created during the specified time frame.
- Recently modified groups: lists all the groups whose attributes were modified within a particular time period.
- Recently deleted groups: identifies all the groups that were deleted from your Active Directory within a specific time span.
- The 'license details' window will now display the product architecture (64/32 bit) information also.
- In bulk user management, if the 'export as' option is used after performing a task/action, the report will also display the type of action performed, in addition to other details like the domain and the objects modified.
- The 'export as' option in Employee Search page can now be hidden by configuring the product database accordingly.
- The naming attributes (Logon name, Pre-windows logon name and Full name) can also be made silently active.
Highlights of build 6210
- Option to customize columns at the time of report scheduling and sort the reports using specific columns included.
- Support added for using Microsoft SQL server as a back end database server for ADManager Plus.
- NTFS report enhanced to handle large volume of data at the time of exporting.
- Issue in deleting memberOf attribute from Group Modification fixed.
- Issue in revoking a role under Security Management handled.
- Issue in listing C Drive in terminal services home directory resolved.
- Issue in increase in db size at the time of report generation fixed.
- Issue with change in Logon name at the time of creating an Office 365 user account resolved.
Highlights of build 6201,6202
- Issue in appearance of list of week days, at the time
of report scheduling handled
- Issue in full name containing special character, at the
time of creating a home folder in single user creation, corrected.
- Issue in duplication of row at the time of exporting a
Highlights of build 6200
added for MS Office 365
extented for provisioning
of user accounts in Microsoft Office 365.
Lync Management and reporting
Exchange policy settings
- You can now modify
policies such as conferencing, archiving and telephony, associated with
a specific Lync User.
- Option to enable,
disable or delete a user from the Lync Server control panel included.
- Reports for Lync
Enabled as well as LCS or OCS enabled users included.
- Reporting capabilities
added for Lync disabled users.
- You can now apply Exchange 2010/2013 policy settings such as
sharing, role assignment, retention, UM Policy and policies on
ActiveSync to appropriate mailboxes.
- Option to enable mailbox archiving included
- Exchange features
enhanced to support enabling and disabling of ActiveSync (2010,2013) /
User Initiated Synchronization(2003) and MAPI Protocol.
- Multiple 'OS
selection' enabled under OS based reports.
- Reset Password option
under Bulk User Modification enhanced. Separate delegation included for
actions under the same.
- Delegated actions
under 'Bulk User Modification' will hence be displayed based on the
- Single User
Modification templates enhanced to include 'Home Folder' Permissions
- Option to set custom
attributes included under modification rules for 'Single user' and
'Single Contact' modification
- Language settings for
the product can now be configured in 'Personalize' Page.
- Issue in setting custom period at the time of scheduling audit
- Issue in handling special characters at the time of displaying
object properties in AD Explorer corrected.
- Issue in clearing 'memberOf' attribute, post unchecking it in
Bulk User Modification resolved.
- Issue in user identification at the time of modifying 'Deliver'
options in Bulk User Modification handled.
- In 'Permission for folders' report, issue in selecting a computer
object under an OU name containing special characters corrected.
- Issue at the time of creating a department fixed. Leading white
- Issue in using 'Random Password' type in custom script resolved.
- Issue in creating groups with pre windows 2000 name greater than
20 characters fixed.
- Issue in naming reports, exported in XLS format corrected.
- Issue in displaying groups at the time of domain change resolved.
Highlights of build 6180
- Logon Hours Configuration:This new option
in single user creation feature empowers you to specify the appropriate
hours during which a user can login by configuring the 'logon hours'
attribute, right while creating a new user account. You can also set
the desired logon hours for any existing user via the enhanced single
user modification feature.
- Enhanced data selection popups:Selecting
the required accounts for any management or reporting operation gets
even more easy and convenient with the option to select the number of
accounts to be displayed in the pop-ups, displaying the matching
objects even as you key in the name in the search box, etc.
- Improved delivery restriction feature, in
bulk user modification, now allows you to set the desired size limit
for sending or receiving emails either in KB or MB, as required.
- Issues in viewing the 'users in groups' report in Excel
2013 format is fixed.
- Help desk technicians not being able to 'enable/disable'
users via 'single user modification' in specific scenarios is fixed.
- Issue while creating mail enabled users in non-English
Exchange environment has been fixed.
- While creating new users, the issue of naming format fields
sometimes not being displayed as per the specified naming-format has
Highlights of build 6173
- Employee Search can now be accessed using just the URL,
from anywhere, and not just from the product screen.
- Blank page issue in single user creation, if there are
spaces in the naming format used in the default template or the default
naming format has been fixed.
- The execution history of ADUpdateScheduler (one of the
default schedulers) not showing up in the 'Scheduler History' is fixed
- In single user modification, the issue of User's office
attribute not displaying the appropriate value in Active Directory is
- The issue of User account status being displayed as 'locked
out' even after it is unlocked has been corrected.
- Issue in saving contact creation templates if the
“Automatically Update Email Policy” option is not selected, is now
- Issue in finding users in the 'delivery options' in single
user modification is fixed now.
- In single user modification, issue in modifying the
“Requires that all senders are authenticated" and "Hide from Exchange
Address lists" options has been fixed.
- The issue of names being displayed with only one space,
even if naming formats are configured with multiple spaces has been
- Issue in creating the homefolder with the desired name if
the naming format is specified using LDAP attributes (%ldapname%) is
- Audit reports not displaying proper homedirectory values
for the 'move homefolder' operation (in bulk user modification) is
- Issue in displaying the Lync conferencing policies properly
in the templates even if the Lync settings have been enabled has been
- Issue of Lync servers sometimes not showing up in the
templates is fixed now.
- Not being able to modify a user via the single user
modification feature, if the user has 'Free/Busy Sharing' enabled is
- Issue in modifying mail enabled accounts in Office 365 via
the single user modification feature has been rectified.
Highlights of build 6170
- Logon hours configuration support included under Bulk User
- The details of modified attributes included in the HDT
Audit reports. Two new formats introduced to view the report - The
standard view and the summary view.
- Manage Users' Group Membership via iPhone app.
- Manager Can Update Group members Option included in Group
Modification with that Option.
- Hide / Display Password option included in Admin server
- 'Move home folder' feature significantly enhanced to
include an option to either delete or retain the existing home folder.
- Issue in Real last logon and Inactive Users report
generation due to high number of DCs addressed.
- Issue in Modifying the Account Expiry Time resolved.
- Problems with selection of child OUs with special
characters in IE handled.
- Issue in removing the description of computer object
- Issue in modifying a user's primary group using mobile app
has been fixed.
- Issue of difference in time at the time of exporting
'Inactive users' report corrected.
- Fixed issues in copying User Modification Templates with
- Issue in Email validation at the time of saving scheduled
- Creating Groups with more than 20 characters made possible.
- Lync Server display issue fixed.
- employeeID attribute can now be used to disable users
- Issue in Server Permission Report generation resolved.
Highlights of Service Pack 6.1 SP 6.0 and build 6151:
- Lync 2010/2013 support: With this new component
of ADManager Plus's user creation templates, you can configure all the
appropriate Lync server settings for your users even as you create new
accounts for them. While Lync makes intra-organizational communication
swift, the new user creation templates make even the process of
configuring / enabling intra-organizational communication equally swift.
- Exchange Server 2013 support: You can now
configure user mailboxes in Exchange Server 2013 and apply the
appropriate mailbox policies required to govern them as well; use all
the latest features and advantages innate to Exchange 2013 and make
your Exchange mailbox management efficient and top of the line.
- Drag-n-Drop Customization in user creation templates
to fine tune the process of creating new user accounts to fit your
organizational policies and requirements to a T; make any attribute
mandatory, read-only or even hidden as per your needs or based on the
technician to whom you will be assigning the user creation template.
- LCS/OCS configuration in user creation template:
The user creation console will now have a separate tab exclusively to
configure all the appropriate settings to enable instant communication
in your organization. This feature will enable you to specify the
appropriate value for LCS/OCS and even Lync Server settings from the
- Exchange 2010 Policies Support: You can now
configure Exchange mailboxes for the new user accounts that you are
provisioning and also apply the appropriate policies at the same time
using this feature.
- Revamped 'Avoid Duplication' feature to check
for duplication of critical/specific attributes at the desired level
(OU / Domain /Forest) and perform the appropriate operation to avoid
- Enhancements in 'User Modification Templates':
- Updates to organization attributes (Title, Department,
Offices and Companies) in 'Admin' tab will reflect in user modification
templates that have been already created.
- 'Member Of' attribute has been added to 'Modification Rules'
component in user modification templates.
- Delete users' existing group membership information during
the modification process.
- Unlock user accounts via templates during user modification
- Recursive naming formats will now be supported in users'
description and custom attributes.
- Execute a custom script on successful modification of a user
- Move users' to a different container during user modification
- Polish characters not exported in PDF format.
- Additional email address attribute in 'group creation template'.
- Hiding the new password generated during single user modification.
- Issues in Cleanup scheduler.
- Issues in authorizing HDTs for 'Move Home Folder' action.
Highlights of build 6140
- The scheduler has been enhanced to accommodate more accurate time
- 'Select only the appended objects from the file' option
has been added to help choose only the appended data while importing
records through iterations from a CSV.
- Filters in AD reports have been enhanced to drill down to the
specifics of reported data; Reports can now be filtered based on
attributes such as Primary Group, WhenChanged, whenCreated,
DisplayName, Account Expires, Bad Password Time, Lockout Time, Last
Logon Time, Last Logon Timestamp, Bad Pwd count, and Pwd status.
- Issue in setting “Deny” permissions over a mailbox during Bulk
User Modification has been fixed.
- Issue in creating Mailbox on Exchange Server 2007 when installed
on Windows server 2012 has been fixed.
- Issue in modifying external email address has been fixed; the
external email address in the additional mail address list will now be
replaced with the newly modified address.
- Issue in using configured custom attribute in CSV while creating
or modifying users via automation has been fixed.
Highlights of build 6130
- ADManager Plus Group Templates standardize the group creation
process. These templates store values and formats that are applied
automatically across all the group objects that are created using these
- The drag-and-drop option in Group Creation Templates helps
customize templates as per organizational needs to display or hide the
specific tabs or attributes as required.
- The UI for Single group creation is now more flexible and user
friendly with the fields categorized under General, Group and Exchange
- 'Managed by' field added to single group creation can be used
designate managers for the groups.
- Issues in configuring HDT, when many templates, OUs and roles
are assigned to him, have been fixed.
- Issue in setting 'Deny Permissions' over a mailbox while
performing set mailbox rights in Bulk User Modification has now
- Issue in importing 'UTF-8' format files in Automation and
Workflow during user creation/modification (using CSVs) has been fixed.
- Browser issue (IE) that occurs when the number of objects chosen
in 'delegate security role-step 1' is huge, has been fixed.
- The resultant page that occurs after 'user creation using CSV'
will no longer have export option issues in Firefox.
- Local groups will no longer be displayed in the 'add members'
options under Universal distribution group creation/modification.
Highlights of Build 6120
- The actions list has been enhanced. Modify
Users by CSV, Add To Group, Remove From Group actions have now been
- Option to enforce “user must change password at next logon”
in reset Password action has been provided.
- Filters have been introduced in library of reports for accurate
Reset password console
- A Quick visibility into User's account lock out status while
trying to reset password from the reset password console.
- Option in Naming Formats to define replacement characters
for 'umlaut accent' has been provided.
- Configuration for multiple domains in employee search.
- Export as PDF, excel, html and CSV options for results from
- Options for attribute-based user/contact search have been
- 'A HDT without permissions to generate a report can do so from
the dashboard when report count is zero' issue has been fixed.
- Special characters issue in HDT role name has been fixed.
- Issue in restoring users when parent OU has been deleted is now
fixed. Users will be restored in the 'users container'.
- Issue in clearing 'show in Address book attribute', when you
uncheck hide from address lists option in single group
modification has been fixed.
- UAC value issue while creating normal accounts through bulk user
creation has been fixed.
Highlights of Build 6110
- The value selected by the technicians for 'Show Rows' option, in
all the features that it is available, will now be saved.
- Delete groups option is now available in 'Groups without Members'
- 'OS Based Report' will now have the operating system of the
customer environment also in the OS list.
- Deleted computers showing up in computer selection pop-up windows
issue is fixed.
- Distribution Groups created with '#' in their name throwing up
'Properties on this object have invalid data' error when opened in
Exchange Management Console is fixed.
- Mismatch in 'password expiry date' in Real Last Logon report for
those users for whom PSO has been applied is fixed.
- Reset Password feature will now display the new passwords
generated as '**********' instead of the actual passwords in the result.
- 'OU' option not working in the 'Advance Filter' of Real Last
Logon report in IE Compatibility mode is fixed now.
Highlights of Build 6.1
- File Server Management: Manage the permissions
on multiple File Servers and workstations across your organization in
just one operation. This feature facilitates bulk modification and
removal of NTFS or Share permissions on Shared Folders and their
- Now you can also manage Active Directory 2012
(in Windows Server 2012) using ADManager Plus.
- This build also included support for Windows 8
- Remote PowerShell Support for Exchange 2010: Even
from a 32-bit machine and with just PowerShell 2.0 you can now create
mailboxes in Exchange 2010. You can accomplish this even if you do not
have Exchange Management Console (EMC) installed on your 32-bit
- Performance tuning for Exchange Management.
- Windows 8 and 2012 have been included in OS based Computer
- Issue in using 'Hide from Exchange Address Lists' option for
Groups has been fixed.
- Issue in fetching information about cross-domain members in
'Detailed Group Members report' has been fixed.
- Issue in setting/updating email address of users through a CSV
file, if it is mentioned as empty in the template being used has been
- Error in exporting filtered (partial) results from reports has
Highlights of Build 6012:
- Mailbox Storage Limits specified using single user modification
will be validated based on the version of mailbox Exchange Server.
- 'Automatically update e-mail addresses based on e-mail address
policy' attribute will also be available in reports now.
- Instead of only the OUs from primary domain, OU's of all the
selected domains will be displayed for 'Move Computers' option in
- In Single Group Modification while adding new members, HDTs can
now select Users, Computers as well as Contacts instead of only Groups.
- The complete value of Office attribute will be displayed as the
tool-tip text in User Creation Template.
- Unable to select AD Objects issue to Delegate Security Role while
using Internet Explorer 9 in Compatibility mode has been fixed.
- Select Country option not being saved issue in user creation
template has been fixed.
Highlights of build 6010:
- Date type columns will be exported as date fields while exporting
- Migration support for 6001 ,6002, 6003.
- Issue in setting dial-in properties during user creation and
modification has been fixed.
- Active sync support issues post 6000 build have been fixed.
- Exporting issues in group members report has been fixed.
- Auditing issues for remove members operation is fixed.
Highlights of build 6001, 6002, 6003:
This release refines 'Report Scheduler' to make it
more efficient with the following enhancements:
- Flexible Schedule Execution Frequency: The
enhanced scheduler provides more options to configure the execution time
and frequency of scheduled reports with flexible time
intervals such as yearly, quarterly, fortnightly, multiple days in a
week, every 15 minutes, etc.
- You can now Disable Email Notifications for
scheduled reports if the reports do not have any data in them.
- Filters are now available in scheduled reports
as well (for Inactive and Password Expired Users reports) to make sure
you get the specific and relevant data that you need.
- Blank attachments issue in email notification of scheduled
reports with no data has been fixed.
- Product Installation issues on non-English Operating systems is
Highlights of build 6000:
Automation: Set up
'end-to-end' automation of any AD task using the 'automation'
feature. Further, with 'automation policy', you can also set
up its time-based sequential follow-up tasks, as per your
organization's requirement. With the 'implement business workflow'
option, you can also set up a controlled workflow-based automation in
which the task will not progress unless the administrator/the
authorized technician gives the go ahead, at each stage of the workflow.
Single User Modification
with/without templates: It is now possible to modify any
existing single user account, with/without using any 'modification
template'. Using these templates, you can allow the help desk
technicians to view/modify only those fields that they are allowed
to, as per your requirement.
Single User Modification through
Rules: Specify the fields that should be automatically populated,
whenever a user account is modified by a help desk technician and these
rules will not be visible at all to the help desk technician.
With this feature, it is now possible to accurately specify and manage
the GPOs that should be applied to any target location. For any
Domain/OU/Site, administrators can now Enable/Disable GPOs
completely or only the User/Computer configuration settings, Add/Remove
GPOs, Enforce/Unenforce GPOs, and also Block/Unblock
GPO inheritance to Domains/OUs, exactly as required. Plus, view all the
GPOs available in all the configured domains along with their
status and the locations that they are linked to, from one central
The following enhancements have been made to the 'Workflow'
Quick-link to 'Create
Request': Requesters can now create requests for all the
management actions that they have permissions for, from just one
Add Requesters Directly:
Now, turn any AD user into a 'requester', even if the user is not a
help desk technician. Just select the required user(s), assign the
appropriate roles domain and save the settings, to turn any normal AD
user(s) into a 'requesters'.
Requester permissions to
Group/OU: Assign 'requester' permissions to an entire
Group/OU, for any AD task, as required. This automatically turns all
the existing members and any user who becomes a member of this group/OU
With these rules, specify the technician(s) to whom the request being
created has to be assigned and also set the required priority for the
request, based on either the type of action or the requester who
creates the request, as needed. Also, specify the technicians/users to
be notified of the request status and progress, at each stage of the
Administrators can create custom roles to specify the task or the set
of tasks for which a 'requester' can create requests. These roles can
be used to provide the necessary request creation permissions to any
new requester. While creating a new requester, by just assigning a
specific 'requester role' to any user, administrators can specify all
the tasks for which this specific requester can create requests, in one
The 'IMAP4 setting not reflecting
when modified through single user modification feature' has been fixed.
'streetAddress' can now store
multiline values also
Customers now have the option of
providing database password in encrypted format, if required.
'Recently Modified Users' report
can now retrieve more than 1000 objects.
Windows 7 Enterprise SP1 has been
added to the options in the 'OS Based Report'.
Approval notification email will be
sent to executors, even if they are not specified in the workflow.
Highlights of Previous Releases (Builds
5200 to 5241)
Active Sync Enabled/Disabled Reports
Single Contact Object Modification
- Contact Modification Templates
Contact Modification Rules
Detailed Group Members Report
Single Computer Object Creation
Delegation of Computer Creation
Templates to Helpdesk Technician(s)
Exchange Mailbox Migration
Restoring Deleted Users/Computers
Single Contact Creation
Template based Contact Creation
Drag-n-Drop customizable Contact
Mandatory field(s) / attribute(s)
for Contact Creation
Disable/Delete User Mailbox for
Exchange 2003, 2007 & 2010
Customized Date/Time Format
Performance enhancement in all
User, Computer reports that retrieve and display the most recently
updated data from multiple Domain Controllers.
Enhanced performance in report
Enhanced Localization and
Internalization for non-English language compatibility.
Includes latest Windows OS releases
in 'OS Based Report'.
Session timeout handling for Help
Custom Attributes / Additional
Contact Creation - Field
Authorization and Template Delegation
Refresh link in Modify Single User
'Unlock Users' option along with
'Reset Password' in 'Helpdesk Reset Password' Console.
'Add/Remove' Users, Computers to
and from multiple groups in just a single action in Bulk User/Bulk