User Object
Property Pages: Table of Contents |
Attributes of
Interest
Setting or resetting a user's password: To set a
user's password use the field "password".
General Tab
The User's Property Page in the Active Directory Users
and Computers MMC contains the following directory attributes.
 |
Tab Field |
LDAP Name |
Display Name |
First Name |
givenName |
Given-Name |
Initials |
initials |
Initials |
Last Name |
sn |
Surname |
Display Name |
displayName |
Display-Name |
Description |
description |
Description |
Office |
physicalDeliveryOfficeName |
Physical-Delivery-Office-Name |
Telephone number |
telephoneNumber |
Telephone-Number |
Telephone number (Other button) |
otherTelephone |
Phone-Office-Other |
E-mail |
mail |
E-mail-Addresses |
Web page |
wWWHomePage |
WWW-Home-Page |
Web page (Other button) |
url |
WWW-Page-Other |
Selecting the "Other..." buttons will display other attributes
that can be changed. For further information about these
attributes and other Active Directory object attributes, please
refer to the following web link:
http://msdn.microsoft.com/library/default.asp?url=/library/en-us/ADSchema/ad/win2k_entry_attributes.asp
|
Address Tab
 |
Tab Field |
LDAP Name |
Display Name |
Street |
streetAddress |
Address |
P.O. Box |
postOfficeBox |
Post-Office-Box |
City |
l |
Locality-Name |
State/province |
st |
State-Or-Province-Name |
Zip/Postal Code |
postalCode |
Postal-Code |
Country/region |
co |
Text-Country |
Reminder about special characters...
The "\r\n" can
be used in your import files to specify return characters.
For example, if you want to import the street address for a user that
contained the following:
1702 First Street
Suite 1427
The value would appear in our import file as: "1702 First Street\r\nSuite1427"
|
Account Tab
 |
Tab Field |
LDAP Name |
Display Name |
User logon name
Applies to both fields, example: "User1T@YYZ.GTAA" |
userPrincipalName |
User-Principal-Name |
User logon name (pre-Windows 2000)
Applies to second field only, example: "User1T" |
sAMAccountName |
SAM-Account-Name |
Logon Hours... |
* see below |
* see below |
Log On To... |
userWorkstations |
User-Workstations |
Account is locked out |
* see below |
* see below |
Account options... |
User must change password at next logon |
* see below |
* see below |
User cannot change password |
* see below |
* see below |
Password never expires |
* see below |
* see below |
Store passwords using reversible encryption |
* see below |
* see below |
Account is disabled |
* see below |
* see below |
Smart card is required for interactive logon |
* see below |
* see below |
Account is trusted for delegation |
* see below |
* see below |
Account is sensitive and cannot be delegated |
* see below |
* see below |
Use DES encryption types for this account |
* see below |
* see below |
Do not require Kerberos for preauthentication |
* see below |
* see below |
Account Expires
For example, if the export entry for "accountExpires" on a user is -1, it
means that the users account never expires.
It is not possible at this time to import time/date attributes using
Directory Mate. |
accountExpires |
Account-Expires |
Note: For check boxes, the attribute value should be
True or False
* This field cannot be imported using Directory Mate.
|
Profile Tab
 |
Tab Field |
LDAP Name |
Display Name |
Profile path |
profilePath |
Profile-Path |
Logon script |
scriptPath |
Script-Path |
Local path |
homeDirectory |
Home-Directory |
Connect |
|
|
Connect (drop down) |
homeDrive |
Home-Drive |
Connect (To:) |
homeDirectory |
Home-Directory |
|
Telephones Tab
 |
Tab Field |
LDAP Name |
Display Name |
Home |
homePhone |
Phone-Home-Primary |
Pager |
pager |
Phone-Pager-Primary |
Mobile |
mobile |
Phone-Mobile-Primary |
Fax |
facsimileTelephoneNumber |
Facsimile-Telephone-Number |
IP phone |
ipPhone |
Phone-Ip-Primary |
Notes: |
info |
Comment |
Reminder about special characters...
The "\r\n" can
be used in your import files to specify return characters.
For example, if you want to import the Notes field for a user that
contained the following:
When not in the office
call pager, not mobile. The value would appear in our import file as:
"When not in the office\r\ncall pager, not mobile." |
Organization Tab
 |
Tab Field |
LDAP Name |
Display Name |
Title |
title |
Title |
Department |
department |
Department |
Company |
company |
Company |
Manager Name |
manager |
Manager |
Direct reports |
* see below |
* see below |
Note, the "Manager Name:" field must be entered as a
distinguished name or GUID when importing.
* Note, the "Direct reports:" field can not be imported.
|
Member Of Tab
Tab Field |
LDAP Name |
Display Name |
Member of |
memberOf |
Is-Member-Of-DL |
Set primary group |
primaryGroupID |
Primary-Group-ID |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Note: When importing "Set Primary Group", the value for
primaryGroupID should be set to the value found in "primaryGroupToken"
of the selected group. |
 |
Dial-in Tab
Tab Field |
LDAP Name |
Display Name |
Allow access |
* see below |
* see below |
Deny access |
* see below |
* see below |
Control access through Remote Access
Policy |
* see below |
* see below |
Verify Caller-ID |
* see below |
* see below |
Verify Caller-ID (box) |
* see below |
* see below |
No Callback |
* see below |
* see below |
Set by Caller
(Routing and Remote Access Service only) |
* see below |
* see below |
Always Callback to: |
* see below |
* see below |
Always Callback to (box) |
* see below |
* see below |
Assign a Static IP Address |
* see below |
* see below |
Apply Static Routes |
* see below |
* see below |
Static
Routes...button |
* see below |
* see below |
* This field cannot be imported using Directory Mate. |
 |
Environment Tab
Tab Field |
LDAP Name |
Display Name |
Start the following program at logon |
* see below |
* see below |
Program file name |
* see below |
* see below |
Start in |
* see below |
* see below |
Connect client drives at logon |
* see below |
* see below |
Connect client printers at logon |
* see below |
* see below |
Default to main client printer |
* see below |
* see below |
* This field cannot be imported using Directory Mate. |
 |
Sessions Tab
Tab Field |
LDAP Name |
Display Name |
End a disconnected session |
* see below |
* see below |
Active session limit |
* see below |
* see below |
Idle session limit |
* see below |
* see below |
Disconnect from session |
* see below |
* see below |
End session |
* see below |
* see below |
From any client |
* see below |
* see below |
From originating client only |
* see below |
* see below |
* This field cannot be imported using Directory Mate. |
 |
Remote Control Tab
 |
Tab Field |
LDAP Name |
Display Name |
Enable remote control |
* see below |
* see below |
Require user's permission |
* see below |
* see below |
View the user's session |
* see below |
* see below |
Interact with the session |
* see below |
* see below |
* This field cannot be imported using Directory Mate.
|
Terminal
Services Profile Tab
 |
Tab Field |
LDAP Name |
Display Name |
User Profile |
* see below |
* see below |
Local path |
* see below |
* see below |
Connect to drive |
* see below |
* see below |
Connect to path |
* see below |
* see below |
Allow logon to terminal server |
* see below |
* see below |
* This field cannot be imported using Directory Mate.
|
|