Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

XGEN: How to Access Active Directory Using the LocalSystem Account


View products that this article applies to.

This article was previously published under Q274585

↑ Back to the top


Summary

In certain situations, it may be necessary to access Active Directory by using LocalSystem credentials. The Ldp.exe program is included with the Windows 2000 Support Tools, and can be used to access Active Directory using Lightweight Directory Access Protocol (LDAP). This procedure may be useful when testing computer account permissions when connecting or binding to an Active Directory container.

↑ Back to the top


More information

WARNING: If you use the ADSI Edit snap-in, the LDP utility, or any other LDAP version 3 client, and you incorrectly modify the attributes of Active Directory objects, you can cause serious problems. These problems may require you to reinstall Microsoft Windows 2000 Server, Microsoft Exchange 2000 Server, or both. Microsoft cannot guarantee that problems that occur if you incorrectly modify Active Directory object attributes can be solved. Modify these attributes at your own risk.
  1. Log in to the Exchange server as a member of that server's Administrator group.
  2. Use the at command (At.exe) to run an instance of Ldp.exe, running in the LocalSystem context
    at xx:xx /interactive "c:\program files\support tools\ldp.exe"
    where xx:xx is a time that is one minute ahead of current time. Correct the path to Ldp.exe if you have it installed in a different location.
  3. Wait for Ldp.exe to open on the console.
  4. Click Connection, and then click Connect. Specify a server name, and port. The default port is 389, and the Global Catalog port is 3268.
  5. Click Connection, and then click Bind. Verify that Username, Password, and Domain are all empty, and then click OK.
Example:
at 17:27 /interactive "c:\winnt\ldp.exe"
Note: The at command will only bring interactive processes up onto the console, and not onto a Terminal Server session.

This allow you to view the directory with the same permissions as the LocalSystem account of that Exchange server. All of the Exchange services run under the LocalSystem account. You can now do any search by using Ldp, to verify that the LocalSystem account has the proper credentials. For additional information about searching the directory using LDP, click the article number below to view the article in the Microsoft Knowledge Base:
271201� XADM: Alternative Methods to Obtain a Dump of an Object
If you are unable to connect or bind, then there may be a permissions problem.

↑ Back to the top


Keywords: KB274585, kbhowto

↑ Back to the top

Article Info
Article ID : 274585
Revision : 6
Created on : 2/27/2007
Published on : 2/27/2007
Exists online : False
Views : 283