You may experience the following problems when you view
disabled user accounts against Windows Server 2003 domains:
- If you click Advanced on the Select Users, Computers, Or Groups dialog
box (this dialog box is also known as the Object Picker dialog box), click to select the Disabled (user)
accounts check box, and then perform a query, disabled user account
items are not returned even though they may exist in the specified
location.
- When you click to clear the Disabled (user)
accounts check box, and then perform a query, the user account items
that are returned by the query may include disabled user accounts that appear
to be enabled.
- If you start Active Directory Users and Computers snap-in
(Dsa.msc), and then select a container that has users, disabled user accounts
that are listed in the details pane appear as if they are enabled.
- If you start the Active Directory Users and Computers
snap-in, and then click Find on the Common Queries menu of a container, disabled account items are not returned in a
query even though they may exist in the specified location.
You do not experience these symptoms if the following
conditions are true:
- You are using an Administrator account.
- You are a member of the Authenticated Users group and the Pre-Windows 2000 compatible permissions option was not selected during Active Directory installation (by
default, this option is not selected during installation).
- You are a member of the Authenticated Users group and the
Pre-Windows 2000 Compatible Access group does not include the Everyone group as
a member.
In these scenarios, only members of the following groups see
the correct query results:
- Domain Administrators
- Account Operators
- RAS Servers group
- Built-in Administrators
- Enterprise Administrators
By default, users who are not members of these groups can
correctly view their own user accounts and any user accounts they create.