Directory and Resource Administrator and Exchange Administrator

Version 8.6 Service Pack 2

Release Notes

Date Published: February 2012

 
 

 

This service pack for the Directory and Resource Administrator product improves usability and resolves several previous issues. Many of these improvements were made in direct response to suggestions from our customers. We thank you for your time and valuable input. We hope you continue to help us ensure our products meet all your needs. You can post feedback in the Directory and Resource Administrator forum on Qmunity, our community Web site that also includes product notifications, blogs, and product user groups.

This document outlines why you should install this service pack, provides information about installing the service pack, and identifies known issues.

For more information about this release and for the latest Release Notes, see the Directory and Resource Administrator and Exchange Administrator Documentation web site.

Why Install This Service Pack?

Directory and Resource Administrator (DRA) and Exchange Administrator (ExA) provide highly secure and automated administration of Microsoft Windows Server and Microsoft Exchange Server environments. Through improved scalability, advanced delegation, and powerful policy-based management capabilities, DRA and ExA increase Active Directory security, dramatically reduce administrative efforts and costs while increasing efficiency, and protect the integrity of data in your Microsoft Windows Active Directory and Microsoft Exchange directory. The following sections outline the key features and functions provided by this version, as well as issues resolved in this release. This release also includes all the features and fixes from DRA and ExA 8.6 SP1. For more information, see Previous Releases.

Additional Resource Types Available to Manage in Web Console

Using the Web console, you can now perform DRA operations on the following resource types:

  • Devices
  • Shares
  • Open files
  • Connected users
  • Event logs

For each of these resource types, you can perform management and configuration tasks, such as creating a resource or viewing resource properties.

Tree Element Added to Web Console Allows Selecting AD Containers

When searching for or creating items in a container, you can now select the container from a tree in the Web console instead of typing it in a text box. When you select a folder in the tree, the Web console sets the folder container as the default target for the operation. For example, when creating new user accounts, you can select the target OU in the tree to designate where DRA should create the user account.

Improved Reporting Performance and Additional Language Support

DRA Reporting now contains the following improvements:

  • The Active Directory Collector contains performance improvements that result in improved group membership collection.
  • The Active Directory Collector and reports now support using the Japanese language. (ENG283963)

Ability to Search Using LDAP Query in Web Console

When searching for items to display in the task pages, you can now select the option to specify an LDAP query from the Name list. The results of the query are listed in the Web console. You can run saved queries or select the Custom option to specify an ad hoc query. Search results are filtered by the selected container in the navigation tree.

Ability to Manage Group Membership Security in Web Console

Using the new Membership security link, you can now delegate group membership management to members of the domain.

To delegate group membership management in the Web console:

  1. From any group properties page, click Membership security.
  2. Click Add trustee or click X to remove a trustee.
  3. If you are adding a trustee, enter your search criteria for the trustee, select a result, specify the trustee's rights, and click Apply.

Ability to Specify Different Exchange Access Accounts on Secondary Administration Servers

When you specify Exchange 2010 management in Exchange Administrator, the Exchange access tab on the Domain Properties window allows you to specify whether to use the domain access account or another access account for all Exchange servers in your environment. DRA now allows you to specify the Exchange access account from secondary Administration servers in the Multi-Master Set (MMS). Before installing this service pack, you could enter the Exchange access account only on the primary Administration server in the MMS.

Removal of NetBIOS Requirement for DRA and AD Collectors

After applying this service pack, you can disable the NetBIOS over TCP/IP protocol on all Administration servers. The setup program requires NetBIOS to be enabled. After installation, all DRA functions are supported without this feature enabled.

To disable NetBIOS over TCP/IP:

  1. Log on to the Administration server computer.
  2. Navigate to the Advanced TCP/IP settings for your Local Area Connection Properties.
  3. On the WINS tab, select Disable NetBIOS over TCP/IP.
  4. Click OK until you have closed all open windows.

Updated Documentation Available

This service pack contains an updated Administration Installation Guide.

Resolves an Issue With the Manage My Account Power

This service pack resolves an issue where the Manage My Account power does not allow the owner of the account to update the phone numbers or some address fields. (ENG309426)

Resolves an Issue With Web Console Display When Computer Browser Service is Disabled

This service pack resolves an issue where some computers appear available and other computers appear unavailable in the Web console when the computer browser service is disabled. (ENG313040)

Resolves an Issue With Displaying Mailbox Status

This service pack resolves an issue where a user's mailbox status is not displayed when the mailbox has been moved from a mailbox store that has since been deleted. (ENG313686)

Resolves an Issue With the NetIQ DRA Core Service

This service pack resolves an issue where the NetIQ DRA Core service fails to start if the Windows event logs are full. (ENG309261)

Resolves an Issue With Deleting Groups

This service pack resolves an issue with deleting groups where DRA displays an error that the object already exists. (ENG305456)

Resolves an Issue With Memory Consumption in the Account and Resource Management Console

This service pack resolves an issue where searching for all objects results in increased memory consumption in the Account and Resource Management console. The console does not release the memory when the search is complete. (ENG313272)

Resolves Issues With the AD Collector

This service pack resolves the following issues with the Active Directory Collector:

  • The Active Directory Collector always runs during server startup when the collection schedule has been changed. (ENG307285)
  • The Active Directory Collector fails for an untrusted managed domain. (ENG314259)
  • The Active Directory Collector Configuration reports cannot access the Deleted Objects container. (ENG315517)

Resolves Issues With DRA Management Reports

This service pack resolves the following issues with DRA Management reports:

  • Some DRA Management reports that have a context to show success and/or failure report only failures. (ENG294473)
  • The Summary of Managed Domains Information report does not show all domains in the environment when an OU name occurs multiple times across the domains. (ENG313496)
  • The datetime values are not stored properly if the default format for the database is not set to US English. (ENG307265)
  • DRA Management reports do not display data if the text contains double-byte characters. (ENG283963)

Resolves Issues With DRA Activity Reports

This service pack resolves the following issues with DRA activity reports:

  • Running an activity report in the Account and Resource Management console may fail if the report contains a user with a newly created mailbox. (ENG308991)
  • The activity reporting for an OU displays the Objects Deleted report option twice. (ENG308899)

Resolves an Issue With the Save As Window Display

This service pack resolves an issue where the Save As confirmation window is partially off the screen when saving configuration changes for the Account and Resource Management console to the .arm file. (ENG310306)

Resolves an Issue With Temporary Group Assignments

This service pack resolves an issue where DRA displays an error message if a temporary group membership is recalculated while DRA is performing a cache refresh. (ENG307991)

Resolves an Issue With Web Console Initialization

This service pack resolves an issue where the Web console is unable to initialize when the locale is set to a language where commas and decimals are the reverse of English. (ENG306194)

Resolves an Issue With Updating ActiveView Descriptions Using the EA Command

This service pack resolves an issue where the ActiveView description field is not updated properly when creating objects using the EA command. (ENG313718)

Resolves an Issue With Memory Consumption on the Administration Server

This service pack resolves an issue where running scripts causes the memory consumption of the Administration server to grow continuously. (ENG312876)

Resolves Issues With Cloning Users

This service pack resolves the following issues with cloning users:

  • When Assistant Admins without Exchange rights attempt to clone users having Exchange Server 2003 mailboxes, the clone operation results in an error message or creates the users in a disabled state. (ENG313183)
  • Cloning a user having the HomeDir and samAccountName in different case replicates the home directory path of the source user instead of resolving to the appropriate path for the target user. (ENG312023)
  • When cloning a user in the Web console, DRA does not create the alias name according to the autonaming policy for Exchange Server 2010 mail-enabled user accounts. (ENG307205)
  • When restoring or cloning an Exchange Server 2010 mail-enabled group account and selecting Send delivery report to group owner in the Exchange Advanced tab, DRA displays an error message. DRA restores or clones the group but does not correctly set all Exchange properties. (ENG307319)

Resolves an Issue With Cloning Contacts

This service pack resolves an issue where DRA copies the legacyExchangeDN of the source contact to the new contact when cloning a contact, which causes a Microsoft Exchange error. (ENG312305)

Resolves an Issue With Windows Terminal Service Path Names

This service pack resolves an issue where DRA does not save a new Windows Terminal Service (WTS) property path for user accounts. (ENG317373)

Resolves an Issue With Restoring Groups

This service pack resolves an issue where DRA cannot locate the original path for the group being restored from the NetIQ Recycle Bin and cannot restore the group to its original location. (ENG315620)

Resolves an Issue With User Interface Extensions

This service pack resolves an issue where a default value for an item on a user interface extension page is not displayed. (ENG310529)

Resolves an Issue With Creating Shares

This service pack resolves an issue where DRA uses the path name for the share name when creating a share. (ENG310619)

Resolves an Issue With Performing Exchange Operations

This service pack resolves an issue where Exchange Administrator could not complete retrieving user mailbox rights or policy lists from Microsoft Exchange Server. (ENG315005)

Resolves an Issue With Saving Changes to Terminal Service Settings

This service pack resolves an issue where DRA does not save changes to Terminal Service settings. (ENG317182)

Resolves an Issue With Last Logon Statistics

This service pack resolves an issue where DRA displays incorrect information for last logon statistics when a DRA administrator views the statistics from a secondary Administration server. (ENG304075)

Resolves an Issue With Delegation Rights in the Web Console

This service pack resolves an issue where users appear to have powers in the Web console that are not delegated to them. (ENG314564)

Return to Top

Installing This Service Pack

To benefit from the new features and fixes provided in this version, install it on each Administration server computer and on each computer where you installed an Account and Resource Management console or Delegation and Configuration console. This service pack contains all the features and fixes included in DRA and ExA 8.6 SP1.

You must have DRA and ExA 8.6 or 8.6 SP1 already installed.

Note
To compute the mailbox count correctly for ExA license enforcement, DRA rebuilds the DOM files when the Administration server initializes after the installation. The Administration server may not be able to process requests until DRA completes this process. The amount of time required to rebuild the DOM files varies by environment.

To install this version:

  1. Download the NetIQ Directory and Resource Administrator and Exchange Administrator 8.6 Service Pack 2 installation program.
  2. Double-click the Setup.exe file.
  3. Follow the on-screen instructions to complete the installation.

Note
If you log on to the primary Administration server with a user account other than the Administration server service account, the installation program prompts you for the service account credentials to be able to extend the AD LDS schema and to update the DRA Reporting database schema.

Return to Top

Known Issues

NetIQ Corporation strives to ensure our products provide quality solutions for your enterprise software needs. The following issues are currently being researched. If you need further assistance with any issue, please contact Technical Support.

Exchange Tasks Not Available When Managed Domain Added to DRA

When a new domain is added to an existing DRA environment that is already configured for Exchange administration, Exchange Administrator does not display Exchange tasks for objects in the new domain because the Exchange provider is not aware of the newly added domain. (ENG305226)

To see Exchange tasks for objects in newly added domains, restart the Administration server computer or follow these steps:

  1. In the Delegation and Configuration Console, select Policy and Automation Management.
  2. Click Configure Exchange Policies.
  3. Clear Enable Exchange Policy and click Apply.
  4. Select Enable Exchange Policy and click Apply.
  5. Select the appropriate Exchange version support and click OK.

DRA Displays Error Message When Checking Exchange Server 2003 Credentials

When the Administration server encounters any problem in checking service account credentials for Exchange Server 2003, DRA displays the following error message:

DRA may not have access to hidden groups in domains supporting Exchange 2003 or later. If accountName is not a member of the group, unexpected results can occur. If you use group memberships to delegate administration of this domain, ensure your access account is a member of the Exchange Domain Servers or Account Operators group.

This error message may be inaccurate. (ENG304359)

DRA May Not Create Home Directories Correctly for User Accounts Created Using the CLI

When you create a user account using the CLI, the home directory may not be created. (ENG307267)

If you encounter this problem, use the Delegation and Configuration console to create a new user account with a home directory.

Exchange Option Unavailable when Assistant Admin has Appropriate Powers

On the Delivery restrictions tab for mailboxes, distribution lists, and contacts, the option Require that all senders are authenticated is disabled even when the Assistant Admin has the appropriate powers to modify this option. (ENG317291)

To work around this issue:

  1. In the Delegation and Configuration console, go to Powers and click New Power.
  2. Add the property msExchRequireAuthToSendTo to the list of included properties.
  3. Associate the new power to the appropriate Assistant Admins.

Return to Top

Previous Releases

This service pack also includes enhancements and fixes added in DRA and ExA 8.6 SP 1.

New Options for Collecting Last Logon Statistics and Removal of DRA Agent

You can now choose whether to use the lastLogonTimestamp attribute on your domain controllers (updated every 14 days) or have DRA collect the lastLogon attribute for each user account in your managed domains (collected according to your schedule). DRA no longer uses an agent to gather last logon statistics.

When you install this service pack, DRA unregisters and uninstalls the DRA Agent from your domain controllers when the NetIQ Administration service restarts.

To configure collection of last logon statistics:

  1. Open the Delegation and Configuration console.
  2. In the Configuration Management node, click Managed Domains.
  3. Select a domain, and click the Properties icon.
  4. Click the Last logon statistics tab, and select the appropriate options for your needs. Additional text has been added to the window to guide you, and the context-sensitive help contains updated information for the new options on this window.

Additional Options for Setting Home Directory Policies

The Home Share/Directory Policies window has been updated to allow you to specify creating and moving home directories for existing users. Additional text has been added to the window to better explain the available options.

To configure home directory policies:

  1. Open the Delegation and Configuration console.
  2. In the Policy and Automation Management node, click Configure Home Directory Policies.
  3. Select the appropriate options for your needs. Additional text has been added to the window to guide you, and the context-sensitive help contains updated information for the new options on this window.

Support for NetIQ Reporting Center 1.5

This version includes NetIQ Reporting Center (NRC) 1.5, which includes the following features:

  • Support for SQL Server 2008 and 2008 R2 on all components
  • Support for Windows Server 2008 and Windows Server 2008 R2 on all components
  • Support for Windows 7 on the Reporting Center Console
  • Compliant with FIPS 140 Inside Program and FIPS 180-3
  • Removed requirement for IIS 6 Resource Kit Tools

Support for Additional Microsoft Exchange Server Features

This version provides additional support for the following Exchange Server features not previously managed by DRA:

  • The new Membership approval tab on the Group Properties window allows you to manage settings for the Exchange 2010 group membership approval feature.
  • A progress bar now displays when you move mailboxes between Exchange Servers. The progress bar displays on all moves to or from Exchange Server 2007 and to or from Exchange Server 2003 servers. (ENG239700)
  • When managing group properties in the Web console, you can now access the Managed by properties. (ENG252766)
  • The Web console now provides support for setting delivery restrictions for a group. (ENG300031)

New License Update Option and Exchange Administrator License Changes

You can now add licenses to the Administration server from a task on the Configuration Management task pad. You must start the Delegation and Configuration console from the Administration server and be connected to the same Administration Server to use this feature. If you have enabled user account control (UAC), you must start the Delegation and Configuration console using Run as Administrator to update the license. After you update the license, the NetIQ Administration service (McsAdminSvc) restarts.

ExA licensing is now consistent with the licensing for account management. The ExA licensing is based on the mailbox count and is checked and enforced when a new mailbox is created.

You can now see a mailbox count on the Statistics tab of the Domain Properties window.

New Access Account Setting for Exchange Server 2010 Allows DRA to Manage Exchange Server 2010 Servers in Untrusted Domains

When you specify Exchange 2010 management in Exchange Administrator, the new Exchange access tab on the Domain Properties window allows you to specify whether to use the Domain access account or another access account for all Exchange servers in your environment. This gives you the ability to configure DRA to manage Exchange Server 2010 servers in untrusted domains.

DRA now stores the credentials for the domain access account and the Exchange access account in AD LDS, so that once you specify these accounts on the primary Administration server, the information is available to all secondary Administration servers in the MMS after replication. Before installing this service pack, you had to specify the domain access account on each Administration server in the MMS.

New Platform Support and Prerequisite Change

This version adds support for the following platforms:

  • SQL Server 2008 and SQL Server 2008 R2
  • Internet Explorer 9

DRA no longer requires installation of Exchange Server 2010 management tools on the Administration server computer. DRA now requires only Powershell 2.0 and Windows Remote Management (WinRM) 2.0 to be installed on the Administration server to remotely manage an Exchange Server 2010 server.

Resolves Administration Server Issues

This service pack resolves the following Administration server issues:

Resolves an Issue Where the Delegation Model Does Not Work After Upgrading DRA 8.5 SP 1 to DRA 8.6
When wildcards are used to associate Assistant Admins with groups in the delegation model, DRA 8.6 now processes group memberships correctly. (ENG302108)
Resolves an Issue Where the Log Archive Data Viewer Shows No Records
The Log Archive Data Viewer now displays records from DRA. (ENG297374)
Resolves an Issue Where DRA Does Not Retain Changes to the Incremental Schedule Settings
DRA now retains changes to the Maximum number of minutes to attempt field. (ENG299443)
Resolves an Issue Where the ADAM or AD LDS Instance on a Secondary Administration Server Does Not Load LDAP
DRA can now connect to the ADAM or AD LDS instance on secondary Administration servers. (ENG298659)
Resolves an Issue Where ActiveViews Created Using the CLI Contain Blank Rule Descriptions
DRA now correctly generates ActiveView rule descriptions that you create using the CLI. (ENG292335)

Resolves User, Computer, and Group Account Administration Issues

This service pack resolves the following user, computer, and group account administration issues:

Resolves an Issue Where Users Are Unable to Create a Share
DRA now correctly sets the path value and users are able to create shares. (ENG300374)
Resolves an Issue Where Users Cannot Reset a Computer Account
DRA no longer incorrectly displays an error message stating This computer is currently not available when a user resets a computer account. (ENG302836)
Resolves an Issue Where Scheduling a Temporary Group Assignment Does Not Allow Specifying an End Time
When you select Immediately to schedule a temporary group assignment, DRA now enables the End time field. (ENG300532)

Resolves Exchange Administrator Issues

This service pack resolves the following Exchange Administrator issues:

Resolves an Issue Where Exchange Parameters for Recycle Bin Objects Can Be Modified
DRA no longer allows objects in the Recycle Bin to be modified. (ENG302230)
Resolves an Issue Where the Move Mailbox Status is Not Available
When a user moves a mailbox from Exchange Server 2010 to Exchange Server 2003, the Move Mailbox Status tab now displays in DRA Exchange Tasks. (ENG301911)
Resolves an Issue Where DRA Displays the Mailbox Storage Limit in Kilobytes Rather Than Megabytes
DRA now displays the Mailbox Storage Limits in megabytes. (ENG295570)
Resolves an Issue Where DRA Allows Spaces and Special Characters in Alias Name Field
DRA no longer allows spaces and special characters to be entered in the Alias name field. (ENG303244)

Resolves DRA Reporting Issues

This service pack resolves the following DRA reporting issues:

Resolves an Issue Where DRA Reporting Installation is Unsuccessful
DRA no longer incorrectly displays a message that the SMCubeDepot database cannot be opened. (ENG301622)
Resolves an Issue Where Change Activity Reports Are Not Available for Objects in the Recycle Bin
DRA now creates change activity reports for objects in the Recycle Bin. (ENG271775)
Resolves an Issue Where Management Reports Are Not Available
The AD collector no longer writes corrupted data to the DRA Reporting database. (ENG301015, ENG301041)
Resolves an Issue Where the AD Collector Data Collection Does Not Finish or Takes More Than 40 Hours to Complete
DRA now completes AD data collection jobs. (ENG307475)
Resolves an Issue Where the AD Collector Does Not Use the Preferred Domain Controller for the Managed Domain
The AD collector now uses the preferred DC for the managed domain. (ENG304685)
Resolves an Issue Where the AD Collector Cannot Collect the proxyAddresses Attribute
The AD collector now collects the proxyAddresses attribute when configured to collect it. (ENG305785)
Resolves an Issue Where the NetIQ Product License Report Contains No Data
The NetIQ Product License Report now contains correct data. (ENG305306)
Resolves an Issue Where the Triggers Table Is Not Updated
The DRA Collector now updates the Triggers table as expected. (ENG299728)

Resolves Policy and Automation Issues

This service pack resolves the following policy and automation issues:

Resolves an Issue Where the Password Generation Policy Does Not Function as Expected
DRA now correctly enforces the password generation policy for minimum and maximum password length and for character restrictions. (ENG297971)
Resolves an Issue Where Triggers No Longer Execute in Alphanumeric Order
DRA now executes triggers in alphanumeric order. (ENG297639, ENG299401)
Resolves an Issue Where Triggers Are Not Executed
DRA now executes triggers as expected. (ENG235155)
Resolves Several Issues Where DRA Does Not Correctly Create or Rename Home Directories
This version resolves several issues where DRA does not correctly create or rename home directories. (ENG265703, ENG301009, ENG246449)
Resolves an Issue Where Existing Triggers Do Not Run on Windows Server 2008 R2 Servers
Triggers now work on Windows Server 2008 R2 servers. (ENG297906)

Resolves Web Console Issues

This service pack resolves the following Web console issues:

Resolves an Issue Where the Web Console Does Not Correctly Display the Previous Search Term
When searching in the Web console, after completing a search, DRA no longer removes the spaces from the search term. (ENG301632)
Resolves an Issue Where Users Are Unable to Remove Home Directory Path Using the Web Console
When the home directory path is blank, the Web console now displays the path in the Connect to field. (ENG299048)
Resolves an Issue Where the Web Console Displays an Incorrect Symbol
When viewing license information in the Web console, the symbol for collapsing information is now the minus sign (-). (ENG304153)
Resolves an Issue Where the Mailbox Store Is Not Displayed
The Web console now displays the full path of the mailbox store for mailboxes. (ENG262402)

Return to Top

Contact Information

Our goal is to provide documentation that meets your needs. If you have suggestions for improvements, please email Documentation-Feedback@netiq.com. We value your input and look forward to hearing from you.

For detailed contact information, see the Support Contact Information Web site.

For interactive conversations with your peers and NetIQ experts, become an active member of Qmunity, our community Web site that offers product forums, product notifications, blogs, and product user groups.

Return to Top

Legal Notice

Return to Top