How to Hide or Display the InetOrgPerson Object Class in Active Directory Users and Computers (311555)
The information in this article applies to:
- Microsoft Windows Server 2003, 64-Bit Datacenter Edition
- Microsoft Windows Server 2003, 64-Bit Enterprise Edition
- Microsoft Windows Server 2003, Datacenter Edition
- Microsoft Windows Server 2003, Enterprise Edition
- Microsoft Windows Server 2003, Standard Edition
- Microsoft Windows Small Business Server 2003, Premium Edition
- Microsoft Windows Small Business Server 2003, Standard Edition
This article was previously published under Q311555 SUMMARY In Windows Server 2003-and-later versions of Active
Directory, an additional object class is introduced -- the InetOrgPerson object class. InetOrgPerson is defined in RFC 2798, and it has been accepted as the de facto
standard in other Lightweight Directory Access Protocol (LDAP) directory
implementations.
Active Directory has been modified to support the InetOrgPerson class, and with the addition of the User class definition, you can now create InetOrgPerson as security principals in Active Directory. This greatly enhances
an administrator's capabilities to migrate user accounts from third-party
directories into the Active Directory.
However, this change may
introduce problems with third-party programs (third-party programs are defined
as any programs that use Active Directory as an authentication method).
Microsoft recommends that you perform complete program compatibility testing
before you use the InetOrgPerson class.
For this reason, and also to avoid confusion,
you may want to disable the visible references to the InetOrgPerson object type in Active Directory Users and Computers. This will
prevent administrators from mistakenly creating InetOrgPerson users instead of the more accepted User type.
Modification Type: | Major | Last Reviewed: | 4/5/2004 |
---|
Keywords: | kbinfo KB311555 |
---|
|