Windows Enterprise Domain
IT Administrator Support


OU Administrator Support

Several policy and procedure documents are available that Windows OU managers should look over. Some of these items have been submitted by current departmental OU managers to assist others. If you have some tips written up that you think would be helpful to others, email them to us.

Key Documentation for OU Managers

IT Handbook

The IT Handbook was developed by the Colleges of Engineering and Liberal Arts and Sciences and Information Technology Services. This handbook is intended to provide answers to common IT questions at Iowa State University.

OU Manager's FAQ

Look at the OU Administation FAQ for the answers to common questions.

OU Administrator Policy and Procedures

Departmental OU Life-cycle Procedures

Policy and Procedures for Managing Users and Computers in an OU

Group Policy

ASW and Institutional Lists as Windows Security Groups

Special Requests (for things only Enterprise Admins can do)

Enterprise Domain Services Available

Security and System Integrity - Recommended practices for users and systems

Deploying Systems and Software

General System Deployment

Macintosh OS X

Labs and Other Multi-User Systems

Unix System Integration

OU Administrator Tools

Several tools have been developed at Iowa State or discovered by our OU admins that are valuable for day-to-day IT admin functions. If you discover any other tools you feel will be widely used by others, email them to us.

  • Active Directory Enumerator (ADE) is an application to perform interrogation and management of users, groups, and computers within Active Directory. It is the “Swiss army knife” of user, group, and computer management within an Active Directory OU environment. ADE can expand the entire group-membership tree for a user or show the users that are members of a group structure. AD attributes can be displayed.

  • Backup Wizard is a frontend to Microsoft’s “User State Migration Tool” (USMT). The Backup Wizard provides a GUI interface to walk you through backing up selected users on a system (including special file locations outside the normal “Documents and Settings” area). This is most useful when replacing a desktop while retaining the users settings, documents, etc. OS upgrades (XP to Vista, for example) are handled.

  • Creating Group-Aware Logon Scripts is a document that provides information on using a Microsoft tool (ifmember.exe) to evaluate user group membership and control logon script processing.

  • MS03-026 Example Scripts is a package distributed by Microsoft to assist in patching Windows NT, 2000, XP, and Server 2003 systems for the MS03-026 RPC vulnerability. This package can be burned on a CD-ROM to provide an automated, easy-to-use method for patching vulnerable systems.

  • PswdUtil is a program that checks user objects in an OU for password age. This program will produce lists of users whose password is over "n" days old and allow an OU administrator to force the user to change their password if desired. Using this utility each OU administrator can enforce a stricter password age policy than the default domain password age policy.

  • ShowUserDept is a program that displays the official university college and department data for a given ISU NetID. This data is used to determine the appropriate departmental OU for location of faculty and staff user objects. An indication as to whether or not the NetID is "inactive" (suspended) or not is also provided. Interactive and batch modes are supported.

Last updated August 17, 2016