WinBatch Tech Support Home

Database Search

If you can't find the information using the categories below, post a question over in our WinBatch Tech Support Forum.

TechHome

wNT
plus

Can't find the information you are looking for here? Then leave a message over on our WinBatch Tech Support Forum.

NT Network Extender and UPN Account Names

 Keywords: Win32 NT Network Extender and UPN User Principal Names Account Names 

Question:

I'm trying to use wntUserExist on a windows 2003 AD domain that has User Principal Names configured to enable users at other domains to logon. That is, my domain is D1.com. A configured UPN is D2.com so user1@D2.com can logon to D1.com. wntUserExist fails to find user1@D2.com, although AD Users & Computers lists it. There can be more than 1 user1 in the entire D1.com domain, so searching for "user1" is insufficient. wntUserExist also appears to use what AD Users & Computers calls the "User logon name (pre-Windows 2000)". Unfortunately, in my case that's sometimes a nasty string like $UH6000-HQI9CPL6M0AA. Is there a way to search on "User logon name" or the full "user1@D2.com"?

Answer:

The NT extender uses the NT domain API functions, which work with account names in the form of "domain\account". UPN formatted account names aren't understood by those API functions, and so the NT extender doesn't accept UPN formatted account names. Use the ADSI extender or the ADSI COM automation interfaces if you need to use UPN account names or LDAP fully distinguished names [FDNs].
Article ID:   W17997
Filename:   NT Network Extender and UPN Account Names.txt
File Created: 2008:12:05:14:57:12
Last Updated: 2008:12:05:14:57:12