Extended Rights define groups of Properties. Access control lists can contain Read and/or Write Access control entries for the Extended Right, granting permission to the associated properties of an object.
Manditory properties Must be readable to grant access Possible imported properties Administrator-set properties
Shaded properties fall into the categories listed:
CN name Display Name
 
No associated Extended Right
Other-Name middleName
Employee-ID employeeID
   
Email-Information Phone and Mail Options
NO ASSOCIATED PROPERTIES
   
Domain-Password Domain Password + Lockout Policies
Lockout-Duration lockoutDuration
Lock-Out-Observation-Window lockOutObservationWindow
Lockout-Threshold lockoutThreshold
Max-Pwd-Age maxPwdAge
Min-Pwd-Age minPwdAge
Min-Pwd-Length minPwdLength
Pwd-History-Length pwdHistoryLength
Pwd-Properties pwdProperties
   
General-Information General Information
Admin-Description adminDescription
Code-Page codePage
Country-Code countryCode
Display-Name displayName
Object-Sid objectSid
Primary-Group-ID primaryGroupID
SAM-Account-Name     sAMAccountName   
SAM-Account-Type sAMAccountType
SD-Rights-Effective sDRightsEffective
Show-In-Advanced-View-Only showInAdvancedViewOnly
SID-History sIDHistory
User-Comment comment
   
Personal-Information Personal Information
Address streetAddress
Address-Home homePostalAddress
Assistant assistant
Comment info
Country-Name c
Facsimile-Telephone-Number facsimileTelephoneNumber
International-ISDN-Number internationalISDNNumber
Locality-Name l
MSMQ-Digests mSMQDigets
MSMQ-Sign-Certificates mSMQSignCertificates
Personal-Title personalTitle
Phone-Fax-Other otherFacsimileTelephoneNumber
Phone-Home-Other otherHomePhone
Phone-Home-Primary homephone
Phone-Ip-Other otherIpPhone
Phone-Ip-Primary ipPhone
Phone-ISDN-Primary primaryInternationalISDNNumber
Phone-Mobile-Other otherMobile
Phone-Mobile-Primary mobile
Phone-Office-Other otherTelephone
Phone-Pager-Other otherPager
Phone-Pager-Primary pager
Physical-Delivery-Office-Name physicalDeliveryOfficeName
Picture thumbnailPhoto
Postal-Address postalAddress
Postal-Code postalCode
Post-Office-Box postOfficeBox
Preferred-Delivery-Method preferredDeliveryMethod
Registered-Address registeredAddress
State-Or-Province-Name st
Street-Address street
Telephone-Number telephoneNumber
Teletex-Terminal-Identifier teletexTerminalIdentifier
Telex-Number telexNumber
Telex-Primary primaryTelexNumber
User-Cert userCert
User-Shared-Folder userSharedFolder
User-Shared-Folder-Other userSharedFolderOther
User-SMIME-Certificate userSMIMECertificate
X121-Address x121Address
X509-Cert userCertificate
   
Public-Information Public Information
Additional-Information notes
Allowed-Attributes allowedAttributes
Allowed-Attributes-Effective allowedAttributesEffective
Allowed-Child-Classes allowedChildClasses
Allowed-Child-Classes-Effective allowedChildClassesEffective
Alt-Security-Identities altSecurityIdentities
Common-Name cn
Company company
Department department
Description description
Display-Name-Printable displayNamePrintable
Division division
E-mail-Addresses mail
Given-Name givenName
Initials initials     (Middle Initial)
Legacy-Exchange-DN legacyExchangeDN
Manager manager
Obj-Dist-Name distinguishedName
Object-Category objectCatagory
Object-Class objectClass
Object-Guid objectGUID
Organizational-Unit-Name ou
Organization-Name o
Other-Mailbox otherMailbox
Proxy-Addresses proxyAddresses
RDN name
Reports directReports
Service-Principal-Name servicePrincipalName
Show-In-Address-Book showInAddressBook
Surname sn
System-Flags systemFlags
Text-Country co
Title title
User-Principal-Name userPrincipalName
   
Membershipmembership
Membermember
   
Ras-Information Remote Access Information
msNPAllowDialin msNPAllowDialin
msNPCallingStationID msNPCallingStationID
msRADIUSCallbackNumber msRADIUSCallbackNumber
msRADIUSFramedIPAddress msRADIUSFramedIPAddress
msRADIUSFramedRoute msRADIUSFramedRoute
msRADIUSServiceType msRADIUSServiceType
Token-Groups tokenGroups
Token-Groups-Global-And-Universal tokenGroupsGlobalAndUniversal
Token-Groups-No-GC-Acceptable tokenGroupsNoGCAcceptable
   
User-Account-Restrictions Account Restrictions
Account-Expires accoutExpires
Pwd-Last-Set pwdLastSet
User-Account-Control userAccountControl
User-Parameters userParameters (Terminal Services Properties)
   
User-Logon Logon Information
Bad-Pwd-Count badPwdCount
Home-Directory homeDirectory
Home-Drive homeDrive
Last-Logoff lastLogoff
Last-Logon lastLogon
Logon-Count logonCount
Logon-Hours logonHours
Logon-Workstation logonWorkstation
Profile-Path profilePath
   
Web-Information Web Information
WWW-Home-Page wWWHomePage
WWW-Page-Other url

 


Return to Infrastructure Documentation
Return to WWW-NT home page
Last modified 10/13/00 by Ross Wilper
©2000 Trustees of the Leland Stanford Junior University