Article ID: 252398 - Last Review: October 12, 2007 - Revision: 3.4 Cannot Grant Dial-in Access to a User from an ADSI ScriptThis article was previously published under Q252398 SYMPTOMS
When you create a user from an Active Directory Services Interface (ADSI) script in Windows 2000, you cannot enable the Remote Access Service (RAS) "Allow Access" permission in the Remote Access Permission (Dial-in or VPN) section of the Dial-In tab in the user's properties.
CAUSE
This behavior occurs when the msNPAllowDialin and userParameters settings are out of synchronization. Lightweight Directory Access Protocol (LDAP) programs, such as the ADSI LDAP provider, can update the msNPAllowDialin setting correctly. However, Active Directory cannot update the userParameters setting. This behavior affects Windows 2000-based domains in Mixed mode or Windows 2000-based domains in Native mode that include RAS servers hosted by Microsoft Windows NT-based computers.
RESOLUTION
The workaround for Windows 2000-based domains in a Mixed-mode environment is to enable the DialinPrivilege user object parameter that is exposed by the Windows NT provider. To implement this workaround:
STATUS
This behavior is by design.
| Article Translations
|

Back to the top
