Skip to content


Quick Connect for Exchange Resource Forests

Last week I forgot to mention that we renamed our Exchange Resource Forest Manager module to Quick Connect for Exchange Resource Forests and updated it to support the latest version of Exchange and ActiveRoles Server.  This module extends the multi-forest management capability of ActiveRoles Server to synchronize and provision accounts between a User Account Forest and the Exchange Resource Forest. Additionally, Exchange properties are projected from the Resource Forest onto the property pages of users in the User Forest for single point user account management.

Post to Twitter

Posted in Active Directory. Tagged with , , , .

Quick Connect 4.5 GA!

I am pleased to announce that later today, Quick Connect 4.5 will be made Generally Available (GA)to the public. You can now download the bits from http://www.quest.com/common/registration.aspx?requestdefid=20088.

What’s New: Password Synchronization – Quick Connect can synchronize passwords between Active Directory and some categories of connected systems. Active Directory and connected systems are governed by different access policies. Consequently, users need to maintain different user accounts and different passwords on these systems.

Maintaining several passwords on several different systems is a hassle for users and administrators. Quick Connect provides for Quick Connect Capture Agent to be installed on all domain controllers in the source Active Directory connections. Capture Agent tracks changes that were made to user password in Active Directory, and then Quick Connect Sync Engine synchronizes the passwords basing on this information.

What’s New: Re-designed Sync History Log – The Sync History feature of the application allows you to view reports on the performed synchronization workflow runs. The Sync History tab allows you to display a list of all performed synchronization workflows runs, and then view the report on the workflow run of interest. In addition to this possibility, the new version of the Sync History tab allows you first to filter the synchronization reports for all object pairs using some filter criteria, and then select the report to view.

What’s New: Additional Rules for Synchronizing Multi-valued attributes – In Quick Connect 4.0 we provided multi-attribute synchronization but we found we needed more options.  Group and role assignments are often stored using multiple values in a single attribute and many traditional provisioning solutions are limited single value attribute provisioning . Flexible multi-value capability allows roles and groups to be synchronized between systems. For example, you may want to synchronize an SAP Role to an Microsoft Exchange Distribution List so you can easily email those individuals. Without multi-value capability coordinating such seemingly simple lists becomes very-very difficult.

Post to Twitter

Posted in Active Directory. Tagged with , , , , , , , , , , , .

Old School threats still persist

Great article in Network world about how companies are chasing the latest threats, but failing to mitigate the older security flaws. It was funny to see that applications exposed to the Internetthat were poorly protected was still happening in this day and age especially with all the two factor and other access protection technology widely available.

http://www.networkworld.com/news/2010/020310-old-security-flaws-still-a.html

Post to Twitter

Posted in Active Directory. Tagged with , .

SUN Identity Manager Customers SOL?

When IBM was bidding on SUN I posed the question…  Question: What do you get if IBM acquires SUN? Answer: IBM. The same joke appears to be coming true now that Oracle is completing acquisition of SUN.

My colleague Jackson Shaw did a great job explaining the situation and sharing his incite on what this means to SUN customers.  His blog is certainly worth the read. http://jacksonshaw.blogspot.com/2010/01/sun-idm-is-dead.html

Post to Twitter

Posted in Active Directory. Tagged with , , .

Windows IT Pro Editor’s Choice: ActiveRoles

Eric Rux at Windows IT Pro magazine took on the job of installing and reviewing a bunch of AD Administration and Provisioning products to help readers select the most comprehensive and complete solution. Eric compared four different products and to me it was no surprise that ActiveRoles came out on top as the clear winner. 

What is our secret? Simple, customer driven development, strong expertise and a team that is passionate about their work.

 http://windowsitpro.com/Windows/Articles/ArticleID/103318/pg/4/4.html

Post to Twitter

Posted in Active Directory. Tagged with , , , , , , , , .

Quick Connect 4.5 Goes Gold!

Following up on our highly successful 4.0 release, 4.5 went gold last week. We are now going through the internal processes needed to release the product to the public next month.

The biggest news about this release is that Quick Connect can synchronize passwords between Active Directory and connected systems. Active Directory and connected systems are governed by different access policies. Consequently, users need to maintain different user accounts and different passwords on these systems. Maintaining several passwords on several different systems is a hassle for users and  administrators.  Quick Connect now provides a Password Capture Agent to be installed on all domain controllers in the source Active Directory connections. The Capture Agent tracks changes that were made to user password in Active Directory, and then Quick Connect Sync Engine synchronizes the passwords basing on this information.

Also new in this release:

  • Updated design of history log to allow better searching and filtering
  • Additional rules for synchronizing multi-value attributes
  • Various improvments and resovled issues

We had a excellent year in 2009 and with this hot new release of Quick Connect I anticipate an even better 2010.

Post to Twitter

Posted in Active Directory. Tagged with , , , , , .

How you can personally help Haiti

You can donate $10 to the Red Cross by texting Haiti to 90999.

This is really-really cool and it appears that $5M has already been raised; a billion will probably be needed. Once you send the txt message, you will get a message back asking you to confirm your donation to which you must reply YES before the $10 is added to your phone bill.  http://www.redcross.org/

If someone else pays your phone bill (like if you have a company phone) you may want to donate a different way.  For example,  The company I work for, Quest Software partnered with Iridium to donate a bunch of Satellite phones and airtime to Haitian officials to coordinate relief efforts. And another example is a video from Jimmy Buffett created to raise awarness about the Red Cross’s text message donation program. The way I look at it, this could be my family needing help.

Post to Twitter

Posted in Active Directory. Tagged with , , , , .

My next web cast:Access Accountability and Sustained Compliance

On January 27th I’ve been asked to deliver another web cast showing  how you can ac hive Access Accountability and Sustained Compliance with Quest’s ActiveRoles Server. I’m going to demonstrate the new features of ActivceRoles Server and Self-Service Manager that allow you to get control over the access granted within your organization while at the same time sustaining compliance; a happy auditor is a quite auditor.

To register visit: http://www.quest.com/events/listdetails.aspx?contentid=10866&searchoff=true&technology=&prod=183&prodfamily=&loc

Post to Twitter

Posted in Active Directory. Tagged with , , , , , .

Quest Password Manager 4.6 ships!

My friend Stuart Harrison just announced that a new version of Quest Password Manager has just been released.  This new version contains several really cool integration points with ActiveRoles Server and ActiveRole Quick Connect to provide a seamless cross-platform credential management solution.

Other new features include:

  • Windows 7 support
  • Windows 2008 R1/R2 support
  • IE8 support
  • Captcha
  • Granular minimum/maximum password age
  • Quick Connect Integration providing cross platform password management
  • Integration with ActiveRoles Server Web UI (Help Desk site)
  • Reporting support for SQL/SRS 2008
  • Defender Integration enabling use of OTP to change password/unlock account and now for initial registration with QPM
  • Various reporting enhancements including email and Help Desk stats
  • For more information see Stuart’s blog: http://stuharrison.blogspot.com/2009/12/quest-password-manager-46-launched.html

    Post to Twitter

    Posted in Active Directory. Tagged with , , , .

    15 years a fugitive

    My Thanksgiving holiday came this year as it has forty three times before in my life. I was expected holiday to deliver the typical car ride to a relative’s home where we I would be allowed to over indulge my disturbing love affair with Turkey, bread stuffing, Pillsbury dinner roles, mashed potato with gravy and butter. I was looking forward to once again becoming a slow land animal participating in an over indulgent food orgy, what I didn’t expect was to have a run-in with .

    Thanksgiving fell on a Thursday November 27th this year and because I was leaving the country for two weeks that same weekend after I decided to work a little late on Wednesday. At some point I concluded that I was ready for my trip so I headed home to begin my three day holiday before leaving. On my way home I decided that I should have a little spending money with me as I would be traveling and feel more comfortable doing so with cash in my pocket. The bank I use is less than a two minute drive from my home and so I decided that I would set a way-point and use their drive through cash machine.

    When I drove up to the cash machine I tried to lower my window and it was only then that I remembered it stopped working more than a week earlier. My forgetfulness can only be attributed to the cold weather we have had making lowering the window unnecessary for some time. With some embarrassment I continued through the cash machine lane then making a sharp right turn toward home. I’m not sure if it was the previous embarrassment or the thought of getting home that pushed me to accelerate past the now obvious police car on my right, but stupidly accelerate I did. Then as the officer approached my Window I raised my voice a little and with great embarrassment told him the window was broken.

    “No problem.” he said and opened the driver’s door. “I stopped you because we have a lot of complaints about speeders on this road.” I admitted that I have probably been one of those who have complained and continued about my situation at the cash machine hoping my temporary insanity plea would help.

    I was surprised that my explanations seem to have a impact on the officer who having gathered the necessary papers was now walking back to his car to verify them and (I assumed) write the ticket. From previous experience I expected this to take no more than ten minutes. After fifteen minutes I started to wonder if there was something else going on and when a second and third police car arrived and I was certain.

    After what seemed like twenty minutes the officer again opened my driver’s door and said, “Mr. Bobel, I have some good news for you. I am going to give you a written warning for speeding so you are not getting a ticket from me today.” He continued, “Now I have some bad news for you – I have a warrant for your arrest.”

    I was speechless.

    I am sure seeing my face go white also had an impact on the officer and he quickly continued “Did you get a ticket in 1994 for an expired car registration?”. My reaction to his question must have only confirmed his assumption that I was just some poor schmuck, not Al Capone, and I genuinely did not know about the ticket.

    “Now I will give you a little more good news – if would not sleep well tonight if I took you to jail for a fifteen year old ticket on the start of the thanksgiving holiday. You will certainly have a lot to be thankful for this thanksgiving.” he said smiling. I was incredibly thankful. The officer went on to explain that clerk told him that the 15 year old ticket could still be paid after which the arrest warrant would be cancelled. The officer then provided me with a business card on which my case number and contact details for payment were written. As he turned to walk back to his patrol car he stopped and turned back and mentioned had known he someone who had a past due ticket that cost $3000 to resolve and that he wasn’t positive that the $140 written on his card included late fees or interest. I thanked him again and drove home.

    Thursday, Thanksgiving day, I was up at 7:00am and on the road by 7:30am to pay my debt to society.  The previous night my father begrudgingly agreed to drive me down to the court avoiding the chance I get pulled over again and sent to the slammer for the weekend. Fortunately, he knew exactly where to go since only weeks before he also had to resolve an unpaid parking ticket and in fact he had taken my children with him to show them the finer workings of the Columbus court system. As it was a holiday there was absolutely no wait required and so my $140 fine was paid resolving the entire matter.

    One question lingered – why no after 15 years. My guess is that the city needs money and so when an officer has the time they make a call to have older records searched. Thank goodness the officer I met used good judgment and discretion for the best possible outcome and I am truly thankful.

    Post to Twitter

    Posted in Bobel.