Create user templates
A user enrollment template is a tool to help you enroll users from i5/OS™ to the Windows environment more efficiently. Rather than manually configuring
many new users, each with identical settings, use a user enrollment template
to automatically configure them. You can learn more about user enrollment
templates at User Enrollment Templates.
Follow these steps to create a Windows template:
For a Windows 2000 Server or Windows Server 2003 domain:
- At the integrated server console click Start —>
Programs —> Administrative Tools —> Active Directory Users and
Computers.
- Click the domain name.
- Right-click Users, then select New—>User.
- In the Username and Logon name fields, enter a distinctive name for the template, such as stduser or admtemp. Click Next.
- It is recommended that you also deselect the User must
change password at next logon check box and select the User cannot change password, Password never expires, and Account is disabled checkboxes. This prevents
anyone using the template account itself to access the integrated server.
- Do not enter a password for a template account.
- Click Finish.
- To set up group memberships, double-click the template name in the list
of domain users and groups that appear in the right pane. Click the Member of tab and then click Add to add the groups
that you want.
For a Windows 2000 Server or Windows Server 2003 server:
- From the integrated server console
- In Windows 2000 Server click Start —> Programs —>
Administrative Tools —> Computer Management —> Local Users and
Groups.
- In Windows Server 2003 click Start —> Programs —>
Administrative Tools —> Computer Management —> System Tools —>
Local Users and Groups.
- Select System Tools —> Local
Users and Groups.
- Right-click Users and select New
User.
- In the User name field, enter a distinctive name
for the template, such as stduser or admtemp.
- It is recommended that you also deselect the User must
change password at next logon check box and select the Password never expires, User cannot change password, and Account is disabled checkboxes. This prevents
anyone using the template account itself to access Windows server.
- Click Create, then Close.
- Click Users or refresh to show the new user template.
- To set up group memberships, double-click the template name in the list
of domain users and groups that appears in the right pane. Click the Member of tab and then click Add to add the groups
that you want.
You can make a user template a member of any Windows server group, whether
you enrolled that group from i5/OS or not. You can enroll users with a template
that is a member of a group that was not enrolled from i5/OS. If you do
this you can only remove users from the group by using the User Manager program
on Windows server.
If you are creating a template that will be used to enroll administrators,
you may want to make the template a member of the Windows server group Administrators. Likewise, if you want to protect Windows
users from accidental deletion from i5/OS, enroll the template in the AS400_Permanent_Users (or OS400_Permanent_Users) group.