3 @IDXATTR: sAMAccountName
11 realm: CASE_INSENSITIVE
12 userPrincipalName: CASE_INSENSITIVE
13 servicePrincipalName: CASE_INSENSITIVE
14 name: CASE_INSENSITIVE WILDCARD
15 dn: CASE_INSENSITIVE WILDCARD
16 sAMAccountName: CASE_INSENSITIVE WILDCARD
17 objectClass: CASE_INSENSITIVE
23 createTimestamp: HIDDEN
24 modifyTimestamp: HIDDEN
32 person: organizationalPerson
33 organizationalPerson: user
35 template: userTemplate
36 template: groupTemplate
44 objectClass: domainDNS
47 dnsDomain: ${DNSDOMAIN}
49 objectGUID: ${DOMAINGUID}
50 creationTime: ${NTTIME}
51 forceLogoff: 0x8000000000000000
52 lockoutDuration: -18000000000
53 lockOutObservationWindow: -18000000000
55 whenCreated: ${LDAPTIME}
56 whenChanged: ${LDAPTIME}
59 maxPwdAge: -37108517437440
62 modifiedCountAtLastProm: 0
66 objectSid: ${DOMAINSID}
70 objectCategory: CN=Domain-DNS,CN=Schema,CN=Configuration,${BASEDN}
71 isCriticalSystemObject: TRUE
73 dn: CN=Users,${BASEDN}
75 objectClass: container
77 description: Default container for upgraded user accounts
79 whenCreated: ${LDAPTIME}
80 whenChanged: ${LDAPTIME}
83 showInAdvancedViewOnly: FALSE
85 objectGUID: ${NEWGUID}
86 systemFlags: 0x8c000000
87 objectCategory: CN=Container,CN=Schema,CN=Configuration,${BASEDN}
88 isCriticalSystemObject: TRUE
90 dn: CN=Computers,${BASEDN}
92 objectClass: container
94 description: Default container for upgraded computer accounts
96 whenCreated: ${LDAPTIME}
97 whenChanged: ${LDAPTIME}
100 showInAdvancedViewOnly: FALSE
102 objectGUID: ${NEWGUID}
103 systemFlags: 0x8c000000
104 objectCategory: CN=Container,CN=Schema,CN=Configuration,${BASEDN}
105 isCriticalSystemObject: TRUE
107 dn: OU=Domain Controllers,${BASEDN}
109 objectClass: organizationalUnit
110 ou: Domain Controllers
111 description: Default container for domain controllers
113 whenCreated: ${LDAPTIME}
114 whenChanged: ${LDAPTIME}
117 showInAdvancedViewOnly: FALSE
118 name: Domain Controllers
119 objectGUID: ${NEWGUID}
120 systemFlags: 0x8c000000
121 objectCategory: CN=Organizational-Unit,CN=Schema,CN=Configuration,${BASEDN}
122 isCriticalSystemObject: TRUE
124 dn: CN=ForeignSecurityPrincipals,${BASEDN}
126 objectClass: container
127 cn: ForeignSecurityPrincipals
128 description: Default container for security identifiers (SIDs) associated with objects from external, trusted domains
130 whenCreated: ${LDAPTIME}
131 whenChanged: ${LDAPTIME}
134 showInAdvancedViewOnly: FALSE
135 name: ForeignSecurityPrincipals
136 objectGUID: ${NEWGUID}
137 systemFlags: 0x8c000000
138 objectCategory: CN=Container,CN=Schema,CN=Configuration,${BASEDN}
139 isCriticalSystemObject: TRUE
141 dn: CN=Builtin,${BASEDN}
143 objectClass: builtinDomain
146 showInAdvancedViewOnly: FALSE
148 forceLogoff: 0x8000000000000000
149 lockoutDuration: -18000000000
150 lockOutObservationWindow: -18000000000
152 maxPwdAge: -37108517437440
155 modifiedCountAtLastProm: 0
163 objectCategory: CN=Builtin-Domain,CN=Schema,CN=Configuration,${BASEDN}
164 isCriticalSystemObject: TRUE
166 dn: CN=Administrator,CN=Users,${BASEDN}
169 objectClass: organizationalPerson
172 description: Built-in account for administering the computer/domain
174 whenCreated: ${LDAPTIME}
175 whenChanged: ${LDAPTIME}
177 memberOf: CN=Group Policy Creator Owners,CN=Users,${BASEDN}
178 memberOf: CN=Domain Admins,CN=Users,${BASEDN}
179 memberOf: CN=Enterprise Admins,CN=Users,${BASEDN}
180 memberOf: CN=Schema Admins,CN=Users,${BASEDN}
181 memberOf: CN=Administrators,CN=Builtin,${BASEDN}
184 objectGUID: ${NEWGUID}
185 userAccountControl: 0x10200
194 objectSid: ${DOMAINSID}-500
198 sAMAccountName: Administrator
199 sAMAccountType: 0x30000000
200 objectCategory: CN=Person,CN=Schema,CN=Configuration,${BASEDN}
201 isCriticalSystemObject: TRUE
202 unicodePwd: ${ADMINPASS}
205 dn: CN=Guest,CN=Users,${BASEDN}
208 objectClass: organizationalPerson
211 description: Built-in account for guest access to the computer/domain
213 whenCreated: ${LDAPTIME}
214 whenChanged: ${LDAPTIME}
216 memberOf: CN=Guests,CN=Builtin,${BASEDN}
219 objectGUID: ${NEWGUID}
220 userAccountControl: 0x10222
229 objectSid: ${DOMAINSID}-501
232 sAMAccountName: Guest
233 sAMAccountType: 0x30000000
234 objectCategory: CN=Person,CN=Schema,CN=Configuration,${BASEDN}
235 isCriticalSystemObject: TRUE
237 dn: CN=Administrators,CN=Builtin,${BASEDN}
241 description: Administrators have complete and unrestricted access to the computer/domain
242 member: CN=Domain Admins,CN=Users,${BASEDN}
243 member: CN=Enterprise Admins,CN=Users,${BASEDN}
244 member: CN=Administrator,CN=Users,${BASEDN}
246 whenCreated: ${LDAPTIME}
247 whenChanged: ${LDAPTIME}
251 objectGUID: ${NEWGUID}
252 objectSid: S-1-5-32-544
254 sAMAccountName: Administrators
255 sAMAccountType: 0x20000000
256 systemFlags: 0x8c000000
257 groupType: 0x80000005
258 objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
259 isCriticalSystemObject: TRUE
261 privilege: SeSecurityPrivilege
262 privilege: SeBackupPrivilege
263 privilege: SeRestorePrivilege
264 privilege: SeSystemtimePrivilege
265 privilege: SeShutdownPrivilege
266 privilege: SeRemoteShutdownPrivilege
267 privilege: SeTakeOwnershipPrivilege
268 privilege: SeDebugPrivilege
269 privilege: SeSystemEnvironmentPrivilege
270 privilege: SeSystemProfilePrivilege
271 privilege: SeProfileSingleProcessPrivilege
272 privilege: SeIncreaseBasePriorityPrivilege
273 privilege: SeLoadDriverPrivilege
274 privilege: SeCreatePagefilePrivilege
275 privilege: SeIncreaseQuotaPrivilege
276 privilege: SeChangeNotifyPrivilege
277 privilege: SeUndockPrivilege
278 privilege: SeManageVolumePrivilege
279 privilege: SeImpersonatePrivilege
280 privilege: SeCreateGlobalPrivilege
281 privilege: SeEnableDelegationPrivilege
282 privilege: SeInteractiveLogonRight
283 privilege: SeNetworkLogonRight
284 privilege: SeRemoteInteractiveLogonRight
287 dn: CN=Users,CN=Builtin,${BASEDN}
291 description: Users are prevented from making accidental or intentional system-wide changes. Thus, Users can run certified applications, but not most legacy applications
292 member: CN=Domain Users,CN=Users,${BASEDN}
294 whenCreated: ${LDAPTIME}
295 whenChanged: ${LDAPTIME}
299 objectGUID: ${NEWGUID}
300 objectSid: S-1-5-32-545
301 sAMAccountName: Users
302 sAMAccountType: 0x20000000
303 systemFlags: 0x8c000000
304 groupType: 0x80000005
305 objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
306 isCriticalSystemObject: TRUE
308 dn: CN=Guests,CN=Builtin,${BASEDN}
312 description: Guests have the same access as members of the Users group by default, except for the Guest account which is further restricted
313 member: CN=Domain Guests,CN=Users,${BASEDN}
314 member: CN=Guest,CN=Users,${BASEDN}
316 whenCreated: ${LDAPTIME}
317 whenChanged: ${LDAPTIME}
321 objectGUID: ${NEWGUID}
322 objectSid: S-1-5-32-546
323 sAMAccountName: Guests
324 sAMAccountType: 0x20000000
325 systemFlags: 0x8c000000
326 groupType: 0x80000005
327 objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
328 isCriticalSystemObject: TRUE
331 dn: CN=Print Operators,CN=Builtin,${BASEDN}
335 description: Members can administer domain printers
337 whenCreated: ${LDAPTIME}
338 whenChanged: ${LDAPTIME}
341 name: Print Operators
342 objectGUID: ${NEWGUID}
343 objectSid: S-1-5-32-550
345 sAMAccountName: Print Operators
346 sAMAccountType: 0x20000000
347 systemFlags: 0x8c000000
348 groupType: 0x80000005
349 objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
350 isCriticalSystemObject: TRUE
351 privilege: SeLoadDriverPrivilege
352 privilege: SeShutdownPrivilege
353 privilege: SeInteractiveLogonRight
355 dn: CN=Backup Operators,CN=Builtin,${BASEDN}
359 description: Backup Operators can override security restrictions for the sole purpose of backing up or restoring files
361 whenCreated: ${LDAPTIME}
362 whenChanged: ${LDAPTIME}
365 name: Backup Operators
366 objectGUID: ${NEWGUID}
367 objectSid: S-1-5-32-551
369 sAMAccountName: Backup Operators
370 sAMAccountType: 0x20000000
371 systemFlags: 0x8c000000
372 groupType: 0x80000005
373 objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
374 isCriticalSystemObject: TRUE
375 privilege: SeBackupPrivilege
376 privilege: SeRestorePrivilege
377 privilege: SeShutdownPrivilege
378 privilege: SeInteractiveLogonRight
380 dn: CN=Replicator,CN=Builtin,${BASEDN}
384 description: Supports file replication in a domain
386 whenCreated: ${LDAPTIME}
387 whenChanged: ${LDAPTIME}
391 objectGUID: ${NEWGUID}
392 objectSid: S-1-5-32-552
394 sAMAccountName: Replicator
395 sAMAccountType: 0x20000000
396 systemFlags: 0x8c000000
397 groupType: 0x80000005
398 objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
399 isCriticalSystemObject: TRUE
401 dn: CN=Remote Desktop Users,CN=Builtin,${BASEDN}
404 cn: Remote Desktop Users
405 description: Members in this group are granted the right to logon remotely
407 whenCreated: ${LDAPTIME}
408 whenChanged: ${LDAPTIME}
411 name: Remote Desktop Users
412 objectGUID: ${NEWGUID}
413 objectSid: S-1-5-32-555
414 sAMAccountName: Remote Desktop Users
415 sAMAccountType: 0x20000000
416 systemFlags: 0x8c000000
417 groupType: 0x80000005
418 objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
419 isCriticalSystemObject: TRUE
421 dn: CN=Network Configuration Operators,CN=Builtin,${BASEDN}
424 cn: Network Configuration Operators
425 description: Members in this group can have some administrative privileges to manage configuration of networking features
427 whenCreated: ${LDAPTIME}
428 whenChanged: ${LDAPTIME}
431 name: Network Configuration Operators
432 objectGUID: ${NEWGUID}
433 objectSid: S-1-5-32-556
434 sAMAccountName: Network Configuration Operators
435 sAMAccountType: 0x20000000
436 systemFlags: 0x8c000000
437 groupType: 0x80000005
438 objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
439 isCriticalSystemObject: TRUE
441 dn: CN=Performance Monitor Users,CN=Builtin,${BASEDN}
444 cn: Performance Monitor Users
445 description: Members of this group have remote access to monitor this computer
447 whenCreated: ${LDAPTIME}
448 whenChanged: ${LDAPTIME}
451 name: Performance Monitor Users
452 objectGUID: ${NEWGUID}
453 objectSid: S-1-5-32-558
454 sAMAccountName: Performance Monitor Users
455 sAMAccountType: 0x20000000
456 systemFlags: 0x8c000000
457 groupType: 0x80000005
458 objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
459 isCriticalSystemObject: TRUE
461 dn: CN=Performance Log Users,CN=Builtin,${BASEDN}
464 cn: Performance Log Users
465 description: Members of this group have remote access to schedule logging of performance counters on this computer
467 whenCreated: ${LDAPTIME}
468 whenChanged: ${LDAPTIME}
471 name: Performance Log Users
472 objectGUID: ${NEWGUID}
473 objectSid: S-1-5-32-559
474 sAMAccountName: Performance Log Users
475 sAMAccountType: 0x20000000
476 systemFlags: 0x8c000000
477 groupType: 0x80000005
478 objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
479 isCriticalSystemObject: TRUE
481 dn: CN=${NETBIOSNAME},OU=Domain Controllers,${BASEDN}
484 objectClass: organizationalPerson
486 objectClass: computer
489 whenCreated: ${LDAPTIME}
490 whenChanged: ${LDAPTIME}
494 objectGUID: ${HOSTGUID}
495 userAccountControl: 532480
501 lastLogon: 127273269057298624
503 pwdLastSet: 127258826171655328
505 objectSid: ${DOMAINSID}-1000
506 accountExpires: 9223372036854775807
508 sAMAccountName: ${NETBIOSNAME}$
509 sAMAccountType: 805306369
510 operatingSystem: Samba
511 operatingSystemVersion: 4.0
512 dNSHostName: ${DNSNAME}
513 objectCategory: CN=Computer,CN=Schema,CN=Configuration,${BASEDN}
514 isCriticalSystemObject: TRUE
515 unicodePwd: ${RANDPASS}
516 servicePrincipalName: HOST/${DNSNAME}
517 servicePrincipalName: HOST/${NETBIOSNAME}
518 servicePrincipalName: CIFS/${DNSNAME}
519 servicePrincipalName: CIFS/${NETBIOSNAME}
520 servicePrincipalName: LDAP/${DNSNAME}
521 servicePrincipalName: LDAP/${NETBIOSNAME}
523 dn: CN=krbtgt,CN=Users,${BASEDN}
526 objectClass: organizationalPerson
529 description: Key Distribution Center Service Account
531 whenCreated: ${LDAPTIME}
532 whenChanged: ${LDAPTIME}
535 showInAdvancedViewOnly: TRUE
537 objectGUID: ${NEWGUID}
538 userAccountControl: 514
545 pwdLastSet: 127258826179466560
547 objectSid: ${DOMAINSID}-502
549 accountExpires: 9223372036854775807
551 sAMAccountName: krbtgt
552 sAMAccountType: 805306368
553 servicePrincipalName: kadmin/changepw
554 objectCategory: CN=Person,CN=Schema,CN=Configuration,${BASEDN}
555 isCriticalSystemObject: TRUE
556 unicodePwd: ${RANDPASS}
558 dn: CN=Domain Computers,CN=Users,${BASEDN}
562 description: All workstations and servers joined to the domain
564 whenCreated: ${LDAPTIME}
565 whenChanged: ${LDAPTIME}
568 name: Domain Computers
569 objectGUID: ${NEWGUID}
570 objectSid: ${DOMAINSID}-515
571 sAMAccountName: Domain Computers
572 sAMAccountType: 268435456
573 groupType: -2147483646
574 objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
575 isCriticalSystemObject: TRUE
577 dn: CN=Domain Controllers,CN=Users,${BASEDN}
580 cn: Domain Controllers
581 description: All domain controllers in the domain
583 whenCreated: ${LDAPTIME}
584 whenChanged: ${LDAPTIME}
587 name: Domain Controllers
588 objectGUID: ${NEWGUID}
589 objectSid: ${DOMAINSID}-516
591 sAMAccountName: Domain Controllers
592 sAMAccountType: 268435456
593 groupType: -2147483646
594 objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
595 isCriticalSystemObject: TRUE
597 dn: CN=Schema Admins,CN=Users,${BASEDN}
601 description: Designated administrators of the schema
602 member: CN=Administrator,CN=Users,${BASEDN}
604 whenCreated: ${LDAPTIME}
605 whenChanged: ${LDAPTIME}
609 objectGUID: ${NEWGUID}
610 objectSid: ${DOMAINSID}-518
612 sAMAccountName: Schema Admins
613 sAMAccountType: 268435456
614 groupType: -2147483646
615 objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
616 isCriticalSystemObject: TRUE
619 dn: CN=Enterprise Admins,CN=Users,${BASEDN}
622 cn: Enterprise Admins
623 description: Designated administrators of the enterprise
624 member: CN=Administrator,CN=Users,${BASEDN}
626 whenCreated: ${LDAPTIME}
627 whenChanged: ${LDAPTIME}
629 memberOf: CN=Administrators,CN=Builtin,${BASEDN}
631 name: Enterprise Admins
632 objectGUID: ${NEWGUID}
633 objectSid: ${DOMAINSID}-519
635 sAMAccountName: Enterprise Admins
636 sAMAccountType: 268435456
637 groupType: -2147483646
638 objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
639 isCriticalSystemObject: TRUE
642 dn: CN=Cert Publishers,CN=Users,${BASEDN}
646 description: Members of this group are permitted to publish certificates to the Active Directory
648 whenCreated: ${LDAPTIME}
649 whenChanged: ${LDAPTIME}
652 name: Cert Publishers
653 objectGUID: ${NEWGUID}
654 objectSid: ${DOMAINSID}-517
655 sAMAccountName: Cert Publishers
656 sAMAccountType: 0x20000000
657 groupType: -2147483644
658 objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
659 isCriticalSystemObject: TRUE
661 dn: CN=Domain Admins,CN=Users,${BASEDN}
665 description: Designated administrators of the domain
666 member: CN=Administrator,CN=Users,${BASEDN}
668 whenCreated: ${LDAPTIME}
669 whenChanged: ${LDAPTIME}
671 memberOf: CN=Administrators,CN=Builtin,${BASEDN}
674 objectGUID: ${NEWGUID}
675 objectSid: ${DOMAINSID}-512
677 sAMAccountName: Domain Admins
678 sAMAccountType: 268435456
679 groupType: -2147483646
680 objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
681 isCriticalSystemObject: TRUE
684 dn: CN=Domain Users,CN=Users,${BASEDN}
688 description: All domain users
690 whenCreated: ${LDAPTIME}
691 whenChanged: ${LDAPTIME}
693 memberOf: CN=Users,CN=Builtin,${BASEDN}
696 objectGUID: ${NEWGUID}
697 objectSid: ${DOMAINSID}-513
698 sAMAccountName: Domain Users
699 sAMAccountType: 268435456
700 groupType: -2147483646
701 objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
702 isCriticalSystemObject: TRUE
705 dn: CN=Domain Guests,CN=Users,${BASEDN}
709 description: All domain guests
711 whenCreated: ${LDAPTIME}
712 whenChanged: ${LDAPTIME}
714 memberOf: CN=Guests,CN=Builtin,${BASEDN}
717 objectGUID: ${NEWGUID}
718 objectSid: ${DOMAINSID}-514
719 sAMAccountName: Domain Guests
720 sAMAccountType: 268435456
721 groupType: -2147483646
722 objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
723 isCriticalSystemObject: TRUE
725 dn: CN=Group Policy Creator Owners,CN=Users,${BASEDN}
728 cn: Group Policy Creator Owners
729 description: Members in this group can modify group policy for the domain
730 member: CN=Administrator,CN=Users,${BASEDN}
732 whenCreated: ${LDAPTIME}
733 whenChanged: ${LDAPTIME}
736 name: Group Policy Creator Owners
737 objectGUID: ${NEWGUID}
738 objectSid: ${DOMAINSID}-520
739 sAMAccountName: Group Policy Creator Owners
740 sAMAccountType: 268435456
741 groupType: -2147483646
742 objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
743 isCriticalSystemObject: TRUE
746 dn: CN=RAS and IAS Servers,CN=Users,${BASEDN}
749 cn: RAS and IAS Servers
750 description: Servers in this group can access remote access properties of users
752 whenCreated: ${LDAPTIME}
753 whenChanged: ${LDAPTIME}
756 name: RAS and IAS Servers
757 objectGUID: ${NEWGUID}
758 objectSid: ${DOMAINSID}-553
759 sAMAccountName: RAS and IAS Servers
760 sAMAccountType: 0x20000000
761 groupType: -2147483644
762 objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
763 isCriticalSystemObject: TRUE
765 dn: CN=Server Operators,CN=Builtin,${BASEDN}
769 description: Members can administer domain servers
771 whenCreated: ${LDAPTIME}
772 whenChanged: ${LDAPTIME}
775 name: Server Operators
776 objectGUID: ${NEWGUID}
777 objectSid: S-1-5-32-549
779 sAMAccountName: Server Operators
780 sAMAccountType: 0x20000000
781 systemFlags: 0x8c000000
782 groupType: 0x80000005
783 objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
784 isCriticalSystemObject: TRUE
785 privilege: SeBackupPrivilege
786 privilege: SeSystemtimePrivilege
787 privilege: SeRemoteShutdownPrivilege
788 privilege: SeRestorePrivilege
789 privilege: SeShutdownPrivilege
790 privilege: SeInteractiveLogonRight
792 dn: CN=Account Operators,CN=Builtin,${BASEDN}
795 cn: Account Operators
796 description: Members can administer domain user and group accounts
798 whenCreated: ${LDAPTIME}
799 whenChanged: ${LDAPTIME}
802 name: Account Operators
803 objectGUID: ${NEWGUID}
804 objectSid: S-1-5-32-548
806 sAMAccountName: Account Operators
807 sAMAccountType: 0x20000000
808 systemFlags: 0x8c000000
809 groupType: 0x80000005
810 objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
811 isCriticalSystemObject: TRUE
812 privilege: SeInteractiveLogonRight
814 dn: CN=Templates,${BASEDN}
816 objectClass: container
818 description: Container for SAM account templates
820 whenCreated: ${LDAPTIME}
821 whenChanged: ${LDAPTIME}
824 showInAdvancedViewOnly: FALSE
826 objectGUID: ${NEWGUID}
827 systemFlags: 0x8c000000
828 objectCategory: CN=Container,CN=Schema,CN=Configuration,${BASEDN}
829 isCriticalSystemObject: TRUE
832 # note! the template users must not match normal searches. Be careful
833 # with what classes you put them in
836 dn: CN=TemplateUser,CN=Templates,${BASEDN}
839 objectClass: organizationalPerson
840 objectClass: Template
841 objectClass: userTemplate
845 userAccountControl: 0x202
856 sAMAccountType: 0x30000000
858 dn: CN=TemplateMemberServer,CN=Templates,${BASEDN}
860 objectClass: Template
861 objectClass: userTemplate
862 cn: TemplateMemberServer
863 name: TemplateMemberServer
865 userAccountControl: 0x1002
876 sAMAccountType: 0x30000001
878 dn: CN=TemplateDomainController,CN=Templates,${BASEDN}
880 objectClass: Template
881 objectClass: userTemplate
882 cn: TemplateDomainController
883 name: TemplateDomainController
885 userAccountControl: 0x2002
896 sAMAccountType: 0x30000001
898 dn: CN=TemplateGroup,CN=Templates,${BASEDN}
900 objectClass: Template
901 objectClass: groupTemplate
905 sAMAccountType: 0x10000000