Posts

Showing posts from September, 2010

Hyper-V replication fails for VMs on one host in a cluster

hi, have 2 sites hyper-v clusters 4 nodes in each cluster. replication has been configured site site b. replica broker in use. replication worked time, vms on 1 host in site not replicating. when these vms migrated other hosts in cluster replication resumed. migrating replicating vm other hosts host goes critical state. it not allow enable new vm replications well, fails kerberos authentication issues. error 0x00002efd one of host @ site b has following errors. event id 29212  hyper-v failed authenticate primary server using kerberos authentication. error: i/o operation has been aborted because of either thread exit or application request. (0x800703e3) i have done tests below url nltest, setspn, kilst , checked local policy accessing computer on network permissions. seems fine. http://blogs.technet.com/b/davguents_blog/archive/2013/02/07/the-case-of-the-unexplained-windows-server-2012-replica-kerberos-errors-0x8009030c-0x00002efe.aspx hi satkare, >> now vms

ldifde of other domain(no trust) is usable if there is one user account and ldap port is open ?

ldifde of other domain(which has no trust) usable if there 1 user account/passowrd of domain , ldap port(389) open ? using ldifde import , export directory objects active directory http://support.microsoft.com/kb/237677 ldifde - export / import data active directory - ldifde commands http://support.microsoft.com/kb/555636 http://support.microsoft.com/kb/555634 ldifde not import users trusted domains http://support.microsoft.com/kb/279259 this linke describes how use ldifde bulk operations: http://technet.microsoft.com/en-us/library/bb727091.aspx hope helps best regards, sandesh dubey. mcse|mcsa:messaging|mcts|mcitp:enterprise adminitrator | blog disclaimer: posting provided "as is" no warranties or guarantees , , confers no rights. Windows Server  >  Dire

Server 2003 critical updates

hi know how long critical updates available server 2003? untill 2014? thanks hi there, i suggest , please use below link know product lifecycle http://support.microsoft.com/gp/lifeselect http://support.microsoft.com/lifecycle/?ln=en-gb&c2=1173 afaik windows xp support cycle extended upto 2014 windows server 2003 + latest service packs in mainstream support through 2008 , in extended support until 2013 sainath !analyze Windows Server  >  Windows Server General Forum

LUN limit with iSCSI (2012 R2)

hi. asked similar question before, , not looking lecture on best practice (although happy discuss architecture if people curious), have use case want address lots of iscsi luns on 2012 r2 machine. seem have hit limit of 255 mounted iscsi volumes. of documentation seems suggests limit per 'target', i'm bit unsure target means in context. possible mount more luns somehow? 'target' mean ip address , port? can have 255+ luns on 1 network card\hba if use multiple ip addresses (same) target. thanks much!  hi. asked similar question before, , not looking lecture on best practice (although happy discuss architecture if people curious), have use case want address lots of iscsi luns on 2012 r2 machine. seem have hit limit of 255 mounted iscsi volumes. of documentation seems suggests limit per 'target', i'm bit unsure target means in context. possible mount more luns somehow? 'target' mean ip address , port? can have 255+ luns on 1 network car

User32 ..EVENTID 1074 winlogon initiated restart of server

one of server hosting hub , client access having restart on everyday 7 am. event viewer details follows:- please send me reason kind of restart. need avoid restart exchange down , sometime restart not proper , cannot rdp server pinging fine server ip.   event type:        information event source:     user32 event category: none event id:           1074 date:                 11/24/2011 time:                 7:00:00 am user:                 ntdomain\administrator computer:          exchhtca description: the process winlogon.exe has initiated restart of computer exchhtca on behalf of user ntdomain\administrator following reason: no title reason found   reason code: 0x840000ff   shutdown type: restart   comment: for more information, see , support center @ http://go.microsoft.com/fwlink/events.asp. data: 0000: ff 00 00 84                ÿ.. „     the restart being initiated ntdomain\administrator account credentials. security log may p

Send to mail icon missing terminal server

hello when users right click on doc , click send - mail option missing. checked roaming profile user , there. missing compress folder, again there in app roaming ms folder. why missing user(s). thanks hi, what has been changed since first happened?is there the possibility system got virus or application incompatibility? pls try restore system status previous using storage facility things see whether works. as last resort, may need to reinstall the server scratch. best regards, clarence please remember click “mark answer” on post helps you, , click “unmark answer” if marked post not answer question. can beneficial other community members reading thread. Windows Server  >  Remote Desktop Services (Terminal Services)

macros

i working student home version of word 2007.  want add macros.  spot asks keystrokes macro , computer not acknowledge keystrokes , therefore won't permit me go further ie assign   ideas??? hi, could describe question more detail? like in spot did ask keystrokes ? and keystrokes did enter? have tried input other keystrokes? none of them recognized?   you may want see this? record or run macro http://office.microsoft.com/en-us/word-help/record-or-run-a-macro-ha010099769.aspx?ctt=1   sincerely, max meng forum support come , mark replies answers if , unmark them if provide no help. Microsoft Office  >  Word IT Pro Discussions

Can not use printer Sharing while on Active Directory?

okay, i do desktop support university has of their pc's  on active directory domain , of pc's running windows xp, a user asked me attach usb printer pc just to share with other pc's in the office... simple right? so did , printer sharing  worked fine, works fine if turn firewall off host pc attached printer or if take pc off of active directory. then if i put the host pc on active directory or turn firewall on can not share printer. checked exception within firewall make sure tcp 139 port there , is, talked with the  it department of university , don't know  what tell me. i'm coming guys, if is  active directory that is causing someone's expertise on issue please!! im desktop support guy don't know active directory.   thank you duplicate post?  http://social.technet.microsoft.com/forums/en-us/winserverds/thread/6cf83886-b358-46d7-a1b6-a2d5bbde416f   santhosh sivarajan | mcts, mcse (w2k3/w2k/nt4), mcsa (w2k3/w2k/msg), ccna, network+ ho

Enabling RDP for Standalone Server 2012 Install

Image
hi all, i'm trying enable rdp our standalone server 2012 install (which going use internal administrative access our 3 support staff (for management of ad, dns, dhcp etc.)) can't seem figure out doing wrong. server trying enable rdp on our domain controller. i've followed advice of few people on here install rd connection broker , rd session host, both installs failed. own 10 server 2012 cals , have configured them using licensing manager, when try connect machine error 'the remote session disconnected because there no remote desktop license servers available provide license'. suggestions? thanks, chris hi chris, according official document, never recommended, allowed install domain controllers , remote desktop services role services until windows server 2012. windows server 2012, configuration no longer supported. http://support.microsoft.com/kb/2799605/en-us niki han technet community support

Stop: c00002e2 Directory Services Could not Start

buen dìa expertos. tengo un servidor hyper-v 2008 r2 donde tengo mi maquina virtual de dominio con un disco con el s.o. sbs2008.vhd, despues de un reinicio inesperado del servidor hyper-v, cuando decido reiniciar mi maquina virtual no arranca, aparece el siguiente error stop: c00002e2 directory services could not start because following error: uno de los dispositivos vinculados al sistema no funciona. error status: 0xc0000001. please shutdown system , reboot directory service restore mode. ck event log more detalled information. se que no es problem del hyper-v pues tengo otras maquinas virtuales y estas si funcionan, no se cual pudo ser la raiz del problema de mi sbs2008, gracias de antemano po su ayuda... hola, probablemente hayas tenido algun problema con algunos de los archivos criticos de active directory o con alguno de los discos virtuales asociados esa maquina virtual, quizas "el apagon"  pudo corromper la base de datos de ad. revisa este documento que t

Using a variable for $db.SetOwner

does know how can use variable this? $owner = "someowner" $srv = new-object microsoft.sqlserver.management.smo.server($destinationinstance) $db = new-object microsoft.sqlserver.management.smo.database $db = $srv.databases.item($sourcedbname) $db.setowner($owner, $true) gives me errors when try above. if use $db.setowner('sa', $true) works need hold variable. system.argumentexception: login 'microsoft.powershell.commands.internal.format.formatstartdata microsoft.powershell.commands.internal.format.groupstartdata microsoft.powershell.commands.internal.format.formatentrydata microsoft.powershell.commands.internal.format.groupenddata microsoft.powershell.commands.internal.format.formatenddata' this error message indicates $owner variable contains format object not simple string. format objects procuced after pipelining data through format-table cmdlet. assigning such objects string variable produces default behaviour, ie, type of object

Azure Active Directory or Win2012 AD

hey everyone. we small business company planing deploy active directory, can centralized our network resources , provide advanced security our network(and prepare future migration exchange , may sharepoint). understand benefits of using windows server 2012 . see azure provide active directory decent price, looking on web few days far , placed trial azure see how works me, dont of that. azure capable of providing network resources , group policy's ordinary ad ? have spend anymore time understanding idea of azure, because not find simple documentation or video explaining things concerning me. on premises domain controllers required if want deploy local exchange , sharepoint things deploy group policy. azure ad not let join computers domain or of functionality looking here. azure ad beneficial if plan deploy resources both on premises , in azure, or if choose utilize services office 365 instead of exchange. http://windowsitpro.com/azure/azure-active-directory-vs-p

question about using secedit.exe to apply password policy

hello, i'm using secedit.exe apply password policy part of unattended installation of server 2008... secedit command runs part of script after os image applied. (i aware of scw afaik secedit fine this) command is: secedit /configure /db c:\passpol.sdb /cfg c:\passpol.inf /log secedit.log question is: basically, passpol.inf security template file copied network share c:\passpol.inf on local server. secedit command run. creates passpol.sdb file. after command completes can delete c:\passpol.sdb , c:\passpol.inf? or continued used? assume if continued used should not have them right on root of c:... if case, should put them them? in advance help. you don't need keep template on computer unless think may need apply again later on. security templates write values registry , sam. if wish keep it, default location security databases , templates %userprofile%\documents\security. way stored in personal profile.

Akamai NetSession and Program in Startup menu

hi have 2 apps i'm not familiar in startup menu akamai netsession client (2) akamai technologies inc. program (no publisher motioned)  is akamai required windows 10 updates or installed other download? what should make of app named program no publisher? upgraded windows 7 ultimate resolved... akamai apparently third party install (i removed it) the app named program, leftovers uninstalled application (i able detect winpatrol). Windows 10 Insider Preview  >  Windows 10 Insider Preview General

Inexperienced IT manager needs help with basic setup of AD without MS Exchange

hi there, trying wrap head around setting active directory. current situation is: windows server 2003 on our "server", file , print server.  no web serving or on it. 13-15 client computers, running win xp pro. set works, server has few shared folders on it, , on each client folders attached network drives.  each workstation has individual "account", named person sits @ desk, getting tired of micro-managing each box, , when moves different position, or people leave , replaced, have re-do accounts on affected box , such... wish implement active directory on server, , allow alot of micro-management designed do. have no idea how implement it!  can walk me through, or point me walkthrough, on setting basic implementation of active directory in environment stated above, (keeping in mind ms exchange not part of this; use individual installs of outlook , respective .pst files on each workstation)?!?  please? input can give me! setting active directory easy

BSOD in VM

i've got hyperv 2012 system several vm's.  one of vm's has thrown bsod couple of times in last month , wondering if procedure figuring out cause little different under hyperv. the bsod i'm getting memory management bugcheck 1a.  the crash dumps don't show "smoking guns": 050815-12437-01.dmp 2015-05-08 9:47:02 memory_management 0x0000001a 00000000`00005003 fffff700`01080000 00000000`00001810 00000000`00000000 ntoskrnl.exe ntoskrnl.exe+72a40 nt kernel & system microsoft® windows® operating system microsoft corporation 6.1.7601.18798 (win7sp1_gdr.150316-1654) x64 ntoskrnl.exe+72a40 c:\windows\minidump\050815-12437-01.dmp 4 15 7601 286,248 2015-05-08 9:48:47 042115-12906-01.dmp 2015-04-21 12:16:16 pm memory_management 0x0000001a 00000000`00003452 00000000`7efb1000 fffff700`010804e0 000000ab`00000000 fltmgr.sys fltmgr.sys+42ec microsoft filesystem filter manager microsof

3 DCs in a domain?

i thinking how best patch servers (and specifically, dcs) , mentioned how have 3 dcs in domain - 1 of "dev dc" (ie testbed patches before rolling out other 2 dcs). fyi, abide best practises such not running auto updates etc on servers. is 3 dcs in domain idea? guess holds no fsmo roles? also, need dns on it? 3 crowd say. also, happen if 2 dcs (which specified in dns settings of member servers) go down? dc able keep things up? thanks is 3 dcs in domain idea? minimum recommendation 2, 3 better.  might not need 3 won't hurt you. also, need dns on it? if running ad integratated dns recommend runs well.  recommend running global catalog.  having dc's gc's idea. also, happen if 2 dcs (which specified in dns settings of member servers) go down? dc able keep things up? dc able handle load, couldn't tell sure since didn't list load model.  rule of thumb quality dc 4 gb ram, etc... can handle 5000 users domain.  guess small shop , load pl

How to authenticate the users login a non-domian pc by NPS as radius server?

i want deploy  test env, windows server nps radius server, , when users login non-domain pc access internet, users firstly should authenticated radius server. authenticate successfully, users can browse internet. so, question how using radius user login non-domian pc , otherwise authentication fail due login user mismatched users stored in radius server. thanks attention , forward suggestion or ideas. hi, based on research, can use certificates authenticate non-domain computers, please refer article more detailed information: certificates , nps http://technet.microsoft.com/en-us/library/cc772401(v=ws.10).aspx if have further requirements nps, please refer forum below professional support: network access protection forum http://social.technet.microsoft.com/forums/windowsserver/en-us/home?forum=winservernap best regards, amy Windows Server  

mapped drive dissappears

mapped drive form login script randomly not connect login. this sporadic.  ocmputer name , share different domain controller i don;t know if name resolutioni issue or what.  works 95% of time.  use net use in script.  if exist v:\nul net use v: /delete net use v: \\servername\share it can fail , can log out , log in again , works?         hi, posting here.   try modifying script remove mapped connection first , remap see how going:   net use * /delete /yes net use v: \\servername.<domainname>\share   how authentication works net use command http://support.microsoft.com/kb/149861   thanks.   tiger li please remember click “mark answer” on post helps you, , click “unmark answer” if marked post not answer question. can beneficial other community members reading thread. Windows Server  

Power shell script with options

i'm trying teach myself powershell , thought i'd start out little script change ip addresses options menu powershell. can't figure out how though take input, example 1, 2 or 3 , have corresponds input, example change ip address address specified. can give me pointers go or how proceed this? many thanks, peter with following small script can ask ip address , validate it: function validateip ($ipaddress) { $pattern = "^(([0-9]|[1-9][0-9]|1[0-9]{2}|2[0-4][0-9]|25[0-5])\.){3}([0-9]|[1-9][0-9]|1[0-9]{2}|2[0-4][0-9]|25[0-5])$"; if ( $ipaddress -match $pattern) { return $true } else { return $false } } $ip = read-host "insert ip-address: " validateip $ip save under meaningful name , start dotsourcing (". <fullnameofyourscript>; can leave path out, if script stored in directory listed in environment path variable). kind regards, wizend

Powershell Script for Activedirectory Dashboard

hi, does have power shell script can create activedirectory dashboard(eg: replication details/tru st status/net logon errors\health check\cpu & memory utilization etc) , notify via email once report ready ? i have requested script in script center  around month before , have not got response yet. appreciate can provide if want in 1 script, need make 1 combining multiple ad objectives server admin objectives, plus asking quite bit ad admin.  , jrv stated, try create , learn quite bit.  then once become manager, purchase 3rd party solution (sorry not resist).  knowing how things work in detail great. one tool can @ replication items ad replication status tool (by microsoft) some powershell starters: get-adforest domains get-addomaincontroller dc's then foreach dc's , grab information want. domain controller information:  foreach ($dc in $dcs) { write-host $dc.operatingsystem}  .......... performance data cpu/memory dive registry dsa database file

netstat reports over 2000 UDP ports listening

when use netstat -a on win 2k3 server standard edition 32 bit set backup domain controller 1 of our private subnets, reports usual tcp , udp ports plus over 2000 udp ports 49153 65533 listening.  any suggestions may be responsible appreciated.  server has mssql 2k , symantec endpoint protection running on it. is dns server? see http://technet.microsoft.com/en-us/library/ee649174(ws.10).aspx  and http://support.microsoft.com/default.aspx/kb/956188 after install security update 953230 on windows server 2003 , down-level platforms, following conditions true: if value of maxuserport registry entry set, ports allocated randomly [1024, maxuserport] range. if value of maxuserport registry entry not set, the ports allocated randomly [49152, 65535] range . -greg Windows Server  >  Network Access Prot

Login Problems

i have windows 2003 domain.  have vista computer when logging domain trust relationship between workstation , domain has failed.  not able disjoin domain , rejoin back.  how can fix issue?  there command can run? gerald hello gerald, you can use netdom.exe reset machine account on windows vista box domain. please refer to: how use netdom.exe reset machine account passwords of windows server 2003 domain controller http://support.microsoft.com/kb/325850 as mentioned, cannot disjon domain, please check verify dns setting on nic of client pointed internal dns server properly. besides, when try disjoin vista box, diaglox pop let input credential? thanks. this posting provided "as is" no warranties, , confers no rights. Windows Server  >  Windows Server General Forum

Connecting XP to server 2008 (not R2) using RDP broken after KB969084 update installed.

we updated our xp sp3 clients remote desktop version 6.1.7600 support rdp 7.0.  i'm not 100% list kb in subject broke it, seems logical choice updates installed yesterday. connections server 2003 , server 2008 r2 xp sp3 work fine, server 2008 sp2 on them seem refuse connection error: connection has been terminated because unexpected server authentication certificate received remote computer. systems received ssl certificate our dc trusted. i'm not sure if 2008 server refusing allow or xp sp3 client. found kb article http://support.microsoft.com/kb/951608/ references credssp enabled on xp sp3 systems. appreciate lost @ point. hi everyone, worked on offline, , fix was: removed server of gpos had set, resulted in believe true error: ca cert not in trusted root store. imported ca cert xp trusted root store...now works. (nferguson, if minute, can post gpos removed? ) hope helps, kristin l. griffin co-author of windows server 2008 terminal services resourc

Windows server 2012 deduplication

hi, i'd grateful if provide definitive answer this, frankly it's driving me loopy. have 2 x server 2012 ( not r2 ) servers. 1 physical full gui. other hyper-v guest, server core, guest running off 1 chunk of san storage and a cifs share scsi attached .vhdx on chunk of san storage. both have dedupe turned on. gui server has stats related dedupe, , backups our backupexec agent. core (virtual) server... doesn't have stats. did 10gb freed up, down 0. every time tries run both servers had fs-fileserver, fs-data-deduplication , fs-resource-manager roles installed. physical box had fs-vss-agent installed. core has role installed. the core box never runs dedupjob without complaining doesn't have enough ram (which rubbish, 'cos it's server core box 4gb ram- identical physical box). a remote explorer session also mis-reports on terabyte of data stored in few gb on disk (i remote explorer, because the remote storage tools know there's 5.1tb of 6tb disk ta

Shoow Copies

hai expertise, i configure shadow copy, base on step step provide microsoft, problem is, make copies each folder inside volume, didn't care it's share folder or not ,based on understand shadows copies work on shared folder only...need assistance expertise here configure shadow copies share folder only.. or if have other link can resolve problem please redirect me link, co-operation appreciated. thank you..     hi, shadow copied of shared folder can turn off/on @ volume based. cannot enable specific folder. used developer of vss writer or application choose exclude files shadow copies. more information, refer articles below: shadow copies of shared folders http://technet.microsoft.com/en-us/library/cc771305.aspx excluding files shadow copies http://msdn.microsoft.com/en-us/library/aa819132(vs.85).aspx regards, we trying better understand customer views on social support experience, participation in interview project appreciated i

Powershell FSRM command action not working

this 2 issue subject i trying create fsrm screen command action it's not firing , no events logged except event log event have in screen. @ point i'm not sure how troubleshoot this. in attempt troubleshoot , because need ot able create screen via powershell decided use example powershell action , add screen erroring out the example new-fsrmaction command -command "c:\windows\system32\cmd.exe"-commandparameters "echo [source file path] >> c:\log.txt" -shouldlogerror this works, create screen doing following fails new-fsrmfilescreen -path "$drive" -active: $false -includegroup "blarg1" -notification $notification new-fsrmfilescreen : 0x80070057, parameter incorrect , gives below error @ line:1 char:5 +     new-fsrmfilescreen -path "$drive" -active: $false -includegroup "blarg1" -no ... + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~     + categoryinfo     

NTFS compression and SYSVOL

i ran across i've never seen before: in 1800 user ws2003 domain, files in sysvol ntfs-compressed. did googling , didn't find practice...but maybe that's because wouldn't occur people try it! i'd have believe it's not best practice, supported practice? documented anywhere? hello, it not recommended compress active directory related files , folders, database files. which kind of files compresses ones, can add screenshot windows sky drive? best regards meinolf weber disclaimer: posting provided "as is" no warranties or guarantees , , confers no rights. Windows Server  >  Directory Services

DNS question

my company has 2 dns servers on network redundancy. had issues, making changes , noticed strange: soa reverting after make changes , log out. server1 main, , server2 secondary. soa files on server2 keep pointing itself. shouldn't soa same on both servers, or misunderstanding something? no - active directory integrated zones soa should point each dc self. in active directory world each dns server writable, except rodcs dns not point soa them self. so seeing correct , expected behavior enfo zipper christoffer andersson – principal advisor http://blogs.chrisse.se - directory services blog Windows Server  >  Directory Services

Unable to copy VHD

hello, i running hyper-v on windows server 2012. trying copy vhd file hyper-v host, however, vhd not copy. i've tried following options: used windows explorer manually copy vhd (fails 50% of way) used windows explorer manually copy vhd hyper-v services off used hyper-v export vhd (incorrect function error) used powershell copy vhd used powershell copy vhd hyper-v services off used vmm migrate virtual machine host all of these options failed, multiple times varying non-descriptive messages. the virtual machine works fine on host (turns on, functions normal). any appreciated. hi hhancock, i not think copy fails due to  occupation  by vm (cause of copied vhdx file of running vm folder ). i assuming shut down vm , stoped hyper-v vmm service but still can not copy vhd file of vm. my suggestion backup host , vms try run chkdsk check disk . hope helps best regards elton ji if not answer please unmark continue we trying better understand customer views o

Delegate sharing rights to a normal user in active directory

hi, i want assign sharing rights normal user i.e. normal user can share folders on dataserver member active directory server windows 2003. how can delegate sharing righs in windows 2003 active directory. kindly help. here go - http://social.technet.microsoft.com/forums/en-us/itcg/thread/cafb1d0c-7f6e-405f-be47-1c15e536c7e8 incorporate script app (e.g. web app) running in security context of account admin privileges target server , restrict access app users permitted to create shares... hth marcin Windows Server  >  Directory Services

dcpromo fails

having installed sbs 2008 server our windows server 2003 forest, try run dcpromo on new server. i error: ad wizard fails: >>the operation failed because: active directory domain services not install. "the replication operation failed allocate memory."<< so dcpromo rerun using install-from-media option. failed. >>the operation failed because: an unknown error occurred while installing active directory domain services. "an error occurred while installing directory service. more information, see event log." you need restore active directory domain services backup files again , restart wizard in order attempt operation again.<< the event log shows: >>the install-from-media promotion of dc cannot start because os version (0.0) of source database not match os version (6.0) of local computer. eventid 2869<< this eventid not documented microsoft nor can find reference anywhere. i please know how run dcpro

Mac RD Client extremely slow printing with PDF files

have installed new version 8 of microsoft remote desktop on macbook pro.  runs fun in general.  when printing out of applications, works fine. but, when printing stand-alone pdf or image file, literally takes hour transfer print file session local printer.  anyone else having problem? hi, based on research, in order printer redirection work properly, client needs have .net framework 3.0 or above work properly, mac not have. by default when connect windows server rds, tries use rds easy print function first. local drivers used server passing print commands directly client; requires .net framework 3.0. on windows side solves lot of headaches printers, won't on mac side. when easy print fails (as on macs), server tries find drivers in local database , try use print. therefore, i'd recommend install necessary print drivers onto server , test issue again. hope helps. we trying better understand customer views on social support experience, participation in

Windows Server Healthcheck

we have got audit number of windows 2008 servers critical controls, albeit not specific security (although undoubtedly there in top 15). database or file servers. audit more risk assessment/healthccheck, not audit can access in traditional sense of word. i trying identify top 10-15 critical controls list servers can as possible in time available. patching, weak password identification etc 2 obvious security ones, don’t want purely focus on security settings. the objective ensure servers have optimum availability, security/confidentiality, integrity, alignment vital controls , best practice. top 15 checks in expert opinion, i.e. important/vital. rather feedback rather being pointed guide. hiya, first of all, said, no guides - microsoft has provided tools scan of system on different levels, giving reports state areas needs attention based on own best practice. - quite useful in situation 1 describe. (attack surface analyzer, microsoft security assessment tool, r

Help needed AD Sites design: remote sites link only to centre (bridge links etc)

i have hub , spoke network central site has vpn links various satellite sites. i.e. satellite sites have ip connectivity central site: satellites can ping centre, not each other. i have created ip site links between centre , each satellite site. @ first left “bridge site links” option box ticked on “ip” node ad sites & services, following problems have un-ticked option box , have created manual site link bridge contains site links satellite sites. my understanding link bridge allows site @ centre bridge links satellite sites not have direct ip connection (i correct?) if run repadmin /kcc against various dc’s or sites “consistency check on x successful” however dc in satellite site have in event log events   1311, 1865 & 1566 in respect dc in satellite site b. log on dc in site b shows no problems. any advice on how have set sites & services topology?  r  in topology described - central hub spokes none of branch locations have direct connectivity each other

Report on OU Delegations?

hi, over years people have delegated various permissions on ous - of ways export delegations (perhaps human readable format?). running windows 2008 r2 dcs. thanks, sk below link might helpful, http://social.technet.microsoft.com/wiki/contents/articles/6477.how-to-view-or-delete-active-directory-delegated-permissions.aspx regards, gopi jiji technologies Windows Server  >  Directory Services

How to set a app Pool using Powershell script

hi, how set app pool using powershell script thanks, nag http://learn.iis.net/page.aspx/433/powershell-snap-in-creating-web-sites-web-applications-virtual-directories-and-application-pools/ http://learn.iis.net/page.aspx/434/powershell-snap-in-making-simple-configuration-changes-to-web-sites-and-application-pools/ Windows Server  >  Windows PowerShell

tcp/ip printer via gpp

server 2008 client xpsp3 ie8 service packed up printer hp4650c can deploy using shared printer discussed here http://social.technet.microsoft.com/forums/en-us/winservergp/thread/2b2007f5-e2c0-4d5c-adb1-24f54cce5eba/ install independant of shared printer (mainly due shared printer causing default page size default letter) following link instructions , setting printer path ip address causes error on client - printer name invalid (tried http:\\x.x.x.x , x.x.x.x) driver installed on client suggestions ? for tcp/ip printers need define the "printer path" has point shared printer of same type. this needed have installation source driver (even if theneeded driver installed locally) and - personal theory - need have pointer printer model itself. how should client , gpp cse know which model of printer you'd install? by pointing shared printer mapping done. according experience needed during printer installation time , there no dependency later. but of course if new c

Windows Server 2012 R2 periodically unreachable yet services still available

hello, our shop installed dozen winserver 2012 r2 servers couple weeks ago. week, have notices odd behaviors reported our networking monitoring tool (solarwinds). @ random times of day, servers icmp unreachable. aside looking @ mt solarwinds console, try manually ping these servers , confirm cannot. yet, example, our "home drive" file server supposedly looses connectivity, yet still mapped , able browse documents; same goes desktops items. there 1 occasion did loose our resources (home drive, desktop) when happened. the weird issue connectivity restored after 4-7 minutes. during outage time, cannot ping or rdp servers. we have looked @ event logs , hbss logs , nothing far reveals error caused issue. also, not happen @ same time, they're "unreachable" 1 or 2 @ time. this stumping me, advice appreciated. are pinging name or address? ' destination host unreachable' have couple different meanings. this message indicates 1 of 2 problems

Difficulty with Windows Shares in Server 2008 and in serious need of help

we're small company without dedicated sysadmin.  being developers can figure out how things done. i have windows 2008 server (web edition), brand new, on public internet.  trying setup shared folder encryption folks in office have shared location, looks other shared windows drive, backup important documents, non technical (admin/support) staff.  have no servers in office, in data center lease space. background helpful suggestions don't address problem (i'm 1 of people) sure pay sme storage or that, paying 3 servers (2 linux & one) don't want spend money!  web servers have huge amount of free space anyway. before bought windows server, tried in van in make webdav publishing work on linux windows 7, it's hopeless unless moving 20k notepad files.  tried samba, same results, doesn't talk windows 7.  of course our debian desktops happily talk our web servers day without hitch.  tried teaching our admin folks ftp, equally hopeless.  norton 360 has nice

Print Server Migration from 2003 SP2 to Server 2008 R2 SP1

i am setting print server on 2008 r2 sp1 , want export/import printer, queues, ports, etc current 2003 sp2 print server.  how do this? hi,   this document provides step-by-step instructions migrating print server running windows server 2003 server running windows server 2008 r2 print , document services role installed.   print services migration guide http://technet.microsoft.com/en-us/library/dd379488(ws.10).aspx   hope helps.   regards, bruce Windows Server  >  Print/Fax

Disconnected terminal services sessions

hi all, there way disconnect user sessions have been idle long period of time, longer 5 hours?  there dozen or on our server , eat valuable resources.  im assuming theres group policy setting somewhere specifies this? thanks, rhys. hi rhys, there several different ways of doing this. common through group policy. in group policy linked terminal servers have find setting: computer configuration > policies > windows components > terminal server > session time limits > set time limit disconnected sessions (once have done not forget rum gpupdate /force) 1 more way set limits in the: terminal services configuration > double click rdp-tcp > sessions tab way set limits in properties of particular user's account in aduc. сила в справедливости Windows Server  >  R

Prevent internal Ldap Queries

what best method prevent internal domain users (non administrators) query ad info. running powershell or other queries against active directory domain joined computer non administrative user must blocked. thank you, darshan active directory not supposed host confidential data such restrictions not required. you can tweak security permissions on ous , containers can revoke read permission non-admin users. however, need careful not impact ad-based applications when changing acls. you can give more details: http://windowsitpro.com/active-directory/hiding-data-active-directory this posting provided "as is" no warranties or guarantees , , confers no rights. get active directory user last logon create active directory test domain similar production one management of test accounts in active directory production domain - part i management of test accounts in active directory production domain - part ii management of test accounts in active directory

DSC Pull Server WMF 5 - node cant pull configuration or dscresource

hi i have think working pull server on ms server 2012r2 wmf 5 installed. node  is running ms server 2012r2 wmf 5. can access pull server's site (xml) without issues on both pull server (vm01) , node (vm08) want pull configurations. setup based on the https://msdn.microsoft.com/en-us/powershell/dsc/pullserver : pull server: $configurationdata = @{ allnodes = @( @{ nodename="*" psdscallowplaintextpassword=$true psdscallowdomainuser = $true } @{ nodename='localhost' } ) } #https://msdn.microsoft.com/en-us/powershell/dsc/pullserver configuration deploydscpullserver { param ( [string[]]$nodename = 'present', [validatenotnullorempty()] [string] $certificatethumbprint, [parameter(mandatory)] [validatenotnullorempty()] [string] $registrationkey ) import-dscresource -modulenam

Created Local User on Windows 2003 SP2 server, gave user local administrator rights

Image
i have user needs admin rights on windows 2003 server. server on windows 2008 ad network. when login locally on box administrator not want them able terminal server or remote else. how block in local security policy settings? hi, i confirm current situation? have resolved problem? if there can you, please not hesitate let know, , happy help. lawrence technet community support Windows Server  >  Management

Hyper-V live migration failed with error 0x8009030E

i have 3 servers. server - windows 2012 data center hyper-v role server b - hyper-v 2012 server server c - windows 2012 data center smb server all servers in same domain windows 2003 domain controller. both server , b configured delegation each other following instructions step step this page http://technet.microsoft.com/en-us/library/jj134199.aspx (configure , use live migration on non-clustered virtual machines). account member of domain admins , added local administators groups on both servers. when tried to move a virtual machine from server server b, got following error. ----------------------------------------------------------- virtual machine migration operation failed @ migration source. failed establish connection host 'serverb': no credentials available in security package (0x8009030e). the virtual machine management service failed authenticate connection virtual machine migration @ source host: no suitable credentials available. make sure opera