Posts

Showing posts from June, 2014

Reverse Zone Lookup

the company have 2 sites. 1 in ny and 1 in dallas. ny site has 2 dcs. dallas site has 1 dc. when nslookup getting server unknown error. @ "reverse zone lookup" , setup ny only. ny ip address 192.168.100.x , dallas ip 192.168.103.x. can create new zone in dns dallas. can ping hosts in dallas ny when nslookup says unknown server. trying install application telling me cannot find server. i think need make ptr record of dns servers in reverse zone, should fix nslookup problem. this should provide guidance. Windows Server  >  Network Infrastructure Servers

UPN Suffix Routing using Wildcards

situation: we have 2 forests (a & b) with forest trust. in 1 forest (a) create accounts external users. other forest (b) contains sharepoint resources. goal: the goal users of forest (a) can logon into and connect sharepoint resources inf using upn equal own mail address. as have lot of different external users, have virtually unlimited number of upn suffixes. how can suffix routing work unlimited number of upn suffixes? users can logon using own mail address instead of using domainname\samaccount tend forget. cheers, frank. kind regards, frank van rijt hi frank,   in case, may consider using forms authentication:   forms authentication in sharepoint products , technologies (part 1): introduction http://msdn.microsoft.com/en-us/library/bb975136.aspx Windows Server  >  Directory Servic

Publish Desktop as Application

hi, we testing windows server 2008 r2 rds 3 servers. server - rds gateway & rds webapp server b & c - rd session host server how publish desktop remote app? when users execute remote app presented desktop we tested trial version of 2x application server terminal services in win 2003 r2 , works. thank you naveen is terminal server 1 want to? if so, making desktop connection available in rd web access checking box: show remote desktop connection rd session host server in rd web access (on rd session host server tab in remoteapp manager properties)? hope helps, kristin l. griffin co-author of windows server 2008 terminal services resource kit (and super big fan of microsoft rdv team!!!)  rds blog: blog.kristinlgriffin.com Windows Server  >  Remote Desktop Ser

powershell command

Image
0 hello all, this photo add command.. , did 1 user $photo = [byte[]](get-content " c:\users\xxx\desktop\1.jpg" -encoding byte) set-aduser ntid -replace @{thumbnailphoto=$photo}, but want remove photo couldn't find command please me in this . thanks amit hello amit, i can't test here, setting value predefined value $null (nothing) should work: set-aduser ntid -replace @{thumbnailphoto =$null } olaf helper * cogito ergo sum * errare humanum est * quote erat demonstrandum * wenn ich denke, ist das ein fehler und das beweise ich täglich blog xing Windows Server  >  Windows PowerShell

Removed Software GPO incorrectly, PCs still try to install a non existent GPO

hi, i have software installation gpo installed a piece of software (obviously) , removed destination .msi , deleted gpo! little did know there way properly. the issue experiencing pcs gpo applied (even though it's removed group policy management) still tries install on login (except file doesn't exist , cannot install anything, tries anyway saying cannot find file). i don't know how remove group policy applying. set install user policy (meaning installs after login instead of computer start up). what have tried recreate policy exact file path , file name , try uinstall software via right click package in gpo > tasks.. > remove > uninstall pcs. unfortunately has not worked out , need remove our pcs prompting users every time log in! any appreciated :) thanks   > issue experiencing pcs gpo applied > (even though it's removed group policy management) still tries > install on login (except file doesn't exist , cannot >

Executables on network share / Windows 2008 R2

hi ! picture this: - windows 2008 r2 server (call him srv1) network share called "file_share$" - native application .exe on share (call test.exe) - application can reached under \\srv1\file_share$\test.exe - windows 2008 r2 server (call him srv2) enabled remote desktop services. now users on srv2 accesses \\srv1\file_share$\test.exe . a new version of test.exe installed \\srv1\file_share$\test.exe . works if test.exe not longer accessed process. administrator tells user quit application. but some users has disconnected there sessions , had not quit application. administrator closes open file sessions on srv1. able copy new test.exe on share. and magic: if user reconnects there rdp sessions, old application still running. if user startes application on srv2 \\srv1\file_share$\test.exe ,  not new test.exe srv1, open cached old version on srv2. if take on opened files on srv1 not see acces test.exe. in windows 2003 closing file session end

Removal of DFS

we migrating new domain infrastructure , know best method/process remove dfs our old environment.    dfs (namespace) servers windows 2008. thanks in advanced.   remove nodes , final step remove dfs-root. wait ad replicate (depends on schedule, 45 mins default think) , should gone. can verify looking @ "dc=yourdomain, cn=system, cn=dfs-configuration" adsi-edit, key holds dfs-config. best regards joachim nässlander senior solution architect microsoft infrastructure , end user computing dell ab, sweden mvp cluster member of microsoft extended experts team (meet) blog: http://www.nullsession.com Windows Server  >  File Services and Storage

Windows Server 2008 R2 --weird scenario

we have 1 windows server 2008 r2 standard version working fine, lost internet connection after patching. we have sophos anti-virus software. can ping internal servers cannot nslookup, no internet connection. can disable av , check? also, disable firewall. arnav sharma | facebook | twitter please remember click “mark answer” on post helps you, , click “unmark answer” if marked post not answer question. can beneficial other community members reading thread. Windows Server  >  Server Manager

Folder Redirection to a DFS share located on our cloud

hi all, i have been tasked new action @ work. this make use of our cloud based service. what me set folder redirection dfs share located on our cloud. does sound correct action take: 1. set 2 windows 2008 boxes located in cloud , configure dfs on both (so replicate etc...) 2. configure ad gpo redirect folders new dfs share are these correct steps? how determine how storage need? can point me at guides/documents regarding this? thanks mac  hi mac, i cannot confirm exact definition of "could" here. whateve, if dfs namespace accessed correctly, redirect gpo work direct folders the dfs share. for size of storage needed, depends on plan. kind of data needs stored on dfs namespace? in addition, reason deploy dfs namespace keep working when 1 of folder target down, seems failover cluster better option. technet subscriber support in forum |if have feedback on our support, please contact tnmff@microsoft.com.

Win2k3 R2 DFS Replication Service

hi there,   i'd advice, setting dfs replication service replicate directories dfs use, because data size large i'm wondering whether possible pre-stage content first , let replicate delta data only. because data size large , we'd minimize time takes sync. using win2k3 r2 dfs , replication services. can advise.     many thanks momo hi momo, generally speaking, backup program reliable use. prestage data, may use backup program (ntbackup utility) restore files parent dfs folders onto alternative disk location on destination server. afterwards, can create new dfs link in current dfs namespace, , add both source dfs folder , target dfs folder folder targets in link. dfs replication prestage operation how use backup program prestage data before dsfr synchronization in windows server 2003 r2 http://support.microsoft.com/default.aspx?scid=kb;en-us;947726 as know, replicaiton flow won't occures since hashes computed dfsr source , destination dfs folde

Dns zone replication error.

This summary is not available. Please click here to view the post.

Vulnerability scan on 2008 R2 Domain Controller

we use qualys scan our servers , our new 2008 r2 domain controllers came 2 vulnerabilities: null session / password netbios access netbios remote user list disclosure a posted in thread found ( http://social.technet.microsoft.com/forums/en-us/winservergen/thread/4f2da8e0-0b56-40c1-a821-bf3b9294fa2c ) had suggested fixes, unsure of consequences.  i figured cross-post in subforum in hopes of more response.  does have suggestions or comments on fixes this?  unfortunately scan points documentation server 2003 , wasn't sure if applicable , wasn't able find other info. any appreciated. hi,   since microsoft tools , third party tools use different mechanism, result may different.   based on current situation, microsoft tools scan system , results good. suggest contact qualys support following link further assistance.     http://www.qualys.com/support/     please note: microsoft provides third-party contact information find technical support. contac

Windows load Balancing

hi, i have file sever one1gb nic ,operating system widows 2003 sp2. sicne few days observed taking time upload or download normal mb files in 10mbps lan. so, have added network card traffic sharing,for trying establish windows load balancing , for 2 network cards gave follwing ip range. nic1: 192.168.1.10 subnet mask:255.255.255.0 gateway:192.168.1.1 nic2:192.168.1.11 subnetmask:255.255.255.0 gateway:192.168.1.1   upto here ok,but unable configure these 2 network cards 1 cluster. please guide how can achove failover/traffic sharing in scanario.   thanks crew.       yeah.. i have configured network load balancing services  available in windows server 2003.   thanks   crew. with regards crew, Windows Server  >  File Services and Storage

Setting up HyperV Replica

i having problem setting hyper-v replica. i have 2 servers running ws2012 datacentre. both in workgroups. dc , dns server in vm. i brought test xp vm try out replica fetures. 1. configured destination server - enabled replication, open firewall port, selected kerberos authentication on port 80. 2. started replication wizard, , plugged in details - kerberos port 80, , kerberos authentication error. "failed enable replication" on host server e ventid 32000 on main server – “ hyper-v failed enable replication virtual machine 'zmattra': no credentials available in security package (0x8009030e). (virtual machine id 6525c88d-a7fe-4d3e-b880-76afad79dd11)” with eventid 29210 – “hyper-v failed authenticate replica server destiny using kerberos authentication. error: no credentials available in security package (0x8009030e)” and on destination, eventid 29212 – “hyper-v failed authenticate primary server using kerberos authentication. error: no credentials a

Shared Folder (New to Clustering)

hi! can brief purpose of having shared folder in cluster? thanks. i going assume quorum fileshare?  this same disk quorum, in fact has vote on whether cluster service remains running or not.  word of caution, if new clusters, careful do, if not sure doing cluster may become hinderance.  i reccommend build duplicate test environment, in configuration have safe test bed cluster alterations may implement.  also there greate resources out there assist in management of cluster Windows Server  >  High Availability (Clustering)

giving https access for "partner companies" but do not want them to go anywhere else on the network

hi  i've been checking previous postings.  opening sharepoint site partner companies. once site don't want them on other servers on network.  i followed info in previous postings , created group called computer_deny, created user , added them group.  created gpo , linked default domain user right deny access computer network enabled , computer_deny group added.  removed authenticated users filtering , added computer_deny group. did gpupdate /force restarted internal machine testing.  logged on user created, user can't server except domain controller.  i'm not sure about....they need authenticate dc, believe, once finish https entry , need sharepoint server.  if true, authentication process has happen on dc.  think authentication process different user trying access computer network.  correct?  least moving in right direction? the user can still access dc various ways i.e. run command, entire network not via rdp since right has not been granted.  further

windows 2008 r2 windows system reserved drive and Netbackup 6.5.6

i running symantec netbackup 6.5.6 backup windows 2008r2 x64 servers.  incremental backups fail because of windows system reserved partition.  know how delete partition existing virtual machine , after incremental backup runs fine.  running vmware , know how during installation of windows 2008r2 delete system reserved drive. once windows 7 setup loaded, press shirt + f10 keys @ first setup screen (which allows selection of language, keyboard , locale). command prompt window opened. run diskpart, built-in disk partitioning tool of windows 7 following command: diskpart type in following command 1 one, follow enter key create partition (text in brackets comments only): list disk (to show id number of hard disk partition, disk 0) select disk 0 (change 0 number if applicable) clean create partition primary size=80000 (create partition 80 gb space; use entire disk 1 partition, omit “size=value” parameter switch; use similar command create more partition if needed or cr

Do I need AD for Terminal Services?

im trying test out terminal services. i have sucessfully installed windows 2008 (finally) on virtual server 2007. didnt know need 32 bit, doesnt warn (its on xp) anyway .... do have set ad or can workstation. thanks hi,   yes, can have workgroup mode terminal server , active directory not essential part in ts environment.   to answer question think based on requirement. test in terminal service? if make server workgroup server, have create local user accounts testing.     Windows Server  >  Remote Desktop Services (Terminal Services)

Windows Server 2008 Standard licensing question

i've been searching quite time answer this, haven't been able find one. apologize if has been asked before. i have windows server standard 2008 x86 needs memory upgrade. license x86 version allow me move windows server standard 2008 x64 without buying new license? thanks, hi. depend of licence bougth. if vlsc might able see x64 product key. re-install in x64. if retail box.. no. if oem.. no too. is enterprise x86 ? can turn on /pae switch wich make memory available on 4g. (i got ts in win2008x86 16g of ram make exemple) need enterprice licence. regards, philippe Windows Server  >  Windows Server General Forum

What are all the password policies that will apply when resetting a password and changing a password of a domain user?

what password policies apply when resetting password , changing password of domain user? lets have defined 6 settings of password policy. when domain user changes his/her password, password policies new password should adhere to? when administrator resets password of domain user, password policies new password should adhere to? thanks , regards, radhakrishnan hello, if have password policy applied @ domain level password policy be, default, applied on domain users. of set settings applied! note can not apply multiple password policies linking multiple ones multiple ous. however, since windows server 2008 dfl, able apply multiple password policies using ad ds-fine grained password policies. details here: http://technet.microsoft.com/en-us/library/cc770394%28v=ws.10%29.aspx this posting provided "as is" no warranties or guarantees , , confers no rights.       microsoft student partner 2010 / 2011 microsoft certified professional microsoft certifi

How to exclude a user from loopback policy

Image
we create loopback policy our windows 2008 r2 rds. works fine. however, want deny policy users. check deny in apply group. sown screenshot. however, computer policy still applies user (user policy denied). post gpresult here. computer settings ------------------         last time group policy applied: 5/20/2013 @ 4:11:00 pm     group policy applied from:       2008dc     group policy slow link threshold:    500 kbps     domain name:                         domain     domain type:                          windows 2000     applied group policy objects     -----------------------------         rds client policy         default domain policy     the following gpos not applied because filtered out     -------------------------------------------------------------------         webhawk ad             filtering:   disabled (gpo)         local group policy             filtering:   not applied (empty) user settings --------------         las

PowerShell console font

hi how possible change font ps console.  seems impossible.  know there 3 fonts avaiable no matter.  use in profile don't have change every time open ps console. thanks mjksgea i tried did not work. when run first command " $host . privatedata . fontname "no result, see out put below.  not make sense c:\users\user> $host.privatedata.fontname c:\users\user> $host.privatedata.fontname c:\users\user> add-content $profile '$host.privatedata.fontname=?' c:\users\user> np $profile c:\users\user> add-content $profile '$host.privatedata.fontname="lucida console"' c:\users\user> np $profile Windows Server  >  Windows PowerShell

TS Gateway issue with Russian locale account name

hi all, it seems have encountered error pertaining ts gateway, causes fail valid log on attempts. here the details: dc machine (windows server 2008 r2 sp1) acts both terminal server , ts gateway. domain (demo) has built-in administrative account (called demo/Администратор) in russian locale. when attempt made log in via rdp (from windows 7 machine) directly in terminal server - works fine. log on goes via ts gateway - fails, , security event log contains record stating account demo/???????????? not found. so, basically, instead of russian letters account name contains ? symbols. error occurs when using either account name , password log in, , when using digital certificate (which contains upn Администратор@demo). at same time log on account name contains letters (like test) works fine. using account name latin letters except 1 russian in middle again leads security event log error account demo/t?st not found. i appreciate on matter. best regards.   hi,   t

Windows 2008 server SMTP issue

i installed windows server 2008 standard rc1 x64 , used server manager (add feature) add smtp server. the installation went successfully, when try open current sessions node in iis 6.0 manager mmc, it displays a "no such interface supported" error. it's freshly installed system, added web server role previously. hi,   as issue related iis, suggest discussing in our iis forum. best resource troubleshoot issue.   http://forums.iis.net/   i hope issue can resolved soon.   tim quan - msft   Windows Server  >  Setup Deployment

Do Whle issue

Image
wanting check if folder exists, if not, keep looping sayings not there yet; if , move on. why not working me?  have misunderstanding how conditional logic of while loop works.  i'm sure there plenty of easier ways this, , i'm game see suggestions, great if explain why logic below isn't sound? runs through 1 iteration, doesn't loop. many thanks, $stoploop = $false { if (test-path c:\path) { write-host 'folder exists';start-sleep -seconds 2 $stoploop = $true } else { write-host 'folder doesnt exist';start-sleep -seconds 2 } } while ($stoploop = $false) hi, this construct use: $found = $false { if (test-path c:\path) { write-host 'path found!' -foregroundcolor green $found = $true

Server 2008 R2 Admin User Locked

dear all windows server 2008 r2 forced me change administrator password, did so. a couple of days later tried access server no luck.  i think not remember new password typed! what can unlock it? reset it? or change it? can not format it!!! please help! thank you! no problem.. und q: boot using windows server 2008r2 dvd or image of ms dart ? : boot 2008r2 dvd q: command should type in cmd? : yes q: after restart boot os , on logon scree press windows+u? gives me ease of access window. should it?      i don't understand line... how cmd? command need type. answer:  c:\windows\system32>copy cmd.exe utilman.exe  > copied cmd.exe utilman.exe so @ logon once u press shortcut u getting cmd. net user administrator "password u want use" - out quotes this should work.... ----------------------- info security foks  these steps performed hack password using backtrack .. we pushed litlle further using official windows server 200

Account Lockout issue

hi all, i facing 1 strange issue on account lock out issue of 1 of user. on domain controller logs caller computer name showing "domain controller" name. while looking on event id 4625 source network address showing other server name. i have checked server user don't have rights login on server whenever user account lock out every time showing server name. in user machine did troubleshooting, enable netlogon debugging on domain controller but  nothing found. nirmal singh administrator you might want enable netlogon debug on dc mentioned in event 4625 check source requesting authorization.  start > run > type in: nltest /dbflag:2080ffff > ok after restart net logon service, related activity may logged %windir%/debug/netlogon.log to disable debug logging start > run > type in: nltest /dbflag:0 > ok it's possible use netwrix account lockout examiner free tool search root cause. --- jeff (netwrix)

Certificate Entrollment

Image
hi, 1) how can enroll following certificated (in red) by using powershell: 2) possible remove enrolled certs powershell? if so, please me script? please, need help, regards, bader two links same site in 1 day - i'm on roll. have @ this:  http://pspki.codeplex.com/   may of help. g. samuel hays Windows Server  >  Windows PowerShell

Issue/approve pending certificate requests with certutil

is possible somehow approve/issue pending certificate requests on standalone ca command line? certutil seems offer -deny , -revoke commands, not -issue. thanks ondrej.   definitely yes. use '-resubmit' option. since option is ambigous, property calls icertadmin::resubmitrequest() method: http://msdn.microsoft.com/en-us/library/aa383250(vs.85).aspx (here can detailed explanation). also may interesting in interesting example in powershell: function issue-pendingrequest { [cmdletbinding()] param ( [parameter(mandatory = $true , valuefompipeline = $true )] [ string ] $caconfig , [parameter(mandatory = $true )] [ int ] $requestid ) try { $certadmin = new-object -comobject certificateauthority.admin } catch { write-warning "unable instantiate icertadmin2 object!"; return } try { $status = switch ( $certadmin .resubmitrequest( $caconfig , $requestid )) { 0 { " the request not complet

Windows 2012 - falling speed write on one of the partitions

welcome,  from time fight declining performance of 1 of partition - , more specifically:  on time write speed decreases on 1 of partitions (called "data") in server managed windows 2012. after rebooting machine - write speed on partition called "data" (gpt) 100mb/s. after 2-3 days of work speed linearly decreases 100-800kb/s. it not matter whether data source locally (partition c) or network share. configuration:  dell r520 , perc h710mini possible patch's 8x 15k rpm disks (internal disk) 2 local partitions (basic windows mbr , gpt "data:)  dfs, nlb - turned off nic teaming - 2x1gb ...already change motherboard , perc on brand new - still same.  have 2 identical servers - second one, working reserve "problematic (first one)," there no such problems.  differences able observe:  1) problematic server - when run command "fsutil fsinfo volumeinfo d" indicates there installed option "supports file-based co