Posts

Showing posts from April, 2010

2012 R2 CA not including Subject

Image
i'm requesting certificates internal windows 2012 r2 certificate authority, the certificates mmc snap-in machine account. the "subject" empty on certificate produced, if add cn=something.domain.com, o=some company, etc. expected? this because template marked on subject name tab build active directory information    or a t least button not checked supply in the request hope helps, bill    Windows Server  >  Security

PowerShell script available to create backups from Replicated VM's

Image
just in case looking such solution; have created powershell script makes backup replicated (hyper-v 2012) vm. correctly pauses replication while copy in progress. additionally adds timestamp name of backup, backups not overwritten. it's cheap & simple solution, far seems trick, long keep eye on storage ;-) script can found here: http://www.servercare.nl/lists/posts/post.aspx?id=117 regards, paul www.servercare.nl hi, great, sharing! regards, yan li technet subscriber support if are technet subscription user , have feedback on our support quality, please send feedback here . cataleya li technet community support Windows Server  >  Hyper-V

Multiple sessions using 1 CAL

hello there, i own school computer lab 20 computers use same user (student) logon @ same time. can use 1 user cal or need 20 device cals? hi john, it's got nothing whether use 1 account students or provision each student own, need cover of them microsoft licences don't have strategy concurrent usage. microsoft licences windows come in 2 flavours: per user , per device (i.e. per computer). if have more students, overall, computers - norm education scenario, cheapest purchase 20 per device licences. if, strange reason, have fewer 20 students overall (not concurrently) 20 per user licences cheapest. licencing microsoft office different licencing windows insofar it's available per device unless you're licencing saas via office 365, in case it's available per user, options dictated buy channel through purchase licences. how technically operate, such you've described using single account, has no bearing whatsoever on how required licence environmen...

Sharepoint Site Requires Network Authentication

i have added sharepoint site trusted sites in ie, , changed custom level trusted sites use current user name , password.  seemed work - able open sharepoint site without entering user name , password, reason, these same settings has begun asking user name , password enter sharepoint site.  have ideas on might causing this? hi cindykf, thank post. i give these suggestions: 1. check ie connection proxy setting, select automatically detect settings and bypass proxy server local addresses 2. check ie trust sites custom level, user authentication select automatic logon current user , password 3. open control panel-- user accounts--manage credentials, check if store credentials sharepoint site if there more inquiries on issue, please feel free let know. regards, rick tan Windows Server  >  ...

PowerShell Scripting Zipping Sub directories.

i appreciate help-- this first job working computers , understand scripting slightly. language remotely have grasp on java. anyways. need write script in powershell of supervisers command. so have network drive has thousands of subfolders. each subfolder has 200 ".tif"s image drives. i need script compress each subfolder individually. example -1 --a ---file.tiff --b ---filex.tiff into -1 --a ---a.zip --c ---c.zip does make sense? each sub-folders content replaced zip file. here code found online, edited , works does, not want do... edited , broken dont kow if helps function select-folder($message='select folder', $path = 0) { $object = new-object -comobject shell.application $folder = $object.browseforfolder(0, $message, 0, $path) if ($folder -ne $null) { $folder.self.path } } function add-zip { param([string]$zipfilename) if(...

Create folder names with random numbers

i want create folder name temp ending set of random numbers (f.e: temp34521) i did not find answer on google. command generate folder lot of numbers $tempdir = [system.guid] ::newguid().tostring() how can accomplish this? have looked @ get-random cmdlet? length of numbers matter? $tempdir = "temp$(get-random -min 100 -max 5000)" if find post has answered question, please mark answer. if find post helpful in anyway, please click vote helpful. Windows Server  >  Windows PowerShell

cannot download and install updates without admin rights

hi all, we using wsus sp1 , i enabled in gpo auto download , install on schedule time option , enabled non-admin group policy .. still users pcs cannot see notfication. if give admin rights domain users after can see notification , install. normal need give admin rights users download , install updates. regards ali with wsus,client not require admin right download/ install. can understand question is,it seem gpo had mis-configuration. try edit policy , reapply it. Windows Server  >  WSUS

Virtual Server 2005 - Logon Failed "http://mehet/VirtualServer/VSWebApp.exe?view=1"

hey guys, i'm running on windows xp , unsuccessfully trying make virtual server 2005 work. time try connect, internet explorer tells me "http 401.1 - unauthorized: logon failed internet information services".  any suggestions, advices appreciated. hi,   according description, issue seems related virtual server. focus on hyper-v question windows server system , here not best support resource virtual server, recommend further support in corresponding community can qualified pool of respondents. understanding.   for convenience, have list related link followed.   discussions in virtual server http://www.microsoft.com/communities/newsgroups/en-us/default.aspx?dg=microsoft.public.virtualserver&cat=en_us_4547053a-f94d-4ba8-8099-616e26d29a02&lang=en&cr=us     best regards, vincent hu   Windows Server ...

Remote Desktop Gateway - Maximum simultaneous connection

hi, i have read running remote desktop gateway on 2008 r2 number of simultaenous connection 250, on enterprise edition unlimited ? (i mean, there no limit on tc/ip connection , terminal services session related gateway server , application server ?...)   in cases, best practices ?   we running infrastructure 2 gateway server , moment have 140 simultaneous user per gateway planning scale out many more users, reccomendation ?   thanks lot help! regards   /danilo hi danilo, correct, running rd gateway on 2008 r2 standard edition limits 250 concurrent sessions , using enterprise edition there theoretically no limit. in calculating how many rd gateway instances use, might useful information: ts gateway scalability white paper http://download.microsoft.com/download/9/9/0/990839d2-ed14-4aca-bfbf-8a40f2a6d2ce/tsg_scalability_whitepaper_final.docx and when started on actual rdgw implementation, blogpost on using multiple rd gateways nlb...

.NET Framework 4.5 via WSUS

good afternoon: i trying clarification in regards .net framework being released via wsus.  i have been reading conflicting things online.  i have 2012r2 deployment wsus 6.3, , noticing none of server 2012 servers have been getting 4.5 framework.  looking in console today, not downloaded update, synchronized thinking maybe missed it, latest framework see 3.5 sp1.  could please advise why not being downloaded wsus console.  i not have language packs selected in classifications, understanding "update". do have manually download this? thanks replies, yeah mine not under update rollups either. i ended manually importing it. Windows Server  >  WSUS

Problem in cryptographic protocols supported Kerberos in A.D

i have question set multi setting simultaneously domain users, 'm set user in active directory setting , enable :   o      use kerberos des encryption types account o    the account supports kerberos aes 128 bit encryption i read article http://blogs.msdn.com/b/openspecification/archive/2011/05/31/windows-configurations-for-kerberos-supported-encryption-type.aspx but don 't know of these options applies way kerberos protocol can store passwords , hash in db? mcse | mcitp [x2] | isms27001 hello - uf_use_des_key_only bit (0x200000) in useraccountcontrol attribute of user object takes precedence pre-windows server 2008 r2 default (or if present in msdc-supportedencryptiontypes) - kerb hashes stored in secret attribute supplementalcredentials in databsae (ntds.dit): http://msdn.microsoft.com/en-us/library/cc245499.aspx dose answer question? enfo zipper christoffer andersson – principal advisor ...

local Group policy editor (windows 8): disable built in speakers

hi  i looking solution where: i can disable laptop built in speakers, when headphone jack inserted, sound should enabled that. i needed know whether can accomplished through local group policy or mix of 1 or more alternatives. thanks am 11.05.2013 12:34, schrieb rishi ashar: > can disable laptop built in speakers, when headphone jack > inserted, sound should enabled that.   short answer: no, not through conventional group policy. if manage to grab relating registry values, might possible through group policy preferences, fail see sense in requirement... sorry ;-)   no not evil, if know doing: or bad gpos? wenn meine antwort hilfreich war, freue ich mich über eine bewertung! if answer helpful, i'm glad rating! Windows Server  >  Group P...

Windows 2003 Server Licensing Question

my client has windows 2003 server sp2 operates provide services several xp terminals mrp software. the server not have active directory installed. currently, "client license mode" setup product: windows server -> per device or per user.    upgrading exchange server have 10 user mail boxes.    first, we'll need upgrade server ads, , install exchange, license mode?  there 5-10 xp workstations connecting weren't connecting before, , addition of xp clients (10) connect current license mode.   thanks,   --tj i'd call them directly. (800) 426-9400 m-f, 6 - 5:30 pm pacific http://www.microsoft.com/licensing/contact-us.aspx       regards, dave patrick .... microsoft certified professional microsoft mvp [windows] Windows Server  >  ...

Windows Server Essentials Connector Download and Installation

Image
i trying install windows sever 2012 essentials connector on windows 7 professional  x64 (sp1) client. download  instructions attached. have tired both windows 6.1 x64 , windows 8.1 x64 download , both don't install on client. download should use windows 7 client? hi, before going further analyze, please let me confirm whether it’s windows server 2012 essentials or windows server 2012 r2 essentials? based on description, guess download connector this link . connector software helps connect pc or mac client windows server 2012 r2 windows server essentials experience server role enabled . the connector software installed when connect computer windows server essentials server using connect computer server wizard. can start wizard typing http://<servername>/connect , <servername> name of server. if computer @ remote location outside of windows server essentials network, run connect computer server wizard, type http://<domainname>...

Applying Permissions to AD

hi, currently have have ad multiple ou's. i wish tie these ou's down these objects themseleves cannot created, modified or deleted by 1st line helpdesk. i know can apply read permissions on each individual ou, possible on ou object type in block.   regards leo  hi,   if change ou permissions in block, may use dsacls tool. detailed dsacls command options, please read following microsoft kb article:   how use dsacls.exe in windows server 2003 , windows 2000 http://support.microsoft.com/kb/281146   you may consider accomplish via scripts. more information, please refer following technet article:   using scripts delegate control of active directory http://technet.microsoft.com/en-us/library/ff406260.aspx   if encounter difficulties when customizing scripts, may submit new question in official scripting guys forum! best resource scripting related issues below.   the official scripting guys forum! ...

Microsoft-Windows Group Policy Error ID 7320

in windows server 2008 r2 os in event viewer there error pertains microsoft windows group policy error id 7320 states-(error: failed register connectivity notification. error code 0x32.) error? , remedy error? - system - provider [ name ] microsoft-windows-grouppolicy [ guid ] {aea1b4fa-97d1-45f2-a64c-4d69fffd92c9} eventid 7320 version 0 level 2 task 0 opcode 0 keywords 0x4000000000000000 - timecreated [ systemtime ] 2012-01-08t11:00:34.194359700z eventrecordid 24412 - correlation [ activityid ] {3400c763-cb23-4ec5-b...

My Network place can't open each workgroup using WINS Server and NAT

hello, i have 2 network nat or router stand alone server , using wins server (windows server 2003), bellow network scope network 1 : 192.168.0.0/24 network 2 : 192.168.88.0/24 all  network working fine can open share between network 1 , 2 typing using windows xp sp2, "ex : \\rico\data\", can ping , no problem found. problem workgroup of each network not shown in "my network place", can open computer name can't browse in network place every workgroup. in wins server (windows server 2003) have fill database workgroup , computer name correctly. solution this? there wins configuration missed? or there bug 'computer browser' services 2 different network in client os? as conclusion point : - can open netbios or network share type \\computer name or ip address each network, - wins server have database correctly computer name , workgroup , ready dhcp/static ip address - "my network place" in client (windows xp) showing work...

When hyper-v deallocates a block of RAM in R2 SP1 dynamic memory, is it erased?

i having hard time finding answer.  perhaps not using right terminology. here scenario.  a program allocates ram data field, containing personal information. a block of ram allocated virtual machine.  data placed in it, , later released program.  block erased?  assume application doesn't it.  assume operating system in virtual machine doesn't either. so if dynamic ram released virtual machine, part of 2008 r2 sp1.  block erased, or still contain data?  after erasing block of ram, action must intentional either application or operating system. i don't know msft person talking in depth of detail. i getting impression question security related - along lines of, can read ram pages outside vm.  answer no.  xenserver , hyper-v share similar architecture , xen documented in how works. is possible read ram of vm parent partition?  different question - , yes possible prevented design.  , possible while machine runnin...

Keeping your servers up-to-date with patches

hello all, please note not wsus question. have installed in our environment , know how use it, or @ least think do. system admin of virtualized environment. our company grows, more , more servers have been built , keeping latest patches has become challenge. looking advice users have more experience here do. up point, have been updating virtual machines esx(i) hosts. okay when there fewer machines. now, if there 20 or more vms on single host, time consuming. also, add more hosts, fall behind updates. so, thinking can keep on top of better if can separate esx(i) updates windows updates. perhaps can update different group of vms each day. production vms need wait until weekend of course. thinking create new group in wsus has of latest updates approved , move vms group ready each machine. manually approve updates can auto-approve critical updates.  anyway, of who work in larger environments , keep on top of windows updates servers, how do it? best practices? of our desktop...

File share Quorum Windows Server 2012 R2 + SQL 2014 AlwaysOn AG

3 cluster nodes (2 in primary , 1 in dr) 2 nodes in primary site alwayson & auto failover (synchronous ) 1 node in dr site alwayson & manual failover (synchronous ) we using file share witness under primary site. each site has own subnet. if have network issues between 2 sites or decided break link between 2 sites testing purpose. how can make sure dr act primary db , once network link how convert primary site primary again. hussain hi hussain, >> how can make sure dr act primary db , once network link how convert primary site primary again. as far know, cluster choose node failover role automatically. you allow failback role, failback preferred role. open properties of role , see option. besides, considering running sql, post in following forum see if know details: https://social.technet.microsoft.com/forums/sqlserver/en-us/home?forum=sqldisasterrecovery best regards, leo please remember mark replies answers if hel...

AD Computer object / General Tab / Site = Empty

hi there, i wonder if has noticed before. running windows server 2008 sp2 domain controller. noticed need clarification on. when viewing properties of computer object on "general" tab, site field empty. this true workstations , servers joined domain. the following fields display information - computer name (pre-windows 2000): [netbios name listed here] - dns name: [fqdn listed here] - dc type: workstation or server - site: [empty] - description: [user editable] shouldn't site field populated site name configured in active directory sites , services? any help, clarification appreciated. if can verify same or different situation in environment. thanks, this matches experience. keep in mind site membership of domain members evaluated dynamically... hth marcin Windows Server  >  Di...

RDS Simple Question about installed apps?

   hi, i'm reading book windows 2008 r2, need setup terminal server called rds, read before install app want share remote users, first need setup rds , latter add app's.    true?    because app installed before rds.    now, app need sql server 2008, them if true, need setup first rds , latter sql server again , latter app?    input appreciated, thanks!!!    windows server 2008 r2 x64, sql server 2008 x64. any thing install on rds server should installed after rds has been installed. if sql server on server, no not need install sql server again Windows Server  >  Remote Desktop Services (Terminal Services)

Passthrough Disk in Hyper-V Cluster

having problem how correctly pass disk child vm host's san disks hyper-v hosts being clustered. hyper-v cluster each node has access san luns two vm's configured high availability each vm has lun on san dedicated chld vm's virtual hard disk boot. each vm needs to have access same physical lun on san sql data storage these vm's clustered within hyper-v level. essentially, need cluster 2 vm's sql servers , have access physical san luns sql data. problem: how configure passthrough disk @ host level when suppose offline in clustered configuration?  configuration shows errors in failover cluster status passthrough disks.  what best practice configuration? additional info: i'm trying setup passthrough disk directly vm un-managed within host failover clustering.  assume disk available of host nodes @ anytime failover cluster between 2 vm's manage ownership of lun directly.  prevent host failover cluster management showing errors b/c disk offline (a requirement @...

Win2003srv and Win 7 clients Home directory icon problem

hi on w2003srv domain have client's home directory store in \\servername\home\nomeutente1. with group policy redirect document's directory home directory. all client's win xp , work fine. now migrate client's win 7 , when browse server home directory see many mydocuments directory , can't see username. example: when browse \\servername\home\ after win 7 migration can see: pluto minny cipciop now after win7 client migration see: mydocuments mydocuments mydocuments if delete file desktop.ini in home directory work fine , browse directory correctly after first login on win7 the user home directory renamed in automatic mydocuments. is possible disable check of desktop.ini file in w2003 when browse filesystem or other solution? ciao Windows Server  >  Windows Server General Forum ...

Applying Domain GPO to standalone machines

Image
hello please point me in right direction find out main differences between available settings of local group policy compared domain group policy? know local gpo supports subset of features in ad-based gpo, , find out missing! i asking because have followed instructions here: http://social.technet.microsoft.com/forums/en-us/winservergp/thread/6ae68aed-7db2-4d5e-b360-c3bf502bfc24#1570ff85-6a18-4caf-827e-0c3053cc6b70 in order export , import our domain policy standalone machines, settings not valid. have comparison list of can , can't apply, or tell me can find 1 please? the aim of game me make ad group policy can import/export batch of standalone machines @ various external locations in order securely lock them down. never contact our domain. many in advance amy hi, > please point me in right direction find out main differences between the > available settings of local group policy compared domain group policy? we can’t find official steps or methods e...

Password Complexity Policy Not Disabling

ive gone through these steps on 2008 standard server: click start , type  gpedit.msc  to open policy editor open  computer configuration  (left hand pane) open  windows settings  (left hand pane) open  security settings  (left hand pane) open  account policies  (left hand pane) open  password policy  (left hand pane) doubleclick on the  password must meet complexity requirements select  disabled press  ok   close policy editor run  gpupdate.exe but still saying passwords dont meet complexity requirements.  is there im missing? hi, how restart computer? seems server not domain-joined, edit local policy set password policy. did create user account under local user , computer? if so, after restart should work. if creating user account under aduc, in domain environment, should modify default domain policy disable passw...

Clients not installing updates

i have installed wsus first time on windows server 2008 r2 , trying learn it.  have approved bunch of updates (critical, security, , office 2010 sp1).  have 1 machine in testing ou reporting in wsus console.  states needs office 2010 sp1 update.  have set group policy install updates @ 2pm everyday (for testing @ moment) laptop i'm testing (xp sp3) not install update.    does have ideas on should/can do? appreciated. windowsupdate.log on xp client start. tell you: a) wu agent working? b) wu agent configured wsus? c) client finding wsus? d) wsus responding? e) client resolving updates needed? (detection) f) client building list of downloads? g) client downloading updates? h) client installing downloaded updates? windowsupdate.log on the client verbose - gold ;) don Windows Server  >  ...

RDS with Windows Server 2012 R2: minimum RDP client requirements

hi all, we planning move new rds server 2012 r2. some of our thin client have rdp client 6.0 no possibility upgrade. we don't need of features of new rdp client. what mimimum rdp client requirements rds in windows server 2012 r2? microsoft confirmed rdp 6 , later supported server 2012 , this  hasn't  changed in r2. best regards, Windows Server  >  Remote Desktop Services (Terminal Services)

turn off option

how turn off option inheriting permission "folder"|file|properties|security|advanced|permissions|change , uncheck include inheritable .....       regards, dave patrick .... microsoft certified professional microsoft mvp [windows] disclaimer: posting provided "as is" no warranties or guarantees , , confers no rights. Windows Server  >  File Services and Storage

Disk performance problems on Windows Server 2003 Std x64

i installed new server win2003 std x64, hardware configuration following: server hp proliant ml380g6 ram 10gb ddr3 disks 3 sas 300 gb configured in raid 5 double cpu (16 cores total) , double power supply the disk logic unit splitted 2 partitions the server configured terminal server 20 users (but have problem single user logged in or administrator using console control) the problem following when user browses folders ont disk, server stops responding 2-3 seconds, performance monitor reports disk queue on 100%, attached link screen shot of performance monitor. we had before old hp server win 2003 x86 worst hardware same configuration (raid5, double cpu, double power supply, 20 users working), never had problem. we have done following tasks tryng solve problem: disabled non-microsoft services (also antivirus) upgrading of hardware firmware the problem persists link screen shot what can do? thank you hi did have simliar issue b...

Domain trust - accounts problem

 hi can help? have domain wide trust configured between abc.com xyz.com . from x computer located in xyz.com m not able see folders security configuration concretelly abc.com accounts appears unknow. on xyz dc servers  abc accounts appears normally so s not global problem on x computer. m able add abc account on x computer after save it than abc account appears unknow.  i suspect it affected settings in local security policy on x computer (there imported security template local administrator)  can have idea security settings cause problem thanks reply    jan   hi,   based on error message, should dns related issue. please perform following action check if nslookup can return srv service location records: 1) on problematic machine, open command prompt. 2) type nslookup , press enter. 3) type set type=all , , press enter. 4) type _ldap._tcp.dc._msdcs. domain_name , domain_name name of domain, , press enter. if dns works properly, please collect mpsreport further research:  ...

Incorrect permissions being set when IT Admin (Non Administrator) Creates user home folders.

hi all, hope can help.... i work organisation of <750 users, domain made of w2k3 machines, both virtual, , physical. heres problem.... it admin user creates new users , specifies thier home drive //server/user$/%username% , when does, gets full permission home drive new user. (this admin user not member of administrators or domain admins group, delegated create new users only) i think problem related permissions set on home$ share, searching , applying different permissions doesnt seem fix problem. seem going round in circles bit! so here's shares set to... //server/user$ share permissions are.... - everyone, full control ntfs permissions are.... - local machine\administrators, full control - authenticated users, special (traverse folder / execute file, list folder / read data, read attributes, create folders / append data, read permissions) - creater owner, special (full control) - system, full control live system, dont want make drastic changes, can enl...

User only gets temprary profile on 2012 Terminal Server

Image
have 3-host remote desktop services farm using 2012 r1. using user profile disks "store user settings , data on user profile disk" enabled. user has full control rights upd share , ntfs permissions. one user cannot login standard profile - keeps getting temporary profile. i have tried deleting sid profile list in registry here:  hkey_local_machine\software\microsoft\windows nt\currentversion\profilelist after reboot , try logging account in again, create temporary profile , leave .bak profile sid in registry.  have tried renaming remove .bak no luck. all other users don't seem having issues. i event id 1515 on user profile service: "windows has backed user profile. windows automatically try use backup profile next time user logs on." and:  event id 1511: windows cannot find local profile , logging on temporary profile. any ideas? hi, thank posting in windows server forum. description seems there single user profile disk issu...

Informacion Log DHCP

se puede saber mediante el log del servidor dhcp cuando un equipos se desconecto de la red? gracias. esta informacion no es un evento de dhcp. usted puede llevar control de informacion cuando un usuario se inicia sesion o termina sesion, habilitando la auditoria en las politicas locales. alli si tiene un control de los usuarios cuando inician sesion o terminan sesion. ing. diego fernando muñoz l. mct - mcsa - mcse - ccai - ccna. Windows Server  >  Administración de servidor

advertised application will not be installed because it might be unsafe

i need group policy assigned software. had old version of software made part of our computer image , company made software decided rebrand , require new install. wanted push new software user’s pc’s found new , old software conflicting. have manually uninstall both , manually install new again. decided manually install software , removed group policy since didn’t want have conflict our manual install. when removed policy have 2 options: the first option "immediately uninstall software users , computers." the second option "allow users continue use software, prevent new installations." being half of users have new software installed , working fine don’t want have group policy uninstall software don’t want block new installations. did second option , added software group policy published it, not auto install. cannot install on computers because has been marked unsafe application. how can remove group policy can go never added? guess is being set regis...

Missing Properties from Win32_LogicalDisk

hello wizards for long time, needed obscure information hard disks; below:     $drive.manufacturer     $drive.interfacetype     $drive.model     $drive.serialnumber     $drive.partitions     $drive.sectorspertrack     $drive.totalcylinders     $drive.totalheads      $drive.totalsectors     $drive.totaltracks     $drive.trackspercylinder i felt excited; when found @ http://msdn.microsoft.com/en-us/library/aa394084%28v=vs.85%29.aspx , information can retrieved the  win32_logicaldisk class. jumped try it; disappointed that, script returns blank values against of them. tried same in vbscript well, same disappointment. would wizard shed light on reason not showing important data, , how circumvent it! eagerly waiting response. you're getting wmi classes mixed up... 1 want is thi...