Posts

Showing posts from September, 2014

Users unable to logon to Windows 2008 Server 64bit after migrating from SBS 2003 Server & after taking SBS 2003 server offline

users unable logon windows 2008 server 64bit after migrating sbs 2003 server & after taking offline. users able logon when sbs 2003 server online. dcdiag runs okay on sbs2003 server except error message in bracket (starting test: services             ismserv service stopped on [sbs2003server]          ......................... sbs2003server failed test services) ideas assist in resolving case appreciated. dcdiag output on windows server 2008 64bit directory server diagnosis performing initial setup:   trying find home server...   home server = server2008   * identified ad forest.    done gathering initial info. doing initial required tests      testing server: default-first-site-name\server2008       starting test: connectivity         ......................... server2008 passed test connectivitydoing primary tests ...

cannot remote control user session in TS 2008 r2

hi domain 2003 terminal server 2008 r2 folder redirection when users connected terminal server 2003 r2 can controll user session. when users connected terminal server 2008 r2 failed error the device attached system not functioning  and sesion disconnected. i try work around no luck administrative templates\windows components\remote desktop services\remote desktop session host\remote session environment 4. in right pane, double-click on set compression algorithm rdp data 5. select enabled, , choose balances memory , network bandwidth 6. click ok save change this hapenning when tring control form both win7&win2008r2&server2003 thanks omer hello omer,   please install fix resolve issue - article id: 976110 a terminal server session shadowed incorrectly disconnected when terminal server session shadowing stops shadowing on computer running windows vista or windows server 2008 . there’s link “view , request hotfix download...

WebDAV and EFS Receiving Access Denied Errors

hello all, i experiencing annoying problem efs implementation.  have created folder accessed using webdav on 1 of file servers.  setup ntfs permissions following settings: ************************************************************************** directory: \\servername\d$vrsecure permissions: type     username                permissions           inheritance allowed  builtin\administrators  full control          folder, subfolders allowed  \creator owner          full control          subfolders , files allowed  nt authority\system     full control          folder, subfolders allowed  domain...

WSUS Failure - Error Code 80246003

we have approximately 1000 servers in our environment, 29 of them have started failing same error code - 80246003. they're either windows 8 or server 2012 machines. our wsus server running windows server 2008 r2 sp1 wsus 3.2.7600.256. we have installed both kb2720211 , kb2734608. as happening on multiple machines , multiple updates, assume issue our wsus server. have tried local client machine fixes such as: - stopping wsus, bits , cryptographic services; renaming wsus download folders; starting services up - re-registering wsus dll's - restarting client machines - restarting wsus server - reinstalling hotfixes listed above - using wsus troubleshooting tool automatically "fix" error(s) - installing 1 update @ time nothing try seems work! when try download , install updates on client machines, downloads reach 100%, instantly see failure message. below excerpt 1 of client machines: 2013-03-04    12:54:05:479     808...

account not authorized for remote login??

i found previous posts , info on other web sites error get, far nothing helped me solve it. what i'm trying quite straightforward -- thought: have 'top level' domain number of subdomains. want create "subdomain administrators" group of users must have administrative rights on subdomains, *without* giving them more ordinary user rights on top level domain. the domains involved server 2008 r2 ad level. both servers server 2008 r2 sp1 standard clean installs, both activated and fully date windows updates before dcpromo-ed. let's call top level domain "dom.local" , first subdomain "sub.dom.local" (all names generalized replacements here on). i created new 'universal' security group called 'subadmins' in dom.local. i created 2 user accounts in dom.local, one member of "domain users" , of "enterprise admins", the other member of "domain users" , of subadmins. then went sub.dom.local ...

start-process with different user credentials as system user getting access denied

i have trying launch powershell script different users using start-process while running system account. ideas how can around this. here code. param($id) set-executionpolicy unrestricted $username = 'blah' $password = 'blahblah' $cred = new-object system.management.automation.pscredential -argumentlist @($username,(convertto-securestring -string $password -asplaintext -force)) start-process -filepath c:\scomscripts\ack_scom_alert.cmd -argumentlist $id -credential $cred -wait -passthru hi ross,   thanks posting here.   i’d suggest first set program(ack_scom_alert.cmd) system service using sc if want initiate system account:   running cmd.exe local system http://blogs.msdn.com/b/adioltean/archive/2004/11/27/271063.aspx   thanks.   tiger li please remember click “mark answer” on post helps you, , click “unmark answer” if marked post not answer question. can beneficial other community members reading thread...

Force DNS Change for Active Directory Integrated DNS Zone After DR Testing

hello, active directory integrated dns zone, what's best way force dns change other ad dns servers (for large number of machines within same zone)?   will incrementing serial number work, or there better way?   or perhaps script run ipconfig /registerdns on list of machines?   i'm asking because conducting disaster recovery testing 1 of our production sites.   the plan let production continue run making production site island , unable communicate other sites.   we our testing bringing clone of server infrastructure in dr site (via vmware srm/3par storage).   the servers brought different ips , dns servers in dr site updated new ips.   once failover testing has completed, discard test clone of servers.   we restore communication production site, since serial number of dns zone in dr higher zone copy in production site, production updated dr's ips.   i prevent this.   i'm thinking around can bump serial number in production ...

MCITP Study Question - operations master roles

i'm using ms press kit study 70-640 exam , 1 of questions on practice test doesn't make sense me.  can second opinion on this?  change bit of wording not directly plagiarizing work: "you administrator @ burlap coats, ltd.  forest consists of 2 domains, burlapcoats.com , windows.burlapcoats.com.  server-02.windows.burlapcoats.com performs of 5 operation master roles.  going decommission windows.burlapcoats.com domain , move accounts burlapcoats.com.  want transfer operations masters server-01.burlapcoats.com  operations masters transfer?  (choose apply)" the program says correct answers schema master , domain naming master.  confused.  possible subdomain hold forest roles?  thought pretty kept @ forest root level. the program says correct answers schema master , domain naming master.  confused.  possible subdomain hold forest roles?  thought pretty kept @ forest root level. hello, ...

Find Accounts with specific License that dont have Litigation Hold enabled

i trying condense current script processes accounts 1 processes newly licensed accounts.  basically im trying find accounts have specific license(sku) not have litigation hold enabled. dont need enable litigation hold on accounts, 1 specific license. when execute this get-mailbox | {$_.litigationholdenabled -match "false"} i list of accounts dont have litigation hold, know part working but when try expand this   $lithold = get-mailbox | {$_.litigationholdenabled -match "false"} $users = $lithold | %{get-msoluser -userprincipalname $_.userprincipalname} | %{$_.licenses[0].accountskuid -like "exchangeenterprise"} i no results, though know test account has exchangeentrerprise license applied , not have litigation hold enabled. what need accomplish enabling litigation hold 3 years(1095 days) on newly licensed accounts specific license applied, or like  $lithold = get-mailbox | {$_.litigationholdenabled -match "fals...

WSUS broken after failed attempt to repair WSUS 3.0 SP2

hi we have tried fix our sbs2008 server had "not configured" and  ( 'the software update configuration has been modified , no longer meets recommended configuration.') in sbs console status. we did research , tried follow these articles: http://msmvps.com/blogs/bradley/archive/2009/08/27/repairing-wsus-3-on-sbs-2008.aspx http://technet.microsoft.com/en-us/library/dd443475%28ws.10%29.aspx we ran command nothing seemes happen , cmd went flashing cmd prompt. left time , tried run cmd 2 times. after twenty minutes decided rollback replacing original wsus folder onto c drive. after server updates console not connect , full error was: the wsus administration console unable connect wsus server via remote api.    verify update services service, iis , sql running on server. if problem persists, try restarting iis, sql, , update services service.   the wsus administration console has encountered unexpected error. may transient error; try...

Server 2008 Cannot remove Indexing in File Server Roles. It says "Element Not Found" .

it not allow me add windows search says cannot install while indexing on. when attempt remove role says element not found. in server manager log. says installed. how remove indexing can enable windows search. thanks hi, you have try run sfc /scannow may caused file corruption. if issue still exists, test tool mentioned in following article generate checksur.log file , see if similar error found descripted. how fix server manager errors after installing updates (hresult:0x800f0818 / hresult:0x800b0100) http://blogs.technet.com/b/roplatforms/archive/2010/05/12/how-to-fix-server-manager-errors-after-installing-updates-hresult-0x800f0818-hresult-0x800b0100.aspx technet subscriber support in forum |if have feedback on our support, please contact tnmff@microsoft.com. Windows Server  >  ...

URGENT - Windows Server 2008 R2 (Printer Driver Issue & Clients Prompted Update Driver)

hi, recently purchased new copier company, loaded new driver , share out driver , listed in ad, once install , share out, clients pc around 100users prompted update new driver on existing printer que happen when printing applications. clients joined domain , have no rights run update manual update clients pc administrative rights. not running gpo. how come problem occurs when installed new driver , share out? work around methods. there couple of print drivers update server side files client need updated driver periodically. if using print drivers included operating system, should not see this. can configure point , print restrictions policy client machine not prompted admin elevation. once determine settings organization deploy domain policy settings. alan morris windows printing team Windows Server  >  ...

Search missing from start menu after BSOD?

i've been using w10 few months , it's been stable, first time morning i've experienced problem. when tried waking computer sleep, bsod'd , @ bottom said search "driver_power_state_failure" more information. after restarting computer, ran windows update (windows defender updated), , since have restarted few more times, search bar missing start menu. it's gone. any suggestions? what if right click @ open spot of taskbar > click search > click show search box. will restore cortana's search bar ? " show search box" checked. i tried changing other 2 options , back, still doesn't show.  clicking on search icon on taskbar doesn't anything. it's search process isn't running or something. you may not suggestion ............ create user account of same privilege. log on , see if search box present. if yes, original user account somehow corrupted. ...

Firewalling Domain Controllers

hi, i have 3 2008r2 domain controllers in environment. 3 protected corporate firewalls external threats, local windows firewall disabled. is possible enhance security these dcs enabling windows firewall? exceptions/rules added automatically firewall policy based on servers' roles, or need add them manually? you can enhance security of these dcs enabling windows firewall. can make sure security updates installed. faik, exceptions / rules added automatically. have microsoft article needed ports ad replication. http://technet.microsoft.com/en-us/library/bb727063.aspx   posting provided "as is" no warranties or guarantees , , confers no rights. microsoft student partner microsoft certified professional microsoft certified systems administrator: security microsoft certified systems engineer: security microsoft certified technology specialist: windows server 2008 active directory, configuration microsoft certified technology specialist: windows ...

IE8 not default browser anymore after applying patches KB2229593, KB2202131, KB980376, KB890830

after applying above mentioned patches, users log in citrix session (terminal session), default browser not set anymore, when click on url link (in outlook 2007, or excel 2007, file extension .htm/.html, or ...) the following message appears user (it translated french): general failure! url was:  url here    application not found. so ie8 not start have. even if give our users temporary administrative rights can save manual setting of making ie8 default browser through program tab in internet option control panel, once log out of terminal session , log one, setting not saved profile. is there way correct have more 100 users i found solution problem. here steps taken resolve problem: 1) uninstalled security patch kb2229593. 2) rebooted server (even though windows did not asked so). 3) re-installed patch kb2229593. 4) rebooted server (even though windows did not asked so). when installed patch first time, there users loggd on server. ma...

Cannot connect to SBS

i running sbs 2008 , having connecting part of network. the server windows ip configuration    host name . . . . . . . . . . . . : ntserver    primary dns suffix  . . . . . . . : custail.local    node type . . . . . . . . . . . . : hybrid    ip routing enabled. . . . . . . . : yes    wins proxy enabled. . . . . . . . : no    dns suffix search list. . . . . . : custail.local ethernet adapter local area connection 2:    connection-specific dns suffix  . :    description . . . . . . . . . . . : realtek rtl8139/810x family fast ethernet nic    physical address. . . . . . . . . : 00-21-27-f1-c2-41    dhcp enabled. . . . . . . . . . . : no    autoconfiguration enabled . . . . : yes    link-local ipv6 address . . . . . : fe80::b841:dc3:33bb:c7ca%11(preferred)    link-local ipv6 address . . . . . : fe80::f12b:74db:ae8a:3a4e%11(preferred)    ipv4 address. . . . . . . . . . . : 192.168.4.4(preferred)    subnet mask . . . . . . . . . . . : 255.255.255.0    default gateway . . . . . . . . . ...

Virtual network printer

i'm working in virtual lab , need test network printing applications without access physical printer.  i'd simulate network printer making ms office document image writer network printer, not have options this.   wondering if has been able simulate network printer? thanks! --max create local port name nul the nul port pipe data nothing.  1 nul port per machine unless write port monitor can same system nul value. add printer using driver , set port nul.  when client application makes connection , prints, data run through spooler process , job gets "printed" without need paper in device.   alan morris windows printing team; search microsoft knowledge base here: http://support.microsoft.com/search/default.aspx?adv=1 Windows Server  >  Prin...

32bit apps not working on Windows 2003 SP2 x64

hi, i'm having trouble on windows server 2003 sp2 x64 (french). 64bit applications working fine 32bit apps not working. error message 0xc0000142 appear 32 bits application. in example, i'm able run calc.exe system32, in syswow64, calc.exe giving me error message. i tried uninstall last updates, still have problem. now, want to reapply service pack 2, can't find service pack 2 in french. tried install english service pack 2, doesn't let me run because of problem , think have language issue because i'm not able run english service pack 2 on server same os/version. can please ? thanks, alain hi,   sorry cannot find because not understand french. may search on french microsoft download center or can contact local microsoft customer service help.   please understand forum english use only. not right place find french service pack or troubleshoot issues on french system.   tim quan technet subscriber support in forum if have feedback on...

Remote Desktop Licensing service will stop almost immediately after being started.

the remote desktop licensing service stopped on our rds licensing server.  after trying start several times keeps stopping after few seconds.  the event viewer logs show error regarding version store.  see details below.  it mentions version store , long-running pending transaction cause this.  how purge such version store or set transaction committed or rolled back?  it seems db full situation in should either allow db grow bigger or cleanup don't have information on perform such operations. please advise. log name:      application source:        esent date:          8/5/2015 9:52:40 am event id:      623 task category: transaction manager level:         error keywords:      classic user:          n/a computer:      orswtsl002.amr.corp.intel.com description: svchost (3368) v...

Command succeeds in PowerShell console but fails when executed from ISE - what can it be?

i have script automates node.js application deployment , in process calls `npm install` this command works ok in both cmd.exe , powershell.exe fails when executed script area of ise (tried run both under standard user , administrator, result same). output like: npm : npm http https://github.com/agilio/node-sqlserver-compiled/tarball/master @ line:1 char:1 + npm install + ~~~~~~~~~~~ + categoryinfo : notspecified: (npm http ht.../tarball/master:string) [], remoteexception + fullyqualifiederrorid : nativecommanderror npm http https://github.com/bnoguchi/everyauth/tarball/express3 npm http https://github.com/agilio/loggly-console/tarball/master npm http 200 https://github.com/agilio/node-sqlserver-compiled/tarball/master npm http 200 https://github.com/agilio/loggly-console/tarball/master npm http 200 https://github.com/bnoguchi/everyauth/tarball/express3 npm warn excluding symb...

extensionattribute6

hi, i new powershell, know should possible :) i have script email managers of , direct reports expire in 30 days (based on mike laughlins one) before script runs need check date in extension attribute 6. logic follows. a new contractor starts , set account expirationdate 3 months today or contract end date if shorter if contract 6 months put contract end date in extensionattribute6 what want @ top of script check there a value in extensionattribute6 , if there , >than account expirydate  extend account expirydate 28 days or date in customattribute6 ever shortest todays date. the issue due format of date (15/06/2014 dd/mm/yyyy), need change so: #change get-aduser -identity auser -properties extensionattribute6 $date = get-date extensionattribute6 # $extatt = get-aduser -identity auser -properties extensionattribute6 $date = [datetime]::parseexact($extatt, "dd/mm/yyyy", $null) should convert date in extensionattribute6 property. assum...

SmartCard Enrollment Station w. 2008 and Vista

Image
hi, since web enrollment component xenroll has been replaced certenroll, it's no more possible enroll smartcards on behalf of user via web enrollment. when searching, found hint functionality implemented in vista certificate client (part of certificate enrollment api?). is there tool shipped vista can use vista machine enrollment station? greets martin i went on trying , found place can request certificates on behalf of user: have open certificate-mmc-snapin, click on personal certificate store , choose action->all tasks->advanced operations->enroll on behalf of , works fine Windows Server  >  Security

equipement hyper v2

hi i want realise  cluster v2 hyper , want type of equipment needed mount cluster without problem worser  research site fabrican hp dell , ibm  not idea please can me solve problem hi wich  manufacturers , vendors storage, including drivers, firmware, , software used storage, compatible failover clusters in windows server 2008 r2? Windows Server  >  Hyper-V

MSMQ and MSDTC: 2012 R2 vs 2008 R2

very strange issue. have service running on server 2012 posts transactional msmq on 2008 r2 remote server. changed config of service post seemingly identically configured 2012 r2 server. started throwing standard msdtc not configured on remote server error. the thing is, remote msdtc not enabled on 2008 r2 server , never has been. dtcping between 2012 , 2008 r2 server doesn't work (unsurprisingly), service works , messages posted queue. go new 2012 r2 server, enable remote msdtc , service starts working! apart port 135, necessary rpc ports not open on firewall between these 2 servers (2012 r2 , 2008 r2) allow msdtc work. to i'm confused going on understatement! the code in service written use transaction , there's no sql server involved; purely msmq. anyone ideas @ all? thanks as always, find answer 5 minutes after posting question. 2012 r2 has msmq ad integration enabled apparently forces transactions use msdtc. ...

Sharing and Securtiy issue in 2003 and 2008 server.

hi all, i using windows 2003 , 2008 server, have done sharing , provided required access(full, contributer. etc) users. after restarting server rights has changed read users except administrator..it happens on both server. m confused in that.. there windows patch removing rights.. or other issue suggestion welcome.. thanks mukesh hi mukesh, sorry, forum adrms discussions only, better answer if post windows security forums: http://social.technet.microsoft.com/forums/en-us/winserversecurity/threads blog link: http://blogs.cyquent.ae | follow on twitter: @cyquent | adrms wiki portal: technet wiki Windows Server  >  Security

Switch color depth within Remote Desktop

hi, i have application needs 'run in 256 colors'. when configure compatibility setting on executable , start application on console of our windows 2008 r2 server, switches color depth of console 8bpp (e.g. 256 colors) when logon same server via rdp @ example 16 bit color depth , start same executable with 'run in 256 colors' switch on, doesn't switch color depth of session 256 colors. is there way can make work? (without running complete rdp session @ 8bpp) kind regards, jeroen de vries hi, sorry, cannot change color depth of session on fly.  change color depth need disconnect , reconnect session using different setting. -tp Windows Server  >  Remote Desktop Services (Terminal Services) ...

Basic Disk / Simple Volume

in windows 2008, found not have options create primary partition , extended partition.  instead, has options create volumes (in earlier versions of windows, had option when had dynamic disks).   is change in windows 2008.  if yes, can have more information on same.     hello,   generally speaking, main difference between new "simple volume" , "partition" (used on basic disk prior windows vista) can resize volume.   in earlier versions of windows, choices resizing volumes , partitions once had been created limited. if needed add space volume, choice make disk dynamic disk , create spanned volume. if wanted expand or contract partition, choice use third-party tools. in windows vista , windows server 2008, however, can expand , contract volumes without data loss , without requiring reboot.   in windows vista , windows server 2008, term "simple volume" has been expanded include both partitions on basic disks , simple volumes on dynamic di...

Enabling Claims Support on Domain Controllers

Image
hello, since there's no dedicated server 2012 directory services forum, post my question here... following white paper dynamic access control, 1 of steps required enable claims based auth. enable gpo setting dcs hand out claims to clients. far good. however, ask myself: wouldn't better achieved automatically enabling feature when switch server 2012 domain/forest functionality mode? enabling feature via gpo can lead situation in mixed environment win8 clients claims because authenticate 2012 dc , not because authenticate downlevel dc. hence you'll inconsistent behavior when access resources. any insight apprecaited! thanks christian hi, claim-based authorization , auditing not have forest functional or domain functional requirement. can implement , configure claims mixture of windows server 2003, 2008, , 2008 r2 domain controllers provided domain has enough windows server 8 beta domain controllers support authentication requests include claim inform...

Built-In Administrators Groups Emptied

a group policy object(restricted groups: members) removed members of local administrators groups member computer(windows server 2008 sp2) , dont know administrator password.now, there 1 user "administrator" in local administrators group. how can repopulate local administrators group membership given fact there no domain users in local administrators group? is possible move computer other ou contains gpo force users local administrators group?will gpo process if "administrators" group on member group computer contain local administrator?     hello, if use restricted groups have understand differences between 2 options “members of group” , lower 1 saying “this group member of”. described in florian's blog: http://www.frickelsoft.net/blog/?p=13 best regards meinolf weber disclaimer: posting provided "as is" no warranties or guarantees , , confers no rights. ...

Windows 2008 Terminal service

hi, i planning implement windows 2008 terminal service in order allow remote users access application. have few questions: a.) avg bandwidth requirement per rdp session? b.) maximum number of concurrent rdp session can 1 server supports? if i have 1 windows 2008 terminal server, can supports more 200 concurrent users?  c.) server's ram requirement per rdp session? d.) limitatation macintoshi user when connecting ts server via rdp client mac? d.) there whitepaper/documentation on microsoft site talk designing a terminal services infrastructure? thanks, alex   hi alex, a) depends, example if bring visual effect minimum , not using redirected ports or devices, 56k may more or less enough. if using, printer redirection, 16 bit color, etc. may need more. have try , see works you. b) yes can support 200 concurrent sessions, server should powerful enough handle such big load. , not number of sessions, everything: bandwidth, used applications, used setti...

Windows 10 Technical Preview Build 10049 BSOD 0x00000133

so have problem check code 0x00000133 , here details: 040615-39562-01.dmp 06/04/2015 17:04:51 0x00000133 00000000`00000000 00000000`00000501 00000000`00000500 00000000`00000000 ntoskrnl.exe ntoskrnl.exe+1470b0 nt kernel & system microsoft® windows® operating system microsoft corporation 10.0.10049.0 (fbl_impressive.150325-1700) x64 ntoskrnl.exe+1470b0 c:\windows\minidump\040615-39562-01.dmp 4 15 10049 297.605 06/04/2015 17:10:05 how can upload minidump can find problem? thank much. so, resolved problem. found old guide windows 8.1 "clean start". used wise registry cleaner suggested guide fix registry keys , optimize system. seems last 1 fixed crashes because modified how o.s. works in these cases. Windows 10 Insider Preview  >  ...

domain name issue

hi while run below command getting weird domain name (dna) not exist in domain. have record in dns. this happening 1 windows 2008 r2 server not others.. net view /domain dna contoso need know why showing dna in net view command. > how can resolve .. please suggest   determine why... security or wmi filtering comes mind.   Windows Server  >  Directory Services

Change group SamAccount name, implications

hi, we have active directory 2008 r2 forest, 2 domains. found 66 duplicate universal security groups same samaccountname. if change samaccount name groups, implications? groups used share permissions , applications, afraid when change samccountname, share/ntfs permissions not update, same applications use groups authenticate users. can please advice? best if cand send link, need proof when present solution client. thank you samaccountname user friendly actual access woked based on sid. associated samaccountname.there no impact name changeing respect ad need check applications. if hard coded there. in ad ,sid responsiple granting/denying permissions & should intact groups after changeing group name. if not changeing acl there should not permission issue. regards~biswajit disclaimer: posting provided & no warranties or guarantees , confers no rights. mcp 2003,mcsa 2003, mcsa:m 2003, ccna, mcts, enterprise admin my blog domain controllers inventory-qu...

remove multiple people from a single group in Active Directory

i trying remove multiple users active directory group.  have list of users user id (account id).  , group changes depending on need.  there way create script request name of ad group, find it, , ask list of users remove?  (cut n paste?)  have no idea how go starting this.  , apreciated.  get-help remove-adgroupmember will show needed, , want use. there many ways go this, -members property takes in array of adprincipal object, can multiple users 1 command $group = read-host "type name of group , hit enter" $users = get-content c:\users.txt remove-adgroupmember -identity $group -members $users work, have not tested though, , there no error checking, basically, when ran prompts user name of group, users removed in text file, line line, use samaccountname in text file. if find post has answered question, please mark answer. if find post helpful in anyway, please click vote helpful. ...

Do they even know the IOS app is broken

Image
are microsoft aware latest update ios on remote desktop not working? speak group of network managers @ schools across uk , none of can latest update work on our ios clients hi chris, sorry hear it's not working you. have tried perform re-install or tried work on other ios device? apart update issue product group. understanding , support! regards. dharmesh solanki technet community support Windows Server  >  Remote Desktop clients

Installing Any Software on a New Windows 2008 Install

hi,   i pulling out hair on issue getting on brand new install of windows server 2008 standard edition (x64). whenever try run installation uses msi install software, fails below error: error 1935. error occurred during installation of assembly component {844efba7-1c24-93b2-a01f-c8b3b9a1e18e}. hresult: 0x80070308 i have installed os twice scratch using formatted disk (san based storage), there no bad files still hanging over. have used 3 different installs (same installs have used elsewhere without issues), , have tried running windows update; brings 80070308 error when tries install windows installer. have used same media install other windows server 2008 installations without these errors, not think installation of os causing issues (i think). at moment, there nice red smear on wall , have sore head issue. if can me, appreciated. regards, byron goatley ibm australia   hi byron,   thank quick response.   at current situation, agree installing version of windows server 2008...