Posts

Showing posts from March, 2015

Admin Tools Windows 7 SP1 no support permanent?

with release of windows 7 sp1 support of admin tools server 2008 not available. looking today see if updated versions of tools available yet , came across phrase on download page of windows 7 rtm tools. this software not supported on computers running windows 7 service pack 1 (sp1). ... this limitation design, , documented in windows 7 sp1 deployment guide . does bolded sentence indicate there no plans have sp1 supported version of admin tools? for reference, link windows 7 rtm page, containing above here: http://www.microsoft.com/downloads/en/details.aspx?familyid=7d2f6ad7-656b-4313-a005-4e344e43997d the paragraph above listed under system requirements, second paragraph. owner, quilnet solutions hello, microsoft working on update rsat tools. believe scheduled release in april Windows Server  >  ...

Visual Studio - Update 2 and 3

good morning, some people asked me other day if wsus didn't updates 2 , 2 of visual studio 2012. the products selected correctly in wsus server but, i've got iso of updates let users update product. anyone knows how make updates appear on wsus? good morning, some people asked me other day if wsus didn't updates 2 , 2 of visual studio 2012. the products selected correctly in wsus server but, i've got iso of updates let users update product. anyone knows how make updates appear on wsus? updates not released wsus yet. products take quite while before released wsus. sql server patches, .net patches, , visual studio patches notorious waiting long time before released wsus. Windows Server  >  WSUS ...

Is their a default time out before the Domain controller looks up a newly installed CA and enrolls for a KDC cert

so have domain controller on 2008r2 , member server 2008r2(non dc). installed enterprise ca on member  server. dc after particular amount of time new ca , kdc or have explicitly run certutil -pulse. i earlier experience remember dc's automagically see new enterprise ca , retrieve domain controller certificate. want know can find settings tell me how long before dc new enterprise ca domain controllers perform group policy *background* refresh each 5 minutes (by default). may have wait 90 minutes when all policies refreshed in same manner gpupdate /force switch. http://www.sysadmins.lv Windows Server  >  Security

Compatibility Check tool For Windows Server 2008 R2

is there comptibility check tool windows server 2008 r2? i running windows server 2008 x64 and wanted see if there problems if upgraded/installed r2 rtm when available.  not find tool , thought windows 7 upgrade advisor beta might serve itstead. it identified v.92 pci voice faxmodem "not compatible".  working fine current system.  driver being used 1 vista x64. is there reason not compatible r2? hello, chedck one: http://technet.microsoft.com/en-us/solutionaccelerators/dd537573.aspx?ca=not&su=winsvr&sa=map&ct=webs&cn=mscomwebs&au=bdm&go=maptn&dt=04012009 also see: http://www.microsoft.com/windowsserver2008/en/us/appcompat.aspx best regards meinolf weber disclaimer: posting provided "as is" no warranties, , confers no rights. Windows Server  >  ...

Mutiple Customers inside Active Directory without the ability for them to see eachother

hiyas, we're working on active directory design struggle. the goal have multiple customers sharing standard windows server platform (like file server, printing, exchange, etc.). normally, inside active directory isn't hard accomplish logically seperating company company b placing objects in seperate organizational units. maintaining security boundary on per service base done on service (e.g. on file server we're planning use access based enumeration) we're dealing following design objectives: 1) make sure company unable see company b inside active directory in way.  objective kind of challenge since authenticated users have 'read' rights throughout entire ad forest. 2) architecture should higly flexible. should able move services , shared resource domain see fit. 3) architecture should accomplished minimal of changes on active directory permissions or schema. updating searchflags attribute each class in active directory schema isn't option. ...

Migrate 2003 Terminal Server Licensing Server timing question.

i have following: - 20+ win2k3 terminal servers/citrix machines - pointing active win2k3 terminal server licensing server - licenses configured "per user" - windows 2008 r2 rds licensing server (no licenses installed yet) we want perform following: 1. call ms clearingwarehouse migrate win2k3 terminal server licenses new w2k8 rds licensing server. (the licenses upgraded 2k8) 2. leave current win2k3 terminal server licensing server active (because servers still pointing it). 3. point win2k3 terminal servers new w2k8 rds licensing server preferred ls server.  4. when terminal servers configured point new preferred w2k8 rds licensing server, , it's confirmed, we decommission old tsls. my question: when call ms clearingwarehouse , migrate new licenses on new rds license server, old win2k3 licensing server automatically no longer work servers still pointing licenses?  is working on "honor system" can decommission old win2...

export to csv issue

hello,  when run script below, i'm having issues processor query.  when runs on computer more 1 cpu can't right csv file.  i'm thinking has putting 2 results in 1 cell.  there way fix this?   $servers = get-content "c:\list.txt" function get-computerinfo { foreach($server in $servers) { $result = "" | select-object name, 'operating system', 'service pack', disks, manufacturer, model, memory, cpu $cs = gwmi win32_computersystem -computername $server | select name, manufacturer, model, totalphysicalmemory $os = gwmi win32_operatingsystem -computername $server | select caption, csdversion $cp = gwmi win32_processor -computername $server | select name, numberofcores, maxclockspeed $lastbootuptime = $wmi.converttodatetime($wmi.lastbootuptime) $result.name = $cs.name $result.manufacturer = $cs.manufacturer $result.model = $cs.model $result.memory = $cs.totalphysicalmemory/1gb $result.'operating system' = $os.caption $resu...

when the new policy will be in effect?

hi all, windows 2003 sp2 dcs supposed default password policy has maxium password age 90 days , 1 user gets warning have 10 days change password.  if change password policy maxium password age 120 days, user new policy , have 40 days change password?  new password policy be in effect immediately? thank you.   no.  current age (expiration) of password stay in effect.  next time a user changes password new policy applied against user object , new expiration value when set.   -- paul bergson mvp - directory services mcitp: enterprise administrator mcts, mct, mcse, mcsa, security+, bs csci 2008, vista, 2003, 2000 (early achiever), nt4 http://www.pbbergs.com     twitter @pbbergs please no e-mails, questions should posted in newsgroup this posting provided "as is" no warranties, , confers no rights. W...

update Department based on AD's OU

hi, i new powershell. have windows server domain controller 200 users. want use powershel update department specifying ou. my pseudo code follow set-aduser -department 'finance' of ou="fin" best regards samnang hi samnang, to ... get users in specific ou set department of them example: get-aduser -filter "*" -searchbase "ou=users,dc=contoso,dc=com" | set-aduser -department "contoso" cheers, fred there's no place 127.0.0.1 Windows Server  >  Windows PowerShell

autoenrollment not an option for a enterprise CA installed

i setup ad cs on domain server , configure server enterprise ca, default gpo autoenrollment users. after assigned certificate template enterprise ca on domain server.  when add authenticated user group want permit autoenrollment have options read, enroll, allow. not have option allow autoenroll in permissions. i have bee using technet article guide. http://technet.microsoft.com/en-us/library/dd379539(v=ws.10)   security sub forum best place ask question. http://social.technet.microsoft.com/forums/en-us/winserversecurity/threads press key... ... where's key ? this posting provided "as is" no warranties or guarantees , confers no rights. about me ? Windows Server  >  Windows Server General Forum ...

Hyper-V server 2008 r2 as a main OS

hi...you have excuse ignorance new hyper-v. waiting windows 10 upgrade next week can have play it. in mean time, wondering. have heard of microsoft hyper-v server 2008 r2, , free. got me wondering... spend lot of time in virtualbox , vmware player experimenting different operating systems (usually unix or windows previews), unfortunately, computer runs i3-2350m , 8gb ram, quite slow things virtualbox. learning how develop web applications, , fair amount of dabbling in c# , java too, virtual machine awesome development work in. starting 4 year masters degree @ university in october in computer science, guessing access making , using virtual machines helpful. can experiment software without worrying mess main installation of windows up, 1 has such strange hardware spend half day installing drivers , software after fresh windows install... cutting chase... question this: how hyper-v server standalone host operating system of main computer. (if there gui allows me access client o...

Access to Word, Excel, Outlook

i have no icons on screen word or excel.  got word using flashdrive, can't there start of home screen. how start>all programs>microsoft office? hope helps. doug robbins - word mvp, dkr[atsymbol]mvps[dot]org posted via community bridge "wayne t wagner" wrote in message news:ab817d1a-b9fb-495c-a3e1-9d5f6d6eed71@communitybridge.codeplex.com... i have no icons on screen word or excel.  got word using flashdrive, can't there start of home screen. doug robbins - word mvp dkr[atsymbol]mvps[dot]org Microsoft Office  >  Word IT Pro Discussions

Error adding ValueQueries to Scheduled Task

Image
i wish extract event data event viewer shceduled task trigger: < eventtrigger > < enabled > true </ enabled > < subscription > &lt; querylist &gt; &lt; query id="0" path="application" &gt; &lt; select path="application" &gt; *[system[provider[@name='biztalk server'] , (eventid=5740)] , eventdata[data[1]='pop3']] &lt; /select &gt; &lt; /query &gt; &lt; /querylist &gt; </ subscription > < valuequeries > < value name = " pop3error " > event/eventdata/data[2] </ value > </ valuequeries > </ eventtrigger > generates following error when import task scheduler , doesn't fire on event: task registered task "\event viewer tasks\pop3 errors" , not specified triggers start task. user action: ensure task triggers valid configured. additional data: error value: 2147942487. without add...

How to trap CTRL-C and user keystroke *without* pause?

hello, short version: need trap ctrl+c , other key user presses in console , continue running script without pause. long version: have ever updating display in console based on work background jobs doing. on occasion, user might want sort display differently pressing key or exit script pressing, say, "q". since there background jobs running, disable ctrl+c can proper cleanup. what's happening after use    [console]::treatcontrolcasinput = $true    if (3 -eq [int]$host.ui.rawui.readkey("allowctrlc,includekeyup,noecho").character) ... have press enter key-presses processed. so,     if ($host.ui.rawui.keyavailable) {         #$k = [system.console]::readkey($true) << pauses.         #$chr = $k.keychar         #if ((($k.modifiers -band [consolemodifiers]"control") -and ($k.key -eq ...

The path in the registry linked to the object in the Local Group Policy: Limit number of connections - WinServer2012 R2

Image
hi, i need i'm trying exact path in registry linked object inside local group policy: limit number of connections . this object in group policy when enable ,  change value of rd maximumconnectionsallowed to 2, it limits remote connections 2 connections only; need change value registry can't reach it's path. for windows server 2012 r2 what have checked far , didn't work:- hkey_local_machine\system\currntcontrolset\control\terminalserver\winstation\rdp-tcp\maxinstancecount hkey_local_machine\software\policies\microsoft\windows nt\terminal services\maxinstancecount hi, i have tested this. configure rd maximum connectionsallowed 100 in domain default group policy. and run process monitor on remote desktop session host , run gpupdate /force. the result maxinstancecount set 100 under path below. if setting not configured, there maxinstancecount key. hkey_local_machine\software\policies\microsoft\windows nt\terminal services best regards, ja...

Terminal services licensing question

good afternoon all, we have upgraded our teminal server license server 2008 server.  appears handing out license of our terminal servers except couple.  license diags show sees new 08 license server , avaialble , picked automatically.  old 03 license server still showing in diags not able assign license understand.  it's notice warning.  i've deactivated it, stopped services on , still showing server in diag list , showing inactive.  on 2 of 08 terminal servers once logged in pop says terminal services stop working becuase it's reached it's temporary license expire. when @ terminal server configuration showing new server not old one, showing avaialble continue error.. is there anyway clear cached information licenses on server referencing old 03 server somewhere it's not on.. thoughts? hi,   if understand correctly, got issue terminal server not able contact windows 2008 license server. since have windows 2003 license server exists ...

NLB in Unicast Kills networking

afternoon all, i getting strange issue nlb configuration , wondered if had seen before. building cas array ontop vmware cluster. using dell switches, having configure in unicast mode. have followed guides vmware , have created dedicated portgroup has 'notify switches' set 'no'. have attached nlb network interfaces dedicated network. i have configured nlb between 2 hosts, using 'nlb' network ip addresses cluster members. nlb comes online, failover works etc. i reboot server, , kind of networking dead in water. able ping other boxes. dns, ad etc not work. if disable , re-enable nlb adapter starts working again. i have configured binding order lan card first. any ideas? thanks paul which vm network adapter have configured on vms, e1000 or vmxnet 2 or vmxnet 3 ? i had seen issues such mentioned in post if use e1000 adapters. might want use vmxnet 3 adapters. i not represent organisation work for, opinions expressed here own. this posting pr...

group policies for printers

hi. know if there way following things: make users not allowed print on printer can't see specific printer. aka. if person b not allowed print on printer if add printer via wizard( add shared pritner) not able see printer in network. a user allowed print on printer can't chagne of settings( duplex printing, color printing, economode, etc) so in other words user can print , not change settings. i'm stuck these 2 things. read stuff working gpo's don't quite understand fully, , printersettings script erase/disable registry values seems bit harsh jsut problem( i'm sure more companis limit usergroups chagne printer preferences. i'd appreciate help/tips/solutions.   thanks i understand trying not sure whether group policy issue. far printer deployment , provisioning clients goes, group policy can used that. put hiding printers based on permissions operating system feature configure on server level - not on client. so i'd search feature ...

how to execute powershell commmand stored inside variable

i've searched previous threads, , net, resolution problem.  not sure why mine seems unique. i want add path script name, execute script, , store results in variable.   this works great.  need results (an array).  but, not "way" need accomplish it. i need place script in folder other whatever current is.     $results = @(.\scriptname.ps1 -debug)   this fails:     $results = @( ($scripts_path + "\" + scriptname).ps1 -debug)   i'd sure obliged if can indicate correct syntax accomplish this. i know invoke-expression , call operator (&).  neither 1 works. i'm sure i've missed fundamental rule here.   if directions go straight, turn left, right: still there? cancel....found answer.... $result = invoke-expression "& $($scripts_path + "\scriptname").ps1 -debug" if directions go straight, turn left, right: still there? ...

How to get the Active Directory User Account Lock Notification to C# application

Image
hi all, i want notification application (c# application , running on windows 7 os) when active directory user account locked in ad server. please let me know how this.  urgent 1 please resolve. vivek >>> i unable account lock event log in local pc(windows 7 pc). you don’t see these details in pc.   it on dc.   santhosh sivarajan | mcts, mcse (w2k3/w2k/nt4), mcsa (w2k3/w2k/msg), ccna, network+| houston, tx blogs - http://blogs.sivarajan.com/ posting provided no warranties,and confers no rights. Windows Server  >  Directory Services

how to use if condition in server 2008R2 in powershell?

hi,  i running  the below script in powershell in server 2008 r2 datacenter .but not displaying output. can me in this. $version=(get-wmiobject win32_operatingsystem).caption  if($version -eq 'microsoft windows server 2008 r2 datacenter') {     echo '2008 r2'         } in above code should display "2008 r2 " running script in server 2008r2 data center. nothing displayed thanks ravitej thanks ravitej reddy i think may need trim -  $version=(get-wmiobject win32_operatingsystem).caption if($version.trim() -eq 'microsoft windows server 2008 r2 datacenter') { echo '2008 r2' } Windows Server  >  Windows PowerShell ...

How GP will synchornize?

dear all, i have create domain around 500 domain user scratch, best practice creating domain around 500 user. ( os windows server 2008 r2 standard ) should create 1 single domain, in 1 single forest 500 user? precaution should take, must not face problem in future. there around 50 laptop user. how gp synchronize if don't come in company lan network ( around 3 6 month ). there method synchronize gp via internet. waiting ur valuable suggestion best regards, param thanks & regards, param mcse, ccna live voice discussion on related issue, please vist blog at www.paramgupta.blogspot.com hello, i have create domain around 500 domain user scratch, best practice creating domain around 500 user. ( os windows server 2008 r2 standard ) should create 1 single domain, in 1 single forest 500 user? what recommend making ad environment simple possible. that, recommend using single domain in single ad forest. what precaution should take, must...

Fix Fix501884 to fix certsutil prompt for smart card

hi there, i have vps windows server 2012 r2 , when use certsutil prompted insert smartcard. saw microsoft has fix problem: fix downloaded , tried run it. tells me fix not applicable computer. downloaded , installed prerequisite updates. i appreciate can offer. hi dave, there kb update fix problem kb 2955631 but when run "this update not applicable computer" mark sasson Windows Server  >  Windows Server General Forum

Event IDs: 5805 and 5723 - Unable to locate in AD...

event id: 5722 session setup computer "" failed authenticate. name(s) of account(s) referenced in security database "".  following error occurred: access denied. event id: 5805 session setup computer "" failed authenticate. following error occurred: access denied. event id: 5723 session setup computer '' failed because security database not contain trust account '$' referenced specified computer.  user action  if first occurrence of event specified computer , account, may transient issue doesn't require action @ time. otherwise, following steps may taken resolve problem:  if '$' legitimate machine account computer '', '' should rejoined domain.  if '$' legitimate interdomain trust account, trust should recreated.  otherwise, assuming '$' not legitimate account, following action should taken on '':  if '' domain controller, trust associated '...

Windows Small Business Server 2011 Essentials - internet and email problems

hi guys, i work small west sussex based charity , have real technical problem. in process of installing our first proper server in windows small business server 2011 essentials. system being installed , road tested alongside our existing 'server' (original windows home server). all of our computers connected micra digital (belkin based) wireless modem router. desktops connected physical cat 5s , laptops via wireless. the issue have this: both server , test clients have attached have major internet issues. pages google, facebook , bbc news refuse open or @ other times open in strange/corrupted way. none of our email addresses (imap based) work in outlook (server cannot found).  none of these issues occur on machines connected directly router, not on new domain created server. i have tried: different web browsers disabling antivirus disabled windows firewall on server completely resetting our router , restoring factory settings in case old ...

802.1x - DHCP release

we using 802.1x enforcement and remediation working fine on our xp machine.  when machine is out of compliance automatically moved to vlan 10 to remediate , moves production vlan.  same thing not working on windows 7 machine.  machine put in remediation vlan , remediated never releases ip remediation production vlan.  issue switch config?  if using cisco 2950's , 2650's.   on windows 7 client? hi, the process should work follows: 1. healthy client in compliant_vlan becomes noncompliant (ex: firewall turned off). 2. client sends new access request health status. 3. nps matches access request noncompliant policy (event id 6272 , 6276 occur), and sends tunnel attribute switch instructing place client in noncompliant_vlan. 4. client moves compliant_vlan noncompliant_vlan, network interface cycle up/down during process. 5. client receives dhcp address on noncompliant_vlan. 6. client automatically remediates , sends new a...

How to pass parameters in scheduling a windows task on command prompt

hi, i want schedule exe, , exe takes argument, couldn't on task schedule window, in http://technet.microsoft.com/en-us/library/bb490996.aspx page, doesn't explain giving parameters. can me? hello, you can schedule batch file example starts .exe required arguments, similar one(conficker.bat), used installing conficker patch .exe file , /quiet argument: ;install kb958644(conficker worm) in silent mode , creates logfile prevent loop on install: if not exist %systemroot%\w2kkb958644.log \\yourdomainname.com\sysvol\yourdomainname.com\policies\{3f30361d-1a8a-4b3f-8d2d-55b53bc28ea8}\machine\scripts\startup\w2kkb958644.exe /quiet if not exist %systemroot%\w2kkb958644.log copy \\yourdomainname.com\sysvol\yourdomainname.com\policies\{3f30361d-1a8a-4b3f-8d2d-55b53bc28ea8}\machine\scripts\startup\w2kkb958644.txt %systemroot%\w2kkb958644.log /y best regards meinolf weber disclaimer: posting provided "as is" no warranties or guarantees , , confers no rights. ...

Ports required from Client to Windows CA

hi i am having windows root ca installed on 1 of member server.this server , clients netwrok on different subnet: for getting client certificates, have opened 135 port client netwrok ca getting error in certificate installation "rpc server unavailable" after doing research, found certificates works on dcom traffic.does mean open dynamic ports between client netwrok ca network ? moreover, if need open few dynamic ports 25000-25100 in between, can bind these ports ca server editing registry key ? if yes, need find other servers dc or number of client getting certificate ca server. any suggestions please.......   regards, ankur  remove firewall between clients , ca <g>. if need through firewall, need restrict ca response single port. with windows ca, either restrict single port (returned query tcp 135), or have open 1024-65534. here wiki post kurt hudson describes need do: http://social.technet.microsoft.com/wik...

PRINTMIGRATOR (PROBLEMAS)

buenos días , tenemos problemas la hora de intentar migrar 1900 impresoras de un servidor de impresión otro servidor de impresión en preproducción . parece ser que la última versión de print migrator 3.1 solo permite hasta 1300 colas de impresión . ¿alguien conoce otra posibilidad para replicar todas las colas de un servidor al otro? sistema operativo w2003 server muchas gracias miguel la ultima version es la 3.1, has probado ir haciendolo por tandas y no las 1900 de una sola vez? saludos. roberto di'lello mvp | mcse 2008 / 2003 - mcsa messaging 2003 - mcts Windows Server  >  Administración de servidor

Pls help: SYSVOL and NetLOGON share not ready after creating first Windows 2012 DC

hi all, i'm setting first dc on windows server 2012 following steps here (social.technet.microsoft.com/wiki/contents/articles/12370.step-by-step-guide-for-setting-up-a-windows-server-2012-domain-controller.aspx). dcdiag gives following errors in sysvolcheck, services, , netlogons while rest of tests successful: ------------------------- cut here --------------------------       test omitted user request: dfsrevent       starting test: sysvolcheck          * file replication service sysvol ready test          [ort001c] net use or lsapolicy operation failed error 67, network name cannot found..          registry lookup failed determine state of sysvol.  error returned  0x43          "the network name cannot found.".  check frs event log...

File associations after migration

hi i'm using admt 3.2 migrate windows 8 machines new domain within same forest , know it's not 100% supported wonder if got same problem me. the migration finish successful without problems when user logs on file associations lost , after choosing program question question turns again next time user tries start program clicking on jpg file or xls file and yes user profiles migrated. any ideas? will there admt 3.x supports windows 8 , windows 2012? thanks magnus hi, for file associate issue, should not related admt. please check following key: hkey_current_user\software\microsoft\windows\currentversion\explorer\fileexts\.xls compare original system , see if changed. if key missing, export working system , import new system. in addition, admt supports windows 8/2012, said newest version still not support windows 8/2012 believe new version in feature. we trying better understand customer views on social support experience, part...

Windows 2003 - Tipo de Zona en Controlador de Dominio

hola amigos: estoy realizando la recopilación de información para la migración de mi servidor dc que también es dns. este es el esquema: dc so: windows server 2000 st active directory, dns (zona primaria) voy migrar windows server 2003 pero dos dc para poder tener una redundancia. luego migrar windows server 2008. la duda que tengo es en la configuración dns, actualmente en el dc que es windows 2000 tiene tipo de zona primaria, mi consulta es que tipo de zona es la mas recomendada para windows 2003 u windowss 2008. ¿zona primaria ó active directory - zona integrada?. el servidor que va ser dc tambén va tener la función de servidor dns. la espera de sus comentarios. manuel a. rojas medina el procedimiento agregando un controlador de dominio adicional es sencillo. puedes usar como guía lo detallado en: cambiar controlador de dominio http://windowserver.wordpress.com/2011/02/26/ca...

Powershell remoting and session management

hi, i new powershell , need use inside java program. want connect remote machines using powershell , invoke commands. using invoke-command cmdlet , working, problem every command need create new session, not efficient. using following script invoking remote commands. param([string]$ip="", [string]$username="", [string]$password="", [string]$cmd) if($ip -eq "") { $ip = "0.0.0.0" } if($username -eq "") { $username = "xyz" } if($password -eq "") { $password = "xyz" } $s = new-pssession if(($s -eq $null -or $s -eq "") -and !$cmd) { $securepassword = $password | convertto-securestring -asplaintext -force; $mycred = new-object -typename system.management.automation.pscredential($username, $securepassword); $session = new-pssession -computername $ip -credential $mycred; write-host "session created."; } else { write-host ...