Posts

Showing posts from July, 2015

Duplicate SPN for Domain Controller account

Image
i worked consultant morning federated services added domain controller , in process manually used setspn.exe -a command add federated services account.  little did know duplicate spn entries domain controller , stop me being able login it.  can still access shares , event viewer got me little further. i found this:   http://support.microsoft.com/kb/2015518   , problem facing.  now have identified duplicate account safest way remove , need completed domain controller? please help! i used ldp.exe procedure find this, why duplicate not show using setspn.exe -x command?  for reason wonder preferred method remove it.  i'm thinking setspn.exe -d not work, i'm not sure , don't want chance it.   will dc need restarted working again or should synchronization work incorrect spn gone? nevermind.  i found answer after more searching.   for interested used adsiedit remove duplicate.  it quite simple.  go offending acco...

Security Zones and Content Ratings just for trusted sites

Image
hello, i'm trying create gpo add sites ie local intranet , trusted zone.  if go user configuration-> administrative templates-> windows components-> internet explorer-> internet control panel-> site zone assignment.  can add in sites local intranet , trusted zones users not able edit field on computer , not add own trusted sites. if go user configuration -> windows settings -> internet explorer maintenance -> security-> security zones , content ratings.  can add sites , users can add own if wish.  gpo copies of security settings imported ie on computer when want trusted sites. is there anyway add sites intranet , trusted zone without additional settings , allow users add own?  can't use group policy prefernce because still have lot of xp computers deployed, our upgrade plan slow moving. thanks, joe hi, i suggest deploy group policy preference client side extensions windows xp , use gpp want achieve: group policy pre...

DNS/Public Domain Name Not Resolving

good day all, thank , contributions.  i installed , configured rds environment on home network in access applications internally , externally via self-signed certificates. when decided configure environment production purposes ran few problems regards pointing/resolving registered domain name (first time registering public domain name) rds server externally. can access remote applications internally via https://mydomain/rdweb when accessing internet receive following error prompt dns_probe_finished_nxdomain – server mydomain.com cant found, because dns lookup failed. quick outline of servers (using 1 physical server) & domain name configs 1 x hyper-v host (ip: xxx.xxx.xxx.82) – (name: vhost01) 1 x addc (dc/dhcp/dns) (ip: xxx.xxx.xxx.83) – vm – (name: dc01) 1 x rds (domain joined) (ip: xxx.xxx.xxx.84) – vm – (name: rds01) credentials of service provider hosting domain name mydomain.com domain :   mydomain.com   xxx.xxx.xxx.177 (this default ip un...

Remote App Screen Refresh

when using outlook 2010 on our terminal server using remote app screen freezes sometimes. if go application , outlook working fine again. problem occurs when switching windows (e.g. after using send button on new email). hi,   you can check whether add-in, com lead issue. please open outlook 2010 in safe mode see whether issue still exists. 1.  open start menu , click on run. 2.  type command line outlook /safe in open: field (note: there space between outlook , forward slash). click ok 3.  open outlook client in safe mode.   work office safe modes http://office.microsoft.com/en-us/outlook-help/work-with-office-safe-modes-hp010140792.aspx   do have installed antivirus software in rds server, may cause issue.   if so,  please try disable antivirus software see if same issue still exists.   ensure users using remote desktop client latest version. remote desktop connection 7.0 client update remote desktop ...

Increase in DEDUP RATE after migration. Why?

i had old fileserver, win2012r2, 3 tb volume dedup enabled , average rate of dedup 49%-52% on tha last 3 years. in 2016, free space of volume going down , in january had 10% freespace , yesterday less 1% of free space on old file server last week we bought  a new fileserver, win2012r2, 10tb volume , i´ve migrated 5.5 million of files week now dedups saving rates 72%!!!!!!!! if files same in both volumes, how saving rate grown much? maybe because there more disk space avalable?  what expecting same saving rate both servers, because set of files , folders same. after week preparing migration, copying files 2 weeks ago in full mode , in last 5 days doing incremental copies, why saving rate higher earlier? hi kayzersoze, thanks feedback. not sure if it's bug. try optimize deduplication jobs , check results. if still shows high, maybe bug, , might need consider to contact microsoft customer support services (css) dedicated support professional can ...

ADMT Computer Migration Fails - ERR2:7711 Unable to retrieve the DNS Hostname for the migrated computer .... (hr=0x8000500d)

hi, issue while inter-forest migration of users 2003 2008 domain using admt 3.2 password migration installed on 1 dc. prerequisite configured ,stub zone have been configured, tcp/ip client support enabled on source pdc.  successfully migrated users & groups. facing issue while migrating computer accounts (windows 7) admt log error : err2:7711 unable retrieve dns hostname migrated computer. 'computerfqdn'. adsi property can not found in property catce (hr=0x8000500d) client login issue :-  after reboot login screen have old domain choosing switch user default new domain.    the problem login attempts greeted red x and  “ the security database on server not have computer account workstation trust relationship. ”   logging in locally, leaving domain , rejoining worked wasn't solution. trouble shooting done 1)firewall disabled on client system 2)manually re added target admt user local administrator of system 3) enabled on dc - gp...

Windows 2008 SP2 - Active Directory Server log in black screen

hi,   in our root domain, have 2 domain controllers installed.   server1: windows server 2008 sp2 / schema master , domain naming master, pdc server2: windows server 2008 sp2 / global catalog     unfortunately, server2 on root domain has failed , had reinstall it. dcpromo.exe , activation of global catalog role possible without issues. after required reboot, logon on server2 "domain admin" account possible, saw error symbol on network icon on taskbar. error message “unknown domain <domain>” or “not connected <domain>” after second reboot, tried using "domain admin" account login , got see "access denied". then, blue screen changed black screen mouse cursor. no longer possible sing me in locally or via rdp, not save mode or command line. remote connection event viewer on server2 shows me domain controller , global catalog installed without error , working fine. possible connect dsa.exe domai...

Sysprep and keep license key not working

hi, i using sysprep on technet license keys. created unattend.xml file (below) , selected generalise , oob sysprep execution. however, on reboot, still prompted license key. <settings pass="generalize"> <component name="microsoft-windows-security-spp" processorarchitecture="amd64" publickeytoken="31bf3856ad364e35" language="neutral" versionscope="nonsxs" xmlns:wcm=" http://schemas.microsoft.com/wmiconfig/2002/state " xmlns:xsi=" http://www.w3.org/2001/xmlschema-instance "> <skiprearm>1</skiprearm> </component> </settings> why? well that's why it's asking it... retail media right? if want work, have use volume activation media , key (mak or kms). more info here: http://www.microsoft.com/licensing/existing-customers/product-activation-faq.aspx ...

Rename Default Server Shared Folder?

we rename 1 of default shared server folders in ws2012e (the "company" folder, specific).  appears can done via simple right-click "rename" command.  there problems or consequences in doing this?  company shared folder empty , unused, way. thanks. john i'm not sure can right click , change name. check out post. it's not specific essentials, and predates ws2012, but the same steps might apply. http://social.microsoft.com/forums/en-us/a55d425b-cbf3-4b25-a11e-e624839b10e0/rename-or-delete-default-shares?forum=whssoftware Windows Server  >  Windows Server 2012 Essentials

Monitor Group Policy Preferences Map Drives

Image
i use gpp map drives @ logon. plan create a  script monitors process of mapping drives, if mapping successful or not, , when mapping finished inform the logged on user. i did not find many information gpp processing. what want is: - getting information gpp mapping results (success or not) in registry there information @ hkcu\network , hkcu\software\microsoft\windows\currentversion\mountpoints2 not consistent ... - getting information when gpp mapping has finished process userinit.exe among other responsible mapping, mapping happens in phase of userinit, dont want wait until userint has finished complete. thanks clients: windows 7 service pack 1 hi, i see want know time when gpp applied, , result whether success, that, know whether it  success check whether mapped drive exist, , time when mapped drive exist, seems use event log check time. if want use script that, suggest post in below forum: the official scripting guys forum http://so...

Powershell Script to list Installed devices

in o365 admin portal, can display list of devices user has installed licensed product.  i'm looking way list information via powershell users.  it doesn't it`s feasible. you correct. can use get-msoluser command license status. however, can’t use powershell command details of users’ activated computer name list office 365 tenant presently. there no support manage through powershell cmdlets currently http://blogs.technet.com/b/odsupport/archive/2015/06/22/office-365-proplus-user-activations-management.aspx https://community.office365.com/en-us/f/148/t/174499 https://www.linkedin.com/grp/post/3724282-5798358639110537218 Windows Server  >  Windows PowerShell

powershll

hia kilaruv india.i hope 1 reply question!    1 how connect claint machine throug power shell ? hi kilaruv,  here article walk through using powershell remotely between 2 windows 7 (or 2008 r2) systems:  http://powershell.com/cs/blogs/tobias/archive/2009/08/30/test-driving-remoting-in-windows-7.aspx . if have further powershell questions, recommend checking out powershell forum here:  http://social.technet.microsoft.com/forums/en-us/winserverpowershell/threads . thanks, guy Windows Server  >  Group Policy

Ideas

i have noticede pople stating tu use server o/s personal sistem instead of original products designed pc. because of have been thinking self upgrade , update of sistems should more friendly. example: people have 2 different internet providers have trouble seting bridges betwen multiple lan conecctions,  creating multiple conecctions between 2 or more computers. creating utilitary programs such porpouses might idea. something else has come attention in small enerpricess when there sistem failure restore takes longer could. recent sistems have backups restoring operation sistem when easier have full sistem restarts inmediatly o/s from  a  diferent  location or hardware. easier start working same software same actualizations restore old one. have executable sistem totaly independent data might create solution individul users. whith constant increase of new , better hardware , requirements of softwares work future solution might see cpu single componento of larger computer. cheaper solut...

How to create second cluster on same SAN

hi there, we having 2 nodes configured one hyper-v cluster ibm ds3300 san system.  looking @ creating second cluster using 2 new nodes using same san.  how achive this?  , can use 2 different physical servers (e.g. x3650 , x3650m3) create cluster? any appreciated. regards winnie hi,   you can build new cluster using 2 different physical servers if don’t want add them current hyper-v failover cluster.   by way, how did connect luns first hyper-v failover cluster nodes ibm ds3300 san, using fiber channel or iscsi? can use same way create luns , connect them second cluster.     best regards, vincent hu   Windows Server  >  High Availability (Clustering) ...

Get filename that does not contain the specified string

i'm looking thru group of files in particular directory specified string, need file names not contain string.  me true / false, without filename: ls . -name incremental* | foreach {select-string -path $_ -pattern "->or_case`:" -quiet} this 1 gets me filenames contain string: ls . -name incremental* | foreach {select-string -path $_ -pattern "->or_case`:" | format-table -property filename} is there way combine both?  "format-table -property filename, equals" did not work, there's no value equals member or no value filename member if use -quiet in 'sls' cmdlet. try this: ls 'c:\temp' | select @{l='file';e={$_.name}}, @{l='string found?';e={if(select-string -path $_ -pattern "language" -quiet){write-output $true}else{write-output $false}}} result: file string found? ---- ------------- users ad...

Erro Server manager

Image
i'm getting error image below when try access shares, has experienced this? hi everton tanamati, thanks post. since english forum, please decribe error in english. according error code  hresult 0x8004100a in screenshot. it means that: internal, critical, , unexpected error occurred. report error microsoft product support services. is there error events in event eviewer? post event id, description in english. recommended repair steps can found here (question 8): http://www.microsoft.com/technet/scriptcenter/resources/wmifaq.mspx if still doesn't work,  try  the restarting service , rebuilding repository have check. best regards, mary please remember mark replies answers if , unmark them if provide no help. if have feedback technet subscriber support, contact tnmff@microsoft.com. Windows Server  >  ...

MAC Address Authorization in a pre-existing RADIUS/NPS environment

i have radius/nps deployed. current solution win2008r2 nps , me authenticating 802.1x clients (hp switches), alcatel ip phones (md5 enabled) , vpn pptp clients (incoming connections through fortigate appliance) now, need solve problem ruckus zone director , limitation of 128 mac addresses per ssid in controlled ssid avoid 128 macs limitation suggested use mac address authorization, see: http://forums.ruckuswireless.com/forums/8/topics/885 far know, need make changes in nps can turn current configurations impossible use without impacting 802.1x, vpn , ip phone clients. nps: override user-name http://technet.microsoft.com/en-us/library/dd197553(v=ws.10).aspx "... if set override user-name 1 , user identity attribute 31, authenticating server can perform automatic number identification/calling line identification (ani/cli)-based authentication. normal authentication using authentication protocols, such microsoft challenge handshake authen...

Cannot authenticate to network share through RODC

hi there we have problem authentication network share (\\server01\share) through rodc. the network follows: server01 in same network (192.168.211.0/24) client should connect share , rodc. login user client works if loged in there before built rodc. if try connect share, authentication prompt. if login client new user (that in allowed rodc password replication group too) error: there no logon servers available... all clients , server accounts , user accounts in allowed rodc password replication group. with regular domain controller works... if login through rodc user1 (already logged in before built rodc) , open cmd , type %logonserver% regular domain controller powered off... sorry complex writing. hope clear :) please ask further informations. thanks , best regards, chris hi chris, if understand correctly, seems clients not using rodc logon server authenticate. if case, please check if clients have pointed dns address ip of rodc if rodc installed dns. if not,...

Error on Enabling Hyper-V Replication...

Image
hi guys i'll fast , simple... when i'm trying enable hyper-v 2012 replica got error 0x8007000d...i'ts "data invalid" show virtual machine name , id. my primary server can connect secundary no problem @ all, firewall rule hyper-v enabled , i'm use kerberos authentication (http) any ideas? hi, > primary server can connect secundary no problem @ all, firewall rule hyper-v enabled so mean error happens when perform reverse replication? you may restart hyper-v host , enable replication again. try , give feedback further troubleshooting. for more information please refer following ms articles: understand , troubleshoot hyper-v replica in windows server "8" beta http://www.microsoft.com/en-us/download/details.aspx?id=29016 lawrence technet community support Windows Server  >  ...

Updates Applications

hi, spain, excuse inglish i have 2003 domain , xp pro clients my clients update using wsus server applications such adobe reader, java, etc. not update because don't know it how deploy applications updates clients? are there software update applications in lan such wsus? thanks , excuse again inglish   hi, you can using sccm example: http://www.microsoft.com/systemcenter/en/us/configuration-manager.aspx i believe there's separte forum technology (system center...), can learn more it.   andreas hultgren mcts, mcitp http://ahultgren.blogspot.com/ Windows Server  >  Directory Services

web application and sql server

why when set binding web application network load balancing address application can't send query sql server, when set binding ip address work fine? i don't know start  problem? hello, for nlb questions, ask them here: http://social.technet.microsoft.com/forums/en-us/winserverclustering/threads for sql questions, ask them here: http://social.technet.microsoft.com/forums/en-us/category/sqlserver this posting provided "as is" no warranties or guarantees , , confers no rights.       microsoft student partner 2010 / 2011 microsoft certified professional microsoft certified systems administrator: security microsoft certified systems engineer: security microsoft certified technology specialist: windows server 2008 active directory, configuration microsoft certified technology specialist: windows server 2008 network infrastructure, configuration microsoft certified technology specialist: windows server 2008 application...

RDC just flash and does nothing

i can rdc out other computer on same lan can not rdc in computer other computer. checked can think of -- firewall, port, firewall exception can't think of else preventing rdc in. advices? thanks much.  windows firewall disabled , firewall exception rdp enabled. remote desktop box checked, rdp-tcp port listening. rdp should working of these setting in place. did not have clue ati display driver cause till seached error message in event log rdpdd.dll failed load. blog suggesting me update ati driver. there many got similar problem , problems has been fixed. can read link:  http://blogs.technet.com/brad_rutkowski/archive/2008/01/04/systemroot-system32-rdpdd-dll-failed-to-load.aspx Windows Server  >  Remote Desktop Services (Terminal Services) ...

Changed secondary domain controller name

Image
i have domain controller that i renamed. while doing wireshark capture notice packet containing old name. 632 12.966401 192.168.0.114 192.168.7.255 nbns name query nb nsi1a<20> the computers new name nsi1, , not nsi1a. can fix this? hi, have find error log after domain controller rename process, or have meet issue after domain controller rename? by default, after domain controller rename, new name of domain controller automatically updated domain name system (dns) , active directory. once new name propagates dns , active directory, clients capable of locating , authenticating renamed domain controller. dns , active directory replication latency may delay client ability locate or authenticate renamed domain controller. length of time takes depends on specifics of network , replication topology of particular organization. during replication latency, clients may not able access newly renamed domain controller. might acceptable clients try...

Unable to Install Desktop Experience Feature

hello, i'm configuring 2012 r2 server rd session host.  whenever try install desktop experience feature, below error.  this happens both gui , powershell.  the feature listed install state of "available" in powershell.  i've tried specifying alternate source path pointing winsxs folder on 2012 r2 server same feature installed, still same error.  rebooting has not helped.  on problem server, i'm able install other features without issue.   has else ever ran issue before? thanks. install-windowsfeature : request add or remove features on specified server failed. installation of 1 or more roles, role services, or features failed. system cannot find path specified. error: 0x80070003 @ line:1 char:1 + install-windowsfeature -name desktop-experience + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~     + categoryinfo          : invalidoperation: (@{vhd=; credent...name=localho...

Licenciamiento

srta silvia. se ha comprado el windows server 2008 r2 enterprise, segun tengo entendido me sirve para instalar 1 servidor fisico y 4 virtuales, como puedo hacer si en mis servidores virtuales instale windows server standar y necesito ingresar las claves, ingreso las claves que me vinieron con la licencia y no me las acepta. gracias por el apoyo. srta silvia. se ha comprado el windows server 2008 r2 enterprise, segun tengo entendido me sirve para instalar 1 servidor fisico y 4 virtuales, como puedo hacer si en mis servidores virtuales instale windows server standar y necesito ingresar las claves, ingreso las claves que me vinieron con la licencia y no me las acepta. gracias por el apoyo. this english forum, please post query in english or else, try posting question in spanish technet forum http://social.technet.microsoft.com/forums/es-es/windowsserveres/threads thank understanding. regards, santosh i not represent organisation work for, opinions expr...

RDP 6.0 Alter Self Certificate

hello all, i have basic yet seemingly unsolved mystery , i'm asking vista question here because they're similar (longhorn & vista).  in vista, recognize can force rdp use nla rather rdp security.  here's problem:  want use enterprise issued cert rdp - not self signed 1 fashioned!  cert want used has been issued in local store on box. can't find life of me alter cert used rdp in vista (like using tscc.msc in w2k3).  there msc/dll can borrow longhorn use in vista, or there somewhere i'm missing in vista? best regards, mark we have local / group policy lets set this. it in gpedit.msc computer settings -> administraive templates -> windows components -> terminal services -> security -> servr authentication certificate this need set on vista host connecting , remember client needs trust cert , / or issuer. oh and nla enhancement rdp security not replacement. alex balcanquall ...

Adding a 2000 R2 as an additional DC to 2003 forest that already contains a 2000 server as a domain controller

 1) can server 2008 r2 64-bit version added additional dc server 2003 enterprise 32-bit windows 2000 server domain controller in forest? hello, there no problem keep in mind windows 2000 server out of support. details in: http://msmvps.com/blogs/mweber/archive/2010/02/06/upgrading-an-active-directory-domain-from-windows-server-2000-to-windows-server-2008-or-windows-server-2008-r2.aspx best regards meinolf weber mvp, mcp, mcts microsoft mvp - directory services my blog : http://msmvps.com/blogs/mweber/ disclaimer: posting provided no warranties or guarantees , confers no rights. Windows Server  >  Migration

Synthetic Fibre Channel HBA - Live migration Save/stop/start

i have 3 node hyperv 2012 r2 cluster. have guest windows sever 2012 r2.  have crated 2 fibre channel san two  qlogic  adapters. have install multipath , required drives  host , guest. guest has  2 virtual san  presented. i  see luns-a , on… can move   virtual machine  between hyper-v host without problem.   only  thing bordering me, live migration shut go without  stopping machine.  lose 6 ping. these can see  on target host, move machine. log  name :  microsoft-windows-hyper-v-synthfc-admin log name:      microsoft-windows-hyper-v-synthfc-admin source:        microsoft-windows-hyper-v-synthfcvdev date:          30.7.2014 15:04:10 event id:      32212 task category: none level:         information keywo...