Add all Windows Server 2012 cmdlets to Windows 7

hi evevyone does know if , how windows server 2012 cmdlets (more 50) and install them on windows 7 workstation? found articles to install ad module , few others, everytime sit @ workstation , open powershell i'm missing bunch of cmdlets, net tcp/ip , on. so there way them on windows 7, 1 shot, can administer servers. regards ernie prescott hi, following discussion might of help missing powershell 3.0 cmdlets in windows 7 (disable-netadapter)

Migrate All GPO from Test Lab (2008) to Production server (2012)

hello i have gpos in test environment (server  2008 ) , wants transfer gpos production server ( server 2012 ) there no trust between them , domains different. pls me how can transfer gpos real server (2008 2012). thanx hi, thanks post. based on experience, key challenge when migrating group policy objects (gpos) 1 domain or forest information in gpo specific domain or forest gpo defined. when transferring gpo new domain or forest, may not desirable, or possible, use same settings. can use migration table reference users, groups, computers, , unc paths in source gpo new values in destination gpo. work migration tables besides, following blog provides method of migrating gpos via powershell: three steps migrate group policy between active directory domains or forests using powershell

Help! Confusing myself with conflicting GPO's

hi there, we have 2 active gpo's. 1. general desktop users applied accross company, 2. laptop users connect remotley our network. i using a test laptop apply laptop users policy to. have added laptop (computer object) policy , logged computer myself (an authenticated user). authenticated users subject general desktop users gpo, policy overriding laptop gpo. is there way can force laptop gpo take control, policy , the computers in policy? thanks in advance! hello, beckyboo123. in gpos, have hability take more or less precedence. review ou want modify , move or down gpo want.

Supporting 32-bit applications on Windows Server 2008 R2 Enterprise

hi, we have been deploying windows 2008 r2 enterprise recently. does version support 32-bit applications? we have service pack 1 installed also. build 7601.   it not seem support 32-bit applications. and getting error messages when installing wow64.   any info appreciated. thanks.   javier lao tech hardware analyst public works it city of houston hello, as microsoft not responsible other vendors software such list doesn't exist. please contact vendor about, if application talking supported, if yes , have problems please post here , add application.

Unable to use Remote desktop with 2 monitors on Windows 10

hello, i used previous os windows vista adding argument /span on client reach office computer under windows 7. but didn't managed on windows 10 remote desktop client reach office pc (on windows 7). my monitors have same resolution 1920*1080. the resolution on office pc dual 2048*1152. thank reading issue. best regards, hi, please try use /multimon switch see whether works. in addition, testing purpose, may lower resolution see happens. here related article below you: using multiple monitors in remote desktop session 

Certificate Authority

i have windows server 2003 standalone root (which offline).   have enterprise subordinates on both 2003 , 2008.  now repalce 2003 standalone root new server running 2008r2.  path doing this?  can following- bring new standalone root, new server name server-x, re-use same root ca names rootca , import backed db/certs, update links , go? rich if existing root ca member of workgroup path simplier: 1) backup existing ca certificate, db, registry configuration 2) setup new standalone root ca. during installation wizard prompted generate new keys or import pfx file. select option , import existing ca certificate. after role installation restore ca database , registry configuration settings. if necessary modify cdp , aia extensions. 

WSUS and IIS integration

ok, have wsus , running on new windows 2012 build.  it's syncing microsoft correctly.  i'm seeing updates.  i'm able approve them , them ready send out unwashed masses here @ office. however, life of me, cannot single client see server.  i've got gpo setup correctly.  (i believe.)  however, know it's more basic that, because if attempt hit http://<servername>/ ?  ie promptly reports me website can't found.  if go "normal" http://<servername>, iis8 banner shows in glory. now...i'll first admit iis isn't forte...but have sneaky suspicion has run amok, or foul within state of iis.  (not denmark, assumed literate types.) any suggestions start digging iis determine connection between iis , wsus might broken?  and really, really, helps if assign group have access gpo you've created.  once went ahead , created , assigned computer group?  worked champ.

Host record wrong in DNS IPv6

hi, having issue in server 2008 host record in ipv6. problem began when changed server name. shows both old , new records server name. have 2 dns servers 1 2003 , 1 2008. have manualy deleted the records both. when forced replication entries don't show , shouldn't. after several hours somehow puts record back. idea getting old server name from? no issues ipv4.... hi there, have enabled dns scavenging on dns server ? can please tell how many nic adapters server has please see below article

User gets locked out repeatedly for no reason

hello about 2 weeks ago logged on 1 of our servers , ever since have been getting locked out randomly no reason. please help thanks josh hello josh there quite lot of  reasons behind problem. there couple of things should verify in order solve this. check similar thread , let know if helpful.   need troubleshooting account lockout but in nutshell: there are plenty of reasons account being locked out. important reasons listed below: some services use credentials in their start up process. have determine if have correctly set user , password services in " services.msc" check  credential manager  for wrong configured user , passwords. mapped drives wrong credential can cause "login failure" event. check your environment for "conficker" worm. there handy tool detecting conficker in network can downloaded from  here.   e ventually event "login failure" can lead account lockout problem. must check event viewe

DFS-namespace server + branchcache content server on one box

hi all, is possible have dfs namspace server working as a branchcache server !!  hi, generally use either dfs or branchcache provide similar function (for accessing files on local site). if dfs repliation set, seems not need use branchcache in same time. what's exact enviroment?   branchcache dfsr hardware infrastructure required none, if running in distributed cache mode need file server in branch office types of data cached smb2, http, https smb1 , smb2 what drives caching user reading data brings data cache administrator defines data set replicated , replication schedule cache lifetime "least used" data evicted cache when under disk pressure. otherwise, data not accessed in 28 days aged out data never expires file version seen clients clients latest content central server clients see version of content has been replicated branch

NPS - Prevent asking for a username?

i have been playing nps few days , basics.. it's not going planned. what wanted achieve nps server used radius authentication server in our aerohive (wired & wireless) solution. want prevent access our network unauthorized devices. therefor whipped basic vlan category. vlan 1: servers every server wired on fixed location. these switchports defined on vlan 1. vlan 2: trusted devices devices need network access printers, access control devices, mfc's, etc. verified mac address vlan 5: domain computers the computer account has member of domain computers. these verified there computer object name. vlan 6: trusted alien computers other computer devices not member of our domain need access our network. verified mac address. vlan 10: ip phones hardware phones need access pabx. mac or switchport. if possible, i'd prefer mac because people use patch port @ of phone wired connection. vlan 20: guest every other request should placed in vlan 20. kind of fa

CRL Download via SCEP fails in CA multi tier Hierarchy (Two tier / Three tier) with Event ID : 45 (NDES cannot match the issuer and serial number in the device request with any CA certificate)

hi all, operating system - windows server 2012 r2 we have set 3 tier ca hierarchy. root ca->subca->issuing ca ndes service installed @ issuing ca. we have developed client application retrieve crl issuing ca via scep protocol. we error "transaction not permitted or supported" reply in client issuing ca ndes. on viewing event viewer @ issuing ca, can see "event id : 45, says "ndes cannot match issuer , serial number in device request certification authority (ca) certificate" -------------------------------- we have reviewed implementation of client multiple times. filling issuer , serial number information "issuing ca certificate" device crl download request. testing purpose, have tried fill same "ca root certificate" "enrolled certificate device received signed issuing ca". the same error happens 2 tier hierarchy well. -------------------------------------------------------- however crl retrie

Most efficient WSUS strategy for basic Test and Production groups?

i'm trying setup basic wsus update strategy testing computer group , production computer group. i'll talk windows 7 keep simple. i've created custom update view called windows 7 show me updates windows 7 products (w7 updates, office updates, silverlight). have created 2 computer groups: testing computers , production computers (they're both nested under computers). want through custom windows 7 update view, select updates , approve them testing computer group, once i've verified updates good, want approve same updates production computers group. far have not figured out intuitive way keep track of updates have been approved testing computer group , production computer group. so make easy this, i've created 2 custom update views named "approved updates testing computers" , "approved updates production computers." i've selected these custom update views show approved updates respective group. ideally can go approved updates testi

Issue creating New-StoragePool and New-VirtualDisk specifying 1 physical Disk

hi all, i'm having issues with script i'm building, want create 1 storagepool with 1 physical drive 2 available disks, then create virtualdisk , volume with 1 disk in storagepool, initialize disk, format volume - the run same remaining disk so far can script building storagepool both available disks get-physical -canpool $true can't specify 1 disk -friendlyname below script -canpool $true works  $drivelogs = "sqldblogs" $physicaldisks = get-storagesubsystem -friendlyname "storage spaces*" | get-physicaldisk -canpool $true new-storagepool -friendlyname $drivelogs -storagesubsystemfriendlyname "storage spaces*" -physicaldisks $physicaldisks | new-virtualdisk -friendlyname $drivelogs -provisioningtype fixed -usemaximumsize | initialize-disk -passthru |new-partition -driveletter e -usemaximumsize | format-volume get-volume -driveletter e | set-volume -newfilesystemlabel sqldblogs specifying 1 disk 2 available (which i'm trying

event viewer cannot open the event log or custom view. verify that event log service is running or query is too long the event log file is corrupted 1500

i message when check windows 2008 r2 server event log go custom view server roles file server then event viewer cannot open event log or custom view. verify event log service running or query long event log file corrupted 1500 besides can check these links

PKI Module for Windows 7

i learned module became available, it's available on windows 10 devices, not windows 7. i've updated powershell on win7 machine using windows management framework 5.1 update , powershell version 5.1.14409.1005, version i'm seeing on win10 machines 5.1.15063.0. is pki module available win7 or need keep using makecert.exe though it's been deprecated? if pki module available win7 need it? i'm looking pki module developed microsoft , included in wmf 5.0, not third party pkitools module. \_(ツ)_/ not available windows 7. \_(ツ)_/

windows closed host domain

i keep getting message windows closed application protect computer , data hi, as meinolf said please provide details this might occur because of dep check link below

3.5mm Jack stopped working after update

i have been running windows 10 few weeks no problems. month update came out downloaded it. point on front , audio jacks don't work, usb's do. have tried different earphones , no luck. i'm guessing a new fault os? i have resolved myself. update not support quality device set to.  for people having issue in future help

Need sample answer file to build 2016 Windows Server

<?xml version="1.0" encoding="utf-8"?> <unattend xmlns="urn:schemas-microsoft-com:unattend"> <settings pass="windowspe"> <component name="microsoft-windows-setup" processorarchitecture="amd64" publickeytoken="31bf3856ad364e35" language="neutral" versionscope="nonsxs" xmlns:wcm="" xmlns:xsi=""> <upgradedata> <upgrade>true</upgrade> </upgradedata> <imageinstall> <osimage> <installfrom> <metadata wcm:action="add"> <key>/image/index</key> <value>windows server 2016 serverdatacenter</value> </metadata> </installfrom> <installtoavailableparti

Event Id 2019 - Server Slow,Unable to RDP,Stopped Shares

dear all, we have dell server 2950 connected t dell md3000 , md 1000 , configured nas server today 1 of user complained unable access share resources on nas server try open rdp denied ping successful when login on nas server physically takes more time normal when open task manager not showing network devices menu , ram 4 gb utilize out of 8 gb re-booted nas server,when check event found below lots of times event id: 2019 source: srv type: error description: server unable allocate system nonpaged pool because pool empty. so after resarch if found , read below mention link indicates happends due multiple issues but in event viewer found , warning before srv following event id: 2013 source: type: warning description: f: disk @ or near capacity.  may need delete files. so found main issue of problem space correct problem ? need valuable comments regards, osama

Viewing user Printers on 2008 R2 Terminal Server

is there way view user's connected printers on 2008 r2 terminal server? appears feature has gone away in r2. also, how can turn on logging of printer redirection see printers or don't connected correctly? we've turned off easy print. orange county district attorney hi, are member of local print operators group on rdsh server?  please open command prompt , enter whoami /groups verify group membership.  should see builtin\print operators in results.  should not necessary, if have uac enabled (the default), may want try right-clicking on print management , choosing run administrator.  make sure print operators enabled in security token, although again print management should automatically elevate enabled.   uac turned on print operators disabled normal processes. print management should work fine--it not require server print server.  use viewing redirected (and local) printers on rdsh servers.

What are SRV Records?

what srv records? hi, an srv record used map name of service dns computer name of server offers service. can find out more info on srv resource records in following technet article:

2008 TS licensing in a 2003 domain

2003 active directory terminal services 2003 -- looking move ts server 2008 -> 280 desktops xpsp3, have 2 dcs 2003, , additional 8 server 2003 std.  have 3 server 2000 machines , 1 server 2008 std (domain member). server 2000 machines run citrix metafame xp, delivering apps.  moving ts apps on server 2008.... 1 server @ time. if move ts licensing server 2008, server 2000ts licenses continue work? is, can follow prompts , migrate our existing 2000 , 2003 licenses 2008 server without losing them?  have additional licenses server 2008 ts clients. hi, w2000 ts licenses not valid 2008. need 2008 ts , server cal's w2000 licenses continue function clients connecting w2000 ts servers, not ones connecting w2008 though. also keep in mind can not go w2000 w2008. as highly recommend go 64bit hence next release w2008 r2 available in 64bit.

How to add local groups to local user account PS script

hello, powershell 3.0 novice , want add feature first ever production script tool. the script below local user accounts remote computers listed in a .txt file export .csv format.  how can incorporate local groups each local user account member of?  each local user account retrieved want list local groups member of. get-ciminstance -classname win32_useraccount -filter "localaccount='true'" -computername (get-content c:\ps\<listofcomputers>.txt) | export-csv c:\ps\<name>_localuseraccounts.csv (export .csv) your insight appreciated, matt, ps 3.0 novice matt hi matt, give try: get-content .\computerstocheck.txt | foreach { $adsi = [adsi]"winnt://$_" $adsi.children | {$_.schemaclassname -eq 'user'} | foreach-object { $groups = $_.groups() | foreach-object {$_.gettype().invokemember("name", 'getproperty', $null, $_, $null)} $_ | select-object @{n='computername';e={$}},@{n='userna

IPSec NAP with a Enterprise Subordinate CA

the step step guide instructs me use stand alone ca complete lab, i've done , success great greg. now need enterprise subordinate ca. i've done following modifications at hra (same box nps), configure "use enterprise certification authority" and chose available template (systemhealthauthentication) then test results, it's quite weird. the hra did request certificate, it's name "", , installed on clients (both domain , non domain clients) it suppose "clientcomputer$" right? what's reason, please help, thank much mcse mcitp:ea ccnp hi andrew, we've exchanged emails on issue already. think that setting certificate template properties "supply in request" on subject name tab fixed problem. you had interesting results @ first caused certificate "unauthenticated system health authentication" i've seen happen couple other times. issue resolved after 10 minutes. going to inve

AD group help

i had guy before me make bunch of group in ad don't need , not sure do.  need know if there ps script can run , see if these group attacted to any folder.  need find way clean ad and this is big part of it. thanks can give.   you might want try shareenum and accessenum

Group Policy setting for offline folders.

hi all, i'm having myself reacquantied offline files after swearing oath stay away them when mixed folder redirections around xp launch timeframe. suffice i've had no real dramas working offline files in own right, i'm having problems working them via group policy settings. in essence, need redirect documents documents folder located within unc mapped home drive. can represented as: h:\ ( \\\dfsnamespace\%username% ) h:\my documents as assumed unc, dfs namespace. so far, i'm @ point documents correctly made available offline - being second bullet point covered. however, can't seem achieve resolving requirement first bullet point made permanently offline. i'm using following 2 group policy settings: computer configuration/policies/administrative templates/network/offline files: administratively assigned offline files = enabled; computer configuration/policies/administrative templates/network/offline files: subfolders available o

Windows Server Update Services error event 10052, but test mail works

greetings! recently i've been seeing windows server update services event 10052 (can't send email notifications) errors in our wsus server application log. error means wsus unable send windows update notification information , via e-mail, , yes, have not received such mail wsus server while.  however, thing not understand can send , receive test mail wsus server fine. means that it that problem not lie smtp server or network, rather wsus server itself. also, windows update programs applied server in question recently, that may have something it. so strange. have ideas going on? hi, event id 10052 indicates invalid server specified or not have permission required complete operation. this issue can occur if specified incorrect exchange server computer or if server cannot reached. verify the configuration,and if persists,you may ask in exchange forum see whether there possible issues.

getting SID out of NT4 PDC or BDC

how can listing of usernames , sid out of nt4 domain controller? far have been able see sid's users have logged on physically controllers not users in nt4 domain. technet hi, nt server has been unsupported long time,  uh..from 2005? nt server tools available nt hard find not mention meet needs here. check here see if here:

MBSA (Microsoft Baseline Security Analyser)

microsoft baseline security analyzer (mbsa) easy-to-use tool designed professional helps small- , medium-sized businesses determine security state in accordance microsoft security recommendations , offers specific remediation guidance. improve security management process using mbsa detect common security misconfigurations , missing security updates on computer systems. if have questions it, please post it. hello, and question mbsa is?

Restar-computer wait for next command

hi, in script want restart  a server , wait until server run next command. i know in posh 3 can use -wait need use posh 2 what best way?  restart-computer  -computername $svr  -asjob thanks you a endless loop until server again restart-computer $server do { sleep 10 # sleep 10 secs, test ping }while (!(test-connection $server)) issue see is, can successful ping, if server isn't up, , still booting. depending on next tasks, may or may not run correctly.

DirectAccess Across Domains

we have direct access deployed in our production

Win2008r2 as iSCSI initiator and target?

i have backup server running win2008r2 veeam. it's using builtin iscsi initiator connect storage. i'd serve storage that's directly connected (dell md1000), backup server.  can run microsoft iscsi software target software acts target? break existing iscsi initiator settings? hi carltonw1, my lab 2012/r2 . i installed new 2008r2 , seems doesn't support iscsi connect . best regards elton ji we trying better understand customer views on social support experience, participation in interview project appreciated if have time. helping make community forums great place. Windows Server  >  Windows Server General Forum

Configure to never prompt for reboot?!?

i have 700 stand alone machines need point @ wsus server via registry settings.  testing now, have dozen pointing there now.  @ of locations getting prompted "updates have been installed , system needs restarted" -- or effect.  is there way can supress , windows update prompts?  these systems pos terminals.  - au scheduled friday @ 1am , got call location getting prompt (12 hours later).  these machines on automatic schedule reboot - happen. here registry settings:   [hkey_local_machine\software\policies\microsoft\windows\windowsupdate] "wuserver"="http://wsus.retail.mydomain.local" "wustatusserver"="http://wsus.retail.mydomain.local" "elevatenonadmins"=dword:00000000 [hkey_local_machine\software\policies\microsoft\windows\windowsupdate\au] "noautoupdate"=dword:00000000 "auoptions"=dword:00000004 "scheduledinstallday"=dword:00000006 "scheduledinstalltime"=dw

access is denied

hi, can answer me such strange issues. i have belong to  domain administrators , domain admins d drive on windows server 2008 r2, when trying modify file, indicate me "access denied"   thanks, charles how troubleshoot ntfs , share permissions   also disable uac, on 2008 r2. to turn off uac click start , , click control panel . in control panel , click user accounts . in user accounts window, click user accounts . in user accounts tasks window, click turn user account control on or off . if uac configured in admin approval mode, user account control message appears. click continue . clear use user account control (uac) protect computer check box, , click ok . click restart now apply change right away, or click restart later , , close use

Strange OCSP response by the Online Responder

hi, when run certutil -verify -urlfetch on 2 different certificates issued same issuing ca, response quite different , raised concern online responder not working should. here 2 outputs.. output nr1. crl (null): issuer: cn=server fqdn thisupdate: 2015-04-14 21:05 nextupdate: 2015-04-22 09:25 39c5508bc895eef3e97d8b611d1fa1fc17d3db19 issuance[0] = 1.2.752. vgc-pki cps application[0] = client authentication application[1] = server authentication output nr2. crl 323e: issuer: cn=ca logical name thisupdate: 2015-04-14 22:05 nextupdate: 2015-04-22 10:25 222195864225835a025a52015d5dca5fc2c71f30 issuance[0] = 1.2.752. vgc-pki cps application[0] = remote desktop authentication why first output missing crl number , why produce response server fqdn , not ca logical name? by way, running 2012 r2 on , online responder. please me understand. kind regards mikael hi 

Archivo gpedit.msc

que tal amigos bueno tengo el siguiente problema quiero editar algunas directivas con el archivo gpedit.msc pero algunas no me permite como por ejemplo la directivas de contraseñas. trabajo con windows server 2003 r2 standar edition sp2 saludos. en un servidor en grupo de trabajo, e iniciando sesión con un administrador, se puede cambiar perfectamente la directiva de contraseñas. si no eres administrador directamente no abre el gpedit. otro es el caso si el servidor es un controlador de dominio, en cuyo caso aparecen deshabilitadas las opciones si entras por gpedit.msc ya que se deben manejar nivel de la default domain policy por favor, explica cuál es exactamente el síntoma porque la expresión "no me permite" no provee información para poder ayudarte ¿están deshabilitadas? ¿no abre el cuadro? ¿no abre el gpedit? guillermo delprato - mvp-mct-mcitp-mcts-mcse mcitp: server administration mcts:active directory/network infrastructure buenos aires, argentina

Account password policy not applied on all domain controlers

hello, i have following problem: * have default domain policy linked @ domain level. * domain controllers in same ou (domain controllers) * no block inheritance enabled on domain controllers ou * default domain policy set enforce. , have no other password policies * domain functional level 2003 dc1 getting default domain policy + pw policy according rsop and result dc2 , dc3 getting default domain policy not account policy's ( password policy any idea? thanks, arjan hi arjan, based on research, in each domain, gpmc uses same domain controller operations in domain, pdc default, in order avoid synchronization issues. would please tell dc1 pdc emulator ? if yes, behavior normal, can refer kb article below: some security policies displayed "not defined" in rsop snap-in on windows server 2003, 2008 or 2008 r2 based domain controller you can verify if account policies have been replicated dc2