Posts

Showing posts from January, 2015

How do I give an AD account "Directory Sync" rights?

hello, for sharepoint 2010 need give ad account "directory sync" rigths or how do this?  i've looked in active directory can see how this. thanks on nc head (partition) give account �??replicate changes�?� see: http://technet.microsoft.com/en-us/library/hh296982.aspx cheers,<o:p></o:p> (hopefully information helps you!) jorge de almeida pinto | mvp identity & access - directory services ------------------------------------------------------------------------------------------------------- * posting provided "as is" no warranties , confers no rights! * evaluate/test before using/implementing this! * disclaimer: http://jorgequestforknowledge.wordpress.com/disclaimer/ ------------------------------------------------------------------------------------------------------- ################# jorge's quest knowledge ############### ###### blog url: http://jorgequestforknowledge.wordpress.com/ ####

How to have users change their domain password who only access the domain through file shares??

how can users change domain password access domain through file shares??  users access filer server through network share , not log , remote servers or log domain. can access web pages on domain? we used use .hta file (can't find @ moment) users sat off on seperate domain no trust, had on desktop. but think web page easier, have @ how use iisadmpwd password change pages: http://support.microsoft.com/?id=907271 Windows Server  >  Windows Server General Forum

First prompt regarding the password change

domain password policy in our domain weak (blank passwords, no expiration, etc). in near future plan enable of password settings including minimal password length & m ax password age . receive prompt new password @ next logon, or prompted after max password age days + next logon?   many users have enabled password never expires property @ account properties. assume have disable property before enabling new password settings?   we posses win server 2003 r2 , xp & 7 clients. existing passwords that 1) set never expire : never prompted update password meet new criteria.  if manually change new password must meet new minimum password length/complexity requirements.  if remove password never expires setting they fall #2 or #3 below 2) are >= to the max password age requirement: force change password @ next logon , must meet new minimum password length/complexity requirements. 3) < max password age requirement: nothing happes.  users prompted when pass

How do I setup Remote Desktop Licensing with an MSDN subscription?

i have msdn subscription , i've installed windows server 2008 r2 remote desktop services. i've installed rd licensing server need install licenses. how do this?  don't have keys or other license numbers use. following webpage says can configure it, dont specify access keys. http://msdn.microsoft.com/en-us/subscriptions/aa948876.aspx i did 1 of our instructors wanted set permanent teaching environment. discovered (by talking microsoft) -our- msdn/dreamspark premium accounts not supply rds user licenses. had purchase them through our campus agreement along server 2008 user licenses. good luck! Windows Server  >  Windows Server General Forum

RDS 2012 R2 (U1) Cofiguring Client Services

i have rds 2012r2 update 1 single box, no farms etc. desktop experience installed is still possible set things max colour depth, show window contents while dragging on session host in version? it under 2008r2, can't seem find options in 2012r2 hi, yes, in server 2012 r2 rds server generates .rdp files automatically using settings configure deployment , collection.  if need use custom .rdp settings, example, disabling font smoothing, need use set-rdsessioncollectionconfiguration powershell cmdlet -customrdpproperty parameter: set-rdsessioncollectionconfiguration http://technet.microsoft.com/en-us/library/jj215443.aspx if clients rdp 8.0 or rdp 8.1 (preferred) recommend test without changing of experience options first, if feel need change option thoroughly test make sure changing benefit experience.  starting rdp 8.0 major changes made rdp protocol.  intended detect connection quality automatically , adjust experience in real time.  example, on low bandwidth conn

How to install Windows Server 2012 with GPT partition on a clean hard drive?

hello, i'd know how install windows server 2012 standard edition gpt onto clean hard drive disk no partition yet? know default os installation mbr partition, if want system partition gpt partition after windows server 2012 standard installation, how do? thanks, jacky hello, your hardware needs efi, check if there bios settings allow hardware change efi system. setup checks if hardware efi or using mbr , install accordingly hardware set mbr boot mbr disks hardware set efi boot gpt disks.. so hardware determining option available setup use. thanks, darrell gorter [msft] posting provided "as is" no warranties, , confers no rights. vamt - volume activation management tool - download link http://www.microsoft.com/downloads/details.aspx?familyid=ec7156d2-2864-49ee-bfcb-777b898ad582&displaylang=en Windows Server  > 

After some updates screen gets weird. Only CMD works, all GUI loses all text below icons and other things

 gui showing windows out of position in fact, gets difficult explain. it´s vm under hyper-v , problem there, in rdp session some gui elements unavailable, right-click, menus, start menu, got cut in half or in wrong place even in safe mode, impossible use in gui, cmd , powershell ok control pane, explorer, gui elements gone! i´m thinking re-installing win2008r2 "over" current install and/or updating virtual machine additions have screen captures , i´m trying figure out best way share iamges in forum solved! i´ve tried reconfigure tha virtual hardware.. nothing. so i´ve decide radical approach: reinstall os again, preseving data. so, i´ve used setup.exe while os running, take long time, come normal. Windows Server  >  Windows Server General Forum

Password Policy

i have been working in in a helpdesk capacity few years , have been asked my management team implement password policy 1500 people.  i need propose solution used across operating systems on site.  knowledge have 114 servers using windows sles , solaris 10.  of windows clients , servers on active directory , first plan bring unix , linux clients , servers onto ad using quest or similar , once these domained apply password policy across domain.  not familiar enterprise password policy , looking ideas on how can maybe implement single sign on client passwords (as have several passwords remember) , have higher level logon helpdesk day day admin work on servers password resets , user creation, etc,  and sort of high level password locked in safe used either server maintenance and/or server configuration. any ideas or appreciated. hi, far know, active directory doesn’t support non windows clients. if need apply password policy unix or linux clients, may need third party products. regar

Change Terminal Licensing server

hi, have terminal licensing server 3 terminal servers. now, want migrate licensing server one, without interrupting users. supported way? br, james hi,     please refer following article describes how migrate windows server 2003 ts license server:   how move terminal services cals 1 license server in windows server 2003 or in windows 2000 server   http://support.microsoft.com/?kbid=953918   migrating windows server 2003 ts license server   http://blogs.msdn.com/b/rds/archive/2009/03/06/migrating-a-windows-server-2003-license-server.aspx       thanks. Windows Server  >  Remote Desktop Services (Terminal Services)

WSUS is not pushing out updates to PC's

i had previous version of windows upgrade software , wait 10 days push out approved updates pc's , monitor if updating.  had continue crash , disappear have latest version installed.  it shows me pc's behind on updates 30 total on 300 updates needed cannot find make push them out pc's.  missing something?  can wsus function or each pc pull makes no sense me.  if aware or can please appriciate it. hello, wsus doesn't push, according configured gpo workstations machine contact wsus server , follow gpo setttings apply updates. on machine updates not applied run rsop.msc , check settings if wsus settings applied correct. if case clear testing c:\windows\softwaredistribution folder, therefore stop automatic update service, delete folder , start service, recreates folder. now run on client machine "wuauclt /detectnow /resetauthorization" from the run line. best regards meinolf weber disclaimer: posting provided "as is" no warranties, , confers no r

Map drives

i have been using vbs logon script in gp map network drives.  has been working on 4 months.  2 days ago drives no longer being mapped.  not feel permission issue user can double click vbs script , drives map.  using windows server 2008 remote desktop (terminal server) hi, are sure script still executed? make modifications script writes output of command i.e. textfile. may ask why using vbs file? suggest using gpo preferences this. it's easier set , maintain , can drivemapping out of box it. example see technet blog post: http://blogs.technet.com/b/askds/archive/2009/01/07/using-group-policy-preferences-to-map-drives-based-on-group-membership.aspx kind regards, freek berson http://www.microsoftplatform.blogspot.com wortell company website Windows Server  >  Remote Desktop

Windows 7 SP1 RDP version disconnects when remote controlling in TSM

i updated windows 7 workstation sp1 , whenever remote control client in our windows 2008 sp2 terminal server, disconnects client's session. suppose can downgrade windows 7 doesn't happen, there fix other downgrading? hi, please apply followinig hotfix server 2008 sp2 terminal server , verify problem solved: a shadowed windows server 2008 terminal services session disconnected computer running windows server 2008 r2 sp1 or windows 7 sp1 http://support.microsoft.com/kb/2523307 thanks. -tp Windows Server  >  Remote Desktop Services (Terminal Services)

TCP/IP failed to establish an outgoing connection because the selected local endpoint was recently used to connect to the same remote endpoint.

Image
tcp/ip failed establish outgoing connection because selected local endpoint used connect same remote endpoint. error typically occurs when outgoing connections opened , closed @ high rate, causing available local ports used , forcing tcp/ip reuse local port outgoing connection. minimize risk of data corruption, tcp/ip standard requires minimum time period elapse between successive connections given local endpoint given remote endpoint. both error show on server after file share can't use require logon folder or permission  Windows Server  >  Windows Server 2012 R2 Application Certification (Logo) program and test tools

How do I remove the "Automatic Browser Configuration" from a GPO?

Image
hi - in our company, use default domain policy (ddp) selection of settings (as expected).  have started using proxy, , since want setting affect users, have created new gpo , defined proxy settings within.  however, these settings not being applied of users.   after doing gp wizard, turns out the ddp winning, , overrides setting.  thing enabled in ddp "automatic browser configuration".  setting 2 tick boxes, both of unticked.   want disable ddp, no matter do, , cannot stop ddp controlling option. is normal beahviour?   missing? many thanks hi, please check threads: cannot remove  ie maintanence settings group policy http://social.technet.microsoft.com/forums/en-us/winservergp/thread/4caa4c91-5cce-49bd-8e92-db04fbdbfa07/ how config proxy settings using group policy management http://techlib.barracuda.com/display/wsflexv41/how+to+configure+proxy+settings+using+group+policy+management hope helps! regards. vivian wang technet community support

Hyper-V 2012 R2 QoS for a specific set of VMs?

i'm trying figure out how setup scvmm 2012 r2 logical switch support qos specific set vms. specifically, have subnet have variety of vms running, within subnet have handful of vms need unique software qos setting. possible? blog: www.derekseaman.com, vmware vexpert 2012/2013 so saying have 1 subnet 2 different types of vm traffic, 1 on want qos , other on not want qos? if so, don't think can that.  should create subnet on want enforce qos , place vms on subnet.  think limitation of networking protocols. . : | : . : | : . tim yes that's want do. subnet "a", , vms need qos x while others can use default qos of y. blog: www.derekseaman.com, vmware vexpert 2012/2013 Windows Server  >  Hyper-V

Drive Mappings Work fine for PC's, not for laptops...

hey everyone, wondering if has every came across before.  have set of laptops won't allow gp map drives need mapped.  i've tried can think of.  i've moved laptop computer object pc ou mapping works, no luck.  i've tried different users, nothing.  running gpresult shows it's being applied, isn't.  there sort of preferences can changed / need set on individual computers might affect this?  said, it's laptops have issue, pcs working fine, know gpo works.  weird, because it's user based policy.  got me? all systems running xp, server ws 2008 sp2 64-bit thanks hi,   would please describe how did configure , apply gpo in detail?   if use gpp apply drive maps gpo, should note drive maps gpp item under user configuration. in addition cse, please make sure gpo applied ou includes laptop users.   if use startup gpo, please make sure laptops in same ou of other pcs work fine drive maps.   for more troubleshooting info

How to restrict RDC [Remote Desktop Connection] to a few programs

i restrict desktop staff connect server via rdc see desktop limited , shows icons 2 or 3 programs access.   i'd them not see other program files nor access control panel, etc when they're logged on via rdc.   i'm using server 2003   if attempt restrict access via gpoe (group policy object editor) blanket restricts me, admin, not want.  want restrict non-admins   i can not use group policy management, says needs part of domain user account how can this??  yes newb (please patient.. , step step instructions appreciated)   thanks i restrict desktop staff connect server via rdc see desktop limited , shows icons 2 or 3 programs access.   i'd them not see other program files nor access control panel, etc when they're logged on via rdc. i'm using server 2003   if attempt restrict access via gpoe (group policy object editor) blanket restricts me, admin, not want.  want restrict non-admins i can not use group policy management, says needs

Merging a differencing VHDX and it's parent to a new disk using powershell

hi, i'm trying figure out how use powershell merge differencing disk it's parent, store result in new vhdx. using "edit disk" wizard possible: on "configure disk" page can select "to new virtual hard disk". however, using "merge-vhd" cmdlet in powershell not possible achive same... when try merge-vhd -path differencing.vhdx -destinationpath new.vhdx i following error: merge-vhd : new.vhdx not existing virtual hard disk file can point me in right direction please? when it's possible in gui, there has be a way achive same  goal in powershell... thanks christian -destinationpath refers child in tree, not different vhdx. try copying .vhd/.avhd files new location.  perform merge , rename. . : | : . : | : . tim Windows Server  > 

Determine forest of domain

hello community     when have domains in different forests on same network how know forest domain in, forests have names, or way differentiate 1 forest another?     thank you     shabeaut check out link:  http://technet.microsoft.com/en-us/library/cc978004.aspx to check forest , domain can go command prompt , type ipconfig /all c:\windows\system32>ipconfig /all windows ip configuration    host name . . . . . . . . . . . . : mycomputername    primary dns suffix  . . . . . . . : contoso.local    node type . . . . . . . . . . . . : hybrid    ip routing enabled. . . . . . . . : no    wins proxy enabled. . . . . . . . : no contoso.local - forest root , domain name also means 1 forest , 1 domain ============================= c:\windows\system32>ipconfig /all windows ip configuration    host name . . . . . . . . . . . . : mycomputername    primary dns suffix  . . . . . . . : contoso.exxcontoso.local    node type . . . . . .

LDAP_MATCHING_RULE_IN_CHAIN with sAMAccountName

hi, is possible use ldap_matching_rule_in_chain samaccountname instead of dn? e.g. until have filter "(member:1.2.840.113556.1.4.1941:=cn=jack public,cn=users,dc=domain)" now great if login name instead of dn because save 1 query (for retrieving dn specific login name). tried around with "(member:1.2.840.113556.1.4.1941:=jpublic\domain)" "(member:1.2.840.113556.1.4.1941:=jpublic\\domain)" "(member:1.2.840.113556.1.4.1941:=jpublic\\\\domain)" but not work.   as alternative: maybe there kind of "variable" can replaced by bind dn? e.g. "(member:1.2.840.113556.1.4.1941:=%dn%)" where %dn% gets automatically replaced bound dn? (e.g. cn=jack public,cn=users,dc=domain)...   regards, peter   peter - far know, need determine dn in order use filter in question - need first identify dn based on samaccountname... hth marcin Windows

change IP Address of domain controllers to match old IPs

dears, i have 80 ad sites, in ho have 2 dcs 2003 sp2  "dc01 , dc02", , 1 dc in each branch site,  introduced 2 new domain controllers 2008 r2 (dc03, dc04) in ho , want swap ips new dcs match ip address of old dcs 2003  in ho...will break replication between branches & ho ? since branches dcs have dc01 or dc02 replication partners , i'm afraid once change ip address  branches dcs can't communicate replication partners  dns name resolved wrong ip your appreciated... thanks, branch dcs accept incoming dns replication fbecause it's authenticated. you can use scenario minimize replication risks 1. set dc02 bridgehead server 2. swap ip-addresses between dc01 , dc03, run ipconfig /registerdns , dcdiag /fix 3. check replication status 4. set dc03 bridgehead server 5. swap ip-addresses between dc02 , dc04, run ipconfig /registerdns , dcdiag /fix 6. check replication status you should check firewall settings before operations. after c

DFS Cloning - how to get this working

hello, i ran problem i'm hoping able me with. next year installing 2 servers in 2 offices. servers replace our current file servers. our current file servers run windows server 2003, , new ones run server 2012 r2. with current setup, data on server-2003-a backed server-2003-b each evening using following robocopy command (initiated on server 2003-b): robocopy \\server-2003-a ip address\homedir d:\homedir /sec /mir /log:something.txt /w:3 /r:2 /ndl /np with new servers want implement dfs replication, current servers not have dfs installed. and gets tricky. the recommended way, know works fine, pre-seed data copying 1 of servers another, both of servers ending in same replication group. want different. want copy: - server-2003-a server-2012-a - server-2003-b server-20012-b and use server-2012-a , server-2012-b in replication. i ran test. used robocopy command on both server-2003 machines: robocopy.exe "d:\homedir\something" \\server-2012\e$\homed

RDS 2012R2 - Server Manager not connecting to correct Broker

ok, i've got issue server manager on my broker servers not connecting broker service on local server rather trying use broker service on other broker servers, which are listed in server list. @ point may sound strange i'll go through environment first before going further. i've got four rds environments set up. 2 of environments are configured with one broker server , 2 session hosts each , other 2 environments each configured broker, web access , session host on a single server. licensing role installed on the broker servers larger rds environments broker01 configured primary license server for all rds environments , broker02 server configured secondary. rds environment 1: broker01 - web access, broker, license server (primary) sessionhost01 - session host sessionhost02 - session host rds environment 2: broker02 - web access, broker, license server (secondary) sessionhost03 - session host sessionhost04 - session host rds environment 3: management0

state of network interfaces fluctuating in cluster netint command

the problem have cluster architecture in there 2 node connectivity between 2 node in cluster netint commands show unreachable 5-10 mins , automatically 20mins or so. , process continues during unreachable state node ips pinged successfully.    c:\winnt\profiles\administrator>cluster netint listing status available network interfaces: node                       network                    status -------------------------- -------------------------- ------- m101ap1b                   ipn100-2                   unreachable m101ap1a                   local maintenance          failed m101ap1a                   heartbeat 2                up m101ap1b                   ipn100-1                   up m101ap1a                   ipn100-2                   unreachable m101ap1a                   heartbeat 1                up m101ap1b                   heartbeat 2                up m101ap1b                   local maintenance          failed m101ap1b                   heartbeat 1 

Hit with Virus that executed via PowerShell Scripting. Can I disable Powershell on my network via Group Policy and what implications does that have for me.

our network hit virus unknown, o97m.crigent.  nasty macro virus targets microsoft office documents & spreadsheets , uses combination of macros , scripts via powershell.  how i disable powershell scripting via group policy? will raise issues such random application or network failures or other issues? can apply entire domain or should selective , apply workstations? network summary: windows 2008 active directoy server, 75% windows 7, 25% windows xp workstations. douglasofsanmarcos disabling windows powershell can done gpo: computer configuration | administrative templates | windows components | windows powershell from gpo description : "this setting exists under both "computer configuration" , "user configuration" in group policy editor. "computer configuration" has precedence on "user configuration." by default option restricted way on computers. i selective when apply @ all: workstations - apply test group of w

GPEDIT.MSC MISSING WINDOW 8

Image
when got windows 8 started deleted apps willie nillie. may have caused problem getting group policy editor. but of right either missing, not exit, or im dumb. i have used windows button + r , typed in gpedit.msc run , windows says "not found" please help. hi, i agree alex, first of all, should verify windows 8 version using. if windows 8, can’t see cannot see gpedit.msc, since there no group policy feature enabled in edition. regarding current issue, suggest refer following article. windows 8 gpedit.msc - group policy editor http://www.computerperformance.co.uk/win8/windows8-gpedit-msc.htm regarding comparison of windows 8 edition, refer article below. announcing windows 8 editions http://blogs.windows.com/windows/b/bloggingwindows/archive/2012/04/16/announcing-the-windows-8-editions.aspx hope helps. best regards, andy qi andy qi technet community support

Error with Synthetic Ethernet Port

hello, i'm trying create new vm associated external network adapter on hyper-v rc0. @ end of creation, vm tries start but two messages appear on host machine , vm disappears (sorry, use french version of windows server 2008 rtm) : virtual machine connection [main instruction] the application encountered error while attempting change state of 'w2008-x64-core'. [content] 'w2008-x64-core' failed start. microsoft synthetic ethernet port (instance id {7618779d-b062-48f0-b59c-00544f914653}): failed power on error 'la ressource ou le périphérique réseau spécifié n'est plus disponible.' [expanded information] 'w2008-x64-core' failed start. (vmid 59a55f8f-e60a-4f9d-9c04-3c8951dd9fc1) 'w2008-x64-core' microsoft synthetic ethernet port (instance id {7618779d-b062-48f0-b59c-00544f914653}): failed power on error 'la ressource ou le périphérique réseau spécifié n'est plus disponible.' (0x80070037). (vmid 59a55f8f-e60a-4f