
Showing posts from August, 2013

Get-Aduser question

hi want retrieve users password expire in less 10 days. so far script goes: #this gets number of days expiry $daystoexpire = (([datetime]::fromfiletime((get-aduser -identity $user -properties "msds-userpasswordexpirytimecomputed")."msds-userpasswordexpirytimecomputed"))-(get-date)).days #this gets users $users= get-aduser -filter {(passwordneverexpires -eq $false) -and (enabled -eq $true)} -searchscope subtree -searchbase "ou=contoso,dc=com" -properties * i want pipe $daystoexpire $users users $daystoexpire -le 10 or can modify this  $daystoexpire = (([datetime]::fromfiletime((get-aduser -identity $user -properties "msds-userpasswordexpirytimecomputed")."msds-userpasswordexpirytimecomputed"))-(get-date)).days to filter inly property "msds-userpasswordexpirytimecomputed" has value -le 10? another way trying  is creating new object again shows users , daystoexpire, want to display users day

Site-to-Site VPN between Windows Server 2008 R2 and Sonicwall

hi i got stuck creating site-to-site vpn between sonicwall tz 210 , windows server 2008 r2. on sonicwall receive error no_proposal_chosen. i checked settings on both sides , looks identical.  on sonicwall side settings are: authentication type: ike using preshared secret phase1: exchange: main mode dh group 2 encryption: 3des authentication: sha1 life time: 28800 phase2: protocol esp encryption 3des authentication sha1 life time: 3600 on windows server side: key exchange settings: sha-1 3des d-hg2 (default) key lifitemes 480 minutes sessions 0 key exchange option: use diffie-hellman enhanced security marked. data protection settings: esp sha-1 3des 60/100.000 require encryption connection security rules - marked. authentication method: preshared key please advise.   not surprised. never have tried because expect fail. never try without identical devices @ both ends.   bill

Which edition I shall select for our VMs

windows server 2012 r2 essentials, latest version of windows small business server essentials, offers flexible, affordable, , easy-to-use server solution small businesses 25 users , 50 devices. hi all, the above copied windows server 2012 r2 essentials datasheet. our hyper-v host server windows server 2012 r2 datacenter edition. going deploy about 10 virtual machines windows server 2012 r2 os under host server offer infrastructure service ad/dns/dhcp/print/sccm/nps/wsus/antivirus/etc. have serveral qusetions os edition of vms. how understand "up 25 users" windows server 2012 r2 essentials? how understand "up 50 devices" windows server 2012 r2 essentials? there hundreds of users in our organization. edition shall select vms used infrastructure service ad/dns/dhcp/print/sccm/nps/wsus/antivirus/etc? essentials? standard? datacenter? thanks, 高麻雀 the 25/50 rule (though technically features still function 75) just caps of features essentials has offer si


i'm using openvpn on linux uses aes-ni significant performance improvement.  since not devices have openvpn client available, add l2tp , sstp vpns using windows server 2012.  unfortunately not finding whether routing , remote access in windows 2012 uses aes-ni when cpu supports it. does rras in windows server 2012 use intel's aes-ni on supported cpus speed l2tp vpns use aes encryption? can windows server 2012 utilize aes-ni sstp vpns, goes through iis?  hi daviddemk, firstly, l2tp message encrypted 1 of following protocols using encryption keys generated ike negotiation process: advanced encryption standard (aes) 256, aes 192, aes 128, , 3des encryption algorithms. quote vpn tunneling protocols and, according article of intel, aes-ni instructions can used in application uses aes encryption. aes used in several applications such network encryption, disk , file encryption applications. file-level , disk encryption applications use aes protect dat

Direct Access Windows Server 2012 on AD and DNS 2008

Add-MailboxPermission - Removing Automapping Piped Command

hi all, i'd remove automapping based upon csv of users via piped command.  i'm pretty close, cannot figure out way structure last portion in remove automapping. for example if query specific mailbox user has full rights "supdude": [ps] c:\>get-mailboxpermission -id | where-object { $_.accessrights -eq "fullaccess" -and $_.isinherited -like "false" } | ft -auto identity                                   user          accessrights isinherited deny --------                                   ----          ------------ ----------- ---- thedomain/users/supdude thedomain\dudethathasfullrights {fullaccess} false       false i'll extract "supdude" csv header of removeautomapping , csv called "removeautomapping.csv" , run following piped command: [ps] c:\>import-csv c:\temp\removeautomapping.csv | foreach { get-mailboxpermission -id $_.removeautomapping } | where-object { $_.accessrigh

SPNs, WCF and Impersonation

hi, i have nlb cluster pointing 2 windows server 2008 r2 (iis 7.5) web machines containing web site uses impersonation. web site runs under app pool running domain account. web site calls wcf service on separate windows server 2008 r2 (iis 7.5) machine. i have not managed wcf call working receiving typical "the http request unauthorized client authentication scheme 'negotiate'" error. have tried setting impersonation , delegation on wcf service no luck. my question follows: i have spns setup domain account running application pool , cluster url, because web site uses impersonation, mean need setup spns actual user account being impersonated? if browse directly 1 of machines (instead of going via nlb cluster) wcf call works! not sure why works in case , not when browse cluster? all machines have been setup trusted delegation. any ideas? thanks! 1) no - should not necessary 2) far understand, expected (

ForestDNSZone fsmoRoleHolder

Guest Cluster Using a Shared Virtual Hard Disk and Replica

Clients not installing updates from Downstream WSUS Server

hello, this first post in technet, new administrator please bare me. initial setup follows: upstream wsus server named bak-wsus1, downstream server name atl-wsus1; atl-wsus1 replica. have made wsus servers site based through gpos named wsus(bakersfield), wsus (atlanta), remote sites , computers added wsus (atlanta) gpo , report atl-wsus1 server should, same true wsus(bakersfield) computers. every computer joined wsus(bakersfield) gpo reports bak-wsus1 server (as stated) , receives updates approve them, however, approved updates not install on computer reporting atl-wsus1 server. when checking reports on server shows sites "approved install" computers "not installed".  i have forced remote clients wuauclt /resetauthorization /detectnow. when checking downstream server status shows following:  mode: replica installed/na: 0% last synchronization:(today). servers infact syncing, downstream server has files install, or atleast thats file status says.  any

User profile services fails to create on 2008 R2 (Desktop Services)

i have working issue few days - , summarize: its´s  virtual unit. (win 2k8 r2 x64) i started suspecting network  - or host issue (running on legacy esx) issue related number of users – user profile service can´t create either local or romaing profile but problem seems more in area of "user specific" instead of periodic.. (host, network or load in general) the error "users logged on temporary profiles" – hence no local or roaming profile created   a lot of 1509 - user profile service cannot contacted 1511  cannot locate profile 1500  network issue after has been tried (local profiles /host moved esx platform / been around issue hgfs (wm)// share / rights , on) i have used :  l ogman -start profiletrace -p {eb7428f5-ab1f-4322-a4cc-1f1a9b2c5e98} 255 3 –ets   to create few traces - cant read ? is there nother way enabled verbose logging on specific service - or piece of software internal use ? / jeppe hi,   based on search, above events

Win10 ENT 10049 - Can't login. Can't get past legal notice.

2008 R2 Not detecting Network

i have had job dropped on me , struggling. have installed win2008 r2 on dl380 g4. seems ok. however, have router, hub ethernet dl380. dl380 cannot connect network. have absolutely no idea start. have checked obvious, cables ok, drivers there etc etc. aim dl380 able see internet can teamviewer or rdc it. can give me link step step guide, or areas need looking at. like say, have googled links seem come trying set 2008 dhcp server, not want do. machine hanging on network, happens running 2008 many in advance wow! no replies despite several views. never knew such difficult task. if falls down on first step going if there problems! i cannot believe this! box 2008 cannot connect network broadcasting dhcp! has 2008 settings, question , settings should looking at? spend day working on boolean logic , ladder, stuff way more weird that! 2008 dummies @ side , glosses on setting networks, assumes dummy knows set up! in case means dumber dummy!

Upgrade from MS Windows Server 2008 R2 Standard to MS Windows Server 2008 R2 Enterprise

dear support, i have installed ms windows server 2008 r2 standard exchange server 2013 enterprise on new server. have discovered standard edition can support 32gb ram max have installed 48gb ram already. server can't use remaining 16gb ram. know exchange server 2013 has used more memory finally. our purchased license product ms windows server 2012 r2 standard allows downgrade ms windows server 2008 r2 enterprise edition. because have installed server software , applications ( exchange 2013 cu8 , symantec backup exec 15 ). can't reinstall server os , applications in order upgrade ms windows server 2008 r2 enterprise. have searched information website, can find 1 link teach how upgrade 2008 std ent without re-install os. true , no other side effect? pls advise. 1. 2. if ok, can use 489j6-v

WSUS group policy issue

RD Licensing

my rd licensing manager activated , showing "windows 200 server - built-in ts per device cals" unlimited , 2 "windows server 2008 or windows server 2008 r2 : installed per device cals (ts, rds or vdi)" volume license 200 cals. there 2 of these went through again double check configuration , added additional mistake. covered these , have cals (2700 believe) on 1 licensing server. need 120 cover our rds project.     the 2008 r2 terminal server remote desktop session host configuration returns number of rds cals available clients: 400. correct 2 200 cals above adds 400.     my concerns rd licensing manager not showing cals in use , constant notification of "no remote desktop license server available" being shown users, though can see 400 available licenses. i have gone through multiple technet documents , set correctly. any appreciated have 71 days left before runs out , 120 users unable work. all servers new build on new hardware , da

Port opening!

Help needed with certificates for RDS Host servers

hi, we have 4 rd session-host servers in our network. 4 servers member of ts farm. have ts gatway server. i managed give tsgw server certificate need support on over rds servers. what happens? when user connects farm, warning pops telling me certificate not issued trusted ca. because rds servers using self signed certificates. because servers farm members user can presented warning several times when session being redirected. how rid of these warnings in our lan on internet? certificate type need? thanks in advance. jasper kimmel hi jasper, server os environment? yeah, certificate related warnings can disappear purchasing certificate public ca. access farm outside environment can buy wildcard certificate. , yes, related queries solved article provide in previous comment. the easiest way certificate, if control client machines connecting, use active directory certificate services.  you can request , deploy own certificates , trusted every machine

CA - Diferent VSIDs same RRID comunication (how do we configure routing between different VSIDs in the sam RRID)

On Improving Windows' Responsiveness

in previous life became familiar internal operating system algorithms. mainframe used called "time-sharing" machine. became obvious cannot serve dozens of logged on users equitably if rely on simple round-robin cpu dispatch scheme. vendor designed , implemented robust scheme ensured every user got slice of machine resources. no 1 user monopolize machine detriment of others. windows appears time slice round-robin scheme. pays no attention processes monopolize machine excessive i/o activity. that's when programs launch display not responding messages. aforementioned vendor apportioned time slices according standard units of processing doled out resources measured not cpu utilization by i/o utilization. perhaps in next round of windows changes, more attention paid such improvement, include giving boost user interested in seeing progress fastest evidenced clicking at, , less attention rearranging operating handles. example, new incantation finding control panel in win

Event id 1085 and 1091 in application tab in event viewer logged every 5 minutes

Best replacement for the msg.exe in windows

TCP error code 10061

Cambias potiticas de contraseñas en servidor standard 2008

queridos amigos: entro la directiva de contraseñas en servidor 2008 standard para cambiar las politicas de contraseñas le doy boton derecho del mouse sobre cualquiera de las opciones pero no puedo cambiar nada porque la opcion me sale en color gris y me es imposible cambiar cualquier opcion. favor ayuda como hago para que me aparezca en color negro y pueda cambiar las opciones de contraseñas. gracias lgmc podrias decirnos donde estas intentando hacerlo? queres modificar la políticas locales de uns ervidor o del dominio? el usuario con el que estas intentando hacerlo, que permisos tiene? moretti maximiliano mcts - mcitp - mcsa -

how to share file between windows server host and hyper-v windows server ??

cannot delete resource from cluster

Install Windows Server 2012 on a HP 3500 Pro with fails (Windows 8 Key in BIOS)

Copy text from Guest to Host

Blank page during ADFS Authentication on Windows 10 PC

Official Microsoft Windows Server 2008 R2 Standard SP1 ISO updated file download link

Shared drive missing after one folder created under a folder which enabled 'Access-Based Enumeration'.

install software only if Role="something "& Environment ="something2"

Windows Server 2012 Essentials BPA reports incorrect certificate

windows 2003 hard drive is full, how to fix it

Easiest way to support multi user svn access over the internet?

Changing the Cluster Disk owner node

BCDEdit pae and page file

External Domain Trust Removal

Fix sync center's errors/conflicts through server

VSS Issues during backup

server running windows 2008 sp1 , having vss issues. when attempting run backup, backup fails information in event log information below displayed.  can disable vss , run our backup software fine.  reboots not solve issue , not able backup exchange without vss. please let me know if have suggestions. log name:      application source:        vss date:          2/10/2010 10:21:08 am event id:      8194 task category: none level:         error keywords:      classic user:          n/a computer:      description: volume shadow copy service error: unexpected error querying ivsswritercallback interface.  hr = 0x80070005. caused incorrect security settings in either writer or requestor process. operation:    gathering writer data context:    writer class id: {e8132975-6f93-4464-a53e-1050253ae220}    writer name: system writer    writer instance id: {96229128-c70c-44dd-8e45-985e3183aafe} event xml: <event xmlns=" ">   &