Posts

NTFS permission, local users and share permissions confusion

for years now, work, file servers have shares "domain\authenticated users" change permissions on them. ntfs permissions set per security group (and in cases specific users if need be). works great, specific groups or users can access share (and whatever allowed according ntfs permissions). here @ home i'm playing hyper-v free 2016 tp3, , created share storing iso files. wanting use more powershell used new-smbshare cmdlet create share. microsoft still uses share permissions, instead of authenticated users more secure imo, surprise able access share using domain user. couldn't write, read. after digging around, found out server's local users group has domain users in it's list. reading old links why still doesn't make clear me why domain users should part of local users group of server. sounds silly me. the fileservers @ work aren't old. server 2012, i've administered them same way in 2008 r2 , 2003. can't remember ever seeing loca...

Managing multiple remote (off network) users with AD

hello! i work @ company multiple users @ client sites anywhere 1 month 1 year. 90% of users utilize windows based pcs 10% mac. currently, none of laptops on our domain. issue is, if can of our user's laptops on domain, how can manage them remotely? i've considered things may work, such creating vpn accounts users , having them 'check in' every x months. ms have out-of-the box solutions this? there externally available ad (maybe available through adfs?) utilized? any feedback appreciated. what os on laptops? have looked direct access  http://technet.microsoft.com/en-us/network/dd420463 http://technet.microsoft.com/en-us/library/dd875522(ws.10).aspx   you can search around lot more info on it.  adfs isn't solution this. thanks mike http://adisfun.blogspot.com follow @mekline Windows Server  >  ...

Server 2012 Direct Access RemoteNetworkAuthenticationFailure

hi, i have setup direct access on server 2012 , in test configuration had working fine. tried reconfigure server live environment issues have rebuilt , start again. on new build, testing windows 8 client, can connect , ping internally resources (except primary dc strange) cannot browse network shares or rdp etc. running get-daconnectionstatus returns error, remotenetworkauthenticationfailure. on da server show client being connected username field empty. my understanding of how direct access works limited feel linked certificate problem on clients. testing windows 8 becaus eit easier troubleshooting aim support windows 7 clients. thanks in advance just update on problem. use certificates our wirless network , da, had checked client had certificate foolishly wrong one. had set permissions wrong on ca certificate template our clients werent getting certificates ca. another foolish thing had done use our dc nls, because happened have https site running. did fix set...

Need to Confirm TS LIC

Image
we have ts lic server on domain we have citrix user in domain , b using same lic server in domain a, we have plan of upgrading or buying new lic  citrix migration required additional 350 lic windows 2008 r2 going remote desktop using citrix xenapp 7.5 i need confirm have 330 showing on console right information of lic in ts server. is there other tool can confirm lic count hi, i recommend confirm licenses own logging on company's vlsc account checking original purchase emails / paperwork / documentation / etc.  may have other licenses installed on server , if happens server or audited need original information regardless. based on screenshot appears have 330 2008 per user rds cals. -tp Windows Server  >  Remote Desktop Services (Terminal Services) ...

Unable to install Windows Updates - Code 80246007

when trying install of 30+ updates have backed since i've been running error: error(s) found code 80246007 after which, ask me restart, cycle through "installing updates 1-3 of 3" screen, restart, , state updates failed , roll back. system update readiness tool fails install appropriate kb well. looking @ windowsupdate.log, see these lines: 2015-02-01 13:18:47:190 7284 1dc8 handler   : warning: command line install completed. return code = 0x09380001, result = failed, reboot required = false 2015-02-01 13:18:47:191 7284 1dc8 handler   : warning: exit code = 0x8024200b i'm not sure if appropriate copy , paste more logs in here, if so, can. appreciated. when trying install of 30+ updates have backed since i've been running error: error(s) found code 80246007 0x80246007     -2145099769     sus_e_dm_notdownloaded update has not been do...

IPSec between Windows XP/2003 and Windows 7/2008 R2

i see lot of posts how people not able ipsec working between windows xp/2003 , windows 7/2008 r2 computers, don't see solutions. has been able working?  if so, how? i have same exact ipsec polices applied xp , windows 7 computers.  when try access xp comptuer windows 7 computer, works fine.  when try access windows 7 computer xp computer, doesn't.  see traffic getting windows 7 computer, being dropped.  firewalls disabled , ipsec policy set "request".  default windows 2003/xp "request" security being used.  windows 7/2008 r2 computers can communicate each other without problems, xp/2003 cannot communicate each other or with windows 7/2008 computers, shows security association has been negotiated , exists using ipsec monitor tool.  if disable ipsec server or apply customized "permit all" unecrypted policy windows xp/2003 computers, can communicate normally. there has difference between xp/2003 , 7/2008, can...

Does installing WSUS 3.0 SP2 affect IIS

i have windows 2008 r2 server running , wanting install wsus 3.0 sp2 on it.  have default website installed on server , wondering wsus iis. because dont want affect default website ideally. wsus affect iis? greatful if me asap. thanks, daniel   so wondering part of website effected, , how so? in minimal installation state (i.e. when choose install alternate v-root, named wsus administration, configured use port 8530), wsus installs virtual directory in default web site named /selfupdate that maps %programfiles%\update services\selfupdate. copies 2 files %programfiles%\update services\wwwroot ~\inetpub\wwwroot folder --  it's there support updating of legacy au clients, incapable of connecting update services source on except port 80. must have anonymous access, means dws has have anonymous access enabled also. the truth is, it's legacy resource, , go away in next release of wsus, fresh installation of windows 2000, windows xp, or windows server 2003 still r...