Posts

Showing posts from July, 2012

Import Access file

  the ssis etl server running on ssis packages doesn;t have ms access install on it.. 1 of ssis packages need grab access db is in network folder and process it .. since etl server dosn;t have ms access , keep giving me error "can not open source file". do have have ms access  installed on ssis server import access db?     no, not need have access installed. need have jet provider ole db installed.   can please post complete error message not not excerpt?   this looks permissions error - account running package not have permissions access mdb file - it's impossible tell based on information in original post. SQL Server  >  SQL Server Integration Services

KB2463332 update set of 4

i have been trying install automatic update ever , not install. hi tuttle1949, did try automatic install of sql2005 sp4?  issue happens because of cached files of windows automatic updates corrupt. please try following steps delete sp4 update windows updates : 1. go control panel -> administrative tools -> services 2. stop service "automatic updates" 3. click start -> run , type following %windir%\softwaredistribution 4. open “download” folder , delete contents of folder 5. start service "automatic updates" if still not work. please try download , update manually. if sure have installed update (kb2463332), can hide in windows update not offer update continuously. obtain sql server 2005 sp4, visit following microsoft web site: http://go.microsoft.com/fwlink/?linkid=204632 obtain sql server 2005 express edition sp4, visit following microsoft web site: http://go.microsoft.com/fwlink/?linkid=204633 regards, amber zhang

OLE DB source-SQL command: cannot use parameter with case statement in where clause

i have installed sql 2005 (built 9.0.3042) and i use ssis to populate data warehouse. create data flow task ole db source - sql command. create variable and i use parameter in sql statement: select case when year(d.data_doc)>year(r.data_cmp) r.data_cmp              else coalesce(d.data_doc,r.data_mov) end data from vratei_rma r              left join doc00 d on d.azienda = r.azienda , d.rc_data=r.data_mov and d.rc_num=r.num_mov where r.azienda=1 ,   (r.imp_anal <> 0) and r.data_mov >= ? and works. if use case statement in clause without parameter: select case when year(d.data_doc)>year(r.data_cmp) r.data_cmp             else coalesce(d.data_doc,r.data_mov) end data from vratei_rma r              left join doc00 d on d.azienda = r.azienda and d.rc_data=r.data_mov , d.rc_num=r.num_mov where r.azienda=1 ,  (r.imp_anal <> 0) and  case when year(d.data_doc)>year(r.data_cmp) r.data_cmp              else coalesce(d.data_doc,r.data_mov) end >= &

Had a previous SQL install, uninstalled by client. Now cant Install SQL Express 2005

  hi, one of our clients computers had sql version unknown installed , removed.  we have gone in try install sql express 2005 no luck following message appears: the setup fails when starting instance during setup title: microsoft sql server 2005 setup ----------------------------- sql server service failed start. more information, see sql server books online topics, "how to: view sql server 2005 setup log files" , "starting sql server manually." help, click: http://go.microsoft.com/fwlink?linkid=20476&prodname=microsoft+sql+server&prodver=9.00.3042.00&evtsrc=setup.rll&evtid=29503&evttype=sqlsetuplib%5cservice.cpp%40do_sqlscript%40sqls%3a%3aservice%3a%3astart%40x42  i can supply following log file verbose logging started: 18/03/2010  13:50:17  build type: ship unicode 3.01.4001.5512  calling process: c:\program files\microsoft sql server\90\setup bootstrap\setup.exe"   in examining setup log find setup blocks upgrade: detail_reas

RD Connection Broker and RD Web Access

i've been working on project few weeks publishing applications through rd web access , fine when using 1 server publish the rd web access portal and 1 server publish applications.  growing in number of users using application, have been trying rd connection broker working load balancing ts farm.  able configure ts farm rd connection broker , works great inside network when trying access outside, things weird.  users able connect first time , load balancing works when disconnect, can't reconnect servers run application.  major problem , can't seem figure out issue lies.  need ts gateway?  or there configuration (checkbox) missed while configuring rd connection broker? hi, yes, need use rd gateway external users.  after have rd gateway working should configure public firewall actively refuse (as opposed configuring silently drop) incoming connections port 3389. you need configure fqdn of rd gateway server in remoteapp manager rdweb have them use rdg when launching

Update Audit

we have windows 2008 r2 servers pointed wsus via gpo. without changing, removing, or adding gpos there way check online windows updates? don't want install updates, scan may needed that's available update catalog. don't want make changes system. there way powershell? will able re-check against wsus after checking against catalog? i familiar option in server 2012 don't recall seeing in 2008 r2. is there way through powershell? this ui option available in version of windows, unless has been disabled via registry or gpo. before doing online check, confirm version of wuagent date (version .256), connection mu/wu force check of wuagent version , if less offered wu/mu, wuagent auto-update. if wsus has not had kb2720211 or kb2734608 applied it, newer wuagent no longer able connect downlevel wsus. don (please take moment "vote helpful" and/or "mark answer", applicable. helps community, keeps forums tidy, , recognises useful contributio

Windows 8.1 Applocker Blocking Packaged App Installation During Deployment

Image
hi all! have run issue while deploying windows 8.1 enterprise using mdt 2013 applocker policies applied. during testing have had no issues default provisioned store apps have configured applocker policy prevent apps being installed other provided windows. when test policy on running computer appears working correctly - of original provisioned apps can run or re-installed store , other apps not install. with policy applied when machine images , joins domain none of provisioned apps download , install instead x in lower right-hand corner. have verified applocker policy culprit disabling , imaging new computer installed default apps. going on here? if policy seems work on computer during normal operation why prevent apps downloading? bug in way applocker works? the policy configured such: executable rules - enforced audit - created default rules packaged app rules - enforced - auto-created rules based on machine default configured apps one workaround considering make sur

Migration from SBS-2008 to Server 2012 R2 and Exchange 2016 running on Hyper-V

i going moving customer sbs-2008 running exchange 2007. have found information going sbs-2008 2012 essentials not server 2012r2. i sure there steps missing or not accurate migration.  i hoping have direct links steps needed move sbs-2008 [not sbs-2008r2] my goal have 4 vms running on hyper-v.  on base server 2012r2. first the  ad/dc , application server. second exchange 2016 (or if cannot there exchange 2013).  3rd accounting server, running sage 300. last server running crm program, sage/timberline application. i have been unable find specific document walk me through process. have new server sitting on lenovo rd550 rack mounted server 2 processors , 128 gb of ram. have base server installed 4 times , updates done on 4. how further can go before taking system on site to begin migration process?  do install ad , setup dc or occur during migration steps? use same domain name on sbs-2008 server or start fresh? should i install exchange 2016 or 2013, or wait until migr

Windows could not search for new udpates

windows 2008 r2 standard version trying install updates.  no wsus server. getting below error message ---------------------------------- windows not search new updates an error occurred while checking new updates fro computer. errors found code 80246002.windows update encountered unknown error. -------------- event logs: log name:      application source:        windows error reporting date:          30/08/2014 11:02:13 pm event id:      1001 task category: none level:         information keywords:      classic user:          n/a computer:      win2k8 description: fault bucket , type 0 event name: windowsupdatefailure response: not available cab id: 0 problem signature: p1: 7.6.7600.320 p2: 80246002 p3: d67661eb-2423-451d-bf5d-13199e37df28 p4: scan p5: 101 p6: unmanaged p7: p8: p9: p10: attached files: these files may available here: c:\programdata\microsoft\windows\wer\reportqueue\noncritical_7.6.7600.320_888a386a

Windows Server 2003 user rights, admin but not all!

hi all, want make user ba admin 1 cannot change rights folders(on specific directory).. possible? i'v tried(and of consultant too) never able this, if gave user many rights able change rights on folder, , if cut wasnt able on server.... local settings , gpo thru didnt find way this. anyone has clue? thanks hi, think that's impossible, because administrator can take ownership of file/folder @ time, if remove or grant deny permission user. take ownership of file or folder http://technet.microsoft.com/en-us/library/cc780020(ws.10).aspx brent please remember click “mark answer” on post helps you, , click “unmark answer” if marked post not answer question. can beneficial other community members reading thread. ” Windows Server  >  Server Manager

Hyper-v cluster node failed.

Image
hello, i have hyper-v on 3 node cluster ( node majority ) csv , one node failed due bad hard drives , wondering steps to rejoin node cluster after reinstalling os? thanks hi,   please check following post.   add 3rd node tp hyper v failover cluster http://social.technet.microsoft.com/forums/en/winserverhyperv/thread/86ba2313-8bd8-42fd-adfd-b89af38695fe   by way, please evict failed node on working failover cluster node.   vincent hu technet community support Windows Server  >  High Availability (Clustering)

Scheduled task with indefinite duration from command line

i have scheduled task set on windows 2008 r2 server runs indefinitely every 5 minutes. setting through gui works fine. however, i'm trying mass deployment via command line. can create options want, except "indefinitely" part of task. current command this: schtasks /create /s systemname /u user /p password /tn "my task" /tr c:\apps\task.bat /sc minute /mo 5 /sd 10/01/2012 /st 01:00:00 /ru user /rp password this creates task need, duration, default, 1 day. have used several combinations of /sc /ri /mo , /du parameters, , haven't been able come out indefinitely. anyone know right combination? tia! maybe you don’t have set start date or start time if want task run indefinitely every 5 minutes. this: schtasks /create /s systemname /u username /p password /tn "mytask" /tr c:\apps\task.bat /sc minute /mo 5 /ru username /rp password thanks zhang Windows Server

Script running against IIS

hi all,   i've got iis box appears have exploit script running against everyday.  when @ iis logs there multiple entries similar one:    2013-05-29 12:14:35 w3svc1 servername 192.168.10.31 /edit_image.php dn=1&userfile=/etc/passwd&userfile_name%20....   80 - 192.168.10.31 http/1.0 - - - - 404 0 2 5462 86 31   there asp.net application logs show unhandled exception has occurred @ same time (event id 1309, event code 3005 request utl trace.axd user host address: 192.168.10.31)   404 messages, script appears coming iis server (based on ip's).  how can determine if script being ran locally on box or remotely?    any appreciated,  bill iis logs show ip of requesting machine (user machine or proxy), unless machine running kind of proxy, guess 'script' running local machine. please note in circumstances, might webapplication running on iis these requests. might due configuration or programming error. the fact seems nic's ip instead of localhost (1

Reproducible Bug: Win7 RDP server selects incorrect keyboard for Mac RDP client

Image
server win7 professional sp1 x64, updates, configured in "text services , input languages" "english (canada) - us" installed services us, canadian multilingual , canadian french keyboards , ink correction. client macbook pro (retina, 15-inch, 2013), os x 10.9.5 (13f34), microsoft remote desktop 8.0.9 (build 25073), updates on mac configure rdp entry not include password.  this force win7 display login screen when remote client connects test 1 - mac configured canadian english configure mac canadian english keyboard (system preference > keyboard > input sources > + > canadian english) , remove (-) other keyboard configurations connect remote win7 x64.  the login screen display keyboard selection button in upper left corner.  hover on button reveal canadian french active keyboard.  this bug. canadian french keyboard different english keyboard.  click button reveal , canadian multilingual standard keyboards available.  you must select 1 of these

Setting up bitlocker network unlock

i'm setting bitlocker network unlock , on wds server when client sends request 2 errors.                           [wdsserver/wdspxe/nkpprov] nkp request processing failed while extracting key material. remote address: ipaddress:68, packet length: 573.                           [wdsserver/wdspxe/nkpprov] could not decrypt data private key. hresult = 0x80090010.                           ideas.  i verified on client certificate installed , thumbprint matches installed on wds server. i opened case microsoft , issue resolved now.  it ended technet article microsoft had incorrect , left out things needed used certificate. Windows Server  >  Setup Deployment

WLAN WiFi with RADIUS client with authentication in NPS Server

dear all, i have configured radius clients in nps server wlan. need add mac address in configuration (.xml) file. but not sure need add in xml file. have nps server in windows server 2008r2. and network policy need add wlan authentication  please help hi durgavaraprasad 2013, >>  i need add mac address in configuration (.xml) file. could you  show me screenshots that  would helpful identify problem? >> what network policy need add wlan authentication the following link includes deployment guide deploying 802.1x authenticated wireless access: 802.1x authenticated wireless deployment guide https://technet.microsoft.com/en-us/library/dd283093(v=ws.10).aspx if want always use mac address user identity, please set override user-name registry value 1 on nps server . for reference: mac address authorization https://technet.microsoft.com/en-us/library/dd197535(ws.10).aspx if want set both 802.1x , mac address authentication working on same nps. yo

DCPROMO query

my env: root domain (x.com child domain 1.x.com child domain 2.x.com my query want build new adc in root domain, can use primary dns ip of dc1.1.x.com. (new root adc , and dc1.1.x.com in same site per subnet)   aliahmurfy hi. depends how you’re replicate dns zones. if you’re storing dns zone forest root domain (x.com) in forestdnszones application partition. fine zone replicate dc has dns service installed in forest (assuming dc1.1.x.com has dns installed) you can read more here: http://blogs.chrisse.se/blogs/chrisse/archive/2011/04/10/are-you-storing-your-ad-integrated-dns-zones-in-the-dns-application-partitions-ncs.aspx   fyi: if you’re installing dns part of dcpromo on computer being promoted new dc, during install set self primary dns, after finished dcpromo process should set dc1.1.x.com secondary dns.   regards, ---------------------------------------------------------- enfo zipper christoffer andersson – principal advisor please

WIn 2012 Essentials not allowing client connections

hi everyone, i stuck here i've followed many tn articles , none of them seem solve what's happening me. i opened 2 brand new comps both win 7 pro , can't connect either let alone other machines win 2012 essentials server. connected i'm under 25 limit at 7 pc's (6 win 7 pro 64bit, 1 win 8 pro) the 2 new ones identical models 2 machines on server updates , patches applied win 7. i've tried ip , host name connect software going. goes stuck @ username/password screen once enter user account info or one's account "the server not available. try connecting computer again, or more information, see troubleshoot connecting computers server" now noticed other day had alert on server , ran best practices said dns issue fixed directed alert went away. also disabled other unused network adapter on server, , heck of disabled ipv6 on 1 of new machines in hopes that's not either. here few of tn articles i've looked @ none of them helpe

DC setup

question server 2008 r2 asking fqdn name new network install first domain im guessing need type in domain name.com correct hi,   during first domain controller installation, requires full domain name system (dns) name forest root domain. more detailed steps, please refer following microsoft technet article:   steps installing ad ds http://technet.microsoft.com/en-us/library/cc754438(ws.10).aspx   regards, please remember click “mark answer” on post helps you, , click “unmark answer” if marked post not answer question. can beneficial other community members reading thread. Windows Server  >  Windows Server General Forum

Raise FFL or DFL first

we had 2 w2k3 dc's in production on class c network, installed 2 new physical servers, w2k8 r2 on class b network, , each has it's own class c.  kept dc_old01/02 servers online few weeks make sure while re-ip'd static network devices new ip range, they'd still accessible via vlans on cisco switches.  then physically removed them production. production servers (reported dc_production01, ad domains , trusts): name: dc_production01, site: default-first-site-name, dc: gc, dc version: w2k8 r2, status: unavailable name: dc_production02, site: default-first-site-name, dc: gc, dc version: w2k8 r2, status: online name: dc_old01, site: default-first-site-name, dc: gc, dc version: w2k3, status: unavailable name: dc_old02, site: default-first-site-name, dc: gc, dc version: w2k3, status: unavailable operations master: dc_production01 current ffl: windows 2000 current dfl: windows server 2003 ad sites , services: subnets:  dc_production01's ip (x.x.x.x/17), 

Script to delete files created on a specific date with sepecific name

hi, is possible me powershell script delete files under folder , subfolders have following attributes 1. have name (default.*) , (index.*) 2. created on specific date 1-9-2014 3. created between specific time between 10:00 - 16:00 thanks in advance! hi, try this: $path=$env:userprofile $startdate=[datetime]::parseexact("01-09-2014 10:00","dd-mm-yyyy hh:mm",$null) $enddate=[datetime]::parseexact("01-09-2014 16:00","dd-mm-yyyy hh:mm",$null) #ps3 version get-childitem -file -path $path -include "default.*","index.*" -recurse | {$_.creationtime -gt $startdate -and $_.creationtime -lt $enddate}| remove-item -whatif #ps2 version get-childitem -path $path -include "default.*","index.*" -recurse | {$_.creationtime -gt $startdate -and $_.creationtime -lt $enddate -and !$_.psiscontainer} | remove-item -whatif luck)

Server 2012 RD Connection Broker sends connections to an unavailable server

in 2012 rds deployment have: 2 servers running rd connection broker , rd session host configured connection broker high availability 2 servers running rd gateway , rd web access rd gateway failover beautiful, if 1 gateway dies transfers connections other available gateway, end user experiences brief interruption, can rd session host also? however session host not appear farmed, if have connections on both session hosts , shut down 1 of servers, users on server lose connection when these users try connect again, seeing in event log connection broker trying send user connections downed server fails.  i have disabled enable automatic reconnection , set "when session limit reached or connection broken end session."  how connection broker aware if session host unavailable?  is possible force connection broker not send connections unavailable server i've tried downing server , running "remove-rdsessionhost" error server unavailable. i've modified r

Server/Outlook issue

hello, i built small server running windows sbs 2011 essentials. when installed software on client computer started having password in outlook rejected. i'm not guy, if need more information please let me know, need fixed. thanks. hello, for sbs essentials please ask experts in http://social.technet.microsoft.com/forums/en-us/home?forum=smallbusinessserver2011essentials&filter=alltypes&sort=lastpostdesc best regards meinolf weber mvp, mcp, mcts microsoft mvp - directory services my blog : http://msmvps.com/blogs/mweber/ disclaimer: posting provided no warranties or guarantees , confers no rights. Windows Server  >  Windows Server General Forum

Verify DC in remote office is utilized?

we have functional level 2003 of our dcs in 1 central office. i've started rolling out win2008 r2 core dcs regional offices (20 or less people in each office). these regional offices on seperate subnet. how can verify computers in regions using local dc authentication? also, in ad sites need create subnets each site? hi carltonw1, yes. make remote computers logons dc in own site, need create subnets each site in active directory sites , services. in way, ad can aware of location of dc, , ntlogon service domain client locate neareast dc in own site during logon process. for more reference, please check: finding domain controller in closest site http://technet.microsoft.com/en-us/library/cc978016.aspx hope helps. thanks , regards scorpio_milo mcts: windows vista | exchange server 2007 mcitp: enterprise support technician mcitp: server & enterprise administrator microsoft infrastructure consultant enterprise service: solution architect contact me my

Terminal Services Configuration on Windows Server 2003

hi techies.. i having windows server 2003 standard edition , want configure server terminal server remote users. remote users not in domain. we have use 1 accounting software through terminal services. can please advice me how shall configure server terminal server , on remote client (win xp sp3) thanks hi, link windows 2000 installing terminal server in application mode there not difference except not prompt remote administation mode/application mode since remote desktop enabled in winodw 2003 default. need install terminal server component from add/remove windows components. asked specify licensing server (you can select 120 days option) , then will asked license type (select per user licensing). naresh negi (msft - windows performance team) Windows Server  >  Remote Desktop Servi

Event ID:6032 Source:EFS My client computer can't copy encrypted file to my server 2003.

event id:6032 source:efs client can't copy encrypted file server 2003. the error description : efs not support encryption on network sessions established using ntlm protocol. background: after upgrade server windows server 2000 windows server 2003 enterprise. client call me can't copy encrypted file server. , copy normal file server extremly slow. check eventlog found issue. please me solve problem. hi, have tried steps on following article? have see if meet environment: event id 6032 logged if clustered share resource fails on or moved cluster node in windows server 2003-based server cluster http://support.microsoft.com/kb/935648   Windows Server  >  File Services and Storage

Release Management with deployment agents using visual studio online

hi all, i using release management visual studio online. have setup on premise build server. want release application environments using deployment agents. here have done: i have setup on premise release management server , deployment agent. have connected release management visual studio online. possible use release management release application environments using deployment agents. if yes helpful if provide steps need performed. regards, hi arun gopakumar, please go through below links give more information release management release application environments using deployment agent. http://blogs.msdn.com/b/visualstudioalm/archive/2014/11/12/using-release-management-vso-service-to-manage-releases.aspx http://blogs.msdn.com/b/buckh/archive/2015/04/08/how-we-deploy-visual-studio-online-using-release-management.aspx https://www.visualstudio.com/en-us/get-started/release/manage-your-release-vs regards, sunil.hp

Time out expired.

  hi all,     when developer  to retreive data through ssms displays this     error source:- .net sql client data provider error message :- time out expired. time out period elapsed prior completion of theoperation or server not responding.    i  checked in ssms tools -->options-->query execution 0. last week users display same above .wht may problem.  why happens?     pls needfull.. thanks in advance regards manoj well investigate if case if work locally @ server. if not there might either complex calculations involved withint simple select * statement or might have hardware issue on machine, having sql server wait hardware ressources or physical io. guess , needs further investigation. jens k. suessmeyer --- http://www.sqlserver2005.de --- SQL Server  > 

Two rows passed to error handler instead of one....

scenario: flat file conneciton manager import, , error exporting oledb destination successful data. transforms connecting flat file source oledb destination on success, , script component, , flat file destination in event of error. goal: very basic - take rows flight file, pipe delimited (cr/lf rows) source, , map table, exporting records error out error file. symptom: given 3 row file (just test), first record missing column, wind 2 records (the record know has error, plus following record) in error file, , 3rd record in success file. 1 one record reported going each file (so, error transform shows single record, though 2 wind in file). couple of lines of code move things on follows... _erroredrow = system.text.encoding.ascii.getstring(row.flatfilesourceerroroutputcolumn.getblobdata(0, (int)row.flatfilesourceerroroutputcolumn.length)); output0buffer.addrow(); output0buffer.record = _erroredrow; what suspect happening here delimiter @ end of first

The underlying connection was closed

support: we've been experiencing following 2 errors past 2 days.  on azure status page, there reference issue affecting services regarding connections has since been resolved.   there additional issues these services or has changed should considering?  thanks in advance response. error 1: microsoft.windowsazure.storageclient.storageserverexception: server encountered unknown failure: underlying connection closed: unexpected error occurred on send. ---> system.net.webexception: underlying connection closed: unexpected error occurred on send. ---> system.io.ioexception: unable write data transport connection: existing connection forcibly closed remote host. ---> system.net.sockets.socketexception: existing connection forcibly closed remote host @ system.net.sockets.networkstream.write(byte[] buffer, int32 offset, int32 size) --- end of inner exception stack trace  error 2: exception:microsoft.servicebus.messaging.messagingexception:

A question on Conversation timer persistence

i'd add code trigger calculate the time to fire message queue based on field changing, , conversation timers seem way go.  first question refers line bol: "calling begin conversation timer on conversation before timer has expired sets timeout new value."  i think in trigger, can begin new conversation if given field has changed reset timer.  intuition tells me in order change timer new value, need retrieve existing conversation, correct? also,  i've read conversation timers persistent in survive database restarts , shutdowns.  i'm not sure extent.  after database restart/shutdown, conversation timer "reset" time interval specified when conversation begun or able account time database down/offline? thanks, chris what need table associate conversation fired timer original work order. when work order created, trigger begin dialog, sets timer , inserts table newly created conversation handle , work order id. when timer fires, activated procedur

Disconnected Shared Drives

i seem have combination of 2 problems. start with, in our company shows "t" drive "disconnected network drive". when click on it, opens fine. t drive maps common network share team folders stored. i'm told "disconnected" issue has forefront av interrupting drive mapping or similar this: http://support.microsoft.com/kb/932463 but have user gets error trying open t drive terminal server session. happens in ts , error "initializing root folders display". hangs excel (which program tries access t drive from) , has end task. microsoft recommends removing disconnected drives rid of problem: http://support.microsoft.com/kb/932463 but drive wants access t, disconnected everyone. removing defeats point that's files stored. anyone seen before? this article should sort it. mapped drive connection network share may lost http://support.microsoft.com/kb/297684     regards, dave patrick .... microsoft certified professional -mi

TMG NIC Settings

hello, have standalone array, have add array member. question is: tmg main having 2 nic's (internal & external) internal ip 192.x.x.x (255.255.255.0) without gw. (local dns) external ip (public) 93.x.x.7 (255.255.255.240) gw (isp dns). want know ip addresses use array member server? , can getting arror msg in main tmg (routing configuration not define in intra-array server .) can please help?   regards, an. hi ! first teal did yours tmg 2010 standard or enterprise , if yours tmg 2010 standard version can have 1 server in array, , not support nlb, , if have enterprise version supported. planning forefront tmg server high availability , scalability http://technet.microsoft.com/en-us/library/dd897010.aspx isaserver.org http://www.isaserver.org/tutorials/closer-look-tmg-2010-enterprise-edition-standalone-arrays.html http://www.isaserver.org/tutorials/tmg-enterprise-arrays-explained.html   best regards

Looks like a local entry in administrator group is interfering with group policy

Image
on our windows 7 machines not want users logging in administrator access.  of course users need able install software on own these users creating 2nd user account  ends '00' can used when elevated privileges required.  have group policy setup add group called adm_%computername% local administrators group on windows 7 machines.  populate groups correct '00' administrator account.  used article here accomplish this: how use group policy preferences secure local administrator groups http://www.grouppolicy.biz/2010/01/how-to-use-group-policy-preferences-to-secure-local-administrator-groups/   it appears work fine machines weird thing happening on machines.  thing can find different these machines not working may have had users '00' account entered in local administrator group when policy pushed out. know sounds weird that's difference can find.   on machines not working processes fine, no errors in group policy, no event log messages, adm

userCertificate Attribute Role

i looking understand usercertificate attribute role. networks work use smart card authentication , usercertificate attribute tends filled expired smart cards , @ times third party encryption certificates. 2 questions: is there white / paper or deep dive discussion on role attribute plays in email or other encryption in windows environment? when performing encryption based on usercertificate attribute certificates, process choosing certificate use encryption when more 1 not expired or revoked? my assumption usercertificate attribute purely public key encryption , used users public key encrypt message. if have more 1 certificate, not sure how right 1 gets selected. the usercertificate attribute used publish certificate public key of associated user/computer. typically used 2 things in ad - smime encryption , encrypted file system. in case of smime, when email encrypted prior sending user, recipients public key used. in case of efs, when user chooses add individual list

ActiveRoles usage after Exchange Org removal

hey guys, know question quest related, know here guys working it, hope not mis-placed. we got configuration multiple account forests , 1 single resource forest. unfortunately quest migration manager all-the-time installation due longterm migrations , issues. make short, microsoft concept of granting permissions in resource forest via powershell not work because in security descriptor wrong sid written. our microsoft call did not yet lead solution. not question. i'm doing progress in deinstalling old exchange 2003 mailbox servers. 1 frontend server each subdomain left. when deinstall last frontend server, exchange org disappear. will still able use exchange tabs in activeroles after deinstalling exchange org in subdomain? in advance. kind regards, christian  Windows Server  > 

Disable write cache on VHDX in Hyper-V DC guests.

i have couple of dc's running server 2012 hyper-v guest machines.  have write caching disabled on hosts raid controller (no cache battery), reason, can't disable write caching on vhdx virtual drives dc guest servers reside on.  has caused me issues twice during extended overnight power outages have caused unclean shutdowns of physical server, corrupting ad databases on guest servers.  spent 4 hours force-removing ad 1 of servers, rejoining, , fixing other associated issues due corrupted ad databases. how heck disable write caching on boot drive on hyper-v guest when guest os says device not allow setting changed?  oh, vhdx mounted ata device.  need create tiny vhdx mount ata device boot volume, , install os on scsi mounted vhdx, or how else can fix problem? any suggestions appreciated! i have couple of dc's running server 2012 hyper-v guest machines.  have write caching disabled on hosts raid controller (no cache battery), reason, can't disable write cachi

IE & powershell

hi everyone, i try add website trusted internet explorer , @ same time authorize activex option on trusted websites... added website trusted list don't find way authorize activex on it. this code using : set-location "hkcu:\software\microsoft\windows\currentversion\internet settings" set-location zonemap\domains new-item *.domain.com set-location *.domain.com new-itemproperty . -name http -value 2 -type dword thank : :) hi genjutsuguy, would please post specific internet explorer setting or registry which used authorize activex? in addition, if want enable , disable ie activex component, script below reference: powershell: enable or disable internet explorer active x components i hope helps. Windows Server  >  Windows PowerShell