Posts

Showing posts from July, 2010

Temporary Demotion of Domain Controller

the cause: have issue new client.... former used evaluation licenses in production environment when setting office. took on contract , had customer comply purchasing proper licenses. able apply purchased licenses evaluation servers, using dism; however, there 1 last server needs converted appropriate license , first domain controller in domain! the objective: objective temporarily demote dc, named " vmdc ", long enough use dism apply appropriate license, , promote again. what i've done: i've transferred fsmo roles , configured clients receive dns server named, " server1 ". when run query fsmo, following.... ps c:\users\administrator> netdom query fsmo schema master               server1.corp.zagglobal.com domain naming master   vmdc.corp.zagglobal.com pdc                         server1.corp.zagglobal.com rid pool manager   ...

Help

i need download above activexclient remote access server in gaylord. got new computer , need access work.  hi, do have trouble downloading activexclient control? if yes, ensure firewall port 80 , 443 open, , disable third party security software might block prompts. more information you: downloading , using remote desktop activex control https://msdn.microsoft.com/en-us/library/aa380808(v=vs.85).aspx what remote desktop services activex control? https://msdn.microsoft.com/en-us/library/remote-desktop-services-activex-2.aspx best regards, amy please remember mark replies answers if , un-mark them if provide no help. if have feedback technet subscriber support, contact tnmff@microsoft.com. Windows Server  >  Remote Desktop Services (Terminal Services) ...

DEP function in bios for deploying hyper-V

<form id="aspnetform" action="./" enctype="application/x-www-form-urlencoded" method="post">  i anderstand education in small business server 2008 that you must  include vt in intel and amd-v in amd processor deploy hyper-v,and  hardware dep must available , enabeled in bios.i have intel processor , when looked bios of computer i see vt enabled don't see about dep(witch intel xd bit intel , amd nx bit amd bios) function in bios..i have enabled dep in system properties(in advanced saettings) of operating system , see under written processor supports dep hardware depended, means processor supports dep function stranger side of don't see dep function in bios. can give advise dep. but real question can use hyper-v role without having dep(data execution prevention)function in bios , install exchange server virtual machine or the hardware dep function must deploying hyp...

W2K8r2 domain issue with replication

i have w2k8r2 domain 2 dc's , pdc not replicate backup dc. i ran dcdiag , below results:i changed name of domain , pdc server security purposes.   directory server diagnosis performing initial setup:    trying find home server...    home server = primary dc    [primary dc] directory binding error 1753:    there no more endpoints available endpoint mapper.    may limit of tests can performed.    * identified ad forest.    done gathering initial info. doing initial required tests    testing server: default-first-site-name\primary dc       starting test: connectivity          [primary dc] dsbindwithspnex() failed error 1753,          there no more endpoints available endpoint mapper..          got error while checking ldap , rpc c...

Word 2003 read-only recommended not honoured by Word 2010

we in process of moving users office 2003 office 2010.  our word documents flagged read-only recommended when these documents opened word 2010, in ro mode, still lock file meaning user cannot make changes document.  ro copy closed editing allowed.  these .doc files.  as a test saved same document a .docx file , file locking worked should, i.e. user edit document although else had open read-only (this have expected, of course). is there work around word 2003 our documents not changed .docx months come, causing real issues as many users modify or refer same document @ time. kind regards, stewart   hi   thank using microsoft office professionals forums.   from description, can start word in safe mode click start. in start search box, type following text, , press enter: winword.exe /safe   if above works, can follow kb article method troubleshoot if helps: http://support.micr...

usmt with winpe offline scanstate only saving shared items

when performing scanstate winpe in offline mode, , saving information network share.   not user information , data seems getting saved.  when restoring on different machine, not user profiles or data comes back.  when open saved mig file windows easy transfer wizard item shows shared items.  below part of script winpe i've been working on.   strange part when run same script on xp machine when running (removing /offlinewindir ) ; there no data loss , can see users on different machine in easy transfer wizard. set systemdrive=c: set usmt_working_dir=c:\temp set mig_ignore_profile_missing=1 set mig_offline_platform_arch=32 scanstate.exe \\networkfileserver\migrate\pcname /o /c /i:%pathtomig%migapp.xml /i:%pathtomig%miguser.xml /offlinewindir:c:\windows /all /v:5 /l:\\networkfileserver\migrate\pcname\scanstate.log what missing? hello, you may ask in migration forum instead here http://social.technet.microsoft.com/forums/en/wins...

Reverse Zone Question

i have 2 forests forest single name ( ela) ( miltidomains ) on windows 2000 4 dcs , dns, wins , dhcp in root domain , each domain child has 2 dcs ( dns, dhcp , wins). each domain has it's own subnet. there revese zone delegation each domain child dns. ex: 172.20.x.x                 > 8  (ex of  ptr : computer.ela)                 >16                 >24                 >etc we migrating new forest b in forest b on windows 2008 ( domain name torano.tld) , with unique domain ( all child domains consolidate in ou) we create same revese zone ex: 172.20.x.x                ...

Creating a tree structure (going from 1 domain to many)

hi all, i run domain hosting sharepoint 2010 dev environment. want create domain, prod environment. i want these 2 domains in foresdt stand "side-by-side". mean, happen, need another domain @ root, form tree? if this, want migrate gpos root domain "pushed down".                                            ??? domain1                  domain2 in general, not - although should consider first objective creating domain. in other words, there a reason can not use same domain use sharepoint development? if looking complete isolation between dev , prod, should consider creating separate forest (i.e. end 2 single-domain forests). if not, need identify want isolate - , whether can not accomplished within single domain hth marcin ...

Internet Explorer ESC will not turn off for some users

Image
we running rd session host farm on server 2k8 r2 servers.   there 4 servers in farm.  we apply 1 gpo users log farm farm servers.   in gpo have locked down ie settings using administrative templates (i don't use internet explorer maintenance or internet settings, administrative templates).  some of settings include hiding internet settings pages, setting security levels , assigning site-to-zone list. the problem is, users esc appears on , many of gpo settings not applied.  i have verified that esc turned off both admin , users on servers including dc used create gpo.  i looked @ both server manager , registry key , both indicate esc off admins/users.  i have verified happens new users log farm first time, not happening users.   performing gpupdate /force doesn't help. if compare gpresults between user is experiencing the issue , 1 not, don't see differences.  all of ie settings appear there , says were suc...

ISA 2004 Proxy Authentication

hi, encounter proxy authentication pop when access web site. asks me key in user name , password. normal browsing, have no problem @ all. ask how disable proxy authtentication pop in isa 2004. hi,   as issue related isa 2004, suggest discussing in our forefront edge security forum. best resource troubleshoot issue.   http://social.technet.microsoft.com/forums/en-us/category/forefrontedgesecurity   i hope issue can resolved soon.   tim quan - msft   Windows Server  >  Security

ES W5570 CPU not recognized by Windows 2008

i have 2 intel w5570 engineering sample cpus ( intel s-spec = qgxr , part number = at80602000816aa) in server. the cpu details are not showing in device manager; displays "genuine intel(r) cpu   @ 0000 @ 2.93ghz". this preventing me installing hyper-v on server. how can windows recognize cpu? hi sean leyne, i suggest contact intel support check if processor supports windows 2008 r2 , tried searching intel web site did not find suitable data. Windows Server  >  Windows Server General Forum

Multiple enterprise subordinate CAs in one domain

lets imagine have following pki stucture – 1 root ca (standalone) , 2 enterprise cas. 1 of these enterprise ca‘s has domain controller authentication template published , other doesn‘t. may domain controllers autoenroll certificates according template time time. question – domain controller able find correct ca in ad  domain controller authentication  template enabled , able autoenroll certificate? affraid can stuck on ca template disabled , fail autoenrollment l thanks. no, domain controller find ca template published , able enroll against template. paul adare cto identit inc. ilm mvp Windows Server  >  Security

drive mappings work fine under xp but not windows 7 as non admin user. Any advise please?

Image
hello, have windows 2008 domain controller using gpo push drive mappings users. our network consists of xp machines starting migration windows 7. when login administrator equivalent on windows 7 pc drive mappings if login non-administrator user (standard user) drive mappings stop mapping after first 2 drives. me 6 of network drives starting drive h through s non admin users first 2. if manually try , map drives later non admin user using net use command works fine running bat file map drives user after, not map @ time of login. have tried disabling uac on windows 7 machine , setting "always wait network @ computer startup" registry key setting enablelinkedconnections. have included login.bat login script use below review. any thoughts appreciated. strange works me standard users stops. thank you. here our login.bat login script net use h: /delete net use i: /delete net use l: /delete net use j: /delete net use p: /delete net use s: /delete net us...

Is Get-Service subject to permissions per Service?

Image
all, i running 2 commands using service, accross netwrok same host.  difference query different services, wuauserv reports fine, , ccmexec reports not existing.  i've tried on number of hosts , have seen behaviour on lot of them, not all.  can explain why get-service work on a subset of services on same box using same credentials? othere services falsly being reported well. i have pasted examples of get-service lines , output below. ps c:\windows\system32> get-service -name wuauserv -computer testserver status name displayname running wuauserv automatic updates ___________________________________________________________________________________________________________ ps c:\windows\system32> get-service -name ccmexec -computer testserver get-service : cannot find service service name 'ccmexec'. @ line:1 char:12 + get-service <<<< -name ccmexec -computer testserver + categoryinfo : objectnotfound: (ccmexec:string) [get-ser...

Unable to browse server

i have strange one.  on 1 windows server 2008 x64 machine, if try browse c$ windows xp machine, , error windows cannot find server.  can ping remote desktop it.  if on windows 7 or server 2008 machine can browse server without hitch.  ideas here great.  i've disabled ipv6 in case problem , i've disabled av.  windows firewall not turned on.  body have clue? thanks brian knight this might worth try. edit registry on 2008 server "uac set not allow access default shares remotely. enable, set key in registry hklm\software\microsoft\windows\currentversion\polies\system\localaccounttokenfilterpolicy 0 - build filtered token (remote uac enabled) 1 - build elevated token (remote uac disabled) setting dword entry 1, able access administrative shares since remote logon token not filtered." http://www.petri.co.il/forums/showthread.php?t=40336 roy mayo | mcts • mcse | usa ...

Licencing issue on RD 2012 svr

hi all, we have dedicated 2012 r2 remote desktop server in domain environment, , have 2 users connect in , 2 user-cal licences. we have installed rd connection broker, session host, licencing , web access, although want remote desktop users can run sage , outlook. basically, getting xxx days grace period notice, although there rd licencing server configured on server. upon running rd licensing diagnoser image below , other image licensing manager. it bizarre, not sure on go, appreciated - thanks ** apparently can't post images ms need verify account. hi james, to confirm, server shows being part of collection in server manager -- rds -- collections -- <collectionname> -- host servers? which version of server 2012 r2 this?  standard or datacenter or ? -tp Windows Server  >  ...

borraron mi administrador

mi computador tienia su admintrador  pricipal mis niñas pusieron otra cuenta no se que aser los otros programas  no me deja abrirlos  no se que aser para regresar a la cuenta principal solo aparese de guest  hola, dale tres veces seguidas la combinacion deteclas ctrl-alt-supr y te va abrir una pantalla para que pongas el nombre de usuario. ahi ponele administrador y fijate si podes entrar. saludos. emanuel weber support Windows Server  >  Administración de servidor

Slow Virtual Machine inside Hyper V Core

Image
i have following : hyper v core 2008 r2 running on 2 x intel xeon e5606 processors. vm windows server 2003 32 bit os. seen below vm quite active, on screenshot below actual hyper v core taskmanager not active. vm quite slow. hyper v core taskmanager to helpful need better understanding of symptom describing 'slowness' there many reasons perception of 'slow' of depends on great number of different possibilities.  one item disk io, 1 processor, can hardware agents in vm, yet can baggage p2v operation, , can applications running in vm, or roles in vm.  these things contribute. simply showing processor metrics (expected metrics way) not useful. http://social.technet.microsoft.com/wiki/contents/articles/hyper-v-concepts-vcpu.aspx and, statements , questions go hypervisor - not hyper-v. brian ehlert http://itproctology.blogspot.com learn. apply. repeat. disclaimer: attempting change of own free will. ...

WMI writing to Eventlog

i new linux environment, trying proof of concept need wmi write eventlog basically trying generate event on linux box gets transmitted wmi , wmi in turn writes "event" eventlog. is possible. thanks you have omitted information on operating system. i recommend address either developer forum or powershell forum (the latter choice): http://social.technet.microsoft.com/forums/en-us/winserverpowershell/threads regards milos Windows Server  >  Windows Server General Forum

How to know if two computers are in the same local network?

hello. our company creating it-infrastructure management software. it client-server architecture system. central server globally visible (like: myserver.liverepair.com) agent applications, installed on computers of it-infrastructure, connect central server , establish communication. server can "request" data agents. now in search of method, of how determine, if 2 agent applications installed on computers, in same local network. possible kind of unique lan id, to defiantly let server know 2 computers that communicate with in same local network? please let me know if question unclear, try provide more info.  thank in advance. max pavlov http://maxpavlov.com hi, following article may helpful: how determine whether ip same lan programatically in .net c# http://stackoverflow.com/questions/416524/how-to-determine-whether-an-ip-is-from-the-same-lan-programatically-in-net-c how determine whether client connected ras or lan http://support.microsoft.com/kb/1735...

Consolidating Session Host Servers - Need to copy RemoteApps

i'm consolidating bunch of session host servers each handful of remoteapps load-balanced session host farm host remoteapps.  is there easy way export remoteapps old session host , import (but append - not overwrite) remoteapps new session hosts? i've tried copying files in the c:\windows\remotepackages\remoteapps folder, target sh server doesn't pick on files. hi tim, if export remoteapps file (following godog's instructions above) , open file notepad, you'll find remoteapp manager uses simple xml format. haven't tried this, assuming of apps use same base rdp file settings (it's requirement if you're planning on hosting them on same farm) should simple manually merge exported .tspub files: copy all the application sections single file. then, import merged file remoteapp manager on servers of farm (again following godog's instructions) , should set. hope helps, travis howe | rds blog: http://blogs.msdn.com/rds/default.aspx ...

Making users to access ADUC

hi ppl, i see administrator users allowed access aduc. , more deeply, found out threads backup operators allowed permissions access aduc. so, guess there list of users or groups can have access aduc. list , how possible edit list ? anand kumar d this posting provided "as is" no warranties, , confers no rights. for accesing the aduc no additional rights required. need install rsat(vista, win7, windows 2008, windows 2008 r2, windows 2012) on prior os like xp need install adminpak.msi. on 2003 there default. also can try below command rundll32 dsquery,openquerywindow hth biswajit my blogs | mcc | tnwiki ninja   best regards biswajit biswas disclaimer: posting provided "as is" no warranties or guarantees , , confers no rights. mcp 2003,mcsa 2003, mcsa:m 2003, ccna, mcts, enterprise admin Windows Server ...

How to convert Int32 Timestamp for DNS Resource Record

hello, id see dns 'a' resource record timestamp in same form displayed in dns console when browse 'a' record, mm/dd/yyyy hours:minutes:seconds am/pm.  when run following list rrs zone, timestamp in int32 format.  how convert wmi timestamp int32 value form i've mentioned above? get-wmiobject -computer prod1 -namespace "root\microsoftdns" -class "microsoftdns_atype" `       -filter "containername="myprodzone" , timestamp<>0" thanks help! sdedot get-wmiobject -computer prod1 -namespace "root\microsoftdns" -class "microsoftdns_atype" -filter "containername='myprodzone' , timestamp <> 0" | select ownername,@{n="date";e={([datetime]"1.1.1601").addhours($_.timestamp)}} Windows Server  >  ...

Query "Last logon" time from AD

i want use power shell query "last logon" time ad. example, if want know did not login domain on 30 days? me? thanks, glaziz this small sample filter users did not logon more 30 days (error on accounts that did never logon) : $ds = new-object system.directoryservices.directorysearcher $ds.filter = "(objectcategory=user)" $ds.findall() |? {[datetime]::fromfiletime($_.properties.lastlogon[0]) -lt (get-date).adddays(-30)} for more info see : http://mow001.blogspot.com/2006/01/get-users-lastlogontime-and.html greetings mow Windows Server  >  Windows PowerShell

VDI for graphic design

we have group of 8 people doing drawing design (simulations…autocad….etc), @ moment have own desktop pc quadro video card. wondering if possible have these people under vdi implementation? has such experience? i read remotefx, how work? need have server quadro graphic card in? or graphic card client desktop pc handle video processing load? hi, yes,of course.it possible have these people under vdi implementation.you need have hardware gpu support in server side.microsoft® remotefx™ included part of rd virtualization host role service, , enables delivery of full windows user experience range of client devices including rich clients, thin clients, , ultrathin clients. remotefx renders content using graphics processing units (gpus) present on server , shared across multiple virtual desktops. remotefx renders range of content including directx , types of multimedia, , optimized lan-based networks. for vdi: technical library microsoft download center deployi...

Error after Migrating app from windows 8.1 to UWP

i downloaded windows 8.1 store sample app from  https://code.msdn.microsoft.com/windowsapps/windows-8-modern-style-app-samples/file/99864/23/windows%208.1%20store%20app%20samples.zip  trying migrate 'multipleviews' app windows 8.1 uwp. platform : windows 10 insider preview build 10074 , microsoft visual studio professional 2015 rc getting below error  message :  error  task 'generateappxpackagerecipe' failed. 0x80070057 - failed index file path. filepath = ' <apppath> \assets\microsoft-sdk.png' how fix error? please help. suchitra, i think better place ask question following forum: https://dev.windows.com/en-us/community regards please remember mark replies answers if help, , unmark answers if provide no help. if have feedback technet support, contact tnmff@microsoft.com. Windows 10 Insider Preview  >...

Migrating WSUS from SBS2003 to SBS2011

the replicaton between old server , new server wsus fails everytime soapexception: fault occurred @ system.web.services.protocols.soaphttpclientprotocol.readresponse(soapclientmessage message, webresponse response, stream responsestream, boolean asynccall)    @ system.web.services.protocols.soaphttpclientprotocol.invoke(string methodname, object[] parameters)    @ microsoft.updateservices.serversyncwebservices.serversync.serversyncproxy.getupdatedata(cookie cookie, updateidentity[] updateids)    @ microsoft.updateservices.serversync.catalogsyncagentcore.webservicegetupdatedata(updateidentity[] updateids, list`1 allmetadata, list`1 allfileurls, boolean isforconfig)    @ microsoft.updateservices.serversync.catalogsyncagentcore.getupdatedatainchunksandimport(list`1 neededupdates, list`1 allmetadata, list`1 allfileurls, boolean isconfigdata)    @ microsoft.updateservices.serversync.catalogsyncagentcore.executesyncprotocol(bool...

Strange Certificate Issue

hi all, i encountering strange issue. on windows xp in workgroup mode, i have created new user called sai, , added him administrator group  i able browse https sites without issue. when remove user "sai" administrator , add him on users group , i unable browse https websites  findings ====== a) found under ie --> tools --> internet options --> content-->certificate there no certificates listed there whcih strange. b) when add user administrator , able see certificates in certificate store. question ======= how these certificates getting populated ? through system certificates under hklm , hkcu please help.   sainath windows driver development hi,   in order keep trace of troubleshooting , avoid confuse, please follow in this thread .   thanks. Windows Server  >  ...

the security database on the server does not have a computer account for this workstation trust relationship

on windows 10 domain machines when user tries change password. on our test machine no updates applied dc server 2008 , server 2008r2     serious bug users must change password per hipaa craig n craig hi craig, regarding error, many reasons cause error, please have try suggested methods in following article , see if helps: https://technet.microsoft.com/en-us/library/ee849847(v=ws.10).aspx https://virtualcurtis.wordpress.com/2011/03/02/fix-the-security-database-on-the-server-does-not-have-a-computer-account-for-this-workstation-trust-relationship/ , have tried remove client domain , re-join see if helps? best regards, wendy please remember mark replies answers if help. if have feedback technet subscriber support, contact tnmff@microsoft.com .  Windows Server  >  ...

detect IP range to execute logon script

Image
hi guys, i having trouble logon script. how can detect ip address of target workstation ? if workstation located within range, (192.168.101.1 192.168.101.254), able execute rest of logon script. thanks in advance. btw, not familiar in vbs hi guys, i having trouble logon script. how can detect ip address of target workstation ? apply group policy based on clients ip address using wmi filtering. need test first. can apply group policies based on site. wmi filter take @ this: wmi filter apply gpo based on default gateway mahdi tehrani   |     |   www.mahditehrani.ir please click on propose answer or mark post , helpful other people. posting provided as-is no warranties, , confers no rights. how query members of 'local administrators' group in computers? Windows Server  >  ...

Windows 2008 R2 Enterprise Evaluation Timeout Issue

i've had eval running 182 days far, , according "slmgr.vbs -dli" "inital grace period" set timeout in 7 days.  i've tried "slmgr.vbs -rearm" command and reboot with no affect.  need addtional 60 days production environment up.  ideas? -rick hi,   please run “slmgr /dlv” , paste output here. in output, find 1 item called “remaining windows rearm count”, if number of “remaining windows rearm count” 0, not able rearm again. way have reinstallation after evaluation day.     best regards, vincent hu   Windows Server  >  Windows Server General Forum

oclist /xml or /?

oclist have qualifiers? can behaviour changed, example output xml?   given previous comments andrew m , comments in forums , blogs think answer no, it’s simple app calling underlying api, thought i'd ask can't seem find anything.   why asking question? i'd @ least 2 things oclist (apart nicer looking output [which i'm not going get], dependances listed [dicussed in forum , ruled out], , refrushing add ad componets , telling use dcpromo [which in banner know]): - whether installing component cuase / require reboot (currently believe qwave , printing services require reboot)   - xml output, can't justify team looking see if can commality with full server   fwiw :j   hi,   oclist not have qualifiers or ways change output. when iis came in late, make oclist output longer, unfortunately late make significant changes.   i'll take feedback , add our list next version.   thanks,   andrew   ...

Get Navigator (browser) geolocation - Script

hi, does knows powershell script latitude & longitude info if wifi card enabled?  i read scripts lat x long ip address, it's not need.  in w3schools website has javascript lat x long information browser (navigator) http://www.w3schools.com/html/tryit.asp?filename=tryhtml5_geolocation this link above return geolocation. enable wi-fi card , it's works. i need powershell script same. thanks if on win10 , have geolocation enabled this: (new-object –comobject locationdisp.latlongreportfactory).latlongreport \_(ツ)_/ Windows Server  >  Windows PowerShell

Windows 2008R2 Inbound Firewall Rule

i added inbound rule server, via protocol , port. when try telnet test says connect failed. firewall disabled on server. after initial connection failure added inbound rule see if did it.  basically trying open port on server , cannot figure out.  any ideas? thanks - sjmp hi, thanks post. in general, inbound block rule has higher precedence inbound allow rule. please check if there block rule. meanwhile, please refer following article check if have created appropriate inbould allow rule, need pay attention on program, protocol, , port. http://technet.microsoft.com/en-us/library/cc753558.aspx thanks, miles please remember click “mark answer” on post helps you, , click “unmark answer” if marked post not answer question. can beneficial other community members reading thread. Windows Server  >  ...

User token absolute limit

we had ad health check, , thing failed absolute token size limit test.  users affected auditing users , able around problem subdividing work.  however, have regular users encroaching on 1000 sid limit in token.  have been doing can remedy problem, wanted double check if understanding of problem accurate, ask couple of questions. 1.  problem occurs authentication/logins.  account nevers logs in not affected.  correct? 2.  current limit 1000 sids? 3.  limit same people authenticating different ad infrastructure levels?  in other words, limit same 2003, 2008 , 2008 r2? 4.  since appears such common problem, limit increased in server 2012? thanks answers. yes 1,000 still limit   http://technet.microsoft.com/en-us/library/cc756101.aspx#bkmk_groups the number of groups hasn't changed in 2012 total objects in forest has.  it in 1 of teched presentations.  i'll try , dig up. thanks mike http://adisfun.blogs...

New RDP User CALs not working

just added 2 additional rdp user cals rdp server , not allowing more logins. had 5 start with, work fine, 2 new licenses not work.  under rd licensing manager, shows original 5 "windows server 2008 or windows server 2008 r2: installed ts or rds per user cals", open license, qty 5, expires never. line shows same thing, qty 2. when run licensing diagnosis, shows number of licenses available clients 7, licensing mode per user. 0 warnings, no problems report. remote desktop services license server shows credentials: available, connectivity: available. we reinstalled licenses yesterday no luck. all users use same login, , under rd session host configuration: server. setting restrict each user single session set no. i have no idea fix this. can first 5 users logged in, try connect 6th user, message saying "this computer can't connect remote computer". have tried logging in user same result. any suggestions? thanks! hi, it set via local policy or do...