Posts

Showing posts from May, 2015

Word Macro Behaves Badly Inside Content Control (Paste & Resize image)

i cobbled pretty cool macro internet, , works great regular word document. the use case has powerpoint slide bunch of stuff on (picture, boxes, text, arrows, etc.)  ctrl-a, ctrl-c powerpoint, , before macro, ctrl-v (as jpg) into word , always have resize it . this macro resizes pastes it.  can't figure out why same macro doesn't work if i'm in content control?  don't error, "works" in sense powerpoint content saved jpg word, won't resize it.  it's code runs, somehow pasted image inside content control read-only or properties read-only. can explain behavior? application.screenupdating = false selection.pastespecial link:=false, datatype:=15, placement:=wdinline, displayasicon:=false 'get image added (last image, li) li = activedocument.inlineshapes.count activedocument.inlineshapes(li).lockaspectratio = msotrue activedocument.inlineshapes(li).height = 0.64 * activedocument.inlineshapes(li).height application.screenupdating = tru...

Tryign to configure SSTP role on server but client won't connect with error 0x800B010F

Image
have client single server (ad, dhcp, etc) sitting behind simple ant firewall.  followed sstp configuration guide , followed kb on ca setup stage: windows vpn (sstp): read first: http://support.microsoft.com/kb/961880 setup guide: http://technet.microsoft.com/en-us/library/cc731352%28ws.10%29.aspx everything appears correct, except unable connect windows 7 station (only station have test with). the client returns error 0x800b010f: certificate's cn name not match passed value. i made sure install server ca cert in client's trusted ca store per guide , in frustration added in vpn certifcate (the 1 public domain name) clients private cert store well.  debugging logs did not help, nore have windows event logs (which restate same error).  i've gone far can skills , use assistance now.  verified rras service using cert public domain name (example: vpn1.public.com).  firewall forwards ports 80 , 443 server (all should required right...

What does DisableBootTimeSecurity setting do?

hi, installed following kbarticles part of security , general update process on windows server 2003 std.  not using isa server.  on rebooting server, server not receiving incoming connections, outgoing working okay. kbartices 2440591; 2207559; 2296199; 2416400; 2419635; 2423089; 2436673; 2467659; 2443105; 2443685; i ended removing of updates, still server did not accept incoming connections.  finally, read on post   http://www.tech-archive.net/archive/windows/microsoft.public.windows.server.sbs/2008-07/msg02573.html  about disableboottimesecurity, , resolved problem.  i'm not networking guy, trying bottom of this, i'll need re-install these patches sometime!   ben howard [mvp] blog | web hi, based on understanding, related boot-time policy of windows firewall. following information helpful work: 897651 vpn clients can no longer access internal resources after install windows server 2003 service pack 1 on computer running i...

Windows 2008 R2 64-bit Port 3389 down

port 3389 down. used cirix xenapp server in 5 server farm. other 4 servers have no troubled @ all. tried no avail. 1 took server out of domain , added several times.. 2. re-installed terminal service role several times. 3. turned on/off firewall several times. 4. added/removed rdp-tcp connections several times. 5. changed authentication method sevral times. 6. uninstalled symantec end point. 7. netstat not show port. 8. can ping server other servers. 9. tried clean boot. 1. how find blocking it? 2. there such thing unblock/open port service restart? 3. there command make port work again? 4. there place in registry can unblocked? hi all, here update. the windows 2008 x64 server using doesn't seem citrix xenapp 5.0 when remove citrix, starts listening. add citrix stops. ideas? doesn't sound exact issue think reg location listed at end of the thread might thing check: http://forums.citrix.com/thread.jspa?threadid=255411&tstart=0 ...

Folder redirection: This security ID may not be assigned as the owner of this object.

i having problem folder redirection 1 user. have changed location documents folder redirection , reason documents not re-directing   the server sbs 2003 pc in question windows xp pro    this group policy redirection error  event type: error event source: folder redirection event category: none event id: 112 date: 07/06/2011 time: 15:43:01 user: domain\user computer: pcxp10 description: failed perform redirection of folder documents. files redirected folder not moved new location. folder configured redirected <\\sbs2ksvr\usermydocuments\%username%\my documents>.  files being moved <\\sbs2ksvr\user\tomkinsonp> <\\sbs2ksvr\usermydocuments\ptomkinson\my documents>. following error occurred while copying <\\sbs2ksvr\user\tomkinsonp\09 1nd 10.doc> <\\sbs2ksvr\usermydocuments\ptomkinson\my documents\09 1nd 10.doc>:  this security id may not assigned owner of object.    for mo...

AD GPO Account Lockout Exemption

i'm running on windows 2003 native mode. want exempt user account lockout policy. there way override default domain account lockout policies? if not, possible create separate gpo account lockout policy on ou level contradict account lockout policy w/c set in default domain policy? fine grain password policy...  little hard implement links below should help.... need have windows server 2008 active directory domain mode enabled. http://technet.microsoft.com/en-us/library/cc770394(ws.10).aspx and http://go.microsoft.com/fwlink/?linkid=128039   and http://capitalhead.com/articles/step-by-step-guide-to-fine-grained-passwords-in-windows-server-2008.aspx alan burchill http://www.grouppolicy.biz Windows Server  >  Group Policy ...

Free Windows 10 Upgrade

with of hype surrounding announcement free windows 10 upgrade, here important qualifications keep in mind: some editions excluded: windows 7 enterprise, windows 8/8.1 enterprise, , windows rt/rt 8.1. active software assurance customers in volume licensing have benefit upgrade windows 10 enterprise outside of offer. sharing more information , additional offer terms in coming months. source: https://winpreview.catalysis.com/registration.aspx?hfid=wrf0&loc=en-us#disclaimer (very bottom of page) paul adare - fim cm mvp must admit microsoft seem bear awful resemblence the sirius cybernetic corporation. considering attempts @ using word resulted in almost, not quite, entirely unlike document. -- rich kaszeta and add information, gabriel aul confirmed free upgrade lasts life of device Windows 10 Insider Preview  >  ...

lost connectivity over weekend

we seem have lost not connectivity between 3 offices connected via mpls wan link on weekend. symptoms follows: office 1 can connect office 2 , office 3 resources without issue. office 2 , 3 can connect each other without issue, and to office 1 resources (i.e. internal shares on ftp server) cannot connect other network shares, nor rdp servers directly. all resources respond ping fqdn offices. interestingly enough office 2 resources not "available" can "made" available win 7 x64 client connecting network share using ip address. once has been done, shares are available via fqdn , netbios name. also, after connecting share, rdp connection works win 7 x64 client. above steps not restore connectivity when performed on xp sp3 client however. the wan link has been checked , pronounced sound service provider. nothing has been changed on infrastructure on weekend. ideas?   "all resources respond ping fqdn offices." when ...

Installing Windows Server 2008 R2

i'm trying install windows server 2008 r2 x64 sp1 on server dell poweredge 1800 i have bought a seagate cheetah 15k.5 - hard drive - 300 gb - ultra320 scsi it working fine windows server 2008 x64 when tried install r2 sp1 x64, the setup cant find hard drive. found drivers scsi , tried load drivers usb still couldn't find the hard drive. thnx in advance easiest boot dell preinstallation evironment prepare os installation. http://support.dell.com/support/downloads/download.aspx?c=us&cs=08w&l=en&s=bsdv&releaseid=r300653&systemid=pwe_1800&servicetag=&os=wnet&osl=en&deviceid=24134&devlib=0&typecnt=0&vercnt=4&catid=-1&impid=-1&formatcnt=0&libid=36&typeid=-1&dateid=-1&formatid=-1&source=-1&fileid=451468         regards, dave patrick .... microsoft certified professional microsoft mvp [windows] ...

DirectAccess in ip4 environment

Image
after reading directaccess 2.0 works better in ip4 environment, decided give try.  not working yet, before spending more time troubleshooting or asking specific help, wanted ask general questions see if should be working. instead of setting pure lab environment, wanted see if work in network setup our production.  of our equipment ip6 capable (modern switches, windows 2008 or higher, clients windows 7).    however, ip6 running default configurations on everything.  in case of our servers, means they're creating own link local addresses , nothing else.  have few switches hosting our pc's.  have a few physical servers, while servers vmware based.  of course, ip4 routable , can communicate else.  ip6 seems limited local broadcast domain.  in other words, 2 workstations on same switch can ping ip6 addresses of each other, not servers on switch.  2 physical servers can ping each other, not vm.  2 vm's can pi...

Network Load Balancing Problems.

hi, setup: server 1 - 2016 connected nlb cluster.  server 2  - 2016 connected same cluster. same hardware on both.  on same subnet, confirmed 100% . multicast mode selected. more settings here: https://www.screencast.com/t/kgfnc3bh using iis 10 connected sql server. problem: web traffic (about 150 mbps) never balanced.  it shifts , forth every few minutes. any suggestions on check? thank you.   the microsoft network load balancing cheap, built-in, easy solution. however, has not same capabilities hardware solutions. basically, ip ranges divided among hosts. means computer same ip address redirected same server. if set affinity none, port ranges divided among hosts instead of ip ranges. means computer redirected same server if requests made inside particular port range. please note not office applications compatible affinity parameter set none. furthermore, microsoft network load balancing checki...

Remote session/script with current user's credentials

Image
is possible start remote session or invoke command current user's credentials (without specifying username , password)? paulo morgado yes. far determine, there's one-way trust relationship between domains. so guess answer original question yes. possible there conditions met. paulo morgado Windows Server  >  Windows PowerShell

WindowsUpdate_800736B3

hi when tried update service pavk 1 message    windowsupdate_800736b3 hi chris,   are trying install windows server 2008 r2 sp1? if so, suggest first try troubleshooter.   open windows update troubleshooter http://windows.microsoft.com/en-us/windows7/open-the-windows-update-troubleshooter   if problem continues, please use system update readiness tool:   description of system update readiness tool windows vista, windows server 2008, windows 7, , windows server 2008 r2 http://support.microsoft.com/kb/947821/en-us   hope helps.   regards, bruce Windows Server  >  Windows Server General Forum

Publication Locations for AIA and CDP

i following guide demonstrared  publishing offline root ca's  cdp , aia http locations iis on sub ca , publish aia , cdp of sub ca external http server. does work or should offline root ca's cdp , aia point external web server? 1) never install iis on subca (i not want anonymous http requests coming cas) 2) publish offline root ca's certificate , base crl group of web servers (behind hw load balancer) both internally , externally accessible using *same* url 3) publish issuing ca certificates, base crls, , delta crls group of web servers (behind hw load balancer) both internally , externally accessible using *same* url brian Windows Server  >  Security

Hyper-V NIC always down if traffic more than ~50%

i have win2012r2 vhost runing on dl380gen9. there ~6 vms reside on it. when tester run automaiton case on these vms, if network traffic reach more ~50%(1gb), the nic binding hyper-v down. but just disable then re-enalbe nic again, network connection get back. anybody have experience troubultshoting this kind of issue? which trace log can analyze issue?  hw: hp dl380gen9 e52698v3 ram: 128gb nic: hp ethernet 1gb 4-port 331i adapter nic driver: 16.6.0.4 os: win2012r2 dc latest windws update. hello there have been problems vmq , broadcom based nics... see http://h20564.www2.hpe.com/hpsc/doc/public/display?docid=emr_na-c04719558&sp4ts.oid=7481830 you may want disable vmq it's 10gbe nics , you're using onboard1gbe nics, unless of course there new driver fixes problem you. enter following command in administrative powershell prompt: get-netadapter | ? interfacedescription -like *hp*331* | disable-netadaptervmq be...

Cannot choose Office 2010 from products in Wsus 3.0 SP2

i want add office 2010 product wsus products , classifications cant find it.   but more helpful reasoning. "reasoning" is not yet needed. is office 2010 not going in wsus? is. might work if patiently waited until actual office 2010 update released! lawrence garvin, m.s., mcitp:ea, mcdba, mcsa principal/cto, onsite technology solutions, houston, texas microsoft mvp - software distribution (2005-2010) mvp profile: http://mvp.support.microsoft.com/profile/lawrence.garvin blog: http://onsitechsolutions.spaces.live.com Windows Server  >  WSUS

PXE-E55: ProxyDHCP service did not reply to request on port 4011 on a virtual WDS

i've never built server before , i'm attempting build virtual wds server. i'm using windows server 2008. i've looked how install wds , have installed ad ds, dhcp, dns(set dcpromo), , wds on 1 virtual server. when boot client pxe, recieves ip dhcp recieve "pxe-e55: proxydhcp service did not reply request on port 4011" error. the dhcp showing option 060 set pxe client, i've found searching error correct. firewall on physical machine disabled, enabled on virtual machine. if disable virtual machine's firewall, clients don't ip dhcp. the person built server no longer here. they had physical server and, have found out, did not make back-up. let me know if more info needed. appreciated since i've been racking brain since monday. hello, is wds , dhcp running on same server? if yes cause conflits both of them use port 69. please proceed that: go hklm\system\currentcontrolset\services\wdsserver\providers\wdspxe , set key usedhcpport...

Group Policy Management Console in Windows Server 2003 Standard Ed. SP2

hi guys, i getting message : access denied" when try "creating , linking gpo here" particular group policy object in windows server 2003 sp2. can help? hi ndubula,   this issue may cause permissions sysvol share incorrect.   please added administrators , give them full control permission @ share. allowed create new gpos , edit existing ones.   the default permissions sysvol share are:   - administrators: full control - authenticated users: full control - everyone: read   you may wish check share permissions on both domain controllers , return them default settings.   also, please check permission sysvol ntfs security:   - administrators: full control - authenticated users: read & execute - create owner: specific permission - server operator: read & execute - system: full control   if problem continues, please temporarily disable antivirus program , try create gpo again.   regards, bruce ...

Force Safe Search Google Search with DNS

have quite interesting issue dns randomly occurred 1 weekend seemingly without change in variables. i work technology of school in north texas. we have been using domain alias (dname) record on our dns servers force traffic use google safe search time now. of sudden, stopped working, refusing resolve google search requests our users network wide. dns record such: have forward lookup zone directory for  www.google.com in directory, have the soa record of parent directory particular dns server, 2 ns records our primary , secondary dns servers. record have added dname record directory takes fqdn of  www.google.com  and target host fqdn of forcesafesearch.google.com. has been working months, forcing google search traffic onto safe search. once stopped working, fixed problem deleting dname record , replacing record for  www.google.com  and ip address of forcesafesearch.google.com, 216.239.38.120. setup works now, want...

Add additional NIC

i in process of selecting hardware our sql cluster. have narrowed down ibm x3650 , x3755. problem each system comes 2 onboard nics. need add dual port nic each server, can have enought ports available.  what options? can select card? thought hardware on cluster certified, kinda concerns me. i know have run cluter utility verify cluster certified, thoughts.  requirement nic has certified windows logo.  every major nic...  pretty free pick please (just verify has logo). in win2008 supported need following: all components in cluster must have logo the validate tool must not fail tests see link more info on new support policy: http://technet.microsoft.com/en-us/library/cc732035.aspx thanks! elden Windows Server  >  High Availability (Clustering) ...

user folder only visible by one user but is listed in the command line

thank attention issue i have folder on server no 1 can see (including domain admins) besides 1 user.  if open command line , run dir on parent folder can see "missing" folder sub files , folders.  the steps took far - ran av , malware test on folder, attrib -h on folder , gave myself full rights on folder.  can me figure out or give me other steps trouble shoot issue? use /d , -s attrbute along -h arnav sharma | http://arnavsharma.net/ please remember click “mark answer” on post helps you, , click “unmark answer” if marked post not answer question. can beneficial other community members reading thread. Windows Server  >  File Services and Storage

Cross Forest File Server Migration with ADMT 3.2

hello all, searching online ms documentation migrating file servers through admt 3.2 unable find. have 2003 file server in source domain without dfs. have migrated groups, users , computers source domain target sidhistory.also have enabled sidhistory , disabled sid filtering on forest trust faciliate cross forest file share access. anybody can provide me high level steps file server migration through admt or can validate below steps please first use normal admt computer migration wizard migrate file server source domain target domain security translation option selected (shares, registry, files , folders , on) in replace mode.once server domain membership changed , rebooted,then use admt security translation wizard translate built-in security principles sid mapping file. or directly disjoin server source domain , join target domain , use admt security translation wizard translate security source domain target ? i confused, method perfect ? thanks in advance. mahes...

Server Upgraded from 2008 R2 to 2012 any potiential problems?

our corporate 2008 r2 image applied image settings built in it.  have not gotten around building 2012 image settings 2008 r2 base image applied image settings updated 2012 , saved template.  there potential downfalls mentality.  putting 2013 sharepoint farm , sql 2012 on image , want other input. hi i prefered clean install,  if can't know setting have not choice. can't list policy , settings applied image ? when upgrade neccesary ? don't forget sysprep image before installing on it. hypervisor not automaticly when clone/ use template , should ok. regards, philippe Windows Server  >  Windows Server General Forum

Windows Server 2012 R2 ignores unattended answer files

i had issues, modeled simple test case , still doesn't work. case 1: create hyper-v vm, attach 2 blank hard vhds , 1 dvd original windows installation media. mount second vhd, initialize, partition, , format it, , copy single file root named autounattend.xml. boot vm, confirm booting dvd. windows setup prompts input locale, follows full manual setup. case 2: use convert-windowsimage.ps1 create vhd, specifying autounattend.xml answer file. create vm, specify vhd hard drive, boot vm (no dvd). windows setup begins specialize pass , prompts input locale, follows manual specialize/oobe sequence. case 3: use sysprepped vhd. specify autounattend.xml use-windowsunattend directed mounted vhd, specifying both path , systemdrive. dismount vhd, attach vm, boot vm. windows setup begins specialize pass , prompts input locale, follows manual specialize/oobe sequence. i've tried naming them both unattend.xml , autounattend.xml.  can't work in of above situatio...

W2K8 R2 Unexpected shutdown

i have windows 2008 r2 vm server shutdowns every hour. event log states "the kernel power manager has initiated shutdown transition" , no other errors. hi, please reconfirm below points:        windows server has activated if not restart/shutdown every hour time        check antivirus; may force server restart.         if there heavy network usage install hotfix http://support.microsoft.com/kb/2263829        please mention event id number overview issue in better way regards, md disclaimer: opinion expressed herein own knowledge. deploy @ own risk. whenever see helpful reply, click on “propose answer” / “marked answer” , "vote". Windows Server  >  ...

Group Policy Software Installation Packages Not Shown in GP Mgmt Console

Image
this weird one. when go group policy management console, none of software installation packages shown when looking @ "settings" tab: however, when go in edit group policy, of installation packages there: i noticed because i'm seeing strange activity when testing latest installation packages. test windows xp client reinstalled of assigned packages, though made no changes machine or policy. worse yet, windows 7 clients don't seem installing packages @ all. when run "gpresult /r" on client machines, shows members of required security groups needed respective software updates, , shows relevant group policy being applied. same if run group policy modeling in gp mgmt console (policy being applied). however, if run rsop.msc on target machine, not list software installation packages under "software settings" though several have been installed in past. i've been doing routine task of deploying package updates years , have sworn packages...

IP Based HRD in AD FS Windows Server 2012 R2?

hi, at moment i'm doing project large financial customer in netherlands plans upgrade ad fs 2.0 farms ad fs windows server 2012 r2 (3.0). the reason customer needs upgrade because going migrate sharepoint 2007 sharepoint 2013 , last 1 using dynamic url's when create sharepoint app. federate ad fs supported in latest ad fs version. the customer using ad fs federate web applications based on sharepoint technology , other web applications. customer using multiple idp's (external, government, internal, customers , stakeholder organizations) relying party trusts , not want users have selection screen select correct idp before login. called home realm discovery (hrd). on current platform have customized web.config , created homerealmdiscovery.asp.cs create temporary domain cookie determines ip address of source client , selects correct idp when connect relying party trust. process triggered determine if user internal client determine if user coming specific external...

Should I remove msPKI-PrivateKeyRecoveryAgent object after Enterprise Root CA has been decomissioned?

hello guys, i've decommissioned old enterprise root ca (windows server 2008 r2). have uninstalled ad cs role old server , cleaning ad objects listed in article below. new enterprise root ca in place. https://support.microsoft.com/en-us/help/889250/how-to-decommission-a-windows-enterprise-certification-authority-and-remove-all-related-objects while cleaning ad objects came across mspki-privatekeyrecoveryagent object in cn=kra,cn=public key services,cn=services,cn=configuration,dc=domain,dc=local. there 2 objects in container, 1 old , 1 new ca. article doesn't advice directly remove this. used , should simple remove it? thank help! yes, safe remove kra certificates active directory because unlikely valid , can used further encryption. vadims podāns, aka powershell cryptoguy weblog: www.sysadmins.lv powershell pki module: pspki check out new: ssl certificate verifier check out new: powershell file checksum integrity verifier tool. ...

GPO to deploy a shortcut to all users in a domain.

hi. i have shortcut need deployed users in domain. cba going each individual computer add =) i have shortcut on p:\xxxx\yyyy.ink or computername: myserverdc01, p: drive. this how did it: gpo management -> create gpo in domain, , link here... -> named xyz -> right click on xyz, edit -> preferences(on both user , computer, since dont know right) -> windows settings ->  shortcut -> new shortcut. so far good? these settings put on new shortcut. action: create -- name: xzy -- target type: file system object -. location: desktop -> target path: p:\xxxx/yyyy.ink -- start in: %commondesktopdir% -- icon file path: p:/xxxx/yyy1.ico -------------------------------------- it creates shortcut on testusers desktop, correct icon. when double click it, sends me c:\users\all desktop (something that).. how can modify opens shortcut located on p:/xxxx/yyyy.ink? should add new shortcut computer config or user config? is there easier way add shortcut ...

Migrating AD objects without connectivity between source and target domains

Image
ok scenario there no network connectivity between source , target domains, ad/dns servers virtual on microsoft platform, what options migrate active directory objects new domain ? thanks in advance thanks, copying vm domain.com , built same domain in new hyper-v , isn't possible ? if not, think option left bare metal recovery , restore in target domain ? hello, of course can use copied vm. still have domain.com on hyper-v host. and can never connect them results in problems!!! bmr still creating new server domain.com. best regards meinolf weber mvp, mcp, mcts microsoft mvp - directory services my blog: http://blogs.msmvps.com/mweber disclaimer: posting provided no warranties or guarantees , confers no rights. twitter:   Windows Server  >  Migratio...