<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Microsoft Supportability e-Newsletter : Active Directory</title><link>http://blogs.technet.com/asiasupp/archive/tags/Active+Directory/default.aspx</link><description>Tags: Active Directory</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>EFS File Recovery</title><link>http://blogs.technet.com/asiasupp/archive/2007/04/26/efs-file-recovery.aspx</link><pubDate>Thu, 26 Apr 2007 12:27:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:825487</guid><dc:creator>gbs</dc:creator><slash:comments>3</slash:comments><comments>http://blogs.technet.com/asiasupp/comments/825487.aspx</comments><wfw:commentRss>http://blogs.technet.com/asiasupp/commentrss.aspx?PostID=825487</wfw:commentRss><wfw:comment>http://blogs.technet.com/asiasupp/rsscomments.aspx?PostID=825487</wfw:comment><description>Windows XP and Windows Server 2003 provide many enhancements in the area of data protection— especially Encrypting File System (EFS). This article provides some common issues and file recovery practices to prevent encrypted files being inaccessible. We...(&lt;a href="http://blogs.technet.com/asiasupp/archive/2007/04/26/efs-file-recovery.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=825487" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/asiasupp/archive/tags/Active+Directory/default.aspx">Active Directory</category><category domain="http://blogs.technet.com/asiasupp/archive/tags/Hot+Issue/default.aspx">Hot Issue</category></item><item><title>Access Denied, or Other Access Failure to SMB Shares from Vista Clients</title><link>http://blogs.technet.com/asiasupp/archive/2007/04/26/hot-issue-access-denied-or-other-access-failure-to-smb-shares-from-vista-clients.aspx</link><pubDate>Thu, 26 Apr 2007 11:29:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:825285</guid><dc:creator>gbs</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.technet.com/asiasupp/comments/825285.aspx</comments><wfw:commentRss>http://blogs.technet.com/asiasupp/commentrss.aspx?PostID=825285</wfw:commentRss><wfw:comment>http://blogs.technet.com/asiasupp/rsscomments.aspx?PostID=825285</wfw:comment><description>Some of the fun we have in product support is that, once a new product is released nowadays, we get to navigate the uncharted waters of new security settings interoperating with our customers’ real world environments. With Windows XP and Server 2003 we...(&lt;a href="http://blogs.technet.com/asiasupp/archive/2007/04/26/hot-issue-access-denied-or-other-access-failure-to-smb-shares-from-vista-clients.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=825285" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/asiasupp/archive/tags/Active+Directory/default.aspx">Active Directory</category><category domain="http://blogs.technet.com/asiasupp/archive/tags/Hot+Issue/default.aspx">Hot Issue</category></item><item><title>Installing Office 2007 Using Group Policy Software Installation</title><link>http://blogs.technet.com/asiasupp/archive/2007/04/26/how-to-installing-office-2007-using-group-policy-software-installation.aspx</link><pubDate>Thu, 26 Apr 2007 11:25:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:825250</guid><dc:creator>gbs</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/asiasupp/comments/825250.aspx</comments><wfw:commentRss>http://blogs.technet.com/asiasupp/commentrss.aspx?PostID=825250</wfw:commentRss><wfw:comment>http://blogs.technet.com/asiasupp/rsscomments.aspx?PostID=825250</wfw:comment><description>The Office team published a great “how to” on installing Office 2007 using Group Policy. The Office 2007 Resource Kit includes this documentation. You can view it online at the Microsoft TechNet site. Here’s a direct link http://technet2.microsoft.com/Office/en-us/library/efd0ee45-9605-42d3-9798-3b698fff3e081033.mspx?mfr=tru...(&lt;a href="http://blogs.technet.com/asiasupp/archive/2007/04/26/how-to-installing-office-2007-using-group-policy-software-installation.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=825250" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/asiasupp/archive/tags/Active+Directory/default.aspx">Active Directory</category><category domain="http://blogs.technet.com/asiasupp/archive/tags/Tips/default.aspx">Tips</category></item><item><title>Temporary profile issue</title><link>http://blogs.technet.com/asiasupp/archive/2007/03/27/temporary-profile-issue.aspx</link><pubDate>Tue, 27 Mar 2007 09:14:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:709968</guid><dc:creator>gbs</dc:creator><slash:comments>5</slash:comments><comments>http://blogs.technet.com/asiasupp/comments/709968.aspx</comments><wfw:commentRss>http://blogs.technet.com/asiasupp/commentrss.aspx?PostID=709968</wfw:commentRss><wfw:comment>http://blogs.technet.com/asiasupp/rsscomments.aspx?PostID=709968</wfw:comment><description>A temporary user profile is issued each time an error condition prevents the user's profile from loading. Temporary profiles are deleted at the end of each session, and changes made by the user to their desktop settings and files are lost when the user...(&lt;a href="http://blogs.technet.com/asiasupp/archive/2007/03/27/temporary-profile-issue.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=709968" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/asiasupp/archive/tags/Active+Directory/default.aspx">Active Directory</category><category domain="http://blogs.technet.com/asiasupp/archive/tags/Hot+Issue/default.aspx">Hot Issue</category></item><item><title>Typical Symptoms when secure channel is broken</title><link>http://blogs.technet.com/asiasupp/archive/2007/01/18/typical-symptoms-when-secure-channel-is-broken.aspx</link><pubDate>Thu, 18 Jan 2007 06:22:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:600814</guid><dc:creator>gbs</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.technet.com/asiasupp/comments/600814.aspx</comments><wfw:commentRss>http://blogs.technet.com/asiasupp/commentrss.aspx?PostID=600814</wfw:commentRss><wfw:comment>http://blogs.technet.com/asiasupp/rsscomments.aspx?PostID=600814</wfw:comment><description>The secure channel is used to validate the member servers or workstations membership in the domain, based upon its hashed password. This discrete communication channel helps provide a more secure communication path between the domain controller and the...(&lt;a href="http://blogs.technet.com/asiasupp/archive/2007/01/18/typical-symptoms-when-secure-channel-is-broken.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=600814" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/asiasupp/archive/tags/Active+Directory/default.aspx">Active Directory</category><category domain="http://blogs.technet.com/asiasupp/archive/tags/Hot+Issue/default.aspx">Hot Issue</category></item><item><title>Ghost trust object caused the network share inaccessible</title><link>http://blogs.technet.com/asiasupp/archive/2007/01/16/ghost-trust-object-caused-the-network-share-inaccessible.aspx</link><pubDate>Tue, 16 Jan 2007 09:11:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:598226</guid><dc:creator>gbs</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/asiasupp/comments/598226.aspx</comments><wfw:commentRss>http://blogs.technet.com/asiasupp/commentrss.aspx?PostID=598226</wfw:commentRss><wfw:comment>http://blogs.technet.com/asiasupp/rsscomments.aspx?PostID=598226</wfw:comment><description>A while back we got involved in a weird issue where a network user encountered network share access problems. The symptom or the error message might be different in some scenarios: 1. Domain controller’s share folders cannot be accessed by the NETBIOS...(&lt;a href="http://blogs.technet.com/asiasupp/archive/2007/01/16/ghost-trust-object-caused-the-network-share-inaccessible.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=598226" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/asiasupp/archive/tags/Active+Directory/default.aspx">Active Directory</category><category domain="http://blogs.technet.com/asiasupp/archive/tags/Hot+Issue/default.aspx">Hot Issue</category></item><item><title>Using ADRestore tool to restore deleted objects</title><link>http://blogs.technet.com/asiasupp/archive/2006/12/14/using-adrestore-tool-to-restore-deleted-objects.aspx</link><pubDate>Thu, 14 Dec 2006 11:23:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:555222</guid><dc:creator>gbs</dc:creator><slash:comments>5</slash:comments><comments>http://blogs.technet.com/asiasupp/comments/555222.aspx</comments><wfw:commentRss>http://blogs.technet.com/asiasupp/commentrss.aspx?PostID=555222</wfw:commentRss><wfw:comment>http://blogs.technet.com/asiasupp/rsscomments.aspx?PostID=555222</wfw:comment><description>Have ever encountered the following scenarios? User accounts, groups, computers, OUs or other objects in domain accidentally deleted. No system state backup available for authoritative restoration. No other DC's available. When an object is deleted from...(&lt;a href="http://blogs.technet.com/asiasupp/archive/2006/12/14/using-adrestore-tool-to-restore-deleted-objects.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=555222" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/asiasupp/archive/tags/Active+Directory/default.aspx">Active Directory</category><category domain="http://blogs.technet.com/asiasupp/archive/tags/Tools/default.aspx">Tools</category></item><item><title>The comprehensive technical articles and best practice of Windows Time </title><link>http://blogs.technet.com/asiasupp/archive/2006/11/16/the-comprehensive-technical-articles-and-best-practice-of-windows-time.aspx</link><pubDate>Thu, 16 Nov 2006 07:48:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:517622</guid><dc:creator>gbs</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/asiasupp/comments/517622.aspx</comments><wfw:commentRss>http://blogs.technet.com/asiasupp/commentrss.aspx?PostID=517622</wfw:commentRss><wfw:comment>http://blogs.technet.com/asiasupp/rsscomments.aspx?PostID=517622</wfw:comment><description>Microsoft has put together a comprehensive and technical article Windows Time and the W32TM service explaining how the Windows Time service works and how the time on desktop machines is synchronized with the server. There are some best practices that...(&lt;a href="http://blogs.technet.com/asiasupp/archive/2006/11/16/the-comprehensive-technical-articles-and-best-practice-of-windows-time.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=517622" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/asiasupp/archive/tags/Active+Directory/default.aspx">Active Directory</category><category domain="http://blogs.technet.com/asiasupp/archive/tags/Best+Practice/default.aspx">Best Practice</category></item><item><title>Regarding AdminSdHolder</title><link>http://blogs.technet.com/asiasupp/archive/2006/11/16/adminsdholder1.aspx</link><pubDate>Thu, 16 Nov 2006 07:40:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:517613</guid><dc:creator>gbs</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/asiasupp/comments/517613.aspx</comments><wfw:commentRss>http://blogs.technet.com/asiasupp/commentrss.aspx?PostID=517613</wfw:commentRss><wfw:comment>http://blogs.technet.com/asiasupp/rsscomments.aspx?PostID=517613</wfw:comment><description>Windows 2000 and 2003 both contain protected groups , called AdminSdHolder . AdminSdHolder is used to control the permissions of user accounts that are members of the built-in Administrators or Domain Administrators groups. Protected Groups are groups...(&lt;a href="http://blogs.technet.com/asiasupp/archive/2006/11/16/adminsdholder1.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=517613" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/asiasupp/archive/tags/Active+Directory/default.aspx">Active Directory</category><category domain="http://blogs.technet.com/asiasupp/archive/tags/Hot+Issue/default.aspx">Hot Issue</category></item><item><title>What’s new in GP in Windows Vista</title><link>http://blogs.technet.com/asiasupp/archive/2006/11/16/what-s-new-in-gp-in-windows-vista.aspx</link><pubDate>Thu, 16 Nov 2006 06:54:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:517590</guid><dc:creator>gbs</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/asiasupp/comments/517590.aspx</comments><wfw:commentRss>http://blogs.technet.com/asiasupp/commentrss.aspx?PostID=517590</wfw:commentRss><wfw:comment>http://blogs.technet.com/asiasupp/rsscomments.aspx?PostID=517590</wfw:comment><description>Group Policy in Windows Vista and Windows Server "Longhorn" provides an infrastructure for centralized configuration management of the operating system and applications that run on the operating system. Expanding on the foundation established in Windows...(&lt;a href="http://blogs.technet.com/asiasupp/archive/2006/11/16/what-s-new-in-gp-in-windows-vista.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=517590" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/asiasupp/archive/tags/Active+Directory/default.aspx">Active Directory</category></item><item><title>Desktop lockdown in a domain or non-domain environment</title><link>http://blogs.technet.com/asiasupp/archive/2006/09/19/457423.aspx</link><pubDate>Tue, 19 Sep 2006 10:18:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:457423</guid><dc:creator>gbs</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/asiasupp/comments/457423.aspx</comments><wfw:commentRss>http://blogs.technet.com/asiasupp/commentrss.aspx?PostID=457423</wfw:commentRss><wfw:comment>http://blogs.technet.com/asiasupp/rsscomments.aspx?PostID=457423</wfw:comment><description>Locking down desktops is becoming more and more prevalent in today’s corporate environment. Malware, viruses and malicious users are putting the pressure on IT staff to remove users as local admin’s and lockdown systems. In order for this to be successful, administrators need a delivery mechanism to install software and hot fixes to users machines. Here is some of our experiences in locking down desktops as a very import step in securing your infrastructure. Specifically, we focused on locking down desktop via Group Policy and how to leverage that in an Active Directory environment. ...(&lt;a href="http://blogs.technet.com/asiasupp/archive/2006/09/19/457423.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=457423" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/asiasupp/archive/tags/Active+Directory/default.aspx">Active Directory</category><category domain="http://blogs.technet.com/asiasupp/archive/tags/Best+Practice/default.aspx">Best Practice</category></item><item><title>DFS namespace permissions</title><link>http://blogs.technet.com/asiasupp/archive/2006/09/19/457422.aspx</link><pubDate>Tue, 19 Sep 2006 10:15:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:457422</guid><dc:creator>gbs</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/asiasupp/comments/457422.aspx</comments><wfw:commentRss>http://blogs.technet.com/asiasupp/commentrss.aspx?PostID=457422</wfw:commentRss><wfw:comment>http://blogs.technet.com/asiasupp/rsscomments.aspx?PostID=457422</wfw:comment><description>This is a common topic in the DFS_FRS field. Customers often describe how some users are unexpectedly denied access to targets in the namespace while other users can access the targets without problems. Customers also ask whether there are DFS permissions somewhere that must be adjusted. The answer is that DFS clients will respect the combination of NTFS and share permissions set on the particular target the client is trying to access. ...(&lt;a href="http://blogs.technet.com/asiasupp/archive/2006/09/19/457422.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=457422" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/asiasupp/archive/tags/Active+Directory/default.aspx">Active Directory</category><category domain="http://blogs.technet.com/asiasupp/archive/tags/Best+Practice/default.aspx">Best Practice</category></item><item><title>Hot issue Errors related to Kerberos authentication</title><link>http://blogs.technet.com/asiasupp/archive/2006/09/19/457413.aspx</link><pubDate>Tue, 19 Sep 2006 09:52:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:457413</guid><dc:creator>gbs</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/asiasupp/comments/457413.aspx</comments><wfw:commentRss>http://blogs.technet.com/asiasupp/commentrss.aspx?PostID=457413</wfw:commentRss><wfw:comment>http://blogs.technet.com/asiasupp/rsscomments.aspx?PostID=457413</wfw:comment><description>Kerberos is the default protocol for network authentication in Windows Server 2003. The Kerberos authentication protocol provides a mechanism for mutual authentication between a client and a server, or between one server and another, before a network connection is opened between them. It is more flexible and efficient than NTLM, and more secure. However, if Kerberos authentication fails between computers in a domain, we may encounter problems in DC replication, sharing resources, logon or other operations. ...(&lt;a href="http://blogs.technet.com/asiasupp/archive/2006/09/19/457413.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=457413" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/asiasupp/archive/tags/Active+Directory/default.aspx">Active Directory</category><category domain="http://blogs.technet.com/asiasupp/archive/tags/Hot+Issue/default.aspx">Hot Issue</category></item><item><title>Forcefully demote a Windows Server 2003 domain controller</title><link>http://blogs.technet.com/asiasupp/archive/2006/09/06/454327.aspx</link><pubDate>Wed, 06 Sep 2006 12:45:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:454327</guid><dc:creator>gbs</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/asiasupp/comments/454327.aspx</comments><wfw:commentRss>http://blogs.technet.com/asiasupp/commentrss.aspx?PostID=454327</wfw:commentRss><wfw:comment>http://blogs.technet.com/asiasupp/rsscomments.aspx?PostID=454327</wfw:comment><description>Under some circumstances, a domain controller cannot be gracefully demoted due to the required dependency or operation failing. These include network connectivity, name resolution, authentication, Active Directory service replication, or the location of a critical object in Active Directory. As a last resort, we can perform a forced removal of a domain controller from Active Directory to avoid having to reinstall the operating system on a domain controller that has failed and cannot be recovered. When a domain controller can no longer function in a domain (that is, it is offline), you cannot remove Active Directory in the normal way, which requires connectivity to the domain. Forced removal is not intended to replace the normal Active Directory removal procedure in any way. It is virtually equivalent to permanently disconnecting the domain controller.  ...(&lt;a href="http://blogs.technet.com/asiasupp/archive/2006/09/06/454327.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=454327" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/asiasupp/archive/tags/Active+Directory/default.aspx">Active Directory</category><category domain="http://blogs.technet.com/asiasupp/archive/tags/Best+Practice/default.aspx">Best Practice</category></item><item><title>Hot Security issues after installing Windows 2003 SP1</title><link>http://blogs.technet.com/asiasupp/archive/2006/09/06/454323.aspx</link><pubDate>Wed, 06 Sep 2006 11:37:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:454323</guid><dc:creator>gbs</dc:creator><slash:comments>4</slash:comments><comments>http://blogs.technet.com/asiasupp/comments/454323.aspx</comments><wfw:commentRss>http://blogs.technet.com/asiasupp/commentrss.aspx?PostID=454323</wfw:commentRss><wfw:comment>http://blogs.technet.com/asiasupp/rsscomments.aspx?PostID=454323</wfw:comment><description>Windows 2003 Service Pack 1 makes some significant changes to security including start up account for services, DCOM security and etc. Services such as RPC and DCOM are integral to Windows Server 2003, but they are also an alluring target for hackers. By requiring greater authentication for RPC and DCOM calls, Service Pack 1 establishes a minimum threshold of security for all applications that use these services, even if they possess little or no security themselves. Since SP1 has stronger defaults and privilege reduction on services, it may result in some issues after installing SP1. ...(&lt;a href="http://blogs.technet.com/asiasupp/archive/2006/09/06/454323.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=454323" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/asiasupp/archive/tags/Active+Directory/default.aspx">Active Directory</category><category domain="http://blogs.technet.com/asiasupp/archive/tags/Hot+Issue/default.aspx">Hot Issue</category></item></channel></rss>