Welcome to TechNet Blogs Sign in | Join | Help

Ask the Directory Services Team

Microsoft's official Enterprise Platform Support DS blog

News

  • Disclaimer: All postings are provided "AS IS" with no warranties, and confer no rights. This weblog does not represent the thoughts, intentions, plans or strategies of Microsoft. Because a weblog is intended to provide a semi-permanent point-in-time snapshot, you should not consider out of date posts to reflect current thoughts and opinions.

    Locations of visitors to this page

Browse by Tags

All Tags » Security   (RSS)
NTLM Blocking and You: Application Analysis and Auditing Methodologies in Windows 7
Ned here again. Windows 7 and Windows Server 2008 R2 introduce a long sought feature known as NTLM blocking. This prevents NTLM from being used for authentication. IT works in both a send or receive mode, and allows you to create exceptions. There’s currently Read More...
Understanding LDAP Security Processing
It’s Randy again, here to discuss LDAP security. Lightweight Directory Access Protocol is an interface used to read from and write to the Active Directory database. Therefore, your Active Directory Administration tools (i.e. AD Users and Computers , AD Read More...
Designing and Implementing a PKI: Part I Design and Planning
Chris here again. This is part of a five part series. In Part I, I will cover design considerations, and planning for deploying a PKI. When implementing a PKI planning is the most important phase, and you can prevent a lot of issues by properly planning Read More...
What occurs when the Security Group Policy CSE encounters a null DACL
The Group Policy security client side extension can distribute security descriptors on files and registry keys. This extension is difficult to troubleshoot because it is considerably durable when it comes to failures. In most situations, it completes Read More...
Null and Empty DACLs
Background Windows uses the concept of a security descriptor to allow or deny security principals (user or groups) access to specific resources. A security descriptor is a data structure that contains: The memory location of a security identifier of a Read More...
MS Security Intelligence Report Volume 6 Released
Ned here again. If you are at all interested in security, here is a must-read: Microsoft Security Intelligence Report volume 6 (July - December 2008) This covers trends and perspectives on: Software vulnerabilities (both in Microsoft software and in third-party Read More...
Five common questions about AdminSdHolder and SDProp
Ned here again. After a few years of supporting Active Directory, nearly everyone runs into an issue with AdminSdHolder . This object and its AD worker code is used by Domain Controllers to protect high-privilege accounts from inadvertent modification Read More...
How to Hide User Information When Computer is Locked
Hi, this is Amit from the Directory Services team and I am going to discuss a Group Policy setting which is now available in XP SP3 & 2003 SP2. Whenever we logon to a Windows workstation, we always see a previously logged on user; we might want to Read More...
Negotiate security support provider behavior
Greetings DS blog readers, Todd here. I wanted to talk a little about the Negotiate security support provider (SSP) and how there are times when it will intentionally use NTLM rather than Kerberos. [ And if that’s not interesting, keep reading anyway Read More...
Getting a CMD prompt as SYSTEM in Windows Vista and Windows Server 2008
Ned here again. In the course of using Windows, it is occasionally useful to be someone besides… you. Maybe you need to be an Administrator temporarily in order to fix a problem. Or maybe you need to be a different user as only they seem to have a problem. Read More...
Fail to log Security Settings from Default Domain Policy
Hello everyone, Scott Goad here, and today I want to take a few minutes and talk about a recent case where we fail to log security settings from the Default Domain Policy. In this case, we had a small environment with 2 domain controllers, one holding Read More...
Default Security Templates in Windows 2008
Hi, David here again. You might be familiar with Security Templates that we use in Windows 2000 and 2003. The template is sort of the master set of security settings that we apply to a server when you either set it up or configure it using the Security Read More...
The Security Descriptor Definition Language of Love (Part 2)
Hi. Jim here from DS here with a follow up to my SDDL blog part I. At the end of my last post I promised to dissect further the SDDL output returned by running the CACLS with the /S switch on tools share as follows: Here is the output exported to a .txt Read More...
The Security Descriptor Definition Language of Love (Part 1)
Hi. Jim from DS here to tell you more than you ever wanted to know about the Security Descriptor Definition Language (SDDL). Windows uses SDDL in the nTSecurityDescriptor. The SDDL defines string elements for enumerating information contained in the security Read More...
Page view tracker