<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Ask the Directory Services Team</title><link>http://blogs.technet.com/askds/default.aspx</link><description>Microsoft's official Enterprise Platform Support DS blog</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>New Directory Services KB Articles/Blogs 1/31-2/6</title><link>http://blogs.technet.com/askds/archive/2010/02/09/new-directory-services-kb-articles-blogs-1-31-2-6.aspx</link><pubDate>Tue, 09 Feb 2010 14:54:22 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3311562</guid><dc:creator>Craig</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/askds/comments/3311562.aspx</comments><wfw:commentRss>http://blogs.technet.com/askds/commentrss.aspx?PostID=3311562</wfw:commentRss><description>&lt;p&gt;&lt;strong&gt;KB&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;No new DS-related KBs this week.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Blogs&lt;/strong&gt;&lt;/p&gt;  &lt;table border="1" cellspacing="0" cellpadding="2" width="500"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blogs.technet.com/askds/archive/2010/02/05/friday-mail-sack-first-attempt-edition.aspx"&gt;Friday Mail Sack – First Attempt Edition&lt;/a&gt;&lt;/u&gt;&lt;u&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;a href="http://blogs.technet.com/askds/archive/2010/02/04/inventorying-computers-with-ad-powershell.aspx"&gt;Inventorying Computers with AD PowerShell&lt;/a&gt;&lt;u&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://www.frickelsoft.net/blog/?p=243"&gt;Categorizing LDAP searches - inefficient vs. expensive?&lt;/a&gt;&lt;/u&gt;&lt;u&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://www.frickelsoft.net/blog/?p=242"&gt;What GP-settings should I roll out in my environment?&lt;/a&gt;&lt;/u&gt;&lt;u&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blogs.msdn.com/rds/archive/2010/02/05/announcing-the-remote-desktop-protocol-performance-improvements-in-windows-server-2008-r2-and-windows-7-white-paper.aspx"&gt;Announcing the Remote Desktop Protocol Performance Improvements in Windows Server 2008 R2 and Windows 7 white paper&lt;/a&gt;&lt;/u&gt;&lt;u&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blog.joeware.net/2010/02/05/1896/"&gt;Active Directory (and ADAM/ADLDS) Tombstone Lifetime&lt;/a&gt;&lt;/u&gt;&lt;u&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blogs.technet.com/grouppolicy/archive/2010/01/25/gp-editorial-group-policy-best-practices.aspx"&gt;GP Editorial: Group Policy Best Practices&lt;/a&gt;&lt;/u&gt;&lt;u&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://edge.technet.com/Media/Windows-7-BranchCache-User-Experience/"&gt;Windows 7 BranchCache™ User Experience&lt;/a&gt;&lt;/u&gt;&lt;u&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://feedproxy.google.com/~r/techtarget/Searchwinsystems/~3/4MecpMqdDl8/0,289142,sid68_gci1380694,00.html"&gt;Updated management pack monitors DFS namespaces&lt;/a&gt;&lt;/u&gt;&lt;u&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blogs.dirteam.com/blogs/sanderberkouwer/archive/2010/02/03/server-core-roles-and-features-in-2008-r2.aspx"&gt;Server Core Roles and Features in 2008 R2&lt;/a&gt;&lt;/u&gt;&lt;u&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blogs.dirteam.com/blogs/sanderberkouwer/archive/2010/02/02/how-to-get-going-with-powershell-in-server-core-r2.aspx"&gt;How to get going with PowerShell in Server Core R2&lt;/a&gt;&lt;/u&gt;&lt;u&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://feeds.ziffdavisenterprise.com/~r/RSS/MicrosoftWatch/~3/sh-VwAJuIqU/windows_7_rc_users_youre_about_to_become_lost.html"&gt;Windows 7 RC Users, You're About to Become Lost&lt;/a&gt;&lt;/u&gt;&lt;u&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blogs.technet.com/askperf/archive/2010/02/02/two-minute-drill-wmi-code-creator.aspx"&gt;Two Minute Drill – WMI Code Creator&lt;/a&gt;&lt;/u&gt;&lt;u&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://trycatch.be/blogs/roggenk/archive/2010/02/01/virtual-machine-manager-2008-r2-listening-ports.aspx"&gt;Virtual Machine Manager 2008 (R2) listening ports&lt;/a&gt;&lt;/u&gt;&lt;u&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://feedproxy.google.com/~r/techtarget/Searchwinsystems/~3/ZGWli3gSSeE/0,295582,sid68_gci1379897,00.html"&gt;Top 10 changes to Windows Server 2008 R2&lt;/a&gt;&lt;/u&gt;&lt;u&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://edge.technet.com/Media/The-PowerShell-management-module-for-Hyper-V/"&gt;The PowerShell management module for Hyper-V&lt;/a&gt;&lt;/u&gt;&lt;u&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://feedproxy.google.com/~r/GroupPolicyCenter/~3/6fJeVnCDJs4/"&gt;Group Policy setting(s) of the week 12 – Prevent changing desktop background &amp;amp; Desktop Wallpaper&lt;/a&gt;&lt;/u&gt;&lt;u&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blogs.technet.com/janelewis/archive/2010/01/31/enterprise-domain-controllers-group-and-group-policys.aspx"&gt;Enterprise Domain Controllers Group and Group Policies&lt;/a&gt;&lt;/u&gt;&lt;u&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blogs.technet.com/filecab/archive/2010/01/31/using-file-classification-infrastructure-fci-and-ad-rms-to-automatically-protect-sensitive-information.aspx"&gt;Using File Classification Infrastructure (FCI) and AD RMS to automatically protect sensitive information&lt;/a&gt;&lt;/u&gt;&lt;u&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3311562" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/askds/archive/tags/KB+Articles/default.aspx">KB Articles</category><category domain="http://blogs.technet.com/askds/archive/tags/Other+Blogs/default.aspx">Other Blogs</category></item><item><title>GP Editorial on the Group Policy blog</title><link>http://blogs.technet.com/askds/archive/2010/02/08/gp-editorial-on-the-group-policy-blog.aspx</link><pubDate>Mon, 08 Feb 2010 15:30:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3311306</guid><dc:creator>NedPyle</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/askds/comments/3311306.aspx</comments><wfw:commentRss>http://blogs.technet.com/askds/commentrss.aspx?PostID=3311306</wfw:commentRss><description>&lt;P&gt;Ned here. Mike Stephens has a short editorial on the GP development team blog. It addresses the fallacy of group policy "best practices" and is a good read for philosophy majors as well as IT staff. Here's a snippet:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"Yes, there might be settings common to “locking down a computer”, but what does “locking down” mean? Everyone is likely to have a different answer.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/grouppolicy/archive/2010/01/25/gp-editorial-group-policy-best-practices.aspx" mce_href="http://blogs.technet.com/grouppolicy/archive/2010/01/25/gp-editorial-group-policy-best-practices.aspx"&gt;Read the rest&lt;/A&gt;&amp;nbsp;and leave some comments.&lt;/P&gt;
&lt;P&gt;- Ned "Descartes" Pyle&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3311306" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/askds/archive/tags/group+policy/default.aspx">group policy</category></item><item><title>Friday Mail Sack – First Attempt Edition</title><link>http://blogs.technet.com/askds/archive/2010/02/05/friday-mail-sack-first-attempt-edition.aspx</link><pubDate>Fri, 05 Feb 2010 15:59:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3310904</guid><dc:creator>NedPyle</dc:creator><slash:comments>6</slash:comments><comments>http://blogs.technet.com/askds/comments/3310904.aspx</comments><wfw:commentRss>http://blogs.technet.com/askds/commentrss.aspx?PostID=3310904</wfw:commentRss><description>&lt;P&gt;Hi all, Ned here again. Today I will share some recent questions we’ve gotten offline that never ended up as full blown blog posts. Naturally any names have been changed to protect the innocent and things are often paraphrased. This post starts a new series that will appear every Friday, barring some kind of disaster such as me being out sick, me taking the day off, or me just not feeling like it (so &lt;EM&gt;nyyyaaahhh&lt;/EM&gt;).&lt;/P&gt;
&lt;P&gt;Onward.&lt;/P&gt;
&lt;H3&gt;Question: &lt;/H3&gt;
&lt;P&gt;Is there any risk running Windows disk defrag on a DC? I need to defrag my drives and I’m worried about &lt;B&gt;NTDS.DIT&lt;/B&gt; corruption.&lt;/P&gt;
&lt;H3&gt;Answer:&lt;/H3&gt;
&lt;P&gt;Nothing to worry about. In fact, starting in Windows Server 2008 and continuing in R2, you have been running a disk defrag every Wednesday at 1 AM whether you knew it or not. This is default behavior, even on domain controllers.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/FridayMailSackFirstAttemptEdition_9A8E/image_2.png" mce_href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/FridayMailSackFirstAttemptEdition_9A8E/image_2.png"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; DISPLAY: inline; BORDER-TOP: 0px; BORDER-RIGHT: 0px" title=image border=0 alt=image src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/FridayMailSackFirstAttemptEdition_9A8E/image_thumb.png" width=616 height=358 mce_src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/FridayMailSackFirstAttemptEdition_9A8E/image_thumb.png"&gt;&lt;/A&gt; &lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Note that the task is designed to run in idle state though, so if things stay really busy on a DC all night long, the automatic defrag may be preempted. The Task Scheduler Help has more info on what “Idle” means.&lt;/P&gt;
&lt;H3&gt;Question: &lt;/H3&gt;
&lt;P&gt;When I search AD for old computer accounts by using the &lt;I&gt;whenChanged&lt;/I&gt; attribute that computers seem to be constantly “new”. How can I find old unused computer accounts using PowerShell? &lt;/P&gt;
&lt;H3&gt;Answer:&lt;/H3&gt;
&lt;P&gt;The attribute you want to use in this scenario is &lt;I&gt;lastLogonTimeStamp&lt;/I&gt;; Warren wrote up a pretty comprehensive treatise &lt;A href="http://blogs.technet.com/askds/archive/2009/04/15/the-lastlogontimestamp-attribute-what-it-was-designed-for-and-how-it-works.aspx" mce_href="http://blogs.technet.com/askds/archive/2009/04/15/the-lastlogontimestamp-attribute-what-it-was-designed-for-and-how-it-works.aspx"&gt;in this older post.&lt;/A&gt; You can search for these inactive accounts using things like AD PowerShell’s cmdlet &lt;B&gt;search-adaccount&lt;/B&gt;. For example, this would find all computers in the domain that have not logged into AD in a year:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;FONT size=2 face=Consolas&gt;Search-ADaccount -AccountInactive -Timespan 365 -ComputersOnly&lt;/FONT&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Avoid looking at stale passwords, as password changes can be disabled. And before acting upon inactive accounts, make &lt;I&gt;triple sure it’s really inactive&lt;/I&gt;. Cluster virtual computer objects don’t necessarily “logon” but if you arbitrarily get rid of them there will be heck to pay. Automating the removal is generally a bad idea.&lt;/P&gt;
&lt;H3&gt;Question:&lt;/H3&gt;
&lt;P&gt;I am trying to use the &lt;B&gt;Delegate Control &lt;/B&gt;wizard within &lt;B&gt;DSA.MSC&lt;/B&gt;. When I use a custom task delegation for &lt;I&gt;User Objects&lt;/I&gt; I can’t specify certain attributes like Office, E-Mail, City, State, or Country. How can I get these?&lt;/P&gt;
&lt;H3&gt;Answer:&lt;/H3&gt;
&lt;P&gt;Choose the &lt;I&gt;inetOrgPerson&lt;/I&gt; object class instead of User – this will get you the granularity you need with the delegation wizard. Chalk this up to vagaries of snap-in, schema, class, and inheritance. &lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/FridayMailSackFirstAttemptEdition_9A8E/image_4.png" mce_href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/FridayMailSackFirstAttemptEdition_9A8E/image_4.png"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; DISPLAY: inline; BORDER-TOP: 0px; BORDER-RIGHT: 0px" title=image border=0 alt=image src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/FridayMailSackFirstAttemptEdition_9A8E/image_thumb_1.png" width=310 height=278 mce_src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/FridayMailSackFirstAttemptEdition_9A8E/image_thumb_1.png"&gt;&lt;/A&gt;&amp;nbsp; &lt;A href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/FridayMailSackFirstAttemptEdition_9A8E/image_6.png" mce_href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/FridayMailSackFirstAttemptEdition_9A8E/image_6.png"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; DISPLAY: inline; BORDER-TOP: 0px; BORDER-RIGHT: 0px" title=image border=0 alt=image src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/FridayMailSackFirstAttemptEdition_9A8E/image_thumb_2.png" width=304 height=277 mce_src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/FridayMailSackFirstAttemptEdition_9A8E/image_thumb_2.png"&gt;&lt;/A&gt; &lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;H3&gt;Question:&lt;/H3&gt;
&lt;P&gt;Application &lt;I&gt;X&lt;/I&gt; doesn’t seem to work correctly with Read-Only Domain Controllers, and I am not finding anything online that says it is compatible. What should I do?&lt;/P&gt;
&lt;H3&gt;Answer:&lt;/H3&gt;
&lt;P&gt;Find out who created that application and talk to their support staff. If it’s a Microsoft application or Windows component, open a support case and ask to speak that particular specialty. If not MS, call that vendor. If internal to your company, find that developer! There’s no way for the AD developers test everything against RODC’s – not even within the MS-developed gamut of applications, which is huge. They have to rely on application developers to add it to their test harnesses. If the conversation with the vendor starts with “What’s an RODC?”, they probably don’t test it. :)&lt;/P&gt;
&lt;P&gt;No matter who you talk to, once it’s established that an RODC is or isn’t supported, &lt;I&gt;make them document it publically&lt;/I&gt;; even if it’s just a blog post, you are helping out your fellow IT humans.&lt;/P&gt;
&lt;H3&gt;Question:&lt;/H3&gt;
&lt;P&gt;Hey, I think I found an error in KB article &lt;I&gt;Y&lt;/I&gt;. Can you fix it? &lt;/P&gt;
&lt;H3&gt;Answer:&lt;/H3&gt;
&lt;P&gt;You betcha. Just tell us exactly what you think is wrong, making sure to give us repro steps. If we confirm it as factual error&amp;nbsp; the KB should be corrected within a few weeks. If it comes down to semantics or a difference of opinion…well, as my wife says “we’ll just have to agree to disagree” (i.e. Ned is wrong, Lisa is right, and there’s nothing Ned can do about it).&lt;/P&gt;
&lt;H3&gt;Question:&lt;/H3&gt;
&lt;P&gt;I need some deeper support than this blog is set up for and time is not an issue, but I am a bit strapped for cash. Is there anywhere reputable I can go?&lt;/P&gt;
&lt;H3&gt;Answer:&lt;/H3&gt;
&lt;P&gt;Our community forums are an excellent place to ask deeper specific questions. These are moderated by MS support engineers and MVP’s. Many questions can be answered quickly and reliably by trustworthy folks. &lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="http://social.technet.microsoft.com/Forums/en-us/categories/" mce_href="http://social.technet.microsoft.com/Forums/en-us/categories/"&gt;TechNet forums&lt;/A&gt; (Windows, Exchange, Forefront, System Center, Office)&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://social.msdn.microsoft.com/Forums/en-US/categories" mce_href="http://social.msdn.microsoft.com/Forums/en-US/categories"&gt;MSDN forums&lt;/A&gt; (Programming languages, SQL)&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;If time and live support is critical though, open a support case. Time is money.&lt;/P&gt;
&lt;P&gt;I reckon that’s enough for today. Have a nice weekend folks.&lt;/P&gt;
&lt;P&gt;- Ned ‘going postal’ Pyle&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3310904" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/askds/archive/tags/KB+Articles/default.aspx">KB Articles</category><category domain="http://blogs.technet.com/askds/archive/tags/RODC/default.aspx">RODC</category><category domain="http://blogs.technet.com/askds/archive/tags/Mail+Sack/default.aspx">Mail Sack</category><category domain="http://blogs.technet.com/askds/archive/tags/Disks+and+NTFS/default.aspx">Disks and NTFS</category></item><item><title>Inventorying Computers with AD PowerShell</title><link>http://blogs.technet.com/askds/archive/2010/02/04/inventorying-computers-with-ad-powershell.aspx</link><pubDate>Thu, 04 Feb 2010 17:04:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3310686</guid><dc:creator>NedPyle</dc:creator><slash:comments>7</slash:comments><comments>http://blogs.technet.com/askds/comments/3310686.aspx</comments><wfw:commentRss>http://blogs.technet.com/askds/commentrss.aspx?PostID=3310686</wfw:commentRss><description>&lt;P&gt;Hi, Ned here again. Have you ever had to figure out what operating systems are running in your domain environment so that you can plan for upgrades, service pack updates, or support lifecycle transitions? Did you know that you don’t have to connect to any of the computers to find out? It’s easier than you might think, and all possible once you start using &lt;A href="http://technet.microsoft.com/en-us/library/dd378937(WS.10).aspx" mce_href="http://technet.microsoft.com/en-us/library/dd378937(WS.10).aspx"&gt;AD PowerShell&lt;/A&gt; in Windows Server 2008 R2 or Windows 7 with &lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyID=7D2F6AD7-656B-4313-A005-4E344E43997D&amp;amp;displaylang=en" mce_href="http://www.microsoft.com/downloads/details.aspx?FamilyID=7D2F6AD7-656B-4313-A005-4E344E43997D&amp;amp;displaylang=en"&gt;RSAT&lt;/A&gt;.&lt;/P&gt;
&lt;H3&gt;Get-ADComputer&lt;/H3&gt;
&lt;P&gt;The cmdlet of choice for inventorying computers through AD is &lt;B&gt;Get-ADComputer&lt;/B&gt;. This command automatically searches for computer objects throughout a domain, returning all sorts of info. &lt;/P&gt;
&lt;P&gt;As I have written about &lt;A href="http://blogs.technet.com/askds/archive/2009/08/27/the-ad-recycle-bin-understanding-implementing-best-practices-and-troubleshooting.aspx" mce_href="http://blogs.technet.com/askds/archive/2009/08/27/the-ad-recycle-bin-understanding-implementing-best-practices-and-troubleshooting.aspx"&gt;previously &lt;/A&gt;my first step is to fire up PowerShell and import the &lt;B&gt;ActiveDirectory&lt;/B&gt; module:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_2.png" mce_href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_2.png"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; DISPLAY: inline; BORDER-TOP: 0px; BORDER-RIGHT: 0px" title=image border=0 alt=image src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_thumb.png" width=393 height=74 mce_src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_thumb.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;Then if I want to see all the details about using this cmdlet, I run:&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face=Consolas&gt;Get-Help Get-ADComputer -Full&lt;/FONT&gt;&lt;/P&gt;
&lt;H3&gt;Getting OS information&lt;/H3&gt;
&lt;H5&gt;Basics&lt;/H5&gt;
&lt;P&gt;Now I want to pull some data from my domain. I start by running the following:&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;I&gt;Important note:&lt;/I&gt;&lt;/B&gt; in all my samples below, the lines are wrapped for readability.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Another important note&lt;/EM&gt; &lt;/STRONG&gt;(thanks dloder): I am going for simplicity and introduction here, so the -Filter and -Property switches are not designed for perfect efficiency. As you get comfortable with AD PowerShell, I highly recommend that you start tuning for less data to be returned - the "filter left, format right" model &lt;A href="http://technet.microsoft.com/en-us/magazine/2009.09.windowspowershell.aspx" mce_href="http://technet.microsoft.com/en-us/magazine/2009.09.windowspowershell.aspx"&gt;described here by Don Jones.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face=Consolas&gt;Get-ADComputer -Filter * -Property * | Format-Table Name,OperatingSystem,OperatingSystemServicePack,OperatingSystemVersion -Wrap –Auto&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_4.png" mce_href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_4.png"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; DISPLAY: inline; BORDER-TOP: 0px; BORDER-RIGHT: 0px" title=image border=0 alt=image src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_thumb_1.png" width=611 height=60 mce_src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_thumb_1.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;This command is filtering all computers for all their properties. It then feeds the data (using that pipe symbol) into a formatted table. The only attributes that the table contains are the computer name, operating system description, service pack, and OS version. It also automatically sizes and wraps the data. When run, I see:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_6.png" mce_href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_6.png"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; DISPLAY: inline; BORDER-TOP: 0px; BORDER-RIGHT: 0px" title=image border=0 alt=image src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_thumb_2.png" width=622 height=218 mce_src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_thumb_2.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;It looks like I have some work to do here – one Windows Server 2003 computer needs &lt;A href="http://support.microsoft.com/lifecycle/search/default.aspx?sort=PN&amp;amp;alpha=windows+server+2003+&amp;amp;Filter=FilterNO" mce_href="http://support.microsoft.com/lifecycle/search/default.aspx?sort=PN&amp;amp;alpha=windows+server+2003+&amp;amp;Filter=FilterNO"&gt;Service Pack 2 installed ASAP&lt;/A&gt;. And I still have a &lt;A href="http://support.microsoft.com/gp/lifean36?info=EXLINK" mce_href="http://support.microsoft.com/gp/lifean36?info=EXLINK"&gt;Windows 2000&lt;/A&gt; server that is going to move quickly and replace that server.&lt;/P&gt;
&lt;H5&gt;Server Filtering&lt;/H5&gt;
&lt;P&gt;Now I start breaking down the results with filters. I run:&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face=Consolas&gt;Get-ADComputer -Filter {OperatingSystem -Like "Windows Server*"} -Property * | Format-Table Name,OperatingSystem,OperatingSystemServicePack -Wrap -Auto&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;I have changed my filter to find all the computers that are running “Windows Server &lt;I&gt;something&lt;/I&gt;”, using the &lt;B&gt;–like&lt;/B&gt; filter. And I stopped displaying the OS version data because it was not providing me anything unique (yet!).&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_8.png" mce_href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_8.png"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; DISPLAY: inline; BORDER-TOP: 0px; BORDER-RIGHT: 0px" title=image border=0 alt=image src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_thumb_3.png" width=627 height=144 mce_src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_thumb_3.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;Cool, now only servers are listed! But wait… where’d my Windows 2000 server go? Ahhhh… sneaky. We didn’t start calling OS’s “Windows Server” until 2003. Before that it was “Windows 2000 Server”. I need to massage my filter a bit:&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face=Consolas&gt;Get-ADComputer -Filter {OperatingSystem -Like "Windows *Server*"} -Property * | Format-Table Name,OperatingSystem,OperatingSystemServicePack -Wrap -Auto&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;See the difference? I just added an extra asterisk to surround “Server”.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_10.png" mce_href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_10.png"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; DISPLAY: inline; BORDER-TOP: 0px; BORDER-RIGHT: 0px" title=image border=0 alt=image src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_thumb_4.png" width=629 height=135 mce_src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_thumb_4.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;As you can see, my environment has a variety of Windows server versions running. I’m interested in the ones that are running Windows Server 2008 or Windows Server 2008 R2. And once I have that, I might just want to see the R2 servers – I have an upcoming &lt;A href="http://technet.microsoft.com/en-us/library/ee307957(WS.10).aspx" mce_href="http://technet.microsoft.com/en-us/library/ee307957(WS.10).aspx"&gt;DFSR clustering project&lt;/A&gt; that requires some R2 computers. I run these two sets of commands:&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face=Consolas&gt;Get-ADComputer -Filter {OperatingSystem -Like "Windows Server*2008*"} -Property * | Format-Table Name,OperatingSystem,OperatingSystemServicePack -Wrap -Auto&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face=Consolas&gt;Get-ADComputer -Filter {OperatingSystem -Like "Windows Server*r2*"} -Property * | Format-Table Name,OperatingSystem,OperatingSystemServicePack -Wrap -Auto&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_12.png" mce_href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_12.png"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; DISPLAY: inline; BORDER-TOP: 0px; BORDER-RIGHT: 0px" title=image border=0 alt=image src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_thumb_5.png" width=631 height=98 mce_src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_thumb_5.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_14.png" mce_href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_14.png"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; DISPLAY: inline; BORDER-TOP: 0px; BORDER-RIGHT: 0px" title=image border=0 alt=image src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_thumb_6.png" width=633 height=96 mce_src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_thumb_6.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;Starting to make sense? Repetition is key; hopefully you are following along with your own servers.&lt;/P&gt;
&lt;H5&gt;Workstation Filtering&lt;/H5&gt;
&lt;P&gt;Okeydokey, I think I’ve got all I need to know about servers – now what about all those workstations? I will simply switch from -&lt;B&gt;Like&lt;/B&gt; to &lt;B&gt;-Notlike &lt;/B&gt;with my previous server query:&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face=Consolas&gt;Get-ADComputer -Filter {OperatingSystem -NotLike "*server*"} -Property * | Format-Table Name,OperatingSystem,OperatingSystemServicePack -Wrap -Auto&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;And blammo:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_16.png" mce_href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_16.png"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; DISPLAY: inline; BORDER-TOP: 0px; BORDER-RIGHT: 0px" title=image border=0 alt=image src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_thumb_7.png" width=634 height=138 mce_src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_thumb_7.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;H5&gt;Family filtering&lt;/H5&gt;
&lt;P&gt;By now these filters should be making more sense and PowerShell is looking less scary. Let’s say I want to filter by the “family” of operating system. This can be useful when trying to identify computers that started having a special capability in one OS release and all subsequent releases, and where I don’t care about it being server or workstation. An example of that would be &lt;B&gt;BitLocker&lt;/B&gt; – it only works on Windows Vista, Windows Server 2008, and later. I run:&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face=Consolas&gt;Get-ADComputer -Filter {OperatingSystemVersion -ge "6"} -Property * | Format-Table Name,OperatingSystem,OperatingSystemVersion -Wrap -Auto&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;See the change? I am now filtering on operating system version, to be equal to or greater than 6. This means that any computers that have a kernel version of 6 (Vista and 2008) or higher will be returned:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_18.png" mce_href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_18.png"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; DISPLAY: inline; BORDER-TOP: 0px; BORDER-RIGHT: 0px" title=image border=0 alt=image src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_thumb_8.png" width=634 height=143 mce_src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_thumb_8.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;If I just wanted my Windows Server 2008 R2 and Windows 7 family of computers, I can change my filter slightly:&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face=Consolas&gt;Get-ADComputer -Filter {OperatingSystemVersion -ge "6.1"} -Property * | Format-Table Name,OperatingSystem,OperatingSystemVersion -Wrap -Auto&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_20.png" mce_href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_20.png"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; DISPLAY: inline; BORDER-TOP: 0px; BORDER-RIGHT: 0px" title=image border=0 alt=image src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_thumb_9.png" width=637 height=102 mce_src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_thumb_9.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;H3&gt;Getting it all into a file&lt;/H3&gt;
&lt;P&gt;So what we’ve done ‘til now was just use PowerShell to send goo out to the screen and stare. In all but the smallest domains, though, this will soon get unreadable. I need a way to send all this out to a text file for easier sorting, filtering, and analysis. &lt;/P&gt;
&lt;P&gt;This is where &lt;B&gt;Export-CSV&lt;/B&gt; comes in. With the chaining of an additional pipeline I can find all the computers, select the attributes I find valuable for them, then send them into a comma-separated text file that is even able to read the weirdo UTF-8 trademark characters that lawyers sometimes make us put in AD.&lt;/P&gt;
&lt;P&gt;Hey, what do you call a million lawyers at the bottom of the ocean? A good start! Why don’t sharks eat lawyers? Professional courtesy! What do have when a lawyer is buried up to his neck in sand? Not enough sand! Haw haw… anyway:&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face=Consolas&gt;Get-ADComputer -Filter * -Property * | Select-Object Name,OperatingSystem,OperatingSystemServicePack,OperatingSystemVersion | Export-CSV AllWindows.csv -NoTypeInformation -Encoding UTF8&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_22.png" mce_href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_22.png"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; DISPLAY: inline; BORDER-TOP: 0px; BORDER-RIGHT: 0px" title=image border=0 alt=image src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_thumb_10.png" width=640 height=57 mce_src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_thumb_10.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;Then I just crack open the &lt;B&gt;AllWindows.CSV&lt;/B&gt; file in Excel and:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_24.png" mce_href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_24.png"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; DISPLAY: inline; BORDER-TOP: 0px; BORDER-RIGHT: 0px" title=image border=0 alt=image src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_thumb_11.png" width=643 height=425 mce_src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/InventoryingComputerswithADPowerShell_A6CF/image_thumb_11.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;H3&gt;What about the whole forest?&lt;/H3&gt;
&lt;P&gt;You may be tempted to take some of the commands above and tack on the necessary arguments to search the entire forest. This means adding:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;FONT size=2 face=Consolas&gt;-searchbase “” –server &lt;I&gt;&amp;lt;domain FQDN&amp;gt;&lt;/I&gt;:3268&lt;/FONT&gt; &lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;That way you wouldn’t have to connect to a DC in every domain for the info – instead you’d just ask a single GC. Unfortunately, &lt;I&gt;this won’t work&lt;/I&gt;; none of the operating system attributes are replicated by global catalog servers. Oh well, that’s not PowerShell’s fault. All the data must be pulled from domains individually, but that can be automated – I leave that to you as a learning exercise.&lt;/P&gt;
&lt;H3&gt;Conclusion&lt;/H3&gt;
&lt;P&gt;The point I made above about support lifecycle is no joke: 2010 is a very important year for a lot of Windows products’ support:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="http://support.microsoft.com/gp/lifean31?sort=PN&amp;amp;alpha=WINDOWS+VISTA" mce_href="http://support.microsoft.com/gp/lifean31?sort=PN&amp;amp;alpha=WINDOWS+VISTA"&gt;Windows XP &lt;B&gt;&lt;I&gt;SP2&lt;/I&gt;&lt;/B&gt;&lt;I&gt; &lt;/I&gt;support ends July 13, 2010&lt;/A&gt; (mainstream support for the whole OS ended in 2009 and you must be running SP3 after July 13)&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://support.microsoft.com/gp/lifean35" mce_href="http://support.microsoft.com/gp/lifean35"&gt;Windows 2000 Professional &lt;B&gt;&lt;I&gt;extended &lt;/I&gt;&lt;/B&gt;support ends July 13, 2010&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://support.microsoft.com/win2000?info=EXLINK" mce_href="http://support.microsoft.com/win2000?info=EXLINK"&gt;Windows 2000 Server &lt;B&gt;&lt;I&gt;extended&lt;/I&gt;&lt;/B&gt; support ends July 13, 2010&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://support.microsoft.com/lifecycle/search/default.aspx?sort=PN&amp;amp;alpha=windows+server+2003+&amp;amp;Filter=FilterNO" mce_href="http://support.microsoft.com/lifecycle/search/default.aspx?sort=PN&amp;amp;alpha=windows+server+2003+&amp;amp;Filter=FilterNO"&gt;Windows Server 2003 and Windows Server 2003 R2 &lt;B&gt;&lt;I&gt;mainstream&lt;/I&gt;&lt;/B&gt; support ends July 13, 2010&lt;/A&gt; (SP1 support ended in 2009, you must be running SP2 now)&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://support.microsoft.com/lifecycle/search/default.aspx?sort=PN&amp;amp;alpha=windows+vista&amp;amp;Filter=FilterNO" mce_href="http://support.microsoft.com/lifecycle/search/default.aspx?sort=PN&amp;amp;alpha=windows+vista&amp;amp;Filter=FilterNO"&gt;Windows Vista &lt;B&gt;&lt;I&gt;RTM&lt;/I&gt;&lt;/B&gt; (no service pack) support ends April 13, 2010&lt;/A&gt; (You are running Vista with no service pack? Really?)&lt;/LI&gt;
&lt;LI&gt;For more info on what “support” really means, head over to the &lt;A href="http://support.microsoft.com/lifecycle/search/" mce_href="http://support.microsoft.com/lifecycle/search/"&gt;Lifecycle&lt;/A&gt; page.&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;Hopefully these simple PowerShell commands make hunting down computers a bit easier for you.&lt;/P&gt;
&lt;P&gt;Until next time.&lt;/P&gt;
&lt;P&gt;- Ned “bird dog” Pyle&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3310686" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/askds/archive/tags/PowerShell/default.aspx">PowerShell</category></item><item><title>New Directory Services KB Articles/Blogs 1/24-1/30</title><link>http://blogs.technet.com/askds/archive/2010/02/01/new-directory-services-kb-articles-blogs-1-24-1-30.aspx</link><pubDate>Mon, 01 Feb 2010 18:37:43 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3309870</guid><dc:creator>Craig</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/askds/comments/3309870.aspx</comments><wfw:commentRss>http://blogs.technet.com/askds/commentrss.aspx?PostID=3309870</wfw:commentRss><description>&lt;p&gt;&lt;strong&gt;KB&lt;/strong&gt;&lt;/p&gt;  &lt;table border="1" cellspacing="0" cellpadding="0" width="500"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="33"&gt;         &lt;p&gt;&lt;a href="977357"&gt;977357&lt;/a&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="465"&gt;         &lt;p&gt;A memory leak issue occurs in the Windows Management Instrumentation service on a computer that is running Windows Server 2008 R2 or Windows 7&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="33"&gt;         &lt;p&gt;&lt;a href="http://support.microsoft.com/?kbid=979384"&gt;979384&lt;/a&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="465"&gt;         &lt;p&gt;The application directory partition is not removed from the replication scope in a Windows Server 2003-based domain or in a Windows Server 2008-based domain&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="33"&gt;         &lt;p&gt;&lt;a href="http://support.microsoft.com/?kbid=979601"&gt;979601&lt;/a&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="465"&gt;         &lt;p&gt;The SSL certificate is still bound to port 443 after you disable the WinRM HTTPS compatibility listener&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;&lt;strong&gt;Blogs&lt;/strong&gt;&lt;/p&gt;  &lt;table border="1" cellspacing="0" cellpadding="0" width="500"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blogs.technet.com/askds/archive/2010/01/27/dcdiag-advertising-test-with-error-81.aspx"&gt;DCDIAG Advertising test with error 81&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blogs.technet.com/askds/archive/2010/02/01/certificate-enrollment-web-services.aspx"&gt;Certificate Enrollment Web Services&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://msmvps.com/blogs/ad/archive/2009/05/04/viewing-your-fsmo-role-holders-remotely.aspx"&gt;Viewing your FSMO Role Holders Remotely&lt;/a&gt;&lt;/u&gt;&lt;u&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://theessentialexchange.com/blogs/michael/archive/2010/01/29/a-brief-history-of-time-ok-ok-let-s-go-with-quot-an-introduction-to-the-windows-time-service-quot.aspx"&gt;A Brief History of Time...(ok ok, let's go with &amp;quot;An Introduction to the Windows Time Service&amp;quot;)&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://feedproxy.google.com/~r/techtarget/Searchwinsystems/~3/Z5UfwxthPho/0,289483,sid68_gci1380082,00.html"&gt;Security best practices for Microsoft Hyper-V installations&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://feedproxy.google.com/~r/JacksonsIdentityManagementActiveDirectoryRealityTourTravelblog/~3/kX7vmbUNy4E/enhancing-security-with-attestation-and.html"&gt;Enhancing Security with Attestation – and Accountability&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://msmvps.com/blogs/ad/archive/2010/01/29/system-health-checks.aspx"&gt;Server Health Checks&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://msmvps.com/blogs/ad/archive/2009/12/17/free-active-directory-virtual-labs.aspx"&gt;Free Active Directory Virtual Labs&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blogs.technet.com/askperf/archive/2010/01/29/vmmap-a-peek-inside-virtual-memory.aspx"&gt;VMMap - A Peek Inside Virtual Memory&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://feedproxy.google.com/~r/GroupPolicyCenter/~3/1Un2ZOJXGwA/"&gt;Quick start step by step for Advanced Group Policy Management (AGPM) v4&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blogs.msdn.com/wmi/archive/2010/01/28/quick-and-dirty-large-scale-event-forwarding-for-windows.aspx"&gt;Quick and Dirty Large Scale Event forwarding for Windows&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blogs.dirteam.com/blogs/tomek/archive/2010/01/28/spot-the-difference.aspx"&gt;Spot the difference&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blogs.technet.com/keithcombs/archive/2010/01/28/quick-reminder-windows-7-rc-expiration-looms.aspx"&gt;Quick Reminder – Windows 7 RC expiration looms&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blogs.msdn.com/card/archive/2010/01/27/customizing-the-ad-fs-2-0-sign-in-web-pages.aspx"&gt;Customizing the AD FS 2.0 Sign-in Web Pages&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blogs.technet.com/server_core/archive/2010/01/27/network-binding-management.aspx"&gt;Network Binding Management&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://feedproxy.google.com/~r/GroupPolicyCenter/~3/BLxpn4F_g6s/"&gt;How to use Group Policy Preferences to dynamically map printers with Roaming Profiles&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://edge.technet.com/Media/Securing-Sensitive-Information--How-MSIT-uses-ADRMS--RSA-DLP/"&gt;Securing Sensitive Information – How MSIT uses ADRMS + RSA DLP&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://feedproxy.google.com/~r/JacksonsIdentityManagementActiveDirectoryRealityTourTravelblog/~3/qy2qpG-EdsI/virtual-less-secure-than-physical.html"&gt;Virtual less secure than physical?&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://edge.technet.com/Media/Windows-Server-2008-R2-Quick-Look8-Active-Directory-Administrative-Center/"&gt;Windows Server 2008 R2 Quick Look#8 - Active Directory Administrative Center&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://feedproxy.google.com/~r/JacksonsIdentityManagementActiveDirectoryRealityTourTravelblog/~3/IpKBBNP8adU/group-policy-preferences-overview.html"&gt;Group Policy Preferences Overview&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blogs.technet.com/askperf/archive/2010/01/26/what-s-new-in-windows-powershell-2-0.aspx"&gt;What’s new in Windows PowerShell 2.0&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blogs.technet.com/virtualization/archive/2010/01/26/Hyper_2D00_V-Network-Command-Line-Tool-NVSPBIND-Now-Available-Externally.aspx"&gt;Hyper-V Network Command Line Tool NVSPBIND Now Available Externally&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blogs.technet.com/activedirectoryua/archive/2010/01/25/allow-logon-locally-to-a-domain-controller.aspx"&gt;Allow logon locally to a domain controller&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3309870" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/askds/archive/tags/KB+Articles/default.aspx">KB Articles</category><category domain="http://blogs.technet.com/askds/archive/tags/Other+Blogs/default.aspx">Other Blogs</category></item><item><title>Certificate Enrollment Web Services</title><link>http://blogs.technet.com/askds/archive/2010/02/01/certificate-enrollment-web-services.aspx</link><pubDate>Mon, 01 Feb 2010 15:46:11 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3309819</guid><dc:creator>NedPyle</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/askds/comments/3309819.aspx</comments><wfw:commentRss>http://blogs.technet.com/askds/commentrss.aspx?PostID=3309819</wfw:commentRss><description>&lt;p&gt;Hey everyone, Rob here again. With the release of Windows Server 2008 R2 and Windows 7 we have added new methods of enrolling for certificates: Certificate Enrollment Policy (CEP) and Certificate Enrollment Service (CES). CEP is a web service that enables users and computers to obtain certificate enrollment policy information. This information includes what types of certificates can be requested and which CAs can issue them. CES is another web service that allows users and computers to perform certificate enrollment by using the HTTPS protocol. Together with the CEP web service, CES enables policy-based certificate enrollment when the client computer is not a member of a domain or when a domain member is not connected to the domain. CEP/CES also enables cross-forest policy-based certificate enrollment for Windows 7 or Windows Server 2008 R2 clients. &lt;/p&gt;  &lt;h4&gt;Certificate enrollment without CEP / CES&lt;/h4&gt;  &lt;p&gt;Prior to Windows 7 and Windows Server 2008 R2 the client requesting a certificate requires network access to a domain controller and the Certification Authority (CA).&lt;/p&gt;  &lt;p&gt;Here is a high level description of the process that is used:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/CertificateEnrollmentWebServices_976D/image_2.png"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/CertificateEnrollmentWebServices_976D/image_thumb.png" width="505" height="230" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&lt;font size="1"&gt;Figure 1 - legacy certificate enrollment&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Step 1. LDAP queries to a domain controller for a list of templates and enterprise CA’s.&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;The client computer does several LDAP queries to a local domain controller to get the following:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Queries for a list of &lt;i&gt;pKICertificateTemplate &lt;/i&gt;objects (Certificate Templates) within the forest.&lt;/li&gt;    &lt;li&gt;Queries for a list of &lt;i&gt;pKIEnrollmentService&lt;/i&gt; objects (Enterprise CA’s) within the forest.&lt;/li&gt;    &lt;li&gt;Queries for a list of &lt;i&gt;msPKI-Enterprise-Oid&lt;/i&gt; objects within the forest.&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;Once all of objects are returned to the client, it determines what Enterprise CA’s are available, and what certificate templates can be issued by each one of them. The client then determines the certificate templates for which it has permissions to enroll or autoenroll. If you are enrolling for certificates via the certificates snap-in it will display this list of available templates to the user.&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Step 2. DCOM connection an Enterprise Certification Authority.&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;Once the client selects the certificate template for which to enroll, a DCOM connection is made to the CA. DCOM connects to the &lt;i&gt;CertSrv Request&lt;/i&gt; DCOM interface to enroll for the certificate. The certificate is then handed back to the client.&lt;/p&gt;  &lt;p&gt;You may be thinking at this point “how does it work with the Web Enrollment pages?”&lt;/p&gt;  &lt;p&gt;Certificate web enrollment behaves in nearly the same way. The main difference is that in Figure 1 the web server running the CertSrv web pages would replace the Client. The actual Client communicates with the web enrollment pages over HTTP, so the web enrollment pages are acting as a proxy, querying Active Directory for a list of templates and converting the client’s HTTP based certificate request into a DCOM-based request that can be sent along to the CA. &lt;/p&gt;  &lt;p&gt;As you can see the client has to have direct network connectivity to a domain controller and the Certification Authority to be able to enroll for certificates. With this as a requirement here are a few examples of where enrollment would fail:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Internet based clients that need to enroll for a certificate or renew a certificate.&lt;/li&gt;    &lt;li&gt;Computers in a DMZ network. Typically computers in a DMZ do not have access to internal corporate resources like domain controllers and CA’s because either they are in a workgroup or they belong to a DMZ forest with a one way trust in place.&lt;/li&gt;    &lt;li&gt;Non-domain joined workstations. They are unable to authenticate to a DC and perform the initial LDAP queries, and thus will never make it to step 2 - the RPC / DCOM call.&lt;/li&gt; &lt;/ul&gt;  &lt;h4&gt;Certificate enrollment with CEP / CES&lt;/h4&gt;  &lt;p&gt;We listened to feedback from customers about the above limitations of enrolling for certificates. Our answer was to create two new web services to proxy the enrollment requests. This allows for CA isolation and removes the requirement that the client be able to contact a domain controller or CA directly.&lt;/p&gt;  &lt;p&gt;These new roles are only available on Windows Server 2008 R2 and the only clients that are capable of requesting certificates via CEP and CES is Windows 7 and Windows Server 2008 R2. However the roles can be used with Windows Server 2003, 2008, and 2008R2 Certification Authorities (CA).&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/CertificateEnrollmentWebServices_976D/image_4.png"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/CertificateEnrollmentWebServices_976D/image_thumb_1.png" width="571" height="224" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&lt;font size="1"&gt;Figure 2 - CEP / CES certificate enrollment&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;NOTE: The CEP and CES web services can be installed on the same server or, as Figure 2 shows, installed on two separate servers.&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Step 1. Client connects to the CEP web service over HTTPS.&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;The Windows 7 / Windows Server 2008R2 computer is configured to enroll for certificates against a CEP server. When a CEP server is configured in the environment the client will connect to the CEP server via port 443 (HTTPS), and connect to the CEP web service.&lt;/p&gt;  &lt;p&gt;Administrators can configure via local / group policy what CEP server to use at the following locations:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;Computer Configuration\Policies\Windows Settings\Security Policy\Public Key Policies\Certificate Services Client – Certificate Enrollment Policy&lt;/p&gt;    &lt;p&gt;User Configuration\Policies\Windows Settings\ Security Policy\Public Key Policies\Certificate Services Client – Certificate Enrollment Policy&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;b&gt;Step 2. – CEP web service queries LDAP.&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;The CEP service will send an LDAP query to a domain controller to get the following:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Queries for a list of &lt;i&gt;pKICertificateTemplate&lt;/i&gt; objects (Certificate Templates) within the forest.&lt;/li&gt;    &lt;li&gt;Queries for a list of &lt;i&gt;pKIEnrollmentService&lt;/i&gt; objects (Enterprise CA’s) within the forest.&lt;/li&gt;    &lt;li&gt;Queries for a list of &lt;i&gt;msPKI-Enterprise-Oid&lt;/i&gt; objects within the forest.&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;Once all the objects are collected and sent back to the client computer it determines the types of certificate for which it can enroll and which enterprise CAs can issue those certificates. There is a new attribute on the CA’s &lt;i&gt;pKIEnrollmentService&lt;/i&gt; object that tells the client computer what the URI’s are for the CES servers in the environment. The attribute name is &lt;i&gt;msPKI-Enrollment-Servers&lt;/i&gt;. The attribute is a multi-valued string so there can be multiple URI’s defined if you need to support different authentication methods. More on that later.&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Step 3. Client connects to the CES web service over HTTPS.&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;The client then connects to the CES web service that answers for the Certification Authority that is configured to issue the certificate. The actual CES URI is defined in &lt;i&gt;the msPKI-Enrollment-Servers&lt;/i&gt; attribute on the &lt;i&gt;pKIEnrollmentService&lt;/i&gt; object for that CA.&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Step 4. CES web service impersonates the client security context to request a certificate via DCOM, and then hands the certificate back to the client.&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;Here are some common questions and answers around CEP / CES:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;b&gt;&lt;i&gt;1. &lt;/i&gt;&lt;/b&gt;&lt;b&gt;&lt;i&gt;If I have Windows 7 or Windows Server 2008R2 are either CEP and CES required for certificate requests?&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;    &lt;p&gt;If the Windows 7 / 2008R2 computer exists in the same Active Directory forest as the CA, then no. If you do not install the new roles Windows 7/2008R2 can still request certificates in the way that legacy clients do (Figure 1). Just like those legacy clients, however, Windows 7/ 2008R2 clients will need network connectivity to a domain controller and the CA.&lt;/p&gt;    &lt;p&gt;&lt;b&gt;&lt;i&gt;2. &lt;/i&gt;&lt;/b&gt;&lt;b&gt;&lt;i&gt;When would CEP / CES be a good solution for my environment?&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;    &lt;p&gt;CEP / CES should be used in the environment when you require any of the following:&lt;/p&gt;    &lt;ul&gt;     &lt;li&gt;Windows 7/2008R2 internet based clients need to be able to enroll for certificates.&lt;/li&gt;      &lt;li&gt;Windows 7 / 2008R2 based clients in another forest need to enroll for certificates against a 2008R2 CA in a separate forest.&lt;/li&gt;      &lt;li&gt;There is a requirement that client computers should not be able to access the CA directly over the network, or there is a Firewall between the CA and client computer and your clients are Windows7 /2008R2.&lt;/li&gt;   &lt;/ul&gt;    &lt;p&gt;&lt;b&gt;&lt;i&gt;3. &lt;/i&gt;&lt;/b&gt;&lt;b&gt;&lt;i&gt;Where can the CEP / CES roles be installed?&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;    &lt;ul&gt;     &lt;li&gt;The roles can be installed on the CA, but that would defeats the purpose since the client will still need network connectivity to the CA.&lt;/li&gt;      &lt;li&gt;The roles can be installed on a domain member. The domain member could be on the internal network, or possibly in a DMZ. Please keep in mind that the CES role will require Kerberos delegation to be configured because it impersonates the user to the CA DCOM interface.&lt;/li&gt;      &lt;li&gt;The roles can be installed on the same computer or on separate computers. Please keep in mind that the CES role will require Kerberos delegation to be configured because it impersonates the user to the CA DCOM interface.&lt;/li&gt;      &lt;li&gt;Multiple instances of the CES web service can be installed on the same server. This allows you to increase the availability of the web service in environments with a large number of clients.&lt;/li&gt;   &lt;/ul&gt; &lt;/blockquote&gt;  &lt;p&gt;I hope that you have been able to learn a little more about these two new roles available on Windows Server 2008R2, and how to determine if you need to install and configure them. If you want more detailed information on CEP and CES you can review the &lt;a href="http://www.microsoft.com/downloads/details.aspx?familyid=28B910F8-6374-48DD-A897-11FFF62AB795&amp;amp;displaylang=en"&gt;Certificate Enrollment Web Services whitepaper&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;Rob “&lt;a href="http://en.wikipedia.org/wiki/Certs"&gt;minty&lt;/a&gt;” Greene&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3309819" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/askds/archive/tags/Certificates/default.aspx">Certificates</category><category domain="http://blogs.technet.com/askds/archive/tags/PKI/default.aspx">PKI</category><category domain="http://blogs.technet.com/askds/archive/tags/Windows+Server+2008+R2/default.aspx">Windows Server 2008 R2</category></item><item><title>It’s Lucha Libre Friday</title><link>http://blogs.technet.com/askds/archive/2010/01/29/it-s-lucha-libre-friday.aspx</link><pubDate>Fri, 29 Jan 2010 15:05:02 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3309322</guid><dc:creator>NedPyle</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/askds/comments/3309322.aspx</comments><wfw:commentRss>http://blogs.technet.com/askds/commentrss.aspx?PostID=3309322</wfw:commentRss><description>&lt;p&gt;I have a teammate with too much time, money and Ebay expertise on his hands. So I am now a &lt;a href="http://en.wikipedia.org/wiki/Lucha_Libre"&gt;luchador&lt;/a&gt;. &lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/ItsLuchaLibreFriday_8DCA/luchalibre2_2.jpg"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: block; float: none; margin-left: auto; border-top: 0px; margin-right: auto; border-right: 0px" title="luchalibre2" border="0" alt="luchalibre2" src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/ItsLuchaLibreFriday_8DCA/luchalibre2_thumb.jpg" width="390" height="657" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;In other news, our holiday posting drought should be at an end – plenty of blog stuff in the pipeline coming your way soon. Stay tuned.&lt;/p&gt;  &lt;p&gt;- Ned “corto y el mal” Pyle&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3309322" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/askds/archive/tags/Silly+Rabbit/default.aspx">Silly Rabbit</category></item><item><title>DCDIAG Advertising test with error 81</title><link>http://blogs.technet.com/askds/archive/2010/01/27/dcdiag-advertising-test-with-error-81.aspx</link><pubDate>Wed, 27 Jan 2010 18:14:59 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3308807</guid><dc:creator>NedPyle</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/askds/comments/3308807.aspx</comments><wfw:commentRss>http://blogs.technet.com/askds/commentrss.aspx?PostID=3308807</wfw:commentRss><description>&lt;p&gt;David Everett here again with an interesting issue that causes the Advertising test in &lt;b&gt;DCdiag.exe&lt;/b&gt; to fail when verifying the role of a global catalog (GC).&lt;/p&gt;  &lt;p&gt;A customer called Microsoft Product Support to determine why the Advertising test in &lt;b&gt;dcdiag.exe&lt;/b&gt; was reporting that the global catalog role was not working on a Windows Server 2008 Read-only domain controller (RODC) when all other indicators suggested it was functioning normally. &lt;b&gt;DCDiag.exe&lt;/b&gt; reported the DC was advertising as a GC but DCDiag couldn’t perform a search against the GC when the command was issued local to the server or remotely:&lt;/p&gt;  &lt;p style="background: #e5f2ff; margin-left: 0.5in"&gt;&lt;span style="font-family: consolas; font-size: 9pt"&gt;Dcdiag /test:advertising /v /s:RODC     &lt;br /&gt;      &lt;br /&gt;&lt;em&gt;&amp;lt;..snip..&amp;gt;&lt;/em&gt;      &lt;br /&gt;      &lt;br /&gt;Doing primary tests      &lt;br /&gt;      &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Testing server: SITEZ\RODC01      &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Starting test: Advertising      &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; The DC RODC01 is advertising itself as a DC and having a DS.       &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; The DC RODC01 is advertising as an LDAP server      &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; The DC RODC01 is not advertising as having a writeable directory because it is an RODC      &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; The DC RODC01 is advertising as a Key Distribution Center      &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; The DC RODC01 is advertising as a time server      &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Ldap search capabality attribute search failed on server RODC01,       &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; return value = 81      &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Server RODC01 is advertising as a global catalog, but       &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; it could not be verified that the server thought it was a GC.       &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; ......................... RODC01 failed test Advertising&lt;span style="color: black"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Tahoma&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 7.5pt"&gt;     &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Determine the health of the Global Catalog&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;There are some simple tests that can be done to verify the DC is advertising the Global Catalog role. First, make a connection to the W2K8 DC's ROOTDSE over port 389 or 3268 to determine if the DC has sourced and is advertising the global catalog: &lt;/p&gt;  &lt;p style="background: #e5f2ff; margin-left: 0.5in"&gt;&lt;span style="font-family: consolas; font-size: 9pt"&gt;isGlobalCatalogReady: TRUE;     &lt;br /&gt;isSynchronized: TRUE;&lt;span style="color: black"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Tahoma&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 7.5pt"&gt;     &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;Another useful test to verify the DC is advertising as a GC is to use the /GC parameter in &lt;b&gt;nltest.exe&lt;/b&gt; and observe that GC is listed in the Flags:&lt;/p&gt;  &lt;p style="background: #e5f2ff; margin-left: 0.5in"&gt;&lt;span style="font-family: consolas; font-size: 9pt"&gt;nltest /dsgetdc:contoso /force /gc     &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; DC: \\RODC01      &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Address: \\11.11.11.25      &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Dom Guid: a238ef59-eeef-11d2-a123-00805f9f123      &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Dom Name: CONTOSO      &lt;br /&gt;&amp;#160; Forest Name: contoso.com      &lt;br /&gt;Dc Site Name: SITEX      &lt;br /&gt;Our Site Name: SITEX      &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Flags: &lt;span style="background: yellow; mso-highlight: yellow"&gt;GC&lt;/span&gt; DS LDAP KDC TIMESERV DNS_FOREST CLOSE_SITE PARTIAL_SECRET      &lt;br /&gt;The command completed successfully&lt;/span&gt;&lt;span style="font-family: &amp;quot;Tahoma&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 7.5pt"&gt;     &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;The first two tests essentially confirm what dcdiag.exe already reports, namely that the server is advertising as a GC. The real question now is, “Do LDAP searches correctly retrieve objects from the global catalog?” Since the DC resides in contoso.com (the forest root domain) the search should be made to query an object from a different domain in the same forest over global catalog LDAP port 3268. The example below shows the GC successfully returns the child domain’s Administrator account:&lt;/p&gt;  &lt;p style="background: #e5f2ff; margin-left: 0.5in"&gt;&lt;span style="font-family: consolas; color: black; font-size: 9pt"&gt;repadmin.exe /showattr RODC01 “DC=child,DC=contoso,DC=com” /subtree /filter:“(&amp;amp;(objectClass=user)(name=Administrator))” /atts:name /gc     &lt;br /&gt;DN: CN=Administrator,CN=users,DC=child,DC=contoso,DC=com      &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; 1&amp;gt; name: Administrator&lt;/span&gt;&lt;span style="font-family: &amp;quot;Tahoma&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 7.5pt"&gt;     &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Understanding why LDAP search in the Advertising test is failing&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;This problem occurs when an administrator removes a domain controller machine account using &lt;b&gt;adsiedit.msc&lt;/b&gt; &lt;i&gt;but&lt;/i&gt; &lt;i&gt;fails to remove the objects from the Configuration partition&lt;/i&gt; and then promotes a new DC with the same name into a different site.&lt;/p&gt;  &lt;p&gt;Apparently an RODC account was pre-created in the wrong Active Directory site using the &lt;b&gt;Pre-created Read-only Domain Controller account...&lt;/b&gt; option in &lt;b&gt;DSA.MSC&lt;/b&gt;. The Active Directory Promotion Wizard prompts the administrator to type the hostname and select the Site where the prospective DC will reside. The wizard uses this information to create the computer account and its corresponding NTDS Settings object. At some point, the unoccupied RODC machine account was deleted from the Domain Controllers OU using &lt;b&gt;adsiedit.msc&lt;/b&gt; but its corresponding NTDS Settings object was left in the Configuration partition. Eventually the server was promoted as a DC into the correct site and successfully promoted to be a GC.&lt;/p&gt;  &lt;p&gt;It’s important to note that this condition isn’t specific to RODCs. The same issue occurs if a writable DC is removed from metadata in the same way and a server with the same name is later promoted into a different site. &lt;/p&gt;  &lt;p&gt;All NTDS Settings objects have a parent server object named after the DC. This parent server object contains a &lt;i&gt;dNSHostName&lt;/i&gt; attribute that is populated with the fully qualified domain name of the DC. In this case the identically named stale and valid NTDS Settings objects in different sites have a dNSHostName attribute with the same FQDN.     &lt;br /&gt;The DCDIAG Advertising test searches the CN=Sites,CN=Configuration,&lt;i&gt;DC=Contoso,DC=Com&lt;/i&gt; container for a Server object whose &lt;i&gt;dNSHostName&lt;/i&gt; attribute matches the fully qualified computer name of the DC being targeted. Once it finds the object with the matching &lt;i&gt;dNSHostname&lt;/i&gt; it retrieves the &lt;i&gt;objectGUID&lt;/i&gt; of the subordinate NTDS Settings object and attempts to contact the target domain controller by its fully qualified CNAME which would normally be registered under the DNS zone “_msdcs.&lt;i&gt;contoso.com&lt;/i&gt;”. &lt;/p&gt;  &lt;p&gt;If DCDIAG discovers a Server object whose &lt;i&gt;dNSHostName&lt;/i&gt; attribute matches the targeted DC but the &lt;i&gt;ObjectGUID&lt;/i&gt; on the subordinate NTDS Settings object wasn't created by the last DCPROMO promotion or machine account pre-creation, then the LDAP bind to the targeted DC will fail with LDAP error 81. To get a better understanding of what this error means, download &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=BE596899-7BB8-4208-B7FC-09E02A13696C&amp;amp;displaylang=en"&gt;Err.exe&lt;/a&gt; and pass it the error code and you find it translates to &amp;quot;LDAP_SERVER_DOWN&amp;quot;.&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Identify Valid and Invalid NTDS Settings objects and clean up&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;1. Determine the &lt;b&gt;DSA object GUID&lt;/b&gt; and &lt;b&gt;Site&lt;/b&gt; name that the DC is currently registering in DNS as a CNAME record by running this command:&lt;/p&gt;  &lt;p style="background: #e5f2ff; margin-left: 0.5in"&gt;&lt;span style="font-family: consolas; color: black; font-size: 9pt"&gt;C:\&amp;gt;repadmin /showreps &amp;lt;name of dc&amp;gt; |more     &lt;br /&gt;&lt;span style="background: yellow"&gt;&amp;lt;AD Site Name&amp;gt;&lt;/span&gt;\RODC01      &lt;br /&gt;DSA Options: IS_GC      &lt;br /&gt;Site Options: (none)      &lt;br /&gt;&lt;span style="background: yellow"&gt;DSA object GUID: 52399da1-87ba-4da6-bce3-71dcf0d85f34&lt;/span&gt;      &lt;br /&gt;DSA invocationID: 18bce5ac-d9f4-46dc-bccf-f3e39da103f9&lt;/span&gt;&lt;span style="font-family: &amp;quot;Tahoma&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 7.5pt"&gt;     &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p&gt;2. Use the &lt;b&gt;repadmin.exe&lt;/b&gt; command below to locate the Site that the invalid NTDS Settings object is in:&lt;/p&gt;  &lt;p style="background: #e5f2ff; margin-left: 0.5in"&gt;&lt;span style="font-family: consolas; color: black; font-size: 9pt"&gt;C:\&amp;gt;repadmin.exe /showattr RODC01 “CN=Sites,CN=Configuration,DC=contoso,DC=com” /subtree /filter:“(&amp;amp;(objectClass=server)(name=RODC01))” /atts:name     &lt;br /&gt;DN: CN=RODC01,CN=Servers,CN=&lt;span style="background: yellow; mso-highlight: yellow"&gt;SITE-A&lt;/span&gt;,CN=Sites,DC=Configuration,DC=contoso,DC=com      &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; 1&amp;gt; name: RODC01      &lt;br /&gt;DN: CN=RODC01,CN=Servers,CN=SITE-Z,CN=Sites,DC=Configuration,DC=contoso,DC=com      &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; 1&amp;gt; name: RODC01&lt;/span&gt;    &lt;p&gt;&lt;/p&gt; &lt;/p&gt;  &lt;p&gt;3. Verify the wrong server object in the undesirable site is causing the failure: &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;a. Open &lt;b&gt;adsiedit.msc&lt;/b&gt; and view the &lt;b&gt;Properties&lt;/b&gt; of the invalid Server object.&lt;/p&gt;    &lt;p&gt;b. Select the &lt;b&gt;Attribute Editor&lt;/b&gt; tab and &lt;b&gt;Edit&lt;/b&gt; the &lt;i&gt;dNSHostName&lt;/i&gt; attribute. &lt;/p&gt;    &lt;p&gt;c. Click &lt;b&gt;Clear&lt;/b&gt;, &lt;b&gt;OK&lt;/b&gt; and &lt;b&gt;Apply&lt;/b&gt; to remove the FQDN of the RODC from the invalid object.&lt;/p&gt;    &lt;p&gt;d. Once AD replication of this change makes it to the RODC run:&lt;/p&gt;    &lt;p&gt;&amp;#160;&amp;#160;&amp;#160; &lt;font size="2" face="Consolas"&gt;dcdiag /test:advertising /v /s:RODC01&lt;/font&gt;&lt;/p&gt;    &lt;p&gt;e. Verify the DC is now advertising as a GC.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;4. Now that DCdiag is free of errors delete the invalid server object using the preferred method of metadata cleanup.&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;a. Right-click the NTDS Settings object of the invalid RODC in Active Directory Sites and Services and select &lt;b&gt;Delete&lt;/b&gt;&lt;/p&gt;    &lt;p&gt;b. Click &lt;b&gt;Yes &lt;/b&gt;at the Active Directory Domain Services prompt to delete the NTDS Settings object&lt;/p&gt;    &lt;p&gt;c. Uncheck all three boxes in the Deleting Domain Controller window and click &lt;b&gt;Delete&lt;/b&gt;&lt;/p&gt;    &lt;p&gt;d. Once the subordinate NTDS Settings object has been removed, delete the invalid server object that is just superior to the NTDS Settings object that was just deleted.&lt;/p&gt;    &lt;p&gt;&lt;b&gt;NOTE:&lt;/b&gt; Because the &lt;i&gt;serverReference&lt;/i&gt; attribute is NULL on the invalid NTDS Settings object the corresponding DC object in the domain partition will not be removed.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;One way to ensure you never encounter this issue with dcdiag.exe is to start using this last step to remove a domain controller from the metadata instead of adsiedit.msc.&lt;/p&gt;  &lt;p&gt;David “Mad Men” Everett&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3308807" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/askds/archive/tags/LDAP/default.aspx">LDAP</category></item><item><title>New Directory Services KB Articles/Blogs 1/10-1/23</title><link>http://blogs.technet.com/askds/archive/2010/01/25/new-directory-services-kb-articles-blogs-1-10-1-23.aspx</link><pubDate>Mon, 25 Jan 2010 16:32:33 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3308178</guid><dc:creator>Craig</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/askds/comments/3308178.aspx</comments><wfw:commentRss>http://blogs.technet.com/askds/commentrss.aspx?PostID=3308178</wfw:commentRss><description>&lt;p&gt;&lt;strong&gt;KB&lt;/strong&gt;&lt;/p&gt;  &lt;table border="1" cellspacing="0" cellpadding="0" width="500"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td width="42"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://support.microsoft.com/?kbid=978155"&gt;978155&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td width="456"&gt;         &lt;p&gt;A memory leak occurs when an ADO Recordset object calls the UpdateBatch method&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="42"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://support.microsoft.com/?kbid=976779"&gt;976779&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td width="456"&gt;         &lt;p&gt;Windows Automation API 3.0 release notes&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="42"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://support.microsoft.com/?kbid=977211"&gt;977211&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td width="456"&gt;         &lt;p&gt;The DFS Replication service exits unexpectedly on a computer that is running Windows Server 2003 R2 SP2&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="42"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://support.microsoft.com/?kbid=977692"&gt;977692&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td width="456"&gt;         &lt;p&gt;The Lsass.exe process exits unexpectedly on a domain controller that is running Windows Server 2008 R2 after a password is synchronized in Identity Management for Unix (IDMU)&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="42"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://support.microsoft.com/?kbid=979281"&gt;979281&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td width="456"&gt;         &lt;p&gt;Error code 0x80070002 when backing up files in Windows 7&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="42"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://support.microsoft.com/?kbid=978042"&gt;978042&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td width="456"&gt;         &lt;p&gt;FIX: A memory leak may occur when you use the Microsoft ActiveX Data Objects Library in Windows Vista, in Windows 7, in Windows Server 2008, or in Windows Server 2008 R2&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="42"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://support.microsoft.com/?kbid=977686"&gt;977686&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td width="456"&gt;         &lt;p&gt;The Licensing Diagnosis tool incorrectly reports that there are no available Terminal Services client access licenses in Windows Server 2008&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="42"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://support.microsoft.com/?kbid=978538"&gt;978538&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td width="456"&gt;         &lt;p&gt;The DFS Replication service crashes randomly in Windows Server 2008&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="42"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://support.microsoft.com/?kbid=979682"&gt;979682&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td width="456"&gt;         &lt;p&gt;Microsoft Security Advisory: Vulnerability in Windows Kernel could allow elevation of privilege&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;&lt;strong&gt;Blogs&lt;/strong&gt;&lt;/p&gt;  &lt;table border="1" cellspacing="0" cellpadding="0" width="500"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blogs.technet.com/askds/archive/2010/01/22/file-services-management-pack-for-system-center-operations-manager-2007-beta-now-open.aspx"&gt;File Services Management Pack for System Center Operations Manager 2007 – Beta now open&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://msmvps.com/blogs/ad/archive/2010/01/25/how-active-directory-powershell-cmdlets-find-a-dc-running-active-directory-web-services.aspx"&gt;How Active Directory PowerShell CMDLETS find a DC running Active Directory Web Services&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blogs.technet.com/askcore/archive/2010/01/25/cluster-migration-wizard-is-this-the-only-way-to-migrate-shares-on-a-cluster.aspx"&gt;Cluster Migration Wizard, is this the only way to migrate shares on a Cluster?&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blogs.msdn.com/powershell/archive/2010/01/25/use-the-right-version-of-powershell.aspx"&gt;Use The Right Version of PowerShell.&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://feedproxy.google.com/~r/GroupPolicyCenter/~3/Wb5GuRxbTo4/"&gt;Group Policy Setting of the Week 11 – Prompt for password on resume from hibernate /suspend&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blog.joeware.net/2010/01/22/1884/"&gt;Cloning Forests for Divestitures / Acquisitions&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://feedproxy.google.com/~r/zdnet/microsoft/~3/uaNcWK1NFpo/"&gt;Microsoft Office 2010 system requirements: Changes in disk space, GPU recommendations&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://jimmytheswede.blogspot.com/2010/01/defining-new-attribute-version-2.html"&gt;Defining a new attribute - version 2&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://jimmytheswede.blogspot.com/2010/01/defining-new-attribute.html"&gt;Defining a new attribute&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://jimmytheswede.blogspot.com/2010/01/outlook-signature-based-on-user-info.html"&gt;Outlook signature based on user info from AD&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blogs.technet.com/askperf/archive/2010/01/22/heads-up-end-of-life-support-for-windows-2000-and-windows-xp-sp2.aspx"&gt;Heads Up: End of Life support for Windows 2000 and Windows XP SP2&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://feedproxy.google.com/~r/GroupPolicyCenter/~3/tlIbGVQVaRM/"&gt;How to schedule a delayed start logon script with Group Policy&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blogs.msdn.com/card/archive/2010/01/21/diagnostics-in-ad-fs-2-0.aspx"&gt;Diagnostics in AD FS 2.0&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://edge.technet.com/Media/SMS-2003-Transitions-to-Extended-Support/"&gt;SMS 2003 Transitions to Extended Support&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://feedproxy.google.com/~r/JacksonsIdentityManagementActiveDirectoryRealityTourTravelblog/~3/etQ_WVvolUk/active-directory-scalability.html"&gt;Active Directory Scalability&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://imav8n.wordpress.com/2010/01/20/forget-your-password/"&gt;Forget your password?&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blogs.technet.com/activedirectoryua/archive/2010/01/20/event-id-2042-it-has-been-too-long-since-this-machine-replicated-updated.aspx"&gt;Event ID 2042: It has been too long since this machine replicated - updated.&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blogs.msdn.com/wmi/archive/2010/01/21/perform-asynchronous-asset-management-using-windows-powershell-cmdlets-for-wmi.aspx"&gt;Perform asynchronous asset management using Windows Powershell cmdlets for WMI&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://feedproxy.google.com/~r/JacksonsIdentityManagementActiveDirectoryRealityTourTravelblog/~3/o6mvF1sD4mA/shared-password-mistake-affects-12.html"&gt;Shared password mistake affects 1.2 million people!&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blogs.msdn.com/rds/archive/2010/01/19/how-to-detect-rds-specific-application-compatibility-issues-by-using-the-rds-application-compatibility-analyzer.aspx"&gt;How to detect RDS-specific application compatibility issues by using the RDS Application Compatibility Analyzer&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://theessentialexchange.com/blogs/michael/archive/2010/01/19/where-oh-where-did-my-ad-site-go-alternate-title-it-s-the-dns-stupid.aspx"&gt;Where oh where, did my AD site go...[Alternate title: It's the DNS, stupid.]&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://research.microsoft.com/en-us/news/features/netmedic-011910.aspx"&gt;Troubleshooting Small Networks&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://edge.technet.com/Media/Windows-Server-2008-R2-Quick-Look7-Best-Practices-Analyzers/"&gt;Windows Server 2008 R2 Quick Look#7 - Best Practices Analyzers&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://feedproxy.google.com/~r/zdnet/microsoft/~3/zB5ToFEnwaU/"&gt;First of the 2010 releases of Microsoft codename tracker is ready for download&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blogs.technet.com/grouppolicy/archive/2010/01/19/tales-from-the-community-how-do-i-deploy-windows-7-policy-settings.aspx"&gt;Tales from the Community: How do I deploy Windows 7 policy settings&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://www.leeholmes.com/blog/DelayedScreenCapturesInPowerShell.aspx"&gt;Delayed Screen Captures in PowerShell&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://feedproxy.google.com/~r/GroupPolicyCenter/~3/fGRUvIAG6Ew/"&gt;Automate Group Policy Preferences printer-management using Windows PowerShell&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://www.frickelsoft.net/blog/?p=238"&gt;How do I get my disk space back? Why does my DIT not shrink?&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blog.joeware.net/2010/01/18/1876/"&gt;AdFind’s objectClass output is correct, it is CSVDE that is incorrect…&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://edge.technet.com/Media/Building-Windows-7-Images/"&gt;Building Windows 7 Images&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://feedproxy.google.com/~r/GroupPolicyCenter/~3/CcVs9aksWj4/"&gt;Group Policy Setting of the Week 10 – Remove Default Programs link from the Start menu&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blogs.msdn.com/card/archive/2010/01/16/configuring-active-directory-federation-services-2-0.aspx"&gt;Configuring Active Directory Federation Services 2.0&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blogs.dirteam.com/blogs/tomek/archive/2010/01/15/where-is-my-dc.aspx"&gt;Where is my DC?&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blogs.technet.com/fdcc/archive/2010/01/15/updated-lgpo-utility-sources.aspx"&gt;Updated LGPO utility sources&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://jimmytheswede.blogspot.com/2010/01/enable-recycle-bin-with-powershell.html"&gt;Enable Recycle Bin - with Powershell&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://feedproxy.google.com/~r/GroupPolicyCenter/~3/lkVziWJOz8E/"&gt;How to mitigate KB979352 (a.k.a. “Google China”) security vulnerability using Group Policy&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://msmvps.com/blogs/ad/archive/2009/12/01/powershell-and-the-event-viewer.aspx"&gt;PowerShell and the Event Viewer&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://theessentialexchange.com/blogs/michael/archive/2010/01/14/speeding-reboot-when-exchange-is-on-a-dc-gc.aspx"&gt;Speeding Reboot When Exchange is on a DC/GC&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://edge.technet.com/Media/Windows-Server-2008-R2-Quick-Look-6-Server-Core/"&gt;Windows Server 2008 R2 Quick Look #6 - Server Core&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://trycatch.be/blogs/roggenk/archive/2010/01/14/active-directory-web-services-adws-and-active-directory-management-gateway-service-admgs.aspx"&gt;Active Directory Web Services (ADWS) and Active Directory Management Gateway Service (ADMGS)&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://edge.technet.com/Media/Remote-Desktop-Services-RDS-Explained/"&gt;Microsoft Remote Desktop Services (RDS) Explained&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://feedproxy.google.com/~r/GroupPolicyCenter/~3/E9Cpwuvkdm0/"&gt;How to make Adobe Reader more secure using Group Policy&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blog.joeware.net/2010/01/12/1872/"&gt;ADAM (aka ADLDS) is available for Windows 7 now!!!&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blogs.technet.com/ipv6/archive/2010/01/12/new-documentation-is-available-for-directaccess-in-windows-server-2008-r2-and-forefront-unified-access-gateway-uag.aspx"&gt;New documentation is available for DirectAccess in Windows Server 2008 R2 and Forefront Unified Access Gateway (UAG)&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blogs.technet.com/askcore/archive/2010/01/12/going-overboard-with-microsoft-virtualization-can-get-you-into-trouble.aspx"&gt;Going Overboard with Microsoft Virtualization can get you into trouble&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blogs.technet.com/janelewis/archive/2010/01/12/a-couple-of-cool-downloads-for-your-win-7-platform.aspx"&gt;A couple of cool downloads for your Win 7 Platform&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://blogs.technet.com/askperf/archive/2010/01/12/an-introduction-to-the-windows-system-state-analyzer.aspx"&gt;An Introduction to the Windows System State Analyzer&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://feedproxy.google.com/~r/GroupPolicyCenter/~3/79afpqvRAVg/"&gt;Windows XP Power Management and Group Policy Preferences Behaviour Explained&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://msmvps.com/blogs/ad/archive/2009/11/05/how-to-verify-trusts.aspx"&gt;How to Verify Trusts&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://feedproxy.google.com/~r/GroupPolicyCenter/~3/Qa1O_1S_E_Q/"&gt;Microsoft release two new Group Policy hot fixes&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://feedproxy.google.com/~r/GroupPolicyCenter/~3/9gALdB9pmr8/"&gt;Group Policy Setting of the Week 9 – Allow Automatic Updates immediate installation&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://feedproxy.google.com/~r/GroupPolicyCenter/~3/ixi-Fis6w14/"&gt;How to use Group Policy Preferences to change account Passwords&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://feedproxy.google.com/~r/GroupPolicyCenter/~3/1fTebzJRHJc/"&gt;How to configure Group Policy to use Data Recovery Agents with “Bitlocker to Go” drives – Part 2&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://feedproxy.google.com/~r/GroupPolicyCenter/~3/CNDk8Tu32_k/"&gt;How to use Group Policy to save “BitLocker to Go” recovery keys in Active Directory – Part 1&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://feedproxy.google.com/~r/GroupPolicyCenter/~3/-kXSBeLoSbY/"&gt;How to use Group Policy Preferences to manage Windows Power Plans&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://feedproxy.google.com/~r/GroupPolicyCenter/~3/Cnp0bDPGv3Y/"&gt;Welcome to the Group Policy Center&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td width="498"&gt;         &lt;p&gt;&lt;u&gt;&lt;a href="http://feedproxy.google.com/~r/GroupPolicyCenter/~3/ZfM_Yt1cAKI/"&gt;Group Policy Setting of the Week 8 – Group Policy refresh interval for computers&lt;/a&gt;&lt;/u&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3308178" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/askds/archive/tags/KB+Articles/default.aspx">KB Articles</category><category domain="http://blogs.technet.com/askds/archive/tags/Other+Blogs/default.aspx">Other Blogs</category></item><item><title>File Services Management Pack for System Center Operations Manager 2007 – Beta now open</title><link>http://blogs.technet.com/askds/archive/2010/01/22/file-services-management-pack-for-system-center-operations-manager-2007-beta-now-open.aspx</link><pubDate>Fri, 22 Jan 2010 14:56:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3307599</guid><dc:creator>NedPyle</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/askds/comments/3307599.aspx</comments><wfw:commentRss>http://blogs.technet.com/askds/commentrss.aspx?PostID=3307599</wfw:commentRss><description>&lt;P&gt;Hi all, Ned here again. We’ve gotten word that the &lt;A href="http://www.microsoft.com/systemcenter/operationsmanager/en/us/default.aspx" mce_href="http://www.microsoft.com/systemcenter/operationsmanager/en/us/default.aspx"&gt;SCOM 2007&lt;/A&gt; management pack for file services has reached beta and is available to the public on our Connect site. Here’s the info:&lt;/P&gt;
&lt;H3&gt;Overview&lt;/H3&gt;
&lt;P&gt;The File Services Team is proud to announce the beta release of our File Services Management Pack for &lt;A href="http://www.microsoft.com/systemcenter/operationsmanager/en/us/default.aspx" mce_href="http://www.microsoft.com/systemcenter/operationsmanager/en/us/default.aspx"&gt;System Center Operations Manager 2007&lt;/A&gt;.&amp;nbsp; This management pack provides health monitoring for SMB shares, NFS shares, DFS Namespaces, DFS Replication and File Server Resource Manager including the File Classification Infrastructure.&lt;/P&gt;
&lt;H3&gt;Supported OS Versions&lt;/H3&gt;
&lt;P&gt;The following table describes which File Services role service can be monitored with the beta management pack on various Windows Server versions:&lt;/P&gt;
&lt;P&gt;
&lt;TABLE border=1 cellSpacing=0 cellPadding=0 width=508&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD vAlign=top width=228&gt;
&lt;P&gt;&lt;B&gt;Role Service&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD vAlign=top width=278&gt;
&lt;P&gt;&lt;B&gt;OS Version Supported&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD vAlign=top width=228&gt;
&lt;P&gt;&lt;B&gt;DFS Namespaces&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD vAlign=top width=278&gt;
&lt;P&gt;Windows Server 2003, 2003 R2, 2008, 2008 R2&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD vAlign=top width=228&gt;
&lt;P&gt;&lt;B&gt;DFS Replication&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD vAlign=top width=278&gt;
&lt;P&gt;Windows Server 2003 R2, 2008, 2008 R2&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD vAlign=top width=228&gt;
&lt;P&gt;&lt;B&gt;File Classification Infrastructure&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD vAlign=top width=278&gt;
&lt;P&gt;Windows Server 2008 R2&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD vAlign=top width=228&gt;
&lt;P&gt;&lt;B&gt;File Server Resource Manager&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD vAlign=top width=278&gt;
&lt;P&gt;Windows Server 2008 R2&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD vAlign=top width=228&gt;
&lt;P&gt;&lt;B&gt;NFS File Sharing&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD vAlign=top width=278&gt;
&lt;P&gt;Windows Server 2008 R2&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD vAlign=top width=228&gt;
&lt;P&gt;&lt;B&gt;SMB File Sharing&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD vAlign=top width=278&gt;
&lt;P&gt;Windows Server 2008 R2&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/P&gt;
&lt;H3&gt;New Features&lt;/H3&gt;
&lt;P&gt;The table below describes several of the key features provided in this beta management pack: &lt;BR&gt;&lt;/P&gt;
&lt;TABLE border=1 cellSpacing=0 cellPadding=0 width=654&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD vAlign=top width=162&gt;
&lt;P&gt;&lt;B&gt;Feature&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD vAlign=top width=490&gt;
&lt;P&gt;&lt;B&gt;Description&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD vAlign=top width=162&gt;
&lt;P&gt;&lt;B&gt;Agentless Monitoring&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD vAlign=top width=490&gt;
&lt;P&gt;Ability to monitor file services on servers without deploying a SCOM agent to the specific server&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD vAlign=top width=162&gt;
&lt;P&gt;&lt;B&gt;Highly Available Cluster Instance Monitoring&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD vAlign=top width=490&gt;
&lt;P&gt;Ability to monitor the health status of a Highly Available File Server deployed on a Failover Cluster&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD vAlign=top width=162&gt;
&lt;P&gt;&lt;B&gt;NFS Role Service&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD vAlign=top width=490&gt;
&lt;P&gt;Monitor activity logging, NIS configuration, port registration, portmaper service, NFS service driver, username mapping service, and more&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD vAlign=top width=162&gt;
&lt;P&gt;&lt;B&gt;FSRM Role Service&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD vAlign=top width=490&gt;
&lt;P&gt;Monitor FSRM service, quota driver, filescreen driver, file classification task progress, and orphaned mountpoints&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD vAlign=top width=162&gt;
&lt;P&gt;&lt;B&gt;DFSR Role Service&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD vAlign=top width=490&gt;
&lt;P&gt;Monitor the health of DFS Replication service, communications with replication partners, database recovery, communications with Domain Controllers, free space on volume containing a replicated folder, USN journal wrap events, overlap with FRS, inconsistent configuration, and more&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD vAlign=top width=162&gt;
&lt;P&gt;&lt;B&gt;DFSR Backlog Tracking&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD vAlign=top width=490&gt;
&lt;P&gt;Ability to display the backlog count per connection for a DFS replication group&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD vAlign=top width=162&gt;
&lt;P&gt;&lt;B&gt;DFSR Performance Counters &lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD vAlign=top width=490&gt;
&lt;P&gt;Track data for bandwidth ravings, replication conflicts, deleted files and staging area&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD vAlign=top width=162&gt;
&lt;P&gt;&lt;B&gt;DFS Namespace Role Service&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD vAlign=top width=490&gt;
&lt;P&gt;Monitor DFS namespace service, health of a single namespace hosted on multiple servers, health of the AD component of DFS namespaces, site table initialization, namespace initialization, Namespace Synchronization with AD, Folder Target Health and more&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD vAlign=top width=162&gt;
&lt;P&gt;&lt;B&gt;SMB Role Service&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD vAlign=top width=490&gt;
&lt;P&gt;Monitor the health of Lanman server service, creation of shares at system startup, IRP stack overflow events, firewall port configuration&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;H3&gt;Download Instructions&lt;/H3&gt;
&lt;OL&gt;
&lt;LI&gt;Log on to &lt;A href="http://connect.microsoft.com/" mce_href="http://connect.microsoft.com/"&gt;Microsoft Connect&lt;/A&gt; and create a profile if you have not already created a profile &lt;/LI&gt;
&lt;LI&gt;Navigate to &lt;A href="https://connect.microsoft.com/directory/" mce_href="https://connect.microsoft.com/directory/"&gt;Connection Directory&lt;/A&gt; &lt;/LI&gt;
&lt;LI&gt;Search for&amp;nbsp; &lt;B&gt;File Services and Storage&lt;/B&gt; and select &lt;B&gt;Apply Now&lt;/B&gt; &lt;/LI&gt;
&lt;LI&gt;Fill-out application survey &lt;/LI&gt;
&lt;LI&gt;Log on to &lt;A href="https://connect.microsoft.com/site554" mce_href="https://connect.microsoft.com/site554"&gt;File Services and Storage&lt;/A&gt; connection &lt;/LI&gt;
&lt;LI&gt;Click the announcement: &lt;A href="https://connect.microsoft.com/site554/content/content.aspx?ContentID=15641" mce_href="https://connect.microsoft.com/site554/content/content.aspx?ContentID=15641"&gt;Beta release of SCOM Management Pack for File Services in Server 2008 R2&lt;/A&gt; &lt;/LI&gt;
&lt;LI&gt;Follow instructions to download the Management Pack&lt;/LI&gt;&lt;/OL&gt;
&lt;H3&gt;Feedback Instructions&lt;/H3&gt;
&lt;P&gt;Submit feedback through the connection [&lt;EM&gt;Ned: and not through AskDS! Remember, Beta means not supported – this is for testing&lt;/EM&gt;].&lt;/P&gt;
&lt;P&gt;- Ned “press agent” Pyle&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3307599" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/askds/archive/tags/DFSR/default.aspx">DFSR</category><category domain="http://blogs.technet.com/askds/archive/tags/DFSN/default.aspx">DFSN</category><category domain="http://blogs.technet.com/askds/archive/tags/Cluster/default.aspx">Cluster</category><category domain="http://blogs.technet.com/askds/archive/tags/scom+2007/default.aspx">scom 2007</category></item><item><title>New Directory Services KB Articles/Blogs 1/3-1/9</title><link>http://blogs.technet.com/askds/archive/2010/01/11/new-directory-services-kb-articles-blogs-1-3-1-9.aspx</link><pubDate>Mon, 11 Jan 2010 19:41:58 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3304952</guid><dc:creator>Craig</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/askds/comments/3304952.aspx</comments><wfw:commentRss>http://blogs.technet.com/askds/commentrss.aspx?PostID=3304952</wfw:commentRss><description>&lt;p&gt;&lt;strong&gt;KB&lt;/strong&gt;&lt;/p&gt;  &lt;table border="1" cellspacing="0" cellpadding="0"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="bottom" width="56"&gt;         &lt;p&gt;&lt;a href="http://support.microsoft.com/?kbid=977983"&gt;977983&lt;/a&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="bottom" width="593"&gt;         &lt;p&gt;Group Policy preferences client-side extension hotfix rollup for Windows Vista&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="bottom" width="56"&gt;         &lt;p&gt;&lt;a href="http://support.microsoft.com/?kbid=971357"&gt;971357&lt;/a&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="bottom" width="593"&gt;         &lt;p&gt;User password is set to NULL when you use Group Policy Preferences to create a user account&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;&lt;strong&gt;Blogs&lt;/strong&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href="http://blogs.technet.com/askds/archive/2010/01/08/the-importance-of-following-all-the-authoritative-restore-steps.aspx"&gt;The importance of following ALL the authoritative restore steps&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://blogs.technet.com/askds/archive/2010/01/07/clustered-certification-authority-maintenance-tasks.aspx"&gt;Clustered Certification Authority maintenance tasks&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://blogs.technet.com/askds/archive/2010/01/05/understanding-dfsr-conflict-algorithms-and-doing-something-about-conflicts.aspx"&gt;Understanding DFSR conflict algorithms (and doing something about conflicts)&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://feedproxy.google.com/~r/JacksonsIdentityManagementActiveDirectoryRealityTourTravelblog/~3/eJXaVUpYssA/speaking-of-pki-again.html"&gt;Speaking of PKI, again!&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://msmvps.com/blogs/ad/archive/2009/10/07/is-my-active-directory-backed-up.aspx"&gt;Is my Active Directory Backed Up?&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://edge.technet.com/Media/Windows-deployment-services--deploying-a-Virtualized-sever/"&gt;Windows deployment services : deploying a Virtualized server&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://blogs.technet.com/netmon/archive/2010/01/04/capturing-a-trace-a-boot-up.aspx"&gt;Capturing a Trace at Boot Up&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.frickelsoft.net/blog/?p=236"&gt;NTDSUtil shows different FSMO role owner than LDIFDE!?&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://edge.technet.com/Media/Windows-Server-2008-R2-Quick-Look-4-System-Health-Report/"&gt;Windows Server 2008 R2 Quick Look #4 - System Health Report&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://blogs.technet.com/uphclean/archive/2010/01/06/status-of-uphclean.aspx"&gt;Status of UPHClean&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://blogs.msdn.com/wmi/archive/2010/01/06/wmic-vs-wmi-powershell-cmdlets.aspx"&gt;wmic vs WMI Powershell cmdlets&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://feedproxy.google.com/~r/techtarget/Searchwinsystems/~3/cPd6xPyj-Bk/0,289483,sid68_gci1378317,00.html"&gt;Disaster prevention strategies for Active Directory forests&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://blogs.technet.com/grouppolicy/archive/2010/01/07/tales-from-the-community-enforced-vs-block-inheritance.aspx"&gt;Tales from the Community: Enforced vs. Block Inheritance&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://blog.joeware.net/2010/01/07/1862/"&gt;AdFind V01.41.00 and AdMod V01.12.00 Betas available&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://blogs.technet.com/keithcombs/archive/2010/01/08/hspd-12-logical-access-authentication-and-active-directory-domains.aspx"&gt;HSPD-12 Logical Access Authentication and Active Directory Domains&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://blogs.technet.com/keithcombs/archive/2010/01/08/changes-in-functionality-windows-server-2008-to-windows-server-2008-r2.aspx"&gt;Changes in Functionality - Windows Server 2008 to Windows Server 2008 R2&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://edge.technet.com/Media/Windows-Server-2008-R2-Quick-Look-5-Group-Policy-Management/"&gt;Windows Server 2008 R2 Quick Look #5 - Group Policy Management&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://blogs.technet.com/netmon/archive/2010/01/08/annotated-traces-for-windows-system-behavior.aspx"&gt;Annotated Traces for Windows System Behavior&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://feedproxy.google.com/~r/techtarget/Searchwinsystems/~3/dgYCttnngMg/0,295582,sid68_gci1174556,00.html"&gt;Tests for securing the internal Windows network&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://blogs.msdn.com/card/archive/2010/01/08/introduction-to-token-issuance-authorization-in-ad-fs-2-0-rc.aspx"&gt;Introduction to Token Issuance Authorization in AD FS 2.0 RC&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.identityblog.com/?p=1076"&gt;Federation with ADFS in Windows Server 2008&lt;/a&gt;&lt;/li&gt; &lt;/ul&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3304952" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/askds/archive/tags/KB+Articles/default.aspx">KB Articles</category><category domain="http://blogs.technet.com/askds/archive/tags/Other+Blogs/default.aspx">Other Blogs</category></item><item><title>The importance of following ALL the authoritative restore steps</title><link>http://blogs.technet.com/askds/archive/2010/01/08/the-importance-of-following-all-the-authoritative-restore-steps.aspx</link><pubDate>Fri, 08 Jan 2010 17:34:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3304566</guid><dc:creator>NedPyle</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/askds/comments/3304566.aspx</comments><wfw:commentRss>http://blogs.technet.com/askds/commentrss.aspx?PostID=3304566</wfw:commentRss><description>&lt;P&gt;Hello, David Everett here again. Recently a customer contacted Microsoft Product Support to determine why the &lt;B&gt;Connect to Domain Controller&lt;/B&gt; option in &lt;B&gt;Active Directory Users and Computers&lt;/B&gt; (aka: ADUC or dsa.msc) was generating an incomplete list of Domain Controllers (DCs) for one domain. Even though the list of available DCs was truncated we found we could manually enter the name of any DC not in the list and &lt;B&gt;Active Directory Users and Computers&lt;/B&gt; would connect to the DC without issue.&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Determining the scope of the issue:&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;Wanting to see if the truncated list of DCs was specific to &lt;B&gt;Active Directory Users and Computers&lt;/B&gt; or if other tools also failed to locate all the DCs we ran &lt;B&gt;nltest.exe /dclist:contoso.com.&lt;/B&gt; The output shown below revealed a complete list of domain controllers for contoso.com but many were missing their &lt;B&gt;[DS] Site:&lt;/B&gt; information. We found that those DCs missing their &lt;B&gt;[DS] Site: &lt;/B&gt;information happened to be the same DCs missing when &lt;B&gt;Connect to Domain Controller&lt;/B&gt; was selected. One final observation was that the list of available DCs varied from one DC to the next when selecting &lt;B&gt;Connect to Domain Controller&lt;/B&gt;.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Get list of DCs in domain 'contoso.com' from '\\dc01.contoso.com '. &lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAYDC01.contoso.com&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [DS] Site: Mayberry &lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAYDC02.contoso.com&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [DS] Site: Mayberry &lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DALDC01.contoso.com&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [DS] Site: Dallas &lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DALDC02.contoso.com&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LADC01.contoso.com&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [DS] Site: LosAngeles &lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LADC02.contoso.com&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SEADC01.contoso.com&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SEADC02.contoso.com&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;The two DCs in the Los Angeles site saw themselves in the list of available DCs but not the other DC in the same site. Suspecting Active Directory (AD) replication might be at fault we ran &lt;B&gt;Repadmin /showrepl * /csv &amp;gt; Showrepl.csv&lt;/B&gt; and found AD replication was free of errors forest wide.&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Checking for Database Inconsistencies:&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;Since AD Replication was not at fault our focus switched to AD database inconsistencies. We focused on three primary objects which house all of the metadata needed for DC discovery:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The Distinguished Name (DN) of the DC’s object in the domain partition&lt;/LI&gt;&lt;/UL&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;I&gt;&lt;FONT size=2 face=Consolas&gt;CN=LADC01,OU=Domain Controllers,DC=contoso,DC=com&lt;/FONT&gt;&lt;/I&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;UL&gt;
&lt;LI&gt;The DN of the DC’s NTDS Settings object and&lt;/LI&gt;&lt;/UL&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;I&gt;&lt;FONT size=2 face=Consolas&gt;CN=NTDS Settings,CN=LADC01,CN=Servers,CN=LosAngeles,CN=Sites,CN=Configuration,DC=contoso,DC=com&lt;/FONT&gt;&lt;/I&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;UL&gt;
&lt;LI&gt;The DN of the DC’s Server object which resides just above the DC’s NTDS Settings object in the Configuration partition&lt;/LI&gt;&lt;/UL&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;I&gt;&lt;FONT size=2 face=Consolas&gt;CN=LADC01,CN=Servers,CN=LosAngeles,CN=Sites,CN=Configuration,DC=contoso,DC=com&lt;/FONT&gt;&lt;/I&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Using &lt;B&gt;LDP.EXE&lt;/B&gt; we connected to both DCs in the Los Angeles site and gathered dumps of all three objects for both DCs and compared the output. For those who tend to avoid this tool, see MSKB &lt;A href="http://support.microsoft.com/kb/252335" mce_href="http://support.microsoft.com/kb/252335"&gt;252335&lt;/A&gt; on how to &lt;B&gt;Bind&lt;/B&gt; and &lt;B&gt;Connect&lt;/B&gt; but make certain to select &lt;I&gt;CN=Configuration,DC=forestrootdomain&lt;/I&gt; from the &lt;B&gt;Base DN:&lt;/B&gt; drop-down. Expand the configuration partition on the left until you locate the server object of the DC that was restored.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/TheimportanceoffollowingALLtheauthoritat_B0CA/image_2.png" mce_href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/TheimportanceoffollowingALLtheauthoritat_B0CA/image_2.png"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; DISPLAY: inline; BORDER-TOP: 0px; BORDER-RIGHT: 0px" title=image border=0 alt=image src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/TheimportanceoffollowingALLtheauthoritat_B0CA/image_thumb.png" width=690 height=376 mce_src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/TheimportanceoffollowingALLtheauthoritat_B0CA/image_thumb.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;This LDP dump of LADC01’s Server object in the Configuration partition was taken while bound to LADC01 (notice the DC name in blue title bar indicating which DC we’re bound to). Looking at the third attribute from the bottom we find the &lt;B&gt;serverReference &lt;/B&gt;forward link attribute in the list of attributes. This attribute contains the DN path of the corresponding DC object in the DC=contoso,DC=com partition. Below is an LDP dump of LADC01’s Server object while bound to LADC02. Notice the &lt;B&gt;serverReference&lt;/B&gt; forward link attribute is missing which indicates it is not populated on this DC’s copy of the AD Database.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/TheimportanceoffollowingALLtheauthoritat_B0CA/image_4.png" mce_href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/TheimportanceoffollowingALLtheauthoritat_B0CA/image_4.png"&gt;&lt;IMG style="BORDER-BOTTOM: 0px; BORDER-LEFT: 0px; DISPLAY: inline; BORDER-TOP: 0px; BORDER-RIGHT: 0px" title=image border=0 alt=image src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/TheimportanceoffollowingALLtheauthoritat_B0CA/image_thumb_1.png" width=690 height=341 mce_src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/TheimportanceoffollowingALLtheauthoritat_B0CA/image_thumb_1.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;When we examined the LDP dumps of LADC02’s Server object we found the same was true. LADC02 had a DN for its own DC object but the LDP dump of LADC02’s Server object taken while bound to LADC01 had an empty &lt;B&gt;serverReference&lt;/B&gt; attribute. Finally, those DCs which always appear in the list of domain controllers had a populated &lt;B&gt;serverReference&lt;/B&gt; attribute on all DCs.&lt;/P&gt;
&lt;P&gt;To determine how widespread this issue was we queried the &lt;B&gt;serverReference&lt;/B&gt; attribute for both Los Angeles DCs from every DC in the forest using the repadmin /showattr command below. DCs that returned a &lt;B&gt;serverReference&lt;/B&gt; attribute had the DC object DN and those DCs that had no &lt;B&gt;serverReference&lt;/B&gt; attribute were empty:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;FONT size=2 face=Consolas&gt;Repadmin.exe /showattr * CN=LADC01,CN=Servers,CN=LosAngeles,CN=Sites,CN=Configuration,DC=contoso,DC=com /atts:serverReference&lt;/FONT&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;B&gt;Fixing the problem:&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;We connected to the configuration partition on LADC01 using &lt;B&gt;adsiedit.msc&lt;/B&gt; and manually added the “CN=LADC02,OU=Domain Controllers,DC=contoso,DC=com” DN to the &lt;B&gt;serverReference&lt;/B&gt; attribute on LADC02. This change made LADC02 appear in the list of available DCs when the &lt;B&gt;Connect to Domain Controller&lt;/B&gt; option was selected in &lt;B&gt;Active Directory Users and Computers&lt;/B&gt;. Also, &lt;B&gt;nltest.exe /dclist:contoso.com &lt;/B&gt;now showed &lt;B&gt;[DS] Site: LosAngeles&lt;/B&gt; next to LADC02.contoso.com on all DCs. Not shown here, but once the DN of the DC’s object in the contoso.com domain was added to the &lt;B&gt;serverReference&lt;/B&gt; attribute, the &lt;B&gt;serverReferenceBL&lt;/B&gt; back-link attribute was automatically populated on the DC object in the contoso.com domain.&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Determining how this occurred:&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;Now that we understood why the DC list was incomplete we started looking for how this occurred. To do this we gathered replication metadata from these three objects for both LADC01 and LADC02. The command used to gather the metadata from LADC01 for LADC02’s server object in the configuration partition is:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;FONT size=2&gt;&lt;FONT face=Consolas&gt;repadmin.exe /showobjmeta LADC01&lt;B&gt; &lt;/B&gt;CN=LADC02,CN=Servers,CN=LosAngeles,CN=Sites,CN=Configuration,DC=contoso,DC=com&lt;B&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;Comparing the objects dumped from LADC01 and LADC02 we found the &lt;B&gt;Ver&lt;/B&gt; (version) numbers matched. It wasn’t until we looked at metadata of the DC object in the domain partition and compared it with the corresponding Server object in the configuration partition that we understood what occurred.&lt;/P&gt;
&lt;P&gt;Here is a showobjmeta dump of CN=LADC02,CN=Servers,CN=LosAngeles,CN=Sites,CN=Configuration,DC=contoso,DC=com from LADC01:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;FONT size=1 face=Consolas&gt;repadmin.exe /showobjmeta ladc01 CN=LADC02,CN=Servers,CN=LosAngeles,CN=Sites,CN=Configuration,DC=contoso,DC=com &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=1 face=Consolas&gt;11 entries. &lt;BR&gt;Loc.USN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Originating DC&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Org.USN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Org.Time/Date&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;FONT color=#ff0000&gt;&lt;STRONG&gt;Ver &lt;/STRONG&gt;&lt;/FONT&gt;&amp;nbsp; Attribute &lt;BR&gt;=======&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ============&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; === ======&amp;nbsp; =============&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ===&amp;nbsp;&amp;nbsp; ========= &lt;BR&gt;&amp;nbsp;&amp;nbsp; 8363&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; b5c14a75-7f99-4f31-b84b-d755190a2c0d&amp;nbsp; 213256008&amp;nbsp;&amp;nbsp; 2007-04-15 15:04:39&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp; objectClass &lt;BR&gt;&amp;nbsp; 85895&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LosAngeles\LADC02&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 85895&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2007-04-15 17:11:27&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&amp;nbsp;&amp;nbsp; cn &lt;BR&gt;&amp;nbsp;&amp;nbsp; 8363&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; b5c14a75-7f99-4f31-b84b-d755190a2c0d&amp;nbsp; 213256008&amp;nbsp;&amp;nbsp; 2007-04-15 15:04:39&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;FONT color=#ff0000&gt;&lt;STRONG&gt;1&amp;nbsp;&amp;nbsp; instanceType&lt;/STRONG&gt;&lt;/FONT&gt; &lt;BR&gt;&amp;nbsp;&amp;nbsp; 8363&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; b5c14a75-7f99-4f31-b84b-d755190a2c0d&amp;nbsp; 213256008&amp;nbsp;&amp;nbsp; 2007-04-15 15:04:39&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp; whenCreated &lt;BR&gt;&lt;EM&gt;&amp;lt;snip&amp;gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Here is a truncated showobjmeta dump of CN=LADC02,OU=Domain Controllers,DC=contoso,DC=com from LADC01:&lt;/P&gt;
&lt;P&gt;repadmin.exe /showobjmeta ladc01 CN=LADC02,OU=Domain Controllers,DC=contoso,DC=com &lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;FONT size=1 face=Consolas&gt;41 entries. &lt;BR&gt;Loc.USN&amp;nbsp;&amp;nbsp; Originating DC&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Org.USN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Org.Time/Date&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;&lt;FONT color=#ff0000&gt;Ver&lt;/FONT&gt;&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Attribute &lt;BR&gt;=======&amp;nbsp;&amp;nbsp; ============&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; === ========&amp;nbsp; =============&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ===&amp;nbsp;&amp;nbsp;&amp;nbsp; ========= &lt;BR&gt;92248340&amp;nbsp; fb36d148-19fd-43f0-8876-91a027863f79&amp;nbsp; 155898&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2009-11-18 12:56:34&amp;nbsp; 100001 objectClass &lt;BR&gt;92248339&amp;nbsp; 77dba4f6-3870-4eb5-b46a-4f1fb1ee0be6&amp;nbsp; 92248339&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2009-11-18 12:59:51&amp;nbsp;&amp;nbsp;&amp;nbsp; 4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;cn &lt;BR&gt;92248340&amp;nbsp; fb36d148-19fd-43f0-8876-91a027863f79&amp;nbsp; 155898&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2009-11-18 12:56:34&amp;nbsp; 100001 description &lt;BR&gt;92248340&amp;nbsp; fb36d148-19fd-43f0-8876-91a027863f79&amp;nbsp; 155898&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2009-11-18 12:56:34&amp;nbsp; &lt;FONT color=#ff0000&gt;&lt;STRONG&gt;100001 instanceType&lt;/STRONG&gt;&lt;/FONT&gt; &lt;BR&gt;9027&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4855f23c-744c-488d-852c-9c170dd3359c&amp;nbsp;&amp;nbsp; 108176481&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2007-04-15 18:10:11&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;whenCreated &lt;BR&gt;&lt;EM&gt;&amp;lt;snip&amp;gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;B&gt;Interpretation of the data:&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;The &lt;B&gt;Version&lt;/B&gt; number of the attributes on LADC01’s DC object in the domain partition have a USN that is 100,000 higher than the DC’s corresponding Server object in the configuration partition. &lt;I&gt;This strongly suggests the DC object in the Domain Controllers OU was authoritatively restored with the default version increase of 100,000 while the DC’s corresponding Server object in the configuration partition was not authoritatively restored. &lt;/I&gt;The customer then remembered accidentally deleting several of the DCs a while back and performing an authoritative restore on the entire Domain Controllers OU.&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Understanding the inconsistencies:&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;Now that we knew an authoritative restore of the domain controllers OU was performed we needed to determine why the &lt;B&gt;serverReference&lt;/B&gt; and &lt;B&gt;serverReferenceBL&lt;/B&gt; attributes for restored DCs were missing and different across all DCs. &lt;/P&gt;
&lt;P&gt;Anyone who has performed authoritative restores of users and groups will recall an issue where group membership is not correct on replica DCs after users and groups are authoritatively restored; this is discussed at length in KB&lt;A href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;280079" mce_href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;280079"&gt;280079&lt;/A&gt;. In the case of restored users and groups, when a user is deleted their membership from the remaining group is removed. If the user is then restored, but the group is not, the membership will not be restored on any DC except the DC where the restore took place. For those wondering what this has to do with DCs being restored, it is identical. DCs are security principals just like users, and the DC’s server object in the configuration partition behaves much like a group. If the DC object is deleted from the domain partition the &lt;B&gt;serverReference&lt;/B&gt; attribute containing the forward link will be NULL’ed out on the server object in the configuration partition. If just the DC object in the domain partition is restored the &lt;B&gt;serverReference&lt;/B&gt; attribute on the corresponding server object in the configuration partition will not be updated on replica DCs once the restored DC object inbound replicates to them.&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Avoiding this issue:&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;Since the release of Windows Server 2003 Service Pack 1 &lt;B&gt;ntdsutil.exe&lt;/B&gt; has automatically created LDF files for all partitions in the forest where restored objects have back-links. This is discussed further in MSKB &lt;A href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;840001" mce_href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;840001"&gt;840001&lt;/A&gt;. In the case of user accounts you ensure all users have the correct group membership on all DCs by allowing the restored user accounts to replicate to all DCs/GCs. Once all DCs have the restored account you use &lt;I&gt;ldifde -i -f &amp;lt;AR*.ldf&amp;gt;&lt;/I&gt; and import the user’s group membership against to the recovery DC. Doing this ensures the user’s DN is added to the member attribute on the group and the version of the &lt;B&gt;member&lt;/B&gt; attribute is bumped higher causing it to replicate to all DCs. Since all DCs have a copy of the restored user account in their local database the DN on the member attribute is retained. As a rule of thumb, if you are authoritatively restoring users, computers or groups you should &lt;EM&gt;always import the LDF files created by &lt;STRONG&gt;ntdsutil.exe&lt;/STRONG&gt;&lt;/EM&gt; and avoid issues like this. &lt;/P&gt;
&lt;P&gt;Or even better, deploy Windows Server 2008 R2 and enable the &lt;A href="http://blogs.technet.com/askds/archive/2009/08/27/the-ad-recycle-bin-understanding-implementing-best-practices-and-troubleshooting.aspx" mce_href="http://blogs.technet.com/askds/archive/2009/08/27/the-ad-recycle-bin-understanding-implementing-best-practices-and-troubleshooting.aspx"&gt;AD Recycle Bin&lt;/A&gt; – it automatically handles back links and forward links.&lt;/P&gt;
&lt;P&gt;- Dave “metadata” Everett&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3304566" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/askds/archive/tags/Disaster+Recovery/default.aspx">Disaster Recovery</category><category domain="http://blogs.technet.com/askds/archive/tags/backup+and+restore/default.aspx">backup and restore</category></item><item><title>Clustered Certification Authority maintenance tasks</title><link>http://blogs.technet.com/askds/archive/2010/01/07/clustered-certification-authority-maintenance-tasks.aspx</link><pubDate>Thu, 07 Jan 2010 16:50:50 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3304254</guid><dc:creator>NedPyle</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/askds/comments/3304254.aspx</comments><wfw:commentRss>http://blogs.technet.com/askds/commentrss.aspx?PostID=3304254</wfw:commentRss><description>&lt;p&gt;Hi all Rob Greene here again. I thought I would share with you how to do some common tasks with a Windows Server 2008 clustered Certification Authority (CA). When the CA is clustered there are definitely different steps that need to be taken when you:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Make a change to the behavior of the CA by using &lt;b&gt;certutil.exe&lt;/b&gt; with &lt;b&gt;–setreg&lt;/b&gt; or &lt;b&gt;–delreg&lt;/b&gt; switches.&lt;/li&gt;    &lt;li&gt;Modify the registry values in the &lt;b&gt;HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\CertSvc&lt;/b&gt; hive.&lt;/li&gt;    &lt;li&gt;Renew the CA’s certificate.&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;In the past before the Certification Authority service (CertSvc) was supported in a cluster, you could make these changes and then stop and start the CertSvc service without a problem. This is still the case when the Certification Authority has not been clustered.&lt;/p&gt;  &lt;p&gt;However, when you have the Certification Authority configured as a cluster you must avoid starting and stopping the service outside of the Cluster Administrator snap-in (&lt;b&gt;Cluadmin.msc&lt;/b&gt;). The reason is that the Cluster Service not only keeps track of the service state for CertSvc, it is also responsible for making sure that the registry key location &lt;b&gt;HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\CertSvc&lt;/b&gt; is saved to the quorum disk when it notices a change to the registry location. This is noted in the &lt;a href="http://technet.microsoft.com/en-us/library/cc742517(WS.10).aspx"&gt;CA Cluster whitepaper&lt;/a&gt; also, which is required reading for anyone clustering CA’s.&lt;/p&gt;  &lt;h3&gt;Changing the behavior of the Certification Authority&lt;/h3&gt;  &lt;p&gt;If you need to make a change to the behavior of the Certification Authority with &lt;b&gt;CertUtil.exe&lt;/b&gt; or direct registry modification, you must always follow the steps below:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;1. Logon to the active clustered Certification Authority node. If you are unsure which node currently owns the resource do the following:&lt;/p&gt;    &lt;p&gt;&amp;#160;&amp;#160;&amp;#160; a. Launch the failover Cluster Management MMC.&lt;/p&gt;    &lt;p&gt;&amp;#160;&amp;#160;&amp;#160; b. Select the Certification Authority resource, and in the right hand pane you will see the “Current Owner” (See figure 1).&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/ClusteredCertificationAuthoritymaintenan_A691/image_2.png"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/ClusteredCertificationAuthoritymaintenan_A691/image_thumb.png" width="581" height="338" /&gt;&lt;/a&gt;       &lt;br /&gt;&lt;font size="1"&gt;Figure 1 - Current Owner of the Certification Authority resource&lt;/font&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;2. Use &lt;b&gt;certutil.exe –setreg&lt;/b&gt; (recommended) command, or modify the registry directly.&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;3. Launch the Failover Cluster Management snap-in.&lt;/p&gt;    &lt;p&gt;4. Take the Certification Authority resource (Service) offline and then bring it back online. We have to take the resource offline and back online since the CertSvc service will not read any registry key changes without being restarted, and as I stated above when the CA is clustered you should refrain from stopping and starting the CertSvc service directly.&lt;/p&gt;    &lt;p&gt;&amp;#160;&amp;#160;&amp;#160; a. Right click on the Certification Authority resource in the tree view pane.&lt;/p&gt;    &lt;p&gt;&amp;#160;&amp;#160;&amp;#160; b. Select either “Bring this service or application online” or “Take this service or application offline” (See figure 2).&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/ClusteredCertificationAuthoritymaintenan_A691/image_4.png"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/ClusteredCertificationAuthoritymaintenan_A691/image_thumb_1.png" width="581" height="336" /&gt;&lt;/a&gt;       &lt;br /&gt;&lt;font size="1"&gt;Figure 2 - Taking the resource offline / online&lt;/font&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;h3&gt;Renewing the subordinate Certification Authority certificate&lt;/h3&gt;  &lt;p&gt;This section discusses the steps that need to be done when renewing a subordinate CA certificate. A Root certification authority shouldn’t be clustered and instead should be configured as an offline root.&lt;/p&gt;  &lt;h5&gt;Verify the request file location&lt;/h5&gt;  &lt;p&gt;When the CA certificate is renewed it will stop the CertSvc service to generate the certificate request file. The request file location and name is dictated by the following registry key:&lt;/p&gt;  &lt;p&gt;&lt;b&gt;HKEY_Local_Machine\System\CurrentControlSet\Services\CertSvc\Configuration\&amp;lt;CA Name&amp;gt;\RequestFileName&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;Before renewing the CA you will want to make sure that the registry key points to a valid file system path. If it is not, either the renewal will fail silently, or you might get the error “The system cannot find the file specified” when you attempt to renew the CA. If you have to change this value do the following on the active CA node:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;1. certutil –setreg CA\RequestFileName “&amp;lt;File path and name&amp;gt;”. For example:     &lt;br /&gt;      &lt;br /&gt;&lt;font size="2" face="Consolas"&gt;&amp;#160; certutil –setreg CA\RequestFileName &amp;quot;c:\contoso_subCA1.req”&lt;/font&gt;&lt;/p&gt;    &lt;p&gt;2. Take the resource offline and back online (See Figure 2 above).&lt;/p&gt; &lt;/blockquote&gt;  &lt;h5&gt;&lt;/h5&gt;  &lt;h5&gt;Renewing the Certification Authority certificate&lt;/h5&gt;  &lt;p&gt;As noted earlier, if the CertSvc service is stopped or started outside of the Failover Cluster Management snap-in the cluster system is not aware of any changes that are done to the registry. Here is a high level process of what happens when a CA is renewed so that you can understand why the below steps are necessary on a clustered CA:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;1. CertSvc service is stopped to generate the certificate request file. It reads the RequestFileName registry value to determine where and what the file name should be for the request file.&lt;/p&gt;    &lt;p&gt;2. CertSvc service is started once the request file has been generated.&lt;/p&gt;    &lt;p&gt;3. CertSvc service is stopped again to install the issued certificate from the CA.&lt;/p&gt;    &lt;p&gt;4. The CACertHash registry value is updated to include the new CA certificate hash.     &lt;br /&gt;&lt;b&gt;&lt;i&gt;         &lt;br /&gt;NOTE&lt;/i&gt;&lt;/b&gt;&lt;i&gt;: NEVER DELETE OR MODIFY this registry value unless directed by Microsoft support. Modifying this registry key can cause the CA not to function properly or in some cases to not even start!&lt;/i&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Here are the actual steps to renew the CA on a cluster.&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;1. Open the Failover Cluster Management snap-in.&lt;/p&gt;    &lt;p&gt;2. “Pause” the inactive Certification Authority node. If you are unsure about which server is the active node see Figure 1. &lt;/p&gt;    &lt;p&gt;&amp;#160;&amp;#160;&amp;#160; a. Select the computer node in the Failover Cluster Management snap-in.&lt;/p&gt;    &lt;p&gt;&amp;#160;&amp;#160;&amp;#160; b. Right click on it select “Pause”.&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/ClusteredCertificationAuthoritymaintenan_A691/image_6.png"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/ClusteredCertificationAuthoritymaintenan_A691/image_thumb_2.png" width="602" height="333" /&gt;&lt;/a&gt;       &lt;br /&gt;&lt;font size="1"&gt;Figure 3 - Pausing the inactive node&lt;/font&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;3. Once the inactive node is paused you can renew the CA’s certificate. Please review the following TechNet article to help with the process of actually getting the &lt;a href="http://technet.microsoft.com/en-us/library/cc776691(WS.10).aspx"&gt;subordinate CA certificate renewed&lt;/a&gt;.&lt;/p&gt;    &lt;p&gt;4. Once you have gotten the CA’s certificate renewed by the root CA, and installed the new certificate to the subordinate CA you will need to take the Certification Authority resource offline and then back online within the Failover Cluster Management snapin.&lt;/p&gt;    &lt;p&gt;&amp;#160;&amp;#160;&amp;#160; a. Right click on the Certification Authority resource in the tree view pane.&lt;/p&gt;    &lt;p&gt;&amp;#160;&amp;#160;&amp;#160; b. Select either “Bring this service or application online” or “Take this service or application offline” (See figure 2 above).&lt;/p&gt;    &lt;p&gt;5. Open the Certification Authority snapin, and target the Clustered Network resource name.&lt;/p&gt;    &lt;p&gt;6. Right click on the Certification Authority name and select properties.&lt;/p&gt;    &lt;p&gt;7. If you renewed with a new key pair you should see several certificates listed as show in figure 4.&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/ClusteredCertificationAuthoritymaintenan_A691/image_8.png"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://blogs.technet.com/blogfiles/askds/WindowsLiveWriter/ClusteredCertificationAuthoritymaintenan_A691/image_thumb_3.png" width="337" height="438" /&gt;&lt;/a&gt;       &lt;br /&gt;&lt;font size="1"&gt;Figure 4 - Certification Authority properties.&lt;/font&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;8. Once you have verified that the Certification Authority is using the renewed CA certificate you can “Resume” the node that was paused in step 2.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Since the Certification Authority service is configured as a generic service the above processes must be adhered to when managing a clustered CA. If changes are made outside of the Cluster service’s knowledge then the nodes will never be in sync and clustering will fail&lt;/p&gt;  &lt;p&gt; - Rob “Raaaahhb” Greene&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3304254" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/askds/archive/tags/Certificates/default.aspx">Certificates</category><category domain="http://blogs.technet.com/askds/archive/tags/PKI/default.aspx">PKI</category><category domain="http://blogs.technet.com/askds/archive/tags/Windows+Server+2008/default.aspx">Windows Server 2008</category><category domain="http://blogs.technet.com/askds/archive/tags/Windows+Server+2008+R2/default.aspx">Windows Server 2008 R2</category><category domain="http://blogs.technet.com/askds/archive/tags/Cluster/default.aspx">Cluster</category></item><item><title>New Directory Services KB Articles/Blogs 12/20-1/2</title><link>http://blogs.technet.com/askds/archive/2010/01/05/new-directory-services-kb-articles-blogs-12-20-1-2.aspx</link><pubDate>Tue, 05 Jan 2010 18:51:51 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3303858</guid><dc:creator>Craig</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/askds/comments/3303858.aspx</comments><wfw:commentRss>http://blogs.technet.com/askds/commentrss.aspx?PostID=3303858</wfw:commentRss><description>&lt;p&gt;&lt;strong&gt;KB&lt;/strong&gt;&lt;/p&gt;  &lt;table border="1" cellspacing="0" cellpadding="0" width="500"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="bottom" width="48"&gt;         &lt;p&gt;&lt;a href="http://support.microsoft.com/?kbid=974841"&gt;974841&lt;/a&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="bottom" width="450"&gt;         &lt;p&gt;An update is available for Windows XP to support protocol negotiation for remote procedure call (RPC) over HTTP Authentication&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="bottom" width="48"&gt;         &lt;p&gt;&lt;a href="http://support.microsoft.com/?kbid=958147"&gt;958147&lt;/a&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="bottom" width="450"&gt;         &lt;p&gt;The Member ID field is logged incorrectly in the audit event on a Windows Server 2003 domain controller if you add a user of a different domain to a universal group&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="bottom" width="48"&gt;         &lt;p&gt;&lt;a href="http://support.microsoft.com/?kbid=955007"&gt;955007&lt;/a&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="bottom" width="450"&gt;         &lt;p&gt;The replication may seem like it is serialized when there are slow connections in a DFS Replication configuration in Windows Server 2003 R2&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="bottom" width="48"&gt;         &lt;p&gt;&lt;a href="http://support.microsoft.com/?kbid=977624"&gt;977624&lt;/a&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="bottom" width="450"&gt;         &lt;p&gt;AD RMS clients cannot authenticate federated identity providers&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="bottom" width="48"&gt;         &lt;p&gt;&lt;a href="http://support.microsoft.com/?kbid=977269"&gt;977269&lt;/a&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="bottom" width="450"&gt;         &lt;p&gt;Error message when you make a remote desktop connection to a terminal server that is running Windows Server 2008: “The requested operation requires elevation”&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="bottom" width="48"&gt;         &lt;p&gt;&lt;a href="http://support.microsoft.com/?kbid=977381"&gt;977381&lt;/a&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="bottom" width="450"&gt;         &lt;p&gt;The DFS Replication service may stop responding when it initializes the replication process for the replicated folders on a computer that is running Windows Server 2008 or Windows Server 2008 R2&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="bottom" width="48"&gt;         &lt;p&gt;&lt;a href="http://support.microsoft.com/?kbid=973243"&gt;973243&lt;/a&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="bottom" width="450"&gt;         &lt;p&gt;The default gateway is missing on a computer that is running Windows Server 2008 or Windows Vista after the computer restarts if the default gateway is set by using the Netsh command&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="bottom" width="48"&gt;         &lt;p&gt;&lt;a href="http://support.microsoft.com/?kbid=976674"&gt;976674&lt;/a&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="bottom" width="450"&gt;         &lt;p&gt;The computer stops responding when you access some shared files from a computer that is running Windows Server 2008 or Windows Vista&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="bottom" width="48"&gt;         &lt;p&gt;&lt;a href="http://support.microsoft.com/?kbid=975363"&gt;975363&lt;/a&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="bottom" width="450"&gt;         &lt;p&gt;A time-out error occurs when many NTLM authentication requests are sent from a computer that is running Windows Server 2008 R2 or Windows 7 in a high latency network&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="bottom" width="48"&gt;         &lt;p&gt;&lt;a href="http://support.microsoft.com/?kbid=978034"&gt;978034&lt;/a&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="bottom" width="450"&gt;         &lt;p&gt;Active Directory Certificate Services cannot be reinstalled by using the &amp;quot;Use existing private key&amp;quot; option on a computer that is running in Windows Server 2008 R2&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="bottom" width="48"&gt;         &lt;p&gt;&lt;a href="http://support.microsoft.com/?kbid=978116"&gt;978116&lt;/a&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="bottom" width="450"&gt;         &lt;p&gt;In an MIT realm, user authentication fails after invalid credentials are received on a computer that is running Windows 7 or Windows Server 2008 R2&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;&lt;strong&gt;Blogs&lt;/strong&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href="http://blogs.dirteam.com/blogs/tomek/archive/2009/12/20/kerberos-a-sprawa-portu.aspx"&gt;Kerberos and non-standard port number&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://feedproxy.google.com/~r/zdnet/microsoft/~3/ZOLDm5l-Af4/"&gt;Near-final build of Microsoft 'Geneva Server' goes to testers&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://theessentialexchange.com/blogs/michael/archive/2009/12/22/getting-the-contents-of-an-active-directory-integrated-dns-zone-version-2.aspx"&gt;Getting the Contents of an Active Directory Integrated DNS Zone, Version 2&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://blogs.technet.com/grouppolicy/archive/2009/12/23/how-to-install-rsat.aspx"&gt;How to Install GPMC on Server 2008, 2008 R2, and Windows 7 (via RSAT)&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://blogs.dirteam.com/blogs/tomek/archive/2009/12/23/adfs-v2-rc-and-iis-certificates.aspx"&gt;ADFS v2 RC and IIS certificates&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://blogs.technet.com/ad/archive/2009/12/29/how-windows-communication-works.aspx"&gt;How Windows Communication Works&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://edge.technet.com/Media/Windows-Server-2008-R2-Quick-Look-2-Active-Directory-Recycle-Bin/"&gt;Windows Server 2008 R2 Quick Look #2 - Active Directory Recycle Bin&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://msmvps.com/blogs/ad/archive/2009/09/30/initiate-replication-across-all-partitions-and-dcs.aspx"&gt;Initiate Replication across all Partitions and DCs&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://www.frickelsoft.net/blog/?p=235"&gt;Are there recommendations on what the “Deleted Object Lifetime” value should be set to?&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://msmvps.com/blogs/ad/archive/2009/10/07/is-my-active-directory-backed-up.aspx"&gt;Is my Active Directory Backed Up?&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://blogs.technet.com/netmon/archive/2010/01/04/capturing-a-trace-a-boot-up.aspx"&gt;Capturing a Trace a Boot Up&lt;/a&gt;&lt;/li&gt; &lt;/ul&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3303858" width="1" height="1"&gt;</description></item><item><title>Understanding DFSR conflict algorithms (and doing something about conflicts)</title><link>http://blogs.technet.com/askds/archive/2010/01/05/understanding-dfsr-conflict-algorithms-and-doing-something-about-conflicts.aspx</link><pubDate>Tue, 05 Jan 2010 18:37:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3303855</guid><dc:creator>NedPyle</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/askds/comments/3303855.aspx</comments><wfw:commentRss>http://blogs.technet.com/askds/commentrss.aspx?PostID=3303855</wfw:commentRss><description>&lt;P&gt;Ned here again. I’m frequently asked to explain the DFSR conflict algorithm – i.e. what happens when files are created or modified on two servers before replication takes place. What we don’t document well is that there are actually &lt;I&gt;three&lt;/I&gt; conflict algorithms and they all behave quite differently. I am breaking these out into scenarios for easier understanding. &lt;/P&gt;
&lt;P&gt;&lt;B&gt;Scenario 1:&lt;/B&gt; &lt;B&gt;Brand new files in initial sync with different versions of the file on each server.&lt;/B&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Two servers, A and B&lt;/LI&gt;
&lt;LI&gt;Both have a folder called c:\rfdata&lt;/LI&gt;
&lt;LI&gt;Folder contains a file called salespitch.pptx&lt;/LI&gt;
&lt;LI&gt;On server A, salespitch.pptx is dated July 2009. On server B, salespitch.pptx is dated October 2009 and was modified by a user very recently.&lt;/LI&gt;&lt;/UL&gt;
&lt;OL&gt;
&lt;LI&gt;I setup a new Replication Group.&lt;/LI&gt;
&lt;LI&gt;I make c:\rfdata the Replicated Folder.&lt;/LI&gt;
&lt;LI&gt;I make Server A the Primary Server.&lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;&lt;B&gt;Result:&lt;/B&gt; salespitch.pptx from A (dated July 2009) will now exist on both servers. The October version will be conflicted on B and it will lose the conflict.&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Explanation:&lt;/B&gt; When setting a server as Primary, it wins all conflicts no matter what. This is the so-called “Initial Sync conflict algorithm”.&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Scenario 2:&lt;/B&gt; &lt;B&gt;Existing files that have been replicated previously and are now being modified on two servers before replicating.&lt;/B&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Two servers, A and B&lt;/LI&gt;
&lt;LI&gt;Both are in an existing Replication Group (not performing initial sync) with a replicated folder pointing to c:\rfdata&lt;/LI&gt;
&lt;LI&gt;Folder contains a file called salespitch.pptx&lt;/LI&gt;
&lt;LI&gt;Replication is latent (in my test, I disconnected network cable from Server A)&lt;/LI&gt;&lt;/UL&gt;
&lt;OL&gt;
&lt;LI&gt;I modify the salespitch.pptx file on both servers. On Server A, I modified salespitch.pptx last.&lt;/LI&gt;
&lt;LI&gt;I plug the network cable back in to allow replication to resume.&lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;&lt;B&gt;Result:&lt;/B&gt; The file I modified last (i.e. the newest file with the latest UTC time stamp) replicates from A to B. B loses the conflict and his older copy will be conflicted.&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Explanation:&lt;/B&gt; This is the classic “last writer wins conflict algorithm” that is usually described for DFSR.&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Scenario 3:&lt;/B&gt; &lt;B&gt;New files that were created on both servers before replicating, but initial sync is not happening&lt;/B&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Two servers, A and B&lt;/LI&gt;
&lt;LI&gt;Both are in a Replication Group with a replicated folder pointing to c:\rfdata&lt;/LI&gt;
&lt;LI&gt;Replication is latent (in my test, I disconnected network cable from Server A)&lt;/LI&gt;&lt;/UL&gt;
&lt;OL&gt;
&lt;LI&gt;I copy an old file to both server A and B – so this file is “new” to DFSR on both servers.&lt;/LI&gt;
&lt;LI&gt;I modify one file on server B.&lt;/LI&gt;
&lt;LI&gt;I plug the network cable back in on A.&lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;&lt;B&gt;Result:&lt;/B&gt; The old file on A is replicated to B, and B loses the conflict. &lt;/P&gt;
&lt;P&gt;&lt;B&gt;Explanation:&lt;/B&gt; This is the only time an older file will win, and this would be the so-called “New to DFSR file conflict algorithm”. The reasoning here would be that when it comes to two files being created, the oldest one is likely the most important as it has been in use the longest. &lt;/P&gt;
&lt;P&gt;&lt;B&gt;That’s all well and good. But how do I get my conflicted files back when the “wrong” one wins?&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;You have a few options here:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;B&gt;Use&lt;/B&gt;&amp;nbsp;&lt;STRONG&gt;DPM&lt;/STRONG&gt; – &lt;A href="http://www.microsoft.com/systemcenter/dataprotectionmanager/en/us/default.aspx" mce_href="http://www.microsoft.com/systemcenter/dataprotectionmanager/en/us/default.aspx"&gt;Data Protection Manager&lt;/A&gt; provides on-the-fly backups of files and near-line recovery. This way your odds are highest that the latest versions of the file have been backed up. &lt;BR&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;B&gt;Use Volume Shadow Copies&lt;/B&gt; – You can configure automatic backups of files on your DFSR servers. Then when users delete or conflict files, the data can be easily restored. With a little training, your users can even restore files themselves and not have to spend time with the help desk. Note also that if you are still running XP or (Dog forbid) Win2000, you need to &lt;A href="http://www.microsoft.com/downloads/details.aspx?familyid=e382358f-33c3-4de7-acd8-a33ac92d295e&amp;amp;displaylang=en" mce_href="http://www.microsoft.com/downloads/details.aspx?familyid=e382358f-33c3-4de7-acd8-a33ac92d295e&amp;amp;displaylang=en"&gt;install a client&lt;/A&gt; to let users restore their own files. See &lt;A href="http://www.microsoft.com/windowsserver2003/techinfo/overview/scr.mspx" mce_href="http://www.microsoft.com/windowsserver2003/techinfo/overview/scr.mspx"&gt;TechNet&lt;/A&gt; and Windows Help for configuring this on a per-OS basis and make sure you read through the best practices info. VSC does &lt;I&gt;not &lt;/I&gt;replace regular backups! &lt;BR&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;B&gt;Use backups&lt;/B&gt; – Windows Server Backup, NT Backup (if still on Win2003 R2), or 3&lt;SUP&gt;rd&lt;/SUP&gt; parties should be used to back up &lt;BR&gt;your data every day. This way no matter what, you can always get back to yesterday’s copy of a file. &lt;BR&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;B&gt;Use the restoredfsr.vbs script&lt;/B&gt; – Unsupported, as-is, and provided without warranty, this script may be your only hope if you have no created backups and shadow copies. Use it at your own risk. I have &lt;A href="http://blogs.technet.com/askds/attachment/3303855.ashx" mce_href="http://blogs.technet.com/askds/attachment/3303855.ashx"&gt;attached an updated copy&lt;/A&gt; to this blog post that handles a few more complex file scenarios. &lt;EM&gt;As always, the script requires you to edit a few variables before running – see the script for how-to documentation&lt;/EM&gt;. You run it with:&lt;BR&gt;&lt;BR&gt;&lt;STRONG&gt;CSCRIPT.EXE restoredfsr.vbs&lt;/STRONG&gt;&lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;Hopefully this makes more sense now.&lt;/P&gt;
&lt;P&gt;- Ned “the mediator” Pyle&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3303855" width="1" height="1"&gt;</description><enclosure url="http://blogs.technet.com/askds/attachment/3303855.ashx" length="2102" type="application/x-zip-compressed" /><category domain="http://blogs.technet.com/askds/archive/tags/DFSR/default.aspx">DFSR</category></item></channel></rss>