Sign in
TechNet Blogs
Technet Blog Images
More ...
Browse by Tags
TechNet Blogs
>
Ask the Directory Services Team
>
All Tags
>
authentication
Server & Tools Blogs
>
Server & Management Blogs
>
Ask the Directory Services Team
All About Windows Server
Windows Server
Windows Server Essentials Blog
Building Clouds
Partner & Customer Solutions
Server & Cloud
Ask The
Performance Team
Ask Premier Field Engineering
Ask the Core Team
Cloud & Datacenter Management
The System Center Team Blog
System Center Virtual Machine Manager
System Center Service Manager
System Center Operations Manager
System Center Data Protection Manager
System Center Orchestrator
Partner & Customer Solutions
Client Management
System Center Configuration Manager
System Center Service Manager
MDOP
Malware Protection Center
Windows Intune
SUS
Partner and Customer Solutions
Virtualization, VDI & Remote Desktop
Virtualization Team Blog
Ben Armstrong’s Virtualization Blog
Jose Barreto Blog on Hyper-V
Partner & Customer Solutions
Remote Desktop Services
Windows Multipoint Server
Ask the Core Team on Hyper-V
File & Storage & High Availability
File & Storage
Jose Barreto
Partner & Customer Solutions
Ask the Core Team on Failover Cluster
Clustering & High Availability
Windows Server Management
PowerShell
Hey Scripting Guy (PowerShell)
Server Manager
Group Policy
Networking
Identity & Access
Ask Directory Services
Active Directory
Microsoft Leadership
Brad Anderson - In the Cloud
Ask the Directory Services Team
Microsoft's official enterprise support blog for AD DS and more
Live Now on Server & Tools Blogs
Subscribe
Comments
Contact
Menu
Blog Home
Atom
Translate this page
Powered by
Microsoft® Translator
Recent Posts
Back to the Loopback: Troubleshooting Group Policy loopback processing, Part 2
Posted
2 days ago
by
David Beach - MSFT
1
Comments
We're back. Did you miss us?
Posted
6 days ago
by
David Beach - MSFT
18
Comments
AD FS 2.0 Claims Rule Language Part 2
Posted
16 days ago
by
Jonathan Stephens, MSFT
0
Comments
Circle Back to Loopback
Posted
3 months ago
by
Jonathan Stephens, MSFT
23
Comments
Tags
AD Replication
audit
Authorization
DFSN
DFSR
DFSR Performance
DNS
FRS
FSMO
group policy
infrastructure
Kerberos
Logon
Mail Sack
Ned Pyle
NTLM
Other Blogs
Rob Greene
Security
Silly Rabbit
USMT
USMT Behaviors
Windows Server 2008
Windows Server 2008 R2
Windows Vista
Archives
Archives
May 2013
(3)
February 2013
(2)
January 2013
(3)
November 2012
(2)
October 2012
(3)
September 2012
(7)
August 2012
(8)
July 2012
(8)
June 2012
(5)
May 2012
(6)
April 2012
(8)
March 2012
(3)
February 2012
(4)
January 2012
(8)
December 2011
(5)
November 2011
(2)
October 2011
(4)
September 2011
(10)
August 2011
(30)
July 2011
(9)
June 2011
(11)
May 2011
(12)
April 2011
(18)
March 2011
(7)
February 2011
(14)
January 2011
(10)
December 2010
(2)
November 2010
(11)
October 2010
(10)
September 2010
(16)
August 2010
(17)
July 2010
(10)
June 2010
(12)
May 2010
(14)
April 2010
(15)
March 2010
(16)
February 2010
(18)
January 2010
(9)
December 2009
(11)
November 2009
(9)
October 2009
(19)
September 2009
(16)
August 2009
(17)
July 2009
(11)
June 2009
(25)
May 2009
(15)
April 2009
(37)
March 2009
(22)
February 2009
(14)
January 2009
(19)
December 2008
(9)
November 2008
(18)
October 2008
(15)
September 2008
(12)
August 2008
(7)
July 2008
(7)
June 2008
(7)
May 2008
(7)
April 2008
(10)
March 2008
(11)
February 2008
(7)
January 2008
(12)
December 2007
(2)
November 2007
(5)
October 2007
(4)
September 2007
(2)
August 2007
(6)
More
▼
Less
▲
Tagged Content List
Blog Post:
MaxTokenSize and Windows 8 and Windows Server 2012
MikeStephensMSFT
Hello AskDS Populous, Mike here and I want to share with you some of the excellent enhancements we accomplished in Windows 8 and Windows Server 2012 around MaxTokenSize. Let’s review MaxTokenSize and its symptoms before we jump in to wonderful world of Windows 8 (say that three times fast). Wonderful...
on
12 Sep 2012
Blog Post:
Monthly Mail Sack: Yes, I Finally Admit It Edition
NedPyle [MSFT]
Heya folks, Ned here again. Rather than continue the lie that this series comes out every Friday like it once did, I am taking the corporate approach and rebranding the mail sack. Maybe we’ll have the occasional Collector’s Edition versions. This week month, I answer your questions on: The semi-myth...
on
24 Aug 2012
Blog Post:
New Slow Logon, Slow Boot Troubleshooting Content
NedPyle [MSFT]
Hi all, Ned here again. We get emailed here all the time about issues involving delays in user logons. Often enough that, a few years back, Bob wrote a multi-part article on the subject. Taking it to the next level, some of my esteemed colleagues have created a multi-part TechNet Wiki series on understanding...
on
1 May 2012
Blog Post:
Friday Mail Sack: Get Off My Lawn Edition
NedPyle [MSFT]
Hi folks, Ned here again. I know this is supposed to be the Friday Mail Sack but things got a little hectic and... ah heck, it doesn't need explaining, you're in IT. This week - with help from the ever-crotchety Jonathan Stephens - we talk about: Multiple WMI Filters LDAP MaxPoolThreads Many...
on
11 Feb 2012
Blog Post:
Friday Mail Sack: Guest Reply Edition
NedPyle [MSFT]
Hi folks, Ned here again. This week we talk: CA migration from 1 to 2 tier ADAM/ADLDS P2V ABC 123 Managing AGPM security filters Multiple IIS App pools and Kerberos AGPM multi-domain comparison ADUC domain password weirdness DFSR deletion conflict handling Stale account deletion...
on
11 Nov 2011
Blog Post:
Friday Mail Sack: Robert Wagner Edition
NedPyle [MSFT]
Hello folks, Ned here again. This week, we discuss: Computer and user name uniqueness DFSR file size matters The weird user unlock in ADUC RDC extras USMT versus full disk encryption DFSN and standalone interlink timing DFSR conflict folder growth Other stuff Things have...
on
9 Sep 2011
Blog Post:
Friday Mail Sack: Charlotte Edition
NedPyle [MSFT]
Hiya folks, Ned back with a palette-cleansing Mail Sack after this monstrosity . This week we talk about: To customize AD schema or not DC and root hints USMT and the case of the missing apps DFSR and %SYSTEMROOT% More fun with DC Same As Parent domain zone records Speeding up DFSN...
on
19 Aug 2011
Blog Post:
Friday Mail Sack: Anchors Aweigh Edition
NedPyle [MSFT]
Hiya folks, Ned here again. I finally have an editor that allows anchors on all the questions, so I am adding a quasi “table of contents” for these posts that allow easier navigation and linking. I’ll retrofit all the old mail sack articles too… eventually. This week we discuss...
on
29 Jul 2011
Blog Post:
Friday Mail Sack: LeBron is not Jordan Edition
NedPyle [MSFT]
Hi folks, Ned here again. Today we discuss trusts rules around domain names, attribute uniqueness, the fattest domains we’ve ever seen, USMT data-only migrations, kicking FRS while it’s down, and a few amusing side topics. Scottie, don’t be that way. Go Mavs. Creating trusts...
on
10 Jun 2011
Blog Post:
RSA SecurID Do Over
NedPyle [MSFT]
Ned here. If you are using RSA SecurID, you’re probably aware they were compromised several months ago . You may also have heard that since then, hackers have been using that stolen info to attack or compromise various organizations. What you may not know is RSA is now issuing replacement tokens...
on
7 Jun 2011
Blog Post:
Friday Mail Sack: Now with 100% more words
NedPyle [MSFT]
Hi folks, Ned here again. It’s been nearly a month since the last Mail Sack post so I’ve built up a good head of steam. Today we discuss FRS, FSMO, Authentication, Authorization, USMT, DFSR, VPN, Interactive Logon, LDAP, DFSN, MS Certified Masters, Kerberos, and other stuff. Plus a small...
on
15 Apr 2011
Blog Post:
What does DCDIAG actually… do?
NedPyle [MSFT]
Hi folks, Ned here again. I recently wrote a KB article about some expected DCDIAG.EXE behaviors . This required reviewing DCDIAG.EXE as I wasn’t finding anything deep in TechNet about the “Services” test that had my interest. By the time I was done, I had found a dozen other test behaviors...
on
22 Mar 2011
Blog Post:
Friday Mail Sack: No Redesign Edition
NedPyle [MSFT]
Hello folks, Ned here again. Today we talk PDCs, DFSN, DFSR, AGPM, authentication, PowerShell, Kerberos, event logs, and other random goo. Let’s get to it. PDCE and user auth DFSR full mesh recommendations Access Denied when delegating Kerberos Clearing Event Logs en mass Where...
on
25 Feb 2011
Blog Post:
Friday Mail Sack: Newfie from the Grave Edition
NedPyle [MSFT]
Heya, Ned here again. Since this another of those catch up mail sacks, there’s plenty of interesting stuff to discuss. Today we talk NSPI, DFSR, USMT, NT 4.0 (!!!), Win2008/R2 AD upgrades, Black Hat 2010, and Irish people who live on icebergs. Faith and Begorrah! NSPI max sessions per...
on
30 Jul 2010
Blog Post:
Friday Mail Sack: Saturday Edition
NedPyle [MSFT]
Ned here. As you may have noticed, it is not Friday. You may also have noticed that this post is awesome and packed with many weeks of delayed content goodness. This notice may extend to the fact that I have no life. You notice a lot, don’t you smarty? I cannot imagine someone looking...
on
17 Jul 2010
Blog Post:
Friday Mail Sack: Walking Tall Edition
NedPyle [MSFT]
Hello folks, Ned here again. After a week in Las Colinas Texas, the blog migration, and Jonathan’s attempted coup, we are still standing. Since I’m sure your whole day has been designed around this post I won’t keep you waiting. RODC WAN down behavior DFSR and the PDCE RPC...
on
4 Jun 2010
Blog Post:
Auditing Password and Account Lockout Policy on Windows Server 2008 and R2
NedPyle [MSFT]
Ned here again. Let’s talk about auditing your domain for changes made to Password and Account Lockout policies. Frankly, it’s a real pain in the neck to figure out Password and Account Lockout auditing and there are legacy architectural decisions behind how this all works, so I’ll...
on
2 Nov 2009
Blog Post:
NTLM Blocking and You: Application Analysis and Auditing Methodologies in Windows 7
NedPyle [MSFT]
Ned here again. Windows 7 and Windows Server 2008 R2 introduce a long sought feature known as NTLM blocking. This prevents NTLM from being used for authentication. IT works in both a send or receive mode, and allows you to create exceptions. There’s currently very little documentation on this...
on
8 Oct 2009
Blog Post:
Internet Explorer behaviors with Kerberos Authentication
NedPyle [MSFT]
Hey Rob here again, I thought that I would share with you some of the things that we see where Internet Explorer Kerberos authentication fails. It is important to understand the default behavior of Internet Explorer and its support for Kerberos authentication so that you don’t start ripping...
on
22 Jun 2009
Blog Post:
SQL Bulk Insert - Access is Denied
NedPyle [MSFT]
Hey all, Mark from DS again. I have found that numerous cases have been opened where Microsoft customers are upgrading from SQL 2000 to SQL 2005. After the upgrade they were attempting to run a bulk insert statement either in the Enterprise Manager or the Management Studio application and getting an...
on
30 Apr 2009
Blog Post:
Conficker causes LSASS to consume CPU Time on Domain Controllers
NedPyle [MSFT]
Hi Gautam here, I wanted to blog about a high-impact problem we have been seeing recently. The problem has to do with LSASS consuming a lot of CPU time on your Domain Controllers (DC's). The cause of this high CPU turns out to be Conficker infected computers throwing bad passwords against the DC's...
on
16 Apr 2009
Blog Post:
“The LastLogonTimeStamp Attribute” – “What it was designed for and how it works”
NedPyle [MSFT]
Warren here. In Windows Server 2003 we introduced the lastLogontimeStamp attribute. Administrators can use the lastLogontimeStamp attribute to determine if a user or computer account has recently logged onto the domain. Using this information administrators can then review the accounts identified and...
on
15 Apr 2009
Blog Post:
How to Hide User Information When Computer is Locked
NedPyle [MSFT]
Hi, this is Amit from the Directory Services team and I am going to discuss a Group Policy setting which is now available in XP SP3 & 2003 SP2. Whenever we logon to a Windows workstation, we always see a previously logged on user; we might want to remove that because of Security Reasons. We already...
on
6 Feb 2009
Blog Post:
Addendum: Making the DelegConfig website work on IIS 7
NedPyle [MSFT]
Hi All Rob here again. I thought I would take the time today and expand upon the Kerberos Delegation website blog to show how you can use the web site on IIS 7. Actually, Ned beat me up pretty badly for not showing how to set the site up on IIS 7 [ I sure did. Rob’s revenge was to make a blog post...
on
26 Jan 2009
Blog Post:
Fun with the Kerberos Delegation Web Site
Craig Landis
Hi, Rob here. First I want to thank you guys for reading and participating in our blogging efforts. I had one of you e-mail us and ask about the web site I used in the Kerberos Authentication Troubleshooting blogs and if they could get a copy of it. The web site was created by our IIS support counterparts...
on
25 Nov 2008
Page 1 of 2 (34 items)
1
2