Sign in
TechNet Blogs
Technet Blog Images
More ...
Browse by Tags
TechNet Blogs
>
Ask the Directory Services Team
>
All Tags
>
rob greene
Server & Tools Blogs
>
Server & Management Blogs
>
Ask the Directory Services Team
All About Windows Server
Windows Server
Windows Server Essentials Blog
Building Clouds
Partner & Customer Solutions
Server & Cloud
Ask The
Performance Team
Ask Premier Field Engineering
Ask the Core Team
Cloud & Datacenter Management
The System Center Team Blog
System Center Virtual Machine Manager
System Center Service Manager
System Center Operations Manager
System Center Data Protection Manager
System Center Orchestrator
Partner & Customer Solutions
Client Management
System Center Configuration Manager
System Center Service Manager
MDOP
Malware Protection Center
Windows Intune
SUS
Partner and Customer Solutions
Virtualization, VDI & Remote Desktop
Virtualization Team Blog
Ben Armstrong’s Virtualization Blog
Jose Barreto Blog on Hyper-V
Partner & Customer Solutions
Remote Desktop Services
Windows Multipoint Server
Ask the Core Team on Hyper-V
File & Storage & High Availability
File & Storage
Jose Barreto
Partner & Customer Solutions
Ask the Core Team on Failover Cluster
Clustering & High Availability
Windows Server Management
PowerShell
Hey Scripting Guy (PowerShell)
Server Manager
Group Policy
Networking
Identity & Access
Ask Directory Services
Active Directory
Microsoft Leadership
Brad Anderson - In the Cloud
Ask the Directory Services Team
Microsoft's official enterprise support blog for AD DS and more
Live Now on Server & Tools Blogs
Subscribe
Comments
Contact
Menu
Blog Home
Atom
Translate this page
Powered by
Microsoft® Translator
Recent Posts
We're back. Did you miss us?
Posted
1 day ago
by
David Beach - MSFT
6
Comments
AD FS 2.0 Claims Rule Language Part 2
Posted
11 days ago
by
Jonathan Stephens, MSFT
0
Comments
Circle Back to Loopback
Posted
3 months ago
by
Jonathan Stephens, MSFT
23
Comments
Distributed File System Consolidation of a Standalone Namespace to a Domain-Based Namespace
Posted
3 months ago
by
Jonathan Stephens, MSFT
1
Comments
Tags
Authentication
Bob Drake
CEP/CES
Certificates
Cluster
Craig Landis
Dave Fisher
David Beach
David Everett
DFSR
Fabian Muller
infrastructure
Jason Fournerat
Jonathan Stephens
Kerberos
Mail Sack
Mark Ramey
Mike Stephens
Ned Pyle
Other Blogs
PKI
Security
Silly Rabbit
USMT
Windows Server 2008 R2
Archives
Archives
May 2013
(2)
February 2013
(2)
January 2013
(3)
November 2012
(2)
October 2012
(3)
September 2012
(7)
August 2012
(8)
July 2012
(8)
June 2012
(5)
May 2012
(6)
April 2012
(8)
March 2012
(3)
February 2012
(4)
January 2012
(8)
December 2011
(5)
November 2011
(2)
October 2011
(4)
September 2011
(10)
August 2011
(30)
July 2011
(9)
June 2011
(11)
May 2011
(12)
April 2011
(18)
March 2011
(7)
February 2011
(14)
January 2011
(10)
December 2010
(2)
November 2010
(11)
October 2010
(10)
September 2010
(16)
August 2010
(17)
July 2010
(10)
June 2010
(12)
May 2010
(14)
April 2010
(15)
March 2010
(16)
February 2010
(18)
January 2010
(9)
December 2009
(11)
November 2009
(9)
October 2009
(19)
September 2009
(16)
August 2009
(17)
July 2009
(11)
June 2009
(25)
May 2009
(15)
April 2009
(37)
March 2009
(22)
February 2009
(14)
January 2009
(19)
December 2008
(9)
November 2008
(18)
October 2008
(15)
September 2008
(12)
August 2008
(7)
July 2008
(7)
June 2008
(7)
May 2008
(7)
April 2008
(10)
March 2008
(11)
February 2008
(7)
January 2008
(12)
December 2007
(2)
November 2007
(5)
October 2007
(4)
September 2007
(2)
August 2007
(6)
More
▼
Less
▲
Tagged Content List
Blog Post:
Windows PowerShell remoting and delegating user credentials
NedPyle [MSFT]
Hey all Rob Greene here again. Yeah, I know, it’s been a while since I’ve written anything for you good people of the Internet. I recently had an interesting issue with the Active Directory Web Services and the Active Directory Windows PowerShell 2.0 modules in Windows 7 and Windows Server...
on
2 Aug 2012
Blog Post:
RSA Key Blocking is Coming
NedPyle [MSFT]
Hey all, Ned here again with one of my rare public service announcement posts: In August 2012, Microsoft will issue a software update for Windows XP, Windows Server 2003, Windows Server 2003 R2, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2. The update will block the use...
on
16 Jul 2012
Blog Post:
Friday Mail Sack: Drop the dope, hippy! edition
NedPyle [MSFT]
Hi all, Ned here again with an actual back to back mail sack. This week we discuss: Running out of USNs and Versions DFSR RDC LAN WAN FWIW AOK NPS and dotted NetBIOS domain names USMT and the case of the failing sourcepriority Revisiting NIC teaming Weird DFSR files MaxConcurrentAPI...
on
20 Apr 2012
Blog Post:
Friday Mail Sack: Best Post This Year Edition
NedPyle [MSFT]
Hi folks, Ned here and welcoming you to 2012 with a new Friday Mail Sack. Catching up from our holiday hiatus, today we talk about: Disabling Administrative Shares Making Get-ADDomainController useful’er Kerberos group bloat USMT moving profiles back from other disks The DFSR...
on
6 Jan 2012
Blog Post:
Friday Mail Sack: Guest Reply Edition
NedPyle [MSFT]
Hi folks, Ned here again. This week we talk: CA migration from 1 to 2 tier ADAM/ADLDS P2V ABC 123 Managing AGPM security filters Multiple IIS App pools and Kerberos AGPM multi-domain comparison ADUC domain password weirdness DFSR deletion conflict handling Stale account deletion...
on
11 Nov 2011
Blog Post:
AskDS is 12,614,400,000,000,000 shakes old
NedPyle [MSFT]
It’s been four years and 591 posts since AskDS reached critical mass. You’d hope our party would look like this: But it’s more likely to be: Without you, we’d be another of those sites that glow red hot, go supernova, then collapse into a white dwarf . We really appreciate your comments, questions...
on
9 Aug 2011
Blog Post:
USMT and Converting Registry Data Types
NedPyle [MSFT]
Heya folks, Ned here again. Microsoft is legendary for its backwards compatibility. No other operating system family can claim to support as much older software and settings as Windows - heck, companies like Apple seem to proudly cut "legacy" support after a few years and spin it like it's a positive...
on
1 Aug 2011
Blog Post:
How to setup a federation with Automatic Data Processing, Inc (ADP) using ADFS 2.0
NedPyle [MSFT]
Hey all, Rob Greene here again. We have been getting calls recently on how to use ADFS 2.0 to federate with ADP , so today I explain how. Disclaimer: If you have problems with connecting to ADP, your first call should be to them. If after talking with ADP you need further assistance you then open...
on
31 Mar 2011
Blog Post:
iPad / iPhone Certificate Issuance
Jonathan Stephens, MSFT
Hey all, Rob here again. It’s been a while since I have written a blog post, and this one was too interesting to pass up. I recently worked a case around deploying certificates to Apple iPhones and iPads to secure their network communications. The investigation uncovered that Apple devices can...
on
22 Nov 2010
Blog Post:
AskDS is 0.03 Centuries Old Today
NedPyle [MSFT]
Three years ago today the AskDS site published its first post and had its first commenter . In the meantime we’ve created 455 articles and we’re now ranked 6th in all of TechNet’s blogs, behind AskPerf , Office2010 , MarkRussinovich , SBS , and HeyScriptingGuy . That’s a pretty amazing group to be lumped...
on
9 Aug 2010
Blog Post:
Enabling CEP and CES for enrolling non-domain joined computers for certificates
Jonathan Stephens, MSFT
Hey all, Rob here again. I thought I would expand upon my last blog describing Certificate Enrollment Web Services by covering some of the different configurations that are possible. As a refresher, Certificate Enrollment Policy and Certificate Enrollment Services abstracts certificate Policy and...
on
25 May 2010
Blog Post:
Certificate Enrollment Web Services
NedPyle [MSFT]
Hey everyone, Rob here again. With the release of Windows Server 2008 R2 and Windows 7 we have added new methods of enrolling for certificates: Certificate Enrollment Policy (CEP) and Certificate Enrollment Service (CES). CEP is a web service that enables users and computers to obtain certificate enrollment...
on
1 Feb 2010
Blog Post:
Clustered Certification Authority maintenance tasks
NedPyle [MSFT]
Hi all Rob Greene here again. I thought I would share with you how to do some common tasks with a Windows Server 2008 clustered Certification Authority (CA). When the CA is clustered there are definitely different steps that need to be taken when you: Make a change to the behavior of the CA by...
on
7 Jan 2010
Blog Post:
Extended Validation support for websites using internal certificates
NedPyle [MSFT]
Hey all Rob here again. One feature that that is new with Windows Server 2008R2 / Windows 7 is the ability to configure your internal certification authority hierarchy in order to issue certificates that can show as Extended Validation certificates. So for those of you who do not know, this means...
on
14 Aug 2009
Blog Post:
Internet Explorer behaviors with Kerberos Authentication
NedPyle [MSFT]
Hey Rob here again, I thought that I would share with you some of the things that we see where Internet Explorer Kerberos authentication fails. It is important to understand the default behavior of Internet Explorer and its support for Kerberos authentication so that you don’t start ripping...
on
22 Jun 2009
Blog Post:
Potential for Kerberos Issues When Using a Cisco VPN/ASA with Win2003 or later DC’s
NedPyle [MSFT]
Hey everyone, Rob Greene here back after a long hiatus from blogging. I had an interesting case come through that I thought many of you IT pros would be interested in. Background The customer had an issue with using Cisco VPN and Cisco ASA concentrators and authenticating the user with Kerberos...
on
18 Jun 2009
Blog Post:
How to configure the Windows Server 2008 CA Web Enrollment Proxy
NedPyle [MSFT]
Hi all, Rob here again. I had a case recently where the customer wanted to have the Windows Server 2008 Certificate Authority website loaded on another machine. For those of you that do not know, you can install the Windows Server 2008 CA web site pages on an alternate server from the CA. One reason...
on
22 Apr 2009
Blog Post:
Addendum: Making the DelegConfig website work on IIS 7
NedPyle [MSFT]
Hi All Rob here again. I thought I would take the time today and expand upon the Kerberos Delegation website blog to show how you can use the web site on IIS 7. Actually, Ned beat me up pretty badly for not showing how to set the site up on IIS 7 [ I sure did. Rob’s revenge was to make a blog post...
on
26 Jan 2009
Blog Post:
Fun with the Kerberos Delegation Web Site
Craig Landis
Hi, Rob here. First I want to thank you guys for reading and participating in our blogging efforts. I had one of you e-mail us and ask about the web site I used in the Kerberos Authentication Troubleshooting blogs and if they could get a copy of it. The web site was created by our IIS support counterparts...
on
25 Nov 2008
Blog Post:
Domain Locator Across a Forest Trust
NedPyle [MSFT]
Rob and Mike here. We're asked, many times, why a user does not authenticate against a local domain controller in the same site when logging on across a forest. We've setup the most common scenario to help explain how domain locator works for user logons across a forest. Scenario Let's explain...
on
24 Sep 2008
Blog Post:
Vista’s MoveUser.exe replacement
NedPyle [MSFT]
Hi Rob here again. I recently had a customer that needed the functionality of MoveUser.exe from the Windows 2000 Resource Kit available in Windows Vista. The customer had quite a few Windows Vista machines that were not joined to the domain but were now migrating to Active Directory. For their own business...
on
9 Sep 2008
Blog Post:
PolicyMaker stops working after installing Windows XP SP3
NedPyle [MSFT]
Hi this is Rob again. We had a couple cases recently where PolicyMaker settings were not applying to computer and users after installing Windows XP Service Pack 3. We found that PolicyMaker client-side extensions (CSE) are not registered after installing Service Pack 3. Examine the following location...
on
30 Jul 2008
Blog Post:
Automatic creation of user folders for home, roaming profile and redirected folders.
NedPyle [MSFT]
Hi Rob here again. Periodically we’re asked "what is the best way to auto-create home, roaming profile, and folder redirection folders instead of Administrators creating and configuring the NTFS permissions manually?" The techniques in this post requires you to use the environment variable %USERNAME...
on
30 Jun 2008
Blog Post:
Kerberos Authentication problems – Service Principal Name (SPN) issues - Part 3
NedPyle [MSFT]
Rob here. Now we have seen what it looks like when there is no Service Principal Name defined , and when the Service Principal Name is not unique in the forest. We will now cover what things look like when the Service Principal Name is NOT added to the correct account. We are still using the same...
on
11 Jun 2008
Blog Post:
Kerberos Authentication problems – Service Principal Name (SPN) issues - Part 2
NedPyle [MSFT]
Rob here. So, we saw in Part 1 what kind of error you could expect when there is no Service Principal Name defined for the Kerberos ticket the application is requesting. The next part I would like to show you is what might be the error message you would get if there were multiple accounts with the same...
on
9 Jun 2008
Page 1 of 2 (28 items)
1
2