Sign in
TechNet Blogs
Technet Blog Images
More ...
Browse by Tags
TechNet Blogs
>
Ask the Directory Services Team
>
All Tags
>
security
Server & Tools Blogs
>
Server & Management Blogs
>
Ask the Directory Services Team
All About Windows Server
Windows Server
Windows Server Essentials Blog
Building Clouds
Partner & Customer Solutions
Server & Cloud
Ask The
Performance Team
Ask Premier Field Engineering
Ask the Core Team
Cloud & Datacenter Management
The System Center Team Blog
System Center Virtual Machine Manager
System Center Service Manager
System Center Operations Manager
System Center Data Protection Manager
System Center Orchestrator
Partner & Customer Solutions
Client Management
System Center Configuration Manager
System Center Service Manager
MDOP
Malware Protection Center
Windows Intune
SUS
Partner and Customer Solutions
Virtualization, VDI & Remote Desktop
Virtualization Team Blog
Ben Armstrong’s Virtualization Blog
Jose Barreto Blog on Hyper-V
Partner & Customer Solutions
Remote Desktop Services
Windows Multipoint Server
Ask the Core Team on Hyper-V
File & Storage & High Availability
File & Storage
Jose Barreto
Partner & Customer Solutions
Ask the Core Team on Failover Cluster
Clustering & High Availability
Windows Server Management
PowerShell
Hey Scripting Guy (PowerShell)
Server Manager
Group Policy
Networking
Identity & Access
Ask Directory Services
Active Directory
Microsoft Leadership
Brad Anderson - In the Cloud
Ask the Directory Services Team
Microsoft's official enterprise support blog for AD DS and more
Live Now on Server & Tools Blogs
Subscribe
Comments
Contact
Menu
Blog Home
Atom
Translate this page
Powered by
Microsoft® Translator
Recent Posts
Back to the Loopback: Troubleshooting Group Policy loopback processing, Part 2
Posted
2 days ago
by
David Beach - MSFT
1
Comments
We're back. Did you miss us?
Posted
6 days ago
by
David Beach - MSFT
18
Comments
AD FS 2.0 Claims Rule Language Part 2
Posted
17 days ago
by
Jonathan Stephens, MSFT
0
Comments
Circle Back to Loopback
Posted
3 months ago
by
Jonathan Stephens, MSFT
23
Comments
Tags
AD Replication
audit
Authentication
Authorization
Certificates
DFSR
group policy
infrastructure
Jonathan Stephens
Kerberos
LDAP
Mail Sack
Ned Pyle
network
NTLM
Other Blogs
PowerShell
RPC
Silly Rabbit
SYSVOL
USMT
Windows 7
Windows 8
Windows Server 2008
Windows Server 2008 R2
Archives
Archives
May 2013
(3)
February 2013
(2)
January 2013
(3)
November 2012
(2)
October 2012
(3)
September 2012
(7)
August 2012
(8)
July 2012
(8)
June 2012
(5)
May 2012
(6)
April 2012
(8)
March 2012
(3)
February 2012
(4)
January 2012
(8)
December 2011
(5)
November 2011
(2)
October 2011
(4)
September 2011
(10)
August 2011
(30)
July 2011
(9)
June 2011
(11)
May 2011
(12)
April 2011
(18)
March 2011
(7)
February 2011
(14)
January 2011
(10)
December 2010
(2)
November 2010
(11)
October 2010
(10)
September 2010
(16)
August 2010
(17)
July 2010
(10)
June 2010
(12)
May 2010
(14)
April 2010
(15)
March 2010
(16)
February 2010
(18)
January 2010
(9)
December 2009
(11)
November 2009
(9)
October 2009
(19)
September 2009
(16)
August 2009
(17)
July 2009
(11)
June 2009
(25)
May 2009
(15)
April 2009
(37)
March 2009
(22)
February 2009
(14)
January 2009
(19)
December 2008
(9)
November 2008
(18)
October 2008
(15)
September 2008
(12)
August 2008
(7)
July 2008
(7)
June 2008
(7)
May 2008
(7)
April 2008
(10)
March 2008
(11)
February 2008
(7)
January 2008
(12)
December 2007
(2)
November 2007
(5)
October 2007
(4)
September 2007
(2)
August 2007
(6)
More
▼
Less
▲
Tagged Content List
Blog Post:
Monthly Mail Sack: Yes, I Finally Admit It Edition
NedPyle [MSFT]
Heya folks, Ned here again. Rather than continue the lie that this series comes out every Friday like it once did, I am taking the corporate approach and rebranding the mail sack. Maybe we’ll have the occasional Collector’s Edition versions. This week month, I answer your questions on: The semi-myth...
on
24 Aug 2012
Blog Post:
Managing RID Issuance in Windows Server 2012
NedPyle [MSFT]
Hi all, Ned here again to talk further about managing your RID pool . By default, a domain has capacity for roughly one billion security principals, such as users, security groups, managed service accounts, and computers. If you run out, you can’t create any more. There aren’t any domains with that many...
on
10 Aug 2012
Blog Post:
Windows PowerShell remoting and delegating user credentials
NedPyle [MSFT]
Hey all Rob Greene here again. Yeah, I know, it’s been a while since I’ve written anything for you good people of the Internet. I recently had an interesting issue with the Active Directory Web Services and the Active Directory Windows PowerShell 2.0 modules in Windows 7 and Windows Server...
on
2 Aug 2012
Blog Post:
Kerberos errors in network captures
NedPyle [MSFT]
Hi guys, Joji Oshima here again. When troubleshooting Kerberos authentication issues, a network capture is one of the best pieces of data to collect. When you review the capture, you may see various Kerberos errors but you may not know what they mean or if they are real problems. In this post, I’m going...
on
27 Jul 2012
Blog Post:
Dynamic Access Control and ISV Goodness
NedPyle [MSFT]
Hey all, Ned here with a quickie: Robert Paige just published an interesting read on Windows Server 2012 Dynamic Access Control over at the Windows Server blog: http://blogs.technet.com/b/wincat/archive/2012/07/20/diving-deeper-into-windows-server-2012-dynamic-access-control.aspx It highlights the work...
on
20 Jul 2012
Blog Post:
Standardizing Dynamic Access Control Configuration – Exporting and Importing Dynamic Access Control objects between Active Directory Forests
NedPyle [MSFT]
[This is a guest post from Joe Isenhour, a Senior Program Manager in Windows Server. You may remember him from his previous ADFS claims rule post . If you are not yet up to speed on the DAC security suite in Windows Server 2012, I recommend our own Mike Stephens’ treatise Understand and Troubleshoot...
on
18 Jul 2012
Blog Post:
RSA Key Blocking is Coming
NedPyle [MSFT]
Hey all, Ned here again with one of my rare public service announcement posts: In August 2012, Microsoft will issue a software update for Windows XP, Windows Server 2003, Windows Server 2003 R2, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2. The update will block the use...
on
16 Jul 2012
Blog Post:
Dynamic Access Control intro on Windows Server blog
NedPyle [MSFT]
Hey all, Ned here with a quick “xerox” post: the Dynamic Access Control developers have released a good intro on their octo-feature through the Windows Server Blog: Introduction to Windows Server 2012 Dynamic Access Control It’s written by Nir Ben-Zvi, a Program Manager on the Windows Server development...
on
22 May 2012
Blog Post:
Saturday Mail Sack: Because it turns out, Friday night was alright for fighting edition
NedPyle [MSFT]
Hello all, Ned here again with our first mail sack in a couple months. I have enough content built up here that I actually created multiple posts, which means I can personally guarantee there will be another one next week. Unless there isn't! Today we answer your questions around: Detecting...
on
14 Apr 2012
Blog Post:
Purging Old NT Security Protocols
NedPyle [MSFT]
Hi folks, Ned here again (with some friends ). Everyone knows that Kerberos is Microsoft’s preeminent security protocol and that NTLM is both inefficient and, in some iterations, not strong enough to avoid concerted attack. NTLM V2 using complex passwords stands up well to common hash cracking tools...
on
2 Feb 2012
Blog Post:
Friday Mail Sack: Carl Sandburg Edition
Jonathan Stephens, MSFT
Hi folks, Jonathan again. Ned is taking some time off visiting his old stomping grounds – the land of Mother-in-Laws and heart-breaking baseball. Or, as Sandburg put it: “ Hog Butcher for the World , Tool Maker, Stacker of Wheat, Player with Railroads and the Nation's Freight Handler;...
on
28 Jan 2012
Blog Post:
If you use Symantec Products, Read Me
NedPyle [MSFT]
Ned here again, with a public service announcement similar to the previous one we did for RSA as it implicitly affects so many Microsoft customers. Symantec has announced: Symantec can confirm that a segment of its source code has been accessed. Upon investigation of the claims made by Anonymous...
on
26 Jan 2012
Blog Post:
Friday Mail Sack: It’s a Dog’s Life Edition
NedPyle [MSFT]
Hi folks, Ned here again with some possibly interesting, occasionally entertaining, and always unsolicited Friday mail sack. This week we talk some: DNS partition absence Controlling DCDIAG event messaging Inventorying SYSVOL replication architecture Weird WMI DFSR volume paths Tightening...
on
20 Jan 2012
Blog Post:
Friday Mail Sack: Best Post This Year Edition
NedPyle [MSFT]
Hi folks, Ned here and welcoming you to 2012 with a new Friday Mail Sack. Catching up from our holiday hiatus, today we talk about: Disabling Administrative Shares Making Get-ADDomainController useful’er Kerberos group bloat USMT moving profiles back from other disks The DFSR...
on
6 Jan 2012
Blog Post:
Friday Mail Sack: They Pull Me Back in Edition
NedPyle [MSFT]
Hiya world, Ned is back with your best questions and comments. I’ve been off to teach this fall’s MCM , done Win8 stuff , and generally been slacking keeping busy; sorry for the delay in posting. That means a hefty backlog - get ready to slurp. Today we talk: Weirdness with NETDOM...
on
28 Oct 2011
Blog Post:
Friday Mail Sack: Super Slo-Mo Edition
NedPyle [MSFT]
Hello folks, Ned here again with another Mail Sack. Before I get rolling though, a quick public service announcement: Plenty of you have downloaded the Windows 8 Developer Preview and are knee-deep in the new goo . We really want your feedback, so if you have comments, please use one of the following...
on
30 Sep 2011
Blog Post:
Windows 8 for the IT Pro: The New Plumbing
NedPyle [MSFT]
Hi folks, Ned coming to you from the secret underground redoubt, where the cable is out, the wife is at grad school , and the dogs are napping as autumn finally reaches North Carolina. I’m not a fan of blog posts that only aggregate links and don’t offer original thought. Today I make...
on
17 Sep 2011
Blog Post:
Is this horse dead yet: NTLM Bottlenecks and the RPC runtime
NedPyle [MSFT]
Hello again, this is guest author Herbert from Germany. It’s harder to let go of old components and protocols than dropping old habits. But, I’m falling back to an old habit myself…there goes the New Year resolution. Quite recently we were faced with a new aspect of an old story...
on
15 Sep 2011
Blog Post:
Managing RID Pool Depletion
NedPyle [MSFT]
Hiya folks, Ned here again. When interviewing a potential support engineer at Microsoft, we usually start with a softball question like “what are the five FSMO roles?” Everyone nails that. Then we ask what each role does. Their face scrunches a bit and they get less assured. “The RID Master… hands out...
on
12 Sep 2011
Blog Post:
The Security Log Haystack – Event Forwarding and You
NedPyle [MSFT]
Hi. This is your guest writer Mark Renoden . I’m a Senior Premier Field Engineer based in Sydney, Australia and I’m going to talk to you about the use of Event Forwarding to collect security events. This is particularly useful when: You have specific events you’re looking for...
on
29 Aug 2011
Blog Post:
Friday Mail Sack: Beard-Seconds Edition
NedPyle [MSFT]
Hiya folks, Ned here again. This week we talk: DC DNS A Records and Web Servers Forwarding Security event log subscriptions Domain password filters Auditing NTLM vs NTLMv2 on Win2003 Programmatically determining if UNC is DFS namespace DFSR and Excel Shared Workbooks DFS, DC,...
on
5 Aug 2011
Blog Post:
Troubleshooting SID translation failures from the obvious to the not so obvious
NedPyle [MSFT]
Hi guys, Joji Oshima here with my first post. A common problem we see is SID translation failure. The problem usually occurs when you add users or groups from a trusted domain into your domain local groups. What you hope to see is the friendly names of the users, and their domain: Unfortunately...
on
28 Jul 2011
Blog Post:
Friday Mail Sack: Wahoo Edition
NedPyle [MSFT]
Hi folks, Ned here again. This week we talk GUI metadata cleanup, your useless manager (attributes), USMT abandonment and weight issues, the meaning of the DFSR nothing state, and the usual “other stuff.” Metadata cleanup when moving DCs The Manager and ManagedBy attributes Overriding...
on
24 Jun 2011
Blog Post:
Friday Mail Sack: Gargamel Edition
NedPyle [MSFT]
Hi folks, Ned here again. This week we talk about 10 reasons not to use list object access dsheuristics, USMT trivia nuggets, poor man’s DFSDIAG, how to get network captures without installing a network capture tool, and some other random goo. Oh yeah, and friggin’ Smurfs. The downsides...
on
17 Jun 2011
Blog Post:
Friday Mail Sack: LeBron is not Jordan Edition
NedPyle [MSFT]
Hi folks, Ned here again. Today we discuss trusts rules around domain names, attribute uniqueness, the fattest domains we’ve ever seen, USMT data-only migrations, kicking FRS while it’s down, and a few amusing side topics. Scottie, don’t be that way. Go Mavs. Creating trusts...
on
10 Jun 2011
Page 1 of 3 (56 items)
1
2
3