<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Ask the Directory Services Team</title><link>http://blogs.technet.com/b/askds/</link><description>Microsoft&amp;#39;s official Enterprise Platform Support DS blog</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>Do not skip the latest B8 boot post</title><link>http://blogs.technet.com/b/askds/archive/2012/05/23/do-not-skip-the-latest-b8-boot-post.aspx</link><pubDate>Wed, 23 May 2012 19:59:03 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3499740</guid><dc:creator>NedPyle [MSFT]</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/rsscomments.aspx?WeblogPostID=3499740</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/commentapi.aspx?WeblogPostID=3499740</wfw:comment><comments>http://blogs.technet.com/b/askds/archive/2012/05/23/do-not-skip-the-latest-b8-boot-post.aspx#comments</comments><description>&lt;p&gt;Hey all, &lt;a href="http://blogs.technet.com/b/askds/archive/tags/Ned+Pyle/"&gt;Ned&lt;/a&gt; here. The &lt;a href="http://blogs.msdn.com/b/b8/"&gt;Building Windows 8 blog&lt;/a&gt; recently posted a new article from Chris Clark that you might have passed over due to the title, which sounds like another article on boot performance:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;a href="http://blogs.msdn.com/b/b8/archive/2012/05/22/designing-for-pcs-that-boot-faster-than-ever-before.aspx"&gt;Designing for PCs that boot faster than ever before&lt;/a&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;em&gt;Don’t skip it!&lt;/em&gt; A more descriptive title would have been “&lt;strong&gt;The F8 and F2 boot menus are gone on Windows 8 and you need to read this post to do your job, IT Pro.&lt;/strong&gt;” &lt;/p&gt;  &lt;p&gt;Windows 8 is designed to run on hardware that boots too fast for a human to react through a keyboard, requiring new methods to get to a boot menu. Note down what the article describes so that when you need to &lt;a href="http://blogs.technet.com/b/askds/archive/2012/05/01/new-slow-logon-slow-boot-troubleshooting-content.aspx"&gt;troubleshoot a slow logon or slow boot&lt;/a&gt;, you can get into Safe Mode and other diagnostic states (&lt;strong&gt;PC Settings&lt;/strong&gt;, &lt;strong&gt;shift+restart&lt;/strong&gt;, &lt;strong&gt;shutdown.exe /o /r&lt;/strong&gt;, &lt;strong&gt;msconfig.exe&lt;/strong&gt;). All of these apply to Windows 8 Developer Preview and Windows Server “8” Beta, which you can get your hot little hands on right now.&lt;/p&gt;  &lt;p&gt;It is also important to note – and not mentioned in the article – that on Windows Server 2012 only, &lt;em&gt;you can still use &lt;strong&gt;F8&lt;/strong&gt;&lt;/em&gt;. The new boot menu system eventually gets you back to the familiar menu with your favorite DSRM option too, so don’t feel like we’re making you relearn everything:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/5807.image_5F00_4355A428.png"&gt;&lt;img title="image" style="display: inline; background-image: none;" border="0" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/2654.image_5F00_thumb_5F00_427D3E3E.png" width="464" height="362" /&gt;&lt;/a&gt;&amp;#160;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Also not mentioned but preemptively answered now: while &lt;strong&gt;shutdown /o &lt;/strong&gt;was updated to support the new boot menus, the &lt;strong&gt;restart-computer&lt;/strong&gt; Windows PowerShell cmdlet was not.&lt;/p&gt;  &lt;p&gt;- Ned “Doc Martens” Pyle&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3499740" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/askds/archive/tags/Ned+Pyle/">Ned Pyle</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Windows+8/">Windows 8</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Windows+8+Developer+Preview/">Windows 8 Developer Preview</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Windows+Server+_2600_quot_3B00_8_2600_quot_3B00_+Beta/">Windows Server &amp;quot;8&amp;quot; Beta</category><category domain="http://blogs.technet.com/b/askds/archive/tags/windows+server+2012/">windows server 2012</category></item><item><title>Dynamic Access Control intro on Windows Server blog</title><link>http://blogs.technet.com/b/askds/archive/2012/05/22/dynamic-access-control-intro-on-windows-server-blog.aspx</link><pubDate>Tue, 22 May 2012 20:16:43 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3499357</guid><dc:creator>NedPyle [MSFT]</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/rsscomments.aspx?WeblogPostID=3499357</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/commentapi.aspx?WeblogPostID=3499357</wfw:comment><comments>http://blogs.technet.com/b/askds/archive/2012/05/22/dynamic-access-control-intro-on-windows-server-blog.aspx#comments</comments><description>&lt;p&gt;Hey all, Ned here with a quick “xerox” post: the Dynamic Access Control developers have released a good intro on their octo-feature through the Windows Server Blog:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;a href="http://blogs.technet.com/b/windowsserver/archive/2012/05/22/introduction-to-windows-server-2012-dynamic-access-control.aspx"&gt;Introduction to Windows Server 2012 Dynamic Access Control&lt;/a&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;It’s written by Nir Ben-Zvi, a Program Manager on the Windows Server development team. If you’re unfamiliar with DAC, this is a great first read. Here’s a quote:&lt;/p&gt;  &lt;p&gt;&lt;em&gt;These focus areas were then translated to a set of Windows capabilities that enable data compliance in partner and Windows-based solutions.&lt;/em&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;em&gt;Add the ability to configure Central Access and Audit Policies in Active Directory. These policies are based on conditional expressions that take into account the following so that organizations can translate business requirements to efficient policy enforcement and considerably reduce the number of security groups needed for access control: &lt;/em&gt;      &lt;ul&gt;       &lt;li&gt;&lt;em&gt;&lt;strong&gt;Who&lt;/strong&gt; the &lt;strong&gt;user&lt;/strong&gt; is &lt;/em&gt;&lt;/li&gt;        &lt;li&gt;&lt;em&gt;&lt;strong&gt;What device&lt;/strong&gt; they are using, and &lt;/em&gt;&lt;/li&gt;        &lt;li&gt;&lt;em&gt;&lt;strong&gt;What data&lt;/strong&gt; is being accessed&lt;/em&gt;&lt;/li&gt;     &lt;/ul&gt;   &lt;/li&gt;    &lt;li&gt;&lt;em&gt;Integrate claims into Windows authentication (Kerberos) so that users and devices can be described not only by the security groups they belong to, but also by claims such as: “User is from the Finance department” and “User’s security clearance is High” &lt;/em&gt;&lt;/li&gt;    &lt;li&gt;&lt;em&gt;Enhance the File Classification Infrastructure to allow business owners and users to identify (tag) their data so that IT administrators are able to target policies based on this tagging. This ability works in parallel with the ability of the File Classification Infrastructure to automatically classify files based on content or any other characteristics &lt;/em&gt;&lt;/li&gt;    &lt;li&gt;&lt;em&gt;Integrate Rights Management Services to automatically protect (encrypt) sensitive information on servers so that even when the information leaves the server, it is still protected.&lt;/em&gt;&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/b/windowsserver/archive/2012/05/22/introduction-to-windows-server-2012-dynamic-access-control.aspx"&gt;Click to the read the rest&lt;/a&gt;. &lt;/p&gt;  &lt;p&gt;If you are looking for more depth and “how it works”, check out our very own Mike Stephens’ downloadable whitepaper:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;a href="http://www.microsoft.com/en-us/download/details.aspx?id=29023"&gt;Understand and Troubleshoot Dynamic Access Control in Windows Server &amp;quot;8&amp;quot; Beta&lt;/a&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Until next time,&lt;/p&gt;  &lt;p&gt;Ned “10 cent copies” Pyle&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3499357" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/askds/archive/tags/Security/">Security</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Ned+Pyle/">Ned Pyle</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Windows+8/">Windows 8</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Windows+Server+_2600_quot_3B00_8_2600_quot_3B00_+Beta/">Windows Server &amp;quot;8&amp;quot; Beta</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Dynamic+Access+Control/">Dynamic Access Control</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Central+Access+Policy/">Central Access Policy</category><category domain="http://blogs.technet.com/b/askds/archive/tags/windows+server+2012/">windows server 2012</category><category domain="http://blogs.technet.com/b/askds/archive/tags/DAC/">DAC</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Central+Access+Policies/">Central Access Policies</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Central+Audit+Policies/">Central Audit Policies</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Nir+Ben_2D00_Zvi/">Nir Ben-Zvi</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Claims/">Claims</category></item><item><title>Friday Mail Sack: Mothers day pfffft… when is son’s day?</title><link>http://blogs.technet.com/b/askds/archive/2012/05/11/friday-mail-sack-mothers-day-pfffft-when-is-son-s-day.aspx</link><pubDate>Sat, 12 May 2012 00:42:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3497578</guid><dc:creator>NedPyle [MSFT]</dc:creator><slash:comments>7</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/rsscomments.aspx?WeblogPostID=3497578</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/commentapi.aspx?WeblogPostID=3497578</wfw:comment><comments>http://blogs.technet.com/b/askds/archive/2012/05/11/friday-mail-sack-mothers-day-pfffft-when-is-son-s-day.aspx#comments</comments><description>&lt;p&gt;Hi folks, &lt;a href="http://blogs.technet.com/b/askds/archive/tags/ned+pyle/"&gt;Ned&lt;/a&gt; here again. It&amp;rsquo;s been a little while since the last sack, but I have a good excuse: I just finished writing a poop ton of Windows Server 2012 depth training that our support folks around the world will use to make your lives easier (someday). If I ever open MS Word again it will be too soon, and I&amp;rsquo;ll probably say the same thing about PowerPoint by June.&lt;/p&gt;
&lt;p&gt;Anyhoo, let&amp;rsquo;s get to it. This week we talk about:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#invoke"&gt;Invoke-command and the ActiveDirectory Windows PowerShell module&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#hardlink"&gt;The mysterious case of USMT hardlink running out of disk space&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#robocopy"&gt;Pre-seeding DFSR with robocopy /B&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#blank"&gt;Blank client names in auditing&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#modernapps"&gt;USMT and Windows 8 modern app breakage&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ocsp"&gt;OCSP scripting&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#wds"&gt;WDS + DFSN = SUX&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#invalid"&gt;USMT hates files ending with dots or spaces&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#other"&gt;Other stuff&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h1&gt;&lt;a name="invoke"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;Is it possible to use any ActiveDirectory module cmdlets through invoke-command against a remote non-DC where the module is installed? It always blows up for me as it tries to &amp;ldquo;locally&amp;rdquo; (remotely) use the non-existent ADWS with error &amp;ldquo;Unable to contact the server. This may be because the server does not exist, it is currently down, or it does not have the active directory web services running&amp;rdquo;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/7433.image_5F00_1229A53C.png"&gt;&lt;img width="579" height="131" title="image" style="display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/4774.image_5F00_thumb_5F00_77E93C17.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;Yes, but you have to ignore that terribly misleading error and put your thinking cap on: the problem is your &lt;em&gt;credentials&lt;/em&gt;. When you &lt;strong&gt;invoke-command&lt;/strong&gt;, you make the remote server run the local PowerShell on your behalf. In this case that remote command has to go off-box to yet &lt;em&gt;another &lt;/em&gt;remote server &amp;ndash; a DC running ADWS. This means a multi-hop credential scenario. Provide &lt;strong&gt;&amp;ndash;credential (get-credential)&lt;/strong&gt; to your called cmdlets inside the curly braces and it&amp;rsquo;ll work fine.&lt;/p&gt;
&lt;h1&gt;&lt;a name="hardlink"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;We are using a USMT &lt;a href="http://technet.microsoft.com/en-us/library/dd939980(v=WS.10).aspx"&gt;/hardlink&lt;/a&gt; migration to preserve disk space and increase performance. However, performance is crazy slow and we&amp;rsquo;re actually running out of disk space on some machines that have very large files like PSTs. My scanstate log shows:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;Error [0x000000] Write error 112 for C:\users\ned\Desktop [somebig.pst]. &lt;span style="background-color: #ffff00;"&gt;Windows error 112 description: There is not enough space on the disk.[gle=0x00000070] &lt;/span&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;Error [0x080000] &lt;span style="background-color: #ffff00;"&gt;Error 2147942512&lt;/span&gt; while gathering object C:\users\ned\Desktop\somebig.pst. Shell application requested abort![gle=0x00000070]&lt;/span&gt; &lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;These files are encrypted and you are using &lt;strong&gt;/efs:copyraw&lt;/strong&gt; instead of&lt;strong&gt; /efs:hardlink&lt;/strong&gt;. Encrypted files are copied into the store whole instead of hardlink'ing, unless you specify &lt;strong&gt;/efs:hardlink&lt;/strong&gt;. If you had not included /efs, this file would have failed with, "File &lt;em&gt;X &lt;/em&gt;is encrypted. Use the /efs option to specify a different way to handle this file".&lt;/p&gt;
&lt;p&gt;Yes, I realize that we should probably just require that option. But think of all the billable hours we just gave you!&lt;/p&gt;
&lt;h1&gt;&lt;a name="robocopy"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;I was using your &lt;a href="http://blogs.technet.com/b/askds/archive/2010/09/07/replacing-dfsr-member-hardware-or-os-part-2-pre-seeding.aspx"&gt;DFSR pre-seeding post&lt;/a&gt; and am finding that &lt;strong&gt;robocopy /B&lt;/strong&gt; is slows down my migration compared to not using it. Is that required for preseeding?&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;The /B mode, while inherently slower, ensures that files are copied using a backup API regardless of permissions. It is the safest way, so I took the prudent route when I wrote the sample command. It&amp;rsquo;s definitely expected to be slower &amp;ndash; in my semi-scientific repro&amp;rsquo;s the difference was ~1.75 times slower on average.&lt;/p&gt;
&lt;p&gt;However, /B not required if you are &lt;i&gt;100% sure &lt;/i&gt;you have at least READ permissions to &lt;i&gt;all &lt;/i&gt;files.&amp;nbsp; As a middle ground approach, you might consider using /ZB to be somewhat faster but then hopefully still copy if there are issues; the downside here is a lot of failures due to permissions might end up making things even &lt;em&gt;slower&lt;/em&gt; than just going /B; you will have to test it. You can also add /MT to offset the /B slowness.&lt;/p&gt;
&lt;h1&gt;&lt;a name="blank"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;Recently I came across an user account that keeps locking out (yes, I've read several of your blogs where you say account lockout policies are bad "Turning on account lockouts is a way to guarantee someone with no credentials can deny service to your entire domain"). We get the Event ID of 4740 saying the account has been locked out, but the calling computer name is &lt;span style="background-color: #ffff00;"&gt;blank&lt;/span&gt;:&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: 12pt;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="CodeCxSpFirst" style="margin: 4pt 0.1in 0pt 0.3in; line-height: normal; list-style-type: disc; background-color: #f2f2f2;"&gt;&lt;span style="font-family: Consolas; font-size: x-small;" size="2" face="Consolas"&gt;&lt;span&gt;&lt;span style="mso-bidi-font-size: 11.5pt;"&gt;Log Name:&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Security&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: 12pt;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="CodeCxSpMiddle" style="margin: 0in 0.1in 0pt 0.3in; line-height: normal; list-style-type: disc; background-color: #f2f2f2;"&gt;&lt;span style="font-family: Consolas; font-size: x-small;" size="2" face="Consolas"&gt;&lt;span&gt;&lt;span style="mso-bidi-font-size: 11.5pt;"&gt;Event ID:&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;4740&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: 12pt;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="CodeCxSpMiddle" style="margin: 0in 0.1in 0pt 0.3in; line-height: normal; list-style-type: disc; background-color: #f2f2f2;"&gt;&lt;span style="font-family: Consolas; font-size: x-small;" size="2" face="Consolas"&gt;&lt;span&gt;&lt;span style="mso-bidi-font-size: 11.5pt;"&gt;Level:&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Information&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: 12pt;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="CodeCxSpMiddle" style="margin: 0in 0.1in 0pt 0.3in; line-height: normal; list-style-type: disc; background-color: #f2f2f2;"&gt;&lt;span style="font-family: Consolas; font-size: x-small;" size="2" face="Consolas"&gt;&lt;span&gt;&lt;span style="mso-bidi-font-size: 11.5pt;"&gt;Description:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: 12pt;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="CodeCxSpMiddle" style="margin: 0in 0.1in 0pt 0.3in; line-height: normal; list-style-type: disc; background-color: #f2f2f2;"&gt;&lt;span style="font-family: Consolas; font-size: x-small;" size="2" face="Consolas"&gt;&lt;span&gt;&lt;span style="mso-bidi-font-size: 11.5pt;"&gt;A user account was locked out.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: 12pt;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="CodeCxSpMiddle" style="margin: 0in 0.1in 0pt 0.3in; line-height: normal; list-style-type: disc; background-color: #f2f2f2;"&gt;&lt;span style="font-family: Consolas; font-size: x-small;" size="2" face="Consolas"&gt;&lt;span&gt;&lt;span style="mso-bidi-font-size: 11.5pt;"&gt;Subject:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: 12pt;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="CodeCxSpMiddle" style="margin: 0in 0.1in 0pt 0.3in; line-height: normal; list-style-type: disc; background-color: #f2f2f2;"&gt;&lt;span style="font-family: Consolas; font-size: x-small;" size="2" face="Consolas"&gt;&lt;span&gt;&lt;span style="mso-bidi-font-size: 11.5pt;"&gt;Security ID: SYSTEM&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: 12pt;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="CodeCxSpMiddle" style="margin: 0in 0.1in 0pt 0.3in; line-height: normal; list-style-type: disc; background-color: #f2f2f2;"&gt;&lt;span style="font-family: Consolas; font-size: x-small;" size="2" face="Consolas"&gt;&lt;span&gt;&lt;span style="mso-bidi-font-size: 11.5pt;"&gt;Account Name: someaccount&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: 12pt;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="CodeCxSpMiddle" style="margin: 0in 0.1in 0pt 0.3in; line-height: normal; list-style-type: disc; background-color: #f2f2f2;"&gt;&lt;span style="font-family: Consolas; font-size: x-small;" size="2" face="Consolas"&gt;&lt;span&gt;&lt;span style="mso-bidi-font-size: 11.5pt;"&gt;Account Domain: somedomain&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: 12pt;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="CodeCxSpMiddle" style="margin: 0in 0.1in 0pt 0.3in; line-height: normal; list-style-type: disc; background-color: #f2f2f2;"&gt;&lt;span style="font-family: Consolas; font-size: x-small;" size="2" face="Consolas"&gt;&lt;span&gt;&lt;span style="mso-bidi-font-size: 11.5pt;"&gt;Logon ID: 0x3e7&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: 12pt;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="CodeCxSpMiddle" style="margin: 0in 0.1in 0pt 0.3in; line-height: normal; list-style-type: disc; background-color: #f2f2f2;"&gt;&lt;span style="font-family: Consolas; font-size: x-small;" size="2" face="Consolas"&gt;&lt;span&gt;&lt;span style="mso-bidi-font-size: 11.5pt;"&gt;Account That Was Locked Out:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: 12pt;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="CodeCxSpMiddle" style="margin: 0in 0.1in 0pt 0.3in; line-height: normal; list-style-type: disc; background-color: #f2f2f2;"&gt;&lt;span style="font-family: Consolas; font-size: x-small;" size="2" face="Consolas"&gt;&lt;span&gt;&lt;span style="mso-bidi-font-size: 11.5pt;"&gt;Security ID: somesid&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: 12pt;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="CodeCxSpMiddle" style="margin: 0in 0.1in 0pt 0.3in; line-height: normal; list-style-type: disc; background-color: #f2f2f2;"&gt;&lt;span style="font-family: Consolas; font-size: x-small;" size="2" face="Consolas"&gt;&lt;span&gt;&lt;span style="mso-bidi-font-size: 11.5pt;"&gt;Account Name: someguy&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: 12pt;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="CodeCxSpMiddle" style="margin: 0in 0.1in 0pt 0.3in; line-height: normal; list-style-type: disc; background-color: #f2f2f2;"&gt;&lt;span style="font-family: Consolas; font-size: x-small;" size="2" face="Consolas"&gt;&lt;span&gt;&lt;span style="mso-bidi-font-size: 11.5pt;"&gt;Additional Information:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: 12pt;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="CodeCxSpLast" style="margin: 0in 0.1in 10pt 0.3in; line-height: normal; list-style-type: disc; background-color: #f2f2f2;"&gt;&lt;span style="font-family: Consolas; font-size: x-small;" size="2" face="Consolas"&gt;&lt;span&gt;&lt;span style="mso-bidi-font-size: 11.5pt;"&gt;&lt;span style="background-color: #ffff00;"&gt;Caller Computer Name:&lt;/span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: 12pt;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;The 0xC000006A indicates a bad password attempt. This happens every 5 minutes and eventually results in the account being locked out. We can see that the bad password attempts are coming via COMP1 (which is a proxy server) however we can't work out what is sending the requests to COMP1 as the computer is blank again (there should be a computer name).&lt;/p&gt;
&lt;p&gt;Are we missing something here? Is there something else we could be doing to track this down? Is the calling computer name being blank indicative of some other problem or just perhaps means the calling device is a non-Microsoft device?&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;(&lt;a href="http://blogs.msdn.com/b/ericfitz/archive/2005/08/04/447934.aspx"&gt;I am going to channel my inner Eric here&lt;/a&gt;):&lt;/p&gt;
&lt;p&gt;A blank computer name is not unexpected, unfortunately. The audit system relies on the sending computers to provide that information as part of the actual authentication attempt. Kerberos does not have a reliable way to provide the remote computer info in many cases. Name resolution info about a sending computer is also easily spoofed. This is especially true with transitive NTLM logons, where we are relying on one computer to provide info for another computer. NTLM provides names but they are also easily spoofed so even when you see a computer name in auditing, you are mainly asking an honest person to tell you the truth.&lt;/p&gt;
&lt;p&gt;Since it happens very frequently and predictably, I&amp;rsquo;d configure a network capture on the sending server to run in a circular fashion, then wait for the lock out and stop the event. You&amp;rsquo;d see all of the traffic and now know exactly who sent it. If the lockout was longer running and less predictable, I&amp;rsquo;d recommend using a network capture configured to trace in a circular fashion until that 4740 event writes. Then you can see what the sending IP address is and hunt down that machine. Different techniques here:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://nm3eventcap.codeplex.com/"&gt;http://nm3eventcap.codeplex.com/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.technet.com/b/netmon/archive/2007/02/22/eventmon-stopping-a-capture-based-on-an-eventlog-event.aspx"&gt;http://blogs.technet.com/b/netmon/archive/2007/02/22/eventmon-stopping-a-capture-based-on-an-eventlog-event.aspx&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;em&gt;[And the customer later noted that since it&amp;rsquo;s a proxy server, it has lots of logs &amp;ndash; and they told him the offender]&lt;/em&gt;&lt;/p&gt;
&lt;h1&gt;&lt;a name="modernapps"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;I am testing &lt;a href="http://blogs.technet.com/b/askds/archive/2012/04/13/new-usmt-5-0-features-for-windows-8-consumer-preview.aspx"&gt;USMT 5.0&lt;/a&gt; and finding that if I migrate certain Windows 7 computers to Windows 8 Consumer Preview, Modern Apps won&amp;rsquo;t start. Some have errors, some just start then go away.&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;Argh. The problem here is Windows 7&amp;rsquo;s built-in manifest that implements &lt;strong&gt;microsoft-windows-com-base&lt;/strong&gt; , which then copies this registry key:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;HKEY_LOCAL_MACHINE\Software\Microsoft\OLE&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;If the DCOM permissions are modified in that key, they migrate over and interfere with the ones needed by Modern Apps to run. This is a known issue and already fixed so that we don&amp;rsquo;t copy those values onto Windows 8 anymore. It was never a good idea in the first place, as any applications needing special permissions will just set their own anyways when installed.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://support.microsoft.com/kb/2481190"&gt;And it&amp;rsquo;s burned us in the past too&amp;hellip;&lt;/a&gt;&lt;/p&gt;
&lt;h1&gt;&lt;a name="ocsp"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;Are there any available PowerShell, WMI, or command-line options for configuring an OCSP responder? I know that I can install the feature with the Add-WindowsFeature, but I'd like to script configuring the responder and creating the array.&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;&lt;em&gt;[Courtesy of the &lt;a href="http://blogs.technet.com/b/askds/archive/tags/jonathan+stephens/"&gt;Jonathan &amp;ldquo;oh no, feet!&amp;rdquo; Stephens&lt;/a&gt; &amp;ndash; Ned]&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;There are currently no command line tools or dedicated PowerShell cmdlets available to perform management tasks on the Online Responder. You can, however, use the COM interfaces &lt;a href="http://msdn.microsoft.com/en-us/library/windows/desktop/aa386313(v=vs.85).aspx"&gt;IOCSPAdmin&lt;/a&gt; and &lt;a href="http://msdn.microsoft.com/en-us/library/windows/desktop/aa386328(v=vs.85).aspxhttp:/msdn.microsoft.com/en-us/library/windows/desktop/aa386328(v=vs.85).aspx"&gt;IOSCPCAConfiguration&lt;/a&gt; to manage the revocation providers on the Online Responder.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Create an &lt;a href="http://msdn.microsoft.com/en-us/library/windows/desktop/aa386313(v=vs.85).aspx"&gt;IOSCPAdmin&lt;/a&gt; object.&lt;/li&gt;
&lt;li&gt;The &lt;a href="http://msdn.microsoft.com/en-us/library/windows/desktop/aa386323(v=vs.85).aspx"&gt;IOSCPAdmin::OCSPCAConfigurationCollection&lt;/a&gt; property will return an &lt;a href="http://msdn.microsoft.com/en-us/library/windows/desktop/aa386330(v=vs.85).aspx"&gt;IOCSPCAConfigurationCollection&lt;/a&gt; object.&lt;/li&gt;
&lt;li&gt;Use &lt;a href="http://msdn.microsoft.com/en-us/library/windows/desktop/aa386335(v=vs.85).aspx"&gt;IOCSPCAConfigurationCollection::CreateCAConfiguration&lt;/a&gt; to create a new revocation provider.&lt;/li&gt;
&lt;li&gt;Make sure you call &lt;a href="http://msdn.microsoft.com/en-us/library/windows/desktop/aa386327(v=vs.85).aspx"&gt;IOCSPAdmin::SetConfiguration&lt;/a&gt; when finished so the online responder gets updated with the new revocation configuration.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Because these are COM interfaces, you can call them from VBScript or PowerShell, so you have great flexibility in how you write your script.&lt;/p&gt;
&lt;h1&gt;&lt;a name="wds"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;I want to use Windows Desktop Search with DFS Namespaces but according to this &lt;a href="http://social.msdn.microsoft.com/Forums/en/windowsdesktopsearchhelp/thread/85525c46-1ab5-46e1-a288-e36561a6ffab"&gt;TechNet Forum thread&lt;/a&gt; it&amp;rsquo;s not possible to add remote indexes on namespaces. What say you?&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;There is no DFSN+WDS remote index integration in any OS, including Windows 8 Consumer Preview. At its heart, this comes down to being a massive architectural change in WDS that just hasn&amp;rsquo;t gotten traction. You can still point to the targets as remote indexes, naturally.&lt;/p&gt;
&lt;h1&gt;&lt;a name="invalid"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;Certain files &amp;ndash; &lt;a href="http://blogs.msdn.com/b/alex_semi/archive/2012/02/22/os-refresh-fails-with-ntldr-can-t-be-found-error.aspx"&gt;as pointed out here by AlexSemi&lt;/a&gt; &amp;ndash; that end with invalid characters like a dot or a space break USMT migration. One way to create these files is to use the echo command into a device path like so:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/5367.image_5F00_4BCC3F26.png"&gt;&lt;img width="299" height="54" title="image" style="display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/4784.image_5F00_thumb_5F00_2491F5F1.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;These files can&amp;rsquo;t be opened by anything in Windows, it seems.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/2727.image_5F00_7D57ACBB.png"&gt;&lt;img width="629" height="442" title="image" style="display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/8507.image_5F00_thumb_5F00_6AA2B304.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;When you try to migrate, you end up with a fatal &amp;ldquo;windows error 2&amp;rdquo; &amp;ldquo;the system cannot find the file specified&amp;rdquo; error unless you skip the files using /C:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/0564.image_5F00_1BC1EDA5.png"&gt;&lt;img width="655" height="310" title="image" style="display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/2211.image_5F00_thumb_5F00_2208C433.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;What gives?&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;Quit making invalid files! :-)&lt;/p&gt;
&lt;p&gt;USMT didn&amp;rsquo;t invent &lt;a href="http://msdn.microsoft.com/en-us/library/windows/desktop/aa363858(v=vs.85).aspx"&gt;CreateFile()&lt;/a&gt; so its options here are rather limited&amp;hellip; &lt;a href="http://blogs.technet.com/b/askds/archive/2012/04/13/new-usmt-5-0-features-for-windows-8-consumer-preview.aspx"&gt;USMT 5.0&lt;/a&gt; handles this case correctly through error control - it skips these files when hardlink&amp;rsquo;ing because Windows returns that they &amp;ldquo;don&amp;rsquo;t exist&amp;rdquo;. Here is my scanstate log using USMT 5.0 beta, where I used &lt;b&gt;/hardlink &lt;/b&gt;and did NOT provide &lt;strong&gt;/C&lt;/strong&gt;:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/8407.image_5F00_4C74F550.png"&gt;&lt;img width="506" height="129" title="image" style="display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/6428.image_5F00_thumb_5F00_39BFFB99.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;In the case of &lt;em&gt;non&lt;/em&gt;-hardlink, scanstate copies them without their invalid names and they become non-dotted/non-spaced valid files (even in USMT 4.0). To make it copy these invalid files with the actual invalid name would require a complete re-architecting of USMT or the Win32 file APIs. And why &amp;ndash; so that everyone could continue to not open them?&lt;/p&gt;
&lt;h1&gt;&lt;a name="other"&gt;&lt;/a&gt;Other Stuff&lt;/h1&gt;
&lt;p&gt;In case you missed it, &lt;a href="http://windowsteamblog.com/windows/b/business/archive/2012/04/18/introducing-windows-8-enterprise-and-enhanced-software-assurance-for-today-s-modern-workforce.aspx"&gt;Windows 8 Enterprise Edition&lt;/a&gt; details. With all the new licensing and activation goodness, Enterprise versions are finally within reach of any size customer. Yes, that means you!&lt;/p&gt;
&lt;p&gt;Very solid &lt;a href="http://flavorwire.com/288529/exclusive-supercut-the-wisdom-of-our-tv-mothers"&gt;Mother&amp;rsquo;s Day TV mash up&lt;/a&gt; (a little sweary, but you can&amp;rsquo;t fight a something that combines The Wire, 30 Rock, and The Cosbys)&lt;/p&gt;
&lt;p&gt;Zombie mall experience. I have to fly to Reading in June to teach&amp;hellip; this might be on the agenda&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;iframe width="560" height="315" src="http://www.youtube.com/embed/g92gPYYYOCQ" frameborder="0" allowfullscreen="allowfullscreen"&gt;&lt;/iframe&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Well, it&amp;rsquo;s about time - &lt;a href="http://arstechnica.com/tech-policy/2012/05/congress-doesnt-like-it-when-employers-ask-for-facebook-login-details/"&gt;Congress doesn't "like" it when employers ask for Facebook login details&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Your mother is not this &lt;a href="http://www.bakingobsession.com/2012/04/02/alduin-the-world-eater-dragon-cake/"&gt;awesome&lt;/a&gt;:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://www.bakingobsession.com/2012/04/02/alduin-the-world-eater-dragon-cake/"&gt;&lt;img width="499" height="476" title="image" style="display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/1641.image_5F00_46B9DBAA.png" border="0" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;span style="font-size: xx-small;" size="1"&gt;That, my friend, is a Skyrim birthday cake&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;SportsCenter wins again (thanks &lt;a href="http://blogs.technet.com/b/markmoro/"&gt;Mark!)&lt;/a&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;iframe width="420" height="315" src="http://www.youtube.com/embed/tlLiViHkVj4" frameborder="0" allowfullscreen="allowfullscreen"&gt;&lt;/iframe&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Don&amp;rsquo;t miss the latest &lt;a href="http://www.funnyordie.com/between_two_ferns"&gt;Between Two Ferns&lt;/a&gt; (veeerrrry sweary, but &lt;a href="http://www.zachgalifianakis.com/"&gt;Zach Galifianakis&lt;/a&gt; at his best; I just wish they&amp;rsquo;d add the Tina Fey episode)&lt;/p&gt;
&lt;p&gt;But what happens if you &lt;a href="http://theinspirationroom.com/daily/2012/land-rover-edible-desert-survival-guide/"&gt;eat it before you read the survival tips, Land Rover?!&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Until next time,&lt;/p&gt;
&lt;p&gt;- Ned &amp;ldquo;demon spawn&amp;rdquo; Pyle&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3497578" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/askds/archive/tags/DFSR/">DFSR</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Certificates/">Certificates</category><category domain="http://blogs.technet.com/b/askds/archive/tags/DFSN/">DFSN</category><category domain="http://blogs.technet.com/b/askds/archive/tags/PKI/">PKI</category><category domain="http://blogs.technet.com/b/askds/archive/tags/PowerShell/">PowerShell</category><category domain="http://blogs.technet.com/b/askds/archive/tags/OCSP/">OCSP</category><category domain="http://blogs.technet.com/b/askds/archive/tags/USMT/">USMT</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Group+Policy+Preferences/">Group Policy Preferences</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Mail+Sack/">Mail Sack</category><category domain="http://blogs.technet.com/b/askds/archive/tags/DFSR+Performance/">DFSR Performance</category><category domain="http://blogs.technet.com/b/askds/archive/tags/DFSR+Migration+or+Upgrade/">DFSR Migration or Upgrade</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Jonathan+Stephens/">Jonathan Stephens</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Ned+Pyle/">Ned Pyle</category><category domain="http://blogs.technet.com/b/askds/archive/tags/USMT+Behaviors/">USMT Behaviors</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Windows+8/">Windows 8</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Windows+Server+_2600_quot_3B00_8_2600_quot_3B00_+Beta/">Windows Server &amp;quot;8&amp;quot; Beta</category><category domain="http://blogs.technet.com/b/askds/archive/tags/windows+server+2012/">windows server 2012</category></item><item><title>New Slow Logon, Slow Boot Troubleshooting Content</title><link>http://blogs.technet.com/b/askds/archive/2012/05/01/new-slow-logon-slow-boot-troubleshooting-content.aspx</link><pubDate>Tue, 01 May 2012 16:36:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3495461</guid><dc:creator>NedPyle [MSFT]</dc:creator><slash:comments>8</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/rsscomments.aspx?WeblogPostID=3495461</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/commentapi.aspx?WeblogPostID=3495461</wfw:comment><comments>http://blogs.technet.com/b/askds/archive/2012/05/01/new-slow-logon-slow-boot-troubleshooting-content.aspx#comments</comments><description>&lt;p&gt;Hi all, &lt;a href="http://blogs.technet.com/b/askds/archive/tags/ned+pyle/"&gt;Ned&lt;/a&gt; here again. We get emailed here all the time about issues involving delays in user logons. Often enough that, a few years back, &lt;a href="http://blogs.technet.com/b/askds/archive/tags/bob+drake/"&gt;Bob&lt;/a&gt; wrote a multi-part &lt;a href="http://blogs.technet.com/b/askds/archive/2009/09/23/so-you-have-a-slow-logon-part-1.aspx"&gt;article&lt;/a&gt; on the subject.&lt;/p&gt;
&lt;p&gt;Taking it to the next level, some of my esteemed colleagues have created a multi-part TechNet Wiki series on understanding, analyzing, and troubleshooting slow logons and slow boots. These include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Root causes for slow boots and logons (sbsl)&lt;/strong&gt; - &lt;a title="http://social.technet.microsoft.com/wiki/contents/articles/10130.root-causes-for-slow-boots-and-logons-sbsl.aspx" href="http://social.technet.microsoft.com/wiki/contents/articles/10130.root-causes-for-slow-boots-and-logons-sbsl.aspx"&gt;http://social.technet.microsoft.com/wiki/contents/articles/10130.root-causes-for-slow-boots-and-logons-sbsl.aspx&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Tools for Troubleshooting slow boots and slow logons (sbsl)&lt;/strong&gt; - &lt;a title="http://social.technet.microsoft.com/wiki/contents/articles/10128.tools-for-troubleshooting-slow-boots-and-slow-logons-sbsl.aspx" href="http://social.technet.microsoft.com/wiki/contents/articles/10128.tools-for-troubleshooting-slow-boots-and-slow-logons-sbsl.aspx"&gt;http://social.technet.microsoft.com/wiki/contents/articles/10128.tools-for-troubleshooting-slow-boots-and-slow-logons-sbsl.aspx&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Troubleshooting slow operating system boot times and slow user logons (sbsl) - &lt;/strong&gt;&lt;a title="http://social.technet.microsoft.com/wiki/contents/articles/10123.troubleshooting-slow-operating-system-boot-times-and-slow-user-logons-sbsl.aspx" href="http://social.technet.microsoft.com/wiki/contents/articles/10123.troubleshooting-slow-operating-system-boot-times-and-slow-user-logons-sbsl.aspx"&gt;http://social.technet.microsoft.com/wiki/contents/articles/10123.troubleshooting-slow-operating-system-boot-times-and-slow-user-logons-sbsl.aspx&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Before you shrug this off, consider the following example, where we assume for our hypothetical company:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Employees work 250 days per year (50 weeks * 5 days per week)&lt;/li&gt;
&lt;li&gt;Employee labor costs $2 per minute&lt;/li&gt;
&lt;li&gt;Each employees boots and logs on to a single desktop computer only once per day&lt;/li&gt;
&lt;li&gt;There are 25 and 30 seconds of removable delay from the boot and logon operations&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;That means an annual cost of:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/1106.image_5F00_292ABCF3.png"&gt;&lt;img width="399" height="207" title="image" style="display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/8611.image_5F00_thumb_5F00_1675C33C.png" border="0" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;span style="font-size: xx-small;" size="1"&gt;Benjamin Franklin would not be pleased&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Even if you take just the understated US Bureau of Labor private sector compensation cost &lt;a href="http://www.bls.gov/news.release/ecec.nr0.htm"&gt;numbers&lt;/a&gt; (roughly $0.50 average employee total compensation cost per minute), you are still hemorrhaging cash. And those numbers just cover direct compensation and benefit costs, not all the other overhead&amp;nbsp; that goes into an employee, as well as the fact that they are not &lt;em&gt;producing&lt;/em&gt; anything during that time - you are paying them to do &lt;em&gt;&lt;strong&gt;nothing&lt;/strong&gt;&lt;/em&gt;.&amp;nbsp;Need I mention that the computer-using employees are probably costing you nearly &lt;a href="http://www.bls.gov/news.release/ecec.t05.htm"&gt;twice that number&lt;/a&gt;?&lt;/p&gt;
&lt;p&gt;Get to reading, people &amp;ndash; this is a big deal.&lt;/p&gt;
&lt;p&gt;- Ned &amp;ldquo;a penny saved is a penny earned&amp;rdquo; Pyle&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3495461" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/askds/archive/tags/group+policy/">group policy</category><category domain="http://blogs.technet.com/b/askds/archive/tags/infrastructure/">infrastructure</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Authorization/">Authorization</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Authentication/">Authentication</category><category domain="http://blogs.technet.com/b/askds/archive/tags/WMI/">WMI</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Logon/">Logon</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Group+Policy+Preferences/">Group Policy Preferences</category><category domain="http://blogs.technet.com/b/askds/archive/tags/performance/">performance</category><category domain="http://blogs.technet.com/b/askds/archive/tags/branch+office/">branch office</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Ned+Pyle/">Ned Pyle</category></item><item><title>Friday Mail Sack: Drop the dope, hippy! edition</title><link>http://blogs.technet.com/b/askds/archive/2012/04/20/friday-mail-sack-drop-the-dope-hippy-edition.aspx</link><pubDate>Sat, 21 Apr 2012 00:43:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3493561</guid><dc:creator>NedPyle [MSFT]</dc:creator><slash:comments>6</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/rsscomments.aspx?WeblogPostID=3493561</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/commentapi.aspx?WeblogPostID=3493561</wfw:comment><comments>http://blogs.technet.com/b/askds/archive/2012/04/20/friday-mail-sack-drop-the-dope-hippy-edition.aspx#comments</comments><description>&lt;p&gt;Hi all, &lt;a href="http://blogs.technet.com/b/askds/archive/tags/ned+pyle/"&gt;Ned&lt;/a&gt; here again with an actual back to back mail sack. This week we discuss:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#usn"&gt;Running out of USNs and Versions&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#rdc"&gt;DFSR RDC LAN WAN FWIW AOK&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#nps"&gt;NPS and dotted NetBIOS domain names&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#usmt"&gt;USMT and the case of the failing sourcepriority&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#nicteam"&gt;Revisiting NIC teaming&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#dfsrdollar"&gt;Weird DFSR files&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#mca"&gt;MaxConcurrentAPI in depth (elsewhere)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#stoprepl"&gt;KB2663685 DFSR goodness&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#other"&gt;Other stuff&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h1&gt;&lt;a name="usn"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;I was reading an article that showed how to update the computer description every time a user logs on. A commenter mentioned that people should be careful as the environment could run out of USNs if this was implemented. Is that true?&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;This was a &lt;i&gt;really&lt;/i&gt; interesting question. The current USN is a 64-bit counter maintained by each Active Directory domain controller as the &lt;a href="http://technet.microsoft.com/en-us/library/cc772726(v=WS.10).aspx"&gt;highestCommittedUsn&lt;/a&gt; attribute on rootDSE.&amp;nbsp; Being an unsigned 64-bit integer, that means 2&lt;sup&gt;64&lt;/sup&gt;-1, which is 18,446,744,073,709,551,615 (i.e. 18 quintillion). Under normal use that is never going to run out. Even more, when AD reaches that top number, it would restart at 1 all over again!&lt;/p&gt;
&lt;p&gt;Let's say I &lt;i&gt;want&lt;/i&gt; to run out of USNs though, so I create a script that makes &lt;i&gt;100 &lt;/i&gt;object write updates &lt;i&gt;per second&lt;/i&gt; on at DC. It would take me &lt;i&gt;54 days&lt;/i&gt; to hit the &lt;i&gt;first&lt;/i&gt; 1 billionth USN. At that rate, this means I am adding ~6.5 billion USN changes a year. Which means at that rate, it would take just under &lt;i&gt;3 billion years&lt;/i&gt; to run out on that DC. Which is probably longer than your hardware warranty.&lt;/p&gt;
&lt;p&gt;My further thought was around Version metadata, which we don't document anywhere I can find. That is an unsigned 32-bit counter for each &lt;i&gt;attribute&lt;/i&gt; on an object and again, so huge it is simply not feasible that it would run out in anything approaching normal circumstances. If you were to update a computer&amp;rsquo;s description every time a user logged on and they only had one computer, at 2&lt;sup&gt;32&lt;/sup&gt;-1 that means they have to logon 4,294,967,295 times to run out. Let&amp;rsquo;s say they logon in the morning and always logoff for bathroom, coffee, meetings and lunch breaks rather than locking their machines &amp;ndash; call it 10 logons a day and 250 working days a year. That is still 1.7 million years before they run out and you need to disjoin, rename, and rejoin their computer so they can start again.&lt;/p&gt;
&lt;p&gt;That said - the commenter was a bit off about the facts, but he had the right notion: not re-writing attributes with unchanged data is definitely a good idea. Less spurious work is always the right answer for DC performance and replication. Figure out a less invasive way to do this, or even better, use a product like System Center Config Manager; it has built in functionality to determine the &amp;ldquo;primary user&amp;rdquo; of computers, involving auditing and some other heuristics. This is part of its &amp;ldquo;&lt;a href="http://technet.microsoft.com/en-us/library/cc161947.aspx"&gt;Asset Intelligence&lt;/a&gt;&amp;rdquo; reporting (maybe called something else in SCCM 2012).&lt;/p&gt;
&lt;p&gt;Interesting side effect of this conversation: I was testing all this out with NTDSUTIL auth restores and setting the version artificially high on an object with VERINC. Repadmin /showmeta gets upset once your version crosses the 2&lt;sup&gt;31&lt;/sup&gt; line.&amp;nbsp;:) See for yourself (in a lab only, please). If you ever find yourself in that predicament, use LDP's metadata displayer, it keeps right on trucking.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/2867.image_5F00_31599EF7.png"&gt;&lt;img width="632" height="127" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border-width: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/7142.image_5F00_thumb_5F00_55EDBD2C.png" border="0" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;span style="font-size: xx-small;" size="1"&gt;Maybe a li'l ol' casting issue here&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/1856.image_5F00_10D4EFF6.png"&gt;&lt;img width="632" height="197" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border-width: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/4571.image_5F00_thumb_5F00_4745A1F8.png" border="0" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;span style="font-size: xx-small;" size="1"&gt;Ahh, that's better. Get out the hex converter.&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h1&gt;&lt;a name="rdc"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;I find replication to be faster with RDC disabled on my LAN connected servers (hmmm, &lt;a href="http://blogs.technet.com/b/askds/archive/2010/03/31/tuning-replication-performance-in-dfsr-especially-on-win2008-r2.aspx"&gt;just like your blog&lt;/a&gt; said), so I have it disabled on the connections between my hub servers and the other servers on the same LAN. I have other servers connected over a WAN, so I kept RDC enabled on those connections.&lt;/p&gt;
&lt;p&gt;By having some connections with RDC enabled and others disabled, am I making my hub server do &amp;lsquo;twice&amp;rsquo; the work? Would it be better if I enabled it on all connections, even the LAN ones?&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;You aren&amp;rsquo;t making your servers do things twice, per se; more like doing the same things, then one does a little more.&lt;/p&gt;
&lt;p&gt;Consider a change made on the hub: it still stage the same file once, compresses it in staging once, creates RDC signatures for it once, and sends the overall calculated SHA-1 file hash to each server once. The only difference will be that one spoke server then receives the whole file and the other spoke does the RDC version vector and signature chunk dance to receive part of the file.&lt;/p&gt;
&lt;p&gt;The non-RDC LAN-based communication will still be more efficient and fast within its context, and the WAN will still get less utilization and faster performance for large files with small changes.&lt;/p&gt;
&lt;h1&gt;&lt;a name="nps"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;I'm trying to get Network Policy Server (RADIUS) to work in my environment to enable WPA-2 authentication from a slick new wireless device. I keep getting the error "There is no domain controller available for domain CONTOSO.COM" in the event log when I try to authenticate, which is our legacy dotted NetBIOS domain name. On a hunch, I created a subdomain without a dot in the NetBIOS name and was able to authenticate right away with any user from that subdomain. Do you have any tricks or advice on how to deal with NPS in a dotted domain running in native Windows 2008 R2 mode other than renaming it (yuck).&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;I don't even know how to spell NPS (it's supported by our Networking team) but I found this internal article from them. You are not going to like the answer:&lt;/p&gt;
&lt;p&gt;&lt;i&gt;Previous versions of IAS/NPS could not perform SPN lookups across domains because it treated the SPN as a string and not an FQDN. Windows Server 2008 R2 corrected that behavior, but now NPS is treating a dotted NetBIOS name as a FQDN and NPS performs a DNS lookup on the CONTOSO.COM name. This fails because DNS does not host a CONTOSO.COM zone. &lt;/i&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;That leaves you with three main solutions:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Rename your domain using &lt;a href="http://technet.microsoft.com/en-us/library/cc786120(v=ws.10).aspx"&gt;rendom.exe&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Migrate your domain using &lt;a href="http://technet.microsoft.com/en-us/library/cc974332(v=WS.10).aspx"&gt;ADMT&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Use a Windows Server 2008 NPS&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;There might be some other workaround - this would be an extremely corner case scenario and I doubt we've explored it deeply.&lt;/p&gt;
&lt;p&gt;The third solution is an ok short-term workaround, but Win2008 isn&amp;rsquo;t going to be supported forever and you might need some R2 features in the meantime. The first two are gnarly, but I gotta tell ya: no one is rigorously testing dotted NetBIOS names anymore, as they were only possible from NT 4.0 domain upgrades and are as rare as an honest politician. They are ticking time bombs. A variety of other applications and products fail when trying to use dotted NetBIOS domain names and they might not have a workaround. A domain rename is probably in your future, and it's for the best.&lt;/p&gt;
&lt;h1&gt;&lt;a name="usmt"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;We are using USMT 4.0 to migrate data with the merge script &lt;b&gt;sourcepriority &lt;/b&gt;option to always overwrite data on the destination with data from the source. No matter what though, the destination always wins and the source copy of the file is renamed with the losing (1) tag.&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;This turned out to be quite an adventure.&lt;/p&gt;
&lt;p&gt;We turned on migdiag logging using SET MIG_ENABLE_DIAG=migdiag.xml in order to see what was happening here; that's a great logging option for figuring out why your rules aren&amp;rsquo;t processing correctly. When it got to the file in question during loadstate, we saw this weirdness:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;&amp;lt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="color: #a31515;" color="#a31515"&gt;Pattern&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="color: #ff0000;" color="#ff0000"&gt;Type&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;=&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="color: #000000;" color="#000000"&gt;"&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;File&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="color: #000000;" color="#000000"&gt;"&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="color: #ff0000;" color="#ff0000"&gt;Path&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;=&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="color: #000000;" color="#000000"&gt;"&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;C:\Users\someuser\AppData\Local\Microsoft\Windows Sidebar [Settings.ini]&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="color: #000000;" color="#000000"&gt;"&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="color: #ff0000;" color="#ff0000"&gt;Operation&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;=&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="color: #000000;" color="#000000"&gt;"&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;DynamicMerge&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-position: 0% 0%; mso-highlight: yellow;"&gt;&lt;span style="background-color: #ffff00;"&gt;,&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="background-color: #ffff00;"&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-position: 0% 0%; mso-highlight: yellow;"&gt;&lt;span style="color: #ff0000;" color="#ff0000"&gt;&amp;amp;lt;&lt;/span&gt;&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-position: 0% 0%; mso-highlight: yellow;"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;unknown&lt;/span&gt;&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-position: 0% 0%; mso-highlight: yellow;"&gt;&lt;span style="color: #ff0000;" color="#ff0000"&gt;&amp;amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-position: 0% 0%; mso-highlight: yellow;"&gt;&lt;span style="color: #000000;" color="#000000"&gt;"&lt;/span&gt;&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-position: 0% 0%; mso-highlight: yellow;"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;/&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Normally, it should have looked like:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;&amp;lt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #a31515;" color="#a31515"&gt;Pattern&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #ff0000;" color="#ff0000"&gt;Type&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;=&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #000000;" color="#000000"&gt;"&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;File&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #000000;" color="#000000"&gt;"&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #ff0000;" color="#ff0000"&gt;Path&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;=&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #000000;" color="#000000"&gt;"&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;C:\Users\someuser\AppData\Roaming\Microsoft\Access\* [*]&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #000000;" color="#000000"&gt;"&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #ff0000;" color="#ff0000"&gt;Operation&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;=&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #000000;" color="#000000"&gt;"&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;DynamicMerge&lt;/span&gt;&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-position: 0% 0%; mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #000000; background-color: #00ff00;" color="#000000"&gt;,CMXEMerge,CMXEMergeScript,MigXmlHelper,SourcePriority"&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;/&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;More interestingly, none of us could reproduce the issue here using the customer's exact same XML file. Finally, I had him reinstall USMT from a freshly downloaded copy of the WAIK, and it all started working perfectly. I've done this a few times in the past with good results for these kinds of weirdo issues; since USMT cannot be installed on Windows XP, it just gets copied around as folders. Sometimes people start mixing in various versions and DLLS, from Beta, RC, and hotfixes, and you end up with something that looks like USMT - but ain't.&lt;/p&gt;
&lt;h1&gt;&lt;a name="nicteam"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;Is teaming network adapters on Domain Controllers supported by Microsoft? I found KB &lt;a href="http://support.microsoft.com/kb/278431"&gt;http://support.microsoft.com/kb/278431&lt;/a&gt;.&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;&lt;strong&gt;(Updated)&lt;/strong&gt; Maybe! :-D&amp;nbsp;We're still in beta and need to get a final word. Sharp-eyed readers know I was already asked this &lt;a href="http://blogs.technet.com/b/askds/archive/2011/01/21/friday-mail-sack-the-gang-s-all-here-edition.aspx"&gt;before&lt;/a&gt;. However, I have a new answer for Windows Server: yes, &lt;a href="http://technet.microsoft.com/en-us/library/hh831648.aspx"&gt;if you use Windows Server "8" Beta&lt;/a&gt;.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/6153.image_5F00_2BA3A6B3.png"&gt;&lt;img width="540" height="359" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border-width: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/7536.image_5F00_thumb_5F00_745D1F77.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Whoa, we joined the 1990s! Seriously though, NIC teaming is the bane of our Networking Support group's existence, so hopefully by creating and implementing our own driver system, we stop the pain customers have using third party solutions of variable quality. At least we'll be able to see what's wrong now if it doesn&amp;rsquo;t work.&lt;/p&gt;
&lt;p&gt;For a lot more info, &lt;a href="http://download.microsoft.com/download/E/1/3/E13C9AD6-B4D6-4041-97E0-6BDC48273BC7/Windows%20Server%208%20Beta%20NIC%20Teaming%20(LBFO)%20Deployment%20and%20Management.docx"&gt;grab the whitepaper.&lt;/a&gt;&amp;nbsp;I'm confirming the whole DC-specific aspect here as well. I have heard several stories now and I want to be nice and crisp; check back later. :)&lt;/p&gt;
&lt;h1&gt;&lt;a name="dfsrdollar"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;What are the DFSR files &lt;b&gt;$db_dirty$&lt;/b&gt;, &lt;b&gt;$db_normal$&lt;/b&gt;, and &lt;b&gt;$db_lost$&lt;/b&gt; mentioned in the KB article &lt;a href="http://support.microsoft.com/kb/822158"&gt;Virus scanning recommendations for Enterprise computers that are running currently supported versions of Windows&lt;/a&gt; ? I only see $db_normal$ on my servers (presumably that's a good thing).&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;&lt;b&gt;$Db_dirty$&lt;/b&gt; exists after a dirty database shutdown and acts as a marker of that fact. &lt;b&gt;$Db_normal$&lt;/b&gt; exists when there are no database issues and is renamed to &lt;b&gt;$db_lost$&lt;/b&gt; if the database goes missing, also acting as a state marker for DFSR between service restarts.&lt;/p&gt;
&lt;h1&gt;&lt;a name="mca"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;Where is the best place to learn more about MaxConcurrentAPI?&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;Right here, and only quite recently:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://social.technet.microsoft.com/wiki/contents/articles/9759.configuring-maxconcurrentapi-for-ntlm-pass-through-authentication.aspx"&gt;http://social.technet.microsoft.com/wiki/contents/articles/9759.configuring-maxconcurrentapi-for-ntlm-pass-through-authentication.aspx&lt;/a&gt;&lt;/p&gt;
&lt;h1&gt;&lt;a name="stoprepl"&gt;&lt;/a&gt;Not a question (new DFSR functionality in KB 2663685)&lt;/h1&gt;
&lt;p&gt;If you missed it, we released a new hotfix for DFSR last month that adds some long-sought functionality for file server administrators: the ability to prevent DFSR from non-authoritatively synchronizing replicated folders on a volume where the database suffered a dirty shutdown:&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Changes that are not replicated to a downstream server are lost on the upstream server after an automatic recovery process occurs in a DFS Replication environment in Windows Server 2008 R2 - &lt;/b&gt;&lt;a href="http://support.microsoft.com/kb/2663685"&gt;http://support.microsoft.com/kb/2663685&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;DFSR now provides the capability to override automatic replication recovery of dirty shutdown-flagged databases. By default, the following registry DWORD value exists:&lt;/p&gt;
&lt;p class="CodeCxSpFirst" style="line-height: normal; background-color: #f2f2f2; list-style-type: disc; margin: 0in 0.1in 0pt 0.3in; mso-add-space: auto;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;HKLM\System\CurrentControlSet\Services\DFSR\Parameters\&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="CodeCxSpLast" style="line-height: normal; background-color: #f2f2f2; list-style-type: disc; margin: 0in 0.1in 0pt 0.3in; mso-add-space: auto;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;StopReplicationOnAutoRecovery = 1&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;If set to&lt;b&gt; 1&lt;/b&gt;, auto recovery is blocked and requires administrative intervention. Set it to 0 to return to the old behavior.&lt;/p&gt;
&lt;p&gt;DFSR writes warning 2213 event to the DFSR event log:&lt;/p&gt;
&lt;p class="CodeCxSpFirst" style="line-height: normal; background-color: #f2f2f2; list-style-type: disc; margin: 4pt 0.1in 0pt 0.3in;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;MessageId=2213 &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="CodeCxSpMiddle" style="line-height: normal; background-color: #f2f2f2; list-style-type: disc; margin: 0in 0.1in 0pt 0.3in;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;Severity=Warning &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="CodeCxSpMiddle" style="line-height: normal; background-color: #f2f2f2; list-style-type: disc; margin: 0in 0.1in 0pt 0.3in;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;Message=&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="CodeCxSpMiddle" style="line-height: normal; background-color: #f2f2f2; list-style-type: disc; margin: 0in 0.1in 0pt 0.3in;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;The DFS Replication service stopped replication on volume %2.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="CodeCxSpMiddle" style="line-height: normal; background-color: #f2f2f2; list-style-type: disc; margin: 0in 0.1in 0pt 0.3in;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;This occurs when a DFSR JET database is not shut down cleanly and Auto Recovery is disabled. To resolve this issue, back up the files in the affected replicated folders, and then use the ResumeReplication WMI method to resume replication.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="CodeCxSpMiddle" style="line-height: normal; background-color: #f2f2f2; list-style-type: disc; margin: 0in 0.1in 0pt 0.3in;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;Additional Information:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="CodeCxSpMiddle" style="line-height: normal; background-color: #f2f2f2; list-style-type: disc; margin: 0in 0.1in 0pt 0.3in;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;Volume: %2&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="CodeCxSpMiddle" style="line-height: normal; background-color: #f2f2f2; list-style-type: disc; margin: 0in 0.1in 0pt 0.3in;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;GUID: %1&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="CodeCxSpMiddle" style="line-height: normal; background-color: #f2f2f2; list-style-type: disc; margin: 0in 0.1in 0pt 0.3in;"&gt;&lt;span style="color: #000000; font-family: Consolas;" face="Consolas" color="#000000"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p class="CodeCxSpMiddle" style="line-height: normal; background-color: #f2f2f2; list-style-type: disc; margin: 0in 0.1in 0pt 0.3in;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;Recovery Steps&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="CodeCxSpMiddle" style="line-height: normal; background-color: #f2f2f2; list-style-type: disc; margin: 0in 0.1in 0pt 0.3in;"&gt;&lt;span style="color: #000000; font-family: Consolas;" face="Consolas" color="#000000"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p class="CodeCxSpMiddle" style="line-height: normal; background-color: #f2f2f2; list-style-type: disc; margin: 0in 0.1in 0pt 0.3in;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;1. Back up the files in all replicated folders on the volume. Failure to do so may result in data loss due to unexpected conflict resolution during the recovery of the replicated folders.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="CodeCxSpMiddle" style="line-height: normal; background-color: #f2f2f2; list-style-type: disc; margin: 0in 0.1in 0pt 0.3in;"&gt;&lt;span style="color: #000000; font-family: Consolas;" face="Consolas" color="#000000"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p class="CodeCxSpMiddle" style="line-height: normal; background-color: #f2f2f2; list-style-type: disc; margin: 0in 0.1in 0pt 0.3in;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;2. To resume the replication for this volume, use the WMI method ResumeReplication of the VolumeConfig class.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="CodeCxSpMiddle" style="line-height: normal; background-color: #f2f2f2; list-style-type: disc; margin: 0in 0.1in 0pt 0.3in;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;For example, from an elevated command prompt, type the following command:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="CodeCxSpMiddle" style="line-height: normal; background-color: #f2f2f2; list-style-type: disc; margin: 0in 0.1in 0pt 0.3in;"&gt;&lt;span style="color: #000000; font-family: Consolas;" face="Consolas" color="#000000"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p class="CodeCxSpMiddle" style="line-height: normal; background-color: #f2f2f2; list-style-type: disc; margin: 0in 0.1in 0pt 0.3in;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;wmic /namespace:\\root\microsoftdfs path dfsrVolumeConfig where volumeGuid="%1" call ResumeReplication&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="CodeCxSpMiddle" style="line-height: normal; background-color: #f2f2f2; list-style-type: disc; margin: 0in 0.1in 0pt 0.3in;"&gt;&lt;span style="color: #000000; font-family: Consolas;" face="Consolas" color="#000000"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p class="CodeCxSpLast" style="line-height: normal; background-color: #f2f2f2; list-style-type: disc; margin: 0in 0.1in 10pt 0.3in;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;For more information, see http://support.microsoft.com/kb/2663685.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;You must then make a decision about resuming replication. You must weigh your decision against the environment:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Are there originating files or modifications on this server?&lt;/b&gt; You can use the DFSRDIAG BACKLOG command with this server as the sending member and each of its partners as the receiving member to determine if this server had any pending outbound replication.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Do you need an out of band backup?&lt;/b&gt; You can check you latest backup logs and compare to file contents to see if you should first backup the RFs.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Are the replicated folders read-only?&lt;/b&gt; If so, there is little reason to examine the server further and you can resume replication. It is impossible for the RO RFs to have originated changes in that case.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;You then have several options:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Resume replication&lt;/b&gt;. By executing the WMI method listed in the event, the database rebuild commences for &lt;i&gt;all&lt;/i&gt; Replicated Folders on that volume. If the database cannot be rebuilt gracefully, DFSR deletes the database and performs initial non-authoritative sync. All data local in those replicated folders is fenced to lose conflict resolutions. Any files that do not match the SHA1 hash of upstream servers move to the circular ConflictAndDeleted folder and, potentially, lost forever.&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;b&gt;Example&lt;/b&gt;:&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p class="Code" style="line-height: normal; background-color: #f2f2f2; list-style-type: disc; margin: 0in 0.1in 0pt 0.8in; mso-add-space: auto;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;Wmic /namespace:\\root\microsoftdfs path dfsrVolumeConfig where volumeGuid="&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;i style="mso-bidi-font-style: normal;"&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-position: 0% 0%; mso-highlight: yellow;"&gt;&lt;span style="background-color: #ffff00;"&gt;&amp;lt;some GUID&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;" call ResumeReplication&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Reconfigure replication on RFs to be authoritative&lt;/b&gt;. If the data is more up to date on the non-replicating RFs or the RFs are designed to originate data (such as Branch servers replicating back to a central hub for backups), you must manually reconfigure replication to force them to win.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;a name="other"&gt;&lt;/a&gt;Other Stuff&lt;/h3&gt;
&lt;p&gt;Holy crap!&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;iframe width="420" height="315" src="http://www.youtube.com/embed/2i2_XDRfkio" frameborder="0" allowfullscreen="allowfullscreen"&gt;&lt;/iframe&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;a href="http://www.pandora.com/"&gt;Pandora.com&lt;/a&gt; is a great way to find new music; I highly recommend it. It can get a little esoteric, though. Real radio will never find you a string duo that plays Guns and Roses songs, for example.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/6153.image_5F00_3D16983C.png"&gt;&lt;img width="459" height="463" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/8204.image_5F00_thumb_5F00_613E837C.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;AskDS reader Joseph Moody sent this along to us:&lt;/p&gt;
&lt;p&gt;&lt;i&gt;"Because I got tired of forwarding the &lt;a href="http://blogs.technet.com/b/askds/archive/2011/09/02/accelerating-your-it-career.aspx"&gt;Accelerating Your IT Career&lt;/a&gt; post to techs in our department, we just had it printed poster size and hung it on an open wall. Now, I just point to it when someone asks how to get better."&lt;/i&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/8357.image_5F00_7074EC49.png"&gt;&lt;img width="484" height="647" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/0830.image_5F00_thumb_5F00_243F734C.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;My wife wanted to be a marine biologist (like George Costanza!) when she was growing up and we got on a killer whale conversation last week when I was watching the amazing &lt;a href="http://dsc.discovery.com/tv/frozen-planet/"&gt;Discovery Frozen Planet&lt;/a&gt; series. She later sent me this &lt;a href="http://news.mongabay.com/2005/0907-ap.html"&gt;tidbit&lt;/a&gt;:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;i&gt;"First, the young whale spit regurgitated fish onto the surface of the water, then sank below the water and waited. &lt;/i&gt;&lt;/p&gt;
&lt;p&gt;&lt;i&gt;If a hungry gull landed on the water, the whale would surge up to the surface, sometimes catching a free meal of his own.&lt;/i&gt; &lt;i&gt;Noonan watched as the same whale set the same trap again and again. Within a few months, the whale's younger half brother adopted the practice. &lt;/i&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;i&gt;Eventually the behavior spread and now five Marineland whales supplement their diet with fresh fowl, the scientist said."&lt;/i&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;a href="http://www.imdb.com/title/tt0149261/"&gt;It's Deep Blue Sea for Realzies!!!&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;Finally&lt;/h3&gt;
&lt;p&gt;Have you ever wanted to know what &lt;a href="http://blogs.technet.com/b/askds/archive/tags/rob+greene/"&gt;AskDS contributor Rob Greene&lt;/a&gt; looks like when his manager 'shops him to a Shrek picture? Now you can:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/7356.image_5F00_5156F0CB.png"&gt;&lt;img width="408" height="405" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/5706.image_5F00_thumb_5F00_40724CDB.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Have a nice weekend folks,&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;- Ned &amp;ldquo;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/8322.image_5F00_3955A114.png"&gt;&lt;img width="118" height="240" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/3036.image_5F00_thumb_5F00_222A2696.png" border="0" /&gt;&lt;/a&gt;&amp;rdquo; Pyle&lt;/p&gt;
&lt;/blockquote&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3493561" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/askds/archive/tags/DFSR/">DFSR</category><category domain="http://blogs.technet.com/b/askds/archive/tags/infrastructure/">infrastructure</category><category domain="http://blogs.technet.com/b/askds/archive/tags/KB+Articles/">KB Articles</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Silly+Rabbit/">Silly Rabbit</category><category domain="http://blogs.technet.com/b/askds/archive/tags/AD+Replication/">AD Replication</category><category domain="http://blogs.technet.com/b/askds/archive/tags/DNS/">DNS</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Other+Blogs/">Other Blogs</category><category domain="http://blogs.technet.com/b/askds/archive/tags/USMT/">USMT</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Mail+Sack/">Mail Sack</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Rob+Greene/">Rob Greene</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Ned+Pyle/">Ned Pyle</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Windows+8/">Windows 8</category><category domain="http://blogs.technet.com/b/askds/archive/tags/windows+server+2012/">windows server 2012</category></item><item><title>How to NOT Use Win32_Product in Group Policy Filtering</title><link>http://blogs.technet.com/b/askds/archive/2012/04/19/how-to-not-use-win32-product-in-group-policy-filtering.aspx</link><pubDate>Thu, 19 Apr 2012 18:22:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3493233</guid><dc:creator>NedPyle [MSFT]</dc:creator><slash:comments>20</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/rsscomments.aspx?WeblogPostID=3493233</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/commentapi.aspx?WeblogPostID=3493233</wfw:comment><comments>http://blogs.technet.com/b/askds/archive/2012/04/19/how-to-not-use-win32-product-in-group-policy-filtering.aspx#comments</comments><description>&lt;p&gt;Hi all, &lt;a href="http://blogs.technet.com/b/askds/archive/tags/Ned+Pyle/"&gt;Ned&lt;/a&gt; here again. I have worked many &lt;a href="http://blogs.technet.com/b/askds/archive/2009/09/23/so-you-have-a-slow-logon-part-1.aspx"&gt;slow boot and slow logon&lt;/a&gt; cases over my career. The Directory Services support team here at Microsoft owns a sizable portion of those operations - user credentials, user profiles, logon and startup scripts, and of course, group policy processing. If I had to pick the initial finger pointing that customers routinely make, it's GP. Perhaps it's because group policy is the least well-understood part of the process, or maybe because it's the one with the most administrative fingers in the pie. When it comes down to reality though, group policy is more often &lt;i&gt;not&lt;/i&gt; the culprit. Our new changes in Windows 8 will &lt;a href="http://blogs.technet.com/b/askds/archive/2012/04/06/group-policy-management-improvements-in-windows-server-quot-8-quot-beta.aspx"&gt;help you make that determination&lt;/a&gt; much quicker now.&lt;/p&gt;
&lt;p&gt;Today I am going to talk about one of those times that GPO &lt;i&gt;is&lt;/i&gt; the villain. Well, sort of... he's at least an enabler. More appropriately, the optional WMI Filtering portion of group policy using the &lt;a href="http://msdn.microsoft.com/en-us/library/windows/desktop/aa394378(v=vs.85).aspx"&gt;Win32_Product&lt;/a&gt; class. Win32_Product has been around for many years and is both an inventory and administrative tool. It allows you to see all the installed MSI packages on a computer, install new ones, reinstall them, remove them, and configure them. When used correctly, it's a valuable option for scripters and Windows PowerShell junkies.&lt;/p&gt;
&lt;p&gt;Unfortunately, Win32_Product also has some unpleasant behaviors. It uses a provider DLL that validates the consistency of every installed MSI package on the computer - or off of it, if using a remote administrative install point. &lt;a href="http://support.microsoft.com/kb/974524"&gt;That makes it very, very slow&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Where people trip up usually is group policy WMI filters. Perhaps the customer wants to apply managed Internet Explorer policy based on the IE version. Maybe they want to set &lt;a href="http://technet.microsoft.com/en-us/library/dd723678(v=WS.10).aspx"&gt;AppLocker&lt;/a&gt; or &lt;a href="http://technet.microsoft.com/en-us/library/cc728085(v=ws.10).aspx"&gt;Software Restriction&lt;/a&gt; policies only if the client has a certain program installed. Perhaps even use - yuck - &lt;a href="http://technet.microsoft.com/en-us/library/cc738151(v=ws.10).aspx"&gt;Software Installation&lt;/a&gt; policy in a more controlled fashion.&lt;/p&gt;
&lt;p&gt;Today I talk about some different options. &lt;a href="http://blogs.technet.com/b/askds/archive/tags/Mike+Stephens/"&gt;Mike&lt;/a&gt; didn&amp;rsquo;t write this but he had some good thoughts when we talked about this offline so he gets some credit here too. A little bit. Tiny amount, really. Hardly worth mentioning.&lt;/p&gt;
&lt;p&gt;If you have no idea what group policy WMI filters are, start here:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://blogs.technet.com/b/askds/archive/2008/09/11/fun-with-wmi-filters-in-group-policy.aspx"&gt;Fun with WMI Filters in Group Policy&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.technet.com/b/askds/archive/2012/02/11/friday-mail-sack-get-off-my-lawn-edition.aspx#wmi"&gt;Multiple WMI Filters&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.technet.com/b/askds/archive/2008/05/16/bulk-exporting-and-importing-wmi-filters-for-group-policy.aspx"&gt;Bulk exporting and importing WMI Filters&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Back? Great, let's get to it.&lt;/p&gt;
&lt;h1&gt;Don&amp;rsquo;t use Win32_Product&lt;/h1&gt;
&lt;p&gt;The Win32_Product WMI class is part of the CIMV2 namespace and implements the MSI provider (msiprov.dll and associated msi.mof) to list and validate&lt;i&gt; &lt;/i&gt;installed installation packages. You will see MsiInstaller event 1035 in the Application log for each application queried by the class:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p class="MsoNormal" style="line-height: 13pt; list-style-type: disc; margin: 0in 0in 0pt 0.5in;"&gt;&lt;span style="line-height: 12pt;"&gt;&lt;span style="font-family: consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;Source: &lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-position: 0% 0%; mso-highlight: yellow;"&gt;&lt;span style="background-color: #ffff00;"&gt;MsiInstaller&lt;/span&gt;&lt;/span&gt; &lt;br /&gt;Event ID: &lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-position: 0% 0%; mso-highlight: yellow;"&gt;&lt;span style="background-color: #ffff00;"&gt;1035&lt;/span&gt;&lt;/span&gt; &lt;br /&gt;Description: &lt;br /&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-position: 0% 0%; mso-highlight: yellow;"&gt;&lt;span style="background-color: #ffff00;"&gt;Windows Installer reconfigured the product. Product Name: &amp;lt;ProductName&amp;gt;. Product Version: &amp;lt;VersionNumber&amp;gt;. Product Language: &amp;lt;languageID&amp;gt;. Reconfiguration success or error status: 0.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;And constantly repeated System events:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;span style="line-height: 12pt;"&gt;&lt;span style="font-family: consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;Event Source: &lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-position: 0% 0%; mso-highlight: yellow;"&gt;&lt;span style="background-color: #ffff00;"&gt;Service Control Manager&lt;/span&gt;&lt;/span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: 13pt; list-style-type: disc; margin: 0in 0in 0pt 0.5in;"&gt;&lt;span style="line-height: 12pt;"&gt;&lt;span style="font-family: consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;Event ID: &lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-position: 0% 0%; mso-highlight: yellow;"&gt;&lt;span style="background-color: #ffff00;"&gt;7035&lt;/span&gt;&lt;/span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: 13pt; list-style-type: disc; margin: 0in 0in 0pt 0.5in;"&gt;&lt;span style="line-height: 12pt;"&gt;&lt;span style="font-family: consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;Description: &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: 13pt; list-style-type: disc; margin: 0in 0in 0pt 0.5in;"&gt;&lt;span style="font-family: consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;&lt;span style="background-image: none; line-height: 12pt; background-attachment: scroll; background-repeat: repeat; background-position: 0% 0%; mso-highlight: yellow;"&gt;&lt;span style="background-color: #ffff00;"&gt;The Windows Installer service was successfully sent a start control.&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: 12pt;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: 13pt; list-style-type: disc; margin: 0in 0in 0pt 0.5in;"&gt;&lt;span style="line-height: 12pt;"&gt;&lt;span style="font-family: consolas; color: #000000;" face="Consolas" color="#000000"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: 13pt; list-style-type: disc; margin: 0in 0in 0pt 0.5in;"&gt;&lt;span style="line-height: 12pt;"&gt;&lt;span style="font-family: consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;Event Type: Information &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: 13pt; list-style-type: disc; margin: 0in 0in 0pt 0.5in;"&gt;&lt;span style="line-height: 12pt;"&gt;&lt;span style="font-family: consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;Event Source: &lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-position: 0% 0%; mso-highlight: yellow;"&gt;&lt;span style="background-color: #ffff00;"&gt;Service Control Manager&lt;/span&gt;&lt;/span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: 13pt; list-style-type: disc; margin: 0in 0in 0pt 0.5in;"&gt;&lt;span style="line-height: 12pt;"&gt;&lt;span style="font-family: consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;Event ID: &lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-position: 0% 0%; mso-highlight: yellow;"&gt;&lt;span style="background-color: #ffff00;"&gt;7036&lt;/span&gt;&lt;/span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: 13pt; list-style-type: disc; margin: 0in 0in 0pt 0.5in;"&gt;&lt;span style="line-height: 12pt;"&gt;&lt;span style="font-family: consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;Description: &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;That validation piece is the real speed killer. So much, in fact, that it can lead to group policy processing taking many extra minutes in Windows XP when you use this class in a WMI filter - or even cause processing to time out and fail altogether.. This is even more likely when:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The client contains many installed applications&lt;/li&gt;
&lt;li&gt;Installation packages are sourced from remote file servers&lt;/li&gt;
&lt;li&gt;Install packages used certificate validation and the user cannot access the certificate revocation list for that package&lt;/li&gt;
&lt;li&gt;Your client hardware is&amp;hellip; crusty.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Furthermore, Windows Vista and later Windows versions cap WMI filters execution times at 30 seconds; if they fail to complete by then, they are treated as FALSE. On those OS versions, it will often appear that Win32_Product just doesn&amp;rsquo;t work at all.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/8713.image_5F00_327A473F.png"&gt;&lt;img width="244" height="164" title="image" style="background-image: none; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border-width: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/3010.image_5F00_thumb_5F00_1AE299CC.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;What are your alternatives?&lt;/p&gt;
&lt;h1&gt;Group Policy Preferences, maybe&lt;/h1&gt;
&lt;p&gt;Depending on what you are trying to accomplish, Group Policy Preferences could be the solution. GPP includes item-level targeting that has fast, efficient filtering of just about any criteria you can imagine. If you are trying to set some computer-based settings that a user cannot change and don&amp;rsquo;t mind preferences instead of managed policy settings, GPP is the way to go. As with all software, make sure you evaluate our latest patches to ensure it works as desired. As of this writing, those are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Win2008, Win2008 R2 - &lt;a href="http://support.microsoft.com/kb/2653810"&gt;http://support.microsoft.com/kb/2653810&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Win7 - &lt;a href="http://support.microsoft.com/kb/2561285"&gt;http://support.microsoft.com/kb/2561285&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;WinXP, Win2003 - &lt;a href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;982051"&gt;http://support.microsoft.com/default.aspx?scid=kb;EN-US;982051&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;WinVista - &lt;a href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;2526870"&gt;http://support.microsoft.com/default.aspx?scid=kb;EN-US;2526870&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For instance, let's say you have a plotting printer that Marketing cannot correctly use without special Contoso client software. Rather than using managed computer policy to control client printer installation and settings, you can use GPP Registry or Printer settings to modify the values needed.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/5670.image_5F00_3F76B801.png"&gt;&lt;img width="409" height="396" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border-width: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/5141.image_5F00_thumb_5F00_688156FD.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Then you can use Item Level Targeting to control the installation based on the specialty software's presence and version.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/3404.image_5F00_639EA341.png"&gt;&lt;img width="399" height="197" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border-width: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/7723.image_5F00_thumb_5F00_17D2CC88.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/4503.image_5F00_0E799805.png"&gt;&lt;img width="606" height="410" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border-width: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/4064.image_5F00_thumb_5F00_697BD78B.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Alternatively, you can use the registry and file system for your criteria, which works even if the software doesn't install via MSI packages:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/3021.image_5F00_649923CF.png"&gt;&lt;img width="604" height="409" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border-width: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/2844.image_5F00_thumb_5F00_0DA3C2CC.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h1&gt;An alternative to Win32_Product&lt;/h1&gt;
&lt;h3&gt;&lt;/h3&gt;
&lt;p&gt;What to do if you really, &lt;i&gt;really&lt;/i&gt; need to use a WMI filter to determine MSI installed versions and names though? If you look around the Internet, you will find a couple of older proposed solutions that - to be frank - will not work for most customers.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Use the Win32reg_AddRemovePrograms class instead.&lt;/li&gt;
&lt;li&gt;Use a custom class (like described &lt;a href="http://technet.microsoft.com/en-us/library/ee692772.aspx"&gt;here&lt;/a&gt; and frequently copied/pasted on the Interwebz).&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The Win32reg_AddRemovePrograms is not present on most client systems though; it is a legacy class, first delivered by the old SMS 2003 management WMI system. I suspect one of the reasons the System Center folks discarded its use&amp;nbsp;years ago for their own native inventory system was the same reason that the customer class above doesn&amp;rsquo;t work in #2 - it didn&amp;rsquo;t return 32-bit software installed on 64-bit computers. The class has not been updated since initial release 10 years ago.&lt;/p&gt;
&lt;p&gt;#2 had the right idea though, at least as a valid customer workaround to avoid using Win32_Product: by creating your own WMI class using the generic registry provider to examine just the MSI uninstall registry keys, you can get a fast and simple query that reasonably detects installed software. Armed with the "how", you can also extend this to any kind of registry queries you need, without risk of tanking group policy processing. To do this, you just need notepad.exe and a little understanding of WMI.&lt;/p&gt;
&lt;h2&gt;Roll Your Own Class&lt;/h2&gt;
&lt;p&gt;Windows Management Instrumentation uses &lt;a href="http://msdn.microsoft.com/en-us/library/windows/desktop/aa823192(v=vs.85).aspx"&gt;Managed Operation Framework&lt;/a&gt; (MOF) files to describe the &lt;a href="http://msdn.microsoft.com/en-us/library/windows/desktop/aa389234(v=vs.85).aspx"&gt;Common Information Model&lt;/a&gt; (CIM) classes. You can create your own MOF files and compile them into the CIM repository using a simple command-line tool called &lt;a href="http://msdn.microsoft.com/en-us/library/windows/desktop/aa392389(v=vs.85).aspx"&gt;mofcomp.exe&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;You need to be careful here. This means that once you write your MOF you should validate it by using the &lt;b&gt;mofcomp.exe&lt;/b&gt; &lt;b&gt;-check &lt;/b&gt;argument on your standard client and server images. It also means that you should test this on those same machines using the &lt;b&gt;-class:createonly &lt;/b&gt;argument (and &lt;i&gt;not&lt;/i&gt; setting the &lt;b&gt;-autorecover&lt;/b&gt; argument or &lt;b&gt;#PRAGMA AUTORECOVER&lt;/b&gt; pre-processor) to ensure it doesn't already exist. The last thing you want to do is break some other class.&lt;/p&gt;
&lt;p&gt;When done testing, you're ready to give it a go. Here is a sample MOF, wrapped for readability. Note the highlighted sections that describe what the MOF &lt;span style="background-color: #ffff00;"&gt;examines&lt;/span&gt; and what the group policy WMI filter can use as &lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-position: 0% 0%; mso-highlight: aqua;"&gt;&lt;span style="background-color: #00ffff;"&gt;query&lt;/span&gt;&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-position: 0% 0%; mso-highlight: aqua;"&gt;&lt;span&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-position: 0% 0%; mso-highlight: aqua;"&gt;&lt;span style="background-color: #00ffff;"&gt;&lt;/span&gt;&lt;/span&gt;criteria. Unlike the oft-copied sample, this one understands both the normal native architecture registry path as well as the Wow6432node path that covers 32-bit applications installed on a 64-bit system.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;i&gt;Start copy below =======&amp;gt; &lt;br /&gt;&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;span style="font-family: consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;// "AS-IS" sample MOF file for returning the two uninstall registry subkeys&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span&gt;&lt;span style="font-family: consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;// Unsupported, provided purely as a sample&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span&gt;&lt;span style="font-family: consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;// Requires compilation. Example: mofcomp.exe sampleproductslist.mof&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span&gt;&lt;span style="font-family: consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;// Implements sample classes: "SampleProductList" and "SampleProductlist32" &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span&gt;&lt;span style="font-family: consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;//&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;(for 64-bit systems with 32-bit software)&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span&gt;&lt;span style="font-family: consolas; color: #000000;" face="Consolas" color="#000000"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span&gt;&lt;span style="font-family: consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;#PRAGMA AUTORECOVER&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span&gt;&lt;span style="font-family: consolas; color: #000000;" face="Consolas" color="#000000"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span&gt;&lt;span style="font-family: consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;[dynamic, provider("RegProv"),&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span&gt;&lt;span style="font-family: consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;ProviderClsid("{fe9af5c0-d3b6-11ce-a5b6-00aa00680c3f}"),ClassContext("&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-position: 0% 0%; mso-highlight: yellow;"&gt;&lt;span style="background-color: #ffff00;"&gt;local|HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall&lt;/span&gt;&lt;/span&gt;")]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span&gt;&lt;span style="font-family: consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;class &lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-position: 0% 0%; mso-highlight: aqua;"&gt;&lt;span style="background-color: #00ffff;"&gt;SampleProductsList&lt;/span&gt;&lt;/span&gt; {&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span&gt;&lt;span style="font-family: consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;[key] string KeyName;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span&gt;&lt;span style="font-family: consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;[read, propertycontext("&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-position: 0% 0%; mso-highlight: aqua;"&gt;&lt;span style="background-color: #00ffff;"&gt;DisplayName&lt;/span&gt;&lt;/span&gt;")] string &lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-position: 0% 0%; mso-highlight: aqua;"&gt;&lt;span style="background-color: #00ffff;"&gt;DisplayName&lt;/span&gt;&lt;/span&gt;;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span&gt;&lt;span style="font-family: consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;[read, propertycontext("&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-position: 0% 0%; mso-highlight: aqua;"&gt;&lt;span style="background-color: #00ffff;"&gt;DisplayVersion&lt;/span&gt;&lt;/span&gt;")] string &lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-position: 0% 0%; mso-highlight: aqua;"&gt;&lt;span style="background-color: #00ffff;"&gt;DisplayVersion&lt;/span&gt;&lt;/span&gt;;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span&gt;&lt;span style="font-family: consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;};&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span&gt;&lt;span style="font-family: consolas; color: #000000;" face="Consolas" color="#000000"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span&gt;&lt;span style="font-family: consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;[dynamic, provider("RegProv"),&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span&gt;&lt;span style="font-family: consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;ProviderClsid("{fe9af5c0-d3b6-11ce-a5b6-00aa00680c3f}"),ClassContext("&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-position: 0% 0%; mso-highlight: yellow;"&gt;&lt;span style="background-color: #ffff00;"&gt;local|HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432node\\Microsoft\\Windows\\CurrentVersion\\Uninstall&lt;/span&gt;&lt;/span&gt;")]&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span&gt;&lt;span style="font-family: consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;class &lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-position: 0% 0%; mso-highlight: aqua;"&gt;&lt;span style="background-color: #00ffff;"&gt;SampleProductsList32&lt;/span&gt;&lt;/span&gt; {&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span&gt;&lt;span style="font-family: consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;[key] string KeyName;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span&gt;&lt;span style="font-family: consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;[read, propertycontext("&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-position: 0% 0%; mso-highlight: aqua;"&gt;&lt;span style="background-color: #00ffff;"&gt;DisplayName&lt;/span&gt;&lt;/span&gt;")] string &lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-position: 0% 0%; mso-highlight: aqua;"&gt;&lt;span style="background-color: #00ffff;"&gt;DisplayName&lt;/span&gt;&lt;/span&gt;;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span&gt;&lt;span style="font-family: consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;[read, propertycontext("&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-position: 0% 0%; mso-highlight: aqua;"&gt;&lt;span style="background-color: #00ffff;"&gt;DisplayVersion&lt;/span&gt;&lt;/span&gt;")] string &lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-position: 0% 0%; mso-highlight: aqua;"&gt;&lt;span style="background-color: #00ffff;"&gt;DisplayVersion&lt;/span&gt;&lt;/span&gt;;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span&gt;&lt;span style="font-family: consolas;" face="Consolas"&gt;&lt;span style="color: #000000;" color="#000000"&gt;};&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;i&gt;&amp;lt;======= End copy above&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;Examining this should also give you interesting ideas about other registry-to-WMI possibilities, I imagine.&lt;/p&gt;
&lt;h2&gt;Test Your Sample&lt;/h2&gt;
&lt;p&gt;Copy this sample to a text file named with a &lt;b&gt;MOF&lt;/b&gt; extension, store it in the %systemroot%\system32\wbem folder on a test machine, and then compile it from an administrator-elevated CMD prompt using &lt;b&gt;mofcomp.exe &lt;i&gt;filename&lt;/i&gt;&lt;/b&gt;. For example:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/5148.image_5F00_36AE61C8.png"&gt;&lt;img width="509" height="151" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border-width: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/7612.image_5F00_thumb_5F00_760C1558.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;To test if the sample is working you can use WMIC.EXE to list the installed MSI packages. For example, here I am on a Windows 7 x64 computer with Office 2010 installed; that suite contains both 64 and 32-bit software so I can use both of my custom classes to list out all the installed software:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/4064.image_5F00_11446E5A.png"&gt;&lt;img width="628" height="279" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border-width: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/5732.image_5F00_thumb_5F00_07EB39D7.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Note that I did not specify a namespace in the sample MOF, which means it updates the &lt;strong&gt;\\root\default&lt;/strong&gt; namespace, instead of the more commonly used &lt;strong&gt;\\root\cimv2&lt;/strong&gt; namespace. This is intentional: the Windows XP implementation of registry provider is in the Default namespace, so this makes your MOF OS agnostic. It will work perfectly well on XP, 2003, 2008, Vista, 7, or even the Windows 8 family. Moreover, I don&amp;rsquo;t like updating the CIMv2 namespace if I can avoid it - it already has enough classes and is a bit of a dumping ground.&lt;/p&gt;
&lt;h2&gt;Deploy Your Sample&lt;/h2&gt;
&lt;p&gt;Now I need a way to get this MOF file to all my computers. The easiest way is to return to Group Policy Preferences; create a GPP policy that copies the file and creates a scheduled task to run MOFCOMP at every boot up (you can change this scheduling later or even turn it off, once you are confident all your computers have the new classes).&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/8787.image_5F00_3089A5DE.png"&gt;&lt;img width="586" height="275" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border-width: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/0250.image_5F00_thumb_5F00_7290151F.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/8875.image_5F00_498806D4.png"&gt;&lt;img width="557" height="460" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border-width: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/0841.image_5F00_thumb_5F00_52779913.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/3073.image_5F00_3F566C67.png"&gt;&lt;img width="349" height="158" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border-width: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/5226.image_5F00_thumb_5F00_2177E866.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/5127.image_5F00_43CF7DDF.png"&gt;&lt;img width="408" height="259" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border-width: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/4150.image_5F00_thumb_5F00_5F07D6E0.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;You can also install and compile the MOF manually, use psexec.exe, make it part of your standard OS image, deploy it using a software distribution system, or whatever. The example above is just that - an example.&lt;/p&gt;
&lt;p&gt;Now that all your computers know about your new WMI class, you can create a group policy WMI filter that uses it. Here are a couple examples; note that I remembered to change the namespace from CIMv2 to DEFAULT!&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/7271.image_5F00_282D829A.png"&gt;&lt;img width="429" height="113" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border-width: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/1423.image_5F00_thumb_5F00_20A2132D.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/2313.image_5F00_5BF578EB.png"&gt;&lt;img width="473" height="335" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border-width: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/8345.image_5F00_thumb_5F00_79D68D9D.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/5611.image_5F00_0DEFAA27.png"&gt;&lt;img width="475" height="338" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border-width: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/8838.image_5F00_thumb_5F00_36FA4923.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;You're in business with a system that, while not optimal, is certainly is far better than Win32_Product. It&amp;rsquo;s fast and lightweight, relatively easy to manage, and like all adequate solutions, designed not to make things worse in its efforts to make things different.&lt;/p&gt;
&lt;h1&gt;And another idea (updated 4/23)&lt;/h1&gt;
&lt;p&gt;AskDS contributor &lt;a href="http://blogs.technet.com/b/askds/archive/tags/fabian+muller/"&gt;Fabian M&amp;uuml;ller&lt;/a&gt;&amp;nbsp;had another idea that he uses with customers:&lt;/p&gt;
&lt;p&gt;1.&amp;nbsp;Define environment variables using GPP based on Registry Item-Level targeting filters or just deploy the variables during software installation phase, e.g. &lt;b&gt;&lt;i&gt;%IEversion%= 9&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;2.&amp;nbsp;Use this environment variable in WMI filters like this: &lt;b&gt;&lt;i&gt;Root\CIMV2;SELECT VARIABLEVALUE FROM Win32_Environment WHERE NAME='IEversion' AND VARIABLEVALUE='9'&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;Disadvantage: First computer start or user logon will not pass the WMI filter since the ENV variable had to be created (if set by GPP). It would be better having this environment variable being created during softwareinstallation / deployment (or whatever software being deployed).&lt;/p&gt;
&lt;p&gt;Advantage: The environment WMI&amp;nbsp;query&amp;nbsp;is very fast compared. And you can use it &amp;ldquo;multi-purpose&amp;rdquo;. For example,&amp;nbsp;as part of CMD-based startup and logon scripts.&lt;/p&gt;
&lt;h1&gt;An aside&lt;/h1&gt;
&lt;p&gt;Software Installation policy is not designed to be an enterprise software management solution and neither are individual application self-update systems. SI works fine in a small business network as a "no frills" solution but doesn&amp;rsquo;t offer real monitoring or remediation, and requires too much of the administrator to manage. If you are using these because of the old "we only fix IT when it's broken" answer, one argument you might take to management is that you &lt;i&gt;are &lt;/i&gt;broken and operating at great risk: you have no way to deploy non-Microsoft updates in a timely and reliable fashion.&lt;/p&gt;
&lt;p&gt;Even though the free Windows Update and &lt;a href="http://technet.microsoft.com/en-us/wsus/bb332157"&gt;Windows Software Update Service&lt;/a&gt; support Windows, Office, SQL, and Exchange patching, it&amp;rsquo;s probably not enough; anyone with more than five minutes in the IT industry knows that &lt;b&gt;&lt;i&gt;all&lt;/i&gt;&lt;/b&gt; of your software should be receiving periodic security updates. Does anyone here still think it's safe to run &lt;a href="http://www.adobe.com/support/security/"&gt;Adobe&lt;/a&gt;, &lt;a href="http://www.oracle.com/technetwork/topics/security/alerts-086861.html"&gt;Oracle&lt;/a&gt;, or &lt;a href="http://secunia.com/community/advisories/vendor/"&gt;thousands of other vendor products&lt;/a&gt; without controlled, monitored, and managed patching? If your network doesn't have a real software patching system, it's like a building with no sprinklers or emergency exits: nothing to worry about&amp;hellip; &lt;i&gt;until there's a fire&lt;/i&gt;. You wouldn&amp;rsquo;t run computers without anti-virus protection, but the number of customers I speak to that have zero security patching strategy is very worrying.&lt;/p&gt;
&lt;p&gt;It's not 1998 anymore, folks. A software and patch management system isn&amp;rsquo;t an option anymore if you have a business with more than a hundred computers; those days are done for everyone. &lt;a href="http://www.forbes.com/sites/andygreenberg/2012/04/09/apple-snubs-firm-who-discovered-mac-botnet-tries-to-cut-off-its-server-monitoring-infections/"&gt;Even for Apple, although they haven't realized it yet&lt;/a&gt;. We make &lt;a href="http://www.microsoft.com/en-us/server-cloud/system-center/default.aspx"&gt;System Center,&lt;/a&gt; but there are other vendors out there too, and I&amp;rsquo;d rather you bought a competing product than have no patch management at all.&lt;/p&gt;
&lt;p&gt;Until next time,&lt;/p&gt;
&lt;p&gt;- Ned "pragma-tism" Pyle&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3493233" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/askds/archive/tags/group+policy/">group policy</category><category domain="http://blogs.technet.com/b/askds/archive/tags/WMI/">WMI</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Ned+Pyle/">Ned Pyle</category></item><item><title>Exclusive! Shocking New Windows Names Revealed!!!</title><link>http://blogs.technet.com/b/askds/archive/2012/04/17/exclusive-shocking-new-windows-names-revealed.aspx</link><pubDate>Tue, 17 Apr 2012 16:02:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3492671</guid><dc:creator>NedPyle [MSFT]</dc:creator><slash:comments>13</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/rsscomments.aspx?WeblogPostID=3492671</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/commentapi.aspx?WeblogPostID=3492671</wfw:comment><comments>http://blogs.technet.com/b/askds/archive/2012/04/17/exclusive-shocking-new-windows-names-revealed.aspx#comments</comments><description>&lt;p&gt;Ok, that might have been a slightly inflammatory and misleading title.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Windows 8 is now officially called... &lt;a href="http://windowsteamblog.com/windows/b/bloggingwindows/archive/2012/04/16/announcing-the-windows-8-editions.aspx"&gt;Windows 8&lt;/a&gt;. The full set of edition names&amp;nbsp;are Windows 8, Windows 8 Pro, Windows RT (that's WOA), and Windows 8 Enterprise. Brandon Leblanc has the full &lt;a href="http://windowsteamblog.com/windows/b/bloggingwindows/archive/2012/04/16/announcing-the-windows-8-editions.aspx"&gt;breakout&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Windows Server "8" is now officially called... &lt;a href="http://www.microsoft.com/en-us/news/press/2012/apr12/04-17MMSDay1PR.aspx"&gt;Windows Server 2012&lt;/a&gt;. You can read more about the strategy from Brad Anderson &lt;a href="http://blogs.technet.com/b/server-cloud/archive/2012/04/17/the-evolving-role-of-it-as-cloud-innovator.aspx"&gt;here&lt;/a&gt;. Editions to follow at a later time.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;That server name also tells you two things: One, if you had bet &lt;em&gt;against&lt;/em&gt; that name in the office pool, you are a born loser. Two, that we may make radical changes in OS capabilities, but when it comes to server branding, we are more conservative than a prom chaperon. Who is also a nun.&amp;nbsp;And voted libertarian. In Switzerland.&lt;/p&gt;
&lt;p&gt;Back to work, you!&lt;/p&gt;
&lt;p&gt;&amp;nbsp;- Ned "Ned Pyle" Pyle&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3492671" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/askds/archive/tags/Other+Blogs/">Other Blogs</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Windows+8/">Windows 8</category><category domain="http://blogs.technet.com/b/askds/archive/tags/windows+server+2012/">windows server 2012</category></item><item><title>Saturday Mail Sack: Because it turns out, Friday night was alright for fighting edition</title><link>http://blogs.technet.com/b/askds/archive/2012/04/14/saturday-mail-sack-because-it-turns-out-friday-night-was-alright-for-fighting.aspx</link><pubDate>Sat, 14 Apr 2012 23:57:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3492204</guid><dc:creator>NedPyle [MSFT]</dc:creator><slash:comments>4</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/rsscomments.aspx?WeblogPostID=3492204</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/commentapi.aspx?WeblogPostID=3492204</wfw:comment><comments>http://blogs.technet.com/b/askds/archive/2012/04/14/saturday-mail-sack-because-it-turns-out-friday-night-was-alright-for-fighting.aspx#comments</comments><description>&lt;p&gt;Hello all, &lt;a href="http://blogs.technet.com/b/askds/archive/tags/Ned+Pyle/"&gt;Ned&lt;/a&gt; here again with our first mail sack in a couple months. I have enough content built up here that I actually created multiple posts, which means I can personally guarantee there will be another one next week. Unless there isn't!&lt;/p&gt;
&lt;p&gt;Today we answer your questions around:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#wmi"&gt;Detecting virtual machines with WMI Filters for group policy processing&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#dns"&gt;Windows Server "8" Beta automatic DNS installation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#disable"&gt;Disabling a user on all DCs (with a visit from Windows Server "8" Beta)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#dfsr"&gt;Avoiding security change replication storms in DFSR (and another visit from Windows Server "8" Beta)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#invalidenumeration"&gt;The mystery of Windows PowerShell's "invalid enumeration context"&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#lock"&gt;DFSR and the chance for in-use files&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#usmtoff"&gt;USMT and partial offline migration&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#cert"&gt;Why you shouldn't change computer certificate storage permissions&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#usmtconfig"&gt;USMT and mixing config files&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#other"&gt;The usual rounds of "other stuff"&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;One side note: as I was groveling old responses, I came across a handful of emails I'd overlooked and never responded to; &lt;i&gt;&amp;lt;insert various excuses here&amp;gt;&lt;/i&gt;. People who know me know that I don&amp;rsquo;t ignore email lightly. Even if I hadn't the foggiest idea how to help, I'd have at least responded with a "&lt;i&gt;Duuuuuuuuuuurrrrrrrr, no clue, sorry&lt;/i&gt;".&lt;/p&gt;
&lt;p&gt;Therefore, I'll make you deal: if you sent us an email in the past few months &lt;i&gt;and never heard back,&lt;/i&gt; please resend your question and I'll answer them as best I can. That way I don&amp;rsquo;t spend cycles answering something you already figured out later, but if you&amp;rsquo;re still stuck, you have another chance. Sorry about all that - what with Windows 8 work, writing our internal support engineer training, writing public content, Jonathan having some kind of south pacific death flu, and presenting at internal conferences&amp;hellip; well, only the usual insane Microsoft Office clipart can sum up why we missed some of your questions:&lt;/p&gt;
&lt;p align="center"&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/4530.clip_5F00_image002_5F00_6ED7D42B.jpg"&gt;&lt;img width="309" height="205" title="clip_image002" style="border: 0px currentcolor; display: inline; background-image: none;" alt="clip_image002" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/4540.clip_5F00_image002_5F00_thumb_5F00_2A2B39EA.jpg" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;On to the goods!&lt;/p&gt;
&lt;h1&gt;&lt;a name="wmi"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;Is it possible to create a &lt;a href="http://blogs.technet.com/b/askds/archive/2008/09/11/fun-with-wmi-filters-in-group-policy.aspx"&gt;WMI Filter&lt;/a&gt; that detects only virtual machines? We want a group policy that will apply specifically to our virtualized guests.&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;Totally possible for Hyper-V virtual machines: You can use the WMI class &lt;b&gt;Win32_ComputerSystem&lt;/b&gt; with a property of &lt;b&gt;Model&lt;/b&gt; like &amp;ldquo;&lt;b&gt;Virtual Machine&lt;/b&gt;&amp;rdquo; and property &lt;b&gt;Manufacturer&lt;/b&gt; of &amp;ldquo;&lt;b&gt;Microsoft Corporation&lt;/b&gt;&amp;rdquo;. You can also use class &lt;b&gt;Win32_BaseBoard&lt;/b&gt; for the &lt;b&gt;Product&lt;/b&gt; property, which will be &amp;ldquo;&lt;b&gt;Virtual Machine&lt;/b&gt;&amp;rdquo; and property &lt;b&gt;Manufacturer&lt;/b&gt; that will be &amp;ldquo;&lt;b&gt;Microsoft Corporation&lt;/b&gt;&amp;rdquo;.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/1374.image_5F00_42BAD73A.png"&gt;&lt;img width="476" height="340" title="image" style="display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/7242.image_5F00_thumb_5F00_542B3812.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Technically speaking, this might also capture Virtual PC machines, but I don&amp;rsquo;t have one handy to see, and I doubt you are allowing those to handle production workloads anyway. As for EMC VMWare, Citrix Xen, KVM, Oracle Virtual Box, etc. you&amp;rsquo;ll have to see what shows for &lt;b&gt;Win32_BaseBoard/Win32_ComputerSystem&lt;/b&gt; in those cases and make sure your WMI filter looks for that too. I don&amp;rsquo;t have any way to test them, and even if I did, I'd still make you do it out of spite. Gimme money!&lt;/p&gt;
&lt;p&gt;Which reminds me - &lt;a href="http://www.vm-limited.com/"&gt;Tad is back&lt;/a&gt;:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://www.vm-limited.com/"&gt;&lt;img width="628" height="147" title="image" style="display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/0724.image_5F00_1388EBA3.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h1&gt;&lt;a name="dns"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;The &lt;a href="http://www.microsoft.com/download/en/details.aspx?id=29019"&gt;Understand and Troubleshoot AD DS Simplified Administration in Windows Server "8" Beta&lt;/a&gt; guide states:&lt;/p&gt;
&lt;p&gt;&lt;i&gt;Microsoft recommends that all domain controllers provide DNS and GC services for high availability in distributed environments; these options default to on when installing a domain controller in any mode or domain. &lt;/i&gt;&lt;/p&gt;
&lt;p&gt;But when I run &lt;b&gt;Install-ADDSDomainController -DomainName corp.contoso.com -whatif &lt;/b&gt;it returns that the cmdlet will not install the DNS Server (&lt;b&gt;DNS Server: No&lt;/b&gt;).&lt;/p&gt;
&lt;p&gt;If Microsoft recommends that all domain controllers provide DNS, why do I need to specify &lt;b&gt;-InstallDNS &lt;/b&gt;argument?&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;The output of &lt;b&gt;DNS Server: No&lt;/b&gt; is a cosmetic issue with the output of &lt;b&gt;-whatif&lt;/b&gt;. It should say &lt;b&gt;YES&lt;/b&gt;, but doesn't unless you specifically use the &lt;b&gt;$true&lt;/b&gt; parameter. You don't have to specify &lt;b&gt;-installdns&lt;/b&gt;; the cmdlet will automatically* install DNS server unless you specify &lt;b&gt;-installdns:$false&lt;/b&gt;.&lt;/p&gt;
&lt;p&gt;* If you are using Windows DNS on domain controllers, that is. The UTG isn't totally accurate in this version (but will be in the next). The logic is that if that domain already hosts the DNS, all subsequent DCs will also host the DNS by default. So to be&amp;nbsp;very specific:&lt;/p&gt;
&lt;p&gt;1. New forest: always install DNS&lt;br /&gt;2. New child or new tree domain: if the parent/tree domain hosts DNS, install DNS&lt;br /&gt;3. Replica: if the current domain hosts DNS, install DNS&lt;/p&gt;
&lt;h1&gt;&lt;a name="disable"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;How can I disable a user on all domain controllers, without waiting for (or forcing) AD replication?&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;The universal in-box way that works in all operating systems would be to use DSMOD.EXE USER and feed it the DC names in a list. For example:&lt;/p&gt;
&lt;p&gt;1. Create a text file that contains all your DC in a forest, in a line-separated list:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;2008r2-01 &lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;2008r2-02&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;2. Run a FOR loop command to read that list and disable the specified user against each domain controller.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;FOR /f %i IN (some text file) DO dsmod user "&lt;i&gt;some DN&lt;/i&gt;" -disabled -yes -s %i&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;For instance:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/0218.image_5F00_6B763C83.png"&gt;&lt;img width="602" height="224" title="image" style="display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/5078.image_5F00_thumb_5F00_4A82C9DC.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;You also have the AD PowerShell option in your Win2008 R2 DC environment, and it&amp;rsquo;s much easier to automate and maintain. You just tell it the domain controllers' OU and the user and let it rip:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;get-adcomputer -searchbase "&lt;i&gt;your DC OU&lt;/i&gt;" -filter * | foreach {disable-adaccount "&lt;i&gt;user logon ID&lt;/i&gt;" -server $_.dnshostname}&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;For instance:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/6253.image_5F00_109386F0.png"&gt;&lt;img width="628" height="92" title="image" style="display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/5584.image_5F00_thumb_5F00_28B6F14B.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;If you weren't strictly opposed to AD replication (short circuiting it like this isn't going to stop eventual replication traffic) you can always disable the user on one DC then force just that single object to replicate to all the other DCs. Check out &lt;a href="http://technet.microsoft.com/en-us/library/cc811569(v=WS.10).aspx"&gt;repadmin /replsingleobj &lt;/a&gt; or the new Windows Server "8" Beta " &lt;a href="http://technet.microsoft.com/en-us/library/hh852296.aspx"&gt;sync-adobject&lt;/a&gt; cmdlet.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/0878.image_5F00_06EEF8ED.png"&gt;&lt;img width="443" height="76" title="image" style="display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/4251.image_5F00_thumb_5F00_6667B93A.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&amp;nbsp;The Internet also has many further thoughts on this. It's a very opinionated place.&lt;/p&gt;
&lt;h1&gt;&lt;a name="dfsr"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;We have found that modifying the security on a DFSR replicated folder and its contents causes a big DFSR replication backlog. We need to make these permissions changes though; is there any way to avoid that backlog?&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;Not the way you are doing it. DFSR has to replicate changes and you are changing every single file; after all, how can you trust a replication system that does not replicate? You could consider changing permissions "from the bottom up" - where you modify perms on lower level folders first - in some sort of staged fashion to minimize the amount of replication that has to occur, but it just sounds like a recipe to get things wrong or end up replicating things twice, making it worse. You will just have to bite the bullet in Windows Server 2008 R2 and older DFSR. Do it on a weekend and next time, treat this as a lesson learned and plan your security design better so that all of your user base fits into the model using groups.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;However&amp;hellip;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;It is a &lt;i&gt;completely&lt;/i&gt; different story if you switch to Windows Server "8" Beta - well really, the RTM version when it ships. There you can use &lt;a href="http://technet.microsoft.com/en-us/library/hh831425.aspx"&gt;Central Access Policies &lt;/a&gt;(similar to Windows Server 2008 R2's global object access auditing). This new kind of security system is part of the &lt;a href="http://technet.microsoft.com/en-us/library/hh831717.aspx"&gt;Dynamic Access Control&lt;/a&gt; feature and abstracts the user access from NTFS, meaning you can change security using claims policy and not actually change the files on the disk. It's amazing stuff; in my opinion, DAC is the first truly huge change in Windows file access control since Windows NT gave us NTFS.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/7120.image_5F00_55CBDE19.png"&gt;&lt;img width="593" height="228" title="image" style="border: 0px currentcolor; display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/7536.image_5F00_thumb_5F00_012FFF14.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Central Access Policy is not a trivial thing to implement, but this is the future of file servers. Admins should seriously evaluate this feature when testing Windows Server "8" Beta in their lab environments and thinking about future designs. Our very own Mike Stephens has written at length about this in the &lt;a href="http://www.microsoft.com/download/en/details.aspx?id=29023"&gt;Understand and Troubleshoot Dynamic Access Control in Windows Server "8" Beta&lt;/a&gt; guide as well.&lt;/p&gt;
&lt;h1&gt;&lt;a name="invalidenumeration"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;&lt;i&gt;[Perhaps interestingly to you the reader, this was &lt;b&gt;my&lt;/b&gt; question to the developers of AD PowerShell. I don&amp;rsquo;t know everything after all&amp;hellip; - Ned]&lt;/i&gt;&lt;/p&gt;
&lt;p&gt;I am periodically seeing error "invalid enumeration context" when querying the Redmond domain using &lt;strong&gt;get-adcomputer&lt;/strong&gt;. It&amp;rsquo;s a simple query to return all the active Windows 8 and Windows Server "8" computers that were logged into since February 15&lt;sup&gt;th&lt;/sup&gt; and write them to a CSV file:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/7711.image_5F00_2B2FFD3C.png"&gt;&lt;img width="680" height="106" title="image" style="display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/0361.image_5F00_thumb_5F00_7140BA4F.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;It runs for quite a while and sometimes works, sometimes fails. I don&amp;rsquo;t find any well-explained reference to what this error means or how to avoid it, but it smells like a &amp;ldquo;too much data asked for over too long a period of time&amp;rdquo; kind of issue.&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;The enumeration contexts do have a finite hardcoded lifetime and you will get an error if they expire. You might see this error when executing searches that search a huge quantity of data using limited indexed attributes and return a small data set. If we hit a DC that is not very busy then the query will run faster and could have enough time to complete for a big dataset like this query. Server hardware would also be a factor here. You can also try searching starting at a deeper level. You could also tweak the indexes, although obviously not in this case.&lt;/p&gt;
&lt;p&gt;&lt;i&gt;[For those interested, when the query worked, it returned roughly 75,000 active Windows 8 family machines from that domain alone. Microsoft dogfoods in production like nobody else, baby - Ned]&lt;/i&gt;&lt;/p&gt;
&lt;h1&gt;&lt;a name="lock"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;Is there any chance that DFSR could lock a file while it is replicating outbound and prevent user access to their data?&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;DFSR uses the &lt;a href="http://blogs.technet.com/b/askds/archive/2010/12/12/3373040.aspx#dfsrperm"&gt;BackupRead()&lt;/a&gt; function when copying a file into the staging folder (i.e. any file over 64KB, by default), so that should prevent any &amp;ldquo;file in use&amp;rdquo; issues with applications or users; the file "copying" to the staging folder is effectively instantaneous and non-exclusive. Once staged and marshaled, the copy of the file is replicated and no user has any access to that version of the file.&lt;/p&gt;
&lt;p&gt;For a file under 64KB, it is simply replicated without staging and that operation of making a copy and sending it into RPC is so fast there&amp;rsquo;s no reasonable way for anyone to ever see any issues there. I have certainly never seen it, for sure, and&amp;nbsp;I should have by now after six years.&lt;/p&gt;
&lt;h1&gt;&lt;a name="usmtoff"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;Why does TechNet &lt;a href="http://technet.microsoft.com/en-us/library/dd560792(v=ws.10).aspx"&gt;state&lt;/a&gt; that USMT 4.0 offline migrations don&amp;rsquo;t work for certain OS settings? How do I figure out the complete list?&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;Manifests that use migration plugin DLLs aren&amp;rsquo;t processed when running offline migrations. It's just a by design limitation of USMT and not a bug or anything. To see which manifests you need to examine and consider creating custom XML to handle, review the complete list at &lt;a href="http://blogs.technet.com/b/askds/archive/2011/08/15/understanding-what-the-usmt-4-0-config-manifests-migrate-part-1.aspx"&gt;Understanding what the USMT 4.0 CONFIG manifests migrate (Part 1: Introduction)&lt;/a&gt;.&lt;/p&gt;
&lt;h1&gt;&lt;a name="cert"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;One of my customers has found that the "Everyone" group is added to the below folders in Windows 2003 and Windows 2008:&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Windows Server 2008&lt;/b&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;C:\ProgramData\Microsoft\Crypto\DSS\MachineKeys&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;C:\ProgramData\Microsoft\Crypto/RSA\MachineKeys&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;b&gt;Windows Server 2003&lt;/b&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\DSS\MachineKeys&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;1. Can we remove the "Everyone" group and give permissions to another group like - Authenticated users for example?&lt;/p&gt;
&lt;p&gt;2. Will replacing that default cause issues?&lt;/p&gt;
&lt;p&gt;3. Why is this set like this by default?&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;&lt;i&gt;[Courtesy of:&lt;/i&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/8284.image_5F00_7E3A9A60.png"&gt;&lt;img width="128" height="164" title="image" style="display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/3021.image_5F00_thumb_5F00_21878F06.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;em&gt;]&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;These permissions are intentional. They are intended to allow any process to generate a new private key, even an Anonymous one. You'll note that the permissions on the &lt;b&gt;MachineKeys&lt;/b&gt; folder are limited to the folder only. Also, you should note that inheritance has been disabled, so the permissions on the MachineKeys folder will not propagate to new files created therein. Finally, the key generation code itself modifies the permissions on new key container files before the private key is actually written to the container file.&lt;/p&gt;
&lt;p&gt;In short, messing with these permissions will probably lead to failures in creating or accessing keys belonging to the computer. So please don't touch them.&lt;/p&gt;
&lt;p&gt;1. Exchanging &lt;b&gt;Authenticated Users&lt;/b&gt; with &lt;b&gt;Everyone&lt;/b&gt; &lt;i&gt;probably&lt;/i&gt; won't cause any problems. Microsoft, however, doesn't test cryptographic operations after such a permission change; therefore, we cannot predict what will happen in all cases.&lt;/p&gt;
&lt;p&gt;2. See my answer above. We haven't tested it. We have, however, been performing periodic security reviews of the default Windows system permissions, tightening them where possible, for the last decade. The default &lt;b&gt;Everyone&lt;/b&gt; permissions on the MachineKeys folder have cleared several of these reviews.&lt;/p&gt;
&lt;p&gt;3. In local operations, &lt;b&gt;Everyone&lt;/b&gt; includes unidentified or anonymous users. The theory is that we always want to allow a process to generate a private key. When the key container is actually created and the key written to it, the permissions on the key container file are updated with a completely different set of default permissions. All the default permissions allow are the ability to create a file, read and write data. The permissions do not allow any process except System to launch any executable code.&lt;/p&gt;
&lt;h1&gt;&lt;a name="usmtconfig"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;If I specify a USMT 4.0 &lt;b&gt;config.xml&lt;/b&gt; child node to prevent migration, I am still seeing the settings migrate. But if I set the parent node, those settings do not migrate. The consequence being that &lt;i&gt;no child nodes&lt;/i&gt; &lt;i&gt;migrate&lt;/i&gt;, which I do not want.&lt;/p&gt;
&lt;p&gt;For example, on XP the Dot3Svc service is set to Manual startup.&amp;nbsp; On Win7, I want the Dot3Svc service set to Automatic startup.&amp;nbsp; If I use this config.xml on the loadstate, the service is set to manual like the XP machine and my "no" setting is ignored:&lt;/p&gt;
&lt;blockquote&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;/span&gt;
&lt;p style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;&amp;lt;&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;component&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt; &lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;displayname&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;="Networking Connections"&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt; &lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;migrate&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;="yes"&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;ID&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;="network_and_internet\networking_connections"&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;/span&gt;
&lt;p style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;&amp;lt;&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;component&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt; &lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;displayname&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;="Microsoft-Windows-Wlansvc"&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt; &lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;migrate&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;="yes"&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;ID&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;="&lt;/span&gt;&lt;span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast;"&gt;&amp;lt;snip&amp;gt;&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;"/&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;/span&gt;
&lt;p style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;&amp;lt;&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;component&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt; &lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;displayname&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;="Microsoft-Windows-VWiFi"&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt; &lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;migrate&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;="yes"&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;ID&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;="&lt;/span&gt;&lt;span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast;"&gt;&amp;lt;snip&amp;gt;&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;"/&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;/span&gt;
&lt;p style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;&amp;lt;&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;component&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt; &lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;displayname&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;="Microsoft-Windows-RasConnectionManager"&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt; &lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;migrate&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;="yes"&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;ID&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;="&lt;/span&gt;&lt;span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast;"&gt;&amp;lt;snip&amp;gt;&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;"/&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;/span&gt;
&lt;p style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;&amp;lt;&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;component&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt; &lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;displayname&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;="Microsoft-Windows-RasApi"&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt; &lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;migrate&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;="yes"&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;ID&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;="&lt;/span&gt;&lt;span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast;"&gt;&amp;lt;snip&amp;gt;&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;"/&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;/span&gt;
&lt;p style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;&amp;lt;&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;component&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt; &lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;displayname&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;="Microsoft-Windows-PeerToPeerCollab"&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt; &lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;migrate&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;="yes"&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;ID&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;="&lt;/span&gt;&lt;span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast;"&gt;&amp;lt;snip&amp;gt;&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;"/&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;/span&gt;
&lt;p style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;&amp;lt;&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;component&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt; &lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;displayname&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;="Microsoft-Windows-Native-80211"&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt; &lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;migrate&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;="yes"&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;ID&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;="&lt;/span&gt;&lt;span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast;"&gt;&amp;lt;snip&amp;gt;&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;"/&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;/span&gt;
&lt;p style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;&amp;lt;&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;component&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt; &lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;displayname&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;="Microsoft-Windows-MPR"&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt; &lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;migrate&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;="yes"&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;ID&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;="&lt;/span&gt;&lt;span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast;"&gt;&amp;lt;snip&amp;gt;&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;"/&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;/span&gt;
&lt;p style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;&amp;lt;&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;component&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt; &lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;displayname&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;="Microsoft-Windows-Dot3svc"&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt; &lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box; mso-highlight: yellow;"&gt;migrate&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box; mso-highlight: yellow;"&gt;=&lt;span style="background-color: #ffff00;"&gt;"no"&lt;/span&gt;&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box; mso-highlight: yellow;"&gt;&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;ID&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;="&lt;/span&gt;&lt;span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: major-fareast;"&gt;&amp;lt;snip&amp;gt;&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;"/&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;/span&gt;
&lt;p style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;&amp;lt;/&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;component&lt;/span&gt;&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box;"&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;Two different configurations can cause this symptom:&lt;/p&gt;
&lt;p&gt;1. You are using a config.xml file created on Windows 7, then running it on a Windows XP computer with scanstate /config&lt;/p&gt;
&lt;p&gt;2. The source computer was Windows XP and it did not have a config.xml file set to block migration.&lt;/p&gt;
&lt;p&gt;When coming &lt;i&gt;from&lt;/i&gt; XP, where downlevel manifests were used, loadstate does not process those differently-named child nodes on the destination Win7 computer. So while the parent node set to NO would work, the child nodes would not, as they have different displayname and ID.&lt;/p&gt;
&lt;p&gt;It&amp;rsquo;s a best practice to use a config.xml in scanstate as described in &lt;a href="http://support.microsoft.com/kb/2481190"&gt;http://support.microsoft.com/kb/2481190&lt;/a&gt;, if going from x86 to x64; otherwise, you end up with damaged COM settings. Otherwise, you only need to generate per-OS config.xml files if you plan to change default behavior. All the manifests run by default if there is a config.xml with no modifications or if there is no config.xml at all.&lt;/p&gt;
&lt;p&gt;Besides being required for XP to block settings, you should also definitely lean towards using config.xml on the scanstate rather than the loadstate. If using Vista to Vista, Vista to 7, or 7 to 7, you could use the config.xml on either side, but I&amp;rsquo;d still recommend sticking with the scanstate; it&amp;rsquo;s typically better to block migration from adding things to the store, as it will be faster and leaner.&lt;/p&gt;
&lt;h1&gt;&lt;a name="other"&gt;&lt;/a&gt;Other Stuff&lt;/h1&gt;
&lt;p&gt;&lt;i&gt;[Many courtesy of our pal &lt;a href="http://blogs.technet.com/b/markmoro/"&gt;Mark Morowczynski &lt;/a&gt; -Ned]&lt;/i&gt;&lt;/p&gt;
&lt;p&gt;Happy belated 175&lt;sup&gt;th&lt;/sup&gt; birthday Chicago. &lt;a href="http://www.suntimes.com/11008357-417/from-twinkies-to-yellow-pencils-175-years-of-firsts-in-chicago.html"&gt;Here's a list of things you can thank us for&lt;/a&gt;, planet Earth; where would you be without your precious Twinkies!?&lt;/p&gt;
&lt;p&gt;Speaking of Chicago&amp;hellip;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;iframe width="560" height="315" src="http://www.youtube.com/embed/mtxo4BnYzro" frameborder="0" allowfullscreen="allowfullscreen"&gt;&lt;/iframe&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;All the new &lt;a href="http://www.microsoft.com/learning/en/us/certification/mcse.aspx"&gt;MCSE&lt;/a&gt; and certification news reminded me of the &lt;a href="http://www.dreichel.com/Articles/Dr_Zoe.htm"&gt;other side to that coin&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Do you know where your nearest gun store is located? &lt;a href="http://www.mapofthedead.com/"&gt;Map of the Dead does&lt;/a&gt;. Review now; it will be too late when the zombies rise from their graves, and I don't plan to share my bunker, Jim.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://www.mapofthedead.com/"&gt;&lt;img width="604" height="337" title="image" style="display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/0755.image_5F00_7C89CE8C.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;If you call yourself an IT Pro, you owe it to yourself to visit &lt;a href="http://www.moviecarposters.com/"&gt;moviecarposters.com&lt;/a&gt; right now and buy&amp;hellip; everything. They make great alpha geek conversation pieces. To get things started, I recommend these:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/0336.clip_5F00_image0026_5F00_3EAD3710.jpg"&gt;&lt;img width="175" height="267" title="clip_image002[6]" style="display: inline; background-image: none;" alt="clip_image002[6]" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/8284.clip_5F00_image0026_5F00_thumb_5F00_12FC6D14.jpg" border="0" /&gt;&lt;/a&gt; &lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/6138.clip_5F00_image004_5F00_395E505F.jpg"&gt;&lt;img width="175" height="267" title="clip_image004" style="display: inline; background-image: none;" alt="clip_image004" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/6786.clip_5F00_image004_5F00_thumb_5F00_3CFC6B3C.jpg" border="0" /&gt;&lt;/a&gt; &lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/0250.clip_5F00_image006_5F00_186ADDB8.jpg"&gt;&lt;img width="176" height="267" title="clip_image006" style="display: inline; background-image: none;" alt="clip_image006" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/5226.clip_5F00_image006_5F00_thumb_5F00_29DB3E90.jpg" border="0" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;a href="http://nerdapproved.com/news/joss-whedon-depresses-us-all-with-the-harsh-reality-of-trying-to-bring-firefly-back/"&gt;&lt;span style="font-size: xx-small;" size="1"&gt;Sigh - there is never going to be another Firefly&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;And finally&amp;hellip;&lt;/p&gt;
&lt;p&gt;I started re-reading &lt;a href="http://www.amazon.com/s/ref=sr_tc_2_0?rh=i%3Astripbooks%2Ck%3ATerry+Pratchett&amp;amp;keywords=Terry+Pratchett&amp;amp;ie=UTF8&amp;amp;qid=1334444129&amp;amp;sr=1-2-ent&amp;amp;field-contributor_id=B000AQ0NN8"&gt;Terry Pratchett&lt;/a&gt;, picking up where from where I left off as a kid. Hooked again. Damn you English writers, with your understated awesomeness!&lt;/p&gt;
&lt;p&gt;Ok, maybe not &lt;i&gt;all&lt;/i&gt; English Writers&amp;hellip;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/6204.image_5F00_3B4B9F68.png"&gt;&lt;img width="604" height="345" title="image" style="display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/7776.image_5F00_thumb_5F00_149D131B.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Until next time,&lt;/p&gt;
&lt;p&gt;- Ned "Jonathan is seriously going to kill me" Pyle&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3492204" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/askds/archive/tags/group+policy/">group policy</category><category domain="http://blogs.technet.com/b/askds/archive/tags/DFSR/">DFSR</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Authorization/">Authorization</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Certificates/">Certificates</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Security/">Security</category><category domain="http://blogs.technet.com/b/askds/archive/tags/WMI/">WMI</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Silly+Rabbit/">Silly Rabbit</category><category domain="http://blogs.technet.com/b/askds/archive/tags/AD+Replication/">AD Replication</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Windows+7/">Windows 7</category><category domain="http://blogs.technet.com/b/askds/archive/tags/DNS/">DNS</category><category domain="http://blogs.technet.com/b/askds/archive/tags/PowerShell/">PowerShell</category><category domain="http://blogs.technet.com/b/askds/archive/tags/USMT/">USMT</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Windows+XP/">Windows XP</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Mail+Sack/">Mail Sack</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Disks+and+NTFS/">Disks and NTFS</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Jonathan+Stephens/">Jonathan Stephens</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Ned+Pyle/">Ned Pyle</category><category domain="http://blogs.technet.com/b/askds/archive/tags/gpmc/">gpmc</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Windows+8/">Windows 8</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Dynamic+Access+Control/">Dynamic Access Control</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Central+Access+Policy/">Central Access Policy</category></item><item><title>New USMT 5.0 Features for Windows 8 Consumer Preview</title><link>http://blogs.technet.com/b/askds/archive/2012/04/13/new-usmt-5-0-features-for-windows-8-consumer-preview.aspx</link><pubDate>Fri, 13 Apr 2012 21:12:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3492119</guid><dc:creator>NedPyle [MSFT]</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/rsscomments.aspx?WeblogPostID=3492119</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/commentapi.aspx?WeblogPostID=3492119</wfw:comment><comments>http://blogs.technet.com/b/askds/archive/2012/04/13/new-usmt-5-0-features-for-windows-8-consumer-preview.aspx#comments</comments><description>&lt;p&gt;Hi all, &lt;a href="http://blogs.technet.com/b/askds/archive/tags/Ned+Pyle/"&gt;Ned&lt;/a&gt; here again. Frequent readers know that I&amp;rsquo;ve written &lt;a href="http://blogs.technet.com/b/askds/archive/tags/usmt/"&gt;many times&lt;/a&gt; about the User State Migration Tool; it&amp;rsquo;s surprising to some, but the Directory Services team owns supporting this tool within Microsoft in the United States (our European colleagues wisely made sure the &lt;em&gt;Deployment &lt;/em&gt;team owns it there). With Windows 8 Consumer Preview, we released the new tongue twisting &lt;a href="http://www.microsoft.com/download/en/details.aspx?id=28997"&gt;Windows Assessment and Deployment Kit for Windows 8 Consumer Preview&lt;/a&gt; (Windows ADK), which replaces the old WAIK and contains the updated User State Migration Tool 5.0 (binary version 6.2.8250). The new tool brings a long sought capability to the toolset: corrupt store detection and extraction. There are also various incremental supportability improvements and bug fixes.&lt;/p&gt;
&lt;h3&gt;Store verification and recovery&lt;/h3&gt;
&lt;p&gt;USMT 4.0 introduced usmtutils.exe, a simple command line tool that was mainly used to delete &lt;a href="http://blogs.technet.com/b/askds/archive/2011/05/27/friday-mail-sack-tuesday-to-you-edition.aspx#hardlink"&gt;hardlink&lt;/a&gt; folders in use by some application and no longer removable through normal measures. The new usmtutils.exe now includes two new command-line arguments:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;b&gt;/verify&lt;/b&gt;[:reportType] &amp;lt;filePath&amp;gt; [/l:logFile] [/decrypt[:&amp;lt;AlgID&amp;gt;]] [/key:keyString] [/keyfile:fileName]&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;b&gt;/extract&lt;/b&gt; &amp;lt;filePath&amp;gt; &amp;lt;destinationPath&amp;gt; [/i:&amp;lt;includePattern&amp;gt;] [/e:&amp;lt;excludePattern&amp;gt;] [/l:logFile] [/decrypt[:&amp;lt;AlgID&amp;gt;]] {/key:keyString] | [/keyfile:fileName] [/o]&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;You use the /&lt;b&gt;verify&lt;/b&gt; option after gathering a scanstate compressed store. This checks the store file&amp;rsquo;s consistency and if it contains corrupted files or a corrupted catalog. It&amp;rsquo;s just a reporting tool, and it has options for the verbosity of the report as well as the optional encryption key info used to secure a compressed store. In Microsoft experience, hardware issues typically cause corrupt compressed stores, especially when errors are not reported back from USB devices.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/7140.image_5F00_6FB09F5C.png"&gt;&lt;img width="544" height="173" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/0184.image_5F00_thumb_5F00_161282A8.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;You use the &lt;b&gt;/extract&lt;/b&gt; option if you want to simply restore certain files, or cannot restore a compressed store with loadstate. For example, you&amp;rsquo;d use it if the store was later partially corrupted after validation, if loadstate cannot operate normally on a destination computer, or if a user deleted a file shortly after loadstate restoration but before their own backups were run. This new capability can restore files based on patterns (both include and exclude). It doesn&amp;rsquo;t restore setting or registry data, just files.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/2728.image_5F00_386A1821.png"&gt;&lt;img width="590" height="127" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/3005.image_5F00_thumb_5F00_17E2D86F.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;Changes in capabilities&lt;/h3&gt;
&lt;p&gt;USMT also now includes a number of other less sexy - but still important - changes. Here are the high points:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Warnings and logging&lt;/b&gt; &amp;ndash; Scanstate and loadstate now warn you at the console with &lt;b&gt;"&amp;hellip;manifests is not present&lt;/b&gt;" if they cannot find the replacement and downlevel manifest folders:&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/0753.image_5F00_6827C0A0.png"&gt;&lt;img width="628" height="123" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/2248.image_5F00_thumb_5F00_63450CE4.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;USMT also warns about the risks of using the &lt;b&gt;/C&lt;/b&gt; option (rather than &lt;b&gt;/VSC&lt;/b&gt; combined with ensuring applications are not locking files), and how many units were not migrated:&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/2728.image_5F00_456688E3.png"&gt;&lt;img width="628" height="135" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/0576.image_5F00_thumb_5F00_04C43C74.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;Remember: you cannot use &lt;b&gt;/vsc&lt;/b&gt; with &lt;b&gt;/hardlink&lt;/b&gt; migrations. Either you continue to use &lt;b&gt;/C&lt;/b&gt; or you figure out why files are in use and stop the underlying issue.&lt;/p&gt;
&lt;p&gt;To that point, the log contains line items for each &lt;b&gt;/C&lt;/b&gt; skipped file as well as a summary error report at the bottom:&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;----------------------------- USMT ERROR SUMMARY ------------------------------ &lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;* One or more errors were encountered in migration (ordered by first occurence) &lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;+------------------------------------------------------------------------------ &lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;| Error Code | Caused Abort | Recurrence | First Occurrence &lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;| 33&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; | No&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; | 18&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; | Read error 33 for D:\foo [bar.pst]. Windows error 33 description: The process cannot access the file because another process has locked a portion of the file.[gle=0x00000012] &lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;+------------------------------------------------------------------------------ &lt;br /&gt;18 migration errors would have been fatal if not for /c. See the log for more information&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Profile scalability&lt;/b&gt; &amp;ndash; USMT 4.0 can &lt;a href="http://blogs.technet.com/b/askds/archive/2011/05/20/friday-mail-sack-ghost-of-the-goat-riding-bambino-edition.aspx#usmtmax"&gt;fail to migrate&lt;/a&gt; if there are too many profiles and not enough memory. It takes a perfect storm but it&amp;rsquo;s possible and you would see error: &amp;ldquo;Close programs to prevent information loss. Your computer is low on memory&amp;rdquo; during loadstate. USMT 5.0 now honors an environmental variable of:&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;b&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; MIG_CATALOG_PRESERVE_MEMORY=1&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;When set, loadstate trims its memory usage much more aggressively. The consequence of this is slower restoration, so don&amp;rsquo;t use this switch willy-nilly.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Built-in Variables &lt;/b&gt;- USMT now supports all of the KNOWNFOLDERID types now. Previously some (such as FOLDERID_Links) were not and &lt;a href="http://blogs.technet.com/b/askds/archive/2011/05/26/links-usmt-4-forgot-my-links.aspx"&gt;required some hacking&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Command-line switches&lt;/b&gt; &amp;ndash; the legacy &lt;b&gt;/ALL&lt;/b&gt;&amp;nbsp;switch was&amp;nbsp;removed.&amp;nbsp;The ALL argument was implicit and therefore pointless; it mainly caused issues when people tried to combine it with other arguments.&amp;nbsp;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;/SF Works&lt;/strong&gt; - the undocumented &lt;strong&gt;/SF&lt;/strong&gt; switch&amp;nbsp;that used to &lt;a href="http://blogs.technet.com/b/askds/archive/2010/03/11/usmt-and-sf.aspx"&gt;break&amp;nbsp;things&lt;/a&gt; no longer breaks things.&amp;nbsp;&lt;br /&gt;&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Scanstate Administrator requirements&lt;/b&gt; &amp;ndash; Previously, loadstate required your membership in the Administrators group, but bizarrely, scanstate did not. This was pointless and confusing, as migration does not work correctly without administrative rights. Now they both require it. &lt;br /&gt;&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;"Bad" data handling &lt;/b&gt;- Certain unexpected file data formats used to lead to errors like "Windows error 4317 description: The operation identifier is not valid". Files with certain strings in alternate data streams would fail with "Windows error 31 description: A device attached to the system is not functioning". USMT handles these scenarios now. &lt;br /&gt;&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;NTUSER.DAT load handling &lt;/b&gt;- The NTUSER.DAT last modified date no longer changes after you run scanstate, meaning that /UEL now works correctly &lt;a href="http://blogs.technet.com/b/askds/archive/2011/05/05/usmt-and-u-migrating-only-fresh-domain-profiles.aspx"&gt;with repeated migrations&lt;/a&gt;. &lt;br /&gt;&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Manifests and UNC paths - &lt;/b&gt;Previously, USMT failed to find its manifest folders if you ran scanstate or loadstate through a UNC path. Now it looks in the same folder as the running executable, regardless of that path's form. &lt;br /&gt;&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Orphaned profiles -&lt;/b&gt; When USMT cannot load a user profile &lt;a href="http://blogs.technet.com/b/askds/archive/2011/04/14/usmt-pauses-at-quot-starting-the-migration-process-quot-for-many-minutes-then-works.aspx"&gt;as described here&lt;/a&gt;, it tries 19 more times (waiting 6 seconds between tries) just like USMT 4.0. However, USMT skips any subsequent profiles that fail to load after one attempt. Therefore, no matter how many incorrectly removed profile entries exist, the most delay you can see is 2 minutes. &lt;br /&gt;&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;UEL and UE &lt;/b&gt;- In USMT 4.0, a &lt;b&gt;/UEL&lt;/b&gt; exclusion rule would &lt;a href="http://blogs.technet.com/b/askds/archive/2009/11/30/understanding-usmt-4-0-behavior-with-uel-and-ue.aspx"&gt;override&lt;/a&gt; the processing of a &lt;b&gt;/UE&lt;/b&gt; exclusion rule, even though it was likely that if you were setting UE because you had specific need. USMT now returns to the USMT 3.01 behavior of UE overriding UEL.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;USMT 5.0 still works with Windows XP through Windows 7, and adds Windows 8 x86 and AMD64 support as well. All of the old rules around CPU architecture and application migration are unchanged in the beta version (USMT 6.2.8250).&lt;/p&gt;
&lt;h3&gt;Feedback and Reminder about the Windows 8 Consumer Preview&lt;/h3&gt;
&lt;p&gt;The place to send issues is the &lt;a href="http://social.technet.microsoft.com/Forums/en-US/w8itproinstall/threads"&gt;IT Pro TechNet forums&lt;/a&gt;. That engages everyone from our side through our main conduits and makes your feedback noticeable. Not all developers are readers of this blog, naturally.&lt;/p&gt;
&lt;p&gt;Furthermore, Windows 8 Consumer Preview is a pre-release product and is not officially supported by Microsoft. In general, it is not recommended pre-release products be used in production environments. For more information on the Windows 8 Consumer Preview, &lt;a href="http://windowsteamblog.com/windows/b/windowsexperience/archive/2012/02/29/introducing-windows-8-consumer-preview.aspx"&gt;read this blog post&lt;/a&gt; from the Windows Experience Blog.&lt;/p&gt;
&lt;p&gt;Until next time,&lt;/p&gt;
&lt;p&gt;Ned &amp;ldquo;there are lots of new manifests too, but I just couldn&amp;rsquo;t be bothered&amp;rdquo; Pyle&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3492119" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/askds/archive/tags/USMT/">USMT</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Ned+Pyle/">Ned Pyle</category><category domain="http://blogs.technet.com/b/askds/archive/tags/USMT+Behaviors/">USMT Behaviors</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Windows+8/">Windows 8</category></item><item><title>Your 24 Month XP Warning</title><link>http://blogs.technet.com/b/askds/archive/2012/04/08/your-24-month-xp-warning.aspx</link><pubDate>Sun, 08 Apr 2012 20:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3490916</guid><dc:creator>NedPyle [MSFT]</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/rsscomments.aspx?WeblogPostID=3490916</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/commentapi.aspx?WeblogPostID=3490916</wfw:comment><comments>http://blogs.technet.com/b/askds/archive/2012/04/08/your-24-month-xp-warning.aspx#comments</comments><description>&lt;p&gt;Hi all, &lt;a href="http://blogs.technet.com/b/askds/archive/tags/Ned+Pyle/"&gt;Ned&lt;/a&gt; here again with a public service announcement:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p align="left"&gt;&lt;a href="http://www.microsoft.com/en-us/windows/endofsupport.aspx"&gt;&lt;strong&gt;&lt;span style="font-size: medium;" size="4"&gt;On April 8&lt;sup&gt;th&lt;/sup&gt; 2014, Windows XP support ends&lt;/span&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;For the temporally challenged, that&amp;rsquo;s exactly two years from today. Hopefully, some of you don&amp;rsquo;t care because you&amp;rsquo;ve already gotten off XP. After all, Windows 7 has a 41% piece of Windows desktop distributions now &lt;a href="http://netmarketshare.com/operating-system-market-share.aspx?qprid=10&amp;amp;qpcustomd=0&amp;amp;qpcustomb=*1"&gt;according to NetMarketShare.com&lt;/a&gt;. Here&amp;rsquo;s their March 2012 take: &lt;/p&gt;
&lt;blockquote&gt;
&lt;p align="left"&gt;&lt;a href="http://netmarketshare.com/operating-system-market-share.aspx?qprid=10&amp;amp;qpcustomd=0&amp;amp;qpcustomb=*1"&gt;&lt;img width="644" height="330" title="image" style="display: inline;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/0458.image_5F00_1BC166CC.png" /&gt;&lt;/a&gt; &lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;What that number also means though is that roughly 51% of the remaining desktops are still on XP.&lt;i&gt; Hundreds of millions&lt;/i&gt; of computers that, two years from today, will stop getting security updates and lose support from &lt;a href="http://download.microsoft.com/download/4/9/7/497A3EA8-09BB-4064-A72C-924C9AC63BE5/creating_a_timeline_for_depl_213442.pdf"&gt;third party software vendors&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;If you have not started &lt;a href="http://technet.microsoft.com/en-us/library/dd349337(v=WS.10).aspx"&gt;migrating your Windows XP environment to Windows 7&lt;/a&gt; and begun &lt;a href="http://technet.microsoft.com/en-us/windows/hh771457.aspx?ITPID=mscomsc"&gt;evaluating Windows 8 Consumer Preview&lt;/a&gt;, you are probably late. According to our own customer deployment data, enterprise desktop replacement projects average 18-32 months. As someone who &lt;a href="http://blogs.technet.com/b/askds/archive/tags/usmt/"&gt;writes a lot about USMT&lt;/a&gt;, I can say that a customized PC migration undertaking is no joke. There are loads of moving parts in mass PC replacements and every company is different, even within the common areas of desktop, mobile, and work-from-home machines. If you&amp;rsquo;re prudent, you&amp;rsquo;ll spend months planning and testing before you get anywhere near your first end user. That means if you&amp;rsquo;re a company with 50,000 XP desktops, you&amp;rsquo;ll have to average around 2,100 desktops migrated a month before support ends. If you take the more realistic thinking and assume 250 working days in a year, you must average 100 migrated computers &lt;em&gt;per working day&lt;/em&gt;, starting this minute.&lt;/p&gt;
&lt;p&gt;The fiscal year is drawing to a close and the 24 month clock is running. Do you know where your XP clients are?&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://technet.microsoft.com/en-us/library/dd349337(v=WS.10).aspx"&gt;Windows 7 Deployment&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://technet.microsoft.com/en-us/solutionaccelerators/dd407791.aspx"&gt;Microsoft Deployment Toolkit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://technet.microsoft.com/en-us/windows/hh771457.aspx?ITPID=mscomsc"&gt;Windows 8 Consumer Preview Evaluation&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Until next time,&lt;/p&gt;
&lt;p&gt;- Ned &amp;ldquo;like the Cubs, it&amp;rsquo;s a rebuilding year&amp;rdquo; Pyle&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;PS: Oh, and Vista mainstream support ended April 10th (today, as I wrote this). That means now it only gets security updates for the next 5 years, no further&amp;nbsp;QFEs or service packs.&lt;/p&gt;
&lt;p&gt;Like you care.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3490916" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/askds/archive/tags/migration/">migration</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Windows+7/">Windows 7</category><category domain="http://blogs.technet.com/b/askds/archive/tags/USMT/">USMT</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Windows+XP/">Windows XP</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Ned+Pyle/">Ned Pyle</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Windows+8/">Windows 8</category></item><item><title>Group Policy Management Improvements in Windows Server "8" Beta</title><link>http://blogs.technet.com/b/askds/archive/2012/04/06/group-policy-management-improvements-in-windows-server-quot-8-quot-beta.aspx</link><pubDate>Fri, 06 Apr 2012 23:13:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3490806</guid><dc:creator>NedPyle [MSFT]</dc:creator><slash:comments>10</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/rsscomments.aspx?WeblogPostID=3490806</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/commentapi.aspx?WeblogPostID=3490806</wfw:comment><comments>http://blogs.technet.com/b/askds/archive/2012/04/06/group-policy-management-improvements-in-windows-server-quot-8-quot-beta.aspx#comments</comments><description>&lt;p&gt;Hi all, &lt;a href="http://blogs.technet.com/b/askds/archive/tags/Ned+Pyle/"&gt;Ned&lt;/a&gt; here again. If you've been supporting group policy for years, you&amp;rsquo;ve grown used to its behaviors. For something designed to manage an enterprise, its initial implementation wasn&amp;rsquo;t easy to manage itself. The Group Policy Management Console improved this greatly after Windows Server 2003, but there was room for enhancement.&lt;/p&gt;
&lt;p&gt;Windows Server "8" Beta introduces a number of interesting Group Policy management changes to advance things. These include detecting overall replication consistency as well as remote policy refresh and easier resultant set of policy troubleshooting. Windows 8 Consumer Preview benefits from some of these changes as well.&lt;/p&gt;
&lt;p&gt;Let's dig in.&lt;/p&gt;
&lt;h2&gt;Infrastructure Status&lt;/h2&gt;
&lt;p&gt;Once upon a time, someone wrote a Windows 2000 resource kit utility called gpotool.exe (no longer supported). It was supposed to tell you if the SYSVOL and AD portions of a group policy were synchronized on a given domain controller and between DCs in a domain. If it returned message "Policies OK", you were supposed to be golden.&lt;/p&gt;
&lt;p&gt;Unfortunately, gpotool is not very bright or honest, which is why we do not recommend customers use it. It only checks the gpt.ini files in SYSVOL. Anyone who manages group policy knows that each GP GUID folder in SYSVOL contains &lt;i&gt;many &lt;/i&gt;files critical to applying group policy. The gpt.ini existing is immaterial if the registry.pol does not exist or is some heinous stale version. Furthermore, gpotool bases everything on the gpt.ini version matching between AD and SYSVOL and alerting you if they don't. Except that the version matching alone has not mattered since Windows 2000 and file consistency checking is super important.&lt;/p&gt;
&lt;p&gt;Enter Windows Server "8" Beta. When you fire up GPMC from a server or &lt;a href="http://www.microsoft.com/download/en/details.aspx?id=28972"&gt;RSAT&lt;/a&gt;, then navigate to a domain node, you now see a new &lt;b&gt;Status&lt;/b&gt; tab (more properly called the &lt;b&gt;Group Policy Infrastructure Status&lt;/b&gt; tool). GPMC sets the DC it connected to as a baseline source of comparison. By default, that would be the PDC emulator, which GPMC tries to connect to first.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/1184.image_5F00_54FE0FF1.png"&gt;&lt;img width="634" height="514" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/3666.image_5F00_thumb_5F00_44859EF6.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;If you click &lt;b&gt;Detect Now&lt;/b&gt;, the computer running GPMC directly reaches out to all the domain controllers in that domain using the LDAP and SMB protocols. It compares &lt;i&gt;all&lt;/i&gt; the SYSVOL group policy file hashes, file counts, ACLs, and GPT versions against the baseline server. It also checks each DC's AD group policy object count, versions, and ACLS against the baseline. If everything is copacetic, you get the good news right there in the UI.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/3666.image_5F00_0D3F17BB.png"&gt;&lt;img width="620" height="505" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/3666.image_5F00_thumb_5F00_43AFC9BD.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;If it's not, you don't:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/4152.image_5F00_7A207BBF.png"&gt;&lt;img width="651" height="457" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/6215.image_5F00_thumb_5F00_659DBCF2.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Note how the report renders above. If the Active Directory and SYSVOL columns are blank, the versions match between gpt and AD, and this means that the file hashes or security are out of sync (an indication of latency at the least); otherwise you will see version messages. If the FRS or DFSR service isn't running on a DC other than the baseline or SYSVOL is not shared, the &lt;b&gt;SysVol&lt;/b&gt; message changes to &lt;b&gt;Inaccessible. &lt;/b&gt;If you turn off a DC or NTDS service, the &lt;b&gt;Active Directory&lt;/b&gt; field changes to &lt;b&gt;Inaccessible&lt;/b&gt;. If you just deleted or added a group policy, the Active Directory field changes to &lt;b&gt;Number of GPOS &lt;/b&gt;for comparison. It's all straightforward.&lt;/p&gt;
&lt;p&gt;This new tool doesn&amp;rsquo;t grant permission to turn off your brain, of course. It's &lt;i&gt;perfectly normal&lt;/i&gt; for AD and SYSVOL to be latent and out of sync between DCs for periods of time. Don't assume that because you see servers showing replication in progress that it is an error - that's why it specifically doesn't say &amp;ldquo;error&amp;rdquo; in GPMC. Finally, keep in mind that this new functionality version in the public Beta is naturally a bit unstable; feel free to report issues the &lt;a href="http://social.technet.microsoft.com/Forums/en-US/category/winserver8"&gt;Windows Server 8 Beta Forums&lt;/a&gt; &lt;i&gt;along with detailed repro steps,&lt;/i&gt; and we can chat about if your issue is unknown. For example, stopping the DFSR service on the PDCE and then then clicking &lt;b&gt;Detect Now&lt;/b&gt; to use that DC as the baseline terminates the MMC. Don&amp;rsquo;t take it too hard - work in progress, right? We'd love your feedback.&lt;/p&gt;
&lt;p&gt;Moving right along&amp;hellip;&lt;/p&gt;
&lt;h2&gt;Remote Policy Refresh&lt;/h2&gt;
&lt;p&gt;You can now use GPMC to target an OU and force group policy refresh on all of its computers and their currently logged on users. Simply right click any organizational unit and click &lt;b&gt;Group Policy Update&lt;/b&gt;. The update occurs within 10 minutes (randomized on each targeted computer) in order to prevent crushing some poor DC in a branch office.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/6215.image_5F00_2737F93F.png"&gt;&lt;img width="663" height="538" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/8372.image_5F00_thumb_5F00_5DA8AB41.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/8546.image_5F00_2D152D89.png"&gt;&lt;img width="400" height="257" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/2502.image_5F00_thumb_5F00_3604BFC8.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/6215.image_5F00_25F881C2.png"&gt;&lt;img width="401" height="301" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/3755.image_5F00_thumb_5F00_15EC43BC.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Windows Server "8" Beta Group Policy also updates the GroupPolicy PowerShell module to include a new cmdlet named &lt;b&gt;Invoke-GpUpdate&lt;/b&gt;. If you examine its help, you see that it is very much like the classic gpupdate.exe. If you &lt;b&gt;-force&lt;/b&gt; using &lt;b&gt;invoke-gpupdate,&lt;/b&gt; you do the same as &lt;b&gt;/force&lt;/b&gt; in &lt;b&gt;gpupdate.exe&lt;/b&gt;, for instance.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;NAME&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;Invoke-GPUpdate&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;SYNTAX&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;Invoke-GPUpdate [[-Computer] &amp;lt;string&amp;gt;] [[-RandomDelayInMinutes] &amp;lt;int&amp;gt;] [-AsJob] [-Boot] [-Force] [-LogOff] [-Target &amp;lt;string&amp;gt;] [&amp;lt;CommonParameters&amp;gt;]&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Obviously, this cmdlet gives you much more control over the remote policy refresh process than GPMC. For instance, you can target a particular computer:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;Invoke-gpupdate -computer &lt;i&gt;&amp;lt;some computer&amp;gt;&lt;/i&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Moreover, unlike the "within 10 minutes" pseudo-random behavior of GPMC, you can make the policy refresh happen &lt;i&gt;right now &lt;/i&gt;and forcing group policy to update regardless of version changes. I don't know about you, but if I am interactively invoking a policy update for a given computer, I am not interested in waiting!&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/6724.image_5F00_5BFD00CF.png"&gt;&lt;img width="596" height="68" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/0028.image_5F00_thumb_5F00_7E549648.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Since this is PowerShell, you have a great deal of flexibility compared to a purpose-built graphical or command-line tool. For example, you can get a list of computers with an arbitrary description then invoke against each one using a pipeline to &lt;b&gt;for-eachobject&lt;/b&gt;, regardless of OU:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/8546.image_5F00_198CEF4A.png"&gt;&lt;img width="511" height="440" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/7206.image_5F00_thumb_5F00_0FC787D2.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;If you&amp;rsquo;re interested, this tool works by creating remote scheduled tasks. That's how it works for logged on users and with randomized refresh times. Another good reason to ensure the Task Scheduler service is running.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/4274.image_5F00_33EF7312.png"&gt;&lt;img width="662" height="373" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/3603.image_5F00_thumb_5F00_7CA8EBD6.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2&gt;New RSOP Logging Data&lt;/h2&gt;
&lt;p&gt;I saved the best for last. The group policy resultant set of planning logs include a number of changes designed make troubleshooting and policy analysis easier. Just like in the last few versions of Windows, you can still use GPMC &lt;b&gt;Group Policy Results&lt;/b&gt; or &lt;b&gt;GPRESULT /H&lt;/b&gt; to gather an html log file showing how and what policy applied to a user and computer.&lt;/p&gt;
&lt;p&gt;When you open that resulting html file, you now see an updated &lt;b&gt;Summary&lt;/b&gt; section that provides better "at a glance" information on policy working or not and the type of network speeds detected. Even better is the new &lt;b&gt;Component Status&lt;/b&gt; area. This shows you the time taken for each element of group policy processing to complete processing.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/8877.image_5F00_68262D09.png"&gt;&lt;img width="696" height="383" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/2514.image_5F00_thumb_5F00_75200D1A.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;It also stores the associated operational event log activity under &lt;b&gt;View Log&lt;/b&gt; that used to require you running &lt;a href="http://www.microsoft.com/download/en/details.aspx?displaylang=en&amp;amp;id=11147"&gt;gplogview.exe&lt;/a&gt;. Rather than parsing the event log with an Activity ID for the computer and user portions of policy processing, you just click the link to see it all unfold before you.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/8054.image_5F00_39CF380D.png"&gt;&lt;img width="511" height="318" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/2110.image_5F00_thumb_5F00_7BD5A74E.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Finally, there is a change to the HTML result file for the applied policies. After 12 years, we&amp;rsquo;ve reached a point where there are thousands of individual Administrative template entries; far more than anyone could possibly remember or reliably discern from their titles. To make this easier, the Windows 8 version of the report now includes explanatory hotlinks to each of those policy entries.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/3000.image_5F00_56D7E6D5.png"&gt;&lt;img width="618" height="184" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/3603.image_5F00_thumb_5F00_31DA265C.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;By clicking the links in the report, you get the full Explanation text included with that policy entry. Like in this case, the new Primary Computer policy for roaming profiles (which I&amp;rsquo;ll discuss in a future post).&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/6330.image_5F00_13FBA25B.png"&gt;&lt;img width="522" height="326" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/8308.image_5F00_thumb_5F00_15CBF822.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Nifty.&lt;/p&gt;
&lt;h3&gt;Key Point&lt;/h3&gt;
&lt;p&gt;Remote RSOP logging and Group Policy refresh require that you open firewall ports on the targeted computers. This means allowing inbound communication for RPC, WMI/DCOM, event logs, and scheduled tasks. You can enable the built-in Windows Advanced Firewall inbound rules: &lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Remote Policy Update&lt;/b&gt;&lt;/li&gt;
&lt;ul&gt;
&lt;li&gt;Remote Scheduled Tasks Management (RPC)&lt;/li&gt;
&lt;li&gt;Remote Scheduled Tasks Management (RPC-EPMAP)&lt;/li&gt;
&lt;li&gt;Windows Management Instrumentation (WMI-in) &lt;br /&gt; &lt;/li&gt;
&lt;/ul&gt;
&lt;li&gt;&lt;b&gt;Remote Policy Logging&lt;/b&gt;&lt;/li&gt;
&lt;ul&gt;
&lt;li&gt;Remote Event Log Management (NP-in)&lt;/li&gt;
&lt;li&gt;Remote Event Log Management (RPC)&lt;/li&gt;
&lt;li&gt;Remote Event Log Management (RPC-EPMAP)&lt;/li&gt;
&lt;li&gt;Windows Management Instrumentation (WMI-in) &lt;/li&gt;
&lt;/ul&gt;
&lt;/ul&gt;
&lt;p&gt;These are part of the &amp;ldquo;Remote Scheduled Tasks Management&amp;rdquo;, &amp;ldquo;Remote Event Log Management&amp;rdquo;, and &amp;ldquo;Windows Management Instrumentation&amp;rdquo; groups. These are TCP RPC port 135, named pipe port 445, and the dynamic ports associated with the endpoint mapper, like always.&lt;/p&gt;
&lt;h3&gt;Feedback and Beta Reminder&lt;/h3&gt;
&lt;p&gt;The place to send issues is the &lt;a href="http://social.technet.microsoft.com/forums/en-us/winserver8gen"&gt;IT Pro TechNet forums&lt;/a&gt;. That engages everyone from our side through our main conduits and makes your feedback noticeable. Not all developers are readers of this blog, naturally.&lt;/p&gt;
&lt;p&gt;Furthermore, remember that this article references a pre-release product. Microsoft does not support Windows 8 Consumer Preview or Windows Server "8" Beta in production environments unless you have a special agreement with Microsoft. Read that EULA you accepted when installing!&lt;/p&gt;
&lt;p&gt;Until next time,&lt;/p&gt;
&lt;p&gt;Ned &amp;ldquo;I used a fancy arrow!&amp;rdquo; Pyle&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3490806" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/askds/archive/tags/group+policy/">group policy</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Ned+Pyle/">Ned Pyle</category><category domain="http://blogs.technet.com/b/askds/archive/tags/gpmc/">gpmc</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Windows+8/">Windows 8</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Windows+Server+_2600_quot_3B00_8_2600_quot_3B00_+Beta/">Windows Server &amp;quot;8&amp;quot; Beta</category><category domain="http://blogs.technet.com/b/askds/archive/tags/windows+server+2012/">windows server 2012</category></item><item><title>Gimme Some Sugar</title><link>http://blogs.technet.com/b/askds/archive/2012/04/06/gimme-some-sugar.aspx</link><pubDate>Fri, 06 Apr 2012 21:36:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3490795</guid><dc:creator>NedPyle [MSFT]</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/rsscomments.aspx?WeblogPostID=3490795</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/commentapi.aspx?WeblogPostID=3490795</wfw:comment><comments>http://blogs.technet.com/b/askds/archive/2012/04/06/gimme-some-sugar.aspx#comments</comments><description>&lt;p&gt;&lt;span style="font-size: small;" size="2"&gt;Hi all, Ned here again. Like Bruce Campbell, we&amp;rsquo;ve been away for awhile, but you can always count on us to return for the sequel. Some of the Windows Server &amp;ldquo;8&amp;rdquo; Beta blogging rules have been relaxed and we&amp;rsquo;re ready to begin firing our boomstick. Look for the first one here in a few minutes.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;" size="2"&gt;Besides that, I&amp;rsquo;ve had plenty of inspiration in the past month from some of your questions and have some other non-8 posts in the quench tub that should be ready to go out soon; I&amp;rsquo;m thinking new USMT tricks, WMI filtering coolness, AD forest recovery gotchas, and some other. I might even find time for a Friday Mail Sack next week, who knows? &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/5344.image_5F00_40254765.png"&gt;&lt;span style="font-size: x-small;" size="2"&gt;&lt;img width="388" height="256" title="image" style="display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/3782.image_5F00_thumb_5F00_6BF59B54.png" border="0" /&gt;&lt;/span&gt;&lt;/a&gt; &lt;br /&gt;&lt;span style="font-size: xx-small;" size="2"&gt;It&amp;rsquo;s a dirty job here, but someone has to get the backend of the pony.&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;span style="font-size: small;" size="2"&gt;Enough with metaphor mixing &amp;ndash; on to the goods. The next post is a doozy: group policy management changes in Windows Server &amp;ldquo;8&amp;rdquo; Beta. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;span size="2"&gt; - Ned &amp;ldquo;Honey, you got reeeal ugly&amp;rdquo; Pyle&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3490795" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/askds/archive/tags/Silly+Rabbit/">Silly Rabbit</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Ned+Pyle/">Ned Pyle</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Windows+Server+_2600_quot_3B00_8_2600_quot_3B00_+Beta/">Windows Server &amp;quot;8&amp;quot; Beta</category></item><item><title>The yuck that is "PC Recycle Day" at Microsoft</title><link>http://blogs.technet.com/b/askds/archive/2012/03/09/the-yuck-that-is-quot-pc-recycle-day-quot-at-microsoft.aspx</link><pubDate>Fri, 09 Mar 2012 21:38:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3485807</guid><dc:creator>NedPyle [MSFT]</dc:creator><slash:comments>26</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/rsscomments.aspx?WeblogPostID=3485807</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/commentapi.aspx?WeblogPostID=3485807</wfw:comment><comments>http://blogs.technet.com/b/askds/archive/2012/03/09/the-yuck-that-is-quot-pc-recycle-day-quot-at-microsoft.aspx#comments</comments><description>&lt;p&gt;Hey all, Ned here again. Still no ETA on Win8 word, and we've&amp;nbsp;already discussed &lt;em&gt;everything&lt;/em&gt; else on Earth ( ;-P ) so now I will share with you some insider knowledge of working in Microsoft Charlotte:&amp;nbsp;the quarterly&amp;nbsp;"PC Recycle Day". Here's an example of what I just saw on my way to get some coffee.&lt;/p&gt;
&lt;p style="padding-left: 30px;"&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02/3857.WP_5F00_000758.jpg"&gt;&lt;img alt="" src="http://blogs.technet.com/resized-image.ashx/__size/550x0/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02/3857.WP_5F00_000758.jpg" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;A couple of these are fairly hard to identify unless you are as old as &lt;a href="http://blogs.technet.com/b/askds/archive/tags/jonathan+Stephens/"&gt;Jonathan&lt;/a&gt;. Take a stab at&amp;nbsp;them in the Comments, if you dare to date yourself. If you've used them all, give yourself a pat on the back - you are really close to retirement.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Update&lt;/strong&gt;: Woo, a &lt;em&gt;particularly&lt;/em&gt; crusty late arrival from the Networking team! They may upset the perennial Setup team favorites here and win it all this year, folks.&lt;/p&gt;
&lt;p style="padding-left: 30px;"&gt;&amp;nbsp;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02/3821.WP_5F00_000760.jpg"&gt;&lt;img alt="" src="http://blogs.technet.com/resized-image.ashx/__size/550x0/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02/3821.WP_5F00_000760.jpg" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Update 2: &lt;/strong&gt;a funeral pyre for once-dominant protocols&lt;/p&gt;
&lt;p style="padding-left: 30px;"&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02/5807.WP_5F00_000762.jpg"&gt;&lt;img alt="" src="http://blogs.technet.com/resized-image.ashx/__size/550x0/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02/5807.WP_5F00_000762.jpg" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Have a nice weekend,&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;- Ned "spring chicken" Pyle&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3485807" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/askds/archive/tags/Silly+Rabbit/">Silly Rabbit</category></item><item><title>Unresponsive Servers due to DST and an unsupported registry key</title><link>http://blogs.technet.com/b/askds/archive/2012/03/09/unresponsive-servers-due-to-dst-and-an-unsupported-registry-key.aspx</link><pubDate>Fri, 09 Mar 2012 16:52:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3485736</guid><dc:creator>Jonathan Stephens, MSFT</dc:creator><slash:comments>14</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/rsscomments.aspx?WeblogPostID=3485736</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/commentapi.aspx?WeblogPostID=3485736</wfw:comment><comments>http://blogs.technet.com/b/askds/archive/2012/03/09/unresponsive-servers-due-to-dst-and-an-unsupported-registry-key.aspx#comments</comments><description>&lt;p&gt;Hi, David here to tell you about a thorny little problem that a few of our customers have run into during their testing for the upcoming Daylight Saving Time changes. For reference, the US enters DST this weekend, and parts of Europe enter DST on March 25th. (For a list of all the various Daylight Saving Time changes, click &lt;a href="http://www.timeanddate.com/time/dst/2012.html"&gt;here&lt;/a&gt;)&lt;/p&gt;
&lt;p&gt;&lt;b&gt;What you need to know&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;If you have the following registry key implemented on any Windows systems, and your system clock is running faster than your CMOS clock, that computer will become unresponsive at the DST change. This unresponsiveness will persist until the CMOS clock catches up with the DST changeover time. For example, if the CMOS clock is set to 3/11/2012 6:55 AM UTC and the OS time is set to 3/11/2012 1:59 AM EST, when the system clock reaches 2:00 AM EST, the CPU will spike to 100%, and will remain pegged for 4 minutes until the CMOS clock reaches 7:00 AM UTC.&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: courier new,courier;"&gt;Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\TimeZoneInformation&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new,courier;"&gt;Value: RealTimeIsUniversal&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new,courier;"&gt;Type: REG_DWORD&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new,courier;"&gt;Data: 0x1 (default: 0x0)&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;We recommend the following steps:&lt;/p&gt;
&lt;p&gt;1. Don&amp;rsquo;t use the &lt;b&gt;undocumented&lt;/b&gt; and &lt;b&gt;unsupported&lt;/b&gt; RealTimeIsUniversal registry key! If you have it set, delete it and reboot that computer. Make sure it doesn&amp;rsquo;t return via automation, like Startup Scripts or Group Policy Preferences&lt;/p&gt;
&lt;p&gt;2. Check CMOS clocks on your systems and make sure that they are set to the correct time (yes, we know this requires a reboot).&lt;/p&gt;
&lt;p&gt;See this KB article:&lt;/p&gt;
&lt;p&gt;&lt;b&gt;268725 - &lt;/b&gt;System may be unresponsive around Daylight Saving Time (DST) change when RealTimeIsUniversal is Set&lt;/p&gt;
&lt;p&gt;&lt;a href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;2687252"&gt;http://support.microsoft.com/default.aspx?scid=kb;EN-US;2687252&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;David &amp;ldquo;What&amp;rsquo;s a TARDIS?&amp;rdquo; Beach&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3485736" width="1" height="1"&gt;</description></item><item><title>Windows Server “8” Beta announcements, availability (updated)</title><link>http://blogs.technet.com/b/askds/archive/2012/03/01/windows-8-docs-and-such.aspx</link><pubDate>Thu, 01 Mar 2012 06:06:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3483989</guid><dc:creator>NedPyle [MSFT]</dc:creator><slash:comments>13</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/rsscomments.aspx?WeblogPostID=3483989</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/commentapi.aspx?WeblogPostID=3483989</wfw:comment><comments>http://blogs.technet.com/b/askds/archive/2012/03/01/windows-8-docs-and-such.aspx#comments</comments><description>&lt;p&gt;Hi all, Ned here. For those who spent the day in a coma, &lt;a href="http://technet.microsoft.com/en-us/evalcenter/hh670538"&gt;Windows Server &amp;ldquo;8&amp;rdquo; Beta&lt;/a&gt; and &lt;a href="http://windows.microsoft.com/en-US/windows-8/iso?ocid=W_OFF_W8P_TechCenter_ISO_EN-US"&gt;Windows 8 CP&lt;/a&gt; are out. Make sure you start by visiting Bill Laing&amp;rsquo;s announcement on the Windows Server Blog. This morning he &lt;a href="http://blogs.technet.com/b/windowsserver/archive/2012/03/01/windows-server-8-beta-available-now.aspx"&gt;formally announced the availability of Windows Server &amp;ldquo;8&amp;rdquo; Beta&lt;/a&gt; and outlined some of the design philosophies in a brief post.&lt;/p&gt;
&lt;p&gt;Next, we have a new kind of document we call the &amp;ldquo;Understand and Troubleshoot&amp;rdquo; guides, which are designed to explain the inner workings of new features and how to troubleshoot them. You may recognize some of the authors (you know I hate link lists, but in this case I&amp;rsquo;ll make an exception).&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/p/?LinkId=237244"&gt;Understand and Troubleshoot AD DS Simplified Administration in Windows Server &amp;ldquo;8&amp;rdquo; Beta&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=245426"&gt;Understand and Troubleshoot Dynamic Access Control in Windows Server &amp;ldquo;8&amp;rdquo; Beta&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/p/?LinkId=236370"&gt;Understand and Troubleshoot Virtualized Domain Controller (VDC) in Windows Server &amp;ldquo;8&amp;rdquo; Beta &lt;/a&gt;&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://social.technet.microsoft.com/wiki/contents/articles/7532.understand-and-troubleshoot-windows-server.aspx"&gt;Windows Server &amp;ldquo;8&amp;rdquo; Beta Understand and Troubleshoot Guides&lt;/a&gt; (Wiki Landing page)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;There are also &amp;ldquo;Test Lab Guides&amp;rdquo; and TechNet docs that introduce and demonstrate features, as well as assist with deployment.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/p/?LinkId=237270"&gt;Test Lab Guide: Demonstrate ADDS Simplified Administration in Windows Server "8" Beta &lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/p/?LinkId=237261"&gt;Test Lab Guide: Demonstrate Virtualized Domain Controller (VDC) in Windows Server "8" Beta &lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://social.technet.microsoft.com/wiki/contents/articles/7807.windows-server-8-beta-test-lab-guides.aspx"&gt;Windows Server &amp;ldquo;8&amp;rdquo; Beta Test Lab Guides&lt;/a&gt; (Wiki Landing Page)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://technet.microsoft.com/en-us/library/hh831484.aspx"&gt;Active Directory Domain Services overview&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://technet.microsoft.com/en-us/library/hh831717.aspx"&gt;Dynamic Access Control: Scenario Overview&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;And a reminder - send all your IT Pro feedback to the links below. People are definitely listening.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://social.technet.microsoft.com/Forums/en-US/category/winserver8"&gt;Windows Server &amp;ldquo;8&amp;rdquo; Beta Forums&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://social.technet.microsoft.com/Forums/en-US/category/w8itpro"&gt;Windows 8 CP IT Pro Forums&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.msdn.com/b/b8/"&gt;B8 Blog&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.technet.com/b/windowsserver/"&gt;Windows Server Blog&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;I know some of you are looking forward to the typical in-depth and honest AskDS beta content you&amp;rsquo;ve read for the past five years - you&amp;rsquo;re IT professionals and chomping at the bit to start learning about all the new enterprise features. Well, we&amp;rsquo;re still muzzled here and not allowed to discuss anything. Hang in there; I&amp;rsquo;m hopeful it won&amp;rsquo;t be too much longer.&lt;/p&gt;
&lt;p&gt;- Ned &amp;ldquo;the gimp&amp;rdquo; Pyle&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3483989" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/askds/archive/tags/Other+Blogs/">Other Blogs</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Ned+Pyle/">Ned Pyle</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Windows+8/">Windows 8</category></item><item><title>Congrats Sean and Mark, the Newest Masters!</title><link>http://blogs.technet.com/b/askds/archive/2012/02/25/congrats-sean-and-mark-the-newest-masters.aspx</link><pubDate>Sat, 25 Feb 2012 19:38:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3483185</guid><dc:creator>NedPyle [MSFT]</dc:creator><slash:comments>4</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/rsscomments.aspx?WeblogPostID=3483185</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/commentapi.aspx?WeblogPostID=3483185</wfw:comment><comments>http://blogs.technet.com/b/askds/archive/2012/02/25/congrats-sean-and-mark-the-newest-masters.aspx#comments</comments><description>&lt;p&gt;Hey all, Ned here again. You probably know our&amp;nbsp;pals &lt;a href="http://blogs.technet.com/b/askds/archive/tags/sean+ivey/"&gt;Sean Ivey&lt;/a&gt; and &lt;a href="http://blogs.technet.com/b/askds/archive/tags/mark+renoden/"&gt;Mark Renoden&lt;/a&gt;&amp;nbsp;from their AskDS blog contributions. Both of them were once Directory Services Support Engineers and are now Premier Field Engineers, traveling the globe to&amp;nbsp;help solve your problems. Much like the A-Team. Or not.&lt;/p&gt;
&lt;p&gt;Anyway, what you probably &lt;em&gt;don't&lt;/em&gt;&amp;nbsp;know is that yesterday they &lt;a href="http://blogs.technet.com/b/themasterblog/archive/2012/02/24/mcm-directory-r14-complete-with-several-new-mcms.aspx"&gt;joined the elite fraternity of Microsoft Certified Masters&lt;/a&gt;&amp;nbsp;along with nine of their new best friends. Having taught that certification since day 0, I can tell you it is a royal gentleman's fruit buster and to get it takes &lt;a href="http://adrocketscience.blogspot.com/2011/04/mountain-awaits.html"&gt;serious dedication and serious smarts&lt;/a&gt;; heck, after&amp;nbsp;five years and&amp;nbsp;fourteen rotations,&amp;nbsp;MCM DS&amp;nbsp;only finally crossed&amp;nbsp;the 100 graduate mark! If you haven't explored the certification that will set you apart from everyone in the IT industry, I suggest you &lt;a href="http://www.microsoft.com/learning/en/us/certification/master.aspx"&gt;start&lt;/a&gt;. Make sure you&amp;nbsp;bank some sleep first though,&amp;nbsp;and don't forget to ask Ryan about the Banana Crown.&lt;/p&gt;
&lt;p&gt;We're&amp;nbsp;awful proud of our former DS support brothers. Congratulations fellas.&lt;/p&gt;
&lt;p&gt;- Ned "and all your old buddies" Pyle&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3483185" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/askds/archive/tags/Ned+Pyle/">Ned Pyle</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Mark+Renoden/">Mark Renoden</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Sean+Ivey/">Sean Ivey</category><category domain="http://blogs.technet.com/b/askds/archive/tags/MCM/">MCM</category></item><item><title>Friday Mail Sack: VROOM VROOM Edition</title><link>http://blogs.technet.com/b/askds/archive/2012/02/17/friday-mail-sack-vroom-vroom-edition.aspx</link><pubDate>Sat, 18 Feb 2012 00:24:40 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3481702</guid><dc:creator>Jonathan Stephens, MSFT</dc:creator><slash:comments>8</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/rsscomments.aspx?WeblogPostID=3481702</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/commentapi.aspx?WeblogPostID=3481702</wfw:comment><comments>http://blogs.technet.com/b/askds/archive/2012/02/17/friday-mail-sack-vroom-vroom-edition.aspx#comments</comments><description>&lt;p&gt;Hi folks, &lt;a href="http://blogs.technet.com/b/askds/archive/tags/jonathan+stephens/" target="_blank"&gt;Jonathan&lt;/a&gt; here again. &lt;a href="http://blogs.technet.com/b/askds/archive/tags/Ned+Pyle/" target="_blank"&gt;Ned&lt;/a&gt;’s a little busy right now trying to get items off the top shelf of the cabinet, I thought I’d grab some responses he was working on off this desk and put this week’s Mail Sack together. Today we talk about:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href="#audit"&gt;Auditing group membership changes &lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="#ao"&gt;Account Operators group &lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="#legacy"&gt;AllowLegacySrvCall explained &lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="#rollback"&gt;Getting around USN rollback…not! &lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="#flags"&gt;NTPServer Flags &lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="#other"&gt;Other stuff &lt;/a&gt;&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;Let me go get Ned a step stool, and then we’ll get started on the Q &amp;amp; A.&lt;/p&gt;  &lt;h1&gt;&lt;a name="audit"&gt;&lt;/a&gt;Question&lt;/h1&gt;  &lt;p&gt;If I use Auditing and remove a user’s group membership, I see Security Group Management events (4729, 4759, etc.). If I delete that user though, I only see “a user account was deleted (4726) events.&amp;#160; There’s no group membership event – is that normal?&lt;/p&gt;  &lt;h1&gt;Answer&lt;/h1&gt;  &lt;p&gt;&lt;em&gt;[Carefully crafted by Ned in his little &lt;a href="http://blogs.technet.com/b/askds/archive/2009/11/16/i-hate-mondays.aspx"&gt;Treebicle&lt;/a&gt;.]&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;User deletion means that the System performs the group membership removal.&amp;#160; You will see the same behavior when you create a user – there is no audit event when they are added to the local Users group, for example. This lack of System update auditing is intentional; otherwise, the log would explode from useless information.&lt;/p&gt;  &lt;h1&gt;&lt;a name="ao"&gt;&lt;/a&gt;Question&lt;/h1&gt;  &lt;p&gt;I was reading &lt;a href="http://technet.microsoft.com/en-us/library/cc756898(v=WS.10).aspx"&gt;documentation&lt;/a&gt; about the Account Operators group’s default behavior. I have found that despite what it says here, members of the account operators group can delete administrators. Is the documentation wrong or is this expected?&lt;/p&gt;  &lt;h1&gt;Answer&lt;/h1&gt;  &lt;p&gt;&lt;em&gt;[Straight from the (tiny) &lt;a href="http://blogs.technet.com/b/askds/archive/2009/09/18/i-hate-fridays.aspx"&gt;desk of Ned&lt;/a&gt;.]&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;Let’s analyze what the article says versus what the author meant:&lt;/p&gt;  &lt;p&gt;&lt;i&gt;Members of this group can create, modify, and delete accounts for users, groups, and computers located in the Users or Computers containers and organizational units in the domain, except the Domain Controllers organizational unit. &lt;/i&gt;&lt;/p&gt;  &lt;p&gt;&lt;i&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p&gt;Mostly true. If you look at the default permissions on the Users container, for example, you see they definitely have create and delete rights: &lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/8764.clip_5F00_image002_5F00_18B94C1F.jpg"&gt;&lt;img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="clip_image002" border="0" alt="clip_image002" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/0250.clip_5F00_image002_5F00_thumb_5F00_08215131.jpg" width="589" height="270" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;It will be similar for your custom OUs, because those OU objects inherit those default permissions from the AD schema upon creation. &lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/8666.clip_5F00_image004_5F00_7B27711F.jpg"&gt;&lt;img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="clip_image004" border="0" alt="clip_image004" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/5621.clip_5F00_image004_5F00_thumb_5F00_0E489DCC.jpg" width="591" height="381" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;If your administrative accounts live in the Users container or a custom OU where you have not modified the default permissions, members of the account operators group can delete those users with impunity. If you want to stop this behavior, place your administrative users in a custom OU where you remove the Account Operators group from the permissions.&lt;/p&gt;  &lt;p&gt;&lt;i&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p&gt;&lt;i&gt;Members of this group do not have permission to modify the Administrators or the Domain Admins groups, nor do they have permission to modify the accounts for members of those groups. &lt;/i&gt;&lt;/p&gt;  &lt;p&gt;True, but sometimes it takes a bit. At first, every user created allows the Account Operators group full control – this comes from the default schema security. They cannot modify administrative users, change their passwords, remove their group memberships, or otherwise manipulate them &lt;i&gt;once &lt;a href="http://support.microsoft.com/kb/232199/"&gt;AdminSDHolder and SDProp&lt;/a&gt; have their way with the account&lt;/i&gt;. Moreover, the author did not mean, “modification equals deletion”, even though you and I know as IT pros that it “is the ultimate modification”, of a sort. Modifying its existence. J At no point can Account Operators modify the members of the high security groups like Domain Admins, regardless of SDProp timing. Otherwise an Account Operator could elevate a normal user to the highest privilege levels in the domain.&lt;/p&gt;  &lt;p&gt;&lt;i&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p&gt;&lt;i&gt;Members of this group can log on locally to domain controllers in the domain and shut them down. &lt;/i&gt;&lt;/p&gt;  &lt;p&gt;&lt;i&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p&gt;True (and subsequent &lt;i&gt;&amp;lt;Rodney Dangerfield collar pull&amp;gt;&lt;/i&gt;). If you are dead set on using the Account Operators, removing this right (stored in the Default Domain Controllers policy) is probably a good idea. These users can deny service to your entire network, by shutting down every DC at once. &lt;/p&gt;  &lt;p&gt;&lt;i&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p&gt;&lt;i&gt;Because this group has significant power in the domain, add users with caution.&lt;/i&gt;&lt;/p&gt;  &lt;p&gt;True! The Account Operators group is one of those NT 4.0 legacies that date back to an operating system that didn’t have a hierarchical management structure like X.500/LDAP, and instead a big blob of goo called a SAM database. Using this group is not ideal; it has far too many privileges and based on SDProp timing, can have too much power over brand new admin users for brief periods of time. We spent countless millions of dollars creating AD and &lt;a href="http://technet.microsoft.com/en-us/library/cc773318(v=ws.10).aspx"&gt;Delegation of Control&lt;/a&gt; so that our customers could abandon the legacy management systems. If the Account Operators group is awesome, why would we have bothered otherwise?&lt;/p&gt;  &lt;h1&gt;&lt;a name="legacy"&gt;&lt;/a&gt;Question&lt;/h1&gt;  &lt;p&gt;There are a lot of articles that discuss CIFS interoperability, and they refer to LAN Manager Authentication Level, but there are very few that mention the registry parameter AllowLegacySrvCall. What does this setting actually do?&lt;/p&gt;  &lt;p&gt;Key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0    &lt;br /&gt;Value: AllowLegacySrvCall     &lt;br /&gt;Type: REG_DWORD     &lt;br /&gt;Default: 0x0&lt;/p&gt;  &lt;h1&gt;Answer&lt;/h1&gt;  &lt;p&gt;Maybe you should sit down.&lt;/p&gt;  &lt;p&gt;When a client attempts to connect to an SMB server the server generates a challenge and sends it to the client. The idea is that the client manipulates the challenge using its secret knowledge (the password) and sends the result back to the server as the response. Local System Authority Subsystem (LSASS) on the server evaluates that response and determines if the user has been properly authenticated. This is standard NTLM challenge/response authentication mechanics. With extended security support, LSASS performs some other checks to evaluate if the response has been tampered with, and if it has, the user is denied access. Unfortunately, this introduced a bug that was discovered in Windows Vista and Windows Server 2008. Creating the registry value &lt;em&gt;AllowLegacySrvCall&lt;/em&gt; was our way of resolving this bug.&lt;/p&gt;  &lt;p&gt;If the client supports extended security, LanManServer goes back to LSASS to generate the challenge to send to the client. If the client does not support extended security for NTLMv2, then LanManServer optimizes by generating its own challenge to the authentication request. Unfortunately, this challenge wasn't created by LSASS so it is missing some information when LSASS later evaluates the response to the challenge. This causes the response to be considered invalid and so authentication fails.&lt;/p&gt;  &lt;p&gt;&lt;em&gt;AllowLegacySrvCall&lt;/em&gt; enables logic in LSASS such that it can detect that a particular response was created from a challenge generated by LanManServer (as opposed to LSASS). In this case, LSASS will omit the extended security checks on the response. The effect of this setting is that if you have older SMB clients that do not support extended security then your NTLMv2 security is slightly compromised because there is no way to detect tampering of the authentication response on the wire.&lt;/p&gt;  &lt;p&gt;So when do you need to enable &lt;em&gt;AllowLegacySrvCall&lt;/em&gt;?&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;You are enforcing NTLMv2 for authentication. &lt;/li&gt;    &lt;li&gt;Your SMB client does not support extended security. This usually means older Mac OS X, jcifs, and Samba. Note that NT 4.0 would also be affected, here. &lt;/li&gt; &lt;/ol&gt;  &lt;h1&gt;&lt;a name="rollback"&gt;&lt;/a&gt;Question&lt;/h1&gt;  &lt;p&gt;I realize this is &lt;a href="http://blogs.technet.com/b/askds/archive/2009/06/05/dc-s-and-vm-s-avoiding-the-do-over.aspx" target="_blank"&gt;an old article&lt;/a&gt; but couldn't you get around the USN rollback issue by doing an authoritative restore on the DC you bring back from a snapshot? Don't actually restore a backup but just run NTDSUTIL to make the DC authoritative for all objects. That would push all that DC's USNs up by 100,000 and the objects would replicate out -- hence no USN rollback issue.&lt;/p&gt;  &lt;h1&gt;Answer&lt;/h1&gt;  &lt;p&gt;Not quite. Consider the scenario where an object is created or an attribute is set on DC1 after the snapshot is taken. This change propagates out to all replication partners with the originating change designated as being on DC1. Now you restore your snapshot and use NTDSUTIL to mark authoritative all the objects and attributes in the Active Directory on DC1. Those objects and attributes will indeed replicate out, but what about the objects (or attributes) on DC1's partners that actually originated on DC1? Those changes will not propagate back to DC1 because the partner must assume that DC1 is already aware of them because the invocation ID of the partner has not changed.&lt;/p&gt;  &lt;p&gt;This is why the invocation ID changes when AD is restored using a supported method. A new invocation ID indicates to all partners that this is essentially a new database with some pre-synchronized data in it and it needs to be updated from all partners. It is not just the USN value itself that impacts the rollback status of a DC, but it is also the invocation ID that distinguishes DC1's restored database from its original database. With the new invocation ID, changes that originated on DC1 after the backup was taken will propagate back to DC1 because partners won't think the changes originated on the now restored DC. Restoring a snapshot does not change the invocation ID, and thus basically breaks AD's ability to properly recover from a restore operation.&lt;/p&gt;  &lt;p&gt;Long story short…don't do it.&lt;/p&gt;  &lt;p&gt;If you have further questions, I recommend &lt;a href="http://blogs.msdn.com/b/richpec/archive/2011/10/07/the-authoritative-restore-explained.aspx"&gt;Rich Peckham's blog post on the topic of authoritative restores&lt;/a&gt;.&lt;/p&gt;  &lt;h1&gt;&lt;a name="flags"&gt;&lt;/a&gt;Question&lt;/h1&gt;  &lt;p&gt;I have read the W32Time documentation and blogs but I do not understand one thing. What is the difference in flags 0x1 and 0x8 in the registry parameter below:&lt;/p&gt;  &lt;p&gt;Key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Parameters    &lt;br /&gt;Value: NtpServer     &lt;br /&gt;Type: REG_SZ     &lt;br /&gt;Example: time.windows.com,0x8&lt;/p&gt;  &lt;h1&gt;Answer&lt;/h1&gt;  &lt;p&gt;The flags value for NtpServer are briefly documented in the following KB article: &lt;a href="http://support.microsoft.com/kb/875424"&gt;Time synchronization may not succeed when you try to synchronize with a non-Windows NTP server in Windows Server 2003&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;&lt;font face="Courier New"&gt;0x01 - use special poll interval SpecialInterval      &lt;br /&gt;&lt;/font&gt;&lt;font face="Courier New"&gt;0x02 – UseAsFallbackOnly      &lt;br /&gt;&lt;/font&gt;&lt;font face="Courier New"&gt;0x04 - send request as SymmetricActive mode      &lt;br /&gt;&lt;/font&gt;&lt;font face="Courier New"&gt;0x08 - send request as Client mode&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;You can find more detail about how these flags interact in the Microsoft Communications Protocol Program (MCPP) library on MSDN: &lt;a href="http://msdn.microsoft.com/en-us/library/cc246903(v=PROT.10).aspx"&gt;[MS-SNTP]: Network Time Protocol (NTP) Authentication Extensions&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;If you need to understand the difference between Symmetric Active mode and Client mode, then you should consult &lt;a href="http://tools.ietf.org/html/rfc5905"&gt;RFC 5905&lt;/a&gt;. It’ll put hair on your chest.&lt;/p&gt;  &lt;h1&gt;&lt;a name="other"&gt;&lt;/a&gt;Other Stuff&lt;/h1&gt;  &lt;p&gt;Is this the greatest &lt;a href="http://social.zune.net/album/Exodus/Shovel-Headed-Kill-Machine/df3d8f00-0100-11db-89ca-0019b92a3933/details?cache=true"&gt;metal album cover&lt;/a&gt; of all time? I think so.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://social.zune.net/album/Exodus/Shovel-Headed-Kill-Machine/df3d8f00-0100-11db-89ca-0019b92a3933/details?cache=true" target="_blank"&gt;&lt;img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="" border="0" alt="" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/5633.Exodus_5F00_442D92E6.jpg" width="401" height="401" /&gt;&lt;/a&gt;     &lt;br /&gt;&lt;font size="1"&gt;Plow tank with gatling guns on a skull road with hardcore driver demanding answers from an uncaring corporate world? Check.&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;Do you have a set of wheels appropriate for the &lt;a href="http://editorial.autos.msn.com/10-best-vehicles-for-the-end-of-the-world?icid=autos_2328#1" target="_blank"&gt;Zombie Apocalypse&lt;/a&gt;? Why not skip the Marauder and &lt;a href="http://www.forceprotection.net/products/cougar_6x6/" target="_blank"&gt;buy American&lt;/a&gt;?&lt;/p&gt; &lt;object style="height: 390px; width: 640px"&gt;&lt;param name="movie" value="http://www.youtube.com/v/5ForVQsgvMo?version=3&amp;amp;feature=player_detailpage"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/5ForVQsgvMo?version=3&amp;amp;feature=player_detailpage" type="application/x-shockwave-flash" allowfullscreen="true" allowScriptAccess="always" width="640" height="360"&gt;&lt;/object&gt;  &lt;p&gt;And here is &lt;a href="http://www.moviecarposters.com/" target="_blank"&gt;some stuff&lt;/a&gt; that makes me wish I still had a dorm room to decorate.&lt;/p&gt;  &lt;p&gt;Until next time, folks.&lt;/p&gt;  &lt;p&gt;- Jonathan “Average Height and Build” Stephens with Ned “Not” Pyle.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3481702" width="1" height="1"&gt;</description></item><item><title>Friday Mail Sack: Get Off My Lawn Edition</title><link>http://blogs.technet.com/b/askds/archive/2012/02/11/friday-mail-sack-get-off-my-lawn-edition.aspx</link><pubDate>Sat, 11 Feb 2012 19:59:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3480359</guid><dc:creator>NedPyle [MSFT]</dc:creator><slash:comments>5</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/rsscomments.aspx?WeblogPostID=3480359</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/commentapi.aspx?WeblogPostID=3480359</wfw:comment><comments>http://blogs.technet.com/b/askds/archive/2012/02/11/friday-mail-sack-get-off-my-lawn-edition.aspx#comments</comments><description>&lt;p&gt;Hi folks, &lt;a href="http://blogs.technet.com/b/askds/archive/tags/Ned+Pyle/"&gt;Ned&lt;/a&gt; here again. I know this is supposed to be the &lt;em&gt;Friday&lt;/em&gt; Mail Sack but things got a little hectic and... ah heck, it doesn't need explaining, you're in IT. This week - with help from the ever-crotchety &lt;a href="http://blogs.technet.com/b/askds/archive/tags/jonathan+stephens/"&gt;Jonathan Stephens&lt;/a&gt; - we talk about:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#wmi"&gt;Multiple WMI Filters&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#maxpoolthreads"&gt;LDAP MaxPoolThreads&lt;/a&gt;&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;a href="#certmap"&gt;Many-to-one certificate mappings&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#linkid"&gt;LinkID attribute weirdness&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#dfsrlogperf"&gt;DFSR logging performance&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#dcjoin"&gt;Previous DC can&amp;rsquo;t join the domain&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#lsamemory"&gt;AD LDS (and AD and DFSR) memory usage&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#usmtjump"&gt;USMT and jump list migration&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#des"&gt;Turning on Kerberos DES the right way&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#other"&gt;Other Stuff&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Now that Jonathan's Rascal Scooter has finished charging, on to the Q &amp;amp; A.&lt;/p&gt;
&lt;h1&gt;&lt;a name="wmi"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;We want to create a group policy for an OU that contains various computers needs to run for just Windows 7 notebooks only. All of our notebooks are named starting with an "N". Does group policy WMI filtering allows stacking conditions on the same group policy?&amp;nbsp;&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;Yes, you can chain together multiple query criteria, and they can even be from different classes or namespaces. For example, here I use both the &lt;a href="http://msdn.microsoft.com/en-us/library/windows/desktop/aa394239(v=vs.85).aspx"&gt;Win32_OperatingSystem&lt;/a&gt; and &lt;a href="http://msdn.microsoft.com/en-us/library/windows/desktop/aa394102(v=vs.85).aspx"&gt;Win32_ComputerSystem&lt;/a&gt;&lt;strong&gt;&lt;/strong&gt; classes:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/0676.image_5F00_6CCC8953.png"&gt;&lt;img width="472" height="337" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border-width: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/0160.image_5F00_thumb_5F00_249ECD77.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;And here I use only the &lt;a href="http://msdn.microsoft.com/en-us/library/windows/desktop/aa394239(v=vs.85).aspx"&gt;Win32_OperatingSystem&lt;/a&gt; class, with multiple filter criteria:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/6740.image_5F00_7FA10CFD.png"&gt;&lt;img width="474" height="337" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border-width: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/4300.image_5F00_thumb_5F00_02D2F4E6.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;As long as they &lt;em&gt;all&lt;/em&gt; evaluate TRUE, you get the policy. If you had a hundred of these criteria (please don&amp;rsquo;t) and 99 evaluate true but just one is false, the policy is skipped.&lt;/p&gt;
&lt;p&gt;Note that my examples above would catch Win2008 R2 servers also; if you&amp;rsquo;ve read my &lt;a href="http://blogs.technet.com/b/askds/archive/2008/09/11/fun-with-wmi-filters-in-group-policy.aspx"&gt;previous posts&lt;/a&gt;, you know that you can also limit queries to client operating systems using the &lt;a href="http://msdn.microsoft.com/en-us/library/windows/desktop/aa394239(v=vs.85).aspx"&gt;Win32_OperatingSystem&lt;/a&gt;&lt;strong&gt;&lt;/strong&gt; property &lt;strong&gt;OperatingSystemSKU&lt;/strong&gt;. Moreover, if you hadn&amp;rsquo;t used a predictable naming convention, you can also filter on with &lt;a href="http://msdn.microsoft.com/en-us/library/windows/desktop/aa394474(v=vs.85).aspx"&gt;Win32_SystemEnclosure&lt;/a&gt; and query the &lt;strong&gt;ChassisTypes &lt;/strong&gt;property for 8, 9, or 10 (respectively: &amp;ldquo;Portable&amp;rdquo;, &amp;ldquo;Laptop&amp;rdquo;, and &amp;ldquo;Notebook&amp;rdquo;). And no, I do not know the difference between these, it is OEM-specific. Just like &amp;ldquo;pizza box&amp;rdquo; is for servers. You stay classy, WMI.&lt;/p&gt;
&lt;h1&gt;&lt;a name="maxpoolthreads"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;Is&amp;nbsp;changing LDAP &lt;a href="http://support.microsoft.com/kb/315071"&gt;MaxPoolThreads&lt;/a&gt;&amp;nbsp;a good or bad idea?&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;MaxPoolThreads controls the maximum number of simultaneous threads per-processor that a DC uses to work on LDAP requests. By default, it&amp;rsquo;s four per processor core. Increasing this value would allow a DC/GC to handle more LDAP requests. So if you have too many LDAP clients talking to too few DCs at once, raising this can reduce LDAP application timeouts and periodic &amp;ldquo;hangs&amp;rdquo;. As you might have guessed, the biggest complainer here is often MS Exchange and Outlook. If the performance counters &amp;ldquo;ATQ Threads LDAP" &amp;amp; "ATQ Threads Total" are constantly at the maximum number based on the number of processor and MaxPoolThreads value, then you are bottlenecking LDAP.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;However!&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;DCs are already optimized to quickly return data from LDAP requests. If your hardware is even vaguely new and if you are not seeing actual issues, you should not increase this default value. MaxPoolThreads depends on non-paged pool memory, which on a Win2003 32-bit Windows OS is limited to 256MB (more on &lt;a href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;2160852"&gt;Win2008 32-bit&lt;/a&gt;). Meaning that if you still have not moved to at least x64 Windows Server 2003, don&amp;rsquo;t touch this value at all &amp;ndash; you can easily hang your DCs. It also means you need to get with the times; we stopped making a 32-bit server OS nearly three years ago and OEMS stopped selling the hardware even before that. A 64-bit system's non-paged pool limit is 128&lt;em&gt;&lt;strong&gt;GB&lt;/strong&gt;&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;In addition, changing the LDAP settings is often a Band-Aid that doesn&amp;rsquo;t address the real issue of DC capacity for your client/server base.&amp;nbsp; Use &lt;a href="http://blogs.technet.com/b/askds/archive/2010/06/08/son-of-spa-ad-data-collector-sets-in-win2008-and-beyond.aspx"&gt;SPA or AD Data Collector&lt;/a&gt; sets to determine "Clients with the Most CPU Usage" under section "Ldap Requests&amp;rdquo;. Especially if the LDAP queries are not just frequent but also gross - there are also built-in diagnostics logs to find poorly-written requests:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;code&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\ &lt;br /&gt;15 Field Engineering&lt;/span&gt;&lt;/code&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;To categorize search operations as expensive or inefficient, two DWORD registry keys are used:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS\Parameters\ &lt;br /&gt;Expensive Search Results Threshold &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS\Parameters\ &lt;br /&gt;Inefficient Search Results Threshold&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;These DWORD registry keys have the following default values:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Expensive Search Results Threshold: 10000&lt;/li&gt;
&lt;li&gt;Inefficient Search Results Threshold: 1000&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For example, here&amp;rsquo;s an inefficient result written in the DS event log; &lt;span style="background-color: #ffff00;"&gt;yuck&lt;/span&gt;, &lt;span style="background-color: #ffc000;"&gt;ick&lt;/span&gt;, &lt;span style="color: #ffffff; background-color: #ff0000;" color="#ffffff"&gt;argh&lt;/span&gt;!:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;Event Type: Information &lt;br /&gt;Event Source: NTDS General &lt;br /&gt;Event Category: Field Engineering &lt;br /&gt;Event ID: &lt;strong&gt;1644&lt;/strong&gt; &lt;br /&gt;Description: &lt;br /&gt;&lt;span style="background-color: #ffff00;"&gt;The Search operation based at RootDSE&lt;/span&gt; &lt;br /&gt;&lt;span style="background-color: #ffc000;"&gt;using the filter: &lt;br /&gt;&amp;amp; ( | ( &amp;amp; ( (objectCategory = &amp;lt;val&amp;gt;) (objectSid = *) ! ( (sAMAccountType | &amp;lt;bit_val&amp;gt;) ) ) &amp;amp; ( (objectCategory = &amp;lt;val&amp;gt;) ! ( (objectSid = *) ) ) &amp;amp; ( (objectCategory = &amp;lt;val&amp;gt;) (groupType | &amp;lt;bit_val&amp;gt;) ) ) (aNR = &amp;lt;substr&amp;gt;) &amp;lt;startSubstr&amp;gt;*) )&lt;/span&gt; &lt;br /&gt;&lt;span style="color: #ffffff; background-color: #ff0000;" color="#ffffff"&gt;visited 40 entries and returned 0 entries.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Finally, this article should be required reading to any application developers in your company:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Creating More Efficient Microsoft Active Directory-Enabled Applications -&lt;/strong&gt; &lt;br /&gt;&lt;a title="http://msdn.microsoft.com/en-us/library/windows/desktop/ms808539.aspx#efficientadapps_topic04" href="http://msdn.microsoft.com/en-us/library/windows/desktop/ms808539.aspx#efficientadapps_topic04"&gt;http://msdn.microsoft.com/en-us/library/windows/desktop/ms808539.aspx#efficientadapps_topic04&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;(The title should be altered to &amp;ldquo;Creating &lt;em&gt;even slightly&lt;/em&gt; efficient&amp;hellip;&amp;rdquo; in my experience).&lt;/p&gt;
&lt;h1&gt;&lt;a name="certmap"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;I want to implement many-to-one certificate mappings by using Issuer and Subject DN match. In altSecurityIdentities I put the following string:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;X509:&amp;lt;I&amp;gt;DC=com,DC=contoso,CN=Contoso CA&amp;lt;S&amp;gt;DC=com,DC=contoso,CN=users,CN=user name&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;In a given example, a certificate with &amp;ldquo;cn=user name, cn=users, dc=contoso, dc=com&amp;rdquo; in the Subject field will be mapped to a user account, where I define the mappings. But in that example I get one-to-one mapping. Can I use wildcards here, say:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;X509:&amp;lt;I&amp;gt;DC=com,DC=contoso,CN=Contoso CA&amp;lt;S&amp;gt;DC=com,DC=contoso,CN=users,CN=*&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;So that any certificate that contains &amp;ldquo;cn=&amp;lt;any value&amp;gt;, cn=users, dc=contoso, dc=com&amp;rdquo; will be mapped to the same user account?&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;&lt;em&gt;[Sent from Jonathan while standing in the 4PM dinner line at Bob Evans]&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Unfortunately, no. All that would do is map a certificate with a wildcard subject to that account. The only type of one-to-many mapping supported by the Active Directory mapper is configuring it to ignore the subject completely. Using this method, you can configure the AD mappings so that any certificate issued by a particular CA can be mapped to a single user account. See the following: &lt;a href="http://technet.microsoft.com/en-us/library/bb742438.aspx#ECAA"&gt;http://technet.microsoft.com/en-us/library/bb742438.aspx#ECAA&lt;/a&gt;&lt;/p&gt;
&lt;h1&gt;&lt;a name="linkid"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;I've recently been working on extending my AD schema with a new back-linked attribute pair, and I used the instructions on &lt;a href="http://blogs.technet.com/b/askds/archive/2009/12/02/link-pairs-and-configuring-bridgeheads-in-adam-adlds.aspx"&gt;this blog&lt;/a&gt; and &lt;a href="http://msdn.microsoft.com/en-us/library/bb891955(v=vs.85).aspx"&gt;MSDN&lt;/a&gt; to auto-generate the linkIDs for my new attributes. Confusingly, the resulting linkIDs are negative values (-912314983 and -912314984). The attributes and backlinks seem to work as expected, but when looking at the &lt;a href="http://msdn.microsoft.com/en-us/library/ms677270%28VS.85%29.aspx"&gt;MSDN definition of the linkID attribute&lt;/a&gt;, it specifically states that the linkID should be a positive value. Do you know why I'm getting a negative value, and if I should be concerned?&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;&lt;em&gt;[Sent from Jonathan&amp;rsquo;s favorite park bench where he feeds the pigeons]&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;The negative numbers are correct and expected, and are the result of a feature called AutoLinkID. Automatically generated linkIDs are in the range of 0xC0000000-0xFFFFFFFC (-1,073,741,824 to -4). This means that it is a good idea to use positive numbers if you are going to set the linkID manually. That way you are guaranteed not to conflict with automatically generated linkIDs.&lt;/p&gt;
&lt;p&gt;The bottom line is, this is expected under the circumstances and you're all good.&lt;/p&gt;
&lt;h1&gt;&lt;a name="dfsrlogperf"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;Is there any performance advantage to turning off the DFSR debug logging, lowering the number of logs, or moving the logs to another drive? You explained how to do this &lt;a href="http://blogs.technet.com/b/askds/archive/2009/03/23/understanding-dfsr-debug-logging-part-1-logging-levels-log-format-guid-s.aspx"&gt;here in the DFSR debug series&lt;/a&gt;, but never mentioned it in your &lt;a href="http://blogs.technet.com/b/askds/archive/2010/03/31/tuning-replication-performance-in-dfsr-especially-on-win2008-r2.aspx"&gt;DFSR performance tuning article&lt;/a&gt;.&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;Yes, you will see some performance improvements turning off the logging or lowering the log count; naturally, all this logging isn&amp;rsquo;t free, it takes CPU and disk time. But before you run off to make changes, remember that if there are &lt;em&gt;any&lt;/em&gt; problems, these logs are the only thing standing between you and the unemployment line. Your server will be much faster without any anti-virus software too, and your company&amp;rsquo;s profits higher without fire insurance; there are trade-offs in life. That&amp;rsquo;s why &amp;ndash; after some brief agonizing, followed by heavy drinking &amp;ndash; I decided not to include it in the performance article.&lt;/p&gt;
&lt;p&gt;Moving the logs to another physical disk than Windows is safe and may take some pressure of the OS drive.&lt;/p&gt;
&lt;h1&gt;&lt;a name="dcjoin"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;When I try to join this Win2008 R2 computer to the domain, it gives an error I&amp;rsquo;ve never seen before:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;"The following error occurred attempting to join the domain "contoso.com": &lt;br /&gt;The request is not supported."&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;This server was once a domain controller. During demotion, something prevented the removal of the following registry value name:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;b&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NTDS\Parameters\ &lt;br /&gt;DSA Database file&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Delete that "&lt;b&gt;Dsa Database File&lt;/b&gt;" value name and attempt to join the domain again. It should work this time. If you take a gander at the %systemroot%\debug\netsetup.log, you&amp;rsquo;ll see another clue that this is your issue:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;i&gt;NetpIsTargetImageADC: Determined this is a DC image as RegQueryValueExW loaded Services\NTDS\Parameters\DSA Database file: 0x0 &lt;br /&gt;NetpInitiateOfflineJoin: The image at C:\Windows\system32\config\SYSTEM is a DC: 0x32&lt;/i&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;We started performing this check in Windows Server 2008 R2, as part of the offline domain join code changes. Hurray for unintended consequences!&lt;/p&gt;
&lt;h1&gt;&lt;a name="lsamemory"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;We have a largish AD LDS (ADAM) instance we update daily through by importing CSV files that deletes all of yesterday&amp;rsquo;s user objects and import today&amp;rsquo;s. Since we don&amp;rsquo;t care about deleted objects, we reduced the tombstoneLifetime to 3 days. The NTDS.DIT usage, as shown by the 1646 Garbage Collection Event ID, shows 1336mb free with a total allocation of 1550mb &amp;ndash; this would suggest that there is a total of 214MB of data in the database.&lt;/p&gt;
&lt;p&gt;The problem is that Task Manager shows a total of 1,341,208K of Memory (Private Working Set) in use. The memory usage is reduced to around the 214MB size when LDS is restarted; however, when Garbage Collection runs the memory usage starts to climb. I have read many KB articles regarding GC but nothing explains what I am seeing here.&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;Generally speaking, LSASS (&lt;i&gt;and DSAMAIN&lt;/i&gt;, it&amp;rsquo;s red-headed ADLDS cousin) is designed to allocate and retain more memory &amp;ndash; especially ESE (aka &amp;ldquo;Jet&amp;rdquo;) cache memory &amp;ndash; than ordinary processes, because LSASS/DSAMAIN are the core processes of a DC or AD/LDS server. I would expect memory usage to grow heavily during the import, the deletions, and then garbage collection; unless something else put pressure on the machine for memory, I&amp;rsquo;d expect the memory usage to remain. That&amp;rsquo;s how well-written Jet database applications work &amp;ndash; they don&amp;rsquo;t give back the memory unless someone asks, because LSASS and Jet can reuse it much faster when needed if it&amp;rsquo;s already loaded; why return memory if no one wants it? That would be a performance bug unto itself.&lt;/p&gt;
&lt;p&gt;The way to show this in practical terms is to start some &lt;em&gt;other&lt;/em&gt; high-memory process and validate that DSAMAIN starts to return the demanded memory. There are test applications like this on the internet, or you can install some app that likes to gobble a lot of RAM. Sometimes I&amp;rsquo;ll just install Wireshark and load a really big saved network capture &amp;ndash; that will do it in a pinch. :-D You can also use the &lt;a href="http://support.microsoft.com/kb/556030"&gt;ESE performance counters&lt;/a&gt; under the &amp;ldquo;Database&amp;rdquo; and &amp;ldquo;Database ==&amp;gt; Instances&amp;rdquo; to see more about how much of the memory usage is Jet database cache size.&lt;/p&gt;
&lt;p&gt;Regular DCs have this behavior too, as does DFSR and do other applications. You paid for all that memory; you might as well use it.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;(Follow up from the customer where he provided a useful PowerShell &amp;ldquo;memory gobbler&amp;rdquo; example)&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;I ran the following Windows PowerShell script a few times to consume all available memory and the DSAMAIN process started releasing memory immediately as expected:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;$chunk = "XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX" &lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;for ($i = 0; $i -lt 5000; $i++) &lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;{&amp;nbsp; &lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; $chunk += $chunk &lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;}&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h1&gt;&lt;a name="usmtjump"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;When I migrate users from Windows 7 to Windows 7 using USMT 4.0, their pinned and automatic taskbar jump lists are lost. Is this expected?&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;Yes. For those &lt;span style="text-decoration: line-through;"&gt;poor $#%^&amp;amp;#s&lt;/span&gt; readers still using XP, Windows 7 introduced application taskbar pinning and a special menu called a jump list:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/1641.image_5F00_5DD5346C.png"&gt;&lt;img width="230" height="345" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border-width: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/7838.image_5F00_thumb_5F00_1CC6B508.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Pinned and Recent jump lists are not migrated by USMT, because the built-in OS Shell32 manifest called by USMT (c:\windows\winsxs\manifests\*_microsoft-windows-shell32_31bf3856ad364e35_6.1.7601.17514_non_ca4f304d289b7800.manifest) contains this specific criterion:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&amp;lt;pattern type="File"&amp;gt;%CSIDL_APPDATA%\Microsoft\Windows\Recent [*]&amp;lt;/pattern&amp;gt;&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Note how it is &lt;i&gt;not&lt;/i&gt; &lt;strong&gt;Recent\&lt;span style="background-color: #ffff00;"&gt;* [*]&lt;/span&gt;&lt;/strong&gt;, which would grab the &lt;i&gt;subfolder contents&lt;/i&gt; of Recent. It only copies the direct file contents of Recent. The pinned/automatic jump lists are stored in special files under the &lt;strong&gt;CustomDestinations&lt;/strong&gt; and &lt;strong&gt;AutomaticDestinations&lt;/strong&gt; folders inside the Recent folder. All the other contents of Recent are shortcut files to recently opened documents anywhere on the system:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/0181.image_5F00_66E1BFED.png"&gt;&lt;img width="593" height="219" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border-width: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/4380.image_5F00_thumb_5F00_1F203706.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;If you examine these special files, you'll see that they are binary, unreadable, and totally proprietary:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/0412.image_5F00_1A3D834A.png"&gt;&lt;img width="671" height="327" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border-width: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/2234.image_5F00_thumb_5F00_1D6F6B32.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Since these files are binary and embed all their data in a big blob of goo, they cannot simply be copied safely between operating systems using USMT. The paths they reference could easily change in the meantime, or the data they reference could have been intentionally skipped. The only way this would work is if the Shell team extended their shell migration plugin code to handle it. Which would be a fair amount of work, and at the time these manifests were being written, customers were not going to be migrating from Win7 to Win7. So no joy. You could always try copying them with custom XML, but I have no idea if it would work at all and you&amp;rsquo;re on your own anyway &amp;ndash; it&amp;rsquo;s not supported.&lt;/p&gt;
&lt;h1&gt;&lt;a name="des"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;We have a third party application that requires &lt;a href="http://blogs.technet.com/b/askds/archive/2010/10/19/hunting-down-des-in-order-to-securely-deploy-kerberos.aspx"&gt;DES encryption for Kerberos&lt;/a&gt;. It wasn&amp;rsquo;t working from our Windows 7 clients though, so we enabled the security group policy &amp;ldquo;Network security: Configure encryption types allowed for Kerberos&amp;rdquo; to allow DES. After that though, these Windows 7 clients stopped working in many other operations, with event log errors like:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;Event ID: 4 &lt;br /&gt;Source: Kerberos &lt;br /&gt;Type: Error &lt;br /&gt;"The kerberos client received a KRB_AP_ERR_MODIFIED error from the server host/myserver.contoso.com. This indicates that the password used to encrypt the kerberos service ticket is different than that on the target server. Commonly, this is due to identically named machine accounts in the target realm (domain.com), and the client realm. Please contact your system administrator."&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;And &amp;ldquo;The target principal name is incorrect&amp;rdquo; or &amp;ldquo;The target account name is incorrect&amp;rdquo; errors connecting to network resources.&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;When you enable DES on Windows 7, you need to ensure you are not accidentally &lt;em&gt;disabling&lt;/em&gt; the other cipher suites. So &lt;strong&gt;&lt;em&gt;don&amp;rsquo;t&lt;/em&gt;&lt;/strong&gt; do this:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/4380.image_5F00_7871AAB8.png"&gt;&lt;img width="429" height="233" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border-width: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/0412.image_5F00_thumb_5F00_7BA392A0.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;That means &lt;em&gt;only&lt;/em&gt; DES is supported and you just disabled RC4, AES, etc.&lt;/p&gt;
&lt;p&gt;Instead, &lt;strong&gt;&lt;em&gt;do this&lt;/em&gt;&lt;/strong&gt;:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/2234.image_5F00_41B44FB4.png"&gt;&lt;img width="429" height="250" title="image" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border-width: 0px;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/3632.image_5F00_thumb_5F00_07C50CC8.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;If it exists at all and you want DES, this registry DWORD value to be 0x7fffffff on Windows 7 or Win2008 R2:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\Kerberos\Parameters\ &lt;br /&gt;SupportedEncryptionTypes&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;If it&amp;rsquo;s set to 0x3, all heck will break loose. This security policy interface is admittedly tiresome in that it has no &amp;ldquo;enabled/disabled&amp;rdquo; toggle. Use &lt;strong&gt;GPRESULT /H&lt;/strong&gt; or&lt;strong&gt; /Z&lt;/strong&gt; to see how it&amp;rsquo;s applying if you&amp;rsquo;re not sure about the actual settings.&lt;/p&gt;
&lt;h1&gt;&lt;a name="other"&gt;&lt;/a&gt;Other Stuff&lt;/h1&gt;
&lt;p&gt;Windows 8 Consumer Preview releases February 29th, &lt;a href="http://www.bing.com/search?q=%22windows+8+consumer+preview%22+february+29&amp;amp;qs=n&amp;amp;form=QBRE&amp;amp;pq=%2522windows%25208%2520consumer%2520preview%2522%2520february%252029&amp;amp;sc=0-35&amp;amp;sp=-1&amp;amp;sk="&gt;as if you didn&amp;rsquo;t already know it&lt;/a&gt;. Don&amp;rsquo;t ask me if this also means Windows Server 8 Beta the same exact day, I can&amp;rsquo;t say. But it definitely means the last 16 months of my life finally start showing some results. As will this blog&amp;hellip;&lt;/p&gt;
&lt;p&gt;Apparently we&amp;rsquo;ve been &lt;a href="http://whatculture.com/film/george-lucas-says-greedo-shot-han-first-weve-been-wrong-all-these-years.php?utm_source=rss&amp;amp;utm_medium=rss&amp;amp;utm_campaign=george-lucas-says-greedo-shot-han-first-weve-been-wrong-all-these-years"&gt;wrong about Han and Greedo&lt;/a&gt; since day one. I &lt;em&gt;want &lt;/em&gt;to be wrong though. Thanks for passing this along Tony. And speaking of which, thanks to Ted O and the rest of the gang at LucasArts for the awesome tee!&lt;/p&gt;
&lt;p&gt;This is a &amp;hellip; &lt;a href="http://www.youtube.com/watch?v=1bG6uA7ln-c&amp;amp;feature=player_embedded"&gt;creepily good music video&lt;/a&gt;? Definitely a nice find, &lt;a href="http://blogs.technet.com/b/markmoro/"&gt;Mark&lt;/a&gt;!&lt;/p&gt;
&lt;blockquote&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;iframe width="560" height="315" src="http://www.youtube.com/embed/1bG6uA7ln-c" frameborder="0" allowfullscreen="allowfullscreen"&gt;&lt;/iframe&gt; &lt;br /&gt;&lt;span style="font-size: xx-small;" size="1"&gt;This is basically my home video collection&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;My new favorite site of the week? &lt;a href="http://theawesomer.com"&gt;The Awesomer&lt;/a&gt;. Do not visit if you have to be somewhere in an hour.&lt;/p&gt;
&lt;p&gt;Wait, no&amp;hellip; my new favorite site is &lt;a href="http://www.thatsnerdalicious.com/"&gt;That&amp;rsquo;s Nerdaliscious.&lt;/a&gt; Do not read if hungry or dorky.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Sick of everyone going on about Angry Birds? Love Chuck Norris? &lt;a href="http://www.youtube.com/watch?v=AKQ2Xks5fWE&amp;amp;feature=youtu.be"&gt;Go here now&lt;/a&gt;. There are a &lt;a href="http://www.youtube.com/view_play_list?annotation_id=annotation_878262&amp;amp;p=8D6F7CC6F03A7E84&amp;amp;src_vid=25_bYxH-wm0&amp;amp;feature=iv"&gt;lot&lt;/a&gt; of these; don't miss Mortal Combat versus Donkey Kong.&lt;/p&gt;
&lt;p&gt;Ah, &lt;a href="http://pics.blameitonthevoices.com/s.php?f=022012&amp;amp;p=waldo_at_the_superbowl.jpg"&gt;there&amp;rsquo;s Waldo&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Likely the coolest advertisement for something that doesn&amp;rsquo;t yet exist that you will see this year.&lt;/p&gt;
&lt;blockquote&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;iframe width="560" height="315" src="http://www.youtube.com/embed/jZkHpNnXLB0" frameborder="0" allowfullscreen="allowfullscreen"&gt;&lt;/iframe&gt; &lt;br /&gt;&lt;span style="font-size: xx-small;" size="1"&gt;I need to buy stock in SC Johnson. Can you &lt;em&gt;imagine&lt;/em&gt; the Windex sales?!&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Until next time.&lt;/p&gt;
&lt;p&gt;- Ned &amp;ldquo;Generation X&amp;rdquo; Pyle with Jonathan &amp;ldquo;The Greatest Generation&amp;rdquo; Stephens&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3480359" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/askds/archive/tags/group+policy/">group policy</category><category domain="http://blogs.technet.com/b/askds/archive/tags/DFSR/">DFSR</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Authorization/">Authorization</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Certificates/">Certificates</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Kerberos/">Kerberos</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Authentication/">Authentication</category><category domain="http://blogs.technet.com/b/askds/archive/tags/AD+LDS/">AD LDS</category><category domain="http://blogs.technet.com/b/askds/archive/tags/WMI/">WMI</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Windows+Server+2008+R2/">Windows Server 2008 R2</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Windows+7/">Windows 7</category><category domain="http://blogs.technet.com/b/askds/archive/tags/DFSR+Debug+Logging/">DFSR Debug Logging</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Other+Blogs/">Other Blogs</category><category domain="http://blogs.technet.com/b/askds/archive/tags/USMT/">USMT</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Mail+Sack/">Mail Sack</category><category domain="http://blogs.technet.com/b/askds/archive/tags/certification+authority/">certification authority</category><category domain="http://blogs.technet.com/b/askds/archive/tags/DFSR+Performance/">DFSR Performance</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Jonathan+Stephens/">Jonathan Stephens</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Ned+Pyle/">Ned Pyle</category><category domain="http://blogs.technet.com/b/askds/archive/tags/USMT+Behaviors/">USMT Behaviors</category></item><item><title>Purging Old NT Security Protocols</title><link>http://blogs.technet.com/b/askds/archive/2012/02/02/purging-old-nt-security-protocols.aspx</link><pubDate>Thu, 02 Feb 2012 23:40:07 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3478646</guid><dc:creator>NedPyle [MSFT]</dc:creator><slash:comments>11</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/rsscomments.aspx?WeblogPostID=3478646</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/commentapi.aspx?WeblogPostID=3478646</wfw:comment><comments>http://blogs.technet.com/b/askds/archive/2012/02/02/purging-old-nt-security-protocols.aspx#comments</comments><description>&lt;p&gt;Hi folks, &lt;a href="http://blogs.technet.com/b/askds/archive/tags/Ned+Pyle/"&gt;Ned&lt;/a&gt; here again (with &lt;a href="http://blogs.technet.com/b/askds/archive/tags/jonathan+stephens/"&gt;some&lt;/a&gt; &lt;a href="http://blogs.technet.com/b/askds/archive/tags/Dave+Fisher/"&gt;friends&lt;/a&gt;). Everyone knows that Kerberos is Microsoft’s preeminent security protocol and that NTLM is both &lt;a href="http://blogs.technet.com/b/askds/archive/2011/09/15/is-this-horse-dead-yet-ntlm-bottlenecks-and-the-rpc-runtime.aspx"&gt;inefficient&lt;/a&gt; and, in some iterations, not strong enough to avoid concerted attack. NTLM V2 using complex passwords stands up well to common hash cracking tools like Cain and Abel, Ophcrack, or John the Ripper. On the other hand, NTLM V1 is defeated far faster and LM is effectively no protection at all.&lt;/p&gt;  &lt;p&gt;I discussed &lt;a href="http://blogs.technet.com/b/askds/archive/2009/10/08/ntlm-blocking-and-you-application-analysis-and-auditing-methodologies-in-windows-7.aspx"&gt;NTLM auditing&lt;/a&gt; years ago, when Windows 7 and Windows Server 2008 R2 introduced the concept of NTLM blocking. That article was for well-controlled environments where you thought that there was some chance of disabling NTLM – only modern clients and servers, the latest applications, and Active Directory. In a few other articles, I gave some further details on the &lt;a href="http://blogs.technet.com/b/askds/archive/2011/07/29/friday-mail-sack-anchors-aweigh-edition.aspx#auditntlm"&gt;limitations&lt;/a&gt; of the Windows auditing system logging. It turns out that while we’re ok at telling when NTLM was used, we’re &lt;a href="http://blogs.technet.com/b/askds/archive/2011/08/05/friday-mail-sack-beard-seconds-edition.aspx#ntlm"&gt;not great&lt;/a&gt; at describing which flavor. For instance, Windows Server 2008+security auditing can tell you about the NTLM version through the &lt;b&gt;4624&lt;/b&gt; event that states a &lt;b&gt;Package Name (NTLM only): NTLM V1 &lt;/b&gt;or &lt;b&gt;Package Name (NTLM only): NTLM V2&lt;/b&gt;, but all prior operating systems cannot. None of the older auditing can tell you if LM is used either. Windows Server 2008 R2 NTLM auditing only shows you NTLM usage in general.&lt;/p&gt;  &lt;p&gt;Today the troika of &lt;a href="http://blogs.technet.com/b/askds/archive/tags/Dave+Fisher/"&gt;Dave&lt;/a&gt;, &lt;a href="http://blogs.technet.com/b/askds/archive/tags/jonathan+stephens/"&gt;Jonathan&lt;/a&gt;, and &lt;a href="http://blogs.technet.com/b/askds/archive/tags/Ned+Pyle/"&gt;Ned&lt;/a&gt; are here to help you discover which computers and applications are using NTLM V1 and LM security, &lt;i&gt;regardless of your operating system&lt;/i&gt;. It’s safe to say that some people aren’t going to like our answers or how much work this entails, but that’s life; when LM security was created as part of &lt;b&gt;L&lt;/b&gt;AN &lt;b&gt;M&lt;/b&gt;anager and OS/2 by Microsoft and IBM, Dave and I were in grade school and Jonathan was only 48. &lt;/p&gt;  &lt;p&gt;If you need to keep using NTLM &lt;i&gt;V2 &lt;/i&gt;and simply want to hunt down the less secure precursors, this should help. &lt;/p&gt;  &lt;p&gt;&lt;b&gt;Finding NTLM V1 and LM Usage via network captures&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;The only universal, OS-agnostic way you can tell which clients are sending NTLMv1 and LM challenges is by examining a network trace taken from destination computers. Using Netmon 3.4 or another network capture tool, look for packets with a negotiated NTLM security mechanism.&lt;/p&gt;  &lt;p&gt;This first example is with &lt;a href="http://technet.microsoft.com/en-us/library/cc960646.aspx"&gt;LMCompatibilityLevel&lt;/a&gt; set to &lt;b&gt;0 &lt;/b&gt;on clients. This example is an SMB session request packet, specifying NTLM authentication.&lt;/p&gt;  &lt;p&gt;Here is the SMB SESSION SETUP request, which specifies the security token mechanism:&lt;/p&gt; &lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160; Frame: Number = 15, Captured Frame Length = 220, MediaType = ETHERNET&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;+ Ethernet: Etype = Internet IP (IPv4),DestinationAddress:[00-15-5D-05-B4-44],SourceAddress:[00-15-5D-05-B4-49]&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;+ Ipv4: Src = 10.10.10.20, Dest = 10.10.10.27, Next Protocol = TCP, Packet ID = 747, Total IP Length = 206&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;+ Tcp: Flags=...AP..., SrcPort=49235, DstPort=Microsoft-DS(445), PayloadLen=166, Seq=2204022974 - 2204023140, Ack=820542383, Win=32724 (scale factor 0x2) = 130896&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;+ SMBOverTCP: Length = 162&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;- SMB2: C&amp;#160;&amp;#160; SESSION SETUP (0x1) &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160; SMBIdentifier: SMB&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160; + SMB2Header: C SESSION SETUP (0x1),TID=0x0000, MID=0x0002, PID=0xFEFF, SID=0x0000&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160; - CSessionSetup: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; StructureSize: 25 (0x19)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; VcNumber: 0 (0x0)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160; + SecurityMode: 1 (0x1)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160; + Capabilities: 0x1&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Channel: 0 (0x0)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; SecurityBufferOffset: 88 (0x58)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; SecurityBufferLength: 74 (0x4A)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; PreviousSessionId: 0 (0x0)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160; - securityBlob: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160; - GSSAPI: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; - InitialContextToken: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + ApplicationHeader: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + ThisMech: SpnegoToken (1.3.6.1.5.5.2)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; - InnerContextToken: 0x1&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; - SpnegoToken: 0x1&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + ChoiceTag: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; - NegTokenInit: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + SequenceHeader: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + Tag0: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + MechTypes: Prefer NLMP (1.3.6.1.4.1.311.2.2.10)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + Tag2: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + OctetStringHeader: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;font style="background-color: rgb(255, 255, 0);"&gt;-&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box; mso-highlight: yellow;"&gt;MechToken: NTLM NEGOTIATE MESSAGE&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; - NLMP: NTLM NEGOTIATE MESSAGE&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Signature: NTLMSSP&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; MessageType: Negotiate Message (0x00000001)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + NegotiateFlags: 0xE2088297 (NTLM v2128-bit encryption, Always Sign)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + DomainNameFields: Length: 0, Offset: 0&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + WorkstationFields: Length: 0, Offset: 0&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + Version: Windows 6.1 Build 7601 NLMPv15&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;  &lt;p&gt;Next, the server sends its NTLM challenge back to the client:&lt;/p&gt; &lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160; Frame: Number = 16, Captured Frame Length = 447, MediaType = ETHERNET&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;+ Ethernet: Etype = Internet IP (IPv4),DestinationAddress:[00-15-5D-05-B4-49],SourceAddress:[00-15-5D-05-B4-44]&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;+ Ipv4: Src = 10.10.10.27, Dest = 10.10.10.20, Next Protocol = TCP, Packet ID = 24310, Total IP Length = 433&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;+ Tcp: Flags=...AP..., SrcPort=Microsoft-DS(445), DstPort=49235, PayloadLen=393, Seq=820542383 - 820542776, Ack=2204023140, Win=512 (scale factor 0x8) = 131072&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;+ SMBOverTCP: Length = 389&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;- SMB2: R&amp;#160; - NT Status: System - Error, Code = (22) STATUS_MORE_PROCESSING_REQUIRED&amp;#160; SESSION SETUP (0x1), SessionFlags=0x0 &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160; SMBIdentifier: SMB&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160; + SMB2Header: R SESSION SETUP (0x1),TID=0x0000, MID=0x0002, PID=0xFEFF, SID=0x0019&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160; - RSessionSetup: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; StructureSize: 9 (0x9)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160; + SessionFlags: 0x0&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; SecurityBufferOffset: 72 (0x48)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; SecurityBufferLength: 317 (0x13D)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160; - securityBlob: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160; - GSSAPI: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; - NegotiationToken: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + ChoiceTag: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; - NegTokenResp: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + SequenceHeader: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + Tag0: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + NegState: accept-incomplete (1)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + Tag1: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + SupportedMech: NLMP (1.3.6.1.4.1.311.2.2.10)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + Tag2: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + OctetStringHeader: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; - ResponseToken: NTLM CHALLENGE MESSAGE&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; - NLMP: NTLM CHALLENGE MESSAGE&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Signature: NTLMSSP&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; MessageType: Challenge Message (0x00000002)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + TargetNameFields: Length: 12, Offset: 56&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + NegotiateFlags: 0xE2898215 (NTLM v2128-bit encryption, Always Sign)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + &lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box; mso-highlight: yellow;"&gt;&lt;font style="background-color: rgb(255, 255, 0);"&gt;ServerChallenge: 67F9C5F851F2CD73&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Reserved: Binary Large Object (8 Bytes)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + TargetInfoFields: Length: 214, Offset: 68&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + Version: Windows 6.1 Build 7601 NLMPv15&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; TargetNameString: CORP01&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + AvPairs: 7 pairs&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;  &lt;p&gt;The client calculates the response to the challenge, using the various available hashes of the password. Note how this response includes both LM and NTLMv1 challenge responses.&lt;/p&gt; &lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&amp;#160;&lt;font face="Consolas"&gt; Frame: Number = 17, Captured Frame Length = 401, MediaType = ETHERNET&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;+ Ethernet: Etype = Internet IP (IPv4),DestinationAddress:[00-15-5D-05-B4-44],SourceAddress:[00-15-5D-05-B4-49]&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;+ Ipv4: Src = 10.10.10.20, Dest = 10.10.10.27, Next Protocol = TCP, Packet ID = 748, Total IP Length = 387&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;+ Tcp: Flags=...AP..., SrcPort=49235, DstPort=Microsoft-DS(445), PayloadLen=347, Seq=2204023140 - 2204023487, Ack=820542776, Win=32625 (scale factor 0x2) = 130500&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;+ SMBOverTCP: Length = 343&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;- SMB2: C&amp;#160;&amp;#160; SESSION SETUP (0x1) &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160; SMBIdentifier: SMB&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160; + SMB2Header: C SESSION SETUP (0x1),TID=0x0000, MID=0x0003, PID=0xFEFF, SID=0x0019&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160; - CSessionSetup: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; StructureSize: 25 (0x19)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; VcNumber: 0 (0x0)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160; + SecurityMode: 1 (0x1)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160; + Capabilities: 0x1&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Channel: 0 (0x0)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160; SecurityBufferOffset: 88 (0x58)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; SecurityBufferLength: 255 (0xFF)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; PreviousSessionId: 0 (0x0)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160; - securityBlob: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160; - GSSAPI: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; - NegotiationToken: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + ChoiceTag: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; - NegTokenResp: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + SequenceHeader: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + Tag0: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + NegState: accept-incomplete (1)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + Tag2: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + OctetStringHeader: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; - ResponseToken: NTLM AUTHENTICATE MESSAGEVersion:v1, Domain: CORP01, User: Administrator, Workstation: CONTOSO-CLI-01&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; - NLMP: NTLM AUTHENTICATE MESSAGEVersion:v1, Domain: CORP01, User: Administrator, Workstation: CONTOSO-CLI-01&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Signature: NTLMSSP&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; MessageType: Authenticate Message (0x00000003)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + LmChallengeResponseFields: Length: 24, Offset: 154&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + NtChallengeResponseFields: Length: 24, Offset: 178&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + DomainNameFields: Length: 12, Offset: 88&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + UserNameFields: Length: 26, Offset: 100&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + WorkstationFields: Length: 28, Offset: 126&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + EncryptedRandomSessionKeyFields: Length: 16, Offset: 202&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + NegotiateFlags: 0xE2888215 (NTLM v2128-bit encryption, Always Sign)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + Version: Windows 6.1 Build 7601 NLMPv15&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + MessageIntegrityCheckNotPresent: 6243C42AF68F9DFE30BD31BFC722B4C0&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; DomainNameString: CORP01&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; UserNameString: Administrator&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; WorkstationString: CONTOSO-CLI-01&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + &lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box; mso-highlight: yellow;"&gt;&lt;font style="background-color: rgb(255, 255, 0);"&gt;LmChallengeResponseStruct: 3995E087245B6F7100000000000000000000000000000000&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + &lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box; mso-highlight: yellow;"&gt;&lt;font style="background-color: rgb(255, 255, 0);"&gt;NTLMV1ChallengeResponse: B0751BDCB116BA5737A51962328D5CCD19EEBEBB15A69B1E&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + SessionKeyString: 397DACB158C9F10EF4903F10D4CBE032&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + Tag3: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + OctetStringHeader: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + MechListMic: Version: 1&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;  &lt;p&gt;The server then responds with successful negotiation state:&lt;/p&gt; &lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160; Frame: Number = 18, Captured Frame Length = 159, MediaType = ETHERNET&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;+ Ethernet: Etype = Internet IP (IPv4),DestinationAddress:[00-15-5D-05-B4-49],SourceAddress:[00-15-5D-05-B4-44]&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;+ Ipv4: Src = 10.10.10.27, Dest = 10.10.10.20, Next Protocol = TCP, Packet ID = 24312, Total IP Length = 145&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;+ Tcp: Flags=...AP..., SrcPort=Microsoft-DS(445), DstPort=49235, PayloadLen=105, Seq=820542776 - 820542881, Ack=2204023487, Win=510 (scale factor 0x8) = 130560&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;+ SMBOverTCP: Length = 101&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;- SMB2: R&amp;#160;&amp;#160; SESSION SETUP (0x1), SessionFlags=0x0 &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160; SMBIdentifier: SMB&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160; + SMB2Header: R SESSION SETUP (0x1),TID=0x0000, MID=0x0003, PID=0xFEFF, SID=0x0019&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160; - RSessionSetup: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; StructureSize: 9 (0x9)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160; + SessionFlags: 0x0&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; SecurityBufferOffset: 72 (0x48)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; SecurityBufferLength: 29 (0x1D)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160; - securityBlob: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160; - GSSAPI: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; - NegotiationToken: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + ChoiceTag: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; - NegTokenResp: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + SequenceHeader: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + Tag0: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; +&lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box; mso-highlight: yellow;"&gt;&lt;font style="background-color: rgb(255, 255, 0);"&gt;NegState: accept-completed (0)&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + Tag3: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + OctetStringHeader: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + MechListMic: Version: 1&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;  &lt;p&gt;To contrast this, consider the challenge response packet when &lt;b&gt;LMCompatibility&lt;/b&gt; is set to &lt;b&gt;4 &lt;/b&gt;or&lt;b&gt; 5 &lt;/b&gt;on the client (meaning it is not allowed to send anything but NTLM V2). The LM response is null, while the NTLMv1 response isn't included at all.&lt;/p&gt; &lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160; Frame: Number = 17, Captured Frame Length = 763, MediaType = ETHERNET&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;+ Ethernet: Etype = Internet IP (IPv4),DestinationAddress:[00-15-5D-05-B4-44],SourceAddress:[00-15-5D-05-B4-49]&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;+ Ipv4: Src = 10.10.10.20, Dest = 10.10.10.27, Next Protocol = TCP, Packet ID = 844, Total IP Length = 749&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;+ Tcp: Flags=...AP..., SrcPort=49231, DstPort=Microsoft-DS(445), PayloadLen=709, Seq=4045369997 - 4045370706, Ack=881301203, Win=32625 (scale factor 0x2) = 130500&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;+ SMBOverTCP: Length = 705&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;- SMB2: C&amp;#160;&amp;#160; SESSION SETUP (0x1) &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160; SMBIdentifier: SMB&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160; + SMB2Header: C SESSION SETUP (0x1),TID=0x0000, MID=0x0003, PID=0xFEFF, SID=0x0021&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160; - CSessionSetup: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; StructureSize: 25 (0x19)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; VcNumber: 0 (0x0)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160; + SecurityMode: 1 (0x1)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160; + Capabilities: 0x1&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Channel: 0 (0x0)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; SecurityBufferOffset: 88 (0x58)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; SecurityBufferLength: 617 (0x269)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; PreviousSessionId: 0 (0x0)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160; - securityBlob: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160; - GSSAPI: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160; - NegotiationToken: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + ChoiceTag: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; - NegTokenResp: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + SequenceHeader: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + Tag0: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + NegState: accept-incomplete (1)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + Tag2: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + OctetStringHeader: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; - ResponseToken: NTLM AUTHENTICATE MESSAGEVersion:v2, Domain: CORP01, User: Administrator, Workstation: CONTOSO-CLI-01&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; - NLMP: NTLM AUTHENTICATE MESSAGEVersion:v2, Domain: CORP01, User: Administrator, Workstation: CONTOSO-CLI-01&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Signature: NTLMSSP&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; MessageType: Authenticate Message (0x00000003)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + LmChallengeResponseFields: Length: 24, Offset: 154&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + NtChallengeResponseFields: Length: 382, Offset: 178&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + DomainNameFields: Length: 12, Offset: 88&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + UserNameFields: Length: 26, Offset: 100&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + WorkstationFields: Length: 28, Offset: 126&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + EncryptedRandomSessionKeyFields: Length: 16, Offset: 560&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + NegotiateFlags: 0xE2888215 (NTLM v2128-bit encryption, Always Sign)&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + Version: Windows 6.1 Build 7601 NLMPv15&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + MessageIntegrityCheck: 2B69C069DD922D4A841D0EC43939DF0F&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; DomainNameString: CORP01&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; UserNameString: Administrator&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; WorkstationString: CONTOSO-CLI-01&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + &lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box; mso-highlight: yellow;"&gt;&lt;font style="background-color: rgb(255, 255, 0);"&gt;LmChallengeResponseStruct: 000000000000000000000000000000000000000000000000&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + &lt;span style="background-image: none; background-attachment: scroll; background-repeat: repeat; background-size: auto; background-origin: padding-box; background-clip: border-box; mso-highlight: yellow;"&gt;&lt;font style="background-color: rgb(255, 255, 0);"&gt;NTLMV2ChallengeResponse: CD22D7CC09140E02C3D8A5AB623899A8&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + SessionKeyString: AF31EDFAAF8F38D1900D7FBBDCB43760&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + Tag3: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + OctetStringHeader: &lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font face="Consolas"&gt;&lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;&lt;/font&gt;  &lt;p class="Code" style="margin: 0in 0in 0pt; line-height: normal; list-style-type: disc; background-color: rgb(191, 191, 191);"&gt;&lt;span&gt;&lt;font face="Consolas"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; + MechListMic: Version: 1&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;font style="font-size: 12pt;"&gt;&lt;/font&gt;  &lt;p&gt;By taking traces and filtering on the NTLMV1ChallengeResponse field, you find those hosts that are sending NTLMv1 responses and determine if you need to upgrade them or if they simply have the wrong LMcompatibility values set through security policy.&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Finding LM usage via Netlogon debug logs&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;If you just want to detect LM authentication and not looking to spend time in network captures, you can instead enable Netlogon logging on all DCs and servers in the environment. &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;font face="Consolas"&gt;Nltest /dbflag:2080ffff        &lt;br /&gt;&lt;/font&gt;&lt;font face="Consolas"&gt;net stop NetLogon       &lt;br /&gt;&lt;/font&gt;&lt;font face="Consolas"&gt;net start NetLogon&lt;/font&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;This creates the netlogon.log in the C:\Windows\Debug folder and it can grow to a maximum of 20 Mb by default. At that point, the server renames the file to netlogon.bak and a new netlogon.log file started. At 20Mb, the server deletes netlogon.bak, renames the netlogon.log to netlogon.bak, and a new netlogon.log file started. To make these log files larger, you can use a registry entry or group policy:&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Registry &lt;/b&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;font face="Consolas"&gt;Path: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters        &lt;br /&gt;Value Name: MaximumLogFileSize        &lt;br /&gt;Value Type: REG_DWORD         &lt;br /&gt;Value Data: &amp;lt;maximum log file size in bytes&amp;gt;&lt;/font&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;b&gt;Group Policy&lt;/b&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;font face="Consolas"&gt;\Computer Configuration\Administrative Templates\System\Net Logon\Maximum Log File Size&lt;/font&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;You aren't trying to capture all data here - just useful samples - but if they wrap so much that you're unsure if they are accurate at all, increasing size is a good idea. As an alternative, you can create a scheduled task that runs ONSTART or a computer startup script. Either of them can use this batch file to make backups of the netlogon log by date/time and the computer name:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;font face="Consolas"&gt;REM Sample script to copy the netlogon.bak to a netlogon_DATETIME_COMPUTERNAME.log backup form every 5 minutes&lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font face="Consolas"&gt;:start        &lt;br /&gt;if exist %windir%\debug\netlogon.bak goto copylog        &lt;br /&gt;        &lt;br /&gt;:&lt;/font&gt;&lt;font face="Consolas"&gt;copylog_return        &lt;br /&gt;sleep 300         &lt;br /&gt;goto start         &lt;br /&gt;        &lt;br /&gt;:copylog        &lt;br /&gt;for /f &amp;quot;tokens=1-7 delims=/:., &amp;quot; %%a in (&amp;quot;%DATE% %TIME%&amp;quot;) do (set DATETIME=%%a-%%b-%%c_%%d-%%e-%%f)         &lt;br /&gt;copy /v %windir%\debug\netlogon.bak %windir%\debug\netlogon_%DATETIME%_%COMPUTERNAME%.log         &lt;br /&gt;if %ERRORLEVEL% EQU 0 del %windir%\debug\netlogon.bak        &lt;br /&gt;goto copylog_return&lt;/font&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Periodically, gather all of the NetLogon logs from the DCs and servers and place them in a single folder. Once you have assembled the NetLogon logs into a single spot, you may then use the following &lt;a href="http://www.microsoft.com/download/en/details.aspx?displaylang=en&amp;amp;id=24659"&gt;LogParser&lt;/a&gt; command from that folder to parse them all for a count of unique &lt;a href="http://msdn.microsoft.com/en-us/library/cc237270(v=prot.13).aspx"&gt;UAS&lt;/a&gt; logons to the domain controller by workstation: &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;font face="Consolas"&gt;Logparser.exe &amp;quot;SELECT TO_UPPERCASE(EXTRACT_SUFFIX(TEXT,0,'returns ')) AS ERR, TO_UPPERCASE (extract_prefix(extract_suffix(TEXT, 0, 'NetrLogonUasLogon of '), 0, 'from ')) as USER, TO_UPPERCASE (extract_prefix(extract_suffix(TEXT, 0, 'from '), 0, 'returns ')) as WORKSTATION, COUNT(*) FROM '*netlogon.*' WHERE INDEX_OF(TO_UPPERCASE (TEXT),'LOGON') &amp;gt;0 AND INDEX_OF(TO_UPPERCASE(TEXT),'RETURNS') &amp;gt;0 AND INDEX_OF(TO_UPPERCASE(TEXT),'NETRLOGONUASLOGON') &amp;gt;0 GROUP BY ERR, USER, WORKSTATION ORDER BY COUNT(*) DESC&amp;quot; -i:TEXTLINE -rtp:-1 &amp;gt;UASLOGON_USER_BY_WORKSTATION.txt&lt;/font&gt; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;UASLOGON_USER_BY_WORKSTATION.txt contains the unique computers and counts. LogParser is available for download from &lt;a href="http://www.microsoft.com/download/en/details.aspx?displaylang=en&amp;amp;id=24659"&gt;here&lt;/a&gt;. &lt;/p&gt;  &lt;p&gt;FIND and PowerShell are options here as well. The simplest approach is just to return the lines, perhaps into a text file for later sorting in say, Excel (which is very fast at sorting and allows you to organize your data).&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/7585.image_5F00_108642B5.png"&gt;&lt;img title="image" style="display: inline; background-image: none;" border="0" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/7288.image_5F00_thumb_5F00_24332C49.png" width="628" height="91" /&gt;&lt;/a&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/4846.image_5F00_2E8450A9.png"&gt;&lt;img title="image" style="display: inline; background-image: none;" border="0" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/0825.image_5F00_thumb_5F00_4DC6F77C.png" width="628" height="57" /&gt;&lt;/a&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/1803.image_5F00_1AF6F108.png"&gt;&lt;img title="image" style="display: inline; background-image: none;" border="0" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/1803.image_5F00_thumb_5F00_00B687E4.png" width="473" height="385" /&gt;&lt;/a&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;I'll wager someone in the comments will take on the rather boring challenge of exactly duplicating what LogParser does. I didn't have the energy this time around. :)&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Final thoughts&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;Microsoft stopped using LM after Windows 95/98/ME. If you do find specific LM-only usage and you don't have any (unsupported) Win9X computers, this is a third party application. A really heinous one. &lt;/p&gt;  &lt;p&gt;All supported versions of Windows obey the LMCompatibility registry setting, and can use NTLMv2 just as easily as NTLMv1. At that point, analyzing network traces just becomes useful for tracking down those hosts that have applied the policy, but have not yet been rebooted. Considering how unsafe LM and NTLMv1 are, enabling NoLMHash and LMCompatibility 4 or 5 on all computers may be a faster alternative to auditing. It could cause some temporary outages, but would definitely catch anyone requiring unsafe protocols. There's no better auditing that a complaining application administrator.&lt;/p&gt;  &lt;p&gt;Finally, do not limit your NTLM inventory to domain controllers and file or application servers. A comprehensive project requires you examine all computers in the environment, as even a Windows XP workstation can be a &amp;quot;server&amp;quot; for some application. Use a multi-pronged approach, where you also inventory operating systems through network probing - if you have Windows 95 or old SAMBA lying around somewhere on a shop floor, they are almost guaranteed to use insecure protocols.&lt;/p&gt;  &lt;p&gt;Until next time,&lt;/p&gt;  &lt;p&gt;- Ned “and Dave and Jonathan and Jonathan's in-home elderly care nurse” Pyle&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3478646" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/askds/archive/tags/network/">network</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Security/">Security</category><category domain="http://blogs.technet.com/b/askds/archive/tags/NTLM/">NTLM</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Jonathan+Stephens/">Jonathan Stephens</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Dave+Fisher/">Dave Fisher</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Ned+Pyle/">Ned Pyle</category></item><item><title>Friday Mail Sack: Carl Sandburg Edition</title><link>http://blogs.technet.com/b/askds/archive/2012/01/28/friday-mail-sack-carl-sandburg-edition.aspx</link><pubDate>Sat, 28 Jan 2012 19:17:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3477646</guid><dc:creator>Jonathan Stephens, MSFT</dc:creator><slash:comments>7</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/rsscomments.aspx?WeblogPostID=3477646</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/commentapi.aspx?WeblogPostID=3477646</wfw:comment><comments>http://blogs.technet.com/b/askds/archive/2012/01/28/friday-mail-sack-carl-sandburg-edition.aspx#comments</comments><description>&lt;p&gt;Hi folks, &lt;a href="http://blogs.technet.com/b/askds/archive/tags/Jonathan+Stephens/"&gt;Jonathan&lt;/a&gt; again. &lt;a href="http://blogs.technet.com/b/askds/archive/tags/Ned+Pyle/"&gt;Ned&lt;/a&gt; is taking some time off visiting his old stomping grounds &amp;ndash; the land of Mother-in-Laws and heart-breaking baseball. Or, as Sandburg put it:&lt;/p&gt;
&lt;p&gt;&amp;ldquo;&lt;a href="http://carl-sandburg.com/chicago.htm"&gt;Hog Butcher for the World&lt;/a&gt;, &lt;br /&gt;Tool Maker, Stacker of Wheat, &lt;br /&gt;Player with Railroads and the Nation's Freight Handler; &lt;br /&gt;Stormy, husky, brawling, &lt;br /&gt;City of the Big Shoulders&amp;rdquo;&lt;/p&gt;
&lt;p&gt;Cool, huh?&lt;/p&gt;
&lt;p&gt;Anyway, today we talk about:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#kdc"&gt;DC utilization&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#dfsn1"&gt;DFS Namespace interoperability&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#dfsn2"&gt;DFSN and NTFS mount points&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#usmt"&gt;Backing up Themes with USMT&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#linkid"&gt;Automatic LinkID creation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#delegate"&gt;Delegating update of the servicePrincipalName attribute&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#enabled"&gt;Enabled property on PowerShell computer objects&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#other"&gt;Other stuff&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;And awayyy we go!&lt;/p&gt;
&lt;h1&gt;&lt;a name="kdc"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;When thousands of clients are rebooted for Windows Update or other scheduled tasks, my domain controllers log many KDC 7 System event errors:&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Courier New;" face="Courier New"&gt;Log Name: System &lt;br /&gt;Source: Microsoft-Windows-Kerberos-Key-Distribution-Center &lt;br /&gt;Event ID: 7 &lt;br /&gt;Level: Error &lt;br /&gt;Description: &lt;br /&gt; &lt;br /&gt;The Security Account Manager failed a KDC request in an unexpected way. The error is in the data field.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Courier New;" face="Courier New"&gt;Error 170000C0&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;I&amp;rsquo;m trying to figure out if this is a performance issue, if the mass reboots are related, if my DCs are over-utilized, or something else.&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;That extended error is:&lt;/p&gt;
&lt;p&gt;&lt;i&gt;C0000017 = &lt;b&gt;STATUS_NO_MEMORY&lt;/b&gt; - {Not Enough Quota} - Not enough virtual memory or paging file quota is available to complete the specified operation.&lt;/i&gt;&lt;/p&gt;
&lt;p&gt;The DCs are being pressured with so many requests that they are running out of Kernel memory. We see this very occasionally with applications that make heavy use of the older &lt;a href="http://msdn.microsoft.com/en-us/library/cc245476(v=prot.10).aspx" target="_blank"&gt;SAMR&lt;/a&gt; protocol for lookups (instead of say, LDAP). In some cases we could change the client application's behavior. In others, the customer just had to add more capacity. The mass reboots alone are not the problem here - it's the software that &lt;i&gt;runs at boot up on each client&lt;/i&gt; that is then creating what amounts to a denial of service attack against the domain controllers.&lt;/p&gt;
&lt;p&gt;Examine one of the client computers mentioned in the event for all non-Windows-provided services, scheduled tasks that run at startup, SCCM/SMS at boot jobs, computer startup scripts, or anything else that runs when the computer is restarted. Then get promiscuous network captures of that computer starting (any time, not en masse) while also running Process Monitor in boot mode, and you'll probably see some very likely candidates. You can also use SPA or AD Data Collector sets (&lt;a href="http://blogs.technet.com/b/askds/archive/2010/06/08/son-of-spa-ad-data-collector-sets-in-win2008-and-beyond.aspx" target="_blank"&gt;http://blogs.technet.com/b/askds/archive/2010/06/08/son-of-spa-ad-data-collector-sets-in-win2008-and-beyond.aspx&lt;/a&gt;) in combination with network captures to see exactly what protocol is being used to overwhelm the DC, if you want to troubleshoot the issue as it happens. Probably at 3AM, that sounds sucky.&lt;/p&gt;
&lt;p&gt;Ultimately, the application causing the issue must be stopped, reconfigured, or removed - the only alternative is to add more DCs as a capacity Band-Aid or stagger your mass reboots.&lt;/p&gt;
&lt;h1&gt;&lt;a name="dfsn1"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;Is it possible to have 2003 and 2008 servers co-exist in the same DFS namespace? I don&amp;rsquo;t see it documented either &amp;ldquo;for&amp;rdquo; or &amp;ldquo;against&amp;rdquo; on the blog anywhere.&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;It's totally ok to mix OSes in the DFSN namespace, as long as you don't use Windows Server 2008 ("&lt;a href="https://technet.microsoft.com/en-us/library/cc770287.aspx" target="_blank"&gt;V2 mode&lt;/a&gt;") namespaces, which won't allow any Win2003 servers. If you are using DFSR to replicate the data, make sure all server have the latest DFSR hotfixes (&lt;a href="https://support.microsoft.com/kb/958802" target="_blank"&gt;here&lt;/a&gt; and &lt;a href="https://support.microsoft.com/kb/968429" target="_blank"&gt;here&lt;/a&gt;), as there &lt;i&gt;are&lt;/i&gt;incompatibilities in DFSR that these hotfixes resolve.&lt;/p&gt;
&lt;h1&gt;&lt;a name="dfsn2"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;Should I create DFS namespace folders (used by the DFS service itself) under NTFS mount points? Is there any advantage to this?&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;DFSN management tools &lt;a href="http://support.microsoft.com/kb/867712" target="_blank"&gt;do not allow you&lt;/a&gt;&amp;nbsp;to create DFSN roots and links under mount points ordinarily, and once you do through alternate hax0r means, they are hard to remove (you have to use FSUTIL). Ergo, do not do it &amp;ndash; the management tools blocking you means that it is not supported.&lt;/p&gt;
&lt;p&gt;There is zero value in placing the DFSN special folders under mount points - the DFSN special folders consume no space, do not contain files, and exist only to provide reparse point tags to the DFSN service and its file IO driver goo. By default, they are configured on the root of the C: drive in a folder called c:\dfsroots. That ensures that they are available when the OS boots. Putting them under a mount point only breaks removing them later and does not serve any convincing purpose.&lt;/p&gt;
&lt;h1&gt;&lt;a name="usmt"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;How do you back up the Themes folder using USMT4 in Windows 7?&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;The built-in USMT migration code copies the settings but not the files, as it knows the files will exist somewhere on the user&amp;rsquo;s source profile and that those are being copied by the migdocs.xml/miguser.xml. It also knows that the Themes system will take care of the rest after migration; the Themes system creates the transcoded image files using the theme settings and copies the image files itself.&lt;/p&gt;
&lt;p&gt;Note here how after scanstate, my USMT store&amp;rsquo;s Themes folder is empty:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/2605.clip_5F00_image001_5F00_62F3BFC4.png"&gt;&lt;img width="777" height="204" title="clip_image001" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border-width: 0px;" alt="clip_image001" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/3683.clip_5F00_image001_5F00_thumb_5F00_2FB7865B.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;After I loadstate that user, the Themes system fixed it all up in that user&amp;rsquo;s real profile when the user logged on:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/0640.clip_5F00_image002_5F00_07A4D73C.png"&gt;&lt;img width="778" height="346" title="clip_image002" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border-width: 0px;" alt="clip_image002" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/0636.clip_5F00_image002_5F00_thumb_5F00_47028ACC.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;However, if you still specifically need to copy the Themes folder intact for some reason, here&amp;rsquo;s a sample custom XML file:&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;&lt;span style="font-size: 9.5pt;"&gt;&amp;lt;?&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 9.5pt;"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #a31515;" color="#a31515"&gt;xml&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #ff0000;" color="#ff0000"&gt;version&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;=&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="font-size: 9.5pt;"&gt;&lt;span style="color: #000000;" color="#000000"&gt;"&lt;/span&gt;&lt;span&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;1.0&lt;/span&gt;&lt;/span&gt;&lt;span style="color: #000000;" color="#000000"&gt;"&lt;/span&gt;&lt;span&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="color: #ff0000;" color="#ff0000"&gt;encoding&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;=&lt;/span&gt;&lt;/span&gt;&lt;span style="color: #000000;" color="#000000"&gt;"&lt;/span&gt;&lt;span&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;UTF-8&lt;/span&gt;&lt;/span&gt;&lt;span style="color: #000000;" color="#000000"&gt;"&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="color: #0000ff; font-size: 9.5pt;" color="#0000ff"&gt;?&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;&lt;span style="font-size: 9.5pt;"&gt;&amp;lt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 9.5pt;"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #a31515;" color="#a31515"&gt;migration&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #ff0000;" color="#ff0000"&gt;urlid&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;=&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="font-size: 9.5pt;"&gt;&lt;span style="color: #000000;" color="#000000"&gt;"&lt;/span&gt;&lt;span&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;http://www.microsoft.com/migration/1.0/migxmlext/migratethemefolder&lt;/span&gt;&lt;/span&gt;&lt;span style="color: #000000;" color="#000000"&gt;"&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="color: #0000ff; font-size: 9.5pt;" color="#0000ff"&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;&lt;span style="font-size: 9.5pt;"&gt;&amp;lt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 9.5pt;"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #a31515;" color="#a31515"&gt;component&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #ff0000;" color="#ff0000"&gt;type&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;=&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="font-size: 9.5pt;"&gt;&lt;span style="color: #000000;" color="#000000"&gt;"&lt;/span&gt;&lt;span&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;Documents&lt;/span&gt;&lt;/span&gt;&lt;span style="color: #000000;" color="#000000"&gt;"&lt;/span&gt;&lt;span&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="color: #ff0000;" color="#ff0000"&gt;context&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;=&lt;/span&gt;&lt;/span&gt;&lt;span style="color: #000000;" color="#000000"&gt;"&lt;/span&gt;&lt;span&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;User&lt;/span&gt;&lt;/span&gt;&lt;span style="color: #000000;" color="#000000"&gt;"&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="color: #0000ff; font-size: 9.5pt;" color="#0000ff"&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;&lt;span style="font-size: 9.5pt;"&gt;&amp;lt;!--&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 9.5pt;"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #008000;" color="#008000"&gt; sample theme folder migrator &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff; font-size: 9.5pt;" color="#0000ff"&gt;--&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;&lt;span style="font-size: 9.5pt;"&gt;&amp;lt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 9.5pt;"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #a31515;" color="#a31515"&gt;displayName&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="font-size: 9.5pt;"&gt;&lt;span style="color: #000000;" color="#000000"&gt;ThemeFolderMigSample&lt;/span&gt;&lt;span&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;&amp;lt;/&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="color: #a31515;" color="#a31515"&gt;displayName&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="color: #0000ff; font-size: 9.5pt;" color="#0000ff"&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 9.5pt;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 9.5pt;"&gt;&amp;lt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 9.5pt;"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #a31515;" color="#a31515"&gt;role&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #ff0000;" color="#ff0000"&gt;role&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;=&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="font-size: 9.5pt;"&gt;&lt;span style="color: #000000;" color="#000000"&gt;"&lt;/span&gt;&lt;span&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;Data&lt;/span&gt;&lt;/span&gt;&lt;span style="color: #000000;" color="#000000"&gt;"&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="color: #0000ff; font-size: 9.5pt;" color="#0000ff"&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 9.5pt;"&gt;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 9.5pt;"&gt;&amp;lt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 9.5pt;"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #a31515;" color="#a31515"&gt;rules&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff; font-size: 9.5pt;" color="#0000ff"&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 9.5pt;"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 9.5pt;"&gt;&amp;lt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 9.5pt;"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #a31515;" color="#a31515"&gt;include&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #ff0000;" color="#ff0000"&gt;filter&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;=&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="font-size: 9.5pt;"&gt;&lt;span style="color: #000000;" color="#000000"&gt;'&lt;/span&gt;&lt;span&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;MigXmlHelper.IgnoreIrrelevantLinks()&lt;/span&gt;&lt;/span&gt;&lt;span style="color: #000000;" color="#000000"&gt;'&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="color: #0000ff; font-size: 9.5pt;" color="#0000ff"&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 9.5pt;"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 9.5pt;"&gt;&amp;lt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 9.5pt;"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #a31515;" color="#a31515"&gt;objectSet&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff; font-size: 9.5pt;" color="#0000ff"&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 9.5pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 9.5pt;"&gt;&amp;lt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 9.5pt;"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #a31515;" color="#a31515"&gt;pattern&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #ff0000;" color="#ff0000"&gt;type&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;=&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="font-size: 9.5pt;"&gt;&lt;span style="color: #000000;" color="#000000"&gt;"&lt;/span&gt;&lt;span&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;File&lt;/span&gt;&lt;/span&gt;&lt;span style="color: #000000;" color="#000000"&gt;"&lt;/span&gt;&lt;span&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="color: #000000;" color="#000000"&gt;%CSIDL_APPDATA%\Microsoft\Windows\Themes\* [*]&lt;/span&gt;&lt;span&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;&amp;lt;/&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="color: #a31515;" color="#a31515"&gt;pattern&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="color: #0000ff; font-size: 9.5pt;" color="#0000ff"&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 9.5pt;"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 9.5pt;"&gt;&amp;lt;/&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 9.5pt;"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #a31515;" color="#a31515"&gt;objectSet&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff; font-size: 9.5pt;" color="#0000ff"&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 9.5pt;"&gt;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 9.5pt;"&gt;&amp;lt;/&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 9.5pt;"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #a31515;" color="#a31515"&gt;include&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff; font-size: 9.5pt;" color="#0000ff"&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 9.5pt;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 9.5pt;"&gt;&amp;lt;/&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 9.5pt;"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #a31515;" color="#a31515"&gt;rules&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff; font-size: 9.5pt;" color="#0000ff"&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; list-style-type: disc; margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Consolas;" face="Consolas"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff;" color="#0000ff"&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 9.5pt;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 9.5pt;"&gt;&amp;lt;/&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 9.5pt;"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #a31515;" color="#a31515"&gt;role&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="color: #0000ff; font-size: 9.5pt;" color="#0000ff"&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman';"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;And here it is in action:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/4331.clip_5F00_image004_5F00_7ED4CEEF.jpg"&gt;&lt;img width="764" height="349" title="clip_image004" style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border-width: 0px;" alt="clip_image004" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/5023.clip_5F00_image004_5F00_thumb_5F00_2BE9BBBE.jpg" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h1&gt;&lt;a name="linkid"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;I've recently been working on extending my AD schema with a new back-linked attribute pair, and I used the instructions on &lt;a href="http://msdn.microsoft.com/en-us/library/bb891955(v=vs.85).aspx" target="_blank"&gt;this blog&lt;/a&gt; to auto-generate the linkIDs for my new attributes. Confusingly, the resulting linkIDs are negative values (-912314983 and -912314984). The attributes and backlinks seem to work as expected, but when looking at the &lt;a href="http://msdn.microsoft.com/en-us/library/ms677270%28VS.85%29.aspx" target="_blank"&gt;MSDN definition of the linkID attribute&lt;/a&gt;, it specifically states that the linkID should be a positive value. Do you know why I'm getting a negative value, and if I should be concerned?&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;The only hard and fast rule is that the forward link (flink) be an even number and the backward link (blink) be the flink's ID plus one. In your case, the flink is -912314984 then the blink had better be -912314983, which I assume is the case since things are working. But, we were curious when you posted the linkID documentation from MSDN so we dug a little deeper.&lt;/p&gt;
&lt;p&gt;The fact that your linkIDs are negative numbers is correct and expected, and is the result of a feature called AutoLinkID. Automatically generated linkIDs are in the range of 0xC0000000-0xFFFFFFFC (-1,073,741,824 to -4). This means that it is a good idea to use positive numbers if you are going to set the linkID manually. That way you are guaranteed not to conflict with automatically generated linkIDs.&lt;/p&gt;
&lt;p&gt;The bottom line is, you're all good.&lt;/p&gt;
&lt;h1&gt;&lt;a name="delegate"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;I am trying to delegate permissions to the DBA team to create, modify, and delete SPNs since they're the team that swaps out the local accounts SQL is installed under to the domain service accounts we create to run SQL.&lt;/p&gt;
&lt;p&gt;Documentation on the Internet has led me down the rabbit hole to no end.&amp;nbsp; Can you tell me how this is done in a W2K8 R2 domain and a W2K3 domain?&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;So you will want to delegate a specific group of users -- your DBA team -- permissions to modify the SPN attribute of a specific set of objects -- computer accounts for servers running SQL server and user accounts used as service accounts under which SQL Server can run.&lt;/p&gt;
&lt;p&gt;The easiest way to accomplish this is to put all such accounts in one OU, ie OU=SQL Server Accounts, and run the following commands:&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Courier New;" face="Courier New"&gt;Dsacls "OU=SQL Server Accounts,DC=corp,DC=contoso,DC=com" /I:S /G "CORP\DBA Team":WPRP;servicePrincipalName;user &lt;br /&gt;Dsacls "OU=SQL Server Accounts,DC=corp,DC=contoso,DC=com" /I:S /G "CORP\DBA Team":WPRP;servicePrincipalName;computer&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;These two commands will grant the DBA Team group permission to read and write the servicePrincipalName attribute on user and computer objects in the SQL Server Accounts OU.&lt;/p&gt;
&lt;p&gt;Your admins should then be able to use setspn.exe to modify that property on the designated accounts.&lt;/p&gt;
&lt;p&gt;But&amp;hellip;what if you have a large number of accounts spread across multiple OUs? The above solution only works well if all of your accounts are concentrated in a few (preferably one) OUs. In this case, you basically have two options:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;You can run the two commands specifying the root of the domain as the object, but you would be delegating permissions for EVERY user and computer in the domain. Do you want your DBA team to be able to modify accounts for which they have no legitimate purpose?&lt;/li&gt;
&lt;li&gt;Compile a list of specific accounts the DBA team can manage and modify each of them individually. That can be done with a single command line. Create a text file that contains the DNs of each account for which you want to delegate permissions and then use the following command: &lt;br /&gt; &lt;br /&gt;&lt;span style="font-family: Courier New;" face="Courier New"&gt;for /f "tokens=*" %i in (object-list.txt) do dsacls "%i" /G "CORP\DBA Team":WPRP;servicePrincipalName&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;None of these are really great options, however, because you&amp;rsquo;re essentially giving a group of non-AD Administrators the ability to screw up authentication to what are perhaps critical business resources. You might actually be better off creating an expedited process whereby these DBAs can submit a request to a real Administrator who already has permissions to make the required changes, as well as the experience to verify such a change won&amp;rsquo;t cause any problems.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;Author&amp;rsquo;s Note: &lt;/strong&gt;This gentleman pointed out in a reply that these DBAs wouldn&amp;rsquo;t want him messing with tables, rows and the SA account, so he doesn&amp;rsquo;t want them touching AD. I thought that was sort of amusing.&lt;/em&gt;&lt;/p&gt;
&lt;h1&gt;&lt;a name="enabled"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;What is Powershell checking when your run &lt;strong&gt;get-adcomputer -properties * -filter * | format-table Name,Enabled&lt;/strong&gt;?&amp;nbsp; Is &lt;strong&gt;Enabled&lt;/strong&gt; an attribute, a flag, a bit, a setting?&amp;nbsp; What, if at all, would that setting show up as in something like ADSIEdit.msc?&lt;/p&gt;
&lt;p&gt;I get that stuff like &lt;strong&gt;samAccountName&lt;/strong&gt;, &lt;strong&gt;sn&lt;/strong&gt;, &lt;strong&gt;telephonenumber&lt;/strong&gt;, etc.&amp;nbsp; are attributes but what the heck is &lt;strong&gt;enabled&lt;/strong&gt;?&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;All objects in PowerShell are PSObjects, which essentially wrap the underlying .NET or COM objects and expose some or all of the methods and properties of the wrapped object. In this case, &lt;strong&gt;Enabled&lt;/strong&gt; is an attribute ultimately inherited from the &lt;a href="http://msdn.microsoft.com/en-us/library/system.directoryservices.accountmanagement.authenticableprincipal.aspx" target="_blank"&gt;System.DirectoryServices.AccountManagement.AuthenticablePrincipal&lt;/a&gt;&amp;nbsp;.NET class. This answer isn&amp;rsquo;t very helpful, however, as it just moves your search for answers from PowerShell to the .NET Framework, right? Ultimately, you want to know how a computer&amp;rsquo;s or user&amp;rsquo;s account state (enabled or disabled) is stored in Active Directory.&lt;/p&gt;
&lt;p&gt;Whether or not an account is disabled is reflected in the appropriate bit being set on the object&amp;rsquo;s userAccountControl attribute. Check out the following KB: &lt;a href="http://support.microsoft.com/kb/305144" target="_blank"&gt;How to use the UserAccountControl flags to manipulate user account properties&lt;/a&gt;. You&amp;rsquo;ll find that the penultimate least significant bit of the userAccountControl bitmask is called ACCOUNTDISABLE, and reflects the appropriate state; 1 is disabled and 0 is enabled.&lt;/p&gt;
&lt;p&gt;If you find that you need to use an actual LDAP query to search for disabled accounts, then you can use a &lt;a href="http://support.microsoft.com/kb/269181" target="_blank"&gt;bitwise filter&lt;/a&gt;. The appropriate LDAP filter would be:&lt;/p&gt;
&lt;pre&gt;(UserAccountControl:1.2.840.113556.1.4.803:=2)&lt;/pre&gt;
&lt;h1&gt;&lt;a name="other"&gt;&lt;/a&gt;Other stuff&lt;/h1&gt;
&lt;p&gt;I watched this and, despite the lack of lots of moving arms and tools, had sort of a &lt;a href="http://www.williamgibsonbooks.com/books/zero.asp" target="_blank"&gt;Count Zero&lt;/a&gt; moment:&lt;/p&gt;
&lt;p&gt;&lt;object width="640" height="360"&gt;&lt;param name="movie" value="http://www.youtube.com/v/RnIvhlKT7SY&amp;amp;rel=0&amp;amp;hl=en_US&amp;amp;feature=player_embedded&amp;amp;version=3" /&gt;&lt;param name="allowFullScreen" value="true" /&gt;&lt;param name="allowScriptAccess" value="always" /&gt;&lt;embed width="640" height="360" src="http://www.youtube.com/v/RnIvhlKT7SY&amp;amp;rel=0&amp;amp;hl=en_US&amp;amp;feature=player_embedded&amp;amp;version=3" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" /&gt;&lt;/object&gt;&lt;/p&gt;
&lt;p&gt;And just for Ned (because he REALLY loves this stuff!): &lt;a href="http://www.bing.com/images/search?q=cute+kittens&amp;amp;qs=n&amp;amp;form=QBIR&amp;amp;pq=cute%2520kittens&amp;amp;sc=8-12&amp;amp;sp=-1&amp;amp;sk=" target="_blank"&gt;Kittens!&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;No need to rush back, dude.&lt;/p&gt;
&lt;p&gt;Jonathan &amp;ldquo;Payback is a %#*@&amp;amp;!&amp;rdquo; Stephens&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3477646" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/askds/archive/tags/DFSN/">DFSN</category><category domain="http://blogs.technet.com/b/askds/archive/tags/LDAP/">LDAP</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Schema/">Schema</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Security/">Security</category><category domain="http://blogs.technet.com/b/askds/archive/tags/PowerShell/">PowerShell</category><category domain="http://blogs.technet.com/b/askds/archive/tags/USMT/">USMT</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Mail+Sack/">Mail Sack</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Jonathan+Stephens/">Jonathan Stephens</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Ned+Pyle/">Ned Pyle</category></item><item><title>If you use Symantec Products, Read Me</title><link>http://blogs.technet.com/b/askds/archive/2012/01/26/if-you-use-symantec-products-read-me.aspx</link><pubDate>Thu, 26 Jan 2012 19:42:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3477444</guid><dc:creator>NedPyle [MSFT]</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/rsscomments.aspx?WeblogPostID=3477444</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/commentapi.aspx?WeblogPostID=3477444</wfw:comment><comments>http://blogs.technet.com/b/askds/archive/2012/01/26/if-you-use-symantec-products-read-me.aspx#comments</comments><description>&lt;p&gt;&lt;a href="http://blogs.technet.com/b/askds/archive/tags/Ned+Pyle/"&gt;Ned&lt;/a&gt; here again, with a public service announcement similar to the previous one &lt;a href="http://blogs.technet.com/b/askds/archive/2011/06/07/rsa-securid-do-over.aspx"&gt;we did for RSA&lt;/a&gt; as it implicitly affects so many Microsoft customers. Symantec has announced:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Symantec can confirm that a segment of its source code has been accessed. Upon investigation of the claims made by Anonymous regarding source code disclosure, Symantec believes that the disclosure was the result of a theft of source code that occurred in 2006.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Read the rest here: &lt;a title="http://www.symantec.com/theme.jsp?themeid=anonymous-code-claims&amp;amp;inid=us_ghp_banner1_anonymous" href="http://www.symantec.com/theme.jsp?themeid=anonymous-code-claims&amp;amp;inid=us_ghp_banner1_anonymous"&gt;http://www.symantec.com/theme.jsp?themeid=anonymous-code-claims&amp;amp;inid=us_ghp_banner1_anonymous&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Older versions of their security products appear to be safe as long as you were maintaining patching (as always with early announcements, return to make sure this story doesn&amp;rsquo;t change). However, but &lt;a href="http://www.symantec.com/connect/blogs/important-information-pcanywhere"&gt;if you use PCAnywhere you must update (for free) to a patched version of 12.5 immediately.&lt;/a&gt; It goes without saying if you were using PCAnywhere prior to this announcement, you should commence auditing your remote access. Symantec isn&amp;rsquo;t clowning around here, their actual guidance is that &lt;a href="http://www.symantec.com/connect/sites/default/files/pcAnywhere%20Security%20Recommendations%20WP_01_23_Final.pdf"&gt;you should not allow PCAnywhere external access to your corporate network &lt;strong&gt;&lt;em&gt;at all&lt;/em&gt;&lt;/strong&gt;&lt;/a&gt;&lt;em&gt;&lt;strong&gt;:&lt;/strong&gt; &lt;/em&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Customers should block pcAnywhere assigned ports (5631, 5632) on Internet facing network connections, or shut off port forwarding of these ports. Blocking these ports will help ensure that an outside entity will not have access to pcAnywhere through these ports, and will help ensure that the use of pcAnywhere remains within the confines of the corporate network.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Which kind of defeats the purpose as I understand it, but whatever.&lt;/p&gt;
&lt;p&gt;- Ned &amp;ldquo;get to it&amp;rdquo; Pyle&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3477444" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/askds/archive/tags/Security/">Security</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Other+Blogs/">Other Blogs</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Ned+Pyle/">Ned Pyle</category></item><item><title>Security Compliance Manager 2.5 Beta is out</title><link>http://blogs.technet.com/b/askds/archive/2012/01/25/security-compliance-manager-2-5-beta-is-out.aspx</link><pubDate>Wed, 25 Jan 2012 22:44:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3477270</guid><dc:creator>NedPyle [MSFT]</dc:creator><slash:comments>4</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/rsscomments.aspx?WeblogPostID=3477270</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/commentapi.aspx?WeblogPostID=3477270</wfw:comment><comments>http://blogs.technet.com/b/askds/archive/2012/01/25/security-compliance-manager-2-5-beta-is-out.aspx#comments</comments><description>&lt;p&gt;Hi folks, &lt;a href="http://blogs.technet.com/b/askds/archive/tags/ned+pyle/"&gt;Ned&lt;/a&gt; here with a quickie advert: The &lt;a href="https://connect.microsoft.com/site715/program2682"&gt;Security Compliance Manager 2.5 beta&lt;/a&gt; released the other day, with a bunch of new features and other goo.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Integration with the System Center 2012 IT GRC Process Pack for Service Manager-Beta&lt;/strong&gt;&lt;strong&gt;:&lt;/strong&gt;Product baseline configurations are integrated into the IT GRC Process Pack to provide oversight and reporting of your compliance activities.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Gold master support&lt;/strong&gt;&lt;strong&gt;:&lt;/strong&gt; Import and take advantage of your existing Group Policy or create a snapshot of a reference machine to kick-start your project.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Configure stand-alone machines&lt;/strong&gt;&lt;strong&gt;:&lt;/strong&gt; Deploy your configurations to non-domain joined computers using the new GPO Pack feature.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Updated security guidance&lt;/strong&gt;&lt;strong&gt;:&lt;/strong&gt; Take advantage of the deep security expertise and best practices in the updated security guides, and the attack surface reference workbooks to help reduce the security risks that you consider to be the most important.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Compare against industry best practices&lt;/strong&gt;&lt;strong&gt;:&lt;/strong&gt; Analyze your configurations against prebuilt baselines for the latest Windows client and server operating systems.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;NEW baselines include:&lt;/strong&gt;&lt;/li&gt;
&lt;ul&gt;
&lt;li&gt;Exchange Server 2007 SP3 Security Baseline&lt;/li&gt;
&lt;li&gt;Exchange Server 2010 SP2 Security Baseline&lt;/li&gt;
&lt;/ul&gt;
&lt;li&gt;&lt;strong&gt;Updated client product baselines include:&lt;/strong&gt;&lt;/li&gt;
&lt;ul&gt;
&lt;li&gt;Windows 7 SP1 Security Compliance Baseline&lt;/li&gt;
&lt;li&gt;Windows Vista SP2 Security Compliance Baseline&lt;/li&gt;
&lt;li&gt;Windows XP SP3 Security Compliance Baseline&lt;/li&gt;
&lt;li&gt;Office 2010 SP1 Security Baseline&lt;/li&gt;
&lt;li&gt;Internet Explorer 8 Security Compliance Baseline&lt;/li&gt;
&lt;/ul&gt;
&lt;/ul&gt;
&lt;p&gt;Hot damn, #2 and #3 are what everyone kept asking for, and they&amp;rsquo;ve finally been delivered.&lt;/p&gt;
&lt;p&gt;Never heard of SCM? &lt;a href="http://blogs.technet.com/b/askds/archive/tags/security+compliance+manager/"&gt;For shame, I&amp;rsquo;ve discussed it here a few times&lt;/a&gt;. You just don&amp;rsquo;t care what I have to say, DO YOU? I AM GOING TO SPEND FOUR HOURS ON THE PHONE TALKING ABOUT YOU WITH MY GIRLFRIENDS!!!&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Update 4/4/2012: SCM 2.5&amp;nbsp;no longer beta and is &lt;a href="http://www.microsoft.com/download/en/details.aspx?id=16776"&gt;released to world&lt;/a&gt;. Thanks for the heads up Mike!&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;- Ned &amp;ldquo;SCMbag&amp;rdquo; Pyle&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3477270" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/askds/archive/tags/Other+Blogs/">Other Blogs</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Security+Compliance+Manager/">Security Compliance Manager</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Ned+Pyle/">Ned Pyle</category></item><item><title>RPC over IT/Pro</title><link>http://blogs.technet.com/b/askds/archive/2012/01/24/rpc-over-it-pro.aspx</link><pubDate>Tue, 24 Jan 2012 17:37:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3477009</guid><dc:creator>NedPyle [MSFT]</dc:creator><slash:comments>23</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/rsscomments.aspx?WeblogPostID=3477009</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/commentapi.aspx?WeblogPostID=3477009</wfw:comment><comments>http://blogs.technet.com/b/askds/archive/2012/01/24/rpc-over-it-pro.aspx#comments</comments><description>&lt;p&gt;Hi folks, &lt;a href="http://blogs.technet.com/b/askds/archive/tags/ned+pyle/"&gt;Ned&lt;/a&gt; here again to talk about one of the most &lt;a href="http://support.microsoft.com/kb/832017"&gt;commonly used&lt;/a&gt; &amp;ndash; and least understood &amp;ndash; network protocols in Windows: &lt;b&gt;Remote Procedure Call&lt;/b&gt;. Understanding RPC is a &lt;a href="http://blogs.technet.com/b/askds/archive/2011/09/02/accelerating-your-it-career.aspx"&gt;foundation&lt;/a&gt; for any successful IT Professional. It&amp;rsquo;s integral to distributed systems like Active Directory, Exchange, SQL, and System Center. The administrator who has never run into RPC configuration issues is either very new or very lucky.&lt;/p&gt;
&lt;p&gt;Today I attempt to explain the protocol in practical terms. As always, the best way to troubleshoot is with an understanding of how things are &lt;i&gt;supposed&lt;/i&gt; to work, so that when it fails the reasons are obvious.&amp;nbsp; If you have a metered or capped Internet connection, read this off hours &amp;ndash; it&amp;rsquo;s a biggee.&lt;/p&gt;
&lt;h3&gt;Some context&lt;/h3&gt;
&lt;p&gt;The RPC concept has roots in ARPANET, but got its first business computing use &amp;ndash; like so many others &amp;ndash; at &lt;a href="http://dl.acm.org/citation.cfm?doid=2080.357392"&gt;Xerox PARC&lt;/a&gt; as &amp;ldquo;Courier&amp;rdquo;. The Microsoft implementation is an extension of &lt;a href="https://www2.opengroup.org/ogsys/jsp/publications/PublicationDetails.jsp?catalogno=c706"&gt;The Open Group&amp;rsquo;s&lt;/a&gt; DCE/RPC, sometimes called MSRPC. We further extended that into the Distributed Component Object Model (DCOM), which is RPC and COM. The Exchange folks heavily invested in RPC over HTTP. Microsoft also retains the legacy "RPC over SMB" system, often referred to as Named Pipes. That ends the brochure.&lt;/p&gt;
&lt;p&gt;As I began to learn RPC, the first problem I ran into was the documentation. It seemed to come in two forms:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Explanations &lt;a href="http://msdn.microsoft.com/en-us/library/aa378623(v=VS.85).aspx"&gt;by developers for developers&lt;/a&gt;, which contain very little architecture and troubleshooting info&lt;/li&gt;
&lt;li&gt;Explanations &lt;a href="http://msdn.microsoft.com/en-us/library/cc243560(v=PROT.10).aspx"&gt;by alien hybrids for robot lawyers&lt;/a&gt;, which contain no understandable information at all&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/0118.image_5F00_75E30561.png"&gt;&lt;img width="262" height="262" title="image" style="display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/2262.image_5F00_thumb_5F00_54835FC5.png" border="0" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;span style="font-size: xx-small;" size="1"&gt;Let&amp;rsquo;s do lunch &amp;ndash; you like human?&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;If you actually read the docs, you're let down in the details. It comes in two arrangements, both of which completely miss the IT boat:&lt;/p&gt;
&lt;p&gt;1. The &amp;ldquo;it&amp;rsquo;s all processes and libraries, get to coding&amp;rdquo; form:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/4747.image_5F00_68304959.png"&gt;&lt;img width="409" height="287" title="image" style="border: 0px currentcolor; display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/5808.image_5F00_thumb_5F00_72816DB9.png" border="0" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;span style="font-size: xx-small;" size="1"&gt;See, it's just code!&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;2. The &amp;ldquo;Jedi network magic&amp;rdquo; form:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/1108.image_5F00_3FB16745.png"&gt;&lt;img width="414" height="324" title="image" style="border: 0px currentcolor; display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/4426.image_5F00_thumb_5F00_77EFDE5D.png" border="0" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;span style="font-size: xx-small;" size="1"&gt;These aren't the computers you're looking for&amp;hellip; move along&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;I find developers are often like &lt;a href="http://www.imdb.com/title/tt0095953/"&gt;Rain Man&lt;/a&gt;: specialist geniuses, bewildered by real life. This isn&amp;rsquo;t bad documentation, but IT pros aren&amp;rsquo;t the audience. The developers of RPC are providing a framework and since they live in a perfect world of design where nothing breaks, &lt;i&gt;how&lt;/i&gt; it works is not important &amp;ndash; they just want you to use the right APIs. The problem is I don&amp;rsquo;t care about the specifics of &lt;a href="http://msdn.microsoft.com/en-us/library/aa367091(v=VS.85).aspx"&gt;MIDL, stubs, or marshaling&lt;/a&gt; unless I&amp;rsquo;m at the point of debugging; I just want to know how it all works in practical networking terms. Then when it breaks, I have somewhere to start, and when I&amp;rsquo;m designing a distributed system, I&amp;rsquo;m not setting my customer up for headaches.&lt;/p&gt;
&lt;p&gt;Today I focus on MSRPC, as that&amp;rsquo;s the main RPC protocol of AD components. I may return someday to discuss the others, if you&amp;rsquo;re interested. And bribe me.&lt;/p&gt;
&lt;h3&gt;The MSRPC details&lt;/h3&gt;
&lt;p&gt;Let's start with an analogy: you meet a nice girl and really hit it off. Like an idiot, you manage to lose her phone number. You know that she works for Microsoft though, so you start by looking up the Charlotte office. You call and get a switchboard, so you ask for her by name. The operator tells you her number and then offers to transfer you &amp;ndash; naturally, you say yes. Someone answers and you make sure it&amp;rsquo;s the nice girl by introducing yourself. You both exchange pleasantries, then make plans for dinner and a movie, with directions to the restaurant and a chat about the Flixster reviews. You hang up and think about what you&amp;rsquo;re going to say to keep her interested until the appetizers arrive. You called her on your mobile phone so you have the outgoing number saved in case you need to call back.&lt;/p&gt;
&lt;p&gt;There, now you understand MSRPC. No really, you do&amp;hellip;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;A client application knows about a server application and wants to communicate with it.&lt;/li&gt;
&lt;li&gt;The client computer uses name resolution to locate the computer where that server application runs.&lt;/li&gt;
&lt;li&gt;The client app connects to an endpoint locator and requests access to the server application.&lt;/li&gt;
&lt;li&gt;The endpoint locator provides that info and the client connects to the server with an initial conversation.&lt;/li&gt;
&lt;li&gt;The client and server apps exchange instructions and data.&lt;/li&gt;
&lt;li&gt;The client and server apps disconnect.&lt;/li&gt;
&lt;li&gt;The client computer has a cache of name resolution and the connection that can save time reconnecting later.&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;RPC allows a client application to let other computers work on its behalf, offloading processing to more powerful centralized servers. Instead of sending real functions over the network, the client tells the server what functions to run, and then the server sends the data back. This has nothing to do with the OS: some of these applications can be both client &lt;i&gt;and&lt;/i&gt; server &amp;ndash; for instance, Active Directory multi-master replication. That RPC application is &lt;b&gt;LSASS.EXE. &lt;/b&gt;I&amp;rsquo;m going to use it as our sample app.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/3404.image_5F00_11703223.png"&gt;&lt;img width="568" height="396" title="image" style="border: 0px currentcolor; display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/8787.image_5F00_thumb_5F00_5780EF36.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;There are a few important terms to understand:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Endpoint mapper&lt;/b&gt; &amp;ndash; a service listening on the server, which guides client apps to server apps by port and UUID&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Tower&lt;/b&gt; &amp;ndash; describes the RPC protocol, to allow the client and server to negotiate a connection&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Floor&lt;/b&gt; &amp;ndash; the contents of a tower with specific data like ports, IP addresses, and identifiers&lt;/li&gt;
&lt;li&gt;&lt;b&gt;UUID&lt;/b&gt; &amp;ndash; a well-known GUID that identifies the RPC application. The UUID is what you use to see a specific kind of RPC application conversation, as there are likely to be many&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Opnum&lt;/b&gt; &amp;ndash; the identifier of a function that the client wants the server to execute. It&amp;rsquo;s just a hexadecimal number, but a good network analyzer will translate the function for you. &lt;a href="http://msdn.microsoft.com/en-us/"&gt;MSDN&lt;/a&gt; can too. If neither knows, your application vendor must tell you&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Port&lt;/b&gt; &amp;ndash; the communication endpoints for the client and server applications&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Stub data&lt;/b&gt; &amp;ndash; the information given to functions and data exchanged between the client and server. This is the payload; the important part&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;There&amp;rsquo;s a lot more but we&amp;rsquo;re getting into developer country. I know it sounds like jabber, so let&amp;rsquo;s dissect this with a real-world example using our old friend &lt;a href="http://www.microsoft.com/download/en/details.aspx?displaylang=en&amp;amp;id=4865"&gt;NetMon&lt;/a&gt; and the latest &lt;a href="http://nmparsers.codeplex.com/"&gt;open source parsers&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Back to reality&lt;/h3&gt;
&lt;p&gt;Here I have two DCs in the same AD site, named WIN2008R2-01 and WIN2008R2-02, with respective IP addresses of 10.0.0.101 and 10.0.0.102. I reboot DC2 and have a network capture running on DC1. I create a brand new test user and let it replicate, then I stop the capture. It&amp;rsquo;s critical to have a network capture see the whole conversation or it will be a mess to analyze; if possible, the captures should always be running on both client and server, but in this case, that&amp;rsquo;s not possible due to the reboot.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/6866.image_5F00_638A18D2.png"&gt;&lt;img width="624" height="492" title="image" style="border: 0px currentcolor; display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/4745.image_5F00_thumb_5F00_1AF02A01.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;When you first examine AD replication traffic in NetMon (like above) it looks like Greek. What the heck is a stub parser? DRSR?&lt;/p&gt;
&lt;p&gt;Open the &lt;b&gt;Options&lt;/b&gt; menu and select &lt;b&gt;Parser Profiles&lt;/b&gt;. The reason you see the &amp;ldquo;Windows stub parser&amp;rdquo; messages is that by default, NetMon uses a balanced set of parsers designed for limited analysis without packet loss.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/3348.image_5F00_52563B2F.png"&gt;&lt;img width="444" height="363" title="image" style="border: 0px currentcolor; display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/1106.image_5F00_thumb_5F00_1F8634BB.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;When analyzing captures on your desktop, set the active parser to &amp;ldquo;Windows&amp;rdquo; and you get the most detail.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/7633.image_5F00_57C4ABD3.png"&gt;&lt;img width="440" height="371" title="image" style="border: 0px currentcolor; display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/0118.image_5F00_thumb_5F00_6215D033.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;While you&amp;rsquo;re in the &lt;b&gt;Options&lt;/b&gt;, I also recommend configuring color filters. Since I am examining AD replication, I want visual cues for &lt;b&gt;DRSR&lt;/b&gt; (Directory Replication Service Remote protocol), &lt;b&gt;EPM &lt;/b&gt;(RPC Endpoint Mapper), &lt;b&gt;MSRPC&lt;/b&gt;, and &lt;b&gt;DNS&lt;/b&gt;. This makes skimming a capture easier.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/5305.image_5F00_2F45C9BF.png"&gt;&lt;img width="441" height="394" title="image" style="border: 0px currentcolor; display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/6076.image_5F00_thumb_5F00_6EA37D4F.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Now I add a simple filter of: &lt;b&gt;msrpc&lt;/b&gt;. Better. Let&amp;rsquo;s start deciphering:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/8130.image_5F00_0013DE28.png"&gt;&lt;img width="632" height="455" title="image" style="border: 0px currentcolor; display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/1273.image_5F00_thumb_5F00_2CBC9801.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Right away, we see the endpoint mapper request above. The tower for Directory Replication is in that request, using the UUID &lt;b&gt;E3514235-4B06-11D1-AB04-00C04FC2DCD2&lt;/b&gt; (that's how Netmon knows to parse it, by the way). It is connecting to TCP port &lt;b&gt;135&lt;/b&gt;. This happens shortly after LSASS.EXE starts, as domain controllers are nearly always talking about replication.&lt;/p&gt;
&lt;p&gt;Naturally, there is a response, and it contains several key ingredients:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/0447.image_5F00_7ADB1937.png"&gt;&lt;img width="668" height="349" title="image" style="border: 0px currentcolor; display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/5633.image_5F00_thumb_5F00_004989DC.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;You can see the towers - there may be more than one - and the floors in each tower with their ports. Importantly, you also see the status of the attempted connection. And a specific server port is listed. That port may be dynamic or static, it depends on the application&amp;rsquo;s configuration.&lt;/p&gt;
&lt;p&gt;Now the client application opens a local client port (again, maybe dynamic, maybe static) and binds to that new application port, using security; the original connection, by default, did not require special permissions - EPM is a switchboard, remember. Because this is MSRPC and domain controllers, this means Kerberos and packet privacy are required. This bind phase below is negotiation.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/7360.image_5F00_05B7FA80.png"&gt;&lt;img width="669" height="469" title="image" style="border: 0px currentcolor; display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/8030.image_5F00_thumb_5F00_443D4826.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/0820.image_5F00_428C7C52.png"&gt;&lt;img width="670" height="54" title="image" style="border: 0px currentcolor; display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/5238.image_5F00_thumb_5F00_53FCDD2A.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;The server responds with the (hopefully) successful negotiation, providing details about which security protocols were selected for further encryption of the traffic. The &lt;b&gt;NegState&lt;/b&gt; field shows how this is not yet complete, but things are proceeding as planned.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/0511.image_5F00_135A90BB.png"&gt;&lt;img width="666" height="487" title="image" style="border: 0px currentcolor; display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/0511.image_5F00_thumb_5F00_71FAEB1E.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;This bind was the negotiation. What follows is the completion of the authentication and encapsulation phase, called an &lt;b&gt;ALTER_CONTEXT&lt;/b&gt; operation. If all goes well, the authentication is accepted and RPC application communications proceeds with some nice secure packet payloads.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/2654.image_5F00_509B4582.png"&gt;&lt;img width="665" height="342" title="image" style="border: 0px currentcolor; display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/6303.image_5F00_thumb_5F00_365ADC5E.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Everything after this point is application&amp;hellip; stuff. RPC connected from a client port to a server port and then communicates along that "channel" for the rest of the conversation. The two halves of the application send each other requests and responses, with stub data used by the application's functions.&lt;/p&gt;
&lt;p&gt;Every application is different, but once you know each one's rules, it will work in a (relatively) predictable fashion. Since this is the well-documented Directory Replication Services application, what happens next is the DC creates a context handle, called a DRSBIND. It then does some work. Let's take a look at one example of the work by switching the NetMon filter to just &lt;b&gt;DRSR&lt;/b&gt;, then apply it to our scenario.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/4237.image_5F00_403FCDC9.png"&gt;&lt;img width="665" height="205" title="image" style="border: 0px currentcolor; display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/3666.image_5F00_thumb_5F00_6CE887A2.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Netmon is politely translating all of these RPC functions above into semi-intelligible words, like &lt;b&gt;DRSBind&lt;/b&gt;, &lt;b&gt;DRSReplicaSync&lt;/b&gt;, and &lt;b&gt;DRSGetNCChanges&lt;/b&gt;. It knows that when there is an opnum it understands for a given protocol, it means an RPC function that the client is telling the server to run remotely on the client's behalf.&lt;/p&gt;
&lt;p&gt;If you examine one of those packets, you see that the data itself is encrypted (good!), but with knowledge of the opnum's purpose and that RPC reached this stage, you have a decent idea what it is doing or how to look it up based on the UUID and Opnum information, even if your network parsers are terrible. In this case:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://msdn.microsoft.com/en-us/library/cc228532(v=PROT.13).aspx"&gt;http://msdn.microsoft.com/en-us/library/cc228532(v=PROT.13).aspx&lt;/a&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;table style="width: 400px;" border="1" cellspacing="0" cellpadding="2"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td width="10" valign="top"&gt;&lt;strong&gt;Function&lt;/strong&gt;&lt;/td&gt;
&lt;td width="237" valign="top"&gt;&lt;strong&gt;Explanation&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td width="10" valign="top"&gt;&lt;a href="http://msdn.microsoft.com/en-us/library/cc228292(v=PROT.13).aspx"&gt;IDL_DRSBind&lt;/a&gt;&lt;/td&gt;
&lt;td width="237" valign="top"&gt;
&lt;p&gt;Creates a context handle necessary to call any other method in this interface. &lt;br /&gt;Opnum: 0&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td width="10" valign="top"&gt;&lt;a href="http://msdn.microsoft.com/en-us/library/cc228237(v=PROT.13).aspx"&gt;IDL_DRSReplicaSync&lt;/a&gt;&lt;/td&gt;
&lt;td width="237" valign="top"&gt;
&lt;p&gt;Triggers &lt;a href="http://msdn.microsoft.com/en-us/library/e5c2026b-f732-4c9d-9d60-b945c0ab54eb(v=PROT.13)#replication"&gt;replication&lt;/a&gt; from another &lt;a href="http://msdn.microsoft.com/en-us/library/8df64cd9-a480-472a-8087-6a5e78f18e49(v=PROT.13)#domain_controller"&gt;DC&lt;/a&gt;. &lt;br /&gt;Opnum: 2&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td width="10" valign="top"&gt;&lt;a href="http://msdn.microsoft.com/en-us/library/dd207691(v=PROT.13).aspx"&gt;IDL_DRSGetNCChanges&lt;/a&gt;&lt;/td&gt;
&lt;td width="237" valign="top"&gt;
&lt;p&gt;Replicates &lt;a href="http://msdn.microsoft.com/en-us/library/e5c2026b-f732-4c9d-9d60-b945c0ab54eb(v=PROT.13)#update"&gt;updates&lt;/a&gt; from an &lt;a href="http://msdn.microsoft.com/en-us/library/e5c2026b-f732-4c9d-9d60-b945c0ab54eb(v=PROT.13)#ncreplica"&gt;NC replica&lt;/a&gt; on the server. &lt;br /&gt;Opnum: 3&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td width="10" valign="top"&gt;&lt;a href="http://msdn.microsoft.com/en-us/library/cc228301(v=PROT.13).aspx"&gt;IDL_DRSCrackNames&lt;/a&gt;&lt;/td&gt;
&lt;td width="237" valign="top"&gt;
&lt;p&gt;Looks up each of a set of objects in the &lt;a href="http://msdn.microsoft.com/en-us/library/8df64cd9-a480-472a-8087-6a5e78f18e49(v=PROT.13)#directory"&gt;directory&lt;/a&gt; and returns it to the caller in the requested format. &lt;br /&gt;Opnum: 12&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td width="10" valign="top"&gt;&lt;a href="http://msdn.microsoft.com/en-us/library/cc228249(v=PROT.13).aspx"&gt;IDL_DRSUnbind&lt;/a&gt;&lt;/td&gt;
&lt;td width="237" valign="top"&gt;
&lt;p&gt;Destroys a context handle previously created by the IDL_DRSBind method. &lt;br /&gt;Opnum: 1&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/3343.image_5F00_681581D2.png"&gt;&lt;img width="662" height="242" title="image" style="border: 0px currentcolor; display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/6082.image_5F00_thumb_5F00_38E3963B.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Importantly, you know that RPC and the network appear to be functioning correctly, so any application problems are likely inside the application itself. If the application has internal logging, you can use these network captures to correlate each opnum request/response to real work, and perhaps see where things are failing internally. If the application doesn&amp;rsquo;t have good security, you can see exactly what it's doing - but so can anyone else. Probably something to bring to the third party vendor's attention, as it will &lt;a href="http://www.microsoft.com/about/twc/en/us/default.aspx"&gt;not be Microsoft&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;A polite application will tear down the connection with noticeable "unbind" traffic, and perhaps even send a network reset, but many simply abandon the conversation and let Windows deal with it later.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/2251.image_5F00_2B9436BD.png"&gt;&lt;img width="624" height="67" title="image" style="border: 0px currentcolor; display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/6545.image_5F00_thumb_5F00_3FAD5346.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;A final note: a domain controller has a great many RPC conversations going with multiple partners; always ensure you are looking at the same conversations by filtering based on IP addresses and ports, as well as your network analysis tools conversation ID system. NetMon makes this pretty easy:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/6052.image_5F00_3ED4ED5C.png"&gt;&lt;img width="624" height="208" title="image" style="border: 0px currentcolor; display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/4810.image_5F00_thumb_5F00_2BB3C0B0.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;And we're done. See? It&amp;rsquo;s just a phone call with a nice girl from Microsoft. Don&amp;rsquo;t be intimidated when she knows more about computers than you do, bub.&lt;/p&gt;
&lt;p&gt;Until next time.&lt;/p&gt;
&lt;p&gt;Ned "really pedantic chatter" Pyle&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3477009" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/askds/archive/tags/network/">network</category><category domain="http://blogs.technet.com/b/askds/archive/tags/AD+Replication/">AD Replication</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Ned+Pyle/">Ned Pyle</category><category domain="http://blogs.technet.com/b/askds/archive/tags/RPC/">RPC</category></item><item><title>Friday Mail Sack: It’s a Dog’s Life Edition</title><link>http://blogs.technet.com/b/askds/archive/2012/01/20/friday-mail-sack-it-s-a-dog-s-life-edition.aspx</link><pubDate>Fri, 20 Jan 2012 22:27:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3476532</guid><dc:creator>NedPyle [MSFT]</dc:creator><slash:comments>3</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/rsscomments.aspx?WeblogPostID=3476532</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/commentapi.aspx?WeblogPostID=3476532</wfw:comment><comments>http://blogs.technet.com/b/askds/archive/2012/01/20/friday-mail-sack-it-s-a-dog-s-life-edition.aspx#comments</comments><description>&lt;p&gt;Hi folks, &lt;a href="http://blogs.technet.com/b/askds/archive/tags/Ned+Pyle/"&gt;Ned&lt;/a&gt; here again with some possibly interesting, occasionally entertaining, and always unsolicited Friday mail sack. This week we talk some:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#dns"&gt;DNS partition absence&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#dcdiag"&gt;Controlling DCDIAG event messaging&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#sysvol"&gt;Inventorying SYSVOL replication architecture&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#dfsrwmi"&gt;Weird WMI DFSR volume paths&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#inactive"&gt;Tightening up your inactive user account queries&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#banner"&gt;More logon banner info&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#smartcard"&gt;Smart card logons working "too well&lt;/a&gt;"&lt;/li&gt;
&lt;li&gt;&lt;a href="#sid"&gt;SID history and up-level auditing annoyance&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#rolesep"&gt;CA role separation&amp;hellip; separation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#other"&gt;Other stuff&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Fetch!&lt;/p&gt;
&lt;h1&gt;&lt;a name="dns"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;We use third party DNS but used to have Windows DNS on domain controllers; that service has been uninstalled and all that remains are the partitions. According to KB835397, deleting the ForestDNSZones and DomainDNSZones partitions is not supported. Soon we will have removed the last few old domain controllers hosting some of those partitions and replaced them with Windows Server 2008 R2 that never had Windows DNS. Are we getting ourselves in trouble or making this environment unsupported?&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;You are supported. Don&amp;rsquo;t interpret the KB too narrowly; there&amp;rsquo;s a difference between deletion of partitions used by DNS and never creating them in the first place. If you are not using MS DNS and the zones don&amp;rsquo;t exist, there&amp;rsquo;s nothing in Windows that should care about them, and we are not aware of any problems.&lt;/p&gt;
&lt;p&gt;This is more of a &amp;ldquo;cover our butts&amp;rdquo; article&amp;hellip; we just don&amp;rsquo;t want you deleting partitions that you are actually using and naturally, we don&amp;rsquo;t rigorously test with non-MS DNS. That&amp;rsquo;s your job. ;-)&lt;/p&gt;
&lt;h1&gt;&lt;a name="dcdiag"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;When I run &lt;a href="http://blogs.technet.com/b/askds/archive/2011/03/22/what-does-dcdiag-actually-do.aspx" target="_blank"&gt;DCDIAG&lt;/a&gt; it returns all warning events for the system event log. I have a bunch of &amp;ldquo;expected&amp;rdquo; warnings, so this just clogs up my results. Can I change this behavior?&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;DCDIAG has no idea what the messages mean and has no way to control the output. You will need to suppress the events themselves in their own native fashion, if their application supports it. For example, if it&amp;rsquo;s a chatty combination domain controller/print server in a branch office that shows endless expected printer Warning messages, you&amp;rsquo;d use the steps &lt;a href="http://technet.microsoft.com/en-us/library/cc784896(v=WS.10).aspx" target="_blank"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;If your application cannot be controlled, there&amp;rsquo;s one (rather gross) alternative to make things cleaner though, and that&amp;rsquo;s to use the FIND command in a few pipelines to remove expected events. For example, here I always see this write cache warning when I boot this DC, and I don&amp;rsquo;t really care about it:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/3125.image_5F00_4BFD9B00.png"&gt;&lt;img width="642" height="447" title="image" style="display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/5282.image_5F00_thumb_5F00_322964D1.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Since I don&amp;rsquo;t care about these entries, I can use pipelined &lt;b&gt;FIND&lt;/b&gt; (with /&lt;b&gt;v&lt;/b&gt; to drop those lines) and narrow down the returned data. I probably don&amp;rsquo;t care about the time generated since DCDIAG only shows the last 60 minutes, nor the event string lines either. So with that, I can use this single wrapped line in a batch file:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;span style="font-family: consolas;" face="Consolas"&gt;&lt;strong&gt;dcdiag/test:systemlog | find /I /v "eventid: 0x80040022" | find /I /v "the driver disabled the write cache on device" | find /i /v "event string:" | find /i /v "time generated:"&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/7345.clip_5F00_image002_5F00_3EB711ED.jpg"&gt;&lt;img width="604" height="281" title="clip_image002" style="display: inline; background-image: none;" alt="clip_image002" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/4705.clip_5F00_image002_5F00_thumb_5F00_0F852656.jpg" border="0" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;span style="font-size: xx-small;" size="1"&gt;Whoops, I need to fix that user&amp;rsquo;s group memberships!&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Voila. I still get most of the useful data and nothing about that write cache issue. Just substitute your own stuff.&lt;/p&gt;
&lt;p&gt;See, I don&amp;rsquo;t always make you use Windows PowerShell for your pipelines. ツ&lt;/p&gt;
&lt;h1&gt;&lt;a name="sysvol"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;If I walk into a new Windows Server 2008 AD environment cold and need to know if they are using DFSR or FRS for SYSVOL replication, what is the quickest way to tell?&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;Just run this DFSRMIG command:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="font-family: consolas;" face="Consolas"&gt;dfsrmig.exe /getglobalstate&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;That tells you what the current state of the SYSVOL DFSR topology and migration.&lt;/p&gt;
&lt;p&gt;If it says:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&amp;ldquo;Eliminated&amp;rdquo;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&amp;hellip; they are using DFSR for SYSVOL. It will show this message even if the domain was built from scratch with a Windows Server 2008 domain functional level or higher &lt;i&gt;and never performed a migration;&lt;/i&gt; the tool doesn&amp;rsquo;t know how to say &amp;ldquo;they always used DFSR from day one&amp;rdquo;.&lt;/p&gt;
&lt;p&gt;If it says:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&amp;ldquo;Prepared&amp;rdquo;&lt;/li&gt;
&lt;li&gt;&amp;ldquo;Redirected&amp;rdquo;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&amp;hellip; they are mid-migration and using &lt;em&gt;both &lt;/em&gt;FRS and DFSR, favoring one or the other for SYSVOL.&lt;/p&gt;
&lt;p&gt;If it says:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&amp;ldquo;Start&amp;rdquo;&lt;/li&gt;
&lt;li&gt;&amp;ldquo;DFSR migration has not yet initialized&amp;rdquo;&lt;/li&gt;
&lt;li&gt;&amp;ldquo;Current domain functional level is not Windows Server 2008 or above&amp;rdquo;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&amp;hellip; they are using FRS for SYSVOL.&lt;/p&gt;
&lt;h1&gt;&lt;a name="dfsrwmi"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;When using the DFSR WMI namespace &amp;ldquo;root\microsoftdfs&amp;rdquo; and class &amp;ldquo;dfsrvolumeconfig&amp;rdquo;, I am seeing weird results for the volume path. On one server it&amp;rsquo;s the C: drive, but on another it just shows a wacky volume GUID. Why?&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;DFSR is replicating data under a mount point. You can see this with any WMI tool (surprise! here&amp;rsquo;s PowerShell) and then use &lt;strong&gt;mountvol.exe&lt;/strong&gt; to confirm your theory. To wit:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/0044.image_5F00_58C90B85.png"&gt;&lt;img width="623" height="164" title="image" style="display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/4657.image_5F00_thumb_5F00_31228F5B.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/5238.image_5F00_1B58A6FE.png"&gt;&lt;img width="625" height="166" title="image" style="display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/1031.image_5F00_thumb_5F00_08A3AD47.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h1&gt;&lt;a name="inactive"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;I notice that the "dsquery user -inactive x" command returns a list of user accounts that have been inactive for x number of weeks, but not days.&amp;nbsp; I suspect that this lack of precision is related to this &lt;a href="http://blogs.technet.com/b/askds/archive/2009/04/15/the-lastlogontimestamp-attribute-what-it-was-designed-for-and-how-it-works.aspx" target="_blank"&gt;older AskDS post&lt;/a&gt; where it is mentioned that the LastLogonTimeStamp attribute is not terribly accurate. I was wondering what your thoughts on this were, and if my only real recourse for precise auditing of inactive user accounts was by parsing the Security logs of my DCs for user logon events.&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;Your supposition about DSQUERY is right. What's worse, that tool's queries do not even include users that have &lt;em&gt;never&lt;/em&gt; logged on in its inactive search. So it's totally misleading. If you use the AD Administrative Center query for inactive accounts, it uses this LDAP syntax, so it's at least catching everyone (note that your lastlogontimestamp UTC value would be different):&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;(&amp;amp;(objectCategory=person)(objectClass=user)(!userAccountControl:1.2.840.113556.1.4.803:=2)(|(lastLogonTimestamp&amp;lt;=&lt;/strong&gt;&lt;em&gt;&lt;b&gt;129528216000000000&lt;/b&gt;&lt;/em&gt;&lt;strong&gt;)(!lastLogonTimestamp=*)))&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;You can lower the msDS-LogonTimeSyncInterval down to 1 day, which removes the randomization and gets you very close to that magic "exactness" (within 24 hours). But this will increase your replication load, perhaps significantly if this is a large environment with a lot of logon activity. Warren's blog post you mentioned describes how to do this. I&amp;rsquo;ve seen some pretty clever PowerShell techniques for this: &lt;a href="http://dmitrysotnikov.wordpress.com/2008/07/18/finding-the-latest-logon-time/" target="_blank"&gt;here's one&lt;/a&gt; (untested, non-MS) example that could be easily adopted into native Windows AD PowerShell or just used as-is. Dmitry is a smart fella. Make sure that you if you find scripts that the the author clearly understood &lt;a href="http://blogs.technet.com/b/askds/archive/2009/04/15/the-lastlogontimestamp-attribute-what-it-was-designed-for-and-how-it-works.aspx" target="_blank"&gt;Warren&amp;rsquo;s rules&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;There is also the option - if you just care about users' &lt;em&gt;interactive &lt;/em&gt;logons and you have all Windows Vista or Windows 7 clients - to implement msDS-LastSuccessfulInteractiveLogonTime. The ups and downs of this are discussed &lt;a href="http://blogs.technet.com/b/askds/archive/2010/07/17/friday-mail-sack-saturday-edition.aspx." target="_blank"&gt;here&lt;/a&gt;. That is replicated normally and could be used as an LDAP query option.&lt;/p&gt;
&lt;p&gt;Windows AD PowerShell has a nice built-in constructed property called &amp;ldquo;LastLogonDate&amp;rdquo; that is the friendly date time info, converted from the gnarly UTC. That might help you in your scripting efforts.&lt;/p&gt;
&lt;p&gt;After all that, you are back to Warren's recommended use of security logs and audit collection services. Which is a good idea anyway. You don't get to be meticulous about just one aspect of security!&lt;/p&gt;
&lt;h1&gt;&lt;a name="banner"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;I was reading your &lt;a href="http://blogs.technet.com/b/askds/archive/2008/02/08/deploying-legal-notices-to-domain-computers-using-group-policy.aspx"&gt;older blog post&lt;/a&gt; about setting legal notice text and had a few questions:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Has Windows 7 changed to make this any easier or better?&lt;/li&gt;
&lt;li&gt;Any way to change the font or its size?&lt;/li&gt;
&lt;li&gt;Any way to embed URLs in the text so the user can see what they are agreeing to in more detail?&lt;/li&gt;
&lt;/ol&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;&lt;em&gt;[Courtesy of that post&amp;rsquo;s author, Mike &amp;ldquo;DiNozzo&amp;rdquo; Stephens]&lt;/em&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;No&lt;/li&gt;
&lt;li&gt;No&lt;/li&gt;
&lt;li&gt;No&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;:)&lt;/p&gt;
&lt;p&gt;#3 is especially impossible. Just imagine what people would do to us if we allowed you to run Internet Explorer &lt;em&gt;before&lt;/em&gt; you logged on!&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/7701.image_5F00_19A7DB2A.png"&gt;&lt;img width="628" height="116" title="image" style="display: inline; background-image: none;" alt="image" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/3755.image_5F00_thumb_5F00_5FB8983D.png" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;em&gt;&lt;/em&gt;&amp;nbsp;&lt;em&gt;[The next few answers courtesy of Jonathan &amp;ldquo;Davros&amp;rdquo; Stephens. Note how he only ever replies with bad news&amp;hellip; &amp;ndash; Neditor]&lt;/em&gt;&lt;/p&gt;
&lt;h1&gt;&lt;a name="smartcard"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;I have encountered the following issue with some of my users performing smart card logon from Windows XP SP3.&lt;/p&gt;
&lt;p&gt;It seems that my users are able to logon using smart card logon even if the certificate on the user&amp;rsquo;s smart card was revoked. &lt;br /&gt;Here are the tests we've performed:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Verified that the CRL is accessible&lt;/li&gt;
&lt;li&gt;Smartcard logon with the working certificate&lt;/li&gt;
&lt;li&gt;Revoked the certificate + waited for the next CRL publish&lt;/li&gt;
&lt;li&gt;Verified that the new CRL is accessible and that the revoked certificate was present in the list&lt;/li&gt;
&lt;li&gt;Tested smartcard logon with the revoked certificate&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;We verified the presence of the following registry keys both on the client machine and on the authenticating DC:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;HKEY_Local_Machine\System\CurrentControlSet\Services\KDC\CRLValidityExtensionPeriod &lt;br /&gt;HKEY_Local_Machine\System\CurrentControlSet\Services\KDC\CRLTimeoutPeriod &lt;br /&gt;HKEY_Local_Machine\System\CurrentControlSet\Control\LSA\Kerberos\Parameters\CRLTimeoutPeriod &lt;br /&gt;HKEY_Local_Machine\System\CurrentControlSet\Control\LSA\Kerberos\Parameters\UseCachedCRLOnlyAndIgnoreRevocationUnknownErrors&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;None of them were found.&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;First, there is an overlap built into CRL publishing. The old CRL remains valid for a time after the new CRL is published to allow clients/servers a window to download the new CRL before the old one becomes invalid. If the old CRL is still valid then it is probably being used by the DC to verify the smart card certificate.&lt;/p&gt;
&lt;p&gt;Second, revocation of a smart card certificate is not intended to be usable as real-time access control -- not even with OCSP involved. If you want to prevent the user from logging on with the smart card then the account should be disabled. That said, one possible hacky alternative that would be take immediate effect would be to change the UPN of the user so it does not match the UPN on the smart card. With mismatched UPNs, implicit mapping of the smart card certificate to the user account would fail; the DC would have no way to determine which account it should authenticate even assuming the smart card certificate verified successfully.&lt;/p&gt;
&lt;p&gt;If you have Windows Server 2008 R2 DCs, you can &lt;a href="http://technet.microsoft.com/en-us/library/ff520074(WS.10).aspx"&gt;disable the implicit mapping of smart card logon certificates to user accounts via the UPN&lt;/a&gt; in favor of explicit certificate mapping. That way, if a user loses his smart card and you want to make sure that that certificate cannot be used for authentication as soon as possible, remove it from the &lt;a href="http://blogs.msdn.com/b/spatdsg/archive/2010/06/18/howto-map-a-user-to-a-certificate-via-all-the-methods-available-in-the-altsecurityidentities-attribute.aspx"&gt;altSecurityIdentities&lt;/a&gt; attribute on the user object in AD. Of course, the tradeoff here is the additional management of updating user accounts before their smart cards can be used for logon.&lt;/p&gt;
&lt;h1&gt;&lt;a name="sid"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;When using the SID cloning tools like sidhist.vbs in a Windows Server 2008 R2 domain, they always fail with error &amp;ldquo;&lt;strong&gt;Destination auditing must be enabled&lt;/strong&gt;&amp;rdquo;. I verified that Account Management auditing is on as required, but then I also found that the newer Advanced Audit policy version of that setting is &lt;em&gt;also&lt;/em&gt; on. It seems like the DSAddSIDHistory() API does not consider this new auditing sufficient? In my test environment everything works fine, but it does not use Advanced Auditing. I also found that if I set &lt;em&gt;all&lt;/em&gt; Account Management advanced audit subcategories to enabled, it works.&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;It turns out that this is a known issue (it affects ADMT too). At this time, DsAddSidHistory() only works if it thinks legacy Account Management is enabled. You will either need to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Remove the Advanced Auditing policy and force the destination computers use legacy auditing by setting &lt;strong&gt;Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings &lt;/strong&gt;to disabled.&lt;/li&gt;
&lt;li&gt;Set &lt;em&gt;all&lt;/em&gt; Account Management advanced audit subcategories to enabled, as you found, which satisfies the SID cloning function.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We are making sure TechNet is updated to reflect this as well.&amp;nbsp; It&amp;rsquo;s not like Advanced Auditing is going to get &lt;em&gt;less &lt;/em&gt;popular over time.&lt;/p&gt;
&lt;h1&gt;&lt;a name="rolesep"&gt;&lt;/a&gt;Question&lt;/h1&gt;
&lt;p&gt;Enterprise and Datacenter editions of Windows Server support enforcing Role Separation based on the common criteria (CC) definitions.&amp;nbsp; But there doesn't seem to be any way to define the roles that you want to enforce.&lt;/p&gt;
&lt;p&gt;CC Security Levels 1 and 2 only define two roles that need to be restricted (CA Administrator and Certificate Manager).&amp;nbsp; Auditing and Backup functions are handled by the CA administrator instead of dedicated roles.&lt;/p&gt;
&lt;p&gt;Is there a way to enforce separation of these two roles without including the Auditor and Backup Operator roles defined in the higher CC Security Levels?&lt;/p&gt;
&lt;h1&gt;Answer&lt;/h1&gt;
&lt;p&gt;Unfortunately, there is no way to make exceptions to role separation. Basically, you have two options:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Enable &lt;a href="http://technet.microsoft.com/en-us/library/cc732590(WS.10).aspx"&gt;Role Separation&lt;/a&gt; and use different user accounts for each role.&lt;/li&gt;
&lt;li&gt;Do not enable Role Separation, turn on &lt;a href="http://technet.microsoft.com/en-us/library/cc772451(WS.10).aspx"&gt;CA Auditing&lt;/a&gt; to monitor actions taken on the CA.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;em&gt;[Now back to Ned for the idiotic finish!]&lt;/em&gt;&lt;/p&gt;
&lt;h1&gt;&lt;a name="other"&gt;&lt;/a&gt;Other Stuff&lt;/h1&gt;
&lt;p&gt;My latest favorite site is &lt;a href="http://cubiclebot.com/" target="_blank"&gt;cubiclebot.com&lt;/a&gt;. Mainly because they lead me to things like this:&lt;/p&gt;
&lt;blockquote&gt;&lt;iframe width="420" height="315" src="http://www.youtube.com/embed/7YmXdeRXqv8" frameborder="0" allowfullscreen="allowfullscreen"&gt;&lt;/iframe&gt; &lt;br /&gt;&lt;span style="font-size: xx-small;" size="1"&gt;Boing boing boing&lt;/span&gt;&lt;/blockquote&gt;
&lt;p&gt;And this:&lt;/p&gt;
&lt;blockquote&gt;&lt;iframe width="560" height="315" src="http://www.youtube.com/embed/uU6U-8LP1DY" frameborder="0" allowfullscreen="allowfullscreen"&gt;&lt;/iframe&gt; &lt;br /&gt;&lt;span style="font-size: xx-small;" size="1"&gt;Wait for the pit!&lt;/span&gt;&lt;/blockquote&gt;
&lt;p&gt;Speaking of cool dogs and songs: &lt;a href="http://www.youtube.com/watch?v=6ntDYjS0Y3w"&gt;Bark bark bark bark, bark bark bark-bark&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Game of Thrones season 2 is &lt;a href="http://tv.ign.com/articles/121/1216472p1.html" target="_blank"&gt;April 1st.&lt;/a&gt; Expect everyone to die, no matter how important or likeable their character. Thanks George!&lt;/p&gt;
&lt;p&gt;At &lt;em&gt;last&lt;/em&gt;, Ninja-related &lt;a href="http://www.thinkgeek.com/geek-kids/3-7-years/ec28/?cpg=cj&amp;amp;ref=&amp;amp;CJURL=&amp;amp;CJID=2617611" target="_blank"&gt;sticky notes&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;For all the &lt;a href="http://fashionablygeek.com/costumes/kids-and-animals-cosplay/" target="_blank"&gt;geek parents&lt;/a&gt; out there. My favorite is:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://fashionablygeek.com/costumes/kids-and-animals-cosplay/"&gt;&lt;img width="485" height="308" title="adorbz-ewok" style="display: inline; background-image: none;" alt="adorbz-ewok" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-58-02-metablogapi/2570.adorbz_2D00_ewok_5F00_57C0F5DB.jpg" border="0" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;span style="font-size: xx-small;" size="1"&gt;For once, an Ewok does not enrage me&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;It was &lt;a href="http://trackerspdx.com/zombie-survival.php"&gt;inevitable&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Finally: I am headed back to Chicagoland next weekend to see my family. If you are in northern Illinois and planning on eating at &lt;a href="http://www.bing.com/maps/default.aspx?q=slotts+hots+libertyville&amp;amp;mkt=en-US&amp;amp;FORM=BYFD" target="_blank"&gt;Slott&amp;rsquo;s Hots&lt;/a&gt; in Libertyville, &lt;a href="http://www.bing.com/maps/default.aspx?q=louie's+restaurant+1009+North+Ave%2c+Waukegan%2c+IL+60085&amp;amp;mkt=en-US&amp;amp;FORM=BYFD" target="_blank"&gt;Louie&amp;rsquo;s&lt;/a&gt; in Waukegan, or &lt;a href="http://www.bing.com/maps/default.aspx?ss=leona's+restaurant&amp;amp;where1=Chicago%2c+Illinois&amp;amp;s_cid=ansPhBkYp01&amp;amp;mkt=en-us&amp;amp;ac=false&amp;amp;FORM=LARE" target="_blank"&gt;Leona&amp;rsquo;s&lt;/a&gt; in Chicago, gimme a wave. Yes, all I care about is the food. My wife only cares about the shopping, that&amp;rsquo;s why we&amp;rsquo;re on Michigan avenue and why she cannot complain. You don&amp;rsquo;t know what it&amp;rsquo;s like living in Charlotte!! D-:&lt;/p&gt;
&lt;p&gt;Have a nice weekend folks,&lt;/p&gt;
&lt;p&gt;Ned &amp;ldquo;my dogs are not quite as athletic&amp;rdquo; Pyle&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3476532" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/askds/archive/tags/DFSR/">DFSR</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Certificates/">Certificates</category><category domain="http://blogs.technet.com/b/askds/archive/tags/PKI/">PKI</category><category domain="http://blogs.technet.com/b/askds/archive/tags/LDAP/">LDAP</category><category domain="http://blogs.technet.com/b/askds/archive/tags/SYSVOL/">SYSVOL</category><category domain="http://blogs.technet.com/b/askds/archive/tags/FRS/">FRS</category><category domain="http://blogs.technet.com/b/askds/archive/tags/ADMT/">ADMT</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Security/">Security</category><category domain="http://blogs.technet.com/b/askds/archive/tags/WMI/">WMI</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Windows+7/">Windows 7</category><category domain="http://blogs.technet.com/b/askds/archive/tags/PowerShell/">PowerShell</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Other+Blogs/">Other Blogs</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Logon/">Logon</category><category domain="http://blogs.technet.com/b/askds/archive/tags/OCSP/">OCSP</category><category domain="http://blogs.technet.com/b/askds/archive/tags/smartcards/">smartcards</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Active+Directory+Migration+Tool/">Active Directory Migration Tool</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Mail+Sack/">Mail Sack</category><category domain="http://blogs.technet.com/b/askds/archive/tags/certification+authority/">certification authority</category><category domain="http://blogs.technet.com/b/askds/archive/tags/SID/">SID</category><category domain="http://blogs.technet.com/b/askds/archive/tags/DFSR+Migration+or+Upgrade/">DFSR Migration or Upgrade</category><category domain="http://blogs.technet.com/b/askds/archive/tags/dcdiag/">dcdiag</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Event+Logs/">Event Logs</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Jonathan+Stephens/">Jonathan Stephens</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Mike+Stephens/">Mike Stephens</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Warren+Williams/">Warren Williams</category><category domain="http://blogs.technet.com/b/askds/archive/tags/Ned+Pyle/">Ned Pyle</category><category domain="http://blogs.technet.com/b/askds/archive/tags/ADAC/">ADAC</category></item><item><title>How to become a PFE (worth reading if you are job hunting)</title><link>http://blogs.technet.com/b/askds/archive/2012/01/16/how-to-become-a-pfe-worth-reading-if-you-are-job-hunting.aspx</link><pubDate>Mon, 16 Jan 2012 17:50:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3475658</guid><dc:creator>NedPyle [MSFT]</dc:creator><slash:comments>5</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/rsscomments.aspx?WeblogPostID=3475658</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/askds/commentapi.aspx?WeblogPostID=3475658</wfw:comment><comments>http://blogs.technet.com/b/askds/archive/2012/01/16/how-to-become-a-pfe-worth-reading-if-you-are-job-hunting.aspx#comments</comments><description>&lt;p&gt;Hi all, &lt;a href="http://blogs.technet.com/b/askds/archive/tags/Ned+Pyle/"&gt;Ned&lt;/a&gt; here. Greg Jaworski&amp;nbsp;has posted an informative read for those looking to join the ranks of Microsoft Premier Field Engineering. They are always hiring and if your New Year's resolution includes travel, career growth, and working for the largest software company in the world, I recommend you give it a look.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/b/askpfeplat/archive/2012/01/16/how-to-become-a-premier-field-engineer-pfe.aspx"&gt;How to become a Premier Field Engineer (PFE&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;It has&amp;nbsp;useful tips, an explanation of the interview process, and other helpful goo. This comes to you the new &lt;a href="http://blogs.technet.com/b/askpfeplat/"&gt;Ask PFE&lt;/a&gt; blog.&lt;/p&gt;
&lt;p&gt;They&amp;nbsp;also appear&amp;nbsp;to favor&amp;nbsp;those with &lt;a href="http://blogs.technet.com/b/markmoro/"&gt;Polish surnames.&lt;/a&gt; I'm not saying it's required, but it&amp;nbsp;seems to help. ;-P&lt;/p&gt;
&lt;p&gt;- Ned "Casimir" Pyle&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3475658" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/askds/archive/tags/Other+Blogs/">Other Blogs</category><category domain="http://blogs.technet.com/b/askds/archive/tags/hiring/">hiring</category></item></channel></rss>
