<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Friday Mail Sack: Best Post This Year Edition</title><link>http://blogs.technet.com/b/askds/archive/2012/01/06/friday-mail-sack-best-post-this-year-edition.aspx</link><description>Hi folks, Ned here and welcoming you to 2012 with a new Friday Mail Sack. Catching up from our holiday hiatus, today we talk about: 
 
 Disabling Administrative Shares 
 Making Get-ADDomainController useful&amp;rsquo;er 
 Kerberos group bloat 
 USMT</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: Friday Mail Sack: Best Post This Year Edition</title><link>http://blogs.technet.com/b/askds/archive/2012/01/06/friday-mail-sack-best-post-this-year-edition.aspx#3475060</link><pubDate>Thu, 12 Jan 2012 04:54:22 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3475060</guid><dc:creator>Ashley McGlone</dc:creator><description>&lt;p&gt;I really like the Get-ADDomainController tip. &amp;nbsp;Nice!&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3475060" width="1" height="1"&gt;</description></item><item><title>re: Friday Mail Sack: Best Post This Year Edition</title><link>http://blogs.technet.com/b/askds/archive/2012/01/06/friday-mail-sack-best-post-this-year-edition.aspx#3474947</link><pubDate>Wed, 11 Jan 2012 15:56:04 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3474947</guid><dc:creator>sgrinker</dc:creator><description>&lt;p&gt;First, glad to have new posts again, hope everyone had a great holiday.&lt;/p&gt;
&lt;p&gt;Second, happy to see more PowerShell.&lt;/p&gt;
&lt;p&gt;Third, I can&amp;#39;t help but feel multi-part comments are a new requirement in 2012 now. &amp;nbsp;:)&lt;/p&gt;
&lt;p&gt;Lastly, I $%^@!% agree, as long as it&amp;#39;s done in the right venue and context. &amp;nbsp;Work not being either... &amp;nbsp;:D&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3474947" width="1" height="1"&gt;</description></item><item><title>re: Friday Mail Sack: Best Post This Year Edition</title><link>http://blogs.technet.com/b/askds/archive/2012/01/06/friday-mail-sack-best-post-this-year-edition.aspx#3474525</link><pubDate>Mon, 09 Jan 2012 14:31:38 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3474525</guid><dc:creator>NedPyle [MSFT]</dc:creator><description>&lt;p&gt;Thanks, I fixed that brain fart. &lt;/p&gt;
&lt;p&gt;As for the group membership - I didn&amp;#39;t really saying having a lot of groups is uniqueness. Creating a design where so many groups are assigned to a security principal that the principal is broken is... I&amp;#39;m sure that the FIM people would have some opinions on this, but they are sooooo boring when they share it. :-P&lt;/p&gt;
&lt;p&gt;Damn right!&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3474525" width="1" height="1"&gt;</description></item><item><title>re: Friday Mail Sack: Best Post This Year Edition</title><link>http://blogs.technet.com/b/askds/archive/2012/01/06/friday-mail-sack-best-post-this-year-edition.aspx#3474433</link><pubDate>Sun, 08 Jan 2012 20:20:30 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3474433</guid><dc:creator>Pronichkin</dc:creator><description>&lt;p&gt;First, re: migrating user docs from D:\ to C:\. There&amp;#39;s no such thing as “move.exe”. (Well, at least on my systems). You likely meant cmd /c move (depending on where you call it from).&lt;/p&gt;
&lt;p&gt;Second, re: clusterd CA. There&amp;#39;s one more reason why you should not use “net stop” style of things. Since cluster has no idea of who stopped the services (and for what reasons), it would treat that as node failure. Guess what, it will immediately restart the service on another node. Probably not what you intended.&lt;/p&gt;
&lt;p&gt;Third, having thousands of groups doesn&amp;#39;t seem like “IT Uniqueness” to me, sorry. More like a thoughtfully designed RBAC. (No, it&amp;#39;s not the same thing). We probably need some “semi-official” guidance on how to do such kind of thins. (Something more robust and concrete than just “use AGDLP, Luke”).&lt;/p&gt;
&lt;p&gt;Last but not least, swearing is goooood!&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3474433" width="1" height="1"&gt;</description></item><item><title>re: Friday Mail Sack: Best Post This Year Edition</title><link>http://blogs.technet.com/b/askds/archive/2012/01/06/friday-mail-sack-best-post-this-year-edition.aspx#3474354</link><pubDate>Sat, 07 Jan 2012 03:49:10 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3474354</guid><dc:creator>Ryan Ries</dc:creator><description>&lt;p&gt;OK, first off, that Battlestar Galactica meets Final Fantasy 3/6 video was amazing. &amp;nbsp;Hilarious.&lt;/p&gt;
&lt;p&gt;Secondly, that was very cruel of you to link to that weird Buscemeyes thing. &amp;nbsp;So many fantasies... utterly ruined...&lt;/p&gt;
&lt;p&gt;Thirdly, I would unleash a hearty laugh if I ever encountered anyone receiving error messages like that because of so many group memberships.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3474354" width="1" height="1"&gt;</description></item></channel></rss>