<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Marcus Hass' [MS] Blog : Windows</title><link>http://blogs.technet.com/mhass/archive/tags/Windows/default.aspx</link><description>Tags: Windows</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Microsoft Online and SBS 2003</title><link>http://blogs.technet.com/mhass/archive/2009/06/02/microsoft-online-and-sbs-2003.aspx</link><pubDate>Wed, 03 Jun 2009 05:16:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3249589</guid><dc:creator>mhass</dc:creator><slash:comments>4</slash:comments><comments>http://blogs.technet.com/mhass/comments/3249589.aspx</comments><wfw:commentRss>http://blogs.technet.com/mhass/commentrss.aspx?PostID=3249589</wfw:commentRss><wfw:comment>http://blogs.technet.com/mhass/rsscomments.aspx?PostID=3249589</wfw:comment><description>&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;I have been working with the Microsoft BPOS aka Microsoft Online guys in Enterprise accounts for a while to help big companies migrate to BPOS dedicated.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Don’t know what that is?&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Check out &lt;/FONT&gt;&lt;A href="http://www.microsoftonline.com/"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;www.microsoftonline.com&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt;.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;To sum it up, it is hosted Exchange, SharePoint, OCS, LiveMeeting, and a few other offerings.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;For bigger businesses, Microsoft sets up dedicated hosting servers, for small it is multitenant.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;I help out a small company from time to time because they have 15 employees and a Small Business Server 2003 environment.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;They are constantly running out of space on their 5 year old server because mail boxes keep growing because of attachment sizes.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;These guys are the perfect scenario to migrate to Microsoft Online!&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;So, I setup a free trial and started loading some of the coexistence tools like email sync and dirsync onto the Small Business server.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Well, that was the plan.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Turns out, dirsync can’t be run on a domain controller and will only run on Windows Server 2003.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I think the BPOS guys missed the Small Businesses aren’t going to have an extra server lying around.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;How can you miss this scenario when building your tools, especially a segment of the market so perfect for BPOS?&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;So, they will have to forgo the coexistence and migrate mailboxes in one fell swoop over a weekend, which won’t be pretty over the small network connection they have.&lt;/FONT&gt;&lt;/P&gt;&lt;FONT size=3 face=Calibri&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="FONT-SIZE: 12pt; mso-ascii-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri"&gt;I am sure there are technical reasons, and that's what will be used as an excuse.&amp;nbsp; It just disappoints me when we have really smart guys that miss such a big opportunity to help small businesses.&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 12pt; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/FONT&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3249589" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mhass/archive/tags/All+Posts+Mhass/default.aspx">All Posts Mhass</category><category domain="http://blogs.technet.com/mhass/archive/tags/SharePoint/default.aspx">SharePoint</category><category domain="http://blogs.technet.com/mhass/archive/tags/Rants/default.aspx">Rants</category><category domain="http://blogs.technet.com/mhass/archive/tags/IM_2F00_LCS/default.aspx">IM/LCS</category><category domain="http://blogs.technet.com/mhass/archive/tags/Exchange/default.aspx">Exchange</category><category domain="http://blogs.technet.com/mhass/archive/tags/Windows/default.aspx">Windows</category></item><item><title>Windows XP/XPe and Remote Desktop Services Single Sign On</title><link>http://blogs.technet.com/mhass/archive/2009/04/16/windows-xp-xpe-and-remote-desktop-services-single-sign-on.aspx</link><pubDate>Thu, 16 Apr 2009 18:03:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3227228</guid><dc:creator>mhass</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/mhass/comments/3227228.aspx</comments><wfw:commentRss>http://blogs.technet.com/mhass/commentrss.aspx?PostID=3227228</wfw:commentRss><wfw:comment>http://blogs.technet.com/mhass/rsscomments.aspx?PostID=3227228</wfw:comment><description>&lt;P&gt;This week I was working with a retail customer that has plans to place HP Windows XP Embedded devices at their many retail stores.&amp;nbsp; Applications will be served up either locally on the XPe device, through a remote desktop, or through Remote Applications.&lt;/P&gt;
&lt;P&gt;There is a slight challenge with this setup because technically Microsoft supports this configuration, but doesn’t give you great tools to setup Single Sign On (SSO).&amp;nbsp; When Vista was first introduced, Microsoft created a new credential manager that could handle SSO for Terminal Server as well as products such as HyperV.&amp;nbsp; Fortunately, the product team also back-ported the credential manager (CredSSP) functionality to Windows XP.&amp;nbsp; While Vista has an easy enough local Group Policy you can edit, Windows XP never got the same treatment. In order to get it to work in XP and XPe, you have to make a bunch or registry edits, which are also not provided in an easy to copy .REG format.&lt;/P&gt;
&lt;P&gt;Well, as a service to the public, I have included a text copy of my .REG file below. The information below is provided as-is, no warranty, no support, please don’t cry to me.&amp;nbsp; But, I have tested it pretty thoroughly and it seems to work.&lt;/P&gt;
&lt;P&gt;A couple caveats:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;If you use a smartcard to authenticate to Windows, no matter how hard you try you won’t be able to get an RDP session to honor your Windows credentials, you will always be prompted for credentials when running MSTSC or a .RDP file.&amp;nbsp; This is counter-intuitive as you would think 2 factor authentication would be more trusted than simple username/password, but it is a known limitation in Windows XP.&amp;nbsp; Citrix does provide their own credential manager that can add functionality here. &lt;/LI&gt;
&lt;LI&gt;One of the registry entries is in hex so you can’t see what it is.&amp;nbsp; It is one of two entries that require you to APPEND the necessary settings for CredSSP to work.&amp;nbsp; If you have other entries for GINA’s or other credential providers, please be careful as this will overwrite them with the default+CredSSP entries &lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;Many thanks to Olga and Sergey on the product team as well as Kevin Martin from HP for their help this week.&lt;/P&gt;
&lt;P&gt;References:&lt;/P&gt;
&lt;P&gt;&lt;A title=http://support.microsoft.com/default.aspx/kb/951608 href="http://support.microsoft.com/default.aspx/kb/951608" mce_href="http://support.microsoft.com/default.aspx/kb/951608"&gt;http://support.microsoft.com/default.aspx/kb/951608&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A title=http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx href="http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx" mce_href="http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx"&gt;http://blogs.msdn.com/rds/archive/2007/04/19/how-to-enable-single-sign-on-for-my-terminal-server-connections.aspx&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Here is my .REG file, I hope to create an ADM file at some point that I can share.&amp;nbsp; You can go ahead and cut/paste the rest of this blog entry into a text file and rename it to a .REG file.&lt;/P&gt;
&lt;P&gt;Windows Registry Editor Version 5.00 &lt;/P&gt;
&lt;P&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders] &lt;BR&gt;"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, credssp.dll" &lt;/P&gt;
&lt;P&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa] &lt;BR&gt;"Security Packages"=hex(7):6b,00,65,00,72,00,62,00,65,00,72,00,6f,00,73,00,00,\ &lt;BR&gt;&amp;nbsp; 00,6d,00,73,00,76,00,31,00,5f,00,30,00,00,00,73,00,63,00,68,00,61,00,6e,00,\ &lt;BR&gt;&amp;nbsp; 6e,00,65,00,6c,00,00,00,77,00,64,00,69,00,67,00,65,00,73,00,74,00,00,00,74,\ &lt;BR&gt;&amp;nbsp; 00,73,00,70,00,6b,00,67,00,00,00,00,00 &lt;/P&gt;
&lt;P&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CredentialsDelegation] &lt;BR&gt;"AllowDefaultCredentials"=dword:00000001 &lt;BR&gt;"ConcatenateDefaults_AllowDefault"=dword:00000001 &lt;BR&gt;"AllowDefCredentialsWhenNTLMOnly"=dword:00000001 &lt;BR&gt;"ConcatenateDefaults_AllowDefNTLMOnly"=dword:00000001 &lt;BR&gt;"AllowFreshCredentials"=dword:00000001 &lt;BR&gt;"ConcatenateDefaults_AllowFresh"=dword:00000000 &lt;BR&gt;"AllowFreshCredentialsWhenNTLMOnly"=dword:00000001 &lt;BR&gt;"ConcatenateDefaults_AllowFreshNTLMOnly"=dword:00000000 &lt;BR&gt;"AllowSavedCredentials"=dword:00000000 &lt;BR&gt;"ConcatenateDefaults_AllowSaved"=dword:00000000 &lt;BR&gt;"AllowSavedCredentialsWhenNTLMOnly"=dword:00000000 &lt;BR&gt;"ConcatenateDefaults_AllowSavedNTLMOnly"=dword:00000000 &lt;BR&gt;"DenyDefaultCredentials"=dword:00000000 &lt;BR&gt;"ConcatenateDefaults_DenyDefault"=dword:00000000 &lt;BR&gt;"DenyFreshCredentials"=dword:00000000 &lt;BR&gt;"ConcatenateDefaults_DenyFresh"=dword:00000000 &lt;BR&gt;"DenySavedCredentials"=dword:00000000 &lt;BR&gt;"ConcatenateDefaults_DenySaved"=dword:00000000 &lt;/P&gt;
&lt;P&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CredentialsDelegation\AllowDefaultCredentials] &lt;BR&gt;"1"="TERMSRV/*" &lt;/P&gt;
&lt;P&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CredentialsDelegation\AllowDefCredentialsWhenNTLMOnly] &lt;BR&gt;"1"="TERMSRV/*" &lt;/P&gt;
&lt;P&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CredentialsDelegation\AllowFreshCredentials] &lt;BR&gt;"1"="TERMSRV/*" &lt;/P&gt;
&lt;P&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CredentialsDelegation\AllowFreshCredentialsWhenNTLMOnly] &lt;BR&gt;"1"="TERMSRV/*" &lt;/P&gt;
&lt;P&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CredentialsDelegation\AllowSavedCredentials] &lt;/P&gt;
&lt;P&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CredentialsDelegation\AllowSavedCredentialsWhenNTLMOnly] &lt;/P&gt;
&lt;P&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CredentialsDelegation\DenyDefaultCredentials] &lt;/P&gt;
&lt;P&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CredentialsDelegation\DenyFreshCredentials] &lt;/P&gt;
&lt;P&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CredentialsDelegation\DenySavedCredentials] &lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3227228" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mhass/archive/tags/All+Posts+Mhass/default.aspx">All Posts Mhass</category><category domain="http://blogs.technet.com/mhass/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.technet.com/mhass/archive/tags/Desktop/default.aspx">Desktop</category><category domain="http://blogs.technet.com/mhass/archive/tags/Windows/default.aspx">Windows</category></item><item><title>Exchange 2007 – Snags during my upgrade</title><link>http://blogs.technet.com/mhass/archive/2007/01/26/exchange-2007-snags-during-my-upgrade.aspx</link><pubDate>Fri, 26 Jan 2007 20:34:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:610724</guid><dc:creator>mhass</dc:creator><slash:comments>9</slash:comments><comments>http://blogs.technet.com/mhass/comments/610724.aspx</comments><wfw:commentRss>http://blogs.technet.com/mhass/commentrss.aspx?PostID=610724</wfw:commentRss><wfw:comment>http://blogs.technet.com/mhass/rsscomments.aspx?PostID=610724</wfw:comment><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;This week I had some time to spend in my lab at home, so I thought I would catch up on some overdue projects,&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;My biggest project was to get my lab up to Exchange 2007 from 2003.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The complication here is that although I have a rack of “real” servers, I don’t have any spare capacity.&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;Virtual PC to the rescue!&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I grabbed a spare laptop from our inventory at the office, and snagged a copy of my sysprep’d Windows Server 2003 R2 image and installed Exchange 2007.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;I decided to write about my experience so that the search engines catch it, and hopefully get you on your way quicker.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2 style="MARGIN: 10pt 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;&lt;FONT size=4&gt;&lt;FONT color=#4f81bd&gt;Mailbox Migration&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;After updating my AD schema and making reasonably sure that the 2007 box could talk to the 2003 box, I moved my mailbox.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I checked, and I could still access my mailbox through OWA, RPC/HTTP, Local MAPI, and EAS (still accessed through the EX2003 box via publishing rules on my ISA 2006 box).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Since all of this worked, I migrated over the 20 or so mailboxes that I host for friends. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;Since I didn’t have any spare boxes, I would have to pave my old EX2003 box, install Exchange 2007, and move the mailboxes back off the VPC Exchange server.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I decided to take an outage and didn’t change the ISA publishing rules to the new EX2007 box, so I don’t know if Exchange out of the box worked for me (something that in retrospect might have helped me).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Uninstalling EX2003 was uneventful.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I had to turn off NNTP and SMTP to allow EX2007 to install on the box, as well as apply a .NET hotfix that the installer guided me to install.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;The “real hardware” EX2007 box was up and running, and was part of the Org.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I moved the mailboxes back, and did a quick check with a local Outlook client to ensure I could still get to mailboxes.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2 style="MARGIN: 10pt 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;&lt;FONT size=4&gt;&lt;FONT color=#4f81bd&gt;Decommissioning the EX2007 VPC&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;This is where I hit my first real snag.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I took care to move mailboxes and Public Folders over to the “Real EX2007” server.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I wanted to ensure that everything was moved over by deleting the Mailbox and Public Folder database before I did the uninstall.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;When I tried to delete the Public Folders database using the GUI I kept getting this error:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=section1 style="MARGIN: 0in 0in 12pt 0.5in"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;--------------------------------------------------------&lt;BR&gt;Microsoft Exchange Error&lt;BR&gt;--------------------------------------------------------&lt;BR&gt;The public folder database 'Public Folder Database' cannot be deleted.&lt;BR&gt;Public Folder Database Failed&lt;BR&gt;Error:&lt;BR&gt;The public folder database specified contains folder replicas. Before deleting the public folder database, remove the folders or move the replicas to another public folder database.&lt;BR&gt;&amp;nbsp;&lt;BR&gt;&lt;BR&gt;--------------------------------------------------------&lt;BR&gt;OK&lt;BR&gt;--------------------------------------------------------&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=section1 style="MARGIN: 0in 0in 12pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;With the help of some really smart Exchange product team guys, they pointed me to a couple TechNet articles:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt 0.5in"&gt;&lt;A href="http://www.microsoft.com/technet/prodtechnol/exchange/e2k7help/5e1e9fbc-53d5-44e3-9b47-6873be84e6ee.mspx?mfr=true"&gt;&lt;SPAN style="FONT-SIZE: 10pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;&lt;FONT color=#0000ff&gt;How to Remove a Public Folder Database&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="FONT-SIZE: 10pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt 0.5in"&gt;&lt;A href="http://www.microsoft.com/technet/prodtechnol/exchange/e2k7help/1f614364-88e1-4a5b-a7e7-f270eaf7782d.mspx?mfr=true"&gt;&lt;SPAN style="FONT-SIZE: 10pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;How to Remove the Last Public Folder Database in the Organization&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="FONT-SIZE: 10pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=section1 style="MARGIN: 0in 0in 12pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;For those with link impairment, and for the sake of search engines, I ran the following commands to resolve this issue:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="BACKGROUND: #dddddd; MARGIN: 0in 0in 12pt 0.5in; LINE-HEIGHT: normal; tab-stops: 45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Segoe UI','sans-serif'; mso-fareast-font-family: 'Times New Roman'"&gt;Get-PublicFolder -Server &amp;lt;server with public folder database&amp;gt; "\" -Recurse -ResultSize:Unlimited | Remove-PublicFolder -Server &amp;lt;server with public folder database&amp;gt; -Recurse -ErrorAction:SilentlyContinue&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="BACKGROUND: #dddddd; MARGIN: 0in 0in 12pt 0.5in; LINE-HEIGHT: normal; tab-stops: 45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Segoe UI','sans-serif'; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;Get-PublicFolder -Server &amp;lt;server with public folder database&amp;gt; "\Non_Ipm_Subtree" -Recurse -ResultSize:Unlimited | Remove-PublicFolder -Server &amp;lt;server with public folder database&amp;gt; -Recurse -ErrorAction:SilentlyContinue&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="BACKGROUND: #dddddd; MARGIN: 0in 0in 12pt 0.5in; LINE-HEIGHT: normal; tab-stops: 45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Segoe UI','sans-serif'; mso-fareast-font-family: 'Times New Roman'"&gt;Remove-PublicFolderDatabase -Identity "&amp;lt;server&amp;gt;\&amp;lt;storage group&amp;gt;\&amp;lt;public folder database&amp;gt;"&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=section1 style="MARGIN: 0in 0in 12pt"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;NOTE: &lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;This is where I had my first Eureka! moment.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The GUI sucks, you can’t do much more than very basic management from the new Exchange System Management console.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The Shell is where it’s at, the more you use it, the more you like it.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=section1 style="MARGIN: 0in 0in 12pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;So all is good in the world: no more mailboxes or public folders on the EX2007 VPC.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;When I try and remove Exchange 2007, I started getting the error:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=section1 style="MARGIN: 0in 0in 12pt 0.5in"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;“this computer is configured as a bridgehead server for 1 routing group connector(s) in the organization.&amp;nbsp; These must be moved or deleted before setup can continue”&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=section1 style="MARGIN: 0in 0in 12pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;Again, product team guys easily direct me to the good Exchange 2007 documentation regarding the &lt;/SPAN&gt;&lt;A href="http://technet.microsoft.com/en-us/library/8d6a9bd6-2233-4fba-9926-4323d392e1e3.aspx"&gt;&lt;SPAN style="FONT-SIZE: 10pt"&gt;cmdlets in the shell&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=section1 style="MARGIN: 0in 0in 12pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;In this case, the GUI didn’t show any routing group connectors (please see my note above about how much the GUI is a waste of time).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;So, I had to use a command to first find out the names of the routing group connector and then delete it.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I ran the following commands:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="BACKGROUND: #dddddd; MARGIN: 0in 0in 12pt 0.5in; LINE-HEIGHT: normal; tab-stops: 45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Segoe UI','sans-serif'; mso-fareast-font-family: 'Times New Roman'"&gt;Get-RoutingGroupConnector [-Identity &amp;lt;RoutingGroupConnectorIdParameter&amp;gt;] [-DomainController &amp;lt;Fqdn&amp;gt;] &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="BACKGROUND: #dddddd; MARGIN: 0in 0in 12pt 0.5in; LINE-HEIGHT: normal; tab-stops: 45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Segoe UI','sans-serif'; mso-fareast-font-family: 'Times New Roman'"&gt;Remove-RoutingGroupConnector -Identity &amp;lt;RoutingGroupConnectorIdParameter&amp;gt; [-DomainController &amp;lt;Fqdn&amp;gt;]&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=section1 style="MARGIN: 0in 0in 12pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;Phew, after deleting the server-to-server routing connector I was able to uninstall EX2007 from the VPC.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2 style="MARGIN: 10pt 0in 0pt"&gt;&lt;FONT face=Cambria color=#4f81bd size=4&gt;Can’t send or receive email&lt;/FONT&gt;&lt;/H2&gt;
&lt;P class=section1 style="MARGIN: 0in 0in 12pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;After numerous attempts to send and receive email from internal and external clients, I wasn’t able to send or receive internal or external email.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I tried using the queue viewer tool in the GUI, and it didn’t give me any clues.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I figured I was missing an external send connector, and a quick glance at the GUI verified my assumption (reminder to self: must stop using the GUI).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;To polish my mad Shell skillz further, I decided to create an external connector for all external domains (*) using the following command:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="BACKGROUND: #dddddd; MARGIN: 0in 0in 12pt 0.5in; LINE-HEIGHT: normal; tab-stops: 45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt"&gt;&lt;SPAN style="FONT-SIZE: 8.5pt; FONT-FAMILY: 'Segoe UI','sans-serif'; mso-fareast-font-family: 'Times New Roman'"&gt;New-SendConnector -Name &amp;lt;String&amp;gt; -AddressSpaces &amp;lt;MultiValuedProperty&amp;gt; [-AuthenticationCredential &amp;lt;PSCredential&amp;gt;] [-Comment &amp;lt;String&amp;gt;] [-ConnectionInactivityTimeOut &amp;lt;EnhancedTimeSpan&amp;gt;] [-DNSRoutingEnabled &amp;lt;$true | $false&amp;gt;] [-DomainController &amp;lt;Fqdn&amp;gt;] [-DomainSecureEnabled &amp;lt;$true | $false&amp;gt;] [-Enabled &amp;lt;$true | $false&amp;gt;] [-Force &amp;lt;SwitchParameter&amp;gt;] [-ForceHELO &amp;lt;$true | $false&amp;gt;] [-Fqdn &amp;lt;Fqdn&amp;gt;] [-IgnoreSTARTTLS &amp;lt;$true | $false&amp;gt;] [-MaxMessageSize &amp;lt;Unlimited&amp;gt;] [-Port &amp;lt;Int32&amp;gt;] [-ProtocolLoggingLevel &amp;lt;None | Verbose&amp;gt;] [-RequireTLS &amp;lt;$true | $false&amp;gt;] [-SmartHostAuthMechanism &amp;lt;None | BasicAuth | BasicAuthRequireTLS | ExchangeServer | ExternalAuthoritative&amp;gt;] [-SmartHosts &amp;lt;MultiValuedProperty&amp;gt;] [-SourceIPAddress &amp;lt;IPAddress&amp;gt;] [-SourceTransportServers &amp;lt;MultiValuedProperty&amp;gt;] [-TemplateInstance &amp;lt;PSObject&amp;gt;] [-Usage &amp;lt;Custom | Internal | Internet | Partner&amp;gt;] [-UseExternalDNSServersEnabled &amp;lt;$true | $false&amp;gt;]&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=section1 style="MARGIN: 0in 0in 12pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;After creating the send connector, I thought my troubles were over.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Wrong!&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Nothing was working.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I did a quick telnet to my server on port 25 and got the error:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=section1 style="MARGIN: 0in 0in 12pt 0.5in"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;“452 4.3.1. Insufficient system resources&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=section1 style="MARGIN: 0in 0in 12pt 0.5in"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;Connection to host lost.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=section1 style="MARGIN: 0in 0in 12pt 0.5in"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;Press any key to continue…”&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=section1 style="MARGIN: 0in 0in 12pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;Well, it just so happens that this machine had two partitions, one for OS and one for the stores.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;By default the SMTP queue is located on the C drive, which only had about 1GB left.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Exchange 2007 has a “Back Pressure” feature that disables the SMTP queue when there is low disk space.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Unfortunately, there is no handy-dandy shell command to move the queue location.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;There is a pretty good article up on Technet that tells you how to &lt;A href="http://technet.microsoft.com/en-us/library/f170cb0c-04a9-4fa7-b594-206e3a787e14.aspx"&gt;Change the location of the Queue Database&lt;/A&gt;,&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;It involves moving some files, granting “Full Control” to the network service on the new directory, and editing an XML file that contains the location of the queue.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I also spotted a way to &lt;A href="http://www.pro-exchange.be/modules.php?name=News&amp;amp;file=article&amp;amp;sid=305"&gt;disable the Back Pressure feature&lt;/A&gt;.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Just sucks that this isn’t in the Shell….&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=section1 style="MARGIN: 0in 0in 12pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;Immediately after this adjustment I got a shotgun of test emails, and the queue monitor lit up light a Christmas tree.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2 style="MARGIN: 10pt 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;&lt;FONT size=4&gt;&lt;FONT color=#4f81bd&gt;Certificates, OWA, and ISA&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;Because I want my buddies to be able to use OWA, EAS and RPC/HTTP securely, I have a public SSL certificate (really cheap from GoDaddy.com).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Exchange actually generates its own certificates which is great, but doesn’t really work for my purposes.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I also wanted to have ISA do the forms authentication, so I had to have the SSL cert on both the ISA server and Exchange box. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;It was pretty routine to export the cert with public key and install it on ISA using certificate manager. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;I used the ISA publishing wizard for Exchange 2007 for OWA and it made it pretty brainless.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I also published IMAP and POP3 for those friends I have that aren’t quite on the RPC/HTTP bandwagon.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Additionally, I had already published the SMTP server and created a rule to allow outgoing SMTP from the Exchange server.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=section1 style="MARGIN: 0in 0in 12pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;When I tried OWA, I kept getting the following Error:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=section1 style="MARGIN: 0in 0in 12pt 0.5in"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;500 Internal Server Error – The target principal name is incorrect” &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;Turns out that ISA’s interface in 2006 has changed a bit, and was misleading for me.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I had created an HTTPS listener with the SSL cert, and everything looked good.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;ISA allows you to “bridge” the names by allowing you to have an “outside” name and route it to an “internal” name.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Turns out, that on the “To” tab of the OWA publishing rule, I had mistakenly specified the “outside” DNS name of instead of my internal server.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;To set this up correctly, it needs to be:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=section1 style="MARGIN: 0in 0in 12pt 0.5in"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;This rule applies to this published site:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=section1 style="MARGIN: 0in 0in 12pt 0.5in"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;Mail.mydomain.com (external certificate name)&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=section1 style="MARGIN: 0in 0in 12pt 0.5in"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;Computer name or IP address (required if the internal site name is different or not resolvable):&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=section1 style="MARGIN: 0in 0in 12pt 0.5in"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;10.1.1.1&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;H2 style="MARGIN: 10pt 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;&lt;FONT size=4&gt;&lt;FONT color=#4f81bd&gt;Summary&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P class=section1 style="MARGIN: 0in 0in 12pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;When I setup numerous Exchange 2003 servers for customers, I have a set way of doing it.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;And between having done it a bunch of times, and most of the tweaking in the GUI, 2003 seems easier.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;That said, I think that if you set the expectation that the Shell is your new config tool, it isn’t much harder.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I really like the flexibility of the Shell, and I assume we took the Shell approach because the GUI would be impossibly complex to design for effective management especially with the Unified Communication components.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=section1 style="MARGIN: 0in 0in 12pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;On your side, Microsoft has provided great documentation this time and it is already published on Technet and other resources.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=section1 style="MARGIN: 0in 0in 12pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;Is it worth the hassle?&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Heck ya.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Can you run setup.exe and be ready to go in 20 minutes?&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Nope.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This is a complex, powerful product with lots of options.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;But, most admins familiar with Exchange should not have many issues getting it up and going.&lt;I style="mso-bidi-font-style: normal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=610724" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mhass/archive/tags/Operations/default.aspx">Operations</category><category domain="http://blogs.technet.com/mhass/archive/tags/All+Posts+Mhass/default.aspx">All Posts Mhass</category><category domain="http://blogs.technet.com/mhass/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.technet.com/mhass/archive/tags/Exchange/default.aspx">Exchange</category><category domain="http://blogs.technet.com/mhass/archive/tags/Windows/default.aspx">Windows</category></item><item><title>Vista RTM + 1 week</title><link>http://blogs.technet.com/mhass/archive/2006/11/20/vista-rtm-1-week.aspx</link><pubDate>Mon, 20 Nov 2006 23:17:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:522753</guid><dc:creator>mhass</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.technet.com/mhass/comments/522753.aspx</comments><wfw:commentRss>http://blogs.technet.com/mhass/commentrss.aspx?PostID=522753</wfw:commentRss><wfw:comment>http://blogs.technet.com/mhass/rsscomments.aspx?PostID=522753</wfw:comment><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;If you have read some of my previous posts around Vista, you know that it was one of few Microsoft products during this “wave” of products that I wasn’t getting excited about.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;In fact, I had so many issues with B2-&amp;gt;RC1 builds that I stopped using it on my tablet back in September.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;Well, I loaded RTM of Business on my tablet the day it RTM’d and it has been surprisingly pleasant.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Why didn’t I load Ultimate?&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I wanted to experience&amp;nbsp;corporate user experience, I loaded Ultimate on my MCE at home (Ultimate is fantastic BTW, but is starting to tax my old desktop machine).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;After some initial struggles with Toshiba drivers (Toshiba pulled their drivers from Windows Update to fix a couple things, should be posted again this week), I have been really happy. &lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;Here are some of the tips and highlights and lowlights after one week of real usage:&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpFirst style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri size=3&gt;Install Vista, once complete go to Windows Update and get all new drivers/software.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;3&lt;SUP&gt;rd&lt;/SUP&gt; parties as well as Microsoft will be providing more and more drivers and software through Windows Update this time.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri size=3&gt;I was able to join my computer to the domain over a VPN connection and get all required certs (IPSec, Smart card, etc).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This was a huge problem with pre-RTM builds&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri size=3&gt;I never had to make my user account a local administrator (and still isn’t).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This is huge for security guys out there.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri size=3&gt;I like the Gadgets, specifically the weather, time and performance Gadgets.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri size=3&gt;Performance has been outstanding&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri size=3&gt;The new display drivers accurately detect if I am using a second monitor now (neither Toshiba&amp;nbsp;or Nvidia drivers ever did this correctly in Windows XP)&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri size=3&gt;Search is fantastic, all items on my HDD as well as Outlook are indexed and immediately available&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri size=3&gt;BIGGEST HIGHLIGHT:&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Life goes on.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;No major problems, but also no major revolutions.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I can still find everything I need.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri size=3&gt;BAD:&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I don’t like the implementation of the network GUI’s.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;It seems that to enable my wireless connection I have 2 more menus to navigate.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This is great for new Windows users, but who really is a new Windows user these days.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I am sure there is a better way to shortcut me to what I want, but I haven’t found it yet.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri size=3&gt;BAD: When prompted for administrator credentials, I use the local administrator.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Vista never helps me select that user like it did in pre-RTM builds.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;It assumes that I want to use domain user credentials or smart card.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Which means that I have to type in a long machinename\localadmin credential.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Security good, having to remember my machine name bad.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpLast style="MARGIN: 0in 0in 10pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri size=3&gt;REALLY BAD: Can’t figure out how to defrag a specific drive.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;It only has a “Defrag Now” button which won’t let you select a drive and doesn’t give you “percentage complete” feedback.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I use a lot of external USB/Firewire drives and can’t wait for it to defrag on its own.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;As I play with Vista more, and find shortcuts for some of my frustrations, I plan on posting them here as usability nuggets.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;If you find solutions or frustrations, please feel free to comment on them.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;&lt;STRONG&gt;Update:&lt;/STRONG&gt;&amp;nbsp; Thanks to Tom Beerley for pointing out that the core defrag is still \windows\system32\defrag.exe which supports command line.&amp;nbsp; Just make sure you run the command line as administrator.&amp;nbsp; Below are the command line switches.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;&lt;EM&gt;V:\Windows\system32&amp;gt;defrag&lt;BR&gt;Windows Disk Defragmenter&lt;BR&gt;Copyright (c) 2006 Microsoft Corp.&lt;BR&gt;Description:&amp;nbsp; Locates and consolidates fragmented files on local volumes to&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; improve system performance.&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;&lt;EM&gt;Syntax:&amp;nbsp; defrag &amp;lt;volume&amp;gt; -a [-v]&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; defrag &amp;lt;volume&amp;gt; [{-r | -w}] [-f] [-v]&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; defrag&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -c [{-r | -w}] [-f] [-v]&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;&lt;EM&gt;Parameters:&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;&lt;EM&gt;Value&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Description&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;&lt;EM&gt;&amp;lt;volume&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Specifies the drive letter or mount point path of the volume to&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; be defragmented or analyzed.&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;&lt;EM&gt;-c&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Defragments all volumes on this computer.&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;&lt;EM&gt;-a&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Performs fragmentation analysis only.&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;&lt;EM&gt;-r&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Performs partial defragmentation (default). Attempts to&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; consolidate only fragments smaller than 64 megabytes (MB).&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;&lt;EM&gt;-w&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Performs full defragmentation. Attempts to consolidate all file&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; fragments, regardless of their size.&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;&lt;EM&gt;-f&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Forces defragmentation of the volume when free space is low.&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;&lt;EM&gt;-v&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Specifies verbose mode. The defragmentation and analysis output&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; is more detailed.&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;&lt;EM&gt;-?&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Displays this help information.&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;&lt;EM&gt;Examples:&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;&lt;EM&gt;defrag d:&lt;BR&gt;defrag d:\vol\mountpoint -w -f&lt;BR&gt;defrag d: -a -v&lt;BR&gt;defrag -c -v&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;&lt;EM&gt;&lt;/EM&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=522753" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mhass/archive/tags/All+Posts+Mhass/default.aspx">All Posts Mhass</category><category domain="http://blogs.technet.com/mhass/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.technet.com/mhass/archive/tags/Windows/default.aspx">Windows</category></item><item><title>Why I need Office 2007</title><link>http://blogs.technet.com/mhass/archive/2006/07/13/441657.aspx</link><pubDate>Fri, 14 Jul 2006 00:53:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:441657</guid><dc:creator>mhass</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.technet.com/mhass/comments/441657.aspx</comments><wfw:commentRss>http://blogs.technet.com/mhass/commentrss.aspx?PostID=441657</wfw:commentRss><wfw:comment>http://blogs.technet.com/mhass/rsscomments.aspx?PostID=441657</wfw:comment><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri&gt;I am back to running XP because Vista 5456 just didn’t like my wireless device in my laptop and kept toggling to connection on and off.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;But, I can’t seem to live without Office 2007.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri&gt;I like the ribbon, and quickly adjusted to it.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I really like the contextual stuff like when you have highlighted text and want to change the font or size, it “previews” it by actually changing the text as you hover above the font or size buttons.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;But there are 2 killer features for me.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpFirst style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT face=Calibri&gt;1)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;RSS Aggregator in Outlook 2007.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Most of you are reading this through some type of aggregator such as &lt;/FONT&gt;&lt;A href="http://www.sharpreader.com/"&gt;&lt;FONT face=Calibri&gt;SharpReader&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Calibri&gt; or &lt;/FONT&gt;&lt;A href="http://www.live.com/"&gt;&lt;FONT face=Calibri&gt;Windows Live&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Calibri&gt;.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Outlook has an aggregator that behaves just like reading email, it does read/unread and preview pane.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;It also lets you import and export your feeds via OPML.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;About the only thing I seem to be missing with the built in aggregator is a way to force it to go out and grab my feeds, it seems to have a mysterious timer that can’t be forced into submission.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Below is a picture of feeds in Outlook 2007&lt;/FONT&gt;&lt;PP&gt;&lt;IMG style="WIDTH: 373px; HEIGHT: 250px" height=150 src="http://blogs.technet.com/photos/mhass/images/441551/425x319.aspx" width=300 border=0&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpLast style="MARGIN: 0in 0in 10pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT face=Calibri&gt;2)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;Publish to Blog (also document management server, SharePoint) in Word 2007.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I can write this post in Word with nice spell checkers and all it’s glory, and then click Publish to Blog and presto. &lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri&gt;Like I said before, I am way more excited about Office than I am about Vista.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Sure there are great features in Vista, but so far they haven’t helped me be nearly as productive as the changes in Office.&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=441657" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mhass/archive/tags/All+Posts+Mhass/default.aspx">All Posts Mhass</category><category domain="http://blogs.technet.com/mhass/archive/tags/Windows/default.aspx">Windows</category></item><item><title>Windows 2000 to XP Upgrade Nuances</title><link>http://blogs.technet.com/mhass/archive/2006/04/24/426164.aspx</link><pubDate>Mon, 24 Apr 2006 19:20:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:426164</guid><dc:creator>mhass</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/mhass/comments/426164.aspx</comments><wfw:commentRss>http://blogs.technet.com/mhass/commentrss.aspx?PostID=426164</wfw:commentRss><wfw:comment>http://blogs.technet.com/mhass/rsscomments.aspx?PostID=426164</wfw:comment><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;In the process of helping a customer upgrade their remaining 5,000 desktops from Windows 2000 to XP, I have found a couple entertaining and frustrating issues with the upgrade process.&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;First of all, this only applies to an unattended upgrade of Windows 2000 Professional but it might also affect servers as our internal bugs indicate.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Second, Microsoft does not recommend that corporate desktop us the Upgrade process, &lt;A href="http://www.microsoft.com/technet/prodtechnol/winxppro/deploy/upwpload.mspx"&gt;rather we recommend “wipe and load”&lt;/A&gt;.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;But, in a customer scenario where you don’t have applications packaged and easily deployable to 5,000 users, upgrades are the way to go.&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;In our specific scenario, we are using various Dell desktops and laptops.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Through testing, we discovered that two of the desktop models completely loose their NIC’s during the upgrade.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;So, we tried to upgrade the drivers for the NIC’s before the upgrade.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;No dice, once the OS is Windows XP the system has an error with the Network Adapter in Device Manager.&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;We then tried to use the Microsoft provided means to upgrade the drivers during Windows Installation in the unattended file (below).&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Comic Sans MS'; mso-bidi-font-family: 'Comic Sans MS'"&gt;[Unattended]&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Comic Sans MS'; mso-bidi-font-family: 'Comic Sans MS'"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Oempreinstall=yes&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Comic Sans MS'; mso-bidi-font-family: 'Comic Sans MS'"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;OEMSkipWelcome=yes&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Comic Sans MS'; mso-bidi-font-family: 'Comic Sans MS'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;This tells setup to look in the SourceFiles\i386\$oem$\ folder for drivers and copy them over during the install process.&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Comic Sans MS'; mso-bidi-font-family: 'Comic Sans MS'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;The only problem is that we are using the UPGRADE flag in the unattended file that negates much of the settings.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;When you set &lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Comic Sans MS'; mso-bidi-font-family: 'Comic Sans MS'"&gt;NTUpgrade=Yes&lt;/SPAN&gt;&lt;/I&gt;, Windows ignores most of the Unattend file.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;In fact, Microsoft officially only supports and tests the following flags when &lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Comic Sans MS'; mso-bidi-font-family: 'Comic Sans MS'"&gt;NTUpgrade=Yes&lt;/SPAN&gt;&lt;/I&gt;:&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Comic Sans MS'; mso-bidi-font-family: 'Comic Sans MS'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Comic Sans MS'; mso-bidi-font-family: 'Comic Sans MS'"&gt;Productkey =&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Comic Sans MS'; mso-bidi-font-family: 'Comic Sans MS'"&gt;AutoActivate =&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Comic Sans MS'; mso-bidi-font-family: 'Comic Sans MS'"&gt;DuDisable =&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Comic Sans MS'; mso-bidi-font-family: 'Comic Sans MS'"&gt;DuShare=&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Comic Sans MS'; mso-bidi-font-family: 'Comic Sans MS'"&gt;DuStopOnError=&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;This means that we can’t use any of the cool $oem$ functionality like upgrading the drivers or even running the $oem$\cmdlines.txt which would allow us to kick off a script before Windows logs in.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The idea being that we could upgrade the drivers with a batch file before the user logs in.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;What a nightmare!&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;I did find that although Microsoft doesn’t support the entries, there are more settings that the unattended process will honor, these include:&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Comic Sans MS'; mso-bidi-font-family: 'Comic Sans MS'"&gt;[GuiRunOnce]&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Comic Sans MS'; mso-bidi-font-family: 'Comic Sans MS'"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;Command0="C:\upgrade\apf\CmdLines.cmd"&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Comic Sans MS'; mso-bidi-font-family: 'Comic Sans MS'"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;Command1="C:\upgrade\apf\PostOS.cmd 1"&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Comic Sans MS'; mso-bidi-font-family: 'Comic Sans MS'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Comic Sans MS'; mso-bidi-font-family: 'Comic Sans MS'"&gt;[WindowsFirewall]&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Comic Sans MS'; mso-bidi-font-family: 'Comic Sans MS'"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;Profiles=WindowsFirewall.TurnOffFirewall&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Comic Sans MS'; mso-bidi-font-family: 'Comic Sans MS'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Comic Sans MS'; mso-bidi-font-family: 'Comic Sans MS'"&gt;[WindowsFirewall.TurnOffFirewall]&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-layout-grid-align: none"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Comic Sans MS'; mso-bidi-font-family: 'Comic Sans MS'"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;Mode=0&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;So, how did I get around these challenges?&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I did a bunch of scripting before the upgrade and after the upgrade.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Basically, here are the steps:&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;SPAN style="mso-list: Ignore"&gt;1)&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Download all the Windows XP source files and drivers to the workstation hard drive&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;SPAN style="mso-list: Ignore"&gt;2)&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Run a script that prepares the box for an upgrade&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 1in; TEXT-INDENT: -0.25in; mso-list: l0 level2 lfo1; tab-stops: list 1.0in"&gt;&lt;SPAN style="mso-list: Ignore"&gt;a.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Disable Wired/Wireless NICS (see my blog on &lt;A href="/mhass/archive/2006/04/07/424699.aspx"&gt;devcon on how to automate this&lt;/A&gt;)&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 1in; TEXT-INDENT: -0.25in; mso-list: l0 level2 lfo1; tab-stops: list 1.0in"&gt;&lt;SPAN style="mso-list: Ignore"&gt;b.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Removes LegalNoticeText to ensure AutoAdmin logons&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 1in; TEXT-INDENT: -0.25in; mso-list: l0 level2 lfo1; tab-stops: list 1.0in"&gt;&lt;SPAN style="mso-list: Ignore"&gt;c.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Resets Local administrator password&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 1in; TEXT-INDENT: -0.25in; mso-list: l0 level2 lfo1; tab-stops: list 1.0in"&gt;&lt;SPAN style="mso-list: Ignore"&gt;d.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Sets AutoAdmin logon settings&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;SPAN style="mso-list: Ignore"&gt;3)&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Starts Windows Unattended Setup and uses local source files&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;SPAN style="mso-list: Ignore"&gt;4)&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;After the OS is upgraded, it does a GUIRunOnce that I specified&lt;BR&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Comic Sans MS'; mso-bidi-font-family: 'Comic Sans MS'"&gt;Command0="C:\upgrade\apf\CmdLines.cmd"&lt;/SPAN&gt;&lt;/I&gt;&lt;BR&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Comic Sans MS'; mso-bidi-font-family: 'Comic Sans MS'"&gt;Command1="C:\upgrade\apf\PostOS.cmd 1"&lt;/SPAN&gt;&lt;/I&gt;&lt;BR&gt;This kicks off a PostOS scripting engine call APF (automated purposing framework) that can be found as part of &lt;A href="http://www.microsoft.com/windowsserver2003/datacenter/default.mspx"&gt;MSA 2.0&lt;/A&gt;.&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;SPAN style="mso-list: Ignore"&gt;5)&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;The APF engine does the following&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 1in; TEXT-INDENT: -0.25in; mso-list: l0 level2 lfo1; tab-stops: list 1.0in"&gt;&lt;SPAN style="mso-list: Ignore"&gt;a.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Phase 1 – HotFixes&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 1in; TEXT-INDENT: -0.25in; mso-list: l0 level2 lfo1; tab-stops: list 1.0in"&gt;&lt;SPAN style="mso-list: Ignore"&gt;b.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Phase 2 – Dell Drivers&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 1in; TEXT-INDENT: -0.25in; mso-list: l0 level2 lfo1; tab-stops: list 1.0in"&gt;&lt;SPAN style="mso-list: Ignore"&gt;c.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Phase 3 – Enable Dell NICS&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 1in; TEXT-INDENT: -0.25in; mso-list: l0 level2 lfo1; tab-stops: list 1.0in"&gt;&lt;SPAN style="mso-list: Ignore"&gt;d.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Phase 4 – Update GPO’s&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 1in; TEXT-INDENT: -0.25in; mso-list: l0 level2 lfo1; tab-stops: list 1.0in"&gt;&lt;SPAN style="mso-list: Ignore"&gt;e.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Phase 5 – Finish&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 1.5in; TEXT-INDENT: -1.5in; mso-list: l0 level3 lfo1; tab-stops: list 1.5in; mso-text-indent-alt: -9.0pt"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;i.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Set RunOnce (sets user profile settings)&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 1.5in; TEXT-INDENT: -1.5in; mso-list: l0 level3 lfo1; tab-stops: list 1.5in; mso-text-indent-alt: -9.0pt"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;ii.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Copies “Default User” profile&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 1.5in; TEXT-INDENT: -1.5in; mso-list: l0 level3 lfo1; tab-stops: list 1.5in; mso-text-indent-alt: -9.0pt"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;iii.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Clears AutoAdminLogon Settings&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 1.5in; TEXT-INDENT: -1.5in; mso-list: l0 level3 lfo1; tab-stops: list 1.5in; mso-text-indent-alt: -9.0pt"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;iv.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Deletes Source bits&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 1in; TEXT-INDENT: -0.25in; mso-list: l0 level2 lfo1; tab-stops: list 1.0in"&gt;&lt;SPAN style="mso-list: Ignore"&gt;f.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Phase 6 – Reboot&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;SPAN style="mso-list: Ignore"&gt;6)&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Once a user logs in for the first time, we fire the RunOnce script that sets some corporate standard user experience settings&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.25in"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.25in"&gt;I guess the overall advice I can lay down for upgrades are, “This isn’t as easy as running winnt32.exe and then upgrading drivers”.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This can be a very complex process to get right, especially when you want to do it for thousands of machines.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Wipe and load is still the preferred mechanism, and there is good justification for getting your application packaging strategy working first before you tackle upgrading OS’s,&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=426164" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mhass/archive/tags/All+Posts+Mhass/default.aspx">All Posts Mhass</category><category domain="http://blogs.technet.com/mhass/archive/tags/Desktop/default.aspx">Desktop</category><category domain="http://blogs.technet.com/mhass/archive/tags/Windows/default.aspx">Windows</category></item><item><title>Updating drivers from the command line</title><link>http://blogs.technet.com/mhass/archive/2006/04/07/424699.aspx</link><pubDate>Sat, 08 Apr 2006 07:53:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:424699</guid><dc:creator>mhass</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.technet.com/mhass/comments/424699.aspx</comments><wfw:commentRss>http://blogs.technet.com/mhass/commentrss.aspx?PostID=424699</wfw:commentRss><wfw:comment>http://blogs.technet.com/mhass/rsscomments.aspx?PostID=424699</wfw:comment><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;So, I am off doing a desktop migration for a customer of approximately 5,000 desktops.&amp;nbsp; &lt;?xml:namespace prefix = st1 ns = "urn:schemas-microsoft-com:office:smarttags" /&gt;&lt;st1:place w:st="on"&gt;Vista&lt;/st1:place&gt; you ask?&amp;nbsp; No, not that sexy.&amp;nbsp; Just trying to help one of our core telco customers get everyone off Windows 2000 onto XP.&amp;nbsp; And by the way, get in infrastructure in place like &lt;A href="http://www.microsoft.com/technet/desktopdeployment/default.mspx"&gt;BDD&lt;/A&gt; using &lt;A href="http://www.microsoft.com/technet/desktopdeployment/depprocess/osddlex.mspx"&gt;OSD&lt;/A&gt; with &lt;A href="http://www.microsoft.com/smserver/default.mspx"&gt;SMS&lt;/A&gt; (it's cool to say all those acronyms really quickly) so they can be ready for &lt;st1:place w:st="on"&gt;Vista&lt;/st1:place&gt; someday.&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;Unfortunately there are forces at work that will not allow us to do wipe-and-loads of desktops, like Microsoft recommends.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;So, me and Mike Vrabel from &lt;A href="http://www.ins.com/"&gt;INS&lt;/A&gt; are having to work through an OS upgrade scenario.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This causes us to upgrade a few corporate applications before we can upgrade the OS, because they just won’t work after the upgrade.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Mike is primarily of storming the beach head of application remediation, while I work on unattend files and drivers.&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;I ran into some serious issues trying to upgrade drivers so that the NIC, Sound and Display would still work after an upgrade.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Here were my approaches:&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;OL style="MARGIN-TOP: 0in" type=1&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;Upgrade Drivers while still in Windows 2000 to the XP version. Since most drivers are compatible, this should work.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;WRONG – the closest I got was the “Windows has found new hardware” once the box was upgraded to XP.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Since this needs to be completely scripted, this isn’t an option&lt;/LI&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;Use the Windows Unattend file to specify new drivers.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I have used unattend files a million times before when building out big datacenters, so I have a really high level of confidence when it comes to unattend files.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;But, the upgrade scenario is different than a bare metal install or sysprep.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;It appears that Windows doesn’t care about the drivers I specify in the Unattend, and won’t even copy the ones I place in the \i386\$oem$\$1\drivers\yadayada folders.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;From what I can tell, these drivers are only copied during text mode (which does not occur in an upgrade), and it never looks in the unattend file for the drivers during an upgrade.&lt;/LI&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;Upgrade the drivers once the upgrade is done.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Ya, but how do you do it from the command line without user interaction?&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Well, &lt;A href="http://msdn.microsoft.com/library/default.asp?url=/library/en-us/DevTest_g/hh/DevTest_g/DevCon_744d640a-c44e-4cb9-a68f-60ce341d1c74.xml.asp"&gt;DEVCON&lt;/A&gt; is your friend.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Devcon.exe is a command line version of Device Manager, and the latest version is included in the &lt;A href="http://www.microsoft.com/downloads/details.aspx?familyid=6ec50b78-8be1-4e81-b3be-4e7ac4f0912d&amp;amp;displaylang=en"&gt;Windows Server 2003 Service Pack 1 Support Tools&lt;/A&gt;.&lt;/LI&gt;&lt;/OL&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;The thing I learned about devcon, thanks to Scott McArthur from Microsoft Support, is that when you specify a device to update, use the “base” id.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;If you run:&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;Devcon driverdetails * &amp;gt; drivers.txt&lt;o:p&gt;&lt;/o:p&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;You will get a list of all devices with their associate drivers.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The devices are very specific like:&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.5in"&gt;PCI\VEN_8086&amp;amp;DEV_100E&amp;amp;SUBSYS_01511028&amp;amp;REV_02\4&amp;amp;1C660DD6&amp;amp;0&amp;amp;60F0&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;There are other devices associated with this device, so if you try and update the specific device, it usually comes back with a “devcon failed”.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;You need to broaden the device path, and take the “base” device like this:&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.5in"&gt;PCI\VEN_8086&amp;amp;DEV_100E&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;So the command that I end up running to update the drivers:&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;devcon updateni "C:\DRIVERS\Intel10.3\PRO1000\WS03XP2K\e1000325.inf" PCI\VEN_8086&amp;amp;DEV_100E&lt;o:p&gt;&lt;/o:p&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;So hopefully this great little devcon tool will help you out, and make sure to be generic when specifying device drivers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=424699" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mhass/archive/tags/All+Posts+Mhass/default.aspx">All Posts Mhass</category><category domain="http://blogs.technet.com/mhass/archive/tags/Desktop/default.aspx">Desktop</category><category domain="http://blogs.technet.com/mhass/archive/tags/Windows/default.aspx">Windows</category></item><item><title>Changes to SharePoint 2003 Installs</title><link>http://blogs.technet.com/mhass/archive/2006/01/25/418103.aspx</link><pubDate>Thu, 26 Jan 2006 00:54:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:418103</guid><dc:creator>mhass</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/mhass/comments/418103.aspx</comments><wfw:commentRss>http://blogs.technet.com/mhass/commentrss.aspx?PostID=418103</wfw:commentRss><wfw:comment>http://blogs.technet.com/mhass/rsscomments.aspx?PostID=418103</wfw:comment><description>&lt;FONT face=Arial size=2&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face="Times New Roman" size=3&gt;I recently worked on another SharePoint project where we did unusual things with SharePoint.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;But, this time we actually used some of the core SPS functionality like search to index about 5,000 documents for a call center.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face="Times New Roman" size=3&gt;We built out Production last week and were doing some testing and discovered that search was broken.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;We could see in the Search Settings page that we were getting an error: “&lt;/FONT&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;An error occurred attempting to connect to the index server”.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face="Times New Roman" size=3&gt;What made this even stranger was that I had just done a full SPS Restore, including the index, which meant the topology was correct and communicating well.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face="Times New Roman" size=3&gt;Turns out that after Windows Service Pack 1, security changed and there are new requirements for the service account used for Application Pools.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Here are the two changes:&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;1)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;The SPS service administrator account was not added in the admin group on the servers in farm.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Originally, the SPS documentation stated this user needed to be a local “Power User”.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This is documented in &lt;/FONT&gt;&lt;/FONT&gt;&lt;A title=http://support.microsoft.com/kb/555309/en-us href="http://support.microsoft.com/kb/555309/en-us"&gt;&lt;FONT face="Times New Roman" size=3&gt;Q555309&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face="Times New Roman" size=3&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;2)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;The SPS website application pool account was not added to the DCOM users group on all the servers in farm.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Apparently this is not documented in a Q article (not sure why), but this is required for search.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face="Times New Roman" size=3&gt;Lastly, our search is still broken because I specified the name of the web site: &lt;/FONT&gt;&lt;A href="https://myapp.mycorp.com/"&gt;&lt;FONT face="Times New Roman" size=3&gt;https://myapp.mycorp.com&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face="Times New Roman" size=3&gt;. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;We hadn’t generated the SSL cert yet, so when the crawler tried to index the site, it doesn’t exist.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face="Times New Roman" size=3&gt;These provided to you free of charge as a public service.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;8)&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=418103" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mhass/archive/tags/All+Posts+Mhass/default.aspx">All Posts Mhass</category><category domain="http://blogs.technet.com/mhass/archive/tags/SharePoint/default.aspx">SharePoint</category><category domain="http://blogs.technet.com/mhass/archive/tags/Windows/default.aspx">Windows</category></item><item><title>Watch out for sober attack on Jan 6, 2006</title><link>http://blogs.technet.com/mhass/archive/2006/01/05/416975.aspx</link><pubDate>Thu, 05 Jan 2006 22:04:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:416975</guid><dc:creator>mhass</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/mhass/comments/416975.aspx</comments><wfw:commentRss>http://blogs.technet.com/mhass/commentrss.aspx?PostID=416975</wfw:commentRss><wfw:comment>http://blogs.technet.com/mhass/rsscomments.aspx?PostID=416975</wfw:comment><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;a href="http://blogs.technet.com/cdnitmanagers/archive/2006/01/05/416941.aspx"&gt;Stephen shares information&lt;/A&gt; about a virus attack timed for Jan 6, 2006&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=416975" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mhass/archive/tags/All+Posts+Mhass/default.aspx">All Posts Mhass</category><category domain="http://blogs.technet.com/mhass/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.technet.com/mhass/archive/tags/Windows/default.aspx">Windows</category></item><item><title>Get a third admin RDP session for FREE!!</title><link>http://blogs.technet.com/mhass/archive/2005/11/03/413605.aspx</link><pubDate>Thu, 03 Nov 2005 21:16:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:413605</guid><dc:creator>mhass</dc:creator><slash:comments>6</slash:comments><comments>http://blogs.technet.com/mhass/comments/413605.aspx</comments><wfw:commentRss>http://blogs.technet.com/mhass/commentrss.aspx?PostID=413605</wfw:commentRss><wfw:comment>http://blogs.technet.com/mhass/rsscomments.aspx?PostID=413605</wfw:comment><description>&lt;P&gt;Many administrators have missed that there is a "hidden" third connection that can be made to Windows Server 2003 servers.&amp;nbsp; I often work with system administrators that are swearing in their cubes because the two admin connections are used up and they can't connect.&amp;nbsp; I ask them why they don't just connect to the console session and boot them?&amp;nbsp; Console session?&amp;nbsp; Huh?&lt;/P&gt;
&lt;P&gt;It's pretty easy, and I actually modify my RDP shortcuts to always connect to the console session so that I never conflict with anyone.&amp;nbsp; Here's how it works:&lt;/P&gt;
&lt;P&gt;MSTSC /v:&amp;lt;name or IP of the server&amp;gt; /console&lt;/P&gt;
&lt;P&gt;This basically uses session 0 or the console session.&amp;nbsp; So, if someone is standing in fron of the monitor connected to the server, it will say locked as you work away (much like Remote Desktop in Windows XP).&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=413605" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mhass/archive/tags/All+Posts+Mhass/default.aspx">All Posts Mhass</category><category domain="http://blogs.technet.com/mhass/archive/tags/Windows/default.aspx">Windows</category></item><item><title>Small Business Server 2003 Upgrade from Hell</title><link>http://blogs.technet.com/mhass/archive/2005/11/02/413546.aspx</link><pubDate>Thu, 03 Nov 2005 06:32:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:413546</guid><dc:creator>mhass</dc:creator><slash:comments>8</slash:comments><comments>http://blogs.technet.com/mhass/comments/413546.aspx</comments><wfw:commentRss>http://blogs.technet.com/mhass/commentrss.aspx?PostID=413546</wfw:commentRss><wfw:comment>http://blogs.technet.com/mhass/rsscomments.aspx?PostID=413546</wfw:comment><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;Last week, I decided to take a few vacation days and fly out to Ogden, Utah to help my wife’s old company upgrade from Small Business Server (SBS) 2000 to SBS 2003.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;They are a small, 10 person operation that manufactures high end ski and board apparel (&lt;A href="http://www.descente.net/"&gt;www.descente.net&lt;/A&gt; or &lt;A href="http://www.ridedna.com/"&gt;www.ridedna.com&lt;/A&gt;). &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;The have a main office in downtown &lt;?xml:namespace prefix = st1 ns = "urn:schemas-microsoft-com:office:smarttags" /&gt;&lt;st1:City w:st="on"&gt;Ogden&lt;/st1:City&gt;, a warehouse about 5 blocks away and a Canadian office in &lt;st1:City w:st="on"&gt;&lt;st1:place w:st="on"&gt;Vancouver&lt;/st1:place&gt;&lt;/st1:City&gt;.&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;The primary reason for the upgrade is that the president now resides in &lt;st1:country-region w:st="on"&gt;Canada&lt;/st1:country-region&gt;, and his mailbox is back in &lt;st1:City w:st="on"&gt;&lt;st1:place w:st="on"&gt;Ogden&lt;/st1:place&gt;&lt;/st1:City&gt;.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;OWA is great, but it times out and the Exchange 2000 version was not the best and fastest interface.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;So, RPC/HTTP aka Outlook over the Internet is the perfect solution!&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;BTW, his laptop runs Windows XP Japanese as well as Office 2000/Outlook 2003 Japanese but when I sit down it almost looks like I can read Japanese because I have almost everything memorized, I was often asked by other employees if I spoke Japanese.&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;Anyway, SBS has always meant in my mind “super tight integration of Microsoft Infrastructure products and a super easy GUI for non-computer type people to manage their business”.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Of course another way of saying this is “I am going to hate using the SBS tools, please god give me normal MMC consoles”.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I also thought, “what a simple upgrade this is going to be, should I fly out or can I do it over VPN if someone sites there on the phone with me”.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Flying turned out to be a godsend.&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;First of all, support calls for Microsoft employees are not free.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;We either have to pay, or we get 3 Quick Assist calls that we can give to people.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;These are mainly meant to give to the guys that stop you and say, “Hey you work for Microsoft?&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I have Windows 98’ and I can’t print to this HP LaserJet II, can you help?”&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;In this case, I needed all three Quick Assists and didn’t have any with me so I bummed a couple from coworkers.&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;Here are the highlights:&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;Support Call 1:&lt;o:p&gt;&lt;/o:p&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;SBS upgrade halted, keeps insisting that “All domain controllers could not be contacted”.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;Some braniac when the system was first installed decided to implement a second DC on some old hardware.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The hardware failed shortly after installation and AD was never cleaned up.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;I made sure that all the roles were seized by their primary DC (they were).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;And I tried to delete the DC out of the domain, no luck.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I used NTDSUTIL, ADSI Edit, DNS srv records, everything was gone, but it still insisted that “All domain controllers could not be contacted”.&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;Support ended up finding a way around this little check in the upgrade process and we were able to continue with the upgrade.&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;Support Call 2:&lt;o:p&gt;&lt;/o:p&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;ISA 2004 is included in on the Technologies disk of SBS 2004 Premium Edition.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;They don’t’ advertise that, but I feel it is critical because&amp;nbsp;the ISA&amp;nbsp;2004 GUI is worlds better than ISA 2000/Proxy Server 2.0.&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;During the install, ISA would bomb out with a .Net runtime error.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;It appeared that ISA completed installing itself and the MSDE for ISA, but it never installed the rules for SBS.&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;Turns out that the SBS wrapper around ISA 2004 forces it to utilize some of the SBS Admin tools that get installed.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The Admin tools were never installed during the upgrade, and I never unselected them.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;To me, there must be a bug in the upgrade process or they purposely defaulted them not to be installed.&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;After installing SBS admin tools, I reran ISA setup and it went through fine.&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;Support Call 3:&lt;o:p&gt;&lt;/o:p&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;After a long debate with SSL certs because for some reason their old SSL cert didn’t correctly move over to the Windows 2003 certificate store, I had to have the cert authority reissue it.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;After reissue, I imported it into both IIS and used it for the web listener in ISA.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;It is a cert from &lt;A href="http://www.xramp.com/"&gt;www.xramp.com&lt;/A&gt; that has a public cert authority at very reasonable prices.&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;After OWA, OMA, and EAS were working, I decided to tackle RPC/HTTP for the president and their warehouse.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;By this time, I had flown back home and I built a Windows XP Virtual Server image and joined it to their domain to test RPC/HTTP.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I VPN’d in from my Virtual Server image, joined the domain and got standard MAPI over TCP/IP working, cool!&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I disconnected the VPN, and setup the RPC/HTTP proxy settings on the client, and I new that the Outlook settings were correct and the certs were good, but it wouldn’t connect.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;It kept prompting me for login credentials.&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;Support traced the problem to the “Proxy Authentication Settings” being set to NTLM Authentication, for SBS apparently it must use Basic Authentication.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The support tech also claimed that you can’t hit the “Check Name” button when you use RPC/HTTP, which I knew for a fact not to be an issue when you initially create the profile with TCP/IP.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I tested this, and there isn’t an issue if you create a profile when you have the full MAPI TCP/IP connection, and later add RPC/HTTP.&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;Summary:&lt;o:p&gt;&lt;/o:p&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;I am disappointed that this wasn’t as smooth as an update as I expected.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Again, SBS is targeted at business of 100 or less people that probably don’t have a full time IT person, or have access to $295 per incident support from Microsoft.&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;In dealing with the SBS products, there seems to be a GUI that has simplified administrative tasks, but the underlying technology seems to still be hobbled together.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Many of the products are wrapped or functionality is hidden/taken away, and don’t appear to be engineered from the beginning to work together on a single server.&amp;nbsp; &lt;STRONG&gt;Overall, I highly recommend SBS 2003 especially since the premium edition includes ISA 2004&lt;/STRONG&gt;.&amp;nbsp; But, I think that we need to have the SBS teams sit in early on Windows, Exchange/Office, ISA, and SQL engineering design sessions and architect those products to operate better together on a single box to give SBS the reliability and ease of updates it deserves.&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=413546" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mhass/archive/tags/Operations/default.aspx">Operations</category><category domain="http://blogs.technet.com/mhass/archive/tags/All+Posts+Mhass/default.aspx">All Posts Mhass</category><category domain="http://blogs.technet.com/mhass/archive/tags/SharePoint/default.aspx">SharePoint</category><category domain="http://blogs.technet.com/mhass/archive/tags/Virtual+PC_2F00_Server/default.aspx">Virtual PC/Server</category><category domain="http://blogs.technet.com/mhass/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.technet.com/mhass/archive/tags/Exchange/default.aspx">Exchange</category><category domain="http://blogs.technet.com/mhass/archive/tags/Windows/default.aspx">Windows</category><category domain="http://blogs.technet.com/mhass/archive/tags/SQL/default.aspx">SQL</category></item><item><title>Microsoft Support from India</title><link>http://blogs.technet.com/mhass/archive/2005/10/27/413189.aspx</link><pubDate>Fri, 28 Oct 2005 04:41:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:413189</guid><dc:creator>mhass</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.technet.com/mhass/comments/413189.aspx</comments><wfw:commentRss>http://blogs.technet.com/mhass/commentrss.aspx?PostID=413189</wfw:commentRss><wfw:comment>http://blogs.technet.com/mhass/rsscomments.aspx?PostID=413189</wfw:comment><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;I admit it, I am not the all-knowing Microsoft consultant I should be.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The real truth is, our support folks have the best tools to diagnose problems a lot faster than I can muddle through things.&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;I have had the occasion over the last few weeks to call Microsoft Support (PSS) several times with issues around SQL, AD, SharePoint and Small Business Server.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Every single time, I was routed to someone in &lt;?xml:namespace prefix = st1 ns = "urn:schemas-microsoft-com:office:smarttags" /&gt;&lt;st1:country-region w:st="on"&gt;&lt;st1:place w:st="on"&gt;India&lt;/st1:place&gt;&lt;/st1:country-region&gt;.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The support was phenomenal (as always), but what was more impressive was the language skills and how hip the support guys were on the other end of the phone, especially for being so far from the &lt;st1:place w:st="on"&gt;&lt;st1:country-region w:st="on"&gt;US&lt;/st1:country-region&gt;&lt;/st1:place&gt;.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I think my expectation was that I would still receive good support, but a bit of a language barrier as well as some bias to culture.&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;Next time you call in, I bet you won’t be able where the person is located that is helping you fix your issue.&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=413189" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mhass/archive/tags/Operations/default.aspx">Operations</category><category domain="http://blogs.technet.com/mhass/archive/tags/All+Posts+Mhass/default.aspx">All Posts Mhass</category><category domain="http://blogs.technet.com/mhass/archive/tags/SharePoint/default.aspx">SharePoint</category><category domain="http://blogs.technet.com/mhass/archive/tags/Exchange/default.aspx">Exchange</category><category domain="http://blogs.technet.com/mhass/archive/tags/Windows/default.aspx">Windows</category></item><item><title>LCS and UPN's</title><link>http://blogs.technet.com/mhass/archive/2005/10/18/412664.aspx</link><pubDate>Tue, 18 Oct 2005 17:03:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:412664</guid><dc:creator>mhass</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/mhass/comments/412664.aspx</comments><wfw:commentRss>http://blogs.technet.com/mhass/commentrss.aspx?PostID=412664</wfw:commentRss><wfw:comment>http://blogs.technet.com/mhass/rsscomments.aspx?PostID=412664</wfw:comment><description>&lt;P&gt;I was messing around with LCS last night here in my lab.&amp;nbsp; I had installed LCS a couple times and helped customers get up and running, but I am not an LCS expert.&amp;nbsp; I was trying to duplicate a customer issue where I wanted to limit how certain users could talk to and add to their various chat client.&amp;nbsp; Instead, I ran into an issue where I couldn't get any clients to sign in.&lt;/P&gt;
&lt;P&gt;After messing around with SRV records, "LCS enabling" users in AD, and making sure the service was starting, I still couldn't log in with ANY users.&amp;nbsp; I then started looking at what the SIP URI was defaulting to.&amp;nbsp; I discovered that it was defaulting to one of the valid UPN names that I have in my domain.&amp;nbsp; But, this wasn't the UPN for the domain the users were in.&lt;/P&gt;
&lt;P&gt;Example:&lt;/P&gt;
&lt;P&gt;Domain name extended for LCS:&amp;nbsp; contoso.com&lt;/P&gt;
&lt;P&gt;SIP URI:&amp;nbsp; &lt;A href="mailto:myuser@vanitydomain.com"&gt;myuser@vanitydomain.com&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Since the SIP URI doesn't match the domain extended for LCS, the user can't login.&amp;nbsp; After adjusting the LCS user properties for my users to reflect the the "real" domain name (&lt;A href="mailto:myuser@contoso.com"&gt;myuser@contoso.com&lt;/A&gt;) everything worked fine.&lt;/P&gt;
&lt;P&gt;I am not sure why any valid UPN wouldn't work since the users are still part of the domain, but I assume it is just how LCS validates users to allow them to use the server.&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=412664" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mhass/archive/tags/All+Posts+Mhass/default.aspx">All Posts Mhass</category><category domain="http://blogs.technet.com/mhass/archive/tags/IM_2F00_LCS/default.aspx">IM/LCS</category><category domain="http://blogs.technet.com/mhass/archive/tags/Windows/default.aspx">Windows</category></item><item><title>IPSEC: Member to DC isn’t supported, but…</title><link>http://blogs.technet.com/mhass/archive/2005/09/25/411525.aspx</link><pubDate>Sun, 25 Sep 2005 16:28:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:411525</guid><dc:creator>mhass</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/mhass/comments/411525.aspx</comments><wfw:commentRss>http://blogs.technet.com/mhass/commentrss.aspx?PostID=411525</wfw:commentRss><wfw:comment>http://blogs.technet.com/mhass/rsscomments.aspx?PostID=411525</wfw:comment><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;I stumbled across this issue a couple weeks ago, and &lt;a href="http://blogs.technet.com/steriley"&gt;Steve Riley&lt;/A&gt; clarified some of it for me.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;We have a really, really large project going with some new technology where securing the networks is a priority.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;We have run into the normal RPC challenges of limited port ranges because the firewall guys don’t want to open thousands of ports.&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;We also brought up the notion of running IPSec everywhere.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I guess I had never realized that member server to DC IPSec is not supported by Microsoft.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;It is because of an issue with Kerberos:&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;How can you use Kerberos to authenticate for IPsec if the computers haven't yet logged onto the domain?&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I never knew the official stance on this because I know customers that have implemented this with no problems.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I have heard that &lt;?xml:namespace prefix = st1 ns = "urn:schemas-microsoft-com:office:smarttags" /&gt;&lt;st1:place w:st="on"&gt;Vista&lt;/st1:place&gt; and the Longhorn Servers might have a fix for this so that it is officially supported, but just something to think about.&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;Don’t you just hate it when you have those circumstances that Microsoft doesn’t officially support something, but you know it works, and works well?&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;We run into it all the time, and either have to back off into what is supported or sign a custom support agreement with Premier support, which can be a politically charged event.&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;Oh, and Steve made a good suggestion of forcing RPC authentication since most RPC based attacks are anonymous.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Good suggestions, I believe this can be done rather easily with GPO, so we will take a look at it. &lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=411525" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mhass/archive/tags/All+Posts+Mhass/default.aspx">All Posts Mhass</category><category domain="http://blogs.technet.com/mhass/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.technet.com/mhass/archive/tags/Windows/default.aspx">Windows</category></item><item><title>Zotob, a hard and unfortunate lesson (again) for Enterprises</title><link>http://blogs.technet.com/mhass/archive/2005/08/17/409371.aspx</link><pubDate>Thu, 18 Aug 2005 01:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:409371</guid><dc:creator>mhass</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/mhass/comments/409371.aspx</comments><wfw:commentRss>http://blogs.technet.com/mhass/commentrss.aspx?PostID=409371</wfw:commentRss><wfw:comment>http://blogs.technet.com/mhass/rsscomments.aspx?PostID=409371</wfw:comment><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;Unless you have been on vacation on the moon for the last few days, you know that there is new exploit in the wild that mainly affect Windows 2000 and pre SP2 Windows XP OS’s called &lt;A href="http://www.microsoft.com/security/incident/zotob.mspx"&gt;Zotob (and variants).&lt;/A&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This worm is hitting some of the same big name companies that were crippled by CodeRed, Sasser and Blaster.&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;In the years since those nightmares, there have been a lot of great tools that have come out to help avoid these nightmares.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I can’t believe that some of the big enterprises (some of them are my customers) don’t have a better strategy or mandatory policy to update desktops and servers with security updates quickly.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Microsoft and others have been preaching for at least the last 3 years that it is only a matter of time for a 0 day exploit.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;While Zotob is not a zero day exploit, it is close.&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;Everyone knows about “patch Tuesday”, including malware authors.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;You absolutely have to have a patch strategy these days to push security updates immediately or within 24 hours.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This means 1000’s of boxes in some cases.&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;If you are an enterprise, don’t just stand there, get something!&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Windows/Microsoft &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;Update, SMS, SUS, WSUS, ONiPatch, Hercules, etc it doesn’t matter!!&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Some you pay for, some are free, but just do it.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I guarantee this isn’t the last time, and the next one might be even bigger.&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;I don’t want to get into a debate about how many security flaws Microsoft has over distributions of Linux or IIS vs Apache.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;You need a strategy for all of these systems.&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;If you have a single PC, home network with a couple computers or if you have an enterprise with 10,000 of pc/servers get a plan on how you get and apply updates.&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;BTW, don't get me started on the Media.&amp;nbsp; Every single time I watch the "tech" portion of our local news channels I want to call them up and make at least 3 corrections (most of the time non-Microsoft stuff).&amp;nbsp; They can't even get mobile phones right.&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;A great blog to subscribe to is the &lt;SPAN class=MsoHyperlink&gt;&lt;a href="http://blogs.technet.com/msrc/default.aspx"&gt;Microsoft Security Response Center Blog!.&lt;/A&gt;&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=409371" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mhass/archive/tags/Operations/default.aspx">Operations</category><category domain="http://blogs.technet.com/mhass/archive/tags/All+Posts+Mhass/default.aspx">All Posts Mhass</category><category domain="http://blogs.technet.com/mhass/archive/tags/Rants/default.aspx">Rants</category><category domain="http://blogs.technet.com/mhass/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.technet.com/mhass/archive/tags/Desktop/default.aspx">Desktop</category><category domain="http://blogs.technet.com/mhass/archive/tags/Windows/default.aspx">Windows</category></item></channel></rss>