<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearchrss/1.0/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0"><id>tag:blogger.com,1999:blog-7365513794075231499</id><updated>2012-05-24T11:06:25.043-07:00</updated><category term="quick-hitters" /><category term="virtualization" /><category term="Army Hooaahh" /><category term="Windows 8 Beta" /><category term="Hotfix" /><category term="Windows 8" /><category term="BlogRoll" /><category term="DNS" /><category term="FGPP" /><category term="Powershell" /><category term="Certification" /><category term="Mailbag" /><category term="vmware" /><category term="admod" /><category term="adfind" /><category term="GPP" /><category term="dcpromo" /><category term="MVP Award" /><category term="Security" /><category term="Group Policy" /><category term="Product Reviews" /><category term="Microsoft News" /><category term="ADAC" /><category term="permissions" /><category term="OU Awards" /><category term="GeekNetwork" /><category term="Active Directory" /><category term="AD Legends" /><category term="Miscellaneous" /><category term="New Features" /><category term="DSRM" /><category term="replication" /><category term="CodePlex" /><title type="text">My blog about Active Directory and everything else</title><subtitle type="html">...by Mike Kline</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://adisfun.blogspot.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://adisfun.blogspot.com/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default?start-index=26&amp;max-results=25" /><author><name>mkline</name><uri>http://www.blogger.com/profile/03770498033295580147</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>60</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/blogspot/jExLn" /><feedburner:info uri="blogspot/jexln" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:browserFriendly></feedburner:browserFriendly><entry><id>tag:blogger.com,1999:blog-7365513794075231499.post-6508551491388845990</id><published>2012-05-24T06:42:00.000-07:00</published><updated>2012-05-24T11:06:25.046-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="AD Legends" /><title type="text">Outstanding Cloud &amp; Identity Talk</title><content type="html">I generally don't post videos or&amp;nbsp;presentations as blog entries but this is one I haven't seen posted by a lot of folks and is a must watch for anyone in the Identity, Active Directory, Directory Services field.&lt;br /&gt;&lt;br /&gt;The main reason I love this talk is because the presenter. &amp;nbsp;Microsoft's &lt;a href="http://www.identityblog.com/?p=360"&gt;Kim Cameron &amp;nbsp;&lt;/a&gt;&amp;nbsp; &amp;nbsp;Kim is the Chief Architect of Identity in the Identity and Access Division at Microsoft. &amp;nbsp;In other words when it comes to anything Active Directory/DS. &amp;nbsp;Kim is "the man"&lt;br /&gt;&lt;br /&gt;Vittorio had an &lt;a href="http://blogs.msdn.com/b/vbertocci/archive/2011/05/08/thank-you-kim.aspx"&gt;excellent blog about Kim&lt;/a&gt;&amp;nbsp; &amp;nbsp;(Kim was retiring when that blog was written but has come back and he talked about that in this presentation)&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;object class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://1.gvt0.com/vi/6qbwTFyJa7k/0.jpg" height="266" width="320"&gt;&lt;param name="movie" value="http://www.youtube.com/v/6qbwTFyJa7k&amp;fs=1&amp;source=uds" /&gt;    &lt;param name="bgcolor" value="#FFFFFF" /&gt;    &lt;embed width="320" height="266"  src="http://www.youtube.com/v/6qbwTFyJa7k&amp;fs=1&amp;source=uds" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;&lt;br /&gt;This is a twenty minute Kim's keynote from the &lt;a href="http://www.id-conf.com/"&gt;European Identity &amp;amp; Cloud Conference 2012.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Some things I liked&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Use the efficiencies of the cloud to enable efficiencies in identity&lt;/li&gt;&lt;li&gt;The Cloud Motor Runs on Identity&lt;/li&gt;&lt;li&gt;Identity Management as a&amp;nbsp;service&amp;nbsp;is an inevitability&lt;/li&gt;&lt;li&gt;There ae other vendors who have similar&amp;nbsp;directories...not as good of course :)&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;There are a lot of people that talk about the cloud and give talks. &amp;nbsp;This is one from a guy who truly knows his stuff. &amp;nbsp; Kim also has an &lt;a href="http://www.identityblog.com/?p=1205"&gt;excellent blog entry&lt;/a&gt; that goes with this video.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I'm personally excited that AD and Directory Services types can evolve our skills and have work for years to come.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7365513794075231499-6508551491388845990?l=adisfun.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://adisfun.blogspot.com/feeds/6508551491388845990/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://adisfun.blogspot.com/2012/05/outstanding-cloud-identity-talk.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/6508551491388845990" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/6508551491388845990" /><link rel="alternate" type="text/html" href="http://adisfun.blogspot.com/2012/05/outstanding-cloud-identity-talk.html" title="Outstanding Cloud &amp; Identity Talk" /><author><name>mkline</name><uri>http://www.blogger.com/profile/03770498033295580147</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7365513794075231499.post-859722471045624093</id><published>2012-04-16T05:34:00.000-07:00</published><updated>2012-04-17T16:57:07.238-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Certification" /><title type="text">New MCSE - Personal FAQs</title><content type="html">As most blog readers know Microsoft has brought back the MCSE &amp;amp; MCSA certifications and titles. &amp;nbsp;For those newer to the field the MCSE was one of Microsoft's most popular certifications and tracks. &amp;nbsp;I'm on the AD/Server side of the house so for me this goes back to an MCSE in Windows NT, 2000, &amp;amp; 2003.&lt;br /&gt;&lt;br /&gt;With the 2008 tracks Microsoft did away with the MCSE &amp;amp; MCSA and introduced the MCITP an MCTS tracks and certifications.&lt;br /&gt;&lt;br /&gt;The MCSE and MCSA are back again but this time they stand for&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Microsoft Certified Solutions Expert&lt;/b&gt;&lt;br /&gt;&lt;b&gt;Microsoft Certified Solutions Associate&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;The Microsoft Learning team has put together a nice page with a lot of information.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://www.microsoft.com/learning/en/us/certification/mcse.aspx"&gt;&lt;span style="font-size: large;"&gt;MSCE: Reinvented for the Cloud&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;There are also some good videos on the site and the&lt;a href="http://www.youtube.com/user/microsoftlearning"&gt; Microsoft Learning YouTube Channel&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;object class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://0.gvt0.com/vi/b3dbPx2_85Q/0.jpg" height="266" width="320"&gt;&lt;param name="movie" value="http://www.youtube.com/v/b3dbPx2_85Q&amp;fs=1&amp;source=uds" /&gt;           &lt;param name="bgcolor" value="#FFFFFF" /&gt;           &lt;embed width="320" height="266"  src="http://www.youtube.com/v/b3dbPx2_85Q&amp;fs=1&amp;source=uds" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;There was a lot of great information on the site, but I still had questions and after asking around I noticed others had the same questions. &amp;nbsp;&lt;a href="https://twitter.com/#!/MSLearning"&gt;MSLearning has a Twitter Account&lt;/a&gt;&amp;nbsp;and that is where I learned a lot more about the new certs and the future.&amp;nbsp;I compiled some of my FAQs here:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;span style="color: red; font-size: large;"&gt;&lt;u&gt;MK FAQ 1 : What happens if I have the MCITP:SA do I need to start from scratch?&lt;/u&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span style="color: red; font-size: large;"&gt;&lt;b&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-64hQavUjysc/T4xTd3IvHRI/AAAAAAAAA0s/fUsSLB-4aVc/s1600/1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://3.bp.blogspot.com/-64hQavUjysc/T4xTd3IvHRI/AAAAAAAAA0s/fUsSLB-4aVc/s400/1.png" width="390" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;So that was good news, as you can see the MCITP:SA will automatically receive the new &lt;a href="http://www.microsoft.com/learning/en/us/certification/cert-windows-server-MCSA.aspx"&gt;MCSA: Windows Server 2008 Certification.&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span style="color: red; font-size: large;"&gt;&lt;u&gt;MK FAQ 2 : What happens if I have the MCITP:EA?&lt;/u&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;&lt;b style="color: red; font-size: x-large;"&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-BhnQpS0dqHg/T4xUN6P_KFI/AAAAAAAAA00/h8wNM328BmM/s1600/EA+Role.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="640" src="http://4.bp.blogspot.com/-BhnQpS0dqHg/T4xUN6P_KFI/AAAAAAAAA00/h8wNM328BmM/s640/EA+Role.png" width="393" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;This was interesting because the MCITP: EA and MCITP: SA will both have the same MCSA: WS2008 title. &amp;nbsp; I was hoping for two certs as I have both :) &amp;nbsp;&amp;nbsp;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Note: It was common for people to get both the MCITP:EA and MCITP:SA certifications.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span style="color: red; text-align: -webkit-auto;"&gt;&lt;u&gt;&lt;span style="font-size: large;"&gt;MK FAQ 3 : When will our transcripts be updated?&lt;/span&gt;&lt;/u&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;According to the twitter conversation above transcripts should change on April 24, 2012.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;b&gt;&lt;span style="color: #274e13;"&gt;UPDATE: &amp;nbsp;Blog reader let me know in the comments that his transcript was updated on 4/17/2012. &amp;nbsp;Nice job by Microsoft getting ahead of schedule.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span style="color: red; text-align: -webkit-auto;"&gt;&lt;u&gt;&lt;span style="font-size: large;"&gt;MK FAQ 4 : What happens to our old certifications?&lt;/span&gt;&lt;/u&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;b style="color: red; text-align: -webkit-auto;"&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-_vHwctYAoyw/T4xWAz61xSI/AAAAAAAAA08/muwu4TGCc8o/s1600/Legacy.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="66" src="http://4.bp.blogspot.com/-_vHwctYAoyw/T4xWAz61xSI/AAAAAAAAA08/muwu4TGCc8o/s640/Legacy.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;b style="color: red; font-size: x-large; text-align: -webkit-auto;"&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-h8xGzyeZu9s/T4xWFzrWN7I/AAAAAAAAA1E/54I5hVqwlu8/s1600/retire.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://4.bp.blogspot.com/-h8xGzyeZu9s/T4xWFzrWN7I/AAAAAAAAA1E/54I5hVqwlu8/s400/retire.png" width="385" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;This one I really like a lot! &amp;nbsp; I like that old certs will enter a legacy state and be stated that way on the official Microsoft transcript.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;I also like that new exams and certifications will also retire. &amp;nbsp;It makes people need to stay somewhat current and&amp;nbsp;re-certify. &amp;nbsp;Other companies already use the model the most famous probably being Cisco. &amp;nbsp;&amp;nbsp;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;I know there are going to be cynics out there that remember MCSE's being referred to as "paper tigers" or MCSEs that got their certs through brain dumps and that made us all look bad but Microsoft is definitely moving in the right direction in my opinion.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;I'll take an analogy from the Army. &amp;nbsp;Every Army soldier goes through bootcamp and has "basic" skills but there is a lot more&amp;nbsp;training&amp;nbsp;and experience needed to become a Ranger or Special forces and deal with the advanced issues/topics. &amp;nbsp; That is how I look at a lot of these certs (from any company). &amp;nbsp;They are a good step but getting an MCSA or MCSE doesn't mean someone knows everything....it is an ongoing process.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;One of my AD Heroes is Joe Richards and he once&amp;nbsp;&lt;a href="http://blog.joeware.net/2008/08/11/1420/"&gt;rated himself a 6 out of 10&lt;/a&gt; in AD. &amp;nbsp; Again it is a lifelong learning process...no one knows it all not even a guy like Joe (love how humble and cool he is)&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;I'd like to hear from the community. &amp;nbsp;What do you think about the new changes and updates?&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7365513794075231499-859722471045624093?l=adisfun.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://adisfun.blogspot.com/feeds/859722471045624093/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://adisfun.blogspot.com/2012/04/new-mcse-personal-faqs.html#comment-form" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/859722471045624093" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/859722471045624093" /><link rel="alternate" type="text/html" href="http://adisfun.blogspot.com/2012/04/new-mcse-personal-faqs.html" title="New MCSE - Personal FAQs" /><author><name>mkline</name><uri>http://www.blogger.com/profile/03770498033295580147</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-64hQavUjysc/T4xTd3IvHRI/AAAAAAAAA0s/fUsSLB-4aVc/s72-c/1.png" height="72" width="72" /><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7365513794075231499.post-2725148576792804946</id><published>2012-04-04T05:00:00.000-07:00</published><updated>2012-04-04T08:00:21.656-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Security" /><category scheme="http://www.blogger.com/atom/ns#" term="Active Directory" /><title type="text">Security Compliance Manager 2.5 Released</title><content type="html">&lt;div class="tr_bq"&gt;Ned Pyle wrote a blog entry in January on the&amp;nbsp;&amp;nbsp;&lt;a href="http://blogs.technet.com/b/askds/"&gt;Microsoft askds blog&amp;nbsp;&lt;/a&gt;&amp;nbsp;about &lt;a href="http://blogs.technet.com/b/askds/archive/2012/01/25/security-compliance-manager-2-5-beta-is-out.aspx"&gt;Security Compliance Manager 2.5 Beta&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;The tool has been &lt;a href="http://www.microsoft.com/download/en/details.aspx?id=16776"&gt;officially released&lt;/a&gt; and is no longer in beta.&lt;br /&gt;&lt;br /&gt;From the download center&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;b&gt;&lt;i&gt;&lt;span style="background-color: rgba(255, 255, 255, 0.917969); color: #222222; font-family: arial, sans-serif; font-size: 13px;"&gt;We are pleased to announce that version 2.5 is released and now available for download from the Microsoft Download Center!&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/blockquote&gt;&lt;i&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href="http://www.microsoft.com/download/en/details.aspx?id=16776"&gt;&amp;nbsp;&lt;b&gt;&lt;span style="background-color: rgba(255, 255, 255, 0.917969); color: #222222; font-family: arial, sans-serif; font-size: 13px;"&gt;Download SCM 2.5 now&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I've been testing 2.5 Beta and really glad that it is now out of beta as it will be much easier to get the tool approved for use where I work.&lt;br /&gt;&lt;br /&gt;You can read about the key features &amp;amp; benefits on the Microsoft site so I won't copy and paste them again here.&lt;br /&gt;&lt;br /&gt;There will be follow up blog posts with more info and screen shots from the tool.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7365513794075231499-2725148576792804946?l=adisfun.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://adisfun.blogspot.com/feeds/2725148576792804946/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://adisfun.blogspot.com/2012/04/security-compliance-manager-25-released.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/2725148576792804946" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/2725148576792804946" /><link rel="alternate" type="text/html" href="http://adisfun.blogspot.com/2012/04/security-compliance-manager-25-released.html" title="Security Compliance Manager 2.5 Released" /><author><name>mkline</name><uri>http://www.blogger.com/profile/03770498033295580147</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7365513794075231499.post-1561874040711992256</id><published>2012-03-30T08:00:00.000-07:00</published><updated>2012-03-30T10:03:31.000-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="ADAC" /><category scheme="http://www.blogger.com/atom/ns#" term="Active Directory" /><title type="text">Active Directory Administrative Center Twitter Question</title><content type="html">I recently saw a question on Twitter about the &lt;a href="http://blogs.technet.com/b/activedirectoryua/archive/2009/01/30/introducing-active-directory-administrative-center.aspx"&gt;Active Directory Administrative Center&lt;/a&gt;&amp;nbsp;(ADAC)&lt;br /&gt;&lt;br /&gt;Twitter is a site everyone knows but more and more it is a great place for tech information and sharing in the community. &amp;nbsp;There are a lot of good tweets on Active Directory and links to information. &amp;nbsp;There is also a fair amount of spam/bad links. &amp;nbsp;Those are usually easy to spot though (picture is a "sexy" model for example)&lt;br /&gt;&lt;br /&gt;Thanks a lot to&lt;a href="https://twitter.com/#!/samerde"&gt; @SamErde&lt;/a&gt; for letting me use his post for this blog. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-9EdmkfRdMcQ/T3HR1lnhm7I/AAAAAAAAAy8/vIHehxyIWAE/s1600/sam+AD+twitter.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="248" src="http://3.bp.blogspot.com/-9EdmkfRdMcQ/T3HR1lnhm7I/AAAAAAAAAy8/vIHehxyIWAE/s640/sam+AD+twitter.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;a href="http://technet.microsoft.com/en-us/library/dd560651(v=ws.10).aspx"&gt;ADAC&lt;/a&gt; was released with Windows 2008 R2. &amp;nbsp;It has gained some traction but currently it is definitely still not the GUI tool of choice for Active Directory Administration. &amp;nbsp;AD Users &amp;amp; Computers still wins but that may change in Windows 8 when features like the AD Recycle Bin and Fine-Grained Passwords are brought into ADAC giving both of those features a much needed GUI.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;In order to truly test I created three forests in my lab and created a forest trusts between the first forest and the other two forests. &amp;nbsp;I did see TechNet articles that this could be done but I like to verify.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-VfoU7FkhQH8/T3HeF5vgyYI/AAAAAAAAAzE/zhfWjRjrK1Q/s1600/Blog+Forest+Trusts.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="308" src="http://1.bp.blogspot.com/-VfoU7FkhQH8/T3HeF5vgyYI/AAAAAAAAAzE/zhfWjRjrK1Q/s400/Blog+Forest+Trusts.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-9gD3zhuV4wU/T3Hjwu0YqDI/AAAAAAAAAzM/qd3HbrP4t4A/s1600/trusts.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://2.bp.blogspot.com/-9gD3zhuV4wU/T3Hjwu0YqDI/AAAAAAAAAzM/qd3HbrP4t4A/s320/trusts.png" width="288" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;I'm not just a blogger I also work in this world and I know setting up the trusts can be a pain. &amp;nbsp;You have to have &lt;a href="http://support.microsoft.com/kb/179442"&gt;proper ports open&lt;/a&gt;&amp;nbsp; That is often easier said than done. &amp;nbsp;Become friends with the firewall admins :) &amp;nbsp; You also need to ensure that name resolution is working. &amp;nbsp;I used&amp;nbsp;conditional&amp;nbsp;forwarders to resolve the domain names in DNS. &amp;nbsp;Stub zones and secondary zones would also work.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;There are a lot of posts and resources about setting up trusts. &amp;nbsp;If you run into issues look at the basics first&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;For potential port blockages tools like telnet, portqry, wireshark, and netmon are really good starting points.&lt;/li&gt;&lt;li&gt;For DNS issues nslookup is a good place to start troubleshooting. &amp;nbsp;(wireshark/netmon are good there too)&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;At this point the forest trusts have been setup and the two way trusts are functional. &amp;nbsp; The first thing we need to do is to try and add one of the other domains in ADAC.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-DEmgka0rjOs/T3HkJHLQrUI/AAAAAAAAAzU/z2CRnNyEMSw/s1600/1.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="152" src="http://1.bp.blogspot.com/-DEmgka0rjOs/T3HkJHLQrUI/AAAAAAAAAzU/z2CRnNyEMSw/s400/1.png" width="400" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Add Navigation Nodes in ADAC - Windows Server 2008 R2&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-VogpwAZ9kdk/T3HkVqXAQiI/AAAAAAAAAzc/cN0-kDm-Npo/s1600/windows8+Navigation+Nodes.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="202" src="http://4.bp.blogspot.com/-VogpwAZ9kdk/T3HkVqXAQiI/AAAAAAAAAzc/cN0-kDm-Npo/s400/windows8+Navigation+Nodes.png" width="400" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Add Navigation Nodes in ADAC - Windows Server 8 Beta&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;I added the screenshot from a Windows Server 8 Beta box just to show that the location for adding the Navigation Nodes has changed.&lt;br /&gt;&lt;div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I'm going to use Windows 2008 R2 for the rest of the examples. &amp;nbsp; I select add navigation nodes from there I can add another domain. &amp;nbsp;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-XMLJ7KQCTks/T3IWAtSRoaI/AAAAAAAAAzs/i02cjyE57hM/s1600/connect+to+other+domain.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;img border="0" height="155" src="http://2.bp.blogspot.com/-XMLJ7KQCTks/T3IWAtSRoaI/AAAAAAAAAzs/i02cjyE57hM/s400/connect+to+other+domain.png" width="400" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Adding domain in another forest to ADAC via Navigation Node&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div style="text-align: left;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: -webkit-auto;"&gt;Once I add the domain from the trusted forest I can now see it in ADAC&lt;/div&gt;&lt;div style="text-align: -webkit-auto;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-aM_4LaG4Q1Q/T3IZdD6NfnI/AAAAAAAAAz0/TDJqdflDY70/s1600/forest3+appears.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;img border="0" height="135" src="http://4.bp.blogspot.com/-aM_4LaG4Q1Q/T3IZdD6NfnI/AAAAAAAAAz0/TDJqdflDY70/s400/forest3+appears.png" width="400" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Remote domain from trusted forest now appears in ADAC&lt;br /&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;That is great but what does that really get me? &amp;nbsp;I am able to view objects in the remote domain due to the default nature of AD allowing read access to most objects.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I'm not able to make any changes which is a good thing. &amp;nbsp;The fact that the forest trust exists doesn't give any rights to administer the remote domain.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Notice in the screenshot below, I attempt to update/edit a user in the remote forest/domain. &amp;nbsp;I'm unable to make any changes but can read his info.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-kUAzRMtacA4/T3Xh9W-SO3I/AAAAAAAAA0A/wcBymhTnjt8/s1600/change+user.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="327" src="http://2.bp.blogspot.com/-kUAzRMtacA4/T3Xh9W-SO3I/AAAAAAAAA0A/wcBymhTnjt8/s400/change+user.png" width="400" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Attempting to update a user&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Without any rights I can't really do much. &amp;nbsp;In this case I want the same account to be able the objects in both forests.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;There are several options here but I added my admin account into the Built-In Administrators group in the remote domain.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-DJyCX-fk40s/T3XjT8M2wWI/AAAAAAAAA0I/7hZ5EkVFw-w/s1600/adding+into+admin+group.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="400" src="http://4.bp.blogspot.com/-DJyCX-fk40s/T3XjT8M2wWI/AAAAAAAAA0I/7hZ5EkVFw-w/s400/adding+into+admin+group.png" width="346" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;My admin account has been added into the Administrators group in the remote domain&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;After the addition has replicated I then try to update the user account from ADAC again. &amp;nbsp;This time you will notice that the fields are not&amp;nbsp;grayed&amp;nbsp;out and I can make changes.&lt;br /&gt;&lt;div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-GdM-r6p48PA/T3Xj7i_xBRI/AAAAAAAAA0Q/_zKA0NlT4pQ/s1600/updated+after+added+to+admin.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="328" src="http://1.bp.blogspot.com/-GdM-r6p48PA/T3Xj7i_xBRI/AAAAAAAAA0Q/_zKA0NlT4pQ/s400/updated+after+added+to+admin.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;b style="color: red;"&gt;Wishlist: &amp;nbsp;&lt;/b&gt;I would like the ability to add another domain in the navigation node but also specify alternate credentials when I do that. &amp;nbsp;That would be handy if an admin has a separate admin account in the remote forest/domain. &amp;nbsp; I'm still researching that and will update the blog if I find something.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;There is a good article about &lt;a href="http://technet.microsoft.com/en-us/library/dd560632(v=ws.10).aspx"&gt;ADAC on TechNet&lt;/a&gt; that is worth reading. &amp;nbsp;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;What are your thoughts on ADAC. &amp;nbsp;For those at 2008 R2 is it gaining traction in your&amp;nbsp;environments?&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7365513794075231499-1561874040711992256?l=adisfun.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://adisfun.blogspot.com/feeds/1561874040711992256/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://adisfun.blogspot.com/2012/03/active-directory-administrative-center.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/1561874040711992256" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/1561874040711992256" /><link rel="alternate" type="text/html" href="http://adisfun.blogspot.com/2012/03/active-directory-administrative-center.html" title="Active Directory Administrative Center Twitter Question" /><author><name>mkline</name><uri>http://www.blogger.com/profile/03770498033295580147</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-9EdmkfRdMcQ/T3HR1lnhm7I/AAAAAAAAAy8/vIHehxyIWAE/s72-c/sam+AD+twitter.png" height="72" width="72" /><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7365513794075231499.post-767413966818235944</id><published>2012-03-22T07:00:00.000-07:00</published><updated>2012-03-27T15:38:10.368-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="adfind" /><category scheme="http://www.blogger.com/atom/ns#" term="Powershell" /><category scheme="http://www.blogger.com/atom/ns#" term="Active Directory" /><title type="text">LastLogonTimestamp for Group Members</title><content type="html">I was recently working in a secure&amp;nbsp;environment&amp;nbsp;and one of the issues was way too many domain admin accounts. &amp;nbsp;This is not a problem just in secure&amp;nbsp;environment. &amp;nbsp;I've yet to encounter a federal organization that does an outstanding job of limiting the number of domain admins. &amp;nbsp;I've seen &lt;a href="http://blog.joeware.net/"&gt;Joe Richards&lt;/a&gt;&amp;nbsp;write about working at a Fortune 5 company where they ran with less than 5 domain administrators. &amp;nbsp;More and more organizations are trying to limit domain admins. &amp;nbsp;I doubt we will ever get to a point where less than five is the norm but things are getting better...slowly but surely.&lt;br /&gt;&lt;br /&gt;The first step the security team took was to identify members of the domain admin group and the last time they logged in. &amp;nbsp;This is a good initial step to remove those that haven't logged on or used their accounts. &amp;nbsp;If someone hasn't used their domain admin account in 120 days or longer then I would question if they need the account.&lt;br /&gt;&lt;br /&gt;Some folks on the security team were manually going and using a box that had the&amp;nbsp;&lt;a href="http://blogs.technet.com/b/askds/archive/2011/04/12/you-probably-don-t-need-acctinfo2-dll.aspx"&gt;additional&amp;nbsp;account info tab from the acctinfo.dll&lt;/a&gt;. &amp;nbsp;They were then looking at lastlogon box within the tab and manually entering that into a spreadsheet.&amp;nbsp;&amp;nbsp;I knew there were easier ways to do this so I stepped in to help out.&lt;br /&gt;&lt;br /&gt;For this exercise I keyed off the&lt;a href="http://blogs.technet.com/b/askds/archive/2009/04/15/the-lastlogontimestamp-attribute-what-it-was-designed-for-and-how-it-works.aspx"&gt; LastLogonTimeStamp&lt;/a&gt;&amp;nbsp;(LLTS) The lastlogontimestamp can be off by 9-14 days. &amp;nbsp;The link to the askds blog entry on LLTS does a great job of explaining it. &amp;nbsp;If 9-14 days is not acceptable then you would have to query lastlogon on every DC. &amp;nbsp;Lastlogon does not replicate and that is why every DC would have to be queried.&lt;br /&gt;&lt;br /&gt;For the examples I'm in my lab domain which is mkw2k8R2.com and I only have three users in the domain admin group. &amp;nbsp;I've only logged in with one of those users.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;span style="color: #134f5c; font-size: large;"&gt;&lt;b&gt;&lt;u&gt;Method 1 - Using ADFIND&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span style="color: red; font-size: large;"&gt;&lt;b&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Regular blog users will not be surprised to find out that I used &lt;a href="http://www.joeware.net/freetools/tools/adfind/index.htm"&gt;adfind&lt;/a&gt; from Joe Richards for method 1. &amp;nbsp;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;&lt;i&gt;adfind -default -f "memberof=cn=domain admins,cn=users,dc=mydomain,dc=mysuffix" samaccountname lastlogontimestamp -tdc -nodn -csv&amp;nbsp;&lt;/i&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-pi9yW1eSkKk/T2tQOSIhECI/AAAAAAAAAyA/qNpA3a8CKJ8/s1600/adfind.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="33" src="http://4.bp.blogspot.com/-pi9yW1eSkKk/T2tQOSIhECI/AAAAAAAAAyA/qNpA3a8CKJ8/s320/adfind.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;span style="color: #134f5c; font-size: large;"&gt;&lt;b&gt;&lt;u&gt;Method 2 - Using Quest AD Powershell Cmdlets&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span style="color: #134f5c; font-size: large;"&gt;&lt;b&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Many people that started with powershell and AD years ago are probably familiar with the &lt;a href="http://www.quest.com/powershell/activeroles-server.aspx"&gt;free AD cmdlets from Quest. &amp;nbsp;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span style="color: red; font-size: large;"&gt;&lt;b&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;&lt;i&gt;get-qaduser -memberof "domain admins" | select-object samaccountname, lastlogontimestamp&lt;/i&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-lYY-mhZVDrA/T2tRipW0MdI/AAAAAAAAAyI/NeVoFNSH5Kc/s1600/quest+cmdlets.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="47" src="http://1.bp.blogspot.com/-lYY-mhZVDrA/T2tRipW0MdI/AAAAAAAAAyI/NeVoFNSH5Kc/s320/quest+cmdlets.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;span style="color: #134f5c; font-size: large;"&gt;&lt;b&gt;&lt;u&gt;Method 3 - Using Microsoft's AD Powershell v2 Cmdlets&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span style="color: #134f5c; font-size: large;"&gt;&lt;b&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;With the introduction of Windows 2008 R2 and Windows 7&amp;nbsp;Microsoft&amp;nbsp;&lt;a href="http://technet.microsoft.com/en-us/library/dd378937(v=ws.10).aspx"&gt;introduced the AD module for Windows Powershell.&lt;/a&gt;&amp;nbsp; There is already a lot of good information about the &lt;a href="http://blogs.msdn.com/b/adpowershell/archive/2009/02/25/ad-powershell-quick-start-guide.aspx"&gt;AD Module for Powershell&lt;/a&gt; so I won't go over that here. &amp;nbsp; I also admit I'm not a powershell master/guru.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;&lt;i&gt;get-aduser -LDAPFilter "(memberof=cn=domain admins,cn=users,dc=mkw2k8r2,dc=com)" -property lastlogondate | ft samaccountname, lastlogondate&lt;/i&gt;&lt;/blockquote&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-zkCZbEPwTtM/T2tUIpsq_OI/AAAAAAAAAyQ/_FdgiLyIIO0/s1600/adcmdlets.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="43" src="http://1.bp.blogspot.com/-zkCZbEPwTtM/T2tUIpsq_OI/AAAAAAAAAyQ/_FdgiLyIIO0/s320/adcmdlets.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;If you noticed I used lastlogondate which is not an actual AD attribute. &amp;nbsp;My friend &lt;a href="https://mvp.support.microsoft.com/profile=947B5A4C-AD73-461F-A133-A5B9923DAC2E"&gt;Richard Mueller&lt;/a&gt; had a &lt;a href="http://social.technet.microsoft.com/Forums/en/winserverDS/thread/838b1e09-7fcb-4ea2-95f4-b21c5bb2c37e"&gt;good writeup on lastlogondate. &amp;nbsp;&lt;/a&gt;&amp;nbsp; See the link and Richard's answer for more info on lastlogondate which is essentially the same as lastlogontimestamp&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span style="color: #134f5c; font-size: large;"&gt;&lt;b&gt;&lt;u&gt;Method 4 - Using CSVDE&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span style="color: red; font-size: large;"&gt;&lt;b&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a href="http://technet.microsoft.com/en-us/library/cc732101(v=ws.10).aspx"&gt;CSVDE &lt;/a&gt;is what you call an old school tool. &amp;nbsp;Those that have been around AD for years have definitely used the tool at some point. &amp;nbsp;It was around before adfind and powershell.&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;&lt;i&gt;csvde -f c:\userslogon.csv -r "(memberof=cn=domain admins,cn=users,dc=mkw2k8r2,dc=com)" -l samaccountname, lastllogontimestamp &amp;nbsp;&lt;/i&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;One problem with the CSVDE method is how it handles the output. &amp;nbsp; LastLogonTimeStamps are Integer8 (64-bit numbers) that CSVDE can't handle. &amp;nbsp;You will notice in methods 1-3 those tools did a good job of decoding the attribute.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://myserverstuff.blogspot.com/2009/03/csvde-to-excel-human-readable-lastlogon.html"&gt;Elizabeth Greene has a really good blog entry&lt;/a&gt; that has a formula you can use in excel to convert it into a readable date.&lt;br /&gt;&lt;br /&gt;Notice in the screenshot the difference between the native format in cell C2 and what it looks like after I applied the formula&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-u0D0mvw4fKs/T2tZgj3bx_I/AAAAAAAAAyg/OvDUfyGSj5g/s1600/csvde.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="48" src="http://3.bp.blogspot.com/-u0D0mvw4fKs/T2tZgj3bx_I/AAAAAAAAAyg/OvDUfyGSj5g/s320/csvde.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span style="color: #134f5c; font-size: large;"&gt;&lt;b&gt;&lt;u&gt;Method 5 - Using Repadmin&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span style="color: #134f5c; font-size: large;"&gt;&lt;b&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;This method I first saw used in the blog from the askds team that I linked to earlier and I'll link to again &lt;a href="http://blogs.technet.com/b/askds/archive/2009/04/15/the-lastlogontimestamp-attribute-what-it-was-designed-for-and-how-it-works.aspx"&gt;here&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;i&gt;repadmin /showattr dc1root dc=mkw2k8r2,dc=com /subtree /filter:"(memberof=cn=domain admins,cn=users,dc=mkw2k8r2,dc=com)" /attrs:lastlogontimestamp&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-rdovB9L5u6Q/T2tb7kiI6fI/AAAAAAAAAys/BnEMubzqzf8/s1600/repadmin.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="32" src="http://1.bp.blogspot.com/-rdovB9L5u6Q/T2tb7kiI6fI/AAAAAAAAAys/BnEMubzqzf8/s320/repadmin.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;span style="color: #134f5c; font-size: large;"&gt;&lt;b&gt;&lt;u&gt;Other Methods&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;span style="color: #134f5c; font-size: large;"&gt;&lt;b&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span style="color: #134f5c;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;I really like methods 1-3 the best. &amp;nbsp;There are other methods that I have not included here but I figured five is a good start for anyone. &amp;nbsp;Some other things you might see out there&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;VBScript - &lt;a href="http://www.rlmueller.net/Last%20Logon.htm"&gt;Richard is the king&lt;/a&gt; in this category and if you want to use VBScript I recommend testing his scripts out.&lt;/li&gt;&lt;li&gt;Powershell v1 without AD cmdlets - remember when I said I was not a powershell guru yet. &amp;nbsp;I'm guessing that is something that can be done but haven't tried to do it yet. &amp;nbsp; The AD cmdlets from Microsoft and Quest both work for me so I try to stick to them.&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;You can use these examples and modify them if you are looking for other groups. &amp;nbsp;There are other/better ways to identify old/stale accounts in a domain if you want to do it domain wide. &amp;nbsp;More to come on that.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I'm really looking forward to hearing from readers and the community on other methods for doing this. &amp;nbsp;If there are better ways to do it in Powershell please leave a comment and I'll definitely update the blog.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Inactive Domain Admins beware....you will be removed :)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7365513794075231499-767413966818235944?l=adisfun.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://adisfun.blogspot.com/feeds/767413966818235944/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://adisfun.blogspot.com/2012/03/lastlogontimestamp-for-group-members.html#comment-form" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/767413966818235944" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/767413966818235944" /><link rel="alternate" type="text/html" href="http://adisfun.blogspot.com/2012/03/lastlogontimestamp-for-group-members.html" title="LastLogonTimestamp for Group Members" /><author><name>mkline</name><uri>http://www.blogger.com/profile/03770498033295580147</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-pi9yW1eSkKk/T2tQOSIhECI/AAAAAAAAAyA/qNpA3a8CKJ8/s72-c/adfind.png" height="72" width="72" /><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7365513794075231499.post-7127739759745568414</id><published>2012-03-19T13:55:00.008-07:00</published><updated>2012-03-19T14:26:46.162-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="virtualization" /><category scheme="http://www.blogger.com/atom/ns#" term="Windows 8 Beta" /><title type="text">Windows Server 8  AD Cloning, Virtualization, and Snapshots Warning</title><content type="html">Windows Server 8 Beta has a lot of nice features. &amp;nbsp;Two features that are getting a lot of buzz in the Active Directory World are the ability to easily clone domain controllers and the support to restore Active Directory using snapshots.&lt;br /&gt;&lt;br /&gt;Using snapshots can cause USN Rollback and &lt;a href="http://support.microsoft.com/kb/2028495"&gt;other problems&lt;/a&gt;. &amp;nbsp;&lt;a href="http://blogs.technet.com/b/askds/archive/2009/06/05/dc-s-and-vm-s-avoiding-the-do-over.aspx"&gt;Mark Ramey from the Microsoft AD team has an excellent blog entry that you can read for more info.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I added the word Warning to the title of this blog because I've seen a few blogs, posts, and articles that may lead people to believe that this can all be done with a few mouse clicks. &amp;nbsp;This is not the case, it is not hard but there are some major prerequisites and steps that people have to be aware of.&lt;br /&gt;&lt;br /&gt;A few screenshots from my lab using VMware workstation. &amp;nbsp;These options exist in most hypervisor &amp;nbsp;products.&lt;br /&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-dki1DXBWhyE/T2eUTI3706I/AAAAAAAAAxQ/kpmP32MRWBM/s1600/clone.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="320" src="http://2.bp.blogspot.com/-dki1DXBWhyE/T2eUTI3706I/AAAAAAAAAxQ/kpmP32MRWBM/s320/clone.png" width="301" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Cloning in VMware Workstation 8&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-_JlgEnT131E/T2eUdTS9y0I/AAAAAAAAAxY/tOWpIHheCNg/s1600/SnapShots.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="301" src="http://4.bp.blogspot.com/-_JlgEnT131E/T2eUdTS9y0I/AAAAAAAAAxY/tOWpIHheCNg/s320/SnapShots.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Snapshot in VMWare Workstation 8&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;&lt;b&gt;***WARNING***&lt;/b&gt;&amp;nbsp; &lt;/span&gt;You can't just use the GUI and start cloning and taking snapshots without causing issues in a domain/forest with multiple DCs. &amp;nbsp;You can't manually copy the virtual machine files. &amp;nbsp;VMWare workstation 8 and the current VMWare products don't support these features. &lt;br /&gt;&lt;br /&gt;To take advantage of these features the virtualization host must support VM Generation ID. &amp;nbsp; I'm guessing by the time Windows 8 is&amp;nbsp;released&amp;nbsp;all major vendors will support this but that means most folks will have to upgrade their hypervisor.&lt;br /&gt;&lt;br /&gt;Microsoft currently has two really good documents that are a must read for anyone interested in these new features&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;a href="http://www.microsoft.com/download/en/details.aspx?id=29027"&gt;Test Lab Guide: &amp;nbsp;Demonstrate Virtualized Domain &amp;nbsp;Controller (VDC) in Windows Server "8" Beta&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;a href="http://www.microsoft.com/download/en/details.aspx?id=29001"&gt;Understand and Troubleshoot Virtualized&amp;nbsp;Domain&amp;nbsp;Controller (VDC) in Windows Server "8" Beta&lt;/a&gt;&amp;nbsp; - written by Ned Pyle - Outstanding&amp;nbsp;document!!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;I won't repeat the documents but some important sections&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Steps to deploy a cloned virtualized domain controller&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="NumberedList1" style="margin-left: .5in; mso-list: l0 level1 lfo2; tab-stops: .25in;"&gt;1.&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Create the customized DcCloneConfig.xml file on a source domain controller&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="NumberedList1" style="margin-left: .5in; mso-list: l0 level1 lfo2; tab-stops: .25in;"&gt;2.&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Detect incompatible programs on the source domain controller&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="NumberedList1" style="margin-left: .5in; mso-list: l0 level1 lfo2; tab-stops: .25in;"&gt;3.&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Ensure the PDC emulator runs Windows Server "8" Beta, is not the clone source, and is available&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="NumberedList1" style="margin-left: .5in; mso-list: l0 level1 lfo2; tab-stops: .25in;"&gt;4.&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Authorize the source domain controller for cloning&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="NumberedList1" style="margin-left: .5in; mso-list: l0 level1 lfo2; tab-stops: .25in;"&gt;5.&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Shutdown the source domain controller and copy its disk&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="NumberedList1" style="margin-left: .5in; mso-list: l0 level1 lfo2; tab-stops: .25in;"&gt;6.&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Create a new clone virtual machine using the copied disks&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="NumberedList1" style="margin-left: .5in; mso-list: l0 level1 lfo2; tab-stops: .25in;"&gt;7.&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Start the source and cloned domain controller, then allow cloning to occur&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="NumberedList1" style="margin-left: 0.5in; text-align: -webkit-auto;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;h1 bi:title="item" id="top" style="background-color: white; color: #4f4f4f; display: table-cell; font-family: 'Segoe UI Light', 'Segoe UI', Arial, Verdana, Tahoma, sans-serif; font-size: 30px; font-weight: normal; height: 75px; line-height: 37px; margin-bottom: 0px; margin-left: 0px; margin-right: 10px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: middle;"&gt;&lt;/h1&gt;&lt;h1 bi:title="item" id="top" style="display: table-cell; height: 75px; margin-bottom: 0px; margin-left: 0px; margin-right: 10px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: middle;"&gt;&lt;span style="font-size: small; font-weight: normal;"&gt;For those that are fans of the GUI&lt;/span&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;&lt;i style="font-size: medium; font-weight: normal;"&gt;There is no task-oriented graphical&amp;nbsp;management&amp;nbsp;program for VDC cloning in Windows Server "8" Beta; the provisioning steps are performed manually or using Windows PowerShell&lt;/i&gt;&amp;nbsp;&lt;/blockquote&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-weight: normal;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h1&gt;&lt;br /&gt;&lt;b&gt;&amp;nbsp;Steps to restore a DC snapshot&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="NumberedList1" style="margin-left: 0.5in;"&gt;1.&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;Take snapshot of DC&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="NumberedList1" style="margin-left: 0.5in;"&gt;2.&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;Create a new Group Policy&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="NumberedList1" style="margin-left: 0.5in;"&gt;3.&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;Validate GP replication (SYSVOL replication)&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="NumberedList1" style="margin-left: 0.5in;"&gt;4.&lt;span style="font-size: 7pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;Restore DC Snapshot&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;You can read the the documents to get a lot more info. &amp;nbsp; Ned's document is 162 pages...Ned is the king of documentation and writing :)&lt;br /&gt;&lt;br /&gt;As I start using this feature more and eventually use this in production in the future I hope to write more on these features. &amp;nbsp;I won't try to replicate Ned's excellent document but there is going to be more to come.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7365513794075231499-7127739759745568414?l=adisfun.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://adisfun.blogspot.com/feeds/7127739759745568414/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://adisfun.blogspot.com/2012/03/windows-server-8-ad-cloning.html#comment-form" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/7127739759745568414" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/7127739759745568414" /><link rel="alternate" type="text/html" href="http://adisfun.blogspot.com/2012/03/windows-server-8-ad-cloning.html" title="Windows Server 8  AD Cloning, Virtualization, and Snapshots Warning" /><author><name>mkline</name><uri>http://www.blogger.com/profile/03770498033295580147</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-dki1DXBWhyE/T2eUTI3706I/AAAAAAAAAxQ/kpmP32MRWBM/s72-c/clone.png" height="72" width="72" /><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7365513794075231499.post-1460372302290441560</id><published>2012-03-15T08:15:00.008-07:00</published><updated>2012-03-15T11:39:16.796-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Security" /><category scheme="http://www.blogger.com/atom/ns#" term="Miscellaneous" /><title type="text">HSPD-12 and Active Directory Domains -Documents Updated</title><content type="html">Microsoft has updated their documentation regarding &lt;a href="http://www.microsoft.com/download/en/details.aspx?displaylang=en&amp;amp;id=9427"&gt;HSPD-12 Logical Access Authentication and Active Directory Domains&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;These documents are probably going to be more valuable to those that support federal customers in the US but they are a good read for anyone planning to deploy smart cards in their&amp;nbsp;environment.&lt;br /&gt;&lt;br /&gt;For those not familiar with &lt;a href="http://www.microsoft.com/industry/government/solutions/HSPD12/default.aspx"&gt;HSPD-12&lt;/a&gt; in a nut shell it is a mandate for federal organizations to issue common ID/Smart cards to their users. &amp;nbsp;This comes into play in the Active Directory arena as the cards are used for login using two-factor authentication/smart card login. &amp;nbsp;The two-factors in this case are:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Something the user has - the smart card&lt;/li&gt;&lt;li&gt;Something the user knows - PIN&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Everyone has seen this referenced in the Account tab of a user in AD Users &amp;amp;&amp;nbsp;Computers.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/--TezPAMGlVA/T2IHPE9MRJI/AAAAAAAAAxI/kzpFnFBt5OI/s1600/smartcards.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://4.bp.blogspot.com/--TezPAMGlVA/T2IHPE9MRJI/AAAAAAAAAxI/kzpFnFBt5OI/s320/smartcards.png" width="235" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Those in the military or who have supported US Military customers will hear the term &lt;a href="http://www.cac.mil/"&gt;CAC Card&lt;/a&gt; used for their smart cards. Those supporting civilian agencies/.gov will hear the term &lt;a href="http://www.va.gov/pivproject/faq.asp"&gt;PIV Card&lt;/a&gt; for their smart cards.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;You can get the updated Microsoft documentation here:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;h3 class="post-name" style="background-color: white; clear: both; font-family: 'Segoe UI Semibold', 'Segoe UI', 'Lucida Grande', Verdana, Arial, Helvetica, sans-serif; line-height: 25px; margin-bottom: 12px; margin-left: 0px; margin-right: 0px; margin-top: 7px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-align: center;"&gt;&lt;span style="color: red; font-size: large;"&gt;&lt;a href="http://www.microsoft.com/download/en/details.aspx?displaylang=en&amp;amp;id=9427"&gt;HSPD-12 Logical Access Authentication and 2008 Active Directory Domains&amp;nbsp;&lt;/a&gt;&lt;/span&gt;&lt;/h3&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://social.technet.microsoft.com/profile/kurt%20l%20hudson/"&gt;Kurt Hudson&lt;/a&gt; has a good quote about the documents on the &lt;a href="http://blogs.technet.com/b/pki/archive/2012/03/14/hspd-12-logical-access-authentication-and-2008-active-directory-domains-on-download-center.aspx"&gt;Windows PKI Blog&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;&lt;i&gt;&lt;span style="background-color: white; color: #333333; font-family: 'Segoe UI', 'Lucida Grande', Verdana, Arial, Helvetica, sans-serif; line-height: 18px; text-align: left;"&gt;Included within this document are detailed steps to configure Windows Server 2008 R2 Active Directory Domain Services (AD DS), Active Directory Certificate Services (AD CS), Windows® 7, and Microsoft® Office 2010 to perform traditional UPN based smart card logon, explicit smart card logon (client authentication certificate mapped to multiple accounts), explicit cross-forest smart card logon and NIST SP800-78-3 compliant S/MIME email exchanges.&lt;/span&gt;&amp;nbsp;&lt;/i&gt;&lt;/blockquote&gt;Smart card/HSPD-12 adoption within agencies varies. &amp;nbsp;DoD has definitely been the leader in this space. &amp;nbsp;There are other agencies that I've been at that are also rolling but there are also those that haven't even started issuing smart cards to the majority of their users yet. &amp;nbsp; I'm not naming names here :)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7365513794075231499-1460372302290441560?l=adisfun.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://adisfun.blogspot.com/feeds/1460372302290441560/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://adisfun.blogspot.com/2012/03/hspd-12-and-active-directory-documents.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/1460372302290441560" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/1460372302290441560" /><link rel="alternate" type="text/html" href="http://adisfun.blogspot.com/2012/03/hspd-12-and-active-directory-documents.html" title="HSPD-12 and Active Directory Domains -Documents Updated" /><author><name>mkline</name><uri>http://www.blogger.com/profile/03770498033295580147</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/--TezPAMGlVA/T2IHPE9MRJI/AAAAAAAAAxI/kzpFnFBt5OI/s72-c/smartcards.png" height="72" width="72" /><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7365513794075231499.post-3151718695107298413</id><published>2012-03-13T18:27:00.007-07:00</published><updated>2012-03-14T04:28:54.805-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Windows 8 Beta" /><title type="text">Windows Server 8 Member Server - ADAC Recycle Bin</title><content type="html">&lt;a href="http://technet.microsoft.com/en-us/evalcenter/hh670538"&gt;Windows Server 8 Beta&lt;/a&gt; was released a few weeks ago and I understand that many organizations may be hesitant to start deploying domain controllers.&lt;br /&gt;&lt;br /&gt;One nice thing is that some of the new features can easily run on a member server or workstation and work fine in your current domains. &amp;nbsp;You don't need to convince anyone about a schema update or new Windows 8 Domain Controllers right now. &amp;nbsp;Enjoy the new features with no risk (I'd argue there is not a lot of risk in adding a domain controller but I understand leadership wanting to wait on domain controllers)&lt;br /&gt;&lt;br /&gt;One of those features is the &lt;a href="http://adisfun.blogspot.com/2011/09/windows-server-8-active-directory_14.html"&gt;AD Recycle Bin GUI&lt;/a&gt;.  That is a nice addition that system administrators have been asking for since 2008 R2 was released.  Your forest does have to be at 2008 R2 Forest Functional Level to enable the recycle bin.&lt;br /&gt;&lt;br /&gt;Many people enabled and used the &lt;a href="http://blogs.technet.com/b/askds/archive/2009/08/27/the-ad-recycle-bin-understanding-implementing-best-practices-and-troubleshooting.aspx"&gt;AD Recycle Bin in 2008 R2 &lt;/a&gt;&amp;nbsp;There are even some &lt;a href="http://www.overall.ca/index.php?option=com_content&amp;amp;view=article&amp;amp;id=40:adrecyclebin&amp;amp;catid=15:adrecyclebinexe&amp;amp;Itemid=64"&gt;3rd party tools&lt;/a&gt; that can help and put a &lt;a href="http://www.powergui.org/entry.jspa?externalID=2461"&gt;GUI front end&lt;/a&gt; around the Recycle Bin.   In my opinion the GUI in Windows Server 8 is much nicer and is definitely a reason to add a Windows Server 8 member server now.&lt;br /&gt;&lt;br /&gt;In my lab I have a 2008 R2 (forest functional level 2008 R2) Domain Controller and a Windows Server 8 Beta member server.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-Yz9kzkyICkU/T1-4-O04r-I/AAAAAAAAAtc/XaTsqxRfg-A/s1600/1.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="294" src="http://2.bp.blogspot.com/-Yz9kzkyICkU/T1-4-O04r-I/AAAAAAAAAtc/XaTsqxRfg-A/s320/1.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Windows 2008 R2 Domain&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;b style="color: red;"&gt;SIDE NOTE:  &lt;/b&gt;As you can see my test domain is named &lt;b&gt;USMCThanksForYourService.mil  &lt;/b&gt;I've heard there might be some Marines stationed in Afghanistan reading this entry so a heartfelt thanks for all you all do. It takes a lot of courage to be in the military right now and you all are on the front lines.  THANK YOU!!&lt;br /&gt;&lt;b style="color: red;"&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;b style="color: red;"&gt;SIDE NOTE II: &amp;nbsp;&lt;/b&gt;Although I'm an Army vet I support all branches of the military. &amp;nbsp;Any other military members reading my blog? &amp;nbsp;Leave a comment, I'd love to hear from you.&lt;br /&gt;&lt;br /&gt;So people don't think I'm cheating I'll first verify that the Recycle Bin is not enabled by using the powershell command  &lt;i&gt;Get-ADOptionalFeature -Filter {name -like "*Recycle Bin*"}&lt;/i&gt;   If EnabledScopes is empty that indicates the Recycle Bin has not been enabled.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-LUFfQFQqLfs/T1-6kfWFQVI/AAAAAAAAAt0/brPwEPOHdVc/s1600/4.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="163" src="http://4.bp.blogspot.com/-LUFfQFQqLfs/T1-6kfWFQVI/AAAAAAAAAt0/brPwEPOHdVc/s320/4.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;AD Recycle Bin not enabled&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;I also join the Windows Server 8 Beta machine to the domain.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-GDrufyrn_NA/T1-6K9GKLpI/AAAAAAAAAtk/bkg0A9w8vuQ/s1600/2.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="225" src="http://4.bp.blogspot.com/-GDrufyrn_NA/T1-6K9GKLpI/AAAAAAAAAtk/bkg0A9w8vuQ/s320/2.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Adding Windows 8 Server to the domain&lt;br /&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;Once the server is added to the USMCThanksForYourService.mil domain I have to install the Remote Server Administration Tools (RSAT) Feature for Active Directory so I can have access to the necessary AD tools and fetures.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-J9BMQrxBhg8/T1-7q3OVfKI/AAAAAAAAAt8/SmfDGrQ3kFI/s1600/3.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="129" src="http://1.bp.blogspot.com/-J9BMQrxBhg8/T1-7q3OVfKI/AAAAAAAAAt8/SmfDGrQ3kFI/s320/3.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Adding Roles and Features in Server Manager&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-x_V3crEkQqM/T1-9B092FMI/AAAAAAAAAus/vj4iedDSIkg/s1600/5.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="233" src="http://3.bp.blogspot.com/-x_V3crEkQqM/T1-9B092FMI/AAAAAAAAAus/vj4iedDSIkg/s320/5.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Adding RSAT Features&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-FSEmh-jJ7KM/T1_tlf_bJ2I/AAAAAAAAAvk/CmK_p0oOv3k/s1600/6.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="234" src="http://1.bp.blogspot.com/-FSEmh-jJ7KM/T1_tlf_bJ2I/AAAAAAAAAvk/CmK_p0oOv3k/s320/6.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Adding RSAT Features Part II&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;Once the RSAT tools have been installed you are ready to use Active Directory Administrative Center (ADAC) against your 2008 R2 domain.&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;You can enable the AD Recycle Bin from the GUI now instead of the old way&lt;a href="http://technet.microsoft.com/en-us/library/dd379481(v=ws.10).aspx"&gt; using Powershell&amp;nbsp;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-25iKaK5yxC0/T1_uWS8ZE1I/AAAAAAAAAv0/-czIWEcvOyI/s1600/7.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="148" src="http://3.bp.blogspot.com/-25iKaK5yxC0/T1_uWS8ZE1I/AAAAAAAAAv0/-czIWEcvOyI/s320/7.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Selecting ADAC from Server Manager in&amp;nbsp;Windows&amp;nbsp;8&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-R7cBeb8wYMc/T1_uQ2NDuhI/AAAAAAAAAvs/zswr8qNG0L8/s1600/8.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="170" src="http://1.bp.blogspot.com/-R7cBeb8wYMc/T1_uQ2NDuhI/AAAAAAAAAvs/zswr8qNG0L8/s320/8.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Enabling the AD Recycle Bin from Windows Server 8 Member Server ADAC&lt;br /&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-sd3vPXy7tGo/T1_umckENoI/AAAAAAAAAv8/0jfpjNPp4ak/s1600/9.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="117" src="http://4.bp.blogspot.com/-sd3vPXy7tGo/T1_umckENoI/AAAAAAAAAv8/0jfpjNPp4ak/s320/9.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;AD Recycle Bin Confirmation 1&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-YB2CGs7T-mM/T1_vGcois7I/AAAAAAAAAwM/YlnfETxFyrQ/s1600/10.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="140" src="http://2.bp.blogspot.com/-YB2CGs7T-mM/T1_vGcois7I/AAAAAAAAAwM/YlnfETxFyrQ/s320/10.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;span style="font-size: 13px;"&gt;AD Recycle Bin Confirmation 2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;Just want to confirm that the AD Recycle Bin has been enabled. &amp;nbsp;Notice this time the same command yielded an entry in "EnabledScopes"...success&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-xYybVv4mj68/T1_v-Gu1-0I/AAAAAAAAAwU/RXReuJOLwjU/s1600/11.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="151" src="http://2.bp.blogspot.com/-xYybVv4mj68/T1_v-Gu1-0I/AAAAAAAAAwU/RXReuJOLwjU/s320/11.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;AD Recycle Bin Enabled - Confirmation&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div&gt;&amp;nbsp;A quick tutorial of the new feature now that it is enabled and the member server is up and ready to go.&lt;span style="font-size: xx-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;As you can see there is a user named &lt;a href="http://en.wikipedia.org/wiki/Dakota_Meyer"&gt;Dakota Meyer&lt;/a&gt; who is in the group "MedalofHonor"&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-JwC5oqCLsSo/T1_wlB0YfZI/AAAAAAAAAwc/otIhXPdell4/s1600/12.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="285" src="http://3.bp.blogspot.com/-JwC5oqCLsSo/T1_wlB0YfZI/AAAAAAAAAwc/otIhXPdell4/s320/12.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;A young contractor was really excited and lost his mind and accidentally deleted the account. &amp;nbsp; Luckily the USMC leadership had allowed this Windows 8 Member Server and Dakota's account would be restored in a few clicks.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-Ce4EmTGDhiY/T1_xLt4ZQgI/AAAAAAAAAwk/BFVk_XkvpwQ/s1600/13.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="203" src="http://3.bp.blogspot.com/-Ce4EmTGDhiY/T1_xLt4ZQgI/AAAAAAAAAwk/BFVk_XkvpwQ/s320/13.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;In ADAC Navigate to the Deleted Objects Container&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-bGIit8mIxyw/T1_x2uv8vAI/AAAAAAAAAws/0U-eQYgM6wQ/s1600/14.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="133" src="http://3.bp.blogspot.com/-bGIit8mIxyw/T1_x2uv8vAI/AAAAAAAAAws/0U-eQYgM6wQ/s320/14.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Notice the deleted user is listed. &amp;nbsp;Right click on the user for Restore Options&lt;br /&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-v_VfmYZ5RCM/T1_0OJFtUfI/AAAAAAAAAw0/l2cp6iG9KE4/s1600/15.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="175" src="http://4.bp.blogspot.com/-v_VfmYZ5RCM/T1_0OJFtUfI/AAAAAAAAAw0/l2cp6iG9KE4/s320/15.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;In ADAC we confirm that the user has been successfully restored&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-6gUdkM66Aec/T1_0VZ_ifNI/AAAAAAAAAw8/vccrrvOXyKY/s1600/16.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="161" src="http://2.bp.blogspot.com/-6gUdkM66Aec/T1_0VZ_ifNI/AAAAAAAAAw8/vccrrvOXyKY/s320/16.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;span style="font-size: x-small;"&gt;On the 2008 R2 DC the restore is confirmed using ADUC&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7365513794075231499-3151718695107298413?l=adisfun.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://adisfun.blogspot.com/feeds/3151718695107298413/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://adisfun.blogspot.com/2012/03/windows-server-8-member-server-adac.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/3151718695107298413" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/3151718695107298413" /><link rel="alternate" type="text/html" href="http://adisfun.blogspot.com/2012/03/windows-server-8-member-server-adac.html" title="Windows Server 8 Member Server - ADAC Recycle Bin" /><author><name>mkline</name><uri>http://www.blogger.com/profile/03770498033295580147</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-Yz9kzkyICkU/T1-4-O04r-I/AAAAAAAAAtc/XaTsqxRfg-A/s72-c/1.png" height="72" width="72" /><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7365513794075231499.post-3707946095223328844</id><published>2012-03-13T11:55:00.001-07:00</published><updated>2012-03-13T11:56:37.274-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="quick-hitters" /><category scheme="http://www.blogger.com/atom/ns#" term="Windows 8 Beta" /><title type="text">Windows Server 8 Beta - Schema Version - Update</title><content type="html">I previously posted a "quick-hitter" blog about the &lt;a href="http://adisfun.blogspot.com/2011/09/windows-server-8-schema-version-quick.html"&gt;Active Directory Schema version in Windows 8 Developers Preview.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Windows Server 8 Beta has been out for over a week now and I have a domain controller in my lab for testing. &amp;nbsp;The schema version is now &lt;span style="color: red; font-size: large;"&gt;&lt;b&gt;52&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red; font-size: large;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;I once again used &lt;a href="http://www.joeware.net/freetools/tools/adfind/index.htm"&gt;adfind&lt;/a&gt;&amp;nbsp;to quickly find the schema version.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-r8iYXTmsGps/T1-XErk7qnI/AAAAAAAAAtU/dNtd44Om0eQ/s1600/Windows+8+Beta+Schema.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="141" src="http://3.bp.blogspot.com/-r8iYXTmsGps/T1-XErk7qnI/AAAAAAAAAtU/dNtd44Om0eQ/s320/Windows+8+Beta+Schema.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;I've updated the Active Directory Schema version table below.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;table border="1" bordercolor="#990000" cellpadding="3" cellspacing="3" style="background-color: #33ff99; font-family: Verdana, Arial, sans-serif; font-size: 13px; line-height: 16px; text-align: left; width: 400px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;b&gt;&lt;span style="color: #cc0000;"&gt;Windows Server 8 Beta&lt;/span&gt;&lt;/b&gt;&lt;/td&gt;&lt;td&gt;&lt;b&gt;&lt;span style="color: #cc0000;"&gt;52&lt;/span&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Windows 2008 R2&lt;/td&gt;&lt;td&gt;47&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Windows 2008&lt;/td&gt;&lt;td&gt;44&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Windows 2003 R2&lt;/td&gt;&lt;td&gt;31&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Windows 2003&lt;/td&gt;&lt;td&gt;30&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Windows 2000&lt;/td&gt;&lt;td&gt;13&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7365513794075231499-3707946095223328844?l=adisfun.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://adisfun.blogspot.com/feeds/3707946095223328844/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://adisfun.blogspot.com/2012/03/windows-server-8-beta-schema-version.html#comment-form" title="4 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/3707946095223328844" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/3707946095223328844" /><link rel="alternate" type="text/html" href="http://adisfun.blogspot.com/2012/03/windows-server-8-beta-schema-version.html" title="Windows Server 8 Beta - Schema Version - Update" /><author><name>mkline</name><uri>http://www.blogger.com/profile/03770498033295580147</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-r8iYXTmsGps/T1-XErk7qnI/AAAAAAAAAtU/dNtd44Om0eQ/s72-c/Windows+8+Beta+Schema.png" height="72" width="72" /><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7365513794075231499.post-5488649157316817785</id><published>2012-03-13T07:33:00.001-07:00</published><updated>2012-03-13T07:43:06.508-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Windows 8" /><category scheme="http://www.blogger.com/atom/ns#" term="vmware" /><title type="text">Windows Server 8 Beta and VMware Tools</title><content type="html">I am running VMware workstation 8.0.2 build-591240 to test Windows Server 8 Beta. &amp;nbsp;I'm doing this on my Windows 7 machine. &amp;nbsp;Right now there is no Microsoft hypervisor that runs on top of Windows 7/client OS that will support a 64 bit operating system (&lt;a href="http://blogs.msdn.com/b/b8/archive/2011/09/07/bringing-hyper-v-to-windows-8.aspx"&gt;that changes with Windows 8&lt;/a&gt;)&lt;br /&gt;&lt;br /&gt;The installation of Windows Server 8 Beta went fine and I had no issues with that. &amp;nbsp;I then tried to install &lt;a href="http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&amp;amp;cmd=displayKC&amp;amp;externalId=340"&gt;VMware Tools&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;After the installation of VMWare tools the Windows Server 8 Beta box became unresponsive and the screen was black and the VM was unusable. &amp;nbsp;I had a snapshot so I went back to that and was able to work and test.&lt;br /&gt;&lt;br /&gt;I looked around the VMware site and found a blog entry about running &lt;a href="http://blogs.vmware.com/workstation/2012/03/windows-8-consumer-preview-running-in-workstation-8.html"&gt;Windows 8 CP in Workstation 8&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;That didn't really help because my issue is with Windows Server 8. &amp;nbsp;I started reading the comments and noticed that there were others having this exact issue. &amp;nbsp;Some folks suggested enabling 3D Acceleration on the VM.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-Ebn5MQiiHKM/T19Z8GHONhI/AAAAAAAAAtI/QkwTXxhXdz4/s1600/3D+Acceleration.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="235" src="http://2.bp.blogspot.com/-Ebn5MQiiHKM/T19Z8GHONhI/AAAAAAAAAtI/QkwTXxhXdz4/s320/3D+Acceleration.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;I enabled the feature and then installed VMware tools again and this time the VM booted up fine. &amp;nbsp;No black/unresponsive screen. &lt;br /&gt;&lt;br /&gt;I hope this helps others trying to install VMWare tools with Windows Server 8.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7365513794075231499-5488649157316817785?l=adisfun.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://adisfun.blogspot.com/feeds/5488649157316817785/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://adisfun.blogspot.com/2012/03/windows-server-8-beta-and-vmware-tools.html#comment-form" title="8 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/5488649157316817785" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/5488649157316817785" /><link rel="alternate" type="text/html" href="http://adisfun.blogspot.com/2012/03/windows-server-8-beta-and-vmware-tools.html" title="Windows Server 8 Beta and VMware Tools" /><author><name>mkline</name><uri>http://www.blogger.com/profile/03770498033295580147</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-Ebn5MQiiHKM/T19Z8GHONhI/AAAAAAAAAtI/QkwTXxhXdz4/s72-c/3D+Acceleration.png" height="72" width="72" /><thr:total>8</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7365513794075231499.post-6261242099686252413</id><published>2012-03-09T09:18:00.003-08:00</published><updated>2012-03-09T09:21:57.449-08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Windows 8 Beta" /><category scheme="http://www.blogger.com/atom/ns#" term="Active Directory" /><title type="text">Windows Server 8 DCPromo Error - FIXED</title><content type="html">In a &lt;a href="http://adisfun.blogspot.com/2011/09/windows-server-8-active-directory.html"&gt;previous post&amp;nbsp;&lt;/a&gt;&amp;nbsp;I showed that there was an error if trying to set the forest and domain functional levels to Windows 8 during DCPROMO using Windows 8 Developers Preview.&lt;br /&gt;&lt;br /&gt;Now that &lt;a href="http://blogs.msdn.com/b/b8/archive/2012/02/29/welcome-to-windows-8-the-consumer-preview.aspx"&gt;Windows Server 8 Beta/Consumer Release Preview has been released&lt;/a&gt;&amp;nbsp;I tested the promotion process again.&lt;br /&gt;&lt;br /&gt;I once again selected Windows Sever 8 for my functional levels&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-_VW3FwGJGdM/T1o6pU4gscI/AAAAAAAAAso/jGlneYksR2o/s1600/Windows+8+Functional+Level.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="234" src="http://4.bp.blogspot.com/-_VW3FwGJGdM/T1o6pU4gscI/AAAAAAAAAso/jGlneYksR2o/s320/Windows+8+Functional+Level.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;I am very pleased to report that I no longer receive the same error that I mentioned with Windows Server 8 Developers Preview.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;After the promotion is done the Functional Levels are set to Windows Server 8&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-E4GNjip3tBw/T1o69MuxhYI/AAAAAAAAAsw/2MwRzKY15b8/s1600/Windows+8+Functional+Level+2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="170" src="http://3.bp.blogspot.com/-E4GNjip3tBw/T1o69MuxhYI/AAAAAAAAAsw/2MwRzKY15b8/s320/Windows+8+Functional+Level+2.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-14BrK-caC3w/T1o7JAZHOEI/AAAAAAAAAs4/kTjcO3FQU-I/s1600/Windows+8+Functional+Level+3.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="171" src="http://2.bp.blogspot.com/-14BrK-caC3w/T1o7JAZHOEI/AAAAAAAAAs4/kTjcO3FQU-I/s320/Windows+8+Functional+Level+3.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Nice job with the fix Microsoft AD Team! &amp;nbsp;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;I don't have a comprehensive list of features that are&amp;nbsp;dependent&amp;nbsp;on Windows Server 8 functional levels (forest &amp;amp; domain). &amp;nbsp;When I have that list I'll post it.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Enjoy Windows Server 8 Beta!&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7365513794075231499-6261242099686252413?l=adisfun.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://adisfun.blogspot.com/feeds/6261242099686252413/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://adisfun.blogspot.com/2012/03/windows-server-8-dcpromo-error-fixed.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/6261242099686252413" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/6261242099686252413" /><link rel="alternate" type="text/html" href="http://adisfun.blogspot.com/2012/03/windows-server-8-dcpromo-error-fixed.html" title="Windows Server 8 DCPromo Error - FIXED" /><author><name>mkline</name><uri>http://www.blogger.com/profile/03770498033295580147</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-_VW3FwGJGdM/T1o6pU4gscI/AAAAAAAAAso/jGlneYksR2o/s72-c/Windows+8+Functional+Level.png" height="72" width="72" /><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7365513794075231499.post-5669772000858576119</id><published>2012-02-03T09:52:00.000-08:00</published><updated>2012-02-03T18:04:49.545-08:00</updated><title type="text">Goodbye Old Friend</title><content type="html">Last night I had to do one of the toughest things any pet owner ever has to do and that is to make the decision to put my cat down.&lt;br /&gt;&lt;br /&gt;My cat was 20 years old and I'd had her for the last 12. &amp;nbsp;She was battling the final stages of kidney failure and had&amp;nbsp;deteriorated&amp;nbsp;badly over the last few days. &amp;nbsp;She also had a small mass in her stomach that was probably cancer. I could have tried to give her more time by giving her IV fluids at home but nothing was guaranteed and I didn't want to put either of us through that. &lt;br /&gt;&lt;br /&gt;Growing up I always thought of myself as a dog person. &amp;nbsp;My good friend John and his wife were starting a family in the late 90's and had two cats that they could no longer give all their attention to. &amp;nbsp;I'm not sure how the discussion happened but my brother and I took them both in. &amp;nbsp;At the time we were living in a shitty apartment but had room for them. &amp;nbsp;It ended up being one of the best&amp;nbsp;decisions&amp;nbsp;I've ever made.&lt;br /&gt;&lt;br /&gt;Growing up as dog owners we didn't know what cats were like but they both ended up being really great pets. &amp;nbsp;Cats are definitely easier than dogs to take care of and yes although they worked and played on their&amp;nbsp;schedule&amp;nbsp;they still gave the same unconditional love that any beloved pet gives. &amp;nbsp;That is probably the greatest thing about a pet. You give them some attention and care for them and they return it back ten fold.&lt;br /&gt;&lt;br /&gt;Max is one of the final links to my youth. &amp;nbsp;When we got her I was recently out of the Army. &amp;nbsp;My brother and I were both starting out with entry level jobs at the time and 12 years later so much has changed but Max was the one constant and I'll miss that a lot. Looking back&amp;nbsp;Max and her sister who died four years earlier taught me that I'm actually a dog &amp;amp; cat person.&lt;br /&gt;&lt;br /&gt;I don't know when or if I'll get another pet. Losing them is so tough. I hate going through this every time but I remember all the good years.&lt;br /&gt;&lt;br /&gt;My girlfriend Michelle went with me last night and I can't repay or thank her for doing that. &amp;nbsp;It's tough times like that when you really see what a person is made of and she was there for me. &amp;nbsp;Also a special thanks to Dr. Reese at &lt;a href="http://tlcvets.com/emergency"&gt;TLC in Leesburg, VA&lt;/a&gt;&amp;nbsp; Dr. Reese is a cat owner and lover herself and was very caring and&amp;nbsp;compassionate&amp;nbsp;with Max until the end. &amp;nbsp;I have no idea how Vets deal with that day in and day out but I'm very glad there are those that go into that profession.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;&lt;span style="color: blue;"&gt;Goodbye Old&amp;nbsp;Friend...Thanks for always being there.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-rcktg37ypu4/TywbbffPRBI/AAAAAAAAArU/7cbKu0c-sqk/s1600/max.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="240" src="http://4.bp.blogspot.com/-rcktg37ypu4/TywbbffPRBI/AAAAAAAAArU/7cbKu0c-sqk/s320/max.jpg" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Max&lt;br /&gt;1992 - Feb 2, 2012&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7365513794075231499-5669772000858576119?l=adisfun.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://adisfun.blogspot.com/feeds/5669772000858576119/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://adisfun.blogspot.com/2012/02/goodbye-old-friend.html#comment-form" title="3 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/5669772000858576119" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/5669772000858576119" /><link rel="alternate" type="text/html" href="http://adisfun.blogspot.com/2012/02/goodbye-old-friend.html" title="Goodbye Old Friend" /><author><name>mkline</name><uri>http://www.blogger.com/profile/03770498033295580147</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-rcktg37ypu4/TywbbffPRBI/AAAAAAAAArU/7cbKu0c-sqk/s72-c/max.jpg" height="72" width="72" /><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7365513794075231499.post-1314184211286576383</id><published>2011-10-18T11:01:00.000-07:00</published><updated>2012-01-26T10:41:49.477-08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="quick-hitters" /><category scheme="http://www.blogger.com/atom/ns#" term="adfind" /><category scheme="http://www.blogger.com/atom/ns#" term="Active Directory" /><title type="text">Find Non Replicated Attributes in Active Directory</title><content type="html">The quick hitter series is back and this entry was inspired by a colleague (thanks Funk!)&lt;br /&gt;&lt;br /&gt;If you are querying AD you may get inaccurate results if you are querying an attribute that is not replicated between all domain controllers. &amp;nbsp; Two common attributes I see people having issues with are lastlogon and whenchanged. &amp;nbsp;The issue here is suppose you query for lastlogon and get a value. &amp;nbsp;That may not be accurate as there may be a newer value on another DC. &amp;nbsp;On a side note for that issue lastlogontimestamp is usually good enough for most folks...but I digress.&lt;br /&gt;&lt;br /&gt;Is there a way to find what attributes are not replicated between DCs? &amp;nbsp;The answer to that is yes and there are various methods to find this&amp;nbsp;information. &amp;nbsp;I once again go to the great &lt;a href="http://www.joeware.net/freetools/tools/adfind/index.htm"&gt;ADFIND&lt;/a&gt; tool from &lt;a href="https://mvp.support.microsoft.com/profile/Joe"&gt;MVP Joe Richards&lt;/a&gt;&amp;nbsp; &amp;nbsp;Joe was recently awarded the MVP for the 10th straight year and that is well deserved.&lt;br /&gt;&lt;br /&gt;Adfind has a ton of great shortcuts and one of them is to find non-replicated attributes.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;b&gt;adfind -sc norepl cn -nodn&lt;/b&gt;&lt;/blockquote&gt;&lt;br /&gt;I only outputted the cn of the object and didn't need the distinguished name so left that off with -nodn&lt;br /&gt;&lt;br /&gt;You can see part of the output below. &amp;nbsp;Notice&amp;nbsp;the whenchanged attribute that was mentioned earlier.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-r6Zn9c_1zQ8/Tp29QG5_UNI/AAAAAAAAAn4/IGH1HW9dhAQ/s1600/nonreplicated.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://3.bp.blogspot.com/-r6Zn9c_1zQ8/Tp29QG5_UNI/AAAAAAAAAn4/IGH1HW9dhAQ/s320/nonreplicated.jpg" width="203" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://msdn.microsoft.com/en-us/library/windows/desktop/ms680022(v=vs.85).aspx"&gt;systemFlags &lt;/a&gt;contains a flag that defines if an attribute is replicated. &amp;nbsp;As you can see in the link if the value 1 is applied to an attribute it will not be replicated. &amp;nbsp;So you could also get fancy with adfind and do something like&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;b&gt;adfind -schema -bit -f &amp;nbsp;"&amp;amp;(objectclass=attributeschema)(systemflags:AND:=1)" cn -nodn&lt;/b&gt;&lt;/blockquote&gt;That should give you the exact same result as the previous command. &amp;nbsp;I'd personally always go with the shortcuts...they are there to make things easier...thanks Joe :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7365513794075231499-1314184211286576383?l=adisfun.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://adisfun.blogspot.com/feeds/1314184211286576383/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://adisfun.blogspot.com/2011/10/find-non-replicated-attributes-in.html#comment-form" title="5 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/1314184211286576383" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/1314184211286576383" /><link rel="alternate" type="text/html" href="http://adisfun.blogspot.com/2011/10/find-non-replicated-attributes-in.html" title="Find Non Replicated Attributes in Active Directory" /><author><name>mkline</name><uri>http://www.blogger.com/profile/03770498033295580147</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-r6Zn9c_1zQ8/Tp29QG5_UNI/AAAAAAAAAn4/IGH1HW9dhAQ/s72-c/nonreplicated.jpg" height="72" width="72" /><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7365513794075231499.post-5160117320068061384</id><published>2011-09-26T12:17:00.000-07:00</published><updated>2011-09-26T12:21:43.484-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Windows 8" /><title type="text">Windows Server 8 - GUI on GUI Off</title><content type="html">Before I start I'd love to hear comments on this feature in Windows 8. &amp;nbsp;Do you all think it is a feature that will be widely&amp;nbsp;adopted?&lt;br /&gt;&lt;br /&gt;This entry is about a new feature in Windows Server 8. &amp;nbsp;The ability to turn on and turn off the graphical shell.&lt;br /&gt;&lt;br /&gt;Prior to Windows 2008 there was no Windows OS that didn't feature a full GUI. &amp;nbsp;Linux folks would often criticize Windows admins for not being talented around the command line. &amp;nbsp;That was true to some extent but there are a lot of Windows admins/engineers who are comfortable around the command line but there were tasks that could only be done via the GUI or were much easier from the GUI.&lt;br /&gt;&lt;br /&gt;In Windows 2008 a new feature was introduced called &lt;a href="http://technet.microsoft.com/en-us/library/cc753802(WS.10).aspx"&gt;server core&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Verdana, Arial, Helvetica, sans-serif;"&gt;&lt;i&gt;The Server Core installation option is an option that you can use for installing Windows Server&amp;nbsp;2008 &amp;nbsp;A Server Core installation provides a minimal environment for running specific server roles, which reduces the maintenance and management requirements and the attack surface for those server roles&lt;/i&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Server core was intimidating to a lot of Windows admins not used to administrating or configuring servers from the command line. &lt;br /&gt;&lt;br /&gt;Server core was also available in 2008 R2 and introduced a tool called &lt;a href="http://technet.microsoft.com/en-us/edge/Video/ff710829"&gt;sconfig&lt;/a&gt; which made configuration much easier. &amp;nbsp;&lt;a href="http://blogs.technet.com/b/server_core/archive/2008/11/13/server-core-changes-in-windows-server-2008-r2.aspx"&gt;Other features&lt;/a&gt;&amp;nbsp;such as powershell were also added in 2008 R2.&lt;br /&gt;&lt;br /&gt;There was no way to convert a server core to a full server if there was a feature that needed to be installed that core didn't support. &amp;nbsp;I'm not sure what the server core adoption rate was. I've seen people speculate 10-15% but have not seen official numbers from Microsoft.&lt;br /&gt;&lt;br /&gt;There are a lot of beneifts to server core including greatly reducing the number of reboots and patches needed. MVP Brian McCann has an &lt;a href="http://blogs.msmvps.com/ad/blog/2011/06/21/windows-server-2008-server-core-r2-reboot-avoidance/"&gt;excellent blog entry on Server Core&lt;/a&gt; with stats.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #494949; font-family: Verdana, Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;i&gt;“In some cases, customers can see up to a 60% reduction in patch requirements and the number of reboots on a monthly basis”&amp;nbsp; These are the numbers that back up statements such as that.&lt;/i&gt;&lt;/span&gt;&lt;/blockquote&gt;Server core is still an option in Windows Server 8. &lt;br /&gt;&lt;br /&gt;However for those that still are not comfortable with core there is an option to remove the GUI from a full installation of Windows 8. &lt;br /&gt;&lt;br /&gt;As Ned Pyle pointed out in the&lt;a href="http://blogs.technet.com/b/askds/archive/2011/09/17/windows-8-for-the-it-pro-the-new-plumbing.aspx#comments"&gt; comments of this AskDS blog&lt;/a&gt;&amp;nbsp;this feature is not quite server core. &amp;nbsp;Meaning using these steps doesn't turn your server into core but it does remove many of the GUI features. &amp;nbsp;You will no longer need to worry about admins surfing the internet from your servers. &amp;nbsp;This may end up being the preferred method for deploying Windows Server 8....time will tell.&lt;br /&gt;&lt;br /&gt;I first noticed the Server Graphical Shell in the Features list in Windows Server 8. &amp;nbsp;I had not seen this feature in the past.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-BRFr25jHpxE/ToDIloieGnI/AAAAAAAAAmM/ckJcbRhIP8M/s1600/1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://3.bp.blogspot.com/-BRFr25jHpxE/ToDIloieGnI/AAAAAAAAAmM/ckJcbRhIP8M/s320/1.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;The feature can be removed by just clearing the&amp;nbsp;check box&amp;nbsp;in the roles and features wizard from server&amp;nbsp;manager.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-w24cZ7cj8YU/ToDI8RDDVAI/AAAAAAAAAmQ/Xtuuoet0Uek/s1600/2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="211" src="http://1.bp.blogspot.com/-w24cZ7cj8YU/ToDI8RDDVAI/AAAAAAAAAmQ/Xtuuoet0Uek/s320/2.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-vCnOlxHVKco/ToDJBlLAK0I/AAAAAAAAAmU/ofDj-zt5JL4/s1600/4.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="234" src="http://4.bp.blogspot.com/-vCnOlxHVKco/ToDJBlLAK0I/AAAAAAAAAmU/ofDj-zt5JL4/s320/4.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;I've unchecked the box in order to remove the Graphical Shell.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-PCPMhaVSXzE/ToDJQOZd2rI/AAAAAAAAAmY/pocJ_M8k3IE/s1600/5.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="234" src="http://1.bp.blogspot.com/-PCPMhaVSXzE/ToDJQOZd2rI/AAAAAAAAAmY/pocJ_M8k3IE/s320/5.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;After the server is rebooted and comes back up the GUI shell is gone. &amp;nbsp;Server manager is still available. &amp;nbsp;Things like the MetroUI are now gone.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-n9oIoKUAT-Q/ToDJh5PqZpI/AAAAAAAAAmc/VS7nTKsAaM4/s1600/8.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="238" src="http://3.bp.blogspot.com/-n9oIoKUAT-Q/ToDJh5PqZpI/AAAAAAAAAmc/VS7nTKsAaM4/s320/8.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;For fun I tried to surf the net using Internet Explorer&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-GJ1NUhq1FfU/ToDJrI0sErI/AAAAAAAAAmg/UGjet9dVzck/s1600/9.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="105" src="http://4.bp.blogspot.com/-GJ1NUhq1FfU/ToDJrI0sErI/AAAAAAAAAmg/UGjet9dVzck/s320/9.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;Items like the MMC and snap-in can be added. &amp;nbsp;The server can also be manged remotely.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-btFAN6mjKlg/ToDJ4gYbX1I/AAAAAAAAAmk/oZCXt8U5lVA/s1600/10.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="254" src="http://4.bp.blogspot.com/-btFAN6mjKlg/ToDJ4gYbX1I/AAAAAAAAAmk/oZCXt8U5lVA/s320/10.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Suppose an admin later decides later that they want this feature back. &amp;nbsp;It is just as easy as removing except this time the box is checked to add the feature&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-US1QzYciwWM/ToDK6NCJUUI/AAAAAAAAAms/iqei7Q1T8W8/s1600/12.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="288" src="http://4.bp.blogspot.com/-US1QzYciwWM/ToDK6NCJUUI/AAAAAAAAAms/iqei7Q1T8W8/s400/12.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;After a reboot the GUI shell is back.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-TFm66rLDkJY/ToDLKPy9GsI/AAAAAAAAAm0/0fCmSZud9so/s1600/14.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="298" src="http://4.bp.blogspot.com/-TFm66rLDkJY/ToDLKPy9GsI/AAAAAAAAAm0/0fCmSZud9so/s400/14.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;For those that prefer PowerShell this can also be done in a few lines via PowerShell&lt;br /&gt;&lt;br /&gt;I import the server manager module and viewed the features (not required)&lt;br /&gt;&lt;br /&gt;From there it is as simple as remove-windowsfeature server-gui-shell&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-zWSbUskz668/ToDL2lnCYuI/AAAAAAAAAm8/P3ojhfUg9yg/s1600/15.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="156" src="http://3.bp.blogspot.com/-zWSbUskz668/ToDL2lnCYuI/AAAAAAAAAm8/P3ojhfUg9yg/s400/15.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-CcVT7dzodzI/ToDMAg7zLyI/AAAAAAAAAnE/iGqVJ1T-oE4/s1600/16.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="293" src="http://4.bp.blogspot.com/-CcVT7dzodzI/ToDMAg7zLyI/AAAAAAAAAnE/iGqVJ1T-oE4/s400/16.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-VvExyGfu-H4/ToDME9Z7j1I/AAAAAAAAAnM/Uy0sRfAHUh4/s1600/18.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="293" src="http://1.bp.blogspot.com/-VvExyGfu-H4/ToDME9Z7j1I/AAAAAAAAAnM/Uy0sRfAHUh4/s400/18.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-pfWg9bFhuY8/ToDMJcjKN6I/AAAAAAAAAnU/jsvPA2cEDu0/s1600/19.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="292" src="http://2.bp.blogspot.com/-pfWg9bFhuY8/ToDMJcjKN6I/AAAAAAAAAnU/jsvPA2cEDu0/s400/19.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Adding it is just as easy...you guessed it &lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;add-windowsfeature Server-Gui-Shell&lt;/blockquote&gt;&lt;br /&gt;Again I'd like to hear comments on this feature. &amp;nbsp;Was it needed since we already have server core or is this a nice middle ground that will be widely adopted?&lt;br /&gt;&lt;br /&gt;Thanks for reading.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7365513794075231499-5160117320068061384?l=adisfun.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://adisfun.blogspot.com/feeds/5160117320068061384/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://adisfun.blogspot.com/2011/09/windows-server-8-gui-on-gui-off.html#comment-form" title="5 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/5160117320068061384" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/5160117320068061384" /><link rel="alternate" type="text/html" href="http://adisfun.blogspot.com/2011/09/windows-server-8-gui-on-gui-off.html" title="Windows Server 8 - GUI on GUI Off" /><author><name>mkline</name><uri>http://www.blogger.com/profile/03770498033295580147</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-BRFr25jHpxE/ToDIloieGnI/AAAAAAAAAmM/ckJcbRhIP8M/s72-c/1.png" height="72" width="72" /><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7365513794075231499.post-1042967419473566538</id><published>2011-09-21T09:08:00.000-07:00</published><updated>2011-09-21T09:08:43.881-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="DNS" /><category scheme="http://www.blogger.com/atom/ns#" term="Windows 8" /><category scheme="http://www.blogger.com/atom/ns#" term="Active Directory" /><title type="text">Windows Server 8 - DNS Management Console</title><content type="html">I have to begin this post with the normal caveat that this is only the developers preview build that I'm testing with and things may change.  &lt;br /&gt;&lt;br /&gt;When I promoted my Windows Server 8  to become a domain controller I also installed DNS.  As most people know AD has to have DNS in order to work.  Most places use Microsoft DNS but you can also use BIND and others but I decided to stick with Microsoft.&lt;br /&gt;&lt;br /&gt;After the DC was installed and rebooted I was able to access all the normal AD management consoles such as AD Users &amp; Computers, Sites and Services, Domains and Trusts, AD Administrative Center and others.&lt;br /&gt;&lt;br /&gt;I went to look at DNS and could not load the DNS management console.&lt;br /&gt;&lt;br /&gt;I verified that the DNS feature had been installed.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: ; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-pipkkdH4R1I/TnoI5RyfGcI/AAAAAAAAAkA/EplNXPqk5Zw/s1600/1.jpg" imageanchor="1" style="margin-left:1em; margin-right:1em"&gt;&lt;img border="0" height="260" width="400" src="http://1.bp.blogspot.com/-pipkkdH4R1I/TnoI5RyfGcI/AAAAAAAAAkA/EplNXPqk5Zw/s400/1.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;I tried to add the DNS console via the MMC snap-in but it was missing.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-GzIeeLsjiUg/TnoJV6EefuI/AAAAAAAAAkI/r3ltuIOSlgc/s1600/2.jpg" imageanchor="1" style="margin-left:1em; margin-right:1em"&gt;&lt;img border="0" height="279" width="400" src="http://2.bp.blogspot.com/-GzIeeLsjiUg/TnoJV6EefuI/AAAAAAAAAkI/r3ltuIOSlgc/s400/2.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;I tried to run the dnsmgmt.msc command and again no luck&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-J-p5EOhan6g/TnoJcUf32BI/AAAAAAAAAkQ/0inhhcwaQa4/s1600/3.jpg" imageanchor="1" style="margin-left:1em; margin-right:1em"&gt;&lt;img border="0" height="204" width="400" src="http://1.bp.blogspot.com/-J-p5EOhan6g/TnoJcUf32BI/AAAAAAAAAkQ/0inhhcwaQa4/s400/3.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;This could not be right and I had to be missing something.  I decided to go look into the roles and features.  Once again I verified that DNS was installed&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-AMz8PaTon7o/TnoJvDxZ8RI/AAAAAAAAAkY/qXm3L0kpN00/s1600/4.jpg" imageanchor="1" style="margin-left:1em; margin-right:1em"&gt;&lt;img border="0" height="282" width="400" src="http://2.bp.blogspot.com/-AMz8PaTon7o/TnoJvDxZ8RI/AAAAAAAAAkY/qXm3L0kpN00/s400/4.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;I went into the features and looked at the Remote Server Administration Tools(RSAT) settings.  I noticed that the DNS Server Tools were not checked/installed.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-bdMQhozkFZI/TnoKI8YloNI/AAAAAAAAAkg/9jb3fKUCsuE/s1600/5.jpg" imageanchor="1" style="margin-left:1em; margin-right:1em"&gt;&lt;img border="0" height="298" width="400" src="http://1.bp.blogspot.com/-bdMQhozkFZI/TnoKI8YloNI/AAAAAAAAAkg/9jb3fKUCsuE/s400/5.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;I checked the box to install the tools and just had to verify and install.  This feature did not require a server reboot.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-O1qPEzA1ePY/TnoKWsT_wTI/AAAAAAAAAko/DlFkqBeCUYI/s1600/6.jpg" imageanchor="1" style="margin-left:1em; margin-right:1em"&gt;&lt;img border="0" height="298" width="400" src="http://2.bp.blogspot.com/-O1qPEzA1ePY/TnoKWsT_wTI/AAAAAAAAAko/DlFkqBeCUYI/s400/6.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;I once again tried to add the DNS tools via the MMC snap-in and this time voila it was there&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-p8feO75DlUM/TnoKfnfYreI/AAAAAAAAAkw/uvgcZ44K0UY/s1600/8.jpg" imageanchor="1" style="margin-left:1em; margin-right:1em"&gt;&lt;img border="0" height="280" width="400" src="http://3.bp.blogspot.com/-p8feO75DlUM/TnoKfnfYreI/AAAAAAAAAkw/uvgcZ44K0UY/s400/8.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;I verified that dnsmgmt.msc would also work from the command line.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-q1mVZ_m3vmU/TnoKs1F5beI/AAAAAAAAAlA/pmVwB-4cqm0/s1600/7.jpg" imageanchor="1" style="margin-left:1em; margin-right:1em"&gt;&lt;img border="0" height="205" width="400" src="http://1.bp.blogspot.com/-q1mVZ_m3vmU/TnoKs1F5beI/AAAAAAAAAlA/pmVwB-4cqm0/s400/7.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;As you can see below the DNS management tools are now accessible and this is what it looks like in Windows Server 8 Developers Preview.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-iWWzZ9w348Q/TnoK7RZsaKI/AAAAAAAAAlI/lROVd2FddVU/s1600/9.jpg" imageanchor="1" style="margin-left:1em; margin-right:1em"&gt;&lt;img border="0" height="252" width="400" src="http://2.bp.blogspot.com/-iWWzZ9w348Q/TnoK7RZsaKI/AAAAAAAAAlI/lROVd2FddVU/s400/9.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7365513794075231499-1042967419473566538?l=adisfun.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://adisfun.blogspot.com/feeds/1042967419473566538/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://adisfun.blogspot.com/2011/09/windows-server-8-dns-management-console.html#comment-form" title="6 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/1042967419473566538" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/1042967419473566538" /><link rel="alternate" type="text/html" href="http://adisfun.blogspot.com/2011/09/windows-server-8-dns-management-console.html" title="Windows Server 8 - DNS Management Console" /><author><name>mkline</name><uri>http://www.blogger.com/profile/03770498033295580147</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-pipkkdH4R1I/TnoI5RyfGcI/AAAAAAAAAkA/EplNXPqk5Zw/s72-c/1.jpg" height="72" width="72" /><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7365513794075231499.post-4389667890803035470</id><published>2011-09-20T14:10:00.002-07:00</published><updated>2012-03-13T11:57:37.627-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="quick-hitters" /><category scheme="http://www.blogger.com/atom/ns#" term="adfind" /><category scheme="http://www.blogger.com/atom/ns#" term="Windows 8" /><title type="text">Windows Server 8 - Schema Version Quick Hitter</title><content type="html">&lt;span style="color: blue; font-size: large;"&gt;&lt;a href="http://adisfun.blogspot.com/2012/03/windows-server-8-beta-schema-version.html"&gt;THERE IS AN UPDATE TO THIS BLOG ENTRY&amp;nbsp;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;After being put on ice the quick hitter series is back.&lt;br /&gt;&lt;br /&gt;I downloaded one of my favorite active directory tools called &lt;a href="http://www.joeware.net/freetools/tools/adfind/index.htm"&gt;ADFIND&lt;/a&gt; from MVP &lt;a href="https://mvp.support.microsoft.com/profile/Joe"&gt;Joe Richards&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;So far adfind seems to work great with Windows Server 8.  I have not tested every switch but so far so good.  &lt;br /&gt;&lt;br /&gt;I really like the adfind shortucts and it is a great way to do things like quickly find the schema verision.   &lt;b&gt;adfind -sc schver&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-iBKHTKjWvYs/Tnj7L6_wbFI/AAAAAAAAAj4/Fm7SBTUhaWc/s1600/adfind%2Bwin8.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://2.bp.blogspot.com/-iBKHTKjWvYs/Tnj7L6_wbFI/AAAAAAAAAj4/Fm7SBTUhaWc/s400/adfind%2Bwin8.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;As you can see the schema version in Windows Server 8 Developers Preview is &lt;b&gt;&lt;span style="color: red;"&gt;51&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;There are other ways to find the schema version if you don't have adfind installed. Santhosh has a &lt;a href="http://portal.sivarajan.com/2010/03/active-directory-schema-version.html"&gt;good blog entry&lt;/a&gt; where he outlines other methods such as adsiedit and dsquery.&lt;br /&gt;&lt;br /&gt;If you are keeping track or are asked in a trivia/interview situation here are the AD schema versions throughout the OS Versions&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;br /&gt;&lt;table border="1" bordercolor="#990000" cellpadding="3" cellspacing="3" style="background-color: #33ff99; width: 400px;"&gt;&lt;tbody&gt;&lt;tr&gt;   &lt;td&gt;&lt;b&gt;&lt;span style="color: #cc0000;"&gt;Windows Server 8 Developers Preview&lt;/span&gt;&lt;/b&gt;&lt;/td&gt;   &lt;td&gt;&lt;b&gt;&lt;span style="color: #cc0000;"&gt;51&lt;/span&gt;&lt;/b&gt;&lt;/td&gt;  &lt;/tr&gt;&lt;tr&gt;   &lt;td&gt;Windows 2008 R2&lt;/td&gt;   &lt;td&gt;47&lt;/td&gt;  &lt;/tr&gt;&lt;tr&gt;   &lt;td&gt;Windows 2008&lt;/td&gt;   &lt;td&gt;44&lt;/td&gt;  &lt;/tr&gt;&lt;tr&gt;   &lt;td&gt;Windows 2003 R2&lt;/td&gt;   &lt;td&gt;31&lt;/td&gt;  &lt;/tr&gt;&lt;tr&gt;   &lt;td&gt;Windows 2003&lt;/td&gt;   &lt;td&gt;30&lt;/td&gt;  &lt;/tr&gt;&lt;tr&gt;   &lt;td&gt;Windows 2000&lt;/td&gt;   &lt;td&gt;13&lt;/td&gt;  &lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/center&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7365513794075231499-4389667890803035470?l=adisfun.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://adisfun.blogspot.com/feeds/4389667890803035470/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://adisfun.blogspot.com/2011/09/windows-server-8-schema-version-quick.html#comment-form" title="4 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/4389667890803035470" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/4389667890803035470" /><link rel="alternate" type="text/html" href="http://adisfun.blogspot.com/2011/09/windows-server-8-schema-version-quick.html" title="Windows Server 8 - Schema Version Quick Hitter" /><author><name>mkline</name><uri>http://www.blogger.com/profile/03770498033295580147</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-iBKHTKjWvYs/Tnj7L6_wbFI/AAAAAAAAAj4/Fm7SBTUhaWc/s72-c/adfind%2Bwin8.jpg" height="72" width="72" /><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7365513794075231499.post-4707903935602927653</id><published>2011-09-16T12:08:00.000-07:00</published><updated>2011-09-16T13:04:36.342-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="virtualization" /><category scheme="http://www.blogger.com/atom/ns#" term="Windows 8" /><category scheme="http://www.blogger.com/atom/ns#" term="Active Directory" /><title type="text">Windows Server 8 &amp; VMware Workstation</title><content type="html">In a &lt;a href="http://adisfun.blogspot.com/2011/09/installing-windows-8-developer-preview.html"&gt;previous post &lt;/a&gt; I outlined installing Windows Server 8 Developer preview and all the current testing and screenshots have been done in a &lt;a href="http://www.virtualbox.org/"&gt;virtual box &lt;/a&gt;environment.&lt;br /&gt;&lt;br /&gt;I also run VMware workstation and was running VMware workstation 7.1.  I currently don't have a dedicated Hyper-V box at home but that will change in the future when I'm running Windows 8 as my desktop OS.&lt;br /&gt;&lt;br /&gt;I tried installing Windows Server 8 on VMware 7.1&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-6NArXzXnzeY/TnOfsdLtkmI/AAAAAAAAAiA/joSDRWTqtao/s1600/vmware7%2Bfirst%2Bscreen.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 272px;" src="http://4.bp.blogspot.com/-6NArXzXnzeY/TnOfsdLtkmI/AAAAAAAAAiA/joSDRWTqtao/s400/vmware7%2Bfirst%2Bscreen.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5653037543376917090" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Initially it looked like it was going to start installing. Since Windows 8 was not an option I chose Windows 2008 R2 as the OS.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-2AwLgb9sT14/TnOgL5f0taI/AAAAAAAAAiI/dXXL8edeeZ4/s1600/vmware7%2Bsecond%2Bscreen.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 305px;" src="http://1.bp.blogspot.com/-2AwLgb9sT14/TnOgL5f0taI/AAAAAAAAAiI/dXXL8edeeZ4/s400/vmware7%2Bsecond%2Bscreen.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5653038083553408418" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-wjlPMNVZfF0/TnOgYDKz6GI/AAAAAAAAAiQ/Sx4Z1IF6nTI/s1600/windows7.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 295px;" src="http://1.bp.blogspot.com/-wjlPMNVZfF0/TnOgYDKz6GI/AAAAAAAAAiQ/Sx4Z1IF6nTI/s400/windows7.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5653038292308060258" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;As you can see I also tried Windows 7 with no luck.  I also tried other scenarios and they all didn't work.  I figured this was a pre-beta release of Windows 8 so no big deal but I was a bit disappointed.  If anyone has gotten this to work please comment.&lt;br /&gt;&lt;br /&gt;On Septmember 14 VMware released &lt;a href="http://www.vmware.com/products/workstation/new.html"&gt;Workstation 8&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I decided to spend the $99 for the upgrade.  Once I received the verification email I went to the download site and noticed there was only one executable for the full version and no upgrade version.  &lt;br /&gt;&lt;br /&gt;I wasn't sure if the full version would work or even let me download it.  The &lt;a href="https://twitter.com/#!/vmw_workstation"&gt;VMware workstation team on twitter&lt;/a&gt; was really helpful and let me know to install the full version.  It would uninstall 7.1 and then install 8.0 without losing any virtual machines. That worked fine so now the moment of truth would VMware workstation 8 support Windows Server 8 Developers Preview.&lt;br /&gt;&lt;br /&gt;I started off with a typical install &lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-a8DuFQ83ez4/TnOjSemGtcI/AAAAAAAAAiY/jVmtmIAQ86w/s1600/vm81.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 363px;" src="http://1.bp.blogspot.com/-a8DuFQ83ez4/TnOjSemGtcI/AAAAAAAAAiY/jVmtmIAQ86w/s400/vm81.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5653041495125964226" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This version still could not detect the OS but I'm guessing that will change in future release and as Windows 8 gets close to RTM.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-bDb81eeb4iI/TnOjhzfSVvI/AAAAAAAAAig/Zg75P_6l7KQ/s1600/vm83.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 363px;" src="http://3.bp.blogspot.com/-bDb81eeb4iI/TnOjhzfSVvI/AAAAAAAAAig/Zg75P_6l7KQ/s400/vm83.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5653041758432548594" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I chose Windows Server 2008 R2 as my guest OS.  &lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/-dPws7xYRkrI/TnOjtCr8PDI/AAAAAAAAAio/XUQCtaqWkKM/s1600/vm84.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 363px;" src="http://2.bp.blogspot.com/-dPws7xYRkrI/TnOjtCr8PDI/AAAAAAAAAio/XUQCtaqWkKM/s400/vm84.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5653041951490718770" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;There is no license key for this version of Windows 8 so that is left blank.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-BsmQJkTo2aQ/TnOkKC_HNtI/AAAAAAAAAiw/GJ3u3h1-FoU/s1600/vm85.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 363px;" src="http://1.bp.blogspot.com/-BsmQJkTo2aQ/TnOkKC_HNtI/AAAAAAAAAiw/GJ3u3h1-FoU/s400/vm85.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5653042449787336402" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/-LsDm4_bMO78/TnOkPdJDPuI/AAAAAAAAAi4/giy9A7eiIwM/s1600/vm86.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 268px; height: 182px;" src="http://2.bp.blogspot.com/-LsDm4_bMO78/TnOkPdJDPuI/AAAAAAAAAi4/giy9A7eiIwM/s400/vm86.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5653042542707687138" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I named my machine and set the location.  I just use an external drive attached via USB 3.0.  I would like a better storage system but I also don't want to break the bank.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-t_mQV4RFAdU/TnOkmTMR_4I/AAAAAAAAAjA/kuTMlZooJds/s1600/vm87.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 363px;" src="http://4.bp.blogspot.com/-t_mQV4RFAdU/TnOkmTMR_4I/AAAAAAAAAjA/kuTMlZooJds/s400/vm87.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5653042935173873538" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I gave myself 40 GB and finished the process of configuring the virtual machine.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-0mpCSbjY4po/TnOlEeSNEkI/AAAAAAAAAjQ/MI4WKMZKgns/s1600/vm89.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 363px;" src="http://4.bp.blogspot.com/-0mpCSbjY4po/TnOlEeSNEkI/AAAAAAAAAjQ/MI4WKMZKgns/s400/vm89.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5653043453547582018" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-tuFaidkx5jA/TnOlBF03czI/AAAAAAAAAjI/YlTnS511pEs/s1600/vm88.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 363px;" src="http://1.bp.blogspot.com/-tuFaidkx5jA/TnOlBF03czI/AAAAAAAAAjI/YlTnS511pEs/s400/vm88.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5653043395442471730" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;After reboot I was stuck in an endless loop telling me that the product key could not be read from the answer file.  This had me worried as there is no product key&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/-7JzR2oz1mN8/TnOlhdaDdgI/AAAAAAAAAjY/j1sXaEJOZD8/s1600/vm90.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 225px;" src="http://2.bp.blogspot.com/-7JzR2oz1mN8/TnOlhdaDdgI/AAAAAAAAAjY/j1sXaEJOZD8/s400/vm90.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5653043951528277506" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The endless loop was no fun so I shut the machine down and looked at the configuration again.  I noticed the floppy drive there and I definitely don't need that.  I removed the floppy drive&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-I0VHouBwpxw/TnOl6D3_XRI/AAAAAAAAAjg/KIyQL1p66SA/s1600/vm91.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 347px;" src="http://1.bp.blogspot.com/-I0VHouBwpxw/TnOl6D3_XRI/AAAAAAAAAjg/KIyQL1p66SA/s400/vm91.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5653044374171245842" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;After removal of the floppy drive the installation proceeded with no issues.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-1FGHiOWja-o/TnOmFjJRgGI/AAAAAAAAAjo/WHOK_65t4Dw/s1600/vm92.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 225px;" src="http://1.bp.blogspot.com/-1FGHiOWja-o/TnOmFjJRgGI/AAAAAAAAAjo/WHOK_65t4Dw/s400/vm92.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5653044571543797858" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;There are some features such as cloning that I like in VMware that I don't get in Virtualbox but both are adequate for testing Windows 8 right now.  &lt;br /&gt;&lt;br /&gt;Thanks to the &lt;a href="https://twitter.com/#!/vmw_workstation"&gt;@vmw_workstation&lt;/a&gt; guys for their tips.&lt;br /&gt;&lt;br /&gt;The normal caveat applies and that is that this is still a pre-beta release of Windows 8....but have fun.&lt;br /&gt;&lt;br /&gt;Not sure if I'll be going to VMware workstation 9 down the road.  I may have all Windows 8 boxes with Hyper-V by then :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7365513794075231499-4707903935602927653?l=adisfun.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://adisfun.blogspot.com/feeds/4707903935602927653/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://adisfun.blogspot.com/2011/09/windows-server-8-vmware-workstation.html#comment-form" title="5 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/4707903935602927653" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/4707903935602927653" /><link rel="alternate" type="text/html" href="http://adisfun.blogspot.com/2011/09/windows-server-8-vmware-workstation.html" title="Windows Server 8 &amp; VMware Workstation" /><author><name>mkline</name><uri>http://www.blogger.com/profile/03770498033295580147</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-6NArXzXnzeY/TnOfsdLtkmI/AAAAAAAAAiA/joSDRWTqtao/s72-c/vmware7%2Bfirst%2Bscreen.png" height="72" width="72" /><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7365513794075231499.post-8606780275370742247</id><published>2011-09-15T12:05:00.000-07:00</published><updated>2011-09-15T13:53:39.527-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="FGPP" /><category scheme="http://www.blogger.com/atom/ns#" term="Windows 8" /><category scheme="http://www.blogger.com/atom/ns#" term="New Features" /><category scheme="http://www.blogger.com/atom/ns#" term="Active Directory" /><title type="text">Windows Server 8 - Fine-Grained Password Policies</title><content type="html">&lt;span style="font-weight:bold;"&gt;BACKGROUND&lt;span style="font-style:italic;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;In the old days (Windows 2000 and Windows 2003) an Active Directory domain could only have one password and account lockout policy per domain for domain accounts.&lt;br /&gt;&lt;br /&gt;The group policy with the password settings had to be linked at the domain level(common method people used was to set the policy in the default domain policy).  &lt;br /&gt;&lt;br /&gt;What options where there if you wanted a different policy for certain users or certain groups?  For example what if you wanted service accounts to have a stricter policy? There were not many options.  Organizations could try and create their own filter (not recommended) or use a third party tool (not native, not cheap, and needs plenty of testing).&lt;br /&gt;&lt;br /&gt;In some cases organizations would create a new domain because they wanted different policies.  I was never involved in a new domain just for a password policy but I've heard of it happening.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;PASSWORD POLICIES IN WINDOWS 2008&lt;span style="font-style:italic;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Microsoft introduced a new feature in Windows 2008 called &lt;a href="http://technet.microsoft.com/en-us/library/cc770842(WS.10).aspx"&gt;Fine Grained Password Policies (FGPP)&lt;/a&gt;.  The domain functional level has to be at Windows 2008 for this feature to work.&lt;br /&gt;&lt;br /&gt;FGPP's allowed organizations to specify multiple password policies within a single domain.  You can use fine-grained password policies to apply different restrictions for password and account lockout policies to different sets of groups and users in a domain. &lt;br /&gt;&lt;br /&gt;The link above is a step by step guide for configuring FGPP's.  There are also some other good FGPP references that I refer to.&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;&lt;a href="http://blogs.technet.com/b/seanearp/archive/2007/10/06/windows-server-2008-fine-grained-password-policy-walkthrough.aspx"&gt;Sean's FGPP Walkthrough&lt;/a&gt;&lt;br /&gt;&lt;li&gt;Florian's &lt;a href="http://www.frickelsoft.net/blog/?p=54"&gt;Windows Server 2008 And Its FGPP's&lt;/a&gt;&lt;br /&gt;&lt;li&gt;Florian's &lt;a href="http://www.frickelsoft.net/blog/?p=57"&gt;How To Create FGPP Setting Objects&lt;/a&gt;&lt;br /&gt;&lt;/ul&gt;&lt;br /&gt;&lt;br /&gt;As you can see in Florian and Sean's great blog entries setting up fine-grained passwords was not the easiest thing to do.  Admins had to use ADSI Edit to configure it and the entire process was not admin/user friendly.  &lt;br /&gt;&lt;br /&gt;There were some third party tools that could make this process easier but again that involved another tool.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;WINDOWS SERVER 8 FGPP IMPLEMENTATION&lt;span style="font-style:italic;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;As noted in my &lt;a href="http://adisfun.blogspot.com/2011/09/windows-server-8-active-directory_14.html"&gt;previous post &lt;/a&gt; there are a lot of improvements in Windows Server 8.  Once again a feature is now exposed using the Active Directory Administrative Center (ADAC).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;To start open ADAC and navigate to the System container.  From there navigate to the Passwords Settings Container and right click and select New &gt; Password Settings&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-Zr3d8tNLLAk/TnJReodI_0I/AAAAAAAAAg8/ay29OsAYAjI/s1600/1.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 280px;" src="http://3.bp.blogspot.com/-Zr3d8tNLLAk/TnJReodI_0I/AAAAAAAAAg8/ay29OsAYAjI/s400/1.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5652670069000961858" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;As you can see I named my Password Setting Object(PSO) and I set a precedence level. Precedence is used if there are multiple PSO's applied, the lower precedent will win. I'd try to limit the number of PSO's in a domain.  &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I've set the minimum length at 14 which is more stringent/strict compared to my normal domain policy which is 8 characters.  I want the service accounts to have stronger passwords.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-TYSX7upMOn4/TnJSkUNvb0I/AAAAAAAAAhE/770c-Xt2efk/s1600/2.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 262px;" src="http://1.bp.blogspot.com/-TYSX7upMOn4/TnJSkUNvb0I/AAAAAAAAAhE/770c-Xt2efk/s400/2.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5652671266158505794" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Next I'm going to select "Add" in the Directly Applies to box.  In this example I am going to apply the PSO to a group named ServiceAccounts.  I could have also selected user accounts here.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/-7z6qu4x_8MA/TnJTHB5RiFI/AAAAAAAAAhM/3H2hL2lkLgs/s1600/3.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 274px;" src="http://2.bp.blogspot.com/-7z6qu4x_8MA/TnJTHB5RiFI/AAAAAAAAAhM/3H2hL2lkLgs/s400/3.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5652671862536243282" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Once I'm done with creating and applying the PSO to the group I can verify that the password is set.  I navigate to my Service account user that is a member of the ServiceAccount group.  I right click and select "View resultant password settings"&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/-w9QLfSVPTtk/TnJTfYQUz3I/AAAAAAAAAhU/p11NworgDgE/s1600/4.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 272px;" src="http://2.bp.blogspot.com/-w9QLfSVPTtk/TnJTfYQUz3I/AAAAAAAAAhU/p11NworgDgE/s400/4.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5652672280855367538" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The resultant password setting box is presented.  It returns the Service Accounts PSO that I created.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/-YWbO5qfQMlw/TnJT35UyfRI/AAAAAAAAAhc/qcsCVivlbRo/s1600/5.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 277px;" src="http://2.bp.blogspot.com/-YWbO5qfQMlw/TnJT35UyfRI/AAAAAAAAAhc/qcsCVivlbRo/s400/5.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5652672702049320210" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;There is also another option for user accounts.  In ADAC you will notice a Password Settings pane.  &lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-lqik-PclG1k/TnJUJiyltbI/AAAAAAAAAhk/5h-6hMrBG5w/s1600/6.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 313px;" src="http://4.bp.blogspot.com/-lqik-PclG1k/TnJUJiyltbI/AAAAAAAAAhk/5h-6hMrBG5w/s400/6.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5652673005237941682" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;PSOs can be directly assigned to user accounts.  I'd recommend using groups when possible but the option is there.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/-t6qysmw6dt0/TnJUWkOXaQI/AAAAAAAAAhs/91Ed4_U2sUE/s1600/7.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 267px;" src="http://2.bp.blogspot.com/-t6qysmw6dt0/TnJUWkOXaQI/AAAAAAAAAhs/91Ed4_U2sUE/s400/7.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5652673228961179906" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;So now the PSO is created in applied...but does it work.  Can I still use an 8 character password for this account?  If it worked correctly the 8 character password should no longer be accepted.  I tried a 10 character complex password&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-dJbshb060a4/TnJUqNmwUZI/AAAAAAAAAh0/Q4o8kJO7fHw/s1600/8.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 149px;" src="http://1.bp.blogspot.com/-dJbshb060a4/TnJUqNmwUZI/AAAAAAAAAh0/Q4o8kJO7fHw/s400/8.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5652673566486843794" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Success Full Success!!  It would be nice if the error message was more verbose.  For example telling the user that they need a 14 character password based off the PSO settings.&lt;br /&gt;&lt;br /&gt;One other area I think admins will continue to ask for is the ability to have a different password policy per OU (not just users and groups).  &lt;br /&gt;&lt;br /&gt;They can't get every feature into every release but this is a huge step forward. Nice job Microsoft AD Team!  I think this will help organizations and now more folks will use FGPP. (just remember the domain functional level has to be at 2008 or higher)&lt;br /&gt;&lt;br /&gt;Also remember this is a pre-Beta release so things can change.  Having said that Steve Ballmer said over 500,000 copies have already been downloaded....the WIndows 8 buzz is on for sure :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7365513794075231499-8606780275370742247?l=adisfun.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://adisfun.blogspot.com/feeds/8606780275370742247/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://adisfun.blogspot.com/2011/09/windows-server-8-fine-grained-password.html#comment-form" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/8606780275370742247" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/8606780275370742247" /><link rel="alternate" type="text/html" href="http://adisfun.blogspot.com/2011/09/windows-server-8-fine-grained-password.html" title="Windows Server 8 - Fine-Grained Password Policies" /><author><name>mkline</name><uri>http://www.blogger.com/profile/03770498033295580147</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-Zr3d8tNLLAk/TnJReodI_0I/AAAAAAAAAg8/ay29OsAYAjI/s72-c/1.jpg" height="72" width="72" /><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7365513794075231499.post-5631125047119680865</id><published>2011-09-14T13:30:00.001-07:00</published><updated>2011-09-14T14:41:14.844-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Windows 8" /><category scheme="http://www.blogger.com/atom/ns#" term="Active Directory" /><title type="text">Windows Server 8 - Active Directory Recycle Bin</title><content type="html">The active directory recycle bin was a welcome addition in 2008 R2.  Prior to Windows 2008 R2 there were no easy ways to fully restore an AD object and keep all their attributes intact.&lt;br /&gt;&lt;br /&gt;There was the &lt;a href="http://technet.microsoft.com/en-us/library/cc779573(WS.10).aspx"&gt;system state/authoritative restore method&lt;/a&gt;&lt;br /&gt;There was the &lt;a href="http://technet.microsoft.com/en-us/magazine/2007.09.tombstones.aspx"&gt;tombstone reanimation method&lt;/a&gt; that didn't restore all the attributes but it was fast.&lt;br /&gt;There were also some third party tools that could help.&lt;br /&gt;&lt;br /&gt;So the options were not great and recovering deleted objects could be a pain.  Admins rejoiced when they first heard of the AD recycle bin.  The forest functional level had to be at Windows 2008 R2 but it was a major incentive to get there.&lt;br /&gt;&lt;br /&gt;The AD recycle bin had to be enabled using Powershell and objects could only be restored using Powershell.  Microsoft released a good &lt;a href="http://technet.microsoft.com/en-us/library/dd392261(WS.10).aspx"&gt;AD recycle bin step by step guide&lt;/a&gt; for 2008 R2 &lt;br /&gt;&lt;br /&gt;Ned Pyle from the Microsoft AD team also had a great blog entry on the askds blog&lt;br /&gt;&lt;br /&gt;&lt;a href="The AD Recycle Bin: Understanding, Implementing, Best Practices, and Troubleshooting"&gt;The AD Recycle Bin: Understanding, Implementing, Best Practices, and Troubleshooting&lt;/a&gt;  &lt;br /&gt;Notice how to enable the feature and restore objects.&lt;br /&gt;&lt;br /&gt;There were third party tools that put a GUI wrapper around the recycle bin but I'm referring to a native build.&lt;br /&gt;&lt;br /&gt;So as you can see the AD Recycle Bin in 2008 R2 was very good step forward but it could be better.  The Microsoft AD team heard the need for improving the feature and the feature has been improved.&lt;br /&gt;&lt;br /&gt;It gets much better in Windows Server 8.  The Active Directory Administrative Center (ADAC) has a lot of improvements and one of the big ones is being able to restore objects from the GUI.  Powershell still works too but this will be easier for a lot of folks.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-j7WhZW9uUDQ/TnERr9mkDzI/AAAAAAAAAfw/msXFwrnPYr0/s1600/1.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 297px;" src="http://3.bp.blogspot.com/-j7WhZW9uUDQ/TnERr9mkDzI/AAAAAAAAAfw/msXFwrnPYr0/s400/1.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5652318454295039794" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The AD Recycle Bin can now be enabled from ADAC&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/--0O5No_moBc/TnESI8a9xhI/AAAAAAAAAf4/g50t9KyrVsI/s1600/2.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 300px;" src="http://4.bp.blogspot.com/--0O5No_moBc/TnESI8a9xhI/AAAAAAAAAf4/g50t9KyrVsI/s400/2.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5652318952194164242" /&gt;&lt;/a&gt;&lt;br /&gt;It can also be enabled by right clicking the domain and enabling it there&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-n-LOaNlPUU8/TnESb8UKc_I/AAAAAAAAAgA/8Kf8LK7ow9U/s1600/3.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 300px;" src="http://1.bp.blogspot.com/-n-LOaNlPUU8/TnESb8UKc_I/AAAAAAAAAgA/8Kf8LK7ow9U/s400/3.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5652319278583149554" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Warning alerting the user that once the Recycle Bin is enabled it can't be disabled...no turning back.&lt;br /&gt;&lt;br /&gt;Note:  In a production Windows Server 2008 R2 domain at Microsoft, the Active Directory Recycle Bin feature increased the size of the &lt;a href="http://technet.microsoft.com/en-us/library/cc753439(WS.10).aspx"&gt;AD DS database by an additional 15 to 20 percent of the original database size.  &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I'm guessing those stats are still accurate and will update the blog if I find out anything new.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-7D7Grd_TFfc/TnETOw0ZvRI/AAAAAAAAAgI/tlyZB7evaZY/s1600/4.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 180px;" src="http://4.bp.blogspot.com/-7D7Grd_TFfc/TnETOw0ZvRI/AAAAAAAAAgI/tlyZB7evaZY/s400/4.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5652320151670471954" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Once the enable recycle bin is chosen and the changes have replicated then the feature will work after a refresh of ADAC.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/-qJ1mV5n61M8/TnETfb0tyKI/AAAAAAAAAgQ/-Et84ZSEafI/s1600/5.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 311px; height: 400px;" src="http://2.bp.blogspot.com/-qJ1mV5n61M8/TnETfb0tyKI/AAAAAAAAAgQ/-Et84ZSEafI/s400/5.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5652320438092417186" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/-dkmc-wE3elU/TnETmDbChUI/AAAAAAAAAgY/0_F2uSsSjHc/s1600/6.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 324px; height: 400px;" src="http://2.bp.blogspot.com/-dkmc-wE3elU/TnETmDbChUI/AAAAAAAAAgY/0_F2uSsSjHc/s400/6.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5652320551801357634" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I have a test user with many attributes populated and a member of a group that I'm going to delete.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-l7mY8rEcvY8/TnETxLHEZ9I/AAAAAAAAAgg/nN8lgcgC6WA/s1600/7%2Bdelete.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 391px; height: 169px;" src="http://4.bp.blogspot.com/-l7mY8rEcvY8/TnETxLHEZ9I/AAAAAAAAAgg/nN8lgcgC6WA/s400/7%2Bdelete.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5652320742843639762" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;So now the user is deleted but how do I get it back.  In ADAC I navigate to the &lt;span style="font-weight:bold;"&gt;Deleted Objects Node&lt;/span&gt;.  As you can see the deleted user is there.  I can right click and restore the object, restore to another location, locate parent, or view properties.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/-KT7nz1jNZrk/TnEUIqCc1LI/AAAAAAAAAgo/70bjjTp1ztU/s1600/8.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 300px;" src="http://2.bp.blogspot.com/-KT7nz1jNZrk/TnEUIqCc1LI/AAAAAAAAAgo/70bjjTp1ztU/s400/8.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5652321146282759346" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The deleted objects node in ADAC is the new hotness :)&lt;br /&gt;&lt;br /&gt;As you can see I restored the object back to its original location and it is back with all attributes populated.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/-QoJel6fAy74/TnEUjMsqMqI/AAAAAAAAAgw/LkZ7cmaVHT0/s1600/9.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 268px;" src="http://2.bp.blogspot.com/-QoJel6fAy74/TnEUjMsqMqI/AAAAAAAAAgw/LkZ7cmaVHT0/s400/9.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5652321602263200418" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Anyone who has been in a pressure filled situation trying to get a user or object back in a hurry (especially if a VIP is involved) will really like this.  &lt;br /&gt;&lt;br /&gt;There will be follow ups to this post about other new features in ADAC and other test scenarios.  Job well done Microsoft AD Team!!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7365513794075231499-5631125047119680865?l=adisfun.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://adisfun.blogspot.com/feeds/5631125047119680865/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://adisfun.blogspot.com/2011/09/windows-server-8-active-directory_14.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/5631125047119680865" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/5631125047119680865" /><link rel="alternate" type="text/html" href="http://adisfun.blogspot.com/2011/09/windows-server-8-active-directory_14.html" title="Windows Server 8 - Active Directory Recycle Bin" /><author><name>mkline</name><uri>http://www.blogger.com/profile/03770498033295580147</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-j7WhZW9uUDQ/TnERr9mkDzI/AAAAAAAAAfw/msXFwrnPYr0/s72-c/1.jpg" height="72" width="72" /><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7365513794075231499.post-7849297006424621789</id><published>2011-09-14T09:15:00.001-07:00</published><updated>2012-03-13T18:56:38.595-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Windows 8" /><category scheme="http://www.blogger.com/atom/ns#" term="dcpromo" /><category scheme="http://www.blogger.com/atom/ns#" term="Active Directory" /><title type="text">Windows Server 8 - Active Directory DCPROMO error</title><content type="html">&lt;a href="http://adisfun.blogspot.com/2012/03/windows-server-8-dcpromo-error-fixed.html"&gt;UPDATE: &amp;nbsp;THIS HAS BEEN FIXED WITH THE RELEASE OF WINDOWS SERVER 8 BETA&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;In my &lt;a href="http://adisfun.blogspot.com/2011/09/installing-windows-8-developer-preview.html"&gt;previous post&lt;/a&gt; I went over installing my first Windows Server 8 box. &lt;br /&gt;&lt;br /&gt;Since one of my skill sets is Active Directory my next step was to promote this box to become a domain controller. &lt;br /&gt;&lt;br /&gt;As noted in the previous post this is an early pre-Beta release so there are going to be features that are not fully developed.  &lt;br /&gt;&lt;br /&gt;During dcpromo you can select your domain and forest functional levels.  &lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-yQ7Bb6X6udo/TnDWhudO_ZI/AAAAAAAAAfQ/q2_OaX0dBQ8/s1600/18.jpg"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5652253407244647826" src="http://3.bp.blogspot.com/-yQ7Bb6X6udo/TnDWhudO_ZI/AAAAAAAAAfQ/q2_OaX0dBQ8/s400/18.jpg" style="cursor: hand; cursor: pointer; display: block; height: 291px; margin: 0px auto 10px; text-align: center; width: 400px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Initially I was ready to go straight to Windows Server 8 levels and why not, it is a lab and we are all learning at this point.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-ZWMHCecuLjM/TnDWyKNNVpI/AAAAAAAAAfY/tNk69gwsPP4/s1600/19%2Bcomplex%2BPW%2Bonly%2Bfor%2Bnext.jpg"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5652253689571530386" src="http://4.bp.blogspot.com/-ZWMHCecuLjM/TnDWyKNNVpI/AAAAAAAAAfY/tNk69gwsPP4/s400/19%2Bcomplex%2BPW%2Bonly%2Bfor%2Bnext.jpg" style="cursor: hand; cursor: pointer; display: block; height: 292px; margin: 0px auto 10px; text-align: center; width: 400px;" /&gt;&lt;/a&gt;&lt;br /&gt;Windows Server 8 Functional Levels selected&lt;br /&gt;&lt;br /&gt;Before dcpromo completes a prerequisite check is conducted.  As you can see I receive an error&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-YDZ9cFNRaNI/TnDXQGpjAJI/AAAAAAAAAfg/oYNxJmHfFWU/s1600/22%2Berror.jpg"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5652254204012724370" src="http://2.bp.blogspot.com/-YDZ9cFNRaNI/TnDXQGpjAJI/AAAAAAAAAfg/oYNxJmHfFWU/s400/22%2Berror.jpg" style="cursor: hand; cursor: pointer; display: block; height: 298px; margin: 0px auto 10px; text-align: center; width: 400px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The error is &lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;The specified value '5' is not valid for the argument 'Domain level'&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;I then went back and changed the functional levels to 2008 R2&lt;br /&gt;&lt;br /&gt;Once that is done the promotion did complete and I now have my first Windows Server 8 Domain Controller.  &lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-xC6gmMSqwXI/TnDXf8jLxvI/AAAAAAAAAfo/MDtqSzXE4Es/s1600/23%2B%2Bchange%2Bfunctional%2Blevel.jpg"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5652254476179588850" src="http://1.bp.blogspot.com/-xC6gmMSqwXI/TnDXf8jLxvI/AAAAAAAAAfo/MDtqSzXE4Es/s400/23%2B%2Bchange%2Bfunctional%2Blevel.jpg" style="cursor: hand; cursor: pointer; display: block; height: 290px; margin: 0px auto 10px; text-align: center; width: 400px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This is a known bug so no reason to report it up the Microsoft chain.  Again...this is an early pre-Beta release.&lt;br /&gt;&lt;br /&gt;Enjoy and have fun with your new Windows Server 8 Domain Controller :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7365513794075231499-7849297006424621789?l=adisfun.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://adisfun.blogspot.com/feeds/7849297006424621789/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://adisfun.blogspot.com/2011/09/windows-server-8-active-directory.html#comment-form" title="8 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/7849297006424621789" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/7849297006424621789" /><link rel="alternate" type="text/html" href="http://adisfun.blogspot.com/2011/09/windows-server-8-active-directory.html" title="Windows Server 8 - Active Directory DCPROMO error" /><author><name>mkline</name><uri>http://www.blogger.com/profile/03770498033295580147</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-yQ7Bb6X6udo/TnDWhudO_ZI/AAAAAAAAAfQ/q2_OaX0dBQ8/s72-c/18.jpg" height="72" width="72" /><thr:total>8</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7365513794075231499.post-1466007970486210118</id><published>2011-09-14T07:18:00.000-07:00</published><updated>2011-09-23T07:58:55.093-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Windows 8" /><title type="text">Installing Windows Server 8 Developer Preview</title><content type="html">The Microsoft &lt;a href="http://www.buildwindows.com/"&gt;BUILD Conference&lt;/a&gt; is happening this week out in California.&lt;br /&gt;&lt;br /&gt;Microsoft is using this conference to mainly talk about the next version of Windows which is Windows 8.  There have been some leaked copies of Windows 8 but this week Microsoft released the first official release.&lt;br /&gt;&lt;br /&gt;The release is a pre-beta released called the Developers Preview and it is not feature complete and still has some things that need to be fixed but it does give us an image to download and start testing and having fun with.&lt;br /&gt;&lt;br /&gt;You can &lt;a href="http://msdn.microsoft.com/en-us/windows/apps/br229516"&gt;download the image from Microsoft.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I don't have a dedicated hyper-v box at home so I'm using &lt;a href="http://www.virtualbox.org/"&gt;VirtualBox &lt;/a&gt;   I did try and install it using VMWare Workstation 7.1 but had errors.  I may write another blog just on that experience.   Again important to note again this is an early version.&lt;br /&gt;&lt;br /&gt;If you are running Windows 7 you can also boot into Windows 8 and Scott Hanselman has a great blog entry on setting that up.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.hanselman.com/blog/GuideToInstallingAndBootingWindows8DeveloperPreviewOffAVHDVirtualHardDisk.aspx"&gt;Guide to Installing and Booting Windows 8 Developer Preview off a VHD &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I personally prefer virtual machines so that is the method I used.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;So off we go for the screenshots of the install&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-J6Ua5wc0w-M/TnC5co1q90I/AAAAAAAAAdY/eaAktzu31yQ/s1600/2.jpg"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5652221433999980354" src="http://3.bp.blogspot.com/-J6Ua5wc0w-M/TnC5co1q90I/AAAAAAAAAdY/eaAktzu31yQ/s400/2.jpg" style="cursor: hand; cursor: pointer; display: block; height: 297px; margin: 0px auto 10px; text-align: center; width: 400px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-74i1utEV0gg/TnC51n1BWTI/AAAAAAAAAdg/0ZQczLWnEtw/s1600/3.jpg"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5652221863225547058" src="http://2.bp.blogspot.com/-74i1utEV0gg/TnC51n1BWTI/AAAAAAAAAdg/0ZQczLWnEtw/s400/3.jpg" style="cursor: hand; cursor: pointer; display: block; height: 275px; margin: 0px auto 10px; text-align: center; width: 400px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-nScEet2bS-M/TnC6EFmnH7I/AAAAAAAAAdo/7E6KGqX1OGc/s1600/4.jpg"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5652222111736340402" src="http://2.bp.blogspot.com/-nScEet2bS-M/TnC6EFmnH7I/AAAAAAAAAdo/7E6KGqX1OGc/s400/4.jpg" style="cursor: hand; cursor: pointer; display: block; height: 295px; margin: 0px auto 10px; text-align: center; width: 400px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Three Options to select from; for this initial install I'm going with the full install.  Future posts will focus on the Server Core and Features On Demand versions.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/--077ZU6g3qk/TnC6p-CA9UI/AAAAAAAAAdw/hiPCYHRKFwA/s1600/5.jpg"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5652222762538825026" src="http://2.bp.blogspot.com/--077ZU6g3qk/TnC6p-CA9UI/AAAAAAAAAdw/hiPCYHRKFwA/s400/5.jpg" style="cursor: hand; cursor: pointer; display: block; height: 298px; margin: 0px auto 10px; text-align: center; width: 400px;" /&gt;&lt;/a&gt;&lt;br /&gt;Obligatory EULA which I fully read :)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-1SnKpr8sxCQ/TnC7Ei0GlxI/AAAAAAAAAd4/5-pq_hx7s6o/s1600/6.jpg"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5652223219089184530" src="http://3.bp.blogspot.com/-1SnKpr8sxCQ/TnC7Ei0GlxI/AAAAAAAAAd4/5-pq_hx7s6o/s400/6.jpg" style="cursor: hand; cursor: pointer; display: block; height: 297px; margin: 0px auto 10px; text-align: center; width: 400px;" /&gt;&lt;/a&gt;&lt;br /&gt;Choose Custom (advanced installation)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-c1TpONSea5M/TnC8EfSBbYI/AAAAAAAAAeA/dnFcJnaLMWw/s1600/7.jpg"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5652224317652561282" src="http://1.bp.blogspot.com/-c1TpONSea5M/TnC8EfSBbYI/AAAAAAAAAeA/dnFcJnaLMWw/s400/7.jpg" style="cursor: hand; cursor: pointer; display: block; height: 299px; margin: 0px auto 10px; text-align: center; width: 400px;" /&gt;&lt;/a&gt;&lt;br /&gt;I usually use around 40 GB for my virtual machines but you technically only need 32 GB of disk space.  Additional information on the system requirements can be found here:&lt;br /&gt;&lt;br /&gt;Windows Server 8 Developer Preview - &lt;a href="http://msdn.microsoft.com/en-us/windowsserver/hh440457"&gt;System Requirements &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-vhPxyM7W3gs/TnC8pjvp0CI/AAAAAAAAAeI/palu1pBSw-c/s1600/8.jpg"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5652224954505744418" src="http://2.bp.blogspot.com/-vhPxyM7W3gs/TnC8pjvp0CI/AAAAAAAAAeI/palu1pBSw-c/s400/8.jpg" style="cursor: hand; cursor: pointer; display: block; height: 301px; margin: 0px auto 10px; text-align: center; width: 400px;" /&gt;&lt;/a&gt;&lt;br /&gt;The familiar installing Windows dialogue box.  Glad some things don't change.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-iIvInYTy7ts/TnC9cMgOWKI/AAAAAAAAAeQ/l73Qpgw7OWA/s1600/9.jpg"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5652225824440342690" src="http://1.bp.blogspot.com/-iIvInYTy7ts/TnC9cMgOWKI/AAAAAAAAAeQ/l73Qpgw7OWA/s400/9.jpg" style="cursor: hand; cursor: pointer; display: block; height: 299px; margin: 0px auto 10px; text-align: center; width: 400px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-Uj6b1Xm9Ybw/TnC9nn1_KyI/AAAAAAAAAeY/Xu67KvqxvNc/s1600/11.jpg"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5652226020757941026" src="http://4.bp.blogspot.com/-Uj6b1Xm9Ybw/TnC9nn1_KyI/AAAAAAAAAeY/Xu67KvqxvNc/s400/11.jpg" style="cursor: hand; cursor: pointer; display: block; height: 274px; margin: 0px auto 10px; text-align: center; width: 400px;" /&gt;&lt;/a&gt;&lt;br /&gt;Getting close to being finished.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-2meFnywWjNs/TnC9y5EhMRI/AAAAAAAAAeg/nxWYD12Sok0/s1600/12.jpg"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5652226214360854802" src="http://3.bp.blogspot.com/-2meFnywWjNs/TnC9y5EhMRI/AAAAAAAAAeg/nxWYD12Sok0/s400/12.jpg" style="cursor: hand; cursor: pointer; display: block; height: 255px; margin: 0px auto 10px; text-align: center; width: 400px;" /&gt;&lt;/a&gt;&lt;br /&gt;Enter a password&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-FK1wzj9P7SU/TnC9-IYW8wI/AAAAAAAAAeo/Rsp3wigGLLw/s1600/13.jpg"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5652226407449162498" src="http://1.bp.blogspot.com/-FK1wzj9P7SU/TnC9-IYW8wI/AAAAAAAAAeo/Rsp3wigGLLw/s400/13.jpg" style="cursor: hand; cursor: pointer; display: block; height: 226px; margin: 0px auto 10px; text-align: center; width: 400px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-C1A-3lYYuqA/TnC-EViMoOI/AAAAAAAAAew/_jZbVzMZlFE/s1600/14.jpg"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5652226514059305186" src="http://4.bp.blogspot.com/-C1A-3lYYuqA/TnC-EViMoOI/AAAAAAAAAew/_jZbVzMZlFE/s400/14.jpg" style="cursor: hand; cursor: pointer; display: block; height: 297px; margin: 0px auto 10px; text-align: center; width: 400px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Moment of truth has arrived, initial screen for Windows Server 8.  It gets me excited as I know I'll be spending years of my life using this OS but this is my first install.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-tWohfY0mvXg/TnC-W9VE8eI/AAAAAAAAAe4/iStyxsaOQCI/s1600/15.jpg"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5652226833979339234" src="http://2.bp.blogspot.com/-tWohfY0mvXg/TnC-W9VE8eI/AAAAAAAAAe4/iStyxsaOQCI/s400/15.jpg" style="cursor: hand; cursor: pointer; display: block; height: 282px; margin: 0px auto 10px; text-align: center; width: 400px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;There are two screens you will see when initially working with Windows 8.  The first is the MetroUI that a lot of people have seen in previews on the &lt;a href="http://blogs.msdn.com/b/b8/"&gt;Windows 8 blog&lt;/a&gt; and other sources.  This is the tile interface&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-psyv-_18J-k/TnDB3Pf4F4I/AAAAAAAAAfA/sD_I-5BcBBQ/s1600/tiles.jpg"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5652230687147169666" src="http://3.bp.blogspot.com/-psyv-_18J-k/TnDB3Pf4F4I/AAAAAAAAAfA/sD_I-5BcBBQ/s400/tiles.jpg" style="cursor: hand; cursor: pointer; display: block; height: 298px; margin: 0px auto 10px; text-align: center; width: 400px;" /&gt;&lt;/a&gt;&lt;br /&gt;MetroUI GUI in Windows Server 8 Developers Preview&lt;br /&gt;&lt;br /&gt;You can use the Windows Key to get to the more familiar desktop&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/--akYL1W-z0Q/TnDCFuk6GSI/AAAAAAAAAfI/3amy5OUQtz0/s1600/16.jpg"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5652230936007940386" src="http://3.bp.blogspot.com/--akYL1W-z0Q/TnDCFuk6GSI/AAAAAAAAAfI/3amy5OUQtz0/s400/16.jpg" style="cursor: hand; cursor: pointer; display: block; height: 297px; margin: 0px auto 10px; text-align: center; width: 400px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;It is a new OS with a lot of graphical changes that are going to take time to get used to it.  For old timers over 35 like me the transition from NT to Windows 2000 was also dramatic.  Remember going from server manager and user manager to AD Users and Computers.&lt;br /&gt;&lt;br /&gt;I'm guessing there is a Group Policy to disable MetroUI and that will be a future posts but for now I'm leaving it on and getting used to it.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7365513794075231499-1466007970486210118?l=adisfun.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://adisfun.blogspot.com/feeds/1466007970486210118/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://adisfun.blogspot.com/2011/09/installing-windows-8-developer-preview.html#comment-form" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/1466007970486210118" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/1466007970486210118" /><link rel="alternate" type="text/html" href="http://adisfun.blogspot.com/2011/09/installing-windows-8-developer-preview.html" title="Installing Windows Server 8 Developer Preview" /><author><name>mkline</name><uri>http://www.blogger.com/profile/03770498033295580147</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-J6Ua5wc0w-M/TnC5co1q90I/AAAAAAAAAdY/eaAktzu31yQ/s72-c/2.jpg" height="72" width="72" /><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7365513794075231499.post-568894999817580158</id><published>2011-04-28T08:10:00.000-07:00</published><updated>2011-04-28T08:13:25.780-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Group Policy" /><category scheme="http://www.blogger.com/atom/ns#" term="Active Directory" /><title type="text">Group Policy for Beginners</title><content type="html">I &lt;a href="http://adisfun.blogspot.com/2009/07/group-policy-recomendations.html"&gt;previously&lt;/a&gt; blogged about resources to learn more about Group Policy.&lt;br /&gt;&lt;br /&gt;Microsoft released a 26 page document today titled&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.microsoft.com/downloads/en/details.aspx?FamilyID=470526da-8350-4314-a48d-ca97721855e1"&gt;Group Policy for Beginners&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Looks really good, and a great way for those new to group policy to start learning.  I still recommend the books and links that I previously outlined.&lt;br /&gt;&lt;br /&gt;I know not everyone that works with AD also does Group Policy work but a large majority do.&lt;br /&gt;&lt;br /&gt;Thanks&lt;br /&gt;&lt;br /&gt;Mike&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7365513794075231499-568894999817580158?l=adisfun.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://adisfun.blogspot.com/feeds/568894999817580158/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://adisfun.blogspot.com/2011/04/group-policy-for-beginners.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/568894999817580158" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/568894999817580158" /><link rel="alternate" type="text/html" href="http://adisfun.blogspot.com/2011/04/group-policy-for-beginners.html" title="Group Policy for Beginners" /><author><name>mkline</name><uri>http://www.blogger.com/profile/03770498033295580147</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7365513794075231499.post-5567603155514721470</id><published>2011-03-09T08:47:00.000-08:00</published><updated>2011-03-09T08:51:31.810-08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Miscellaneous" /><title type="text">Microsoft Premier Field Engineering Platform Reporting Tool</title><content type="html">Microsoft has released an updated MPS Reports Tool.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.microsoft.com/downloads/en/details.aspx?FamilyID=00ad0eac-720f-4441-9ef6-ea9f657b5c2f"&gt;Microsoft Premier Field Engineering Platform Reporting Tool &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;If you open a call with Microsoft you will often be told to upload the MPS reports.  The reports can take a while to run to I always recommend running them before hand or as you are calling.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7365513794075231499-5567603155514721470?l=adisfun.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://adisfun.blogspot.com/feeds/5567603155514721470/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://adisfun.blogspot.com/2011/03/microsoft-premier-field-engineering.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/5567603155514721470" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/5567603155514721470" /><link rel="alternate" type="text/html" href="http://adisfun.blogspot.com/2011/03/microsoft-premier-field-engineering.html" title="Microsoft Premier Field Engineering Platform Reporting Tool" /><author><name>mkline</name><uri>http://www.blogger.com/profile/03770498033295580147</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7365513794075231499.post-3762777817762276985</id><published>2011-02-14T13:57:00.000-08:00</published><updated>2011-02-14T14:02:13.789-08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Hotfix" /><category scheme="http://www.blogger.com/atom/ns#" term="Active Directory" /><title type="text">Password Hotfix from Microsoft site not working</title><content type="html">Just wanted to post this for those that are not on the AD/TechNet Forums daily&lt;br /&gt;&lt;br /&gt;This is just a repost from the moderators; I'll update the blog posting when the issue is fixed&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;&lt;a href="http://social.technet.microsoft.com/Forums/en/winserverDS/thread/cf121b14-73da-4b09-9cf3-393acad847c1"&gt;Password for hotfix downloaded from Microsoft website is not working&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;When you try to download a hotfix from Microsoft web site, the hotfix may not be able to be extracted properly with the password included in the email from hotfix@microsoft.com.&lt;br /&gt; &lt;br /&gt;We apologize for the inconvenience that this issue may have brought to you. Microsoft is aware of this problem and is trying our best to fix it as soon as possible. You may wait for a while and then try to download hotfix again. If it’s urgent, please contact us by calling:&lt;br /&gt; &lt;br /&gt;ITPro 800-936-4900&lt;br /&gt;Consumer 800-936-5700&lt;br /&gt;&lt;br /&gt;Or visit http://support.microsoft.com for regional support phone numbers. Hotfix request is free of charge.&lt;br /&gt; &lt;br /&gt;When this issue is resolved, we will also update it in the forum.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7365513794075231499-3762777817762276985?l=adisfun.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://adisfun.blogspot.com/feeds/3762777817762276985/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://adisfun.blogspot.com/2011/02/password-hotfix-from-microsoft-site-not.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/3762777817762276985" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/3762777817762276985" /><link rel="alternate" type="text/html" href="http://adisfun.blogspot.com/2011/02/password-hotfix-from-microsoft-site-not.html" title="Password Hotfix from Microsoft site not working" /><author><name>mkline</name><uri>http://www.blogger.com/profile/03770498033295580147</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7365513794075231499.post-4374904953746762256</id><published>2010-07-02T08:12:00.000-07:00</published><updated>2010-07-02T08:35:50.883-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="MVP Award" /><title type="text">THANK YOU AGAIN - MVP Award</title><content type="html">I found out yesterday that I was awarded the MVP for Active Directory/Directory Services again. &lt;br /&gt;&lt;br /&gt;&lt;a href="http://adisfun.blogspot.com/2009/07/im-microsoft-mvp-now-thank-you.html"&gt;I thanked the world last year &lt;/a&gt; so I won't do that again but just read that post and I'll say "ditto".&lt;br /&gt;&lt;br /&gt;The first year of being and MVP was really great with the highlight definitely being the MVP summit and I'm looking forward to that again in early 2011.&lt;br /&gt;&lt;br /&gt;Thanks to everyone on the TechNet Forums and the Experts Exchange forums that helps and contributes to this great community.  I try my best to help but I also learn a ton which is great for me.&lt;br /&gt;&lt;br /&gt;Also again thanks to all the smart people within Microsoft and the MVP community that inspire me.  People like  joe, Laura, Brian D., Jorge, Sander, Mark P, Paul, Marcin, Chris D, Meinolf, Brandon, Dean, Florian, Darren, Eric J, Crandall brothers, Mark H, Rick S, etc....the list goes on and on and on.&lt;br /&gt;&lt;br /&gt;Thanks to everyone again and see you all here on the blog or on one of the forums.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7365513794075231499-4374904953746762256?l=adisfun.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel="replies" type="application/atom+xml" href="http://adisfun.blogspot.com/feeds/4374904953746762256/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://adisfun.blogspot.com/2010/07/thank-you-again-mvp-award.html#comment-form" title="4 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/4374904953746762256" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7365513794075231499/posts/default/4374904953746762256" /><link rel="alternate" type="text/html" href="http://adisfun.blogspot.com/2010/07/thank-you-again-mvp-award.html" title="THANK YOU AGAIN - MVP Award" /><author><name>mkline</name><uri>http://www.blogger.com/profile/03770498033295580147</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>4</thr:total></entry></feed>

