Showing posts with label 2008. Show all posts
Showing posts with label 2008. Show all posts

Friday, November 22, 2013

6419 - Configuring Managing and Maintaining Windows Server 2008

6419B Introduction

Course Description
http://www.microsoft.com/learning/en/us/course.aspx?ID=6419b

Course Prerequisites
http://www.microsoft.com/learning/en/us/course.aspx?ID=6419b#tab3

Before attending this course, students must have:
•At least one year experience operating Windows Servers in the area of account management, server maintenance, server monitoring, or server security.
•A+, Server+, hardware portion of Net+, and familiarity with Windows (client side).
•Working knowledge of networking technologies.
•Intermediate understanding of network operating systems.
•Working experience with Windows Server 2003 and Windows Server 2008.
•Basic knowledge of Active Directory.
•An understanding of security concepts and methodologies (for example, corporate policies).
•Basic knowledge of TCP/IP.
•Basic knowledge of scripting tools such as PowerShell and WMI.
Exam 70-640 Learning Plan
Suggested Additional Material 6426 Course
http://www.microsoft.com/learning/en/us/course.aspx?id=6426c


Module 1 - Server 2008 Overview
2008 Server Info
http://technet.microsoft.com/en-us/windowsserver/cc304052.aspx
2008 Server R2 Info
http://technet.microsoft.com/en-us/windowsserver/bb310558.aspx
What's New
http://technet.microsoft.com/en-us/library/dd282984(v=ws.10).aspx
RSAT – Remote Server Administration Tools
http://support.microsoft.com/kb/958830/en-us

Module 2 - Infrastructure
Roles and Features
http://technet.microsoft.com/en-us/library/jj134039.aspx
PowerShell v2.0 OS info (XP, Vista …)
http://support.microsoft.com/kb/968929
Moving DNS Checklist
http://technet.microsoft.com/en-us/library/cc755303.aspx

Module 3 – Access to File Services
File Services for Windows Server 2008 R2
http://technet.microsoft.com/en-us/library/dd463985(v=ws.10).aspx
File and Storage Overview
http://technet.microsoft.com/en-us/library/hh831487.aspx
Share and Storage Management
http://technet.microsoft.com/en-us/library/cc731574.aspx

Module 4 – DFS
Replication Migration Guide: FRS to DFS Replication
http://technet.microsoft.com/en-us/library/dd640019(WS.10).aspx
Should you use DFS-R
http://blogs.technet.com/b/notesfromthefield/archive/2008/04/27/upgrading-your-sysvol-to-dfs-r-replication.aspx
DFS FAQ
http://technet.microsoft.com/en-us/library/cc773238(WS.10).aspx
Access-based enumeration hides files and folders that users do not have permission to access
http://support.microsoft.com/kb/961658

Module 5 - FSRM - File Server Resource Manager
FSRM
http://technet.microsoft.com/en-us/library/cc754810(v=WS.10).aspx
Old FSRM

http://technet.microsoft.com/en-us/library/cc755603(v=WS.10).aspx

Delegation and Access Control
http://technet.microsoft.com/en-us/library/cc772723(WS.10).aspx
Working with File Management Tasks
http://technet.microsoft.com/en-us/library/dd758756(WS.10).aspx
Automatically Move All Files
http://technet.microsoft.com/en-us/library/dd758756(WS.10).aspx#BKMK_CreateExpire

Module 6 - Remote Access
Routing and Remote Access
http://technet.microsoft.com/en-us/library/cc754634(v=WS.10).aspx
Old RRAS info
http://technet.microsoft.com/en-us/library/cc787456(v=ws.10).aspx
Security Tools
http://www.backtrack-linux.org/downloads/

Direct Access
http://technet.microsoft.com/en-us/library/dd758757(v=WS.10).aspx

Module 7 & 8 – AD – Active Directory
Forest Domains OUs – Oh My (What Are Domains and Forests?)
http://technet.microsoft.com/en-us/library/cc759073(v=ws.10).aspx
AD – Active Directory
http://technet.microsoft.com/en-us/library/cc758107(v=WS.10).aspx
Compare Forest and Domain Function Levels
http://technet.microsoft.com/en-us/library/understanding-active-directory-functional-levels(v=ws.10).aspx
AD PowerShell
http://technet.microsoft.com/en-us/library/ee617195.aspx
ADAC Regressions
http://blogs.msdn.com/b/lixiong/archive/2011/08/21/two-years-review-look-back-with-active-directory-administrative-center.aspx

AD Auditing
Audit Policy
http://technet.microsoft.com/en-us/library/dd941595(v=ws.10).aspx
Building a Case
http://blogs.msdn.com/b/ericfitz/archive/2008/08/20/tracking-user-logon-activity-using-logon-events.aspx
Security Events
http://support.microsoft.com/kb/947226
AD Diagnostic Logging
http://technet.microsoft.com/en-us/library/cc961809.aspx
Audit AD User Creation/Deletion
http://social.technet.microsoft.com/wiki/contents/articles/17055.event-ids-when-a-new-user-account-is-created-on-active-directory.aspx
http://social.technet.microsoft.com/wiki/contents/articles/17056.event-ids-when-a-user-account-is-deleted-from-active-directory.aspx

Module 9 10 & 11 – GPO

GPO for the IT Pro
http://windows.microsoft.com/en-US/windows7/Group-Policy-management-for-IT-pros
What's New
http://technet.microsoft.com/en-us/library/dd367853(v=ws.10).aspx
Windows 7 and cached credentials
http://support.microsoft.com/kb/172931
GPO Refresh Policy
http://technet.microsoft.com/en-us/library/cc757597(WS.10).aspx
GPO Reference Tools
http://gps.cloudapp.net/
http://gpsearch.azurewebsites.net/default.aspx
http://www.microsoft.com/en-us/download/details.aspx?id=25250
Windows 7 clients and 2003 Domain Controllers with 2003 Function Level
http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/dc5ee374-56ba-4a6c-aaee-2ee7137f166a
GPO Issues Problems and Potential Fixes
VPN GPO issues - due to cached credentials – Possible solution - to avoid that select logon using dial-up connections check box
http://technet.microsoft.com/en-us/library/cc736905(WS.10).aspx
Remove Run Once for IE
http://randelhall.blogspot.com/2010/07/remove-run-once-from-ie.html

Module 12 - Branch Office
RODC – Read Only Domain Controller
http://technet.microsoft.com/en-us/library/dd734758(v=WS.10).aspx
Password Replication
http://technet.microsoft.com/en-us/library/cc753470(v=ws.10).aspx
QoS – Quality of Service
http://technet.microsoft.com/en-us/network/bb530836.aspx
BranchCache
http://technet.microsoft.com/en-us/network/dd425028.aspx

Module 13 - Performance
Performance Guidelines
http://msdn.microsoft.com/en-us/windows/hardware/gg463394.aspx
PAL (Performance Analysis of Logs) tool
http://pal.codeplex.com/
http://www.petri.co.il/analyze-windows-performance-logs.htm
Relog
http://blogs.technet.com/b/richard_macdonald/archive/2008/04/08/3032386.aspx

Module 14 - Backup and Recover
Step by Step Guide
http://technet.microsoft.com/en-us/library/cc770266(v=WS.10).aspx

Extras

More from PowerShell 101
http://powershell101.blogspot.com

Copy User
http://randelhall.blogspot.com/2011/04/are-you-copying-user-in-active.html
Active Directory Replication 2008
http://technet.microsoft.com/en-us/library/cc772726(WS.10).aspx
Active Directory Replication (old 2003 but good reference)
http://technet.microsoft.com/en-us/library/cc782376(WS.10).aspx
Replication Topology (old 2003 but good reference)
http://technet.microsoft.com/en-us/library/cc755994(WS.10).aspx
Technet guide to assist you upgrade to 2008
http://technet.microsoft.com/en-us/library/cc731188(WS.10).aspx
AD recycle bin in 2008 R2
http://technet.microsoft.com/en-us/library/dd392261(WS.10).aspx
Free AD Tool to help recover users
http://www.ldapexplorer.com/en/lazarus.htm
More PowerShell ISE - free
http://powergui.org/index.jspa
http://www.idera.com/Free-Tools/PowerShell-Plus/
Create AD using PowerShell 2008 R2
http://blogs.metcorpconsulting.com/tech/?p=517
http://lyncdup.com/2013/06/setup-a-2008-r2-domain-controller-with-powershell-install-tafirst2008r2domaincontroller/

Tuesday, January 29, 2013

Logmein - Sticky Key Issue

image

Due to delay and network latency found issues using Logmein and getting sticky keys when using SHIFT during typing of passwords etc.

To turn this off … (both host and VM)

Control Panel – Ease of Access Center

image

Make the Keyboard Easier to Use

image

Clear em all

image

ref

http://mctexpert.blogspot.com/2012/09/sticky-key-problem-between-windows.html

Monday, November 19, 2012

10159 - Updating Your Windows Server 2008 Technology Skills to Windows Server 2008 R2

Course Info from Microsoft Site
10159A Web Page

Lesson 1
Requirements and Limits for Virtual Machines and Hyper-V in Windows Server 2008 R2
http://technet.microsoft.com/en-us/library/ee405267(v=ws.10).aspx
Foundation (OEM only)
http://www.microsoft.com/en-us/server-cloud/windows-server/2008-r2-foundation.aspx
Great blog from Hyper-V team on comparision between 2008 and 2008 R2
http://blogs.technet.com/b/virtualization/archive/2009/07/30/microsoft-hyper-v-server-2008-r2-rtm-more.aspx
VHD boot
http://blogs.technet.com/b/gmarchetti/archive/2009/07/14/vhd-boot.aspx
Install Server Migration Tools from ps or gui
http://technet.microsoft.com/pt-pt/library/dd379545(WS.10).aspx
More on BCDBOOT
http://technet.microsoft.com/en-us/library/dd744347(WS.10).aspx
USB Boot
http://msdn.microsoft.com/en-us/windows/hardware/gg463427
USB Install Video
http://technet.microsoft.com/en-us/edge/Video/ff710663


Lesson 2
Check out the new features of 2008 R2
1.DNS Security Extensions (DNSSEC)
2.DNS Devolution
3.DNS Cache Locking
4.DNS Socket Pool
DNS http://technet.microsoft.com/en-us/library/dd378952(WS.10).aspx
NAP http://www.microsoft.com/windowsserver2008/en/us/nap-main.aspx
RDS http://www.microsoft.com/windowsserver2008/en/us/rds-technical-resources.aspx
File Classification
http://channel9.msdn.com/Learn/Courses/WindowsServer2008R2/FileClassifictionInfrastructure/NewFileSystemClassificationInfrastructure

Lesson 3
More from Powershell 101
http://powershell101.blogspot.com/2012/04/active-directory.html

Powershell requirements
http://support.microsoft.com/kb/968929
Running powershell from command line is easy just type powershell.exe or powershell.exe .\script.ps1, but heres more
http://www.leeholmes.com/blog/2006/05/05/running-powershell-scripts-from-cmd-exe/
Powershell Library
http://technet.microsoft.com/en-us/library/bb978526.aspx
2003 Powershell
http://www.microsoft.com/en-us/download/details.aspx?displaylang=en&id=20020
AD Powershell
http://technet.microsoft.com/en-us/library/ee617195.aspx

Lesson 4A - Active Directory
New Active Directory Administrative Center
http://technet.microsoft.com/en-us/library/dd560651.aspx
Manage a different domain using ADAC
http://technet.microsoft.com/en-us/library/dd560632(WS.10).aspx
Install Gateway for 2003 R2 up to 2008 R2
http://www.microsoft.com/download/en/details.aspx?id=2852
Managing 2003? You need to install the AD mangement gateway.
http://www.microsoft.com/download/en/details.aspx?id=2852

Lesson 4B - GPO
What's new in Group Policy
http://technet.microsoft.com/en-us/library/dd367853(WS.10).aspx
Download GPO help file
http://www.microsoft.com/download/en/details.aspx?id=25250
GPO Help Online
http://gps.cloudapp.net/

Lesson 5
Hyper-V can run in core, see here for more
http://technet.microsoft.com/en-us/library/cc794852(WS.10).aspx
Core Config
http://technet.microsoft.com/en-us/library/cc753802(WS.10).aspx
VMM 2008 R2
http://technet.microsoft.com/en-us/library/ee230429.aspx

Lesson 6
RDS (Remote Desktop Services)
General http://www.microsoft.com/windowsserver2008/en/us/rds-product-home.aspx
Technet http://www.microsoft.com/windows/enterprise/solutions/virtualization/products/rds.aspx
VDI (Virtual Desktop Intrastructure)
General http://www.microsoft.com/windowsserver2008/en/us/rds-vdi.aspx
Technet http://technet.microsoft.com/en-us/windows/gg276319.aspx
Video http://channel9.msdn.com/Events/TechEd/NorthAmerica/2011/VIR312
Lesson 7
VPN - Step by Step setup
http://technet.microsoft.com/en-us/library/dd637783(WS.10).aspx
DirectAccess - Step by Step Guide
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=24144
DirectAccess - Good Article and Video
http://www.networkworld.com/community/DirectAccess
http://channel9.msdn.com/Events/TechEd/NorthAmerica/2011/WSV404
Compare - ISA TMG UAG
http://www.isaserver.org/tutorials/Microsoft-Forefront-TMG-UAG-feature-comparison.html

Lesson 8
New to R2 and Windows 7 is Branch Cache to speed up access to files at corporate
BranchCache
Step by Step http://technet.microsoft.com/en-us/library/dd637820(WS.10).aspx
Video http://technet.microsoft.com/en-us/edge/branch-cache-in-windows-7.aspx

Lesson 8 - Server Core
http://technet.microsoft.com/en-us/library/dd184075.aspx
Add PowerShell to Server Core
http://social.technet.microsoft.com/Forums/en-US/windowsserver2008r2management/thread/83b7d33b-ee27-45ae-8e68-ab5e63cd7274
More on adding PowerShell to Server Core
http://dmitrysotnikov.wordpress.com/2008/05/15/powershell-on-server-core/
Server Core Tool
http://redmondmag.com/articles/2011/03/01/cutting-to-the-core.aspx
Server Core Tool Download
http://coreconfig.codeplex.com/
Remote Server Manager - Setup and Limitations
http://technet.microsoft.com/en-us/library/dd759202.aspx

Lesson 9 – Web Services - IIS –FTP
IIS PowerShell
http://www.iis.net/learn/manage/powershell


Extra
Need to view events from other servers or concentrate your events on one management server.
http://technet.microsoft.com/en-us/library/cc749183.aspx

Free Stuff
Download Free Windows 2008 R2 Poster or Download Free E-Book

Non Microsoft Sources
Good Article on RDS Setup
http://www.bloggersbase.com/computers/remote-desktop-services-in-windows-2008-r2-1/

PowerGUI
http://redmondmag.com/articles/2010/03/01/powershell-without-the-shell.aspx
POWERGUI
http://powergui.org/

Tuesday, January 3, 2012

6433A - Planning and Implementing Windows Server 2008

General Class Information
Primary training resource for Exam 70-646 preparation (MCITP: Server Administrator certification)
http://www.microsoft.com/learning/en/us/Course.aspx?ID=6433A
Covers Windows Server 2008 and Windows 2008 R2 SP1

Student Prerequisites
http://www.microsoft.com/learning/en/us/Course.aspx?ID=6433A#tab3
This course requires that you meet the following prerequisites:
At least one year experience in implementing server plans
Technology skills equivalent to course 6418C: Deploying Windows Server 2008
Also, the following prerequisite certifications would support your preparation for attending this
course (6433A) and related exam (70-646):
MCTS: Windows Server 2008 Active Directory Configuration - Equivalent courses: 6425C and 6426C
MCTS: Windows Server 2008 Network Infrastructure Configuration - Equivalent course: 6421B
 
Module 1 - Planning Server Deployment and Upgrade

Module 2 - Planning Server Management and Delegated Administration

Module 3 - Planning Network Addressing and Name Resolution

Module 4 - Planning and Provisioning Active Directory Domain Services

Module 5 - Planning Group Policy Strategy

Module 6 - Planning Active Directory Certificate Services

Module 7 - Planning and Provisioning Application Servers

Module 8 - Planning File and Print Services

Module 9 - Planning Network Access

Module 10 - Provisioning Data and Storage

Module 11 - Planning Update Deployment

Module 12 - Planning High Availability

Module 13 - Performance and Event Monitoring

Module 14 - Enterprise Backup and Recovery

Tuesday, November 8, 2011

Setup Windows Server 2008 R2 as a workstation


Great list of features tweaks and software tools to add to your 2008 R2 Server working as a workstation

Server Manager
Configure IE ESC - Off for admin and users
Start the “Windows Audio” service and set startup to “Automatic”.

Add Features
“Wireless LAN Service”

"Desktop Experience"
Windows 7 components: Windows Media Player, Desktop themes, Video for Windows (AVI support), Windows SideShow, Windows Defender, Disk Cleanup, Sync Center, Sound Recorder, Character Map, and Snipping Tool.

GPO
Local Policies>Security Options> enable “Interactive logon: Do not require CTRL+ALT+DEL”.

Local Computer Policies>Administrative Templates>Computer Configuration>System>disable "Display Shutdown Event Tracker”

Local Computer Policies>Computer Configuration>Windows Settings>Security Settings>Local Policies>User Rights Assignment> Add the User or Interactive to the “Shut down the system”

More tweaks
Advanced system settings>Performance Settings>Advanced>Processor Scheduling> click programs

Now add the tools
PDF - Foxit
http://www.foxitsoftware.com/

Paint
http://paint.net/
snipping tool - already installed by adding desktop experience

Media Tools
VLC media player for Windows:
http://www.videolan.org/vlc/download-windows.html

Codec - Download K-Lite Codec Pack:
http://www.codecguide.com/download_kl.h

Podcast Tools
http://www.apple.com/itunes/
http://www.freeyoutubetomp3converter.org/
http://www.mp3-joiner.net/

Archive - Add 7 Zip
http://www.7-zip.org/

Disk Space - WinDirStat
http://windirstat.sourceforge.net/

References:
http://4sysops.com/archives/windows-server-2008-r2-server-the-perfect-workstation-os/
http://www.petri.co.il/tools-for-customizing-windows-server-2008-as-a-workstation.htm
http://www.petri.co.il/customizing-windows-server-2008-as-a-workstation.htm

Thursday, October 20, 2011

REPOST - 2008 R2 Core Installation

REPOST - I found this great article on 2008 R2 Core install.  Reposted here I hope you enjoy.

Implementing a Windows Server 2008 R2 Core Domain Controller into an existing Active Directory Forest is not a daunting task in itself but requires changes in the way many Administrators approach the installation and configuration of the base Windows installation.

Here will go through common configuration steps for integrating Windows Server 2008 R2 Core into an existing corporate Active Directory.

Domain Controllers are prime candidates for Server Core, they provide a smaller OS surface area that in theory at least should ensure there are less vulnerabilities exposed to possible malicious attacks. This means fewer critical hotfixes released by Microsoft are required to be installed on Server Core and can reduce the frequency of maintenance cycles and accompanying reboots, Microsoft estimate if there had been a Server Core edition of Windows Server 2003 it would have required 40% fewer patches than the Gui edition.

Section 1 – Prepare Existing Windows 2000/2003 AD

Section 2 – Configure Windows Server 2008 R2 Core

Section 3 – DCPromo and post DCPromo tasks

Pre-Requisites

Many organisations today still run Windows XP as the standard desktop OS, this is an issue for administrators who support existing AD environments using the Adminpak supplied in Windows 2003. The tools in the Windows Server 2003 Adminpak do not work seamlessly with Windows Server 2008 and the RSAT (Remote Server Administration Tools, the Adminpak replacement for Windows Server 2008) will not run on XP. The RSAT delivered with Windows Server 2008 R1 will run only on Windows Vista Desktops whilst the RSAT delivered with R2 only runs on Windows 7. The RSAT can be installed on a Gui based Windows 2008 server by installing the RSAT feature.

ADPrep needs to be run for both the forest and the individual domain where the Windows Server 2008 R2 Domain Controller will be installed.

Section 1 – Prepare Existing Windows 2000/2003 AD

The ADPrep in Windows Server 2008 adds the RODC (Read Only Domain Controller) ADPrep to the traditional forest and domain ADPreps. In short a RODC contains read-only partitions of the Active Directory Database. Common deployments of RODCs are in branch offices where physical security cannot be guaranteed, benefits offered include improved security, user credential caching meaning faster logon times and make more efficient access to resources on the network. More information on RODCs can be found here. The RODC ADPrep is run once at the forest level.

ADPrep is located on the Windows Server 2008 R2 DVD in the \Support\adprep directory, adprep.exe is the 64 bit version and adprep32.exe is the 32 bit version of the tool. Ensure the command prompt has been started using the “Run As Administrator” if running on a Windows Vista, Windows 7 or Windows Server 2008.

Forest ADPrep

The forest ADPrep requires that the logged in user is a member of the Enterprise Admins and Schema Admins groups as well as being a Domain Admin for the Domain containing the forests Schema Master. The forest ADPrep must be run on the Domain Controller holding the AD forests Schema Master FSMO role, to identify the FSMO roles at a command prompt (on any Domain Controller in the forest) enter, netdom query fsmo To run the forest ADPrep enter the following from the /support/adprep DVD directory.

adprep /forestprep

once completed allow time for the changes to replicate across the entire AD forest before ADPrep’ing any domains in the forest.

Domain ADPrep

The domain ADPrep requires that the logged in user is a member of the Domains Domain Admins group. The Domain ADPrep must be run on the Domain Controller holding the Domains Infrastructure Master FSMO role (see Forest ADPrep on how to identify FSMO roles). To run the Domain ADPrep enter:

adprep /domainprep /gpprep

once completed allow time for the changes to replicate across the entire AD forest before installing any new Domain Controllers in the Domain.

RODC ADPrep

The RODC ADPrep can be run on any computer in the Active Directory Forest and must be able to access all Infrastructure to run successfully. In firewalled/isolated environments it is important to choose a suitable computer on which to run the RODC ADPrep. The user performing the RODC ADPrep must be a member of the Enterprise Admins group. From the /support/adprep directory on the Windows Server 2008 R2 DVD enter:
adprep /rodcprep

once completed allow time for the changes to replicate across the entire AD before installing a RODC.

Section 2 – Configure Windows Server 2008 R2 Core

We will now go through the steps to introduce a first Windows Server 2008 R2 Core Domain Controller into an existing Active Directory forest (for information, into a Windows 2003 R2 forest and domain functional level directory). Ordinarily most of the steps detailed for configuring the Windows Server 2008 R2 Core are included in the server provisioning process. Interactively the sconfig utility is available in R2 which is a text based menu system that can be run from the console command prompt and allow a number of system settings such as TCP/IP network configuration to be made.

Detailed below are the command lines that can be included in an automated provisioning environment, a post installation script or typed directly from the console command prompt.

To identify the features that are enabled (and disabled) on Windows Server Core, enter

dism /online /get-features

Install Powershell 2.0

I advocate using PowerShell as the tool of choice for managing Windows (and VMware) environments. To enable PowerShell the dotNet Framework version 2 and version 3/3.5 must first be enabled. (note: dotNet 3.0 and 3.5 are contained within a single feature). In addition on a Windows Server 2008 R2 DC the Active Directory PowerShell cmdlets module can be enabled allowing a more straightforward approach to AD Powershell similar to the Quest PowerShell Commands for Active Directory used by many Administrators.

dism /online /enable-feature /featurename=NetFx2-ServerCore

dism /online /enable-feature /featurename=NetFx3-ServerCore

dism /online /enable-feature /featurename=MicrosoftWindowsPowerShell dism /online /enable-feature /featurename=ActiveDirectory-PowerShell

Powershell 2.0 WOW64 Support (Optional)

If WOW64 (32bit) support is required additional features need to be enabled.

dism /online /enable-feature /featurename=NetFx2-ServerCore-Wow64

dism /online /enable-feature /featurename=MicrosoftWindowsPowershell-Wow64

Install DNS Server

If the Domain Controller will also be configured as a DNS Server as they often are, the DNS-Server-Core-Role can be added using, (DNS Server can also be installed as a part of the DCPromo):

dism /online /enable-feature /featurename=DNS-Server-Core-Role

Network Configuration

Assuming the Windows Server Core instance has a single interface and is using the logical name “Local Area Connection”, first disable any other network cards, run the following command for each disconnected network connection.

netsh interface set interface “Local Area Connection 2″ DISABLE

configure the IP address, subnet mask and default gateway.

netsh interface ipv4 set address name=”Local Area Connection” static 172.24.32.10 255.255.255.0 172.24.32.1

configure the dns servers for the network connection, in this instance 3 dns servers are specified, of course ensure that the server is configured to point at existing DNS servers that have access to the AD SRV records.

netsh interface ipv4 set dns name=”Local Area Connection” static 172.24.32.4

netsh interface ipv4 add dns name=”Local Area Connection” 172.24.32.5 index=2

netsh interface ipv4 add dns name=”Local Area Connection” 172.24.22.8 index=3

to disable NetBIOS over TCP/IP first identify the adapters index number using

wmic nicconfig get caption,index,TcpipNetbiosOptions

then using one of the following values:

0 – Use NetBios setting from DHCP
1 – Enable NetBios over TCP/IP
2 – Disable NetBios over TCP/IP

set the required NetBIOS over TCP/IP value to each Nic.

wmic nicconfig where index=1 call SetTcpipNetbios 2

In the above example, index=1 is the index number returned for “Local Area Connection” from the earlier command. configure the primary DNS suffix, whether the suffix should change if domain membership changes and set the DNS suffix search list

reg add HKLM\System\CurrentControlSet\Services\Tcpip\Parameters /v Domain /t REG_SZ /d “ad.mydomain.com”

reg add HKLM\System\CurrentControlSet\Services\Tcpip\Parameters /v “NV Domain” /t REG_SZ /d “ad.mydomain.com”

reg add HKLM\System\CurrentControlSet\Services\Tcpip\Parameters /v “SyncDomainWithMembership” /t REG_DWORD /d 1

reg add HKLM\System\CurrentControlSet\Services\Tcpip\Parameters /v “SearchList” /t REG_SZ /d “ad.mydomain.com,mydomain.com,os.mydomain.com”

optionally a nic config can be backed up and restored using netsh, the following commands perform a backup and then a restore, this is useful if you wish to import a config instead of running many individual netsh commands.

netsh -c interface dump > c:\backup.txt

netsh -f c:\backup.txt

Configure Time Zone

to list the time zone names used by the time zone configuration utility run:

tzutil /l

then configure the time zone using one of the zone names. “_dstoff” can be appended to a zone name to have Daylight Savings Time disabled; the default enables Daylight Savings Time. To configure for GMT with DST switched off:

tzutil /s “GMT Standard Time_dstoff”

Rename Computer

if the server has a temporary name provisioning, it can be renamed using:

netdom renamecomputer /newname:

Diskpart to Create the NTDS/SYSVOL and Log Partitons

To create on Disk 0 a d: drive 50GB in size, a e: drive of 16GB and a f: drive using the remaining free space:

diskpart

select disk 0

list partition

create partition

primary size=50000

list partition

select partion 3

assign letter=D

format FS=NTFS LABEL=”DDrive” QUICK

create partition extended

list partition

select partition 0

create partition logical size=16000

assign letter=E

format FS=NTFS LABEL=”EDrive” QUICK

create partition logical

assign letter=F

format FS=NTFS LABEL=”FDrive” QUICK

list part

exit

The above can be saved as a text file and run using :

diskpart /s

Once created view the partitions using:

diskpart

list part

exit

something similar to the following should be displayed:diskpart

diskpart

list part

Partition ### Type Size Offset

------------- ---------------- ------- -------

Partition 1 Primary 8144 KB 16 KB

Partition 2 Primary 124 GB 8160 KB

Partition 3 Primary 48 GB 125 GB

Partition 0 Extended 105 GB 173 GB

Partition 4 Logical 15 GB 173 GB

* Partition 5 Logical 89 GB 189 GBBe sure to have rebooted to make all the above settings stick before proceeding further.

Section 3 – DCPromo and Post Promotion Configuration

Promoting a Windows Server Core instance to a Domain Controller must be done using an unattend answer file, this is because Windows Server Core does not support the DCPromo Gui wizard. If a problem is encountered running DCPromo be aware that DCPromo removes all passwords from the unattend answer file including where ”prompt for password” has been set by setting the password value to “*”. Before re-running DCPromo the unattend file must be edited to reset the values in the password password fields. In the following templates the affected fields are:

DNSDelegationPassword=*

Password=*

SafeModeAdminPassword=Password1

AdministratorPassword=Password1

All DC configuration scenarios available running DCPromo in Gui mode are supported using an unattend answer file, (creating a new forest, creating a new domain, removing the last Domain Controller in a domain etc.). As this posting is targeted at introducing a Server Core DC into an already running Active Directory Forest only adding a new DC to an existing domain and removing (in the event a fallback is required!) a DC from a domain.

DC Promote Unattend Template

This template contains the parameters for adding a DC to an existing domain. Details of parameters used in DCPromo unattend files can be found in MS KB947034. A DCPromo unattend file can be created by running and completing the DCPromo wizard on an existing Gui Windows server. In the final step of the wizard an export button is displayed, use this to export the unattend file and simply cancel the wizard so the DCPromo is not run. The saved unattend file can be edited in a text editor and used for running DCPromo in unattend mode.

DC Promote

[DCInstall]

ReplicaOrNewDomain=Replica

ReplicaDomainDNSName=ad.mydomain.com

SiteName=ADSite1

InstallDNS=Yes

ConfirmGc=Yes

CreateDNSDelegation=Yes

DNSDelegationUserName=admydomain\stuartconey

DNSDelegationPassword=*

UserDomain=ad.mydomain.com

UserName=admydomain\stuartconey

Password=*

ReplicationSourceDC=dc2.ad.mydomain.com

DatabasePath=”D:\NTDS”

LogPath=”E:\NTDS”

SYSVOLPath=”D:\SYSVOL”

SafeModeAdminPassword=Password1

; Run-time flags (optional)

; CriticalReplicationOnly=Yes

; RebootOnCompletion=Yes

* substitute Password1 to your standard Safe Mode Password

In the above example, the InstallDNS=yes line will install the DNS Server service. The default for installing DNS is dependent on the environment detected when DCPromo is run. MS KB947034 describes in detail all DCPromo Unattend parameters.

DC Demote Unattend Template

This template demotes a running DC back to member server.

 DC Demote

[DCInstall]

UserName=admydomain\stuartconey

password=*

administratorpassword=Password1

removeapplicationpartitions=yes

removeDNSDelegation=yes

DNSDelegationUserName=admydomain\stuartconey

DNSDelegationPassword=*

* substitute Password1 to your standard local Adminstrator Password

For Domain Controllers Located Behind Firewalls

In environments where domain controllers are separated from other domain controllers or member servers by firewalls it is possible to configure FRS and RPC traffic to use specific ports. Microsoft has the following document and KBs covering this issue.

MS Active Directory in Networks Segmented By Firewalls (Word Document)

MS KB224196, Restricting Active Directory replication traffic to a specific port

MS KB319553, How to restrict FRS traffic o a specific static port

MS KB154596, How to configure RPC dynamic port allocation to work with firewalls

In summary the following registry settings are used to set the ports used by the Active Directory FRS and RPC services.

Port used by FRS for Active Directory Replication:

HKLM\CurrentControlSet\Services\NTDS\ParametersRegistry value: TCP/IPValue type: REG_DWORDValue data: (available port)

Port used for client RPC traffic to a specific port:

HKLM\CurrentControlSet\Services\Netlogon\ParametersRegistry value: DCTcpipPortValue type: REG_DWORDValue data: (available port)

Port used by FRS:

HKLM\CurrentControlSet\Services\NTFRS\ParametersRegistry value: RPC TCP/IP Port AssignmentValue type: REG_DWORDValue data: (available port)

RPC Dynamic Port Range:

HKLM\Software\Microsoft\Rpc\Internet\Ports: REG_MULTI_SZ: 5000-5100PortsInternetAvailable: REG_SZ: YUseInternetPorts: REG_SZ: Y

the above registry settings can be applied on Server Core using regedit /s filename, here is an example regedit file:

Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS\Parameters] “TCP/IP Port”=dword:0000422a

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters] “DCTcpipPort”=dword:0000422b

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTFRS\Parameters] “RPC TCP/IP Port Assignment”=dword:0000411c

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Internet] “Ports”=hex(7):35,00,32,00,30,00,30,00,2d,00,35,00,33,00,30,00,30,00,00,00,00,00\

“PortsInternetAvailable”=”Y”

“UseInternetPorts”=”Y”

DNS Server Final Configuration

If the Windows Server Core Domain Controller is running DNS Server all AD integrated zones that are configured to “replicate to all DNS servers in the Domain” or “replicate to all DNS servers in the forest” will be synchronized to the DC. The DNS Server can be configured further, (for example configuring forwarding rules) using DNS Server Management MMC snap-in on either a Windows Server 2008 or Windows 7 (RSAT). One time saving new feature in Windows Server 2008 DNS Server is to set the Conditional Forwarding rules for a DNS server and request that they are replicated to all DNS servers in the Domain.

The dnscmd command line utility also offers comprehensive management of the DNS Server on Windows Server Core.

…and finally, if the new Windows Server Core DC is a replacement for an existing DC that will be decommissioned, remember to update GPOs containing DNS Server IP address assignments to Member Workstations and Servers in the forest.

Reference http://stuartconey.com/wp/?p=215

Monday, May 16, 2011

Course 6425B - Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Class Overview and Prerequisites
6425 Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Lesson 1
Max Number of Objects in AD
RODC info

Lesson 2
How to create OU with script
http://msdn.microsoft.com/en-us/library/aa705902(VS.85).aspx

Lesson 3
You can change the complex password requirements by a password filter
Fine Grained Password Policy

Lesson 5
Reset LSA secret on computer accounts
http://support.microsoft.com/kb/216393

Lesson 6
Copy GPO from forest to forest or domain to domain
UAC control with GPO
Change GPO refresh interval
Group Policy Settings Reference for Windows and Windows Server
Starter GPO
Great web site on GPO - great reminder from Derek Rose - thank you
GPO documentation

Lesson 7
Security Configuration and Analysis Tool Step by Step Guide
http://technet.microsoft.com/en-us/library/bb742512.aspx

Lesson 8
Active Directory Auditing Guidelines
AD DS Auditing Step-by-Step Guide
http://technet.microsoft.com/en-us/library/cc731607(WS.10).aspx

Lesson 11
DFS-R FAQ
http://technet.microsoft.com/en-us/library/cc773238(WS.10).aspx
NTDSUTIL
http://support.microsoft.com/kb/255504
RODC
http://technet.microsoft.com/en-us/library/cc732801(WS.10).aspx
Conversion SYSVOL from FRS to DFS Replication
http://technet.microsoft.com/en-us/library/dd641227(WS.10).aspx
SYSVOL migration states
http://technet.microsoft.com/en-us/library/dd641052(WS.10).aspx

Lesson 12

REPADMIN examples
http://technet.microsoft.com/en-us/library/cc773062(WS.10).aspx
Display replication partners
repadmin /showrepl hqdc01.contoso.com
Start a replication event between two replication partners
repadmin /replicate hqdc01.contoso.com hqdc02.contoso.com dc=contoso,dc=com
Start a replication event between all replication partners
repadmin /syncall hqdc01.contoso.com dc=contoso,dc=com
Show connections objects
repadmin /showconn hqdc01.contoso.com
Show replication status in forest
repadmin /replsummary
FSMO Placement
http://technet.microsoft.com/en-us/library/cc754889(WS.10).aspx
Find all GC's using powershell or dsquery server -forest -isgc
  • $forestinfo = [system.directoryservices.activedirectory.forest]::getcurrentforest()
  • $forestinfo.findallglobalcatalogs()
http://exchangeshare.wordpress.com/2008/04/05/powershell-forest-information-find-all-gcs/
AD PREP
http://technet.microsoft.com/en-us/library/cc782481(WS.10).aspx
http://technet.microsoft.com/en-us/library/dd464018(WS.10).aspx
AD cleanup
http://support.microsoft.com/kb/216498

Additional Reading
http://www.pbbergs.com/windows/windows.htm

Wednesday, April 27, 2011

Server Core 2008

Server Core is a minimal more secure version of Windows Server 2008 more info here
http://technet.microsoft.com/en-us/library/dd184075.aspx

Server Core Installation Option Getting Started Guide
http://technet.microsoft.com/en-us/library/cc753802(v=ws.10).aspx

Server Core Application Analyser is a downloadab le tool to help determine if your application can run on server core technology
http://www.microsoft.com/downloads/en/details.aspx?FamilyID=e0396bd8-a49b-41e5-a992-fb33e7883444&displaylang=en#Overview

Neat site about just the core
http://servercore.net/index.php/category/server-core/
Core Features
http://servercore.net/index.php/2010/09/server-core-roles-and-features-in-2008-r2/

Cool new site - GPO search

Cool new app.  If you want to look up your GPO try this new site.  http://gps.cloudapp.net/

You can still download the excel spreadsheet here or use the new filter option in GPME

Thursday, November 11, 2010

Missing your Admin Tools?

Due to security, it is better to manage that server with your desktop.

So how do you get the admin tools on your desktop

First install RSAT from here
http://www.microsoft.com/downloads/en/details.aspx?FamilyID=7d2f6ad7-656b-4313-a005-4e344e43997d&displaylang=en

then if it is still missing make sure to add the tools back to start in your start menu properties more here
http://www.sevenforums.com/tutorials/8891-administrative-tools-add-remove-start-menu.html

Wednesday, August 18, 2010

What is the difference between 2003 2008 2008 R2 server?

The differences are big, remember that if you are running vista then 2008 is ok, if you are running windows 7 you need to upgrade to 2008 R2 to get all the features.

 Differences from 2003 to 2008 http://www.microsoft.com/downloads/details.aspx?FamilyID=173E6E9B-4D3E-4FD4-A2CF-73684FA46B60&displaylang=en


Differences between 2008 2008 r2
http://www.microsoft.com/windowsserver2008/en/us/r2-compare-features.aspx

Monday, July 19, 2010

Course 5118B: Supporting Windows Vista and Applications in the Enterprise

Online Live
Eval http://www.metricsthatmatter.com/cincy12nh

Vista Features and Compare Editions
http://www.microsoft.com/windows/windows-vista/compare-editions/default.aspx

Vista Security
http://www.microsoft.com/windows/windows-vista/features/security-center.aspx
http://technet.microsoft.com/en-us/library/cc507844.aspx

MAP
http://www.microsoft.com/downloads/details.aspx?FamilyID=67240b76-3148-4e49-943d-4d9ea7f77730&displaylang=en

Easy Transfer for XP
http://www.microsoft.com/downloads/details.aspx?familyid=2B6F1631-973A-45C7-A4EC-4928FA173266&displaylang=en

User state migration
http://technet.microsoft.com/en-us/library/cc507855.aspx
http://technet.microsoft.com/en-us/library/dd883247(WS.10).aspx
 http://technet.microsoft.com/en-us/library/cc749015(WS.10).aspx
 http://technet.microsoft.com/en-us/library/cc766226(WS.10).aspx
http://technet.microsoft.com/en-us/library/cc722032(WS.10).aspx

Sysprep
 http://technet.microsoft.com/en-us/library/cc766049(WS.10).aspx
 http://technet.microsoft.com/en-us/library/cc721973(WS.10).aspx

Link Layer Topology Discovery (LLTD) responder for XP sp2
http://www.microsoft.com/downloads/details.aspx?familyid=4F01A31D-EE46-481E-BA11-37F485FA34EA&displaylang=en

Vista Security Guide
http://www.microsoft.com/downloads/details.aspx?FamilyId=A3D1BBED-7F35-4E72-BFB5-B84A526C1565&displaylang=en

Change GPO refresh interval
http://technet.microsoft.com/en-us/library/cc757597(WS.10).aspx
http://www.windowsecurity.com/articles/Controlling-Group-Policy-Security-Settings-Refresh-Application.html

Group Policy Settings Reference for Windows and Windows Server
http://www.microsoft.com/downloads/details.aspx?FamilyID=18c90c80-8b0a-4906-a4f5-ff24cc2030fb&displaylang=en

2003 and vista gpo issues
 http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/0a9124d8-6c91-442d-8564-cb92164386d0

Managing Group Policy ADMX Files Step-by-Step Guide:
http://technet2.microsoft.com/WindowsVista/en/library/02633470-396c-4e34-971a-0c5b090dc4fd1033.mspx?mfr=true

ADMX Schema:
http://msdn2.microsoft.com/en-us/library/aa373476(VS.85).aspx

ADMX Technology Review:
http://www.microsoft.com/technet/windowsvista/library/ef346453-eee8-4abe-ba6c-2160fee3be46.mspx

ADMX Migrator (this tool is used for converting existing Group Policy ADM Templates to the new ADMX format):
http://www.microsoft.com/downloads/details.aspx?familyid=0F1EEC3D-10C4-4B5F-9625-97C2F731090C&displaylang=en

Process Explorer and other great tools at sysinternals
http://technet.microsoft.com/en-us/sysinternals/default.aspx

Virtual Tools
http://www.virtualbox.org/
http://www.microsoft.com/windows/virtual-pc/
http://technet.microsoft.com/en-us/library/cc732470(WS.10).aspx

VHD
http://technet.microsoft.com/en-us/bb738372.aspx