<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-5978273702195385869</id><updated>2011-11-28T00:35:50.844+01:00</updated><category term='Windows 2008 R2'/><category term='Exchange 2010'/><category term='ConfigMgr'/><category term='File Services'/><category term='Active Directory'/><category term='DFS'/><category term='Windows 7'/><category term='BitLocker'/><title type='text'>Stefan Hazenbroek</title><subtitle type='html'>Everything can be done automatically, as long as you first configure it manually.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://stefanhazenbroek.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://stefanhazenbroek.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Stefan Hazenbroek</name><uri>http://www.blogger.com/profile/02126356175626503768</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>26</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-5978273702195385869.post-3693187730456625363</id><published>2011-07-04T08:18:00.001+02:00</published><updated>2011-07-11T16:55:07.323+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ConfigMgr'/><title type='text'>ConfigMgr: SMS SRS web service is not running on SRS Reporting point server when using SQL 2008 R2</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Hi,&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana;"&gt;&lt;span style="font-size: x-small;"&gt;Since about a year SQL 2008 R2 is a supported platform for System Center Configuration Manager. However, when you use the Reporting Services Server as apposed to the ConfigMgr &lt;span style="font-family: Verdana, sans-serif;"&gt;Reporting you get an error every hour, stating your Reporting Services Point cannot be reached. When you connect to the point, it works without a problem though.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;The exact message from the ConfigMgr console is:&lt;/span&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;SMS SRS web service is not running on SRS Reporting point server &lt;servername&gt;&lt;/servername&gt;&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;The error has error message 7403.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Some time ago the SQL Server product team released a new Cumulative Update (CU) for SQL Server 2008 R2, which fixes the issue.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;If you are encountering above mentioned issue, please download CU4 from &lt;a href="http://support.microsoft.com/kb/2345451"&gt;http://support.microsoft.com/kb/2345451&lt;/a&gt;&amp;nbsp;and install it on the SQL server used for hosting the Site Database and Reporting Services.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Hope this helps.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Regards,&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Stefan Hazenbroek&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5978273702195385869-3693187730456625363?l=stefanhazenbroek.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stefanhazenbroek.blogspot.com/feeds/3693187730456625363/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://stefanhazenbroek.blogspot.com/2011/07/configmgr-sms-srs-web-service-is-not.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/3693187730456625363'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/3693187730456625363'/><link rel='alternate' type='text/html' href='http://stefanhazenbroek.blogspot.com/2011/07/configmgr-sms-srs-web-service-is-not.html' title='ConfigMgr: SMS SRS web service is not running on SRS Reporting point server when using SQL 2008 R2'/><author><name>Stefan Hazenbroek</name><uri>http://www.blogger.com/profile/02126356175626503768</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5978273702195385869.post-5430589728621770312</id><published>2011-06-25T17:30:00.000+02:00</published><updated>2011-06-25T17:30:22.422+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ConfigMgr'/><title type='text'>ConfigMgr: Deploy Internet Explorer 9 as part of a Task Sequence</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Hi,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;When installing Internet Explorer 9 during OS Deployment the installation gives a weird issue after the machine is fully deployed. When a non-administrative user logs in to the machine, the Internet Explorer&amp;nbsp;shortcutshows up as a "blank" icon and the target points to a non-existent path like T:\.&amp;nbsp; When an Administrative user logs on to the computer before a non-administrative user does, everything will be okay.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;This error seems to be caused by an issue in the Active Setup part of Internet Explorer 9. Please see &lt;/span&gt;&lt;a href="http://bonemanblog.blogspot.com/2004/12/active-setup-registry-keys-and-their.html"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;this&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt; post by Steven Bone explaining what Active Setup is and means.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Workaround&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;As long as there is no bugfix available for this issue, you can deploy Internet Explorer 9 correctly via a task sequence following these steps.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;- Install Internet Explorer 9 in the task sequence by using the .msu file.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;- After a reboot, create the following two task sequence actions:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Task Sequence Step 1:&lt;/span&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;reg.exe DELETE "HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components" /v "NoIE4StubProcessing" /f&amp;nbsp;&lt;/span&gt;&lt;/blockquote&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;The task sequence step (Run Command Line) should look like this:&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-dLtUQNrGE14/TgX-J2ZG0JI/AAAAAAAAALg/AGSBLqVQmxs/s1600/Remove+Active+Setup+NoIE4StubProcessing.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;img border="0" height="295" src="http://3.bp.blogspot.com/-dLtUQNrGE14/TgX-J2ZG0JI/AAAAAAAAALg/AGSBLqVQmxs/s320/Remove+Active+Setup+NoIE4StubProcessing.jpg" width="320" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Task Sequence Step 2:&lt;/span&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;reg.exe DELETE "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce" /v "NoIE4StubProcessing" /f&lt;/span&gt;&lt;/blockquote&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;The task sequence step (Run Command Line) should look like this:&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-ZowWFCOYnKg/TgX-lznNz3I/AAAAAAAAALk/KZI-Tcw9kK8/s1600/Remove+RunOnce+NoIE4StubProcessing.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;img border="0" height="295" src="http://4.bp.blogspot.com/-ZowWFCOYnKg/TgX-lznNz3I/AAAAAAAAALk/KZI-Tcw9kK8/s320/Remove+RunOnce+NoIE4StubProcessing.jpg" width="320" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;In my case I have to tick the box "Disable 64-bit file system redirection" because I am deploying Windows 7 x64 workstations.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;I hope this helps in deploying Internet Explorer 9 successfully.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Regards,&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Stefan Hazenbroek&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5978273702195385869-5430589728621770312?l=stefanhazenbroek.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stefanhazenbroek.blogspot.com/feeds/5430589728621770312/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://stefanhazenbroek.blogspot.com/2011/06/configmgr-deploy-internet-explorer-9-as.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/5430589728621770312'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/5430589728621770312'/><link rel='alternate' type='text/html' href='http://stefanhazenbroek.blogspot.com/2011/06/configmgr-deploy-internet-explorer-9-as.html' title='ConfigMgr: Deploy Internet Explorer 9 as part of a Task Sequence'/><author><name>Stefan Hazenbroek</name><uri>http://www.blogger.com/profile/02126356175626503768</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-dLtUQNrGE14/TgX-J2ZG0JI/AAAAAAAAALg/AGSBLqVQmxs/s72-c/Remove+Active+Setup+NoIE4StubProcessing.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5978273702195385869.post-3421260066414512572</id><published>2011-05-30T12:27:00.000+02:00</published><updated>2011-05-30T12:27:17.079+02:00</updated><title type='text'>ConfigMgr: OSD Domain Join fails when Computers CN/OU is chosen</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Hi all,&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;When I build up an environment, I always try to keep everything tidy and as close to reallife as possible. This made me find out the fact that ConfigMgr's OSD domain join will fail when you choose for the Computers CN as a container instead of a "real" OU.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;So, when you have a task sequence to install Windows (whatever version) within SMS 2003, SCCM 2007 or even SCCM 2012, if the domain join fails without an error in the Advertisement status, this is most likely the problem.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Open up the &lt;strong&gt;Apply Network Settings&lt;/strong&gt; step in the Task Sequence and change the OU to&amp;nbsp;a real OU, or to blank when the computers should be put in the Computers CN.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;I hope this helps.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Regards,&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Stefan Hazenbroek&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5978273702195385869-3421260066414512572?l=stefanhazenbroek.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stefanhazenbroek.blogspot.com/feeds/3421260066414512572/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://stefanhazenbroek.blogspot.com/2011/05/configmgr-osd-domain-join-fails-when.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/3421260066414512572'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/3421260066414512572'/><link rel='alternate' type='text/html' href='http://stefanhazenbroek.blogspot.com/2011/05/configmgr-osd-domain-join-fails-when.html' title='ConfigMgr: OSD Domain Join fails when Computers CN/OU is chosen'/><author><name>Stefan Hazenbroek</name><uri>http://www.blogger.com/profile/02126356175626503768</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5978273702195385869.post-1024195732334012839</id><published>2011-03-24T19:59:00.000+01:00</published><updated>2011-03-24T19:59:09.962+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='BitLocker'/><title type='text'>BitLocker: Microsoft BitLocker Administration and Monitoring beta available for download</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Microsoft has just released the Microsoft BitLocker Administration and Monitoring (MBAM) beta to the public. This beta can be downloaded by subscribing to the Connect site of &lt;a href="https://connect.microsoft.com/site1115/Downloads"&gt;Malta&lt;/a&gt;.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;For more information about MBAM, check out the following link: &lt;a href="http://windowsteamblog.com/windows/b/springboard/archive/2011/02/09/microsoft-announces-microsoft-bitlocker-administration-and-monitoring-mbam.aspx"&gt;http://windowsteamblog.com/windows/b/springboard/archive/2011/02/09/microsoft-announces-microsoft-bitlocker-administration-and-monitoring-mbam.aspx&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;In the following posts I'll cover the installation and configuration of MBAM.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Regards,&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Stefan Hazenbroek&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5978273702195385869-1024195732334012839?l=stefanhazenbroek.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stefanhazenbroek.blogspot.com/feeds/1024195732334012839/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://stefanhazenbroek.blogspot.com/2011/03/bitlocker-microsoft-bitlocker.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/1024195732334012839'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/1024195732334012839'/><link rel='alternate' type='text/html' href='http://stefanhazenbroek.blogspot.com/2011/03/bitlocker-microsoft-bitlocker.html' title='BitLocker: Microsoft BitLocker Administration and Monitoring beta available for download'/><author><name>Stefan Hazenbroek</name><uri>http://www.blogger.com/profile/02126356175626503768</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5978273702195385869.post-8017828605580223331</id><published>2011-02-25T12:45:00.001+01:00</published><updated>2011-02-25T12:45:57.117+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Windows 7'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows 2008 R2'/><title type='text'>W7/2K8 R2 SP1: Remove unneeded Service Pack files</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;As you might know SP1 for Windows 7 and Windows Server 2008 R2 has been released recently. This SP contains all prior updates released through Windows update and some important updates aside from that.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;In this short blogpost I will explain how you can remove the installation files of the SP so you can keep your installation tidy. This is particularly handy when you want to create an image of the installation so you can have your pc's deployed with SP1 included from now on.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Now, off we go.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;1. First, open &lt;strong&gt;My Computer.&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;2. Right click on your &lt;strong&gt;C-Drive&lt;/strong&gt; (or the drive on which Windows is installed on, for the sake of argument I'll assume this is &lt;strong&gt;C&lt;/strong&gt;).&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;3. Choose &lt;strong&gt;Properties&lt;/strong&gt;.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-ytzJzOzAuYM/TWeVQwNW4PI/AAAAAAAAALQ/kwLrkjCHZ7c/s1600/diskcleanup1.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" l6="true" src="http://1.bp.blogspot.com/-ytzJzOzAuYM/TWeVQwNW4PI/AAAAAAAAALQ/kwLrkjCHZ7c/s200/diskcleanup1.jpg" width="166" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;4. Clik &lt;strong&gt;Disk Cleanup&lt;/strong&gt;.&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-eym5mKU5LvA/TWeVfSeI_zI/AAAAAAAAALU/qHUZKUOl8f8/s1600/diskcleanup2.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" l6="true" src="http://1.bp.blogspot.com/-eym5mKU5LvA/TWeVfSeI_zI/AAAAAAAAALU/qHUZKUOl8f8/s200/diskcleanup2.jpg" width="150" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;﻿&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;5. Click &lt;strong&gt;Clean up System Files&lt;/strong&gt;.&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-AXHR-F2PwWE/TWeVvD9J67I/AAAAAAAAALY/7nJdaIpy2F4/s1600/diskcleanup3.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" l6="true" src="http://3.bp.blogspot.com/-AXHR-F2PwWE/TWeVvD9J67I/AAAAAAAAALY/7nJdaIpy2F4/s200/diskcleanup3.jpg" width="163" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;6. Tick &lt;strong&gt;Service Pack Backup Files&lt;/strong&gt; so the checkbox is selected. As you can see this will cleanup about 540M on my pc.&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-YT39q7Mze3g/TWeWDRzDlWI/AAAAAAAAALc/dRSQP1FNQIU/s1600/diskcleanup4.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" l6="true" src="http://3.bp.blogspot.com/-YT39q7Mze3g/TWeWDRzDlWI/AAAAAAAAALc/dRSQP1FNQIU/s200/diskcleanup4.jpg" width="163" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;I hope this helps.&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Regards,&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Stefan Hazenbroek&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5978273702195385869-8017828605580223331?l=stefanhazenbroek.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stefanhazenbroek.blogspot.com/feeds/8017828605580223331/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://stefanhazenbroek.blogspot.com/2011/02/w72k8-r2-sp1-remove-unneeded-service.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/8017828605580223331'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/8017828605580223331'/><link rel='alternate' type='text/html' href='http://stefanhazenbroek.blogspot.com/2011/02/w72k8-r2-sp1-remove-unneeded-service.html' title='W7/2K8 R2 SP1: Remove unneeded Service Pack files'/><author><name>Stefan Hazenbroek</name><uri>http://www.blogger.com/profile/02126356175626503768</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-ytzJzOzAuYM/TWeVQwNW4PI/AAAAAAAAALQ/kwLrkjCHZ7c/s72-c/diskcleanup1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5978273702195385869.post-8997516780282611401</id><published>2011-01-13T14:25:00.000+01:00</published><updated>2011-01-13T14:25:58.834+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ConfigMgr'/><title type='text'>ConfigMgr: Drivers not applicable.</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Consider the following scenario. You're running SCCM 2007 SP2 with R2 (or R3 for that matter) on Windows Server 2008 and want to deploy Windows 7 cliënts. When you try to import the drivers for your Windows 7 workstations into SCCM you might run into the issue when some drivers give the error:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;driver file=""&gt;The selected driver is not applicable to any supported platforms&lt;/span&gt; &lt;br /&gt;&lt;/blockquote&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;You'll only get this error when you're trying to import drivers that are Windows 7 exclusive. This issue is due to the fact that SCCM uses the internal methods of handling inf files and Windows Server 2008 does not 'know' of Windows 7 yet. Install the following hotfix from Microsoft to fix this issue.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;a href="http://support.microsoft.com/kb/978754"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;http://support.microsoft.com/kb/978754&lt;/span&gt;&lt;/a&gt;&lt;/blockquote&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Remember, this is not applicable on Windows Server 2008 R2 but only for windows Server 2008.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Hope this helps.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Regards,&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Stefan Hazenbroek&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5978273702195385869-8997516780282611401?l=stefanhazenbroek.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stefanhazenbroek.blogspot.com/feeds/8997516780282611401/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://stefanhazenbroek.blogspot.com/2011/01/configmgr-drivers-not-applicable.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/8997516780282611401'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/8997516780282611401'/><link rel='alternate' type='text/html' href='http://stefanhazenbroek.blogspot.com/2011/01/configmgr-drivers-not-applicable.html' title='ConfigMgr: Drivers not applicable.'/><author><name>Stefan Hazenbroek</name><uri>http://www.blogger.com/profile/02126356175626503768</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5978273702195385869.post-5609359869420619823</id><published>2011-01-13T14:13:00.000+01:00</published><updated>2011-01-13T14:13:46.838+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Active Directory'/><title type='text'>AD CS: Move AD CS Database and Log to a different drive</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;What if you created a certificate infrastructure, sized it according to the requirements known at the moment and a new project comes along that requires a certifcate services Database and log that is three times the size of the original one, so it doesn't fit onto your sized harddisk. In alot of scenario's it's possible to expand the disks (using vmware, xenserver or hyper-v this is quite easy), but when you're using physical servers it's not so easy.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Or, maybe, when you installed AD CS you forgot to move it from c:\windows\system32\Certsvc. No worries, it's quite easy to change it.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;In this short blogpost I'll explain how to move the certificate services database and log location after AD Certificate Services has been installed.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;1. Prepare the disk, LUN or whatever you have in mind for your database and log. Ideally both will be placed on separate disks for performance reasons. Create the path for the database and log. In case it'll be placed on one disk I always assume &lt;strong&gt;CertDB&lt;/strong&gt; for the database and &lt;strong&gt;CertDB\Logs&lt;/strong&gt; for the logs, to keep things tidy.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;2. Stop the AD Certificate Services service by running &lt;strong&gt;net stop certsvc&lt;/strong&gt; from an elevated command prompt or by right clicking and selecting Stop service in the Services MMC.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;3. Copy the database and the logs to their new location.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;4. Open the registry editor by starting &lt;strong&gt;regedit&lt;/strong&gt; and browse to &lt;strong&gt;HKLM\System\CurrentControlSet\Services\CertSvc\Configuration&lt;/strong&gt;.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;5. Edit the following entries:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;&lt;strong&gt;DBDirectory &lt;/strong&gt;(default is C:\Windows\System32\CertLog\..., change it to your new databasedir)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;&lt;strong&gt;DBLogDirectory&lt;/strong&gt; (default is C:\Windows\System32\CertLog, change it to your new logdir)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;&lt;strong&gt;DBSystemDirectory&lt;/strong&gt; (default is C:\Windows\System32\CertLog, change it to your new databasedir)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;&lt;strong&gt;DBTempDirectory&lt;/strong&gt; (default is C:\Windows\System32\CertLog, change it to your new databasedir)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;6. Start the certification authority again by running &lt;strong&gt;net start certsvc&lt;/strong&gt; from the commandline or by right clicking the AD Certification Services service and choosing &lt;strong&gt;Start&lt;/strong&gt;. From this moment your DB and log should be running from the new location.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;7. Verify it is running from the new location. You can do this by opening up the certification authority MMC. Right click on the name of your CA and choose &lt;strong&gt;Properties&lt;/strong&gt;. Choose the tab &lt;strong&gt;Storage&lt;/strong&gt;. The tab should look like this, with the location of your DB and Logs on a perhaps different drive/letter.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Y9qL3xVT9hA/TS76Us0f3nI/AAAAAAAAALI/tQcdWt1Wjpw/s1600/CAStorage.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" n4="true" src="http://1.bp.blogspot.com/_Y9qL3xVT9hA/TS76Us0f3nI/AAAAAAAAALI/tQcdWt1Wjpw/s320/CAStorage.jpg" width="256" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Hope this helps.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Regards,&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Stefan Hazenbroek&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5978273702195385869-5609359869420619823?l=stefanhazenbroek.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stefanhazenbroek.blogspot.com/feeds/5609359869420619823/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://stefanhazenbroek.blogspot.com/2011/01/ad-cs-move-ad-cs-database-and-log-to.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/5609359869420619823'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/5609359869420619823'/><link rel='alternate' type='text/html' href='http://stefanhazenbroek.blogspot.com/2011/01/ad-cs-move-ad-cs-database-and-log-to.html' title='AD CS: Move AD CS Database and Log to a different drive'/><author><name>Stefan Hazenbroek</name><uri>http://www.blogger.com/profile/02126356175626503768</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Y9qL3xVT9hA/TS76Us0f3nI/AAAAAAAAALI/tQcdWt1Wjpw/s72-c/CAStorage.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5978273702195385869.post-8115331420603542398</id><published>2010-12-28T12:39:00.001+01:00</published><updated>2010-12-28T12:40:21.283+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='File Services'/><title type='text'>FS: Disable the Restore button in Previous Versions</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Previous Versions (or, Volume Shadow Copy Service) is a very powerful way of letting users manage their own files in an enterprise environment. One issue however, especially for department-shares, is the possibility to&amp;nbsp;&lt;em&gt;restore&lt;/em&gt; a file using Previous Versions. There is no pretty way to disable this using a group policy or something similar, but it IS possible.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;By default it is possible for users to restore files. By following the next steps you can turn this off so that only Open and Copy can be used.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Fire up the registry (regedit).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Browse to: &lt;strong&gt;HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer&lt;/strong&gt; to turn it on or off for the current user or &lt;strong&gt;HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer&lt;/strong&gt; to turn it off for the local machine. I suggest turning this off on a user basis, so that your IT Administrators can still manage this if needed.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Create a new REG_DWORD with the name &lt;strong&gt;NoPreviousVersionsRestore&lt;/strong&gt;. The value for this entry is &lt;strong&gt;1&lt;/strong&gt;.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;It isn't needed for the users to log off and on again for the setting to be put into place. &lt;/span&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;I suggest putting this in a group policy preference for ease of management.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Hope this helps.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Regards,&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Stefan Hazenbroek&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5978273702195385869-8115331420603542398?l=stefanhazenbroek.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stefanhazenbroek.blogspot.com/feeds/8115331420603542398/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://stefanhazenbroek.blogspot.com/2010/12/fs-disable-restore-button-in-previous.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/8115331420603542398'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/8115331420603542398'/><link rel='alternate' type='text/html' href='http://stefanhazenbroek.blogspot.com/2010/12/fs-disable-restore-button-in-previous.html' title='FS: Disable the Restore button in Previous Versions'/><author><name>Stefan Hazenbroek</name><uri>http://www.blogger.com/profile/02126356175626503768</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5978273702195385869.post-1994289077117638029</id><published>2010-10-23T13:31:00.001+02:00</published><updated>2010-10-24T11:38:10.725+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='File Services'/><category scheme='http://www.blogger.com/atom/ns#' term='DFS'/><title type='text'>DFS: Manual removal of a DFS Link.</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;It can happen to everybody. A DFS Link gets deleted in the wrong way by accident, and now it's stale sources are being a burden in your DFSroots directory. This can happen due to errors in namespace replication or unclean shutdowns. The directory cannot be opened or manually deleted, so how can we get rid of this?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;When you try to open the directory you'll get the following error:&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Y9qL3xVT9hA/TMK21_WwmkI/AAAAAAAAAKs/4zCvS8Xep6o/s1600/dfsremoval1.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="56" nx="true" src="http://2.bp.blogspot.com/_Y9qL3xVT9hA/TMK21_WwmkI/AAAAAAAAAKs/4zCvS8Xep6o/s200/dfsremoval1.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;It makes sense to get this error, because DFS make a sort of junction point on your fileserver to relocate you to the real point. When you try to delete the folder you'll get this error:&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Y9qL3xVT9hA/TMK3M7Y7i4I/AAAAAAAAAKw/KXBDhp2lFec/s1600/dfsremoval2.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="155" nx="true" src="http://1.bp.blogspot.com/_Y9qL3xVT9hA/TMK3M7Y7i4I/AAAAAAAAAKw/KXBDhp2lFec/s200/dfsremoval2.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;When a DFS link gets created, a reparsepoint is created in the DFSroots directory. This is a link to the original directory. Also, see: &lt;a href="http://msdn.microsoft.com/en-us/library/aa365503(VS.85).aspx"&gt;http://msdn.microsoft.com/en-us/library/aa365503(VS.85).aspx&lt;/a&gt;&amp;nbsp;for more information.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;This reparsepoint is also what's causing the error. Normally, if you try to open a reparsepoint (like AppData in Windows 7 is), you'll get redirected to the original directory. In the case of DFS this works somewhat different, because the original directory isn't located on the same server.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;To fix this we have to take some steps. First, open up Command Prompt and browse to your DFSroots directory. In my case this is C:\DFSroots. Open up your DFS namespace and look at the folder contents. This folder is what's being published when an user accesses your DFS namespace.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Y9qL3xVT9hA/TMLFErW7vUI/AAAAAAAAAK0/xPM63WVFyzg/s1600/dfsremoval3.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="98" nx="true" src="http://3.bp.blogspot.com/_Y9qL3xVT9hA/TMLFErW7vUI/AAAAAAAAAK0/xPM63WVFyzg/s200/dfsremoval3.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Above are the folder contents of the DFSroots folder in my test environment. Top Secret is a stale folder, so I'd like to delete this. Windows contains a tool called &lt;strong&gt;fsutil&lt;/strong&gt; that can help us reach this goal. Type: &lt;strong&gt;fsutil reparsepoint query &lt;path dfsroots="" to=""&gt;\&lt;namespace&gt;\&lt;folder name=""&gt;&lt;/strong&gt;. In my case this would be &lt;strong&gt;fsutil reparsepoint query "C:\DFSroots\Public\Top Secret"&lt;/strong&gt;. Remember to enclose your query with quotes ("") when your name contains spaces.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;The result should look alot like the following:&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Y9qL3xVT9hA/TMLGHqwziJI/AAAAAAAAAK4/t4a1mLt2elY/s1600/dfsremoval4.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="98" nx="true" src="http://2.bp.blogspot.com/_Y9qL3xVT9hA/TMLGHqwziJI/AAAAAAAAAK4/t4a1mLt2elY/s200/dfsremoval4.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;As you can see within the Tag Value, this reparsepoint is created by/for Microsoft DFS. Now, we're gonna delete this reparsepoint so our view of the namespace will be nice and clean again. Type: &lt;strong&gt;fsutil reparsepoint delete &lt;path dfsroots="" to=""&gt;\&lt;namespace&gt;\&lt;folder name=""&gt;&lt;/strong&gt; and press Enter. Again, mind the quotes.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Y9qL3xVT9hA/TMLGywE4TAI/AAAAAAAAAK8/T3z-04S0YxQ/s1600/dfsremoval5.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="98" nx="true" src="http://2.bp.blogspot.com/_Y9qL3xVT9hA/TMLGywE4TAI/AAAAAAAAAK8/T3z-04S0YxQ/s200/dfsremoval5.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;In this case the rule is: No result is good result. When you get a blank line your command succeeded. When you try to remove something that's not a reparse point you'll get an error looking a lot like the following one:&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Y9qL3xVT9hA/TMLHKQ5qWzI/AAAAAAAAALA/bK1N5fdUNl0/s1600/dfsremoval6.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="98" nx="true" src="http://2.bp.blogspot.com/_Y9qL3xVT9hA/TMLHKQ5qWzI/AAAAAAAAALA/bK1N5fdUNl0/s200/dfsremoval6.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;This means the reparse point is already deleted or you're giving in the wrong directory in your command line.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Hope this helps in keeping your DFS environment clean and tidy.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Regards,&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Stefan Hazenbroek&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5978273702195385869-1994289077117638029?l=stefanhazenbroek.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stefanhazenbroek.blogspot.com/feeds/1994289077117638029/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://stefanhazenbroek.blogspot.com/2010/10/dfs-manual-removal-of-dfs-link.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/1994289077117638029'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/1994289077117638029'/><link rel='alternate' type='text/html' href='http://stefanhazenbroek.blogspot.com/2010/10/dfs-manual-removal-of-dfs-link.html' title='DFS: Manual removal of a DFS Link.'/><author><name>Stefan Hazenbroek</name><uri>http://www.blogger.com/profile/02126356175626503768</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Y9qL3xVT9hA/TMK21_WwmkI/AAAAAAAAAKs/4zCvS8Xep6o/s72-c/dfsremoval1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5978273702195385869.post-5837754973292054039</id><published>2010-10-23T12:15:00.002+02:00</published><updated>2010-10-24T11:37:56.363+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='BitLocker'/><category scheme='http://www.blogger.com/atom/ns#' term='File Services'/><title type='text'>File Services: Shares not available after a reboot</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;A short while ago a question was asked on the Technet Forums regarding folders not being shared as expected after a reboot. This specific issue was in regard to BitLocker, but this same issue applies when the folders are being hosted on a volume that's connected through a SAN (Fibre/iSCSI and such)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;After being able to answer the question&amp;nbsp;I thought I'd post a short blog article in regard to this issue, because it's a very common issue and not very well documented.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Issue&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;When you reboot your server all shares that are hosted on a SAN, on a BitLocker protected volume or anything other that needs a service in order to ensure it's availability. After restarting the &lt;strong&gt;Server&lt;/strong&gt; service these shares come available, but there are no clear errors in the eventlog that states something is wrong.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Resolution&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;The issue is due to the &lt;strong&gt;BitLocker&lt;/strong&gt; (or the service that connects your FC/iSCSI devices) service not being started yet when the &lt;strong&gt;Server&lt;/strong&gt; service is started. When the server service is started, it tries to locate all folders to share and disregard the ones that aren't reachable. Because the service required is started shortly after, you won't notice any apparent issues until you investigate them.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Luckily this issue is quite easily fixed by editing a value in the registry. I'll explain this by showing an example.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;1. First, open up &lt;strong&gt;services.msc&lt;/strong&gt;.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;When you look at the screenshot below, you'll see the shortname of &lt;strong&gt;BitLocker Drive Encryption&lt;/strong&gt;. Write down this name or save it somewhere, we'll need it later.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Y9qL3xVT9hA/TMK1okJyKQI/AAAAAAAAAKk/rZrk0W_rg5o/s1600/bdesvc.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" nx="true" src="http://2.bp.blogspot.com/_Y9qL3xVT9hA/TMK1okJyKQI/AAAAAAAAAKk/rZrk0W_rg5o/s200/bdesvc.jpg" width="177" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;2. Open &lt;strong&gt;regedit&lt;/strong&gt; (Start, Run, type: regedit)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Browse to &lt;strong&gt;Hkey Local Machine\SYSTEM\CurrentControlSet\LanManServer&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Y9qL3xVT9hA/TMKzyxrDp4I/AAAAAAAAAKc/uKk-i_Tnj9g/s1600/lmserver.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="75" nx="true" src="http://2.bp.blogspot.com/_Y9qL3xVT9hA/TMKzyxrDp4I/AAAAAAAAAKc/uKk-i_Tnj9g/s200/lmserver.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;When you look in the key you'll see a value called &lt;strong&gt;DependsOnService&lt;/strong&gt;. In my case this value is filled with &lt;strong&gt;SamSS&lt;/strong&gt; and &lt;strong&gt;Srv&lt;/strong&gt;. Open up this value.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Y9qL3xVT9hA/TMK1BdqHxAI/AAAAAAAAAKg/DjqPm2akaaI/s1600/dependsonservice1.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="177" nx="true" src="http://3.bp.blogspot.com/_Y9qL3xVT9hA/TMK1BdqHxAI/AAAAAAAAAKg/DjqPm2akaaI/s200/dependsonservice1.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;As you can see, both services that need to be started in order to start the &lt;strong&gt;Server&lt;/strong&gt; service are &lt;strong&gt;SamSS&lt;/strong&gt; and &lt;strong&gt;Srv&lt;/strong&gt;. Place the cursor after &lt;strong&gt;Srv&lt;/strong&gt; and press Enter. Now type &lt;strong&gt;bdesvc&lt;/strong&gt; (or the name of your required service you located in Step 1) and press Enter again. After filling in the value it should look like this:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Y9qL3xVT9hA/TMK1ytMapoI/AAAAAAAAAKo/Q25TVM_ZFDk/s1600/dependsonservice2.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="176" nx="true" src="http://2.bp.blogspot.com/_Y9qL3xVT9hA/TMK1ytMapoI/AAAAAAAAAKo/Q25TVM_ZFDk/s200/dependsonservice2.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Press &lt;strong&gt;Ok&lt;/strong&gt; and reboot your server.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;After a reboot your shares will be available directly from boot as they should be. Remember to remove the added service when you disable BitLocker again or remove the disks from SAN, otherwise the &lt;strong&gt;Server&lt;/strong&gt; service won't be able to start.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Hope this helps.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Regards,&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Stefan Hazenbroek&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5978273702195385869-5837754973292054039?l=stefanhazenbroek.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stefanhazenbroek.blogspot.com/feeds/5837754973292054039/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://stefanhazenbroek.blogspot.com/2010/10/file-services-shares-not-available.html#comment-form' title='1 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/5837754973292054039'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/5837754973292054039'/><link rel='alternate' type='text/html' href='http://stefanhazenbroek.blogspot.com/2010/10/file-services-shares-not-available.html' title='File Services: Shares not available after a reboot'/><author><name>Stefan Hazenbroek</name><uri>http://www.blogger.com/profile/02126356175626503768</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Y9qL3xVT9hA/TMK1okJyKQI/AAAAAAAAAKk/rZrk0W_rg5o/s72-c/bdesvc.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5978273702195385869.post-6847980837738113922</id><published>2010-07-05T21:00:00.022+02:00</published><updated>2010-10-09T16:29:40.810+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Active Directory'/><title type='text'>Active Directory: Managed Service Accounts</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;Windows Server 2008 R2 introduces the new and nifty feature that's called "Managed Service Accounts". A Managed Service Account (from now on I'll call it a MSA) is an account that is tied to a specific computer (for example an IIS Server) and maintains it's own password and SPN's. I can't remember the number of times a service wouldn't start after a reboot of a server because the password for the service had changed but they forgot to change the password at all necessary places.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;In this blogpost I will explain the following items: &lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;The requirements for MSA’s &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: xx-small;"&gt;Implementation of MSA's&lt;/span&gt; &lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;strong&gt;1. The requirements for MSA's&lt;/strong&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;A MSA depends on the object class &lt;strong&gt;msDS-ManagedServiceAccount&lt;/strong&gt;, for which your schema needs to be at the level of Windows Server 2008 R2. Also, only Windows Server 2008 R2 and Windows 7 support MSA's.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;MSA's update the password in the same way as a computer account updates it. By default, the password of a MSA gets updated when the computer account updates it's password. They don't listen to password policies and cannot be locked out or perform interactive logons. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;By default all MSA's are created in the &lt;strong&gt;CN=Managed Service Accounts,DC=domain,DC=net&lt;/strong&gt;. When using DSA.MSC and setting it to show "Advanced Features" also displays them.&lt;/span&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_Y9qL3xVT9hA/TDIgbwRYknI/AAAAAAAAAJI/vTP9VsqJTHE/s1600/msa1.jpg"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;However, as you see when you open the properties of a MSA, there's nothing to be set apart from the description. This is because all administration of MSA's is done in Powershell.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;span style="clear: left; cssfloat: left; float: left; font-family: Verdana, sans-serif; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" ex="true" height="200" src="http://1.bp.blogspot.com/_Y9qL3xVT9hA/TLB4XpVVyqI/AAAAAAAAAKM/JgovPcZCmH4/s200/msa1.jpg" width="180" /&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;span style="font-size: xx-small;"&gt;MSA's automatically maintain their own SPN's but cannot be linked to multiple computers at a time or to a cluster node.&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;strong&gt;2. Implementation of MSA's&lt;/strong&gt; &lt;span style="font-size: xx-small;"&gt;For the sake of argument I'll assume you are creating a service account for use with SQL (although this isn't supported by SQL Server yet because of VSS Backups and such). Also, I will use the name &lt;strong&gt;SASQL02&lt;/strong&gt;, but ofcourse you're free to change this to anything you want. For the servername I will use &lt;strong&gt;DB01&lt;/strong&gt;. &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;At the moment it's not possible to create a MSA that's longer than 15 characters, so stay under this limitation (see &lt;/span&gt;&lt;a href="http://derek858.blogspot.com/2010/02/server-2008-r2-managed-service-account.html"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;http://derek858.blogspot.com/2010/02/server-2008-r2-managed-service-account.html&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt; for more information about this)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;1. Open Powershell with the AD-Powershell modules loaded (Load this by using &lt;strong&gt;import-module ActiveDirectory&lt;/strong&gt; within Powershell)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;2. Create the MSA by using:&lt;/span&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;New-ADServiceAccount -Name SASQL02 -Enabled $True&lt;/span&gt;&lt;/blockquote&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;3. Now, associate the MSA to a computer account:&lt;/span&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;Add-ADComputerServiceAccount -Identity DB01 -ServiceAccount SASQL02&lt;/span&gt;&lt;/blockquote&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;4. Logon to the server on which the MSA will be running (in my case DB01). It's necessary to have the following features enabled on the target server:&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;Active Directory Module for Windows Powershell &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;.NET Framework 3.5.1 &lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;5. On the server start Powershell with the Active Directory modules loaded.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;6. Install the MSA at the server by using:&lt;/span&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;Install-ADServiceAccount -Identity SASQL02&lt;/span&gt;&lt;/blockquote&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;To install a MSA on a server you will need Local Administrator permissions on the target server and modify permissions on the MSA object in Active Directory.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;7. Open up &lt;strong&gt;services.msc&lt;/strong&gt;.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;8. Browse to your service and double click on it.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;9. Click the tab &lt;strong&gt;Log On&lt;/strong&gt;.&lt;/span&gt;&lt;br /&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;a href="http://2.bp.blogspot.com/_Y9qL3xVT9hA/TLB4kMTlGYI/AAAAAAAAAKQ/CaeWAdiHjto/s1600/msa2.jpg" imageanchor="1" style="clear: left; cssfloat: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;img border="0" ex="true" height="200" src="http://2.bp.blogspot.com/_Y9qL3xVT9hA/TLB4kMTlGYI/AAAAAAAAAKQ/CaeWAdiHjto/s200/msa2.jpg" width="177" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;a href="http://4.bp.blogspot.com/_Y9qL3xVT9hA/TDIl2jjZO0I/AAAAAAAAAJY/xse38lRsZgU/s1600/msa3.jpg"&gt;&lt;span style="font-size: xx-small;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;10. Click &lt;strong&gt;Browse &lt;/strong&gt;and type the name of the MSA.&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;a href="http://3.bp.blogspot.com/_Y9qL3xVT9hA/TLB4rKZFBgI/AAAAAAAAAKU/0Xbealcwz8I/s1600/msa3.jpg" imageanchor="1" style="clear: left; cssfloat: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;img border="0" ex="true" height="105" src="http://3.bp.blogspot.com/_Y9qL3xVT9hA/TLB4rKZFBgI/AAAAAAAAAKU/0Xbealcwz8I/s200/msa3.jpg" width="200" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;a href="http://3.bp.blogspot.com/_Y9qL3xVT9hA/TDImg-H3ECI/AAAAAAAAAJg/VXMDxkUlz6M/s1600/msa4.jpg"&gt;&lt;span style="font-size: xx-small;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;11. The account name is filled in in the following screen. You can see it's a MSA by looking at the dollar sign ($) behind the account name. Also, it's very important that the password field remains empty!&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;a href="http://4.bp.blogspot.com/_Y9qL3xVT9hA/TLB4xSfqK9I/AAAAAAAAAKY/KGIa6Z5JtEk/s1600/msa4.jpg" imageanchor="1" style="clear: left; cssfloat: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;img border="0" ex="true" height="200" src="http://4.bp.blogspot.com/_Y9qL3xVT9hA/TLB4xSfqK9I/AAAAAAAAAKY/KGIa6Z5JtEk/s200/msa4.jpg" width="176" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;a href="http://2.bp.blogspot.com/_Y9qL3xVT9hA/TDInGl_fevI/AAAAAAAAAJo/yb_sh2Pkxtc/s1600/msa5.jpg"&gt;&lt;span style="font-size: xx-small;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;12. Click OK and restart your service. After this moment it's no longer needed to manually change passwords, because your MSA will take care of this.&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;In a later blogpost I will explain how MSA's are maintained through your environment. In the meantime also check out &lt;/span&gt;&lt;a href="http://blogs.technet.com/b/askds/archive/2009/09/10/managed-service-accounts-understanding-implementing-best-practices-and-troubleshooting.aspx"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;This post by Ned Pyle&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;.&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;Regards,&lt;/span&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;Stefan Hazenbroek&lt;/span&gt;&lt;/div&gt;&lt;span style="font-size: xx-small;"&gt;&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;strong&gt;NOTE:&lt;/strong&gt; For some reason all images have gone byebye on me. I’ll repost them soon.&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5978273702195385869-6847980837738113922?l=stefanhazenbroek.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stefanhazenbroek.blogspot.com/feeds/6847980837738113922/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://stefanhazenbroek.blogspot.com/2010/07/active-directory-managed-service.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/6847980837738113922'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/6847980837738113922'/><link rel='alternate' type='text/html' href='http://stefanhazenbroek.blogspot.com/2010/07/active-directory-managed-service.html' title='Active Directory: Managed Service Accounts'/><author><name>Stefan Hazenbroek</name><uri>http://www.blogger.com/profile/02126356175626503768</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Y9qL3xVT9hA/TLB4XpVVyqI/AAAAAAAAAKM/JgovPcZCmH4/s72-c/msa1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5978273702195385869.post-5348952871326437156</id><published>2010-05-11T07:32:00.002+02:00</published><updated>2010-05-11T07:33:26.353+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ConfigMgr'/><category scheme='http://www.blogger.com/atom/ns#' term='Active Directory'/><title type='text'>ConfigMgr: AD Permissions for Domain Join Account</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;It's a good practise to use a service account for any sort of automated task, and this is no different with SCCM Operating System Deployment.&lt;br /&gt;&lt;br /&gt;SCCM OSD has the capability of automatically adding a workstation to the domain during the Task Sequence, so the amount of work that needs to be done by hand is kept to a bare minimum. You use a service account in SCCM that has the permissions to add the computer to the needed OU, but what permissions do you need exactly?&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;Well, at a minimum you'll need the following permissions:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://1.bp.blogspot.com/_Y9qL3xVT9hA/S-jriC4Sq8I/AAAAAAAAAJA/9VQapRDrGfw/s1600/sccmosd1.jpg"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;&lt;img src="http://1.bp.blogspot.com/_Y9qL3xVT9hA/S-jriC4Sq8I/AAAAAAAAAJA/9VQapRDrGfw/s320/sccmosd1.jpg" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: xx-small;"&gt;I hope this helps, I know I'll be back when I need it set again :)&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;&lt;br /&gt;Stefan Hazenbroek&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5978273702195385869-5348952871326437156?l=stefanhazenbroek.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stefanhazenbroek.blogspot.com/feeds/5348952871326437156/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://stefanhazenbroek.blogspot.com/2010/05/configmgr-ad-permissions-for-osd.html#comment-form' title='2 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/5348952871326437156'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/5348952871326437156'/><link rel='alternate' type='text/html' href='http://stefanhazenbroek.blogspot.com/2010/05/configmgr-ad-permissions-for-osd.html' title='ConfigMgr: AD Permissions for Domain Join Account'/><author><name>Stefan Hazenbroek</name><uri>http://www.blogger.com/profile/02126356175626503768</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Y9qL3xVT9hA/S-jriC4Sq8I/AAAAAAAAAJA/9VQapRDrGfw/s72-c/sccmosd1.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5978273702195385869.post-2255594803383356460</id><published>2010-05-10T21:43:00.001+02:00</published><updated>2010-07-05T21:09:25.373+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DFS'/><title type='text'>HOWTO: DFS and ABE in Server 2008 and 2008 R2</title><content type='html'>&lt;p&gt;&lt;font size="1" face="verda"&gt;This blogpost will be quite alot longer than other blogposts, but that’s not an issue in my opinion. Too many times I encounter a situation in which DFS is misconfigured for use with Access-based Enumeration. Some of the times I even encounter an environment in which the fileservers themselves are configured incorrectly. In this blogpost I will explain the following items:&lt;/font&gt;&lt;/p&gt;&lt;ol&gt;&lt;li&gt;&lt;font size="1" face="verda"&gt;Installing Distributed File System. &lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font size="1" face="verda"&gt;Configure a domain-based DFS Namespace.&lt;/font&gt; &lt;/li&gt;&lt;li&gt;&lt;font size="1" face="verda"&gt;Creating a DFS Link (Target/Folder Target). &lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font size="1" face="verda"&gt;Configuring Access-based Enumeration on the DFS Namespace and the DFS Links.&lt;/font&gt; &lt;/li&gt;&lt;li&gt;&lt;font size="1" face="verda"&gt;Setting the correct (NTFS and Share) permissions on the File Share that the DFS Link points to.&lt;/font&gt; &lt;/li&gt;&lt;li&gt;&lt;font size="1" face="verda"&gt;Enabling Access-based Enumeration on the File Share on the File Server.&lt;/font&gt; &lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;I’ll assume the following items are running as they should/are available, so I’ll not go into them any further:&lt;/font&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;font size="1" face="verda"&gt;A correctly working Active Directory infrastructure, running at least Windows Server 2008 Domain Functional Level. &lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font size="1" face="verda"&gt;Familiarity with creating users, groups and manipulating NTFS permissions. &lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font size="1" face="verda"&gt;You are logged in as a Domain Administrator. &lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font size="1" face="verda"&gt;The needed groups are available. This means you’ll need a group per DFS Link (or multiple, but that’s up to your design) and a group per folder that should have permissions set. I suggest you never set permissions deeper than the 4th folder, so that would be A\B\C\D and no deeper. &lt;/font&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;Now, on with the fun stuff.&lt;/font&gt;&lt;/p&gt;&lt;h5&gt;&lt;font face="verda"&gt;1. Install Distributed File System&lt;/font&gt;&lt;/h5&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;1) Open Server Manager, click &lt;strong&gt;Roles&lt;/strong&gt; and right-click on &lt;strong&gt;Roles&lt;/strong&gt;. Now click &lt;strong&gt;Add Roles&lt;/strong&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh5.ggpht.com/_Y9qL3xVT9hA/S-hgaKec5RI/AAAAAAAAACg/wvJ8t3mKCkU/s1600-h/dfs1%5B2%5D.jpg"&gt;&lt;font color="#333333" size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs1" border="0" alt="dfs1" src="http://lh5.ggpht.com/_Y9qL3xVT9hA/S-hga341xTI/AAAAAAAAACk/I1JOaJB8HfU/dfs1_thumb.jpg?imgmax=800" width="179" height="140" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;2) Click &lt;strong&gt;Next&lt;/strong&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;&amp;#160;&lt;/font&gt;&lt;a href="http://lh3.ggpht.com/_Y9qL3xVT9hA/S-hgbkaEWhI/AAAAAAAAACo/TWXaGnCGLgY/s1600-h/dfs2%5B2%5D.jpg"&gt;&lt;font color="#333333" size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs2" border="0" alt="dfs2" src="http://lh5.ggpht.com/_Y9qL3xVT9hA/S-hgcFS0tYI/AAAAAAAAACs/kaSfHcxFqBg/dfs2_thumb.jpg?imgmax=800" width="244" height="181" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;3) Select &lt;strong&gt;File Services&lt;/strong&gt; and click &lt;strong&gt;Next&lt;/strong&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh4.ggpht.com/_Y9qL3xVT9hA/S-hgctCRvfI/AAAAAAAAACw/VvNLG3LTouM/s1600-h/dfs3%5B2%5D.jpg"&gt;&lt;font color="#333333" size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs3" border="0" alt="dfs3" src="http://lh3.ggpht.com/_Y9qL3xVT9hA/S-hgdNRqAuI/AAAAAAAAAC0/4WjcUTRn2rE/dfs3_thumb.jpg?imgmax=800" width="244" height="181" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;4) Click &lt;strong&gt;Next&lt;/strong&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh3.ggpht.com/_Y9qL3xVT9hA/S-hgeJMy54I/AAAAAAAAAC4/i7zO6PXohBY/s1600-h/dfs4%5B2%5D.jpg"&gt;&lt;font color="#333333" size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs4" border="0" alt="dfs4" src="http://lh5.ggpht.com/_Y9qL3xVT9hA/S-hgexgZm6I/AAAAAAAAAC8/8xShWWd-xz0/dfs4_thumb.jpg?imgmax=800" width="244" height="181" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt;&amp;#160; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;5) Select &lt;strong&gt;DFS Namespaces&lt;/strong&gt; and click &lt;strong&gt;Next&lt;/strong&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh4.ggpht.com/_Y9qL3xVT9hA/S-hgfRJqrBI/AAAAAAAAADA/0p7mKAJh298/s1600-h/dfs5%5B2%5D.jpg"&gt;&lt;font color="#333333" size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs5" border="0" alt="dfs5" src="http://lh6.ggpht.com/_Y9qL3xVT9hA/S-hggIqNxSI/AAAAAAAAADE/RO_gQThhtb0/dfs5_thumb.jpg?imgmax=800" width="244" height="181" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;6) Choose &lt;strong&gt;Create a namespace later using the DFS Management Snap-in in Server Manager&lt;/strong&gt; and click &lt;strong&gt;Next&lt;/strong&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh5.ggpht.com/_Y9qL3xVT9hA/S-hgggQSJkI/AAAAAAAAADI/8sftV335gsw/s1600-h/dfs6%5B2%5D.jpg"&gt;&lt;font color="#333333" size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs6" border="0" alt="dfs6" src="http://lh6.ggpht.com/_Y9qL3xVT9hA/S-hghNYtYEI/AAAAAAAAADM/osiFjvDp8co/dfs6_thumb.jpg?imgmax=800" width="244" height="181" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1"&gt;&lt;font face="verda"&gt;7) Click &lt;strong&gt;Install.&lt;/strong&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh5.ggpht.com/_Y9qL3xVT9hA/S-hghUCvPAI/AAAAAAAAADQ/rk9mjLrf9to/s1600-h/dfs7%5B2%5D.jpg"&gt;&lt;font color="#333333" size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs7" border="0" alt="dfs7" src="http://lh3.ggpht.com/_Y9qL3xVT9hA/S-hgh-dnPqI/AAAAAAAAADU/VAi91EHFD0w/dfs7_thumb.jpg?imgmax=800" width="244" height="181" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;8) Click &lt;strong&gt;Close&lt;/strong&gt; and reboot the server.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh4.ggpht.com/_Y9qL3xVT9hA/S-hgiUiWLSI/AAAAAAAAADY/lxmO5jZmRgQ/s1600-h/dfs8%5B2%5D.jpg"&gt;&lt;font color="#333333" size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs8" border="0" alt="dfs8" src="http://lh5.ggpht.com/_Y9qL3xVT9hA/S-hgjGGgdzI/AAAAAAAAADc/1jnO2v6bbB4/dfs8_thumb.jpg?imgmax=800" width="244" height="181" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;&lt;h5&gt;&lt;font face="veda"&gt;&lt;strong&gt;2. Configure a domain-based DFS Namespace&lt;/strong&gt;.&lt;/font&gt;&lt;/h5&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;Now that DFS is up and running we need to create a DFS namespace. This part of the blogpost will explain how you can install a domain-based DFS namespace and configure it for use with Access-based Enumeration.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;1) Open the DFS Management Snap-in. This can be found in &lt;strong&gt;Start&lt;/strong&gt;, &lt;strong&gt;All Programs&lt;/strong&gt;, &lt;strong&gt;Administrative Tools&lt;/strong&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh4.ggpht.com/_Y9qL3xVT9hA/S-hgjem2i5I/AAAAAAAAADg/ddJBQbPRt3s/s1600-h/dfs9%5B2%5D.jpg"&gt;&lt;font color="#333333" size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs9" border="0" alt="dfs9" src="http://lh6.ggpht.com/_Y9qL3xVT9hA/S-hgj-3GbtI/AAAAAAAAADk/D88sSO1Mh6k/dfs9_thumb.jpg?imgmax=800" width="244" height="201" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;2) Click on &lt;strong&gt;Namespaces&lt;/strong&gt;. Right-click on Namespaces and choose &lt;strong&gt;New Namespace&lt;/strong&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh4.ggpht.com/_Y9qL3xVT9hA/S-hgkS5umAI/AAAAAAAAADo/gvTjhlqAl_o/s1600-h/dfs10%5B2%5D.jpg"&gt;&lt;font size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs10" border="0" alt="dfs10" src="http://lh6.ggpht.com/_Y9qL3xVT9hA/S-hglHHle7I/AAAAAAAAADs/3RPNAQNgVfk/dfs10_thumb.jpg?imgmax=800" width="244" height="152" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;3) Fill in the servername. In my case this is &lt;strong&gt;FS01 &lt;/strong&gt;and click &lt;strong&gt;Next&lt;/strong&gt;. This is the server that will be running as namespace server. This means in a domain based DFS infrastructure that the server hosts the namespaces, but all configuration items are also available in Active Directory (in CN=DFS-Configuration, CN=System, DC=contoso, DC=com for example). This is still a single point of failure because no other namespace servers are designated.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh4.ggpht.com/_Y9qL3xVT9hA/S-hglupF9wI/AAAAAAAAADw/Y8DFOlPivDs/s1600-h/dfs11%5B2%5D.jpg"&gt;&lt;font size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs11" border="0" alt="dfs11" src="http://lh3.ggpht.com/_Y9qL3xVT9hA/S-hgmGfe3dI/AAAAAAAAAD0/hsH6giC13WM/dfs11_thumb.jpg?imgmax=800" width="244" height="196" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;4) Fill in the name of your namespace and click &lt;strong&gt;Edit Settings&lt;/strong&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh5.ggpht.com/_Y9qL3xVT9hA/S-hgmvhqcXI/AAAAAAAAAD4/_9rcx1q77J4/s1600-h/dfs12%5B2%5D.jpg"&gt;&lt;font size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs12" border="0" alt="dfs12" src="http://lh6.ggpht.com/_Y9qL3xVT9hA/S-hgnLsZ2RI/AAAAAAAAAD8/084H1cZ_jzU/dfs12_thumb.jpg?imgmax=800" width="244" height="196" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt;&amp;#160;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;5) If needed, move the local path of the shared folder. You can do this by clicking &lt;strong&gt;Browse&lt;/strong&gt; and choosing a new path. This path will be in the metadata of the DFS infrastructure, or the empty copy of your file server infrastructure when it’s finished. This directory is 0 bytes and will stay this way when it’s managed correctly. Click &lt;strong&gt;Use custom permissions&lt;/strong&gt; and click &lt;strong&gt;Customize&lt;/strong&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh5.ggpht.com/_Y9qL3xVT9hA/S-hgns5qhZI/AAAAAAAAAEA/U_AzeXzsgHE/s1600-h/dfs13%5B2%5D.jpg"&gt;&lt;font size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs13" border="0" alt="dfs13" src="http://lh3.ggpht.com/_Y9qL3xVT9hA/S-hgoG_-3HI/AAAAAAAAAEE/kQ_QVhU8nww/dfs13_thumb.jpg?imgmax=800" width="200" height="244" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;6) Call me paranoid, but I like to keep my permissions granted to an absoluted minimum. Depending on the environment, I give &lt;strong&gt;Domain Admins&lt;/strong&gt; or fileserveradmins Full Control on the share and &lt;strong&gt;Domain Users&lt;/strong&gt; (also dependant on the environment) Change permissions. This way nobody can mess with the permissions except those that should maintain them. Click &lt;strong&gt;OK&lt;/strong&gt; when done adding the needed groups.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh5.ggpht.com/_Y9qL3xVT9hA/S-hgo1Ods4I/AAAAAAAAAEI/0YuoBo70u4E/s1600-h/dfs14%5B2%5D.jpg"&gt;&lt;font size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs14" border="0" alt="dfs14" src="http://lh4.ggpht.com/_Y9qL3xVT9hA/S-hgphBBQnI/AAAAAAAAAEM/Yw3P2Lth80k/dfs14_thumb.jpg?imgmax=800" width="202" height="244" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;7) Click &lt;strong&gt;Next&lt;/strong&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh3.ggpht.com/_Y9qL3xVT9hA/S-hgp0zHs2I/AAAAAAAAAEQ/ehyG_WH1BdY/s1600-h/dfs15%5B2%5D.jpg"&gt;&lt;font size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs15" border="0" alt="dfs15" src="http://lh3.ggpht.com/_Y9qL3xVT9hA/S-hgqSKlTXI/AAAAAAAAAEU/8IYLwM5xGf4/dfs15_thumb.jpg?imgmax=800" width="244" height="196" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt;&amp;#160;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;8) Choose &lt;strong&gt;domain-based namespace&lt;/strong&gt; and toggle &lt;strong&gt;Enable Windows Server 2008 Mode&lt;/strong&gt; to enabled. Click &lt;strong&gt;Next&lt;/strong&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1"&gt;&lt;font face="verda"&gt;&lt;strong&gt;&lt;em&gt;Important:&lt;/em&gt;&lt;/strong&gt; Access-based Enumeration will not function unless you have your namespace running in &lt;strong&gt;Windows Server 2008&lt;/strong&gt; mode.&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh4.ggpht.com/_Y9qL3xVT9hA/S-hgq8ModyI/AAAAAAAAAEY/f1qc7atHzYo/s1600-h/dfs16%5B2%5D.jpg"&gt;&lt;font size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs16" border="0" alt="dfs16" src="http://lh4.ggpht.com/_Y9qL3xVT9hA/S-hgsFjz-rI/AAAAAAAAAEc/vWZ42neaRj0/dfs16_thumb.jpg?imgmax=800" width="244" height="196" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;9) Review all your namespace settings and if everything is correct, click &lt;strong&gt;Create&lt;/strong&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh6.ggpht.com/_Y9qL3xVT9hA/S-hgs0L2ebI/AAAAAAAAAEg/8tZxFXQV9yg/s1600-h/dfs17%5B2%5D.jpg"&gt;&lt;font size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs17" border="0" alt="dfs17" src="http://lh3.ggpht.com/_Y9qL3xVT9hA/S-hgtZqRrZI/AAAAAAAAAEk/t7KbGteiUKg/dfs17_thumb.jpg?imgmax=800" width="244" height="196" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;10) Click &lt;strong&gt;Close&lt;/strong&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh6.ggpht.com/_Y9qL3xVT9hA/S-hgtqR7vRI/AAAAAAAAAEo/iLC57ScoIWo/s1600-h/dfs18%5B2%5D.jpg"&gt;&lt;font size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs18" border="0" alt="dfs18" src="http://lh3.ggpht.com/_Y9qL3xVT9hA/S-hguPCaJ0I/AAAAAAAAAEs/r_oC0txAci8/dfs18_thumb.jpg?imgmax=800" width="244" height="196" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;h5&gt;&lt;font face="Verdana"&gt;3. Create a DFS Link (Target/Folder Target)&lt;/font&gt;&lt;/h5&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;A DFS Link can be seen as a shortcut to another file server on which the files themself are hosted. In this part I will explain how to create a DFS Link.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;1) Open DFS Namespaces, expand Namespaces and right-click on the namespace created earlier. Click &lt;strong&gt;New Folder&lt;/strong&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh3.ggpht.com/_Y9qL3xVT9hA/S-hguiqcmqI/AAAAAAAAAEw/_6Zr856fN_s/s1600-h/dfs19%5B2%5D.jpg"&gt;&lt;font size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs19" border="0" alt="dfs19" src="http://lh5.ggpht.com/_Y9qL3xVT9hA/S-hgvGEYlOI/AAAAAAAAAE0/YAkeJCoKzHg/dfs19_thumb.jpg?imgmax=800" width="244" height="192" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;2) Fill in the name of the folder, for this example I used &lt;strong&gt;Legal&lt;/strong&gt; and click &lt;strong&gt;Add&lt;/strong&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh6.ggpht.com/_Y9qL3xVT9hA/S-hgvtZ3wjI/AAAAAAAAAE4/pB4uKTxEOTs/s1600-h/dfs20%5B2%5D.jpg"&gt;&lt;font size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs20" border="0" alt="dfs20" src="http://lh6.ggpht.com/_Y9qL3xVT9hA/S-hgwYtIoYI/AAAAAAAAAE8/VeXB6N0h17M/dfs20_thumb.jpg?imgmax=800" width="238" height="244" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;3) Fill in the path to the shared folder on your fileserver or click &lt;strong&gt;Browse&lt;/strong&gt;. Click &lt;strong&gt;OK&lt;/strong&gt; in the Folder Target dialog box and in the Folder dialog box.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh5.ggpht.com/_Y9qL3xVT9hA/S-hgwzHphmI/AAAAAAAAAFA/gfU3A5XCbic/s1600-h/dfs21%5B2%5D.jpg"&gt;&lt;font size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs21" border="0" alt="dfs21" src="http://lh3.ggpht.com/_Y9qL3xVT9hA/S-hgxdfViuI/AAAAAAAAAFE/x2W4P69QBao/dfs21_thumb.jpg?imgmax=800" width="244" height="105" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh6.ggpht.com/_Y9qL3xVT9hA/S-hgxz56T8I/AAAAAAAAAFI/R5venvwjA6A/s1600-h/dfs22%5B2%5D.jpg"&gt;&lt;font size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs22" border="0" alt="dfs22" src="http://lh4.ggpht.com/_Y9qL3xVT9hA/S-hgyHQnCMI/AAAAAAAAAFM/Jh2mZ1qWY20/dfs22_thumb.jpg?imgmax=800" width="244" height="244" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;h5&gt;&lt;font size="1"&gt;&lt;font face="verda"&gt;&lt;strong&gt;4. Configuring Access-based Enumeration on the DFS Namespace and the DFS Links&lt;/strong&gt;.&lt;/font&gt;&lt;/font&gt;&lt;/h5&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;Access-based Enumeration is a method to hide files that users don’t have permissions to. As easy as this sounds, this means the NTFS permissions should be setup correctly, otherwise users will still see all files. In this part I will explain how the DFS namespace and the DFS Links can be configured to have Access-based Enumeration in place. I will assume all needed Active Directory Groups are already in place and filled with the users that need permission to this location. For the sake of demonstration I will use the group name &lt;strong&gt;DL-Legal-R&lt;/strong&gt; for the DFS Link &lt;strong&gt;Legal&lt;/strong&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1"&gt;&lt;font face="verda"&gt;&lt;strong&gt;NOTE! &lt;/strong&gt;All commands in this section will give a “Done processing this command” notice when the command executed succesfully.&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1"&gt;&lt;font face="verda"&gt;&lt;strong&gt;NOTE!&lt;/strong&gt; Although it is possible to set permissions on the DFS Link (in C:\DFSRoots\…) this is not supported as the permissions will be overwritten by the next Active Directory or registry poll-cycle of DFS. The following method is the only supported method of configuring Access-based Enumeration.&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;1) Open up &lt;strong&gt;Command Prompt&lt;/strong&gt; (Start, type &lt;strong&gt;cmd&lt;/strong&gt;).&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1"&gt;&lt;font face="verda"&gt;2) Type &lt;strong&gt;dfsutil property abde enable &amp;lt;path to the DFS Namespace (in my case &lt;/strong&gt;&lt;/font&gt;&lt;/font&gt;&lt;a href="file://\\stefanhazenbroek.net\public"&gt;&lt;strong&gt;&lt;font size="1" face="verda"&gt;\\stefanhazenbroek.net\public&lt;/font&gt;&lt;/strong&gt;&lt;/a&gt;&lt;font size="1"&gt;&lt;font face="verda"&gt;&lt;strong&gt;) &lt;/strong&gt;and press enter&lt;strong&gt;.&lt;/strong&gt; This will enable abde (Access-based Directory Enumeration) on the namespace.&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh6.ggpht.com/_Y9qL3xVT9hA/S-hgyrtHlRI/AAAAAAAAAFQ/k6XqPawnOOk/s1600-h/dfs23%5B2%5D.jpg"&gt;&lt;font size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs23" border="0" alt="dfs23" src="http://lh5.ggpht.com/_Y9qL3xVT9hA/S-hgzA-4JZI/AAAAAAAAAFU/NESUks7dB8M/dfs23_thumb.jpg?imgmax=800" width="244" height="27" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;3) Type &lt;strong&gt;dfsutil property acl reset &amp;lt;path to the DFS Link (in my case &lt;a href="file://\\stefanhazenbroek.net\public\legal"&gt;\\stefanhazenbroek.net\public\legal&lt;/a&gt;)&lt;/strong&gt; and press enter. This will reset all permissions on the DFS Link to the default.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh6.ggpht.com/_Y9qL3xVT9hA/S-hgzkjvGcI/AAAAAAAAAFY/dTQX-dWEM2w/s1600-h/dfs24%5B2%5D.jpg"&gt;&lt;font size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs24" border="0" alt="dfs24" src="http://lh3.ggpht.com/_Y9qL3xVT9hA/S-hg0MCqY3I/AAAAAAAAAFc/TYxe5bfQG9o/dfs24_thumb.jpg?imgmax=800" width="244" height="27" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1"&gt;&lt;font face="verda"&gt;4) Type &lt;strong&gt;dfsutil property acl control &amp;lt;path to the DFS Link (in my case &lt;/strong&gt;&lt;/font&gt;&lt;/font&gt;&lt;a href="file://\\stefanhazenbroek.net\public\legal"&gt;&lt;strong&gt;&lt;font size="1" face="verda"&gt;\\stefanhazenbroek.net\public\legal&lt;/font&gt;&lt;/strong&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt;)&amp;gt;&lt;strong&gt; protect&lt;/strong&gt; and press enter.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh6.ggpht.com/_Y9qL3xVT9hA/S-hg0lAHrvI/AAAAAAAAAFg/hLyE68t53GE/s1600-h/dfs25%5B2%5D.jpg"&gt;&lt;font size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs25" border="0" alt="dfs25" src="http://lh5.ggpht.com/_Y9qL3xVT9hA/S-hg1CNAmSI/AAAAAAAAAFk/jlG7fG3FCA0/dfs25_thumb.jpg?imgmax=800" width="244" height="25" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;5) Type &lt;strong&gt;dfsutil property acl grant &amp;lt;path to the DFS Link (in my case \\stefanhazenbroek.net\public\legal&amp;gt; &amp;lt;AD Groupname&amp;gt;:R) &lt;/strong&gt;and press enter. Repeat this step for every group that needs access to the DFS Link. Remember, all groups that are added in here will see the DFS Link, the rest won’t know it exists.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh3.ggpht.com/_Y9qL3xVT9hA/S-hg1nW8YWI/AAAAAAAAAFo/a95AiYzuSKM/s1600-h/dfs26%5B2%5D.jpg"&gt;&lt;font size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs26" border="0" alt="dfs26" src="http://lh5.ggpht.com/_Y9qL3xVT9hA/S-hg1xPNSRI/AAAAAAAAAFs/XTHl0g2DIZw/dfs26_thumb.jpg?imgmax=800" width="244" height="22" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1"&gt;&lt;font face="verda"&gt;6) Type &lt;strong&gt;dfsutil property acl &amp;lt;path to the DFS Link (in my case &lt;/strong&gt;&lt;/font&gt;&lt;/font&gt;&lt;a href="file://\\stefanhazenbroek.net\public\legal"&gt;&lt;strong&gt;&lt;font size="1" face="verda"&gt;\\stefanhazenbroek.net\public\legal&lt;/font&gt;&lt;/strong&gt;&lt;/a&gt;&lt;font size="1"&gt;&lt;font face="verda"&gt;&lt;strong&gt;)&amp;gt;&lt;/strong&gt; and check if all permissions are set correctly. R stands for Read-only, F stands for Full Control.&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh4.ggpht.com/_Y9qL3xVT9hA/S-hg2y6EOZI/AAAAAAAAAFw/3ZK9e2Kh_Aw/s1600-h/dfs27%5B2%5D.jpg"&gt;&lt;font size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs27" border="0" alt="dfs27" src="http://lh3.ggpht.com/_Y9qL3xVT9hA/S-hg3ul0jkI/AAAAAAAAAF0/TuLyofXfh7Q/dfs27_thumb.jpg?imgmax=800" width="244" height="36" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;h5&gt;&lt;font size="1" face="verda"&gt;&lt;/font&gt;&lt;/h5&gt;&lt;h5&gt;&lt;font size="1" face="verda"&gt;&lt;/font&gt;&lt;/h5&gt;&lt;h6&gt;&lt;font face="verda"&gt;&lt;/font&gt;&lt;/h6&gt;&lt;h5&gt;&lt;font size="1" face="verda"&gt;&lt;font size="2" face="Verdana"&gt;5 Setting the correct (NTFS and Share) permissions on the File share the DFS link points to.&lt;/font&gt;&amp;#160;&lt;/font&gt;&lt;/h5&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;As important as setting the correct permissions on your DFS Links is, it’s nothing compared to setting the correct permissions on your Fileservers. In this example I will explain setting the correct permissions on the fileserver by setting permissions on the root folder (so the folder that your DFS Link points to) and one folder deeper by using Active Directory groups.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1"&gt;&lt;font face="verda"&gt;1) Go to your fileserver and right-click on the folder that operates as root folder for your DFS Link (this is the same folder as your filled in during step 3.3 in this blogpost. Choose &lt;strong&gt;Properties&lt;/strong&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1"&gt;&lt;font face="verda"&gt;&lt;strong&gt;REMEMBER!&lt;/strong&gt; The permissions set on this folder should be the same as the permissions set on your DFS Link as set in 4.5 of this blogpost.&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh3.ggpht.com/_Y9qL3xVT9hA/S-hg4AHSTLI/AAAAAAAAAF4/c0cmf4M9_Tk/s1600-h/dfs28%5B2%5D.jpg"&gt;&lt;font color="#333333" size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs28" border="0" alt="dfs28" src="http://lh4.ggpht.com/_Y9qL3xVT9hA/S-hg4sOhfMI/AAAAAAAAAF8/PAQ1nw96RGg/dfs28_thumb.jpg?imgmax=800" width="226" height="244" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;2) As you can see, the permissions are still set as they were by default. Click &lt;strong&gt;Advanced&lt;/strong&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh3.ggpht.com/_Y9qL3xVT9hA/S-hg5JcGRwI/AAAAAAAAAGA/PWBb8xkTQzY/s1600-h/dfs29%5B2%5D.jpg"&gt;&lt;font color="#333333" size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs29" border="0" alt="dfs29" src="http://lh3.ggpht.com/_Y9qL3xVT9hA/S-hg5kIgDlI/AAAAAAAAAGE/NCUNIFHNVlo/dfs29_thumb.jpg?imgmax=800" width="190" height="244" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;3) Now, click &lt;strong&gt;Change Permissions&lt;/strong&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh4.ggpht.com/_Y9qL3xVT9hA/S-hg6pjdXXI/AAAAAAAAAGI/5u1Rc1oAHXQ/s1600-h/dfs30%5B2%5D.jpg"&gt;&lt;font color="#333333" size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs30" border="0" alt="dfs30" src="http://lh5.ggpht.com/_Y9qL3xVT9hA/S-hg7TtzYTI/AAAAAAAAAGM/kt3vCYvn714/dfs30_thumb.jpg?imgmax=800" width="244" height="184" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;4) Untoggle the checkbox at &lt;strong&gt;Include inheritable permissions from this object’s parent &lt;/strong&gt;and click &lt;strong&gt;Apply&lt;/strong&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh6.ggpht.com/_Y9qL3xVT9hA/S-hg8PyN5yI/AAAAAAAAAGQ/9GNpG0pzoIc/s1600-h/dfs31%5B2%5D.jpg"&gt;&lt;font color="#333333" size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs31" border="0" alt="dfs31" src="http://lh6.ggpht.com/_Y9qL3xVT9hA/S-hg8gf76jI/AAAAAAAAAGU/Lhk5ykA3U5Y/dfs31_thumb.jpg?imgmax=800" width="244" height="184" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;5) Click &lt;strong&gt;Remove&lt;/strong&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh6.ggpht.com/_Y9qL3xVT9hA/S-hg9B-t70I/AAAAAAAAAGY/RkYgEtSYi9g/s1600-h/dfs32%5B2%5D.jpg"&gt;&lt;font color="#333333" size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs32" border="0" alt="dfs32" src="http://lh4.ggpht.com/_Y9qL3xVT9hA/S-hg9jFxNcI/AAAAAAAAAGc/JxxgQigAHIw/dfs32_thumb.jpg?imgmax=800" width="244" height="113" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;6) Click &lt;strong&gt;Add&lt;/strong&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh4.ggpht.com/_Y9qL3xVT9hA/S-hg-GrnUJI/AAAAAAAAAGg/KNNE8aOlN0s/s1600-h/dfs33%5B2%5D.jpg"&gt;&lt;font color="#333333" size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs33" border="0" alt="dfs33" src="http://lh6.ggpht.com/_Y9qL3xVT9hA/S-hg-S1EvmI/AAAAAAAAAGk/xbAS0mt_A8c/dfs33_thumb.jpg?imgmax=800" width="244" height="184" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;7) Search for &lt;strong&gt;Domain Admins&lt;/strong&gt; or any other group that will manage the fileserver infrastructure, for example &lt;strong&gt;FileServerAdmins &lt;/strong&gt;and click OK.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh5.ggpht.com/_Y9qL3xVT9hA/S-hg-0h5x2I/AAAAAAAAAGo/hi2o3jvxtBw/s1600-h/dfs34%5B2%5D.jpg"&gt;&lt;font color="#333333" size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs34" border="0" alt="dfs34" src="http://lh3.ggpht.com/_Y9qL3xVT9hA/S-hg_hOEhJI/AAAAAAAAAGs/gXZjtrIAAdo/dfs34_thumb.jpg?imgmax=800" width="244" height="131" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;8) Toggle &lt;strong&gt;Full Control&lt;/strong&gt; (all other checkboxes will be marked automatically) and click &lt;strong&gt;OK&lt;/strong&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh4.ggpht.com/_Y9qL3xVT9hA/S-hhAMyPqZI/AAAAAAAAAGw/bvuW259usys/s1600-h/dfs35%5B2%5D.jpg"&gt;&lt;font color="#333333" size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs35" border="0" alt="dfs35" src="http://lh6.ggpht.com/_Y9qL3xVT9hA/S-hhAtXfiUI/AAAAAAAAAG0/t9HOuQUuXhs/dfs35_thumb.jpg?imgmax=800" width="192" height="244" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt;&amp;#160; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;9) Click &lt;strong&gt;OK&lt;/strong&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh4.ggpht.com/_Y9qL3xVT9hA/S-hhBK2nusI/AAAAAAAAAG4/F9lRVN2aP-A/s1600-h/dfs36%5B2%5D.jpg"&gt;&lt;font color="#333333" size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs36" border="0" alt="dfs36" src="http://lh3.ggpht.com/_Y9qL3xVT9hA/S-hhBksUsCI/AAAAAAAAAG8/u2nhAsh-aII/dfs36_thumb.jpg?imgmax=800" width="244" height="184" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;10) Click &lt;strong&gt;OK&lt;/strong&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh4.ggpht.com/_Y9qL3xVT9hA/S-hhCcfmSJI/AAAAAAAAAHA/6dcyw-j4X2c/s1600-h/dfs37%5B2%5D.jpg"&gt;&lt;font color="#333333" size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs37" border="0" alt="dfs37" src="http://lh4.ggpht.com/_Y9qL3xVT9hA/S-hhDJjPzcI/AAAAAAAAAHE/ENtoMdI96YQ/dfs37_thumb.jpg?imgmax=800" width="244" height="184" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;11) Click &lt;strong&gt;Add&lt;/strong&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh4.ggpht.com/_Y9qL3xVT9hA/S-hhDfmuyyI/AAAAAAAAAHI/m2Crku5tAo8/s1600-h/dfs38%5B2%5D.jpg"&gt;&lt;font color="#333333" size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs38" border="0" alt="dfs38" src="http://lh3.ggpht.com/_Y9qL3xVT9hA/S-hhEPJaTII/AAAAAAAAAHM/bu9gevgBiaY/dfs38_thumb.jpg?imgmax=800" width="203" height="244" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;12) Search for the group you use to give access to the folder.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh4.ggpht.com/_Y9qL3xVT9hA/S-hhExGYYFI/AAAAAAAAAHQ/tvQ7a9IOq8I/s1600-h/dfs39%5B2%5D.jpg"&gt;&lt;font color="#333333" size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs39" border="0" alt="dfs39" src="http://lh6.ggpht.com/_Y9qL3xVT9hA/S-hhFSh085I/AAAAAAAAAHU/IuDQ4N2YmXk/dfs39_thumb.jpg?imgmax=800" width="244" height="132" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;13) Grant Read &amp;amp; Execute, List Folder Contents and Read permissions to this group and click &lt;strong&gt;Advanced&lt;/strong&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh6.ggpht.com/_Y9qL3xVT9hA/S-hhFw9udxI/AAAAAAAAAHY/2WQlJ0sxKAA/s1600-h/dfs40%5B2%5D.jpg"&gt;&lt;font color="#333333" size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs40" border="0" alt="dfs40" src="http://lh3.ggpht.com/_Y9qL3xVT9hA/S-hhGVadGpI/AAAAAAAAAHc/i7dTEmhPLC0/dfs40_thumb.jpg?imgmax=800" width="190" height="244" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;14) Click &lt;strong&gt;Change Permissions&lt;/strong&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh3.ggpht.com/_Y9qL3xVT9hA/S-hhG9G35QI/AAAAAAAAAHg/eb7Kfli4YwE/s1600-h/dfs41%5B2%5D.jpg"&gt;&lt;font color="#333333" size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs41" border="0" alt="dfs41" src="http://lh3.ggpht.com/_Y9qL3xVT9hA/S-hhHb4lb2I/AAAAAAAAAHk/y8BWlhLurUg/dfs41_thumb.jpg?imgmax=800" width="244" height="184" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;15) Click &lt;strong&gt;Edit&lt;/strong&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh5.ggpht.com/_Y9qL3xVT9hA/S-hhIC30-ZI/AAAAAAAAAHo/WSx5ZZTa98k/s1600-h/dfs42%5B2%5D.jpg"&gt;&lt;font color="#333333" size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs42" border="0" alt="dfs42" src="http://lh3.ggpht.com/_Y9qL3xVT9hA/S-hhI6pbfvI/AAAAAAAAAHs/8-WQFSZ_D9k/dfs42_thumb.jpg?imgmax=800" width="244" height="184" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt;&amp;#160; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;16) Change &lt;strong&gt;Apply To&lt;/strong&gt; from “This Folder, Subfolders and files” to “This Folder Only” and click &lt;strong&gt;OK&lt;/strong&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh3.ggpht.com/_Y9qL3xVT9hA/S-hhJEdGK2I/AAAAAAAAAHw/QG-1U8Xr68M/s1600-h/dfs43%5B2%5D.jpg"&gt;&lt;font color="#333333" size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs43" border="0" alt="dfs43" src="http://lh4.ggpht.com/_Y9qL3xVT9hA/S-hhJvf1cKI/AAAAAAAAAH0/HyaqmbDIYuQ/dfs43_thumb.jpg?imgmax=800" width="192" height="244" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;17) As you can see now, the permission is changed from “Read and Execute” to “Special”. Click &lt;strong&gt;OK&lt;/strong&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh6.ggpht.com/_Y9qL3xVT9hA/S-hhKY98baI/AAAAAAAAAH4/TuBz-oXTcZ8/s1600-h/dfs44%5B2%5D.jpg"&gt;&lt;font color="#333333" size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs44" border="0" alt="dfs44" src="http://lh6.ggpht.com/_Y9qL3xVT9hA/S-hhKzNuT-I/AAAAAAAAAH8/1bLDFKlHxYU/dfs44_thumb.jpg?imgmax=800" width="244" height="184" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;18) Click &lt;strong&gt;OK&lt;/strong&gt; again. Now the NTFS permissions for this folder are set up correctly. Repeat the step as needed until all groups that you’ve added in the DFS Link are also added here. Administrative Groups should have “This Folder, Subfolders and Files” set as permission, groups that contain users should have “This Folder Only” permission set.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh5.ggpht.com/_Y9qL3xVT9hA/S-hhLVUjfOI/AAAAAAAAAIA/OKdeNIfC9hw/s1600-h/dfs45%5B2%5D.jpg"&gt;&lt;font color="#333333" size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs45" border="0" alt="dfs45" src="http://lh3.ggpht.com/_Y9qL3xVT9hA/S-hhMaShSBI/AAAAAAAAAIE/DZqUVzMvkTg/dfs45_thumb.jpg?imgmax=800" width="189" height="244" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;19) Now we go a folder deeper. For this case I created the folder &lt;strong&gt;Legaldocuments&lt;/strong&gt; with the Active Directory group &lt;strong&gt;DL-Legal-Legaldocuments-M&lt;/strong&gt; and set this as the final folder in my permissions structure. In your case there’ll probably be one or two extra folders before you reach the last one, but in that case you can repeat the earlier steps with new groups. Keep in mind that Domain Admins is already added because we granted inherited permissions to this group.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;20) Click &lt;strong&gt;Edit&lt;/strong&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh4.ggpht.com/_Y9qL3xVT9hA/S-hhM_fgQ6I/AAAAAAAAAII/7RlL-vX65NM/s1600-h/dfs46%5B2%5D.jpg"&gt;&lt;font color="#333333" size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs46" border="0" alt="dfs46" src="http://lh6.ggpht.com/_Y9qL3xVT9hA/S-hhNY7AvQI/AAAAAAAAAIM/jmy9N3eHYyo/dfs46_thumb.jpg?imgmax=800" width="190" height="244" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;21) Click &lt;strong&gt;Add&lt;/strong&gt; and add the group you created for this folder, see earlier in this blogpost how this is done. In my case I added the group &lt;strong&gt;DL-Legal-Legaldocuments-M&lt;/strong&gt; and granted &lt;strong&gt;Modify&lt;/strong&gt; permissions. Click &lt;strong&gt;OK&lt;/strong&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh6.ggpht.com/_Y9qL3xVT9hA/S-hhN5w2KoI/AAAAAAAAAIQ/B0g5EsR15SQ/s1600-h/dfs47%5B2%5D.jpg"&gt;&lt;font color="#333333" size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs47" border="0" alt="dfs47" src="http://lh4.ggpht.com/_Y9qL3xVT9hA/S-hhORPisnI/AAAAAAAAAIU/aFpEqm2_bGo/dfs47_thumb.jpg?imgmax=800" width="203" height="244" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;22) Click &lt;strong&gt;OK&lt;/strong&gt; again.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh3.ggpht.com/_Y9qL3xVT9hA/S-hhPe9l3EI/AAAAAAAAAIY/ukgB1va8LUk/s1600-h/dfs48%5B2%5D.jpg"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs48" border="0" alt="dfs48" src="http://lh5.ggpht.com/_Y9qL3xVT9hA/S-hhtzrxdGI/AAAAAAAAAIc/SDJOtJ959uM/dfs48_thumb.jpg?imgmax=800" width="190" height="244" /&gt;&lt;/a&gt; &lt;/p&gt;&lt;p&gt;&lt;font face="Verdana"&gt;&lt;strong&gt;6 Enabling Access-based Enumeration on the File Share on the File Server.&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;1) Go to &lt;strong&gt;Start&lt;/strong&gt;, &lt;strong&gt;Administrative Tools&lt;/strong&gt; and click on &lt;strong&gt;Share and Storage Management&lt;/strong&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh4.ggpht.com/_Y9qL3xVT9hA/S-hhubeeHTI/AAAAAAAAAIg/LFC02ey-1to/s1600-h/dfs49%5B2%5D.jpg"&gt;&lt;font color="#333333" size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs49" border="0" alt="dfs49" src="http://lh6.ggpht.com/_Y9qL3xVT9hA/S-hhu6du78I/AAAAAAAAAIk/9VaTvnKyyIQ/dfs49_thumb.jpg?imgmax=800" width="244" height="127" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;2) Choose the Share for use with DFS and click &lt;strong&gt;Properties&lt;/strong&gt; on the right-side of the screen (second blue tab at the right).&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh4.ggpht.com/_Y9qL3xVT9hA/S-hhvRCiwpI/AAAAAAAAAIo/sOyuMztHBfw/s1600-h/dfs50%5B2%5D.jpg"&gt;&lt;font color="#333333" size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs50" border="0" alt="dfs50" src="http://lh5.ggpht.com/_Y9qL3xVT9hA/S-hhvzSxltI/AAAAAAAAAIs/dUZNrVbIW0E/dfs50_thumb.jpg?imgmax=800" width="244" height="179" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;3) Click &lt;strong&gt;Advanced&lt;/strong&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh3.ggpht.com/_Y9qL3xVT9hA/S-hhwP5GxbI/AAAAAAAAAIw/JLqfN-02nIg/s1600-h/dfs51%5B2%5D.jpg"&gt;&lt;font color="#333333" size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs51" border="0" alt="dfs51" src="http://lh4.ggpht.com/_Y9qL3xVT9hA/S-hhwtR1RCI/AAAAAAAAAI0/MGcs5WlSIdg/dfs51_thumb.jpg?imgmax=800" width="193" height="244" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;4) Toggle &lt;strong&gt;Enable access-based enumeration&lt;/strong&gt; so the checkbox is enabled.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://lh3.ggpht.com/_Y9qL3xVT9hA/S-hhxUQpHHI/AAAAAAAAAI4/K4nGGALpMug/s1600-h/dfs52%5B2%5D.jpg"&gt;&lt;font color="#333333" size="1" face="verda"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="dfs52" border="0" alt="dfs52" src="http://lh4.ggpht.com/_Y9qL3xVT9hA/S-hhx4sERpI/AAAAAAAAAI8/NmtqzeK7enA/dfs52_thumb.jpg?imgmax=800" width="220" height="244" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="1" face="verda"&gt;&amp;#160; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;Congratulations, you’ve succesfully setup a simple DFS environment with a file share that has access-based enumeration enabled. It’s up to you to scale this to the enterprise solution you want it to be. Ofcourse, in the case of questions you can always ask them here or by emailing me at stefan&amp;lt;dot&amp;gt;hazenbroek&amp;lt;@&amp;gt;descentes&amp;lt;dot&amp;gt;nl (replace &amp;lt;dot&amp;gt; with . and &amp;lt;@&amp;gt; with @ ofcourse :))&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;I hope this howto has been of use for you.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1" face="verda"&gt;Stefan Hazenbroek&lt;/font&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5978273702195385869-2255594803383356460?l=stefanhazenbroek.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stefanhazenbroek.blogspot.com/feeds/2255594803383356460/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://stefanhazenbroek.blogspot.com/2010/05/dfs-domain-based-dfs-and-access-based.html#comment-form' title='2 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/2255594803383356460'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/2255594803383356460'/><link rel='alternate' type='text/html' href='http://stefanhazenbroek.blogspot.com/2010/05/dfs-domain-based-dfs-and-access-based.html' title='HOWTO: DFS and ABE in Server 2008 and 2008 R2'/><author><name>Stefan Hazenbroek</name><uri>http://www.blogger.com/profile/02126356175626503768</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh5.ggpht.com/_Y9qL3xVT9hA/S-hga341xTI/AAAAAAAAACk/I1JOaJB8HfU/s72-c/dfs1_thumb.jpg?imgmax=800' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5978273702195385869.post-6366371803037162360</id><published>2010-04-19T10:56:00.000+02:00</published><updated>2010-04-19T10:56:36.820+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ConfigMgr'/><title type='text'>ConfigMgr: Software Update Point - The server name or address could not be resolved</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;The first thing I recommend costumers who are using SCCM is: Install the ConfigMgr Admin Console on a management server and keep your hands off the site server. This way when you accidentally fire up a script that contains a reboot, it'll restart your management server and not your site server. Also, when using it like this it'll keep your site server cleaned up and tidy, which is always something you'd want.&lt;br /&gt;&lt;br /&gt;However, when this is the case and you're using a proxy server this also brings along some issues. When trying to download the updates you can run into the following error:&lt;br /&gt;&lt;blockquote&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;The server name or address could not be resolved&lt;/div&gt;&lt;/blockquote&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Y9qL3xVT9hA/S8wZ7UW7GHI/AAAAAAAAACI/02r_VJ90QZU/s1600/servernameoraddresscouldnotberesolved.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_Y9qL3xVT9hA/S8wZ7UW7GHI/AAAAAAAAACI/02r_VJ90QZU/s320/servernameoraddresscouldnotberesolved.jpg" wt="true" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"&gt;&lt;/div&gt;&lt;br /&gt;It took me a while to figure this one out, but it's quite easily fixed. Open up internet explorer and go to &lt;strong&gt;Internet Options&lt;/strong&gt;. Now, go to &lt;strong&gt;Connections&lt;/strong&gt; and choose &lt;strong&gt;Lan Settings&lt;/strong&gt;. Fill in the same proxy server, so you can resolve internet addresses without issues. Close and re-open the ConfigMgr Admin Console and try to download the updates again. As you can see, the error is gone.&lt;br /&gt;&lt;br /&gt;Hope this helps.&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;&lt;br /&gt;Stefan Hazenbroek&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5978273702195385869-6366371803037162360?l=stefanhazenbroek.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stefanhazenbroek.blogspot.com/feeds/6366371803037162360/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://stefanhazenbroek.blogspot.com/2010/04/configmgr-software-update-point-server.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/6366371803037162360'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/6366371803037162360'/><link rel='alternate' type='text/html' href='http://stefanhazenbroek.blogspot.com/2010/04/configmgr-software-update-point-server.html' title='ConfigMgr: Software Update Point - The server name or address could not be resolved'/><author><name>Stefan Hazenbroek</name><uri>http://www.blogger.com/profile/02126356175626503768</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Y9qL3xVT9hA/S8wZ7UW7GHI/AAAAAAAAACI/02r_VJ90QZU/s72-c/servernameoraddresscouldnotberesolved.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5978273702195385869.post-8322256128728471622</id><published>2010-01-30T10:21:00.000+01:00</published><updated>2010-01-30T10:21:15.487+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ConfigMgr'/><title type='text'>ConfigMgr: The process is not in background processing mode.</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;When trying to provision updates using the ConfigMgr Console of System Center Configuration Manager 2007 (R2 SP2 in my case, but it also applies to earlier versions) you can get the following error in the process screen of the Update List Wizard.&lt;br /&gt;&lt;blockquote&gt;The process is not in background processing mode&lt;/blockquote&gt;&lt;br /&gt;Now what? Background processing mode makes you think it's because of BITS being used. Well, you're right. This is the way you can resolve this issue.&lt;br /&gt;&lt;br /&gt;1. Login to your WSUS Server.&lt;br /&gt;2. Stop the BITS Service (through Services.msc or &lt;strong&gt;net stop bits&lt;/strong&gt; at a commandline)&lt;br /&gt;3. Stop the Automatic Updates Service (through Services.msc or &lt;strong&gt;net stop wuauserv&lt;/strong&gt; at a commandline)&lt;br /&gt;4. Browse to: &lt;strong&gt;Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader&lt;/strong&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;strong&gt;Note: &lt;/strong&gt;If you're using Windows Server 2008 or Server 2008 R2 the Application Data folder is a junction point which has &lt;strong&gt;deny list&lt;/strong&gt; permissions set to &lt;strong&gt;Everyone&lt;/strong&gt;. If you need to be able to browse this folder you need to remove these NTFS permissions.&lt;/blockquote&gt;5. In the &lt;strong&gt;\Downloader&lt;/strong&gt; folder delete the files &lt;strong&gt;qmgr0.dat&lt;/strong&gt; and &lt;strong&gt;qmgr1.dat&lt;/strong&gt;. These files will be recreated once you start the BITS service.&lt;br /&gt;6. In the &lt;strong&gt;C:\Windows\&lt;/strong&gt; directory delete the folder &lt;strong&gt;SoftwareDistribution&lt;/strong&gt; This folder will be recreated once you start the Automatic Updates service.&lt;br /&gt;7. Start the Automatic Updates service using services.msc or by using &lt;strong&gt;net start wuauserv&lt;/strong&gt;&lt;br /&gt;8. Start the BITS service using services.msc or by using &lt;strong&gt;net start bits&lt;/strong&gt;&lt;br /&gt;9. Go into the ConfigMgr Console and go to &lt;strong&gt;Software Updates&lt;/strong&gt; and right click on &lt;strong&gt;Software Repository&lt;/strong&gt;. Choose &lt;strong&gt;Run Synchronisation&lt;/strong&gt;.&lt;br /&gt;&lt;br /&gt;Now you're able to download the updates again. I hope this helps.&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;&lt;br /&gt;Stefan Hazenbroek&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5978273702195385869-8322256128728471622?l=stefanhazenbroek.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stefanhazenbroek.blogspot.com/feeds/8322256128728471622/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://stefanhazenbroek.blogspot.com/2010/01/configmgr-process-is-not-in-background.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/8322256128728471622'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/8322256128728471622'/><link rel='alternate' type='text/html' href='http://stefanhazenbroek.blogspot.com/2010/01/configmgr-process-is-not-in-background.html' title='ConfigMgr: The process is not in background processing mode.'/><author><name>Stefan Hazenbroek</name><uri>http://www.blogger.com/profile/02126356175626503768</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5978273702195385869.post-9188896997252439358</id><published>2010-01-29T16:16:00.002+01:00</published><updated>2010-01-29T16:17:12.821+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Exchange 2010'/><title type='text'>Exchange 2010: Certification achieved!</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;I just recieved the following email from Microsoft Learning:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;Congratulations on earning your Enterprise Messaging Administrator 2010 certification! We hope you enjoy the benefits of your certification and of membership in the Microsoft Certified Professional community.&lt;/blockquote&gt;&lt;br /&gt;Now that's a message you like to hear in the early morning!&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5978273702195385869-9188896997252439358?l=stefanhazenbroek.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stefanhazenbroek.blogspot.com/feeds/9188896997252439358/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://stefanhazenbroek.blogspot.com/2010/01/exchange-2010-certification-achieved.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/9188896997252439358'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/9188896997252439358'/><link rel='alternate' type='text/html' href='http://stefanhazenbroek.blogspot.com/2010/01/exchange-2010-certification-achieved.html' title='Exchange 2010: Certification achieved!'/><author><name>Stefan Hazenbroek</name><uri>http://www.blogger.com/profile/02126356175626503768</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5978273702195385869.post-7399100255942037780</id><published>2010-01-16T23:34:00.002+01:00</published><updated>2010-01-18T22:45:07.705+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ConfigMgr'/><title type='text'>ConfigMgr 2007 R2 SP2: Windows Server 2008 R2, WSUS 3.0 SP2 on Site Server</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;And we have another one!&lt;br /&gt;&lt;br /&gt;In my testlab I have WSUS setup on the same server as the SCCM Site Server. However, when trying to setup the Active SUP I got the following error in the &lt;strong&gt;WSYNCMGR.log&lt;/strong&gt;&lt;br /&gt;&lt;blockquote&gt;SMS WSUS Synchronization failed. Message: WSUS server not configured. Source: CWSyncMgr::DoSync. The operating system reported error 2147500037: Unspecified error&lt;/blockquote&gt;&lt;br /&gt;From this message it looks as if WSUS could not be contacted, but the &lt;strong&gt;WSUSCtrl.log&lt;/strong&gt; states that all connections to the WSUS server are succesful. After searching around it seemed that this issue was due to the fact of WSUS and the SCCM Site Server being on the same machine. The fix is as follows (also check out &lt;a href="http://support.microsoft.com/kb/896861"&gt;http://support.microsoft.com/kb/896861&lt;/a&gt; for more information (choose Method 1)):&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;1) Fire up regedit.&lt;br /&gt;2) Go to &lt;strong&gt;HKLM\System\CurrentControlSet\Control\LSA&lt;/strong&gt;&lt;br /&gt;3) Create a new &lt;strong&gt;DWORD&lt;/strong&gt; value called &lt;strong&gt;DisableLoopbackCheck&lt;/strong&gt;&lt;br /&gt;4) Edit the value and in the &lt;strong&gt;Value Data&lt;/strong&gt; box type &lt;strong&gt;1&lt;/strong&gt;&lt;br /&gt;5) Close regedit&lt;br /&gt;6) In the SCCM Console right-click on &lt;strong&gt;Update Repository&lt;/strong&gt; and check the &lt;strong&gt;WSYNCMgr.log&lt;/strong&gt; for any issues.&lt;/blockquote&gt;&lt;br /&gt;In my case this fixed my issues.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5978273702195385869-7399100255942037780?l=stefanhazenbroek.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stefanhazenbroek.blogspot.com/feeds/7399100255942037780/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://stefanhazenbroek.blogspot.com/2010/01/configmgr-2007-r2-sp2-windows-server.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/7399100255942037780'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/7399100255942037780'/><link rel='alternate' type='text/html' href='http://stefanhazenbroek.blogspot.com/2010/01/configmgr-2007-r2-sp2-windows-server.html' title='ConfigMgr 2007 R2 SP2: Windows Server 2008 R2, WSUS 3.0 SP2 on Site Server'/><author><name>Stefan Hazenbroek</name><uri>http://www.blogger.com/profile/02126356175626503768</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5978273702195385869.post-5938397803527731553</id><published>2010-01-16T22:24:00.001+01:00</published><updated>2010-01-16T22:26:03.147+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ConfigMgr'/><title type='text'>ConfigMgr 2007 R2 SP2: Windows Server 2008 R2 and Management Point</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif;"&gt;&lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;br /&gt;I've been reinstalling my testenvironment to support Windows Server 2008 R2 instead of Windows Server 2008, but while installing SCCM 2007 R2 SP2 I ran into the following problem:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;SMS Site Component Manager failed to install component SMS_MP_CONTROL_MANAGER on server.&lt;br /&gt;&lt;br /&gt;The WebDAV server extension is either not installed or not configured properly.&lt;br /&gt;Solution: Make sure WebDAV is installed and enabled. Make sure there is an authoring rule that allow “All users” read access to “All content”. Make sure the WebDAV settings “Allow anonymous property queries” and “Allow property queries with infinite depth” are set to “true” and “Allow Custom Properties” is set to false.&lt;/blockquote&gt;&lt;br /&gt;Now what? I am 100% sure I have the correct settings in WebDAV (according to the log also) but it doesn't seem to recognize it. After doing some searching on the internet I found the location of the configuration file of Webdav. This file is located in: &lt;strong&gt;C:\Windows\System32\inetsrv\config\schema\WebDAV_schema.xml&lt;/strong&gt;. After opening this file up I noticed that the settings in this file were different from the settings I changed in the IIS Manager.&lt;br /&gt;&lt;br /&gt;The settings were configured as:&lt;br /&gt;&lt;blockquote&gt;&amp;lt;attribute name=”allowAnonymousPropfind” type=”bool” defaultValue=”false” /&amp;gt;&lt;br /&gt;&amp;lt;attribute name=”allowInfinitePropfindDepth” type=”bool” defaultValue=”false” /&amp;gt;&lt;br /&gt;&amp;lt;attribute name=”allowCustomProperties” type=”bool” defaultValue=”true” /&amp;gt;&lt;/blockquote&gt;&lt;br /&gt;However they should be:&lt;br /&gt;&lt;blockquote&gt;&amp;lt;attribute name=”allowAnonymousPropfind” type=”bool” defaultValue=”true” /&amp;gt;&lt;br /&gt;&amp;lt;attribute name=”allowInfinitePropfindDepth” type=”bool” defaultValue=”true” /&amp;gt;&lt;br /&gt;&amp;lt;attribute name=”allowCustomProperties” type=”bool” defaultValue=”false” /&amp;gt;&lt;/blockquote&gt;&lt;br /&gt;After correcting these settings (remember you have to take ownership of the file to be able to change it) and restarting the &lt;strong&gt;World Wide Web Publishing Service&lt;/strong&gt; and the &lt;strong&gt;SMS_SITE_COMPONENT_MANAGER&lt;/strong&gt; the Management Point gets installed correctly. You can check if the installation is succesful in the logfile &lt;strong&gt;MPSetup.log&lt;/strong&gt; in your SCCM\Logs directory. If succesful the log looks like this:&lt;br /&gt;&lt;blockquote&gt;&amp;lt;01-16-2010 22:08:36&amp;gt;         ======== Completed Installation of Pre Reqs for Role SMSMP ========&lt;br /&gt;&amp;lt;01-16-2010 22:08:36&amp;gt; Installing the SMSMP&lt;br /&gt;&amp;lt;01-16-2010 22:08:36&amp;gt; Passed OS version check.&lt;br /&gt;&amp;lt;01-16-2010 22:08:36&amp;gt; IIS Service is installed.&lt;br /&gt;&amp;lt;01-16-2010 22:08:36&amp;gt; checking WebDAV configuraitons&lt;br /&gt;&amp;lt;01-16-2010 22:08:37&amp;gt;  WebDAV is configured&lt;br /&gt;&amp;lt;01-16-2010 22:08:37&amp;gt; No versions of SMSMP are installed.  Installing new SMSMP.&lt;br /&gt;&amp;lt;01-16-2010 22:08:37&amp;gt; Enabling MSI logging.  mp.msi will log to C:\Program Files (x86)\Microsoft Configuration Manager\logs\mpMSI.log&lt;br /&gt;&amp;lt;01-16-2010 22:08:37&amp;gt; Installing C:\Program Files (x86)\Microsoft Configuration Manager\bin\i386\mp.msi CCMINSTALLDIR="C:\Program Files (x86)\SMS_CCM" CCMSERVERDATAROOT="C:\Program Files (x86)\Microsoft Configuration Manager" USESMSPORTS=TRUE SMSPORTS=80 USESMSSSLPORTS=TRUE SMSSSLPORTS=443 USESMSSSL=TRUE SMSSSLSTATE=0 CCMENABLELOGGING=TRUE CCMLOGLEVEL=1 CCMLOGMAXSIZE=1000000 CCMLOGMAXHISTORY=1&lt;br /&gt;&amp;lt;01-16-2010 22:08:57&amp;gt; mp.msi exited with return code: 0&lt;br /&gt;&amp;lt;01-16-2010 22:08:57&amp;gt; Verifying CCM_CLIENT virtual directory.&lt;br /&gt;&amp;lt;01-16-2010 22:08:57&amp;gt; Website path is IIS://LocalHost/W3SVC/1.&lt;br /&gt;&amp;lt;01-16-2010 22:08:57&amp;gt; Connecting to IIS.&lt;br /&gt;&amp;lt;01-16-2010 22:08:57&amp;gt; CCM_CLIENT is currently C:\Program Files (x86)\Microsoft Configuration Manager\Client.&lt;br /&gt;&amp;lt;01-16-2010 22:08:57&amp;gt; Installation was successful.&lt;/blockquote&gt;&lt;br /&gt;One last thing. When creating a backup of the WebDav_schema.xml, do not create the backup in the same directory as the original file. All .xml files put in this directory will be read by IIS so your settings will not seem changed afterwards.&lt;br /&gt;&lt;br /&gt;Good luck, I hope this helps.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5978273702195385869-5938397803527731553?l=stefanhazenbroek.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stefanhazenbroek.blogspot.com/feeds/5938397803527731553/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://stefanhazenbroek.blogspot.com/2010/01/configmgr-2007-sp2-windows-server-2008.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/5938397803527731553'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/5938397803527731553'/><link rel='alternate' type='text/html' href='http://stefanhazenbroek.blogspot.com/2010/01/configmgr-2007-sp2-windows-server-2008.html' title='ConfigMgr 2007 R2 SP2: Windows Server 2008 R2 and Management Point'/><author><name>Stefan Hazenbroek</name><uri>http://www.blogger.com/profile/02126356175626503768</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5978273702195385869.post-57756317069092662</id><published>2010-01-12T20:07:00.000+01:00</published><updated>2010-01-12T20:07:04.104+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Active Directory'/><title type='text'>AD Certificate Services: How To Install on Windows Server 2008 R2 Core</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Windows Server 2008 R2 Core offers the possibility of installing a Certificate Authority. However, not much documentation is available on how to configure the role using the commandline.&lt;br /&gt;&lt;br /&gt;In this blogpost I will explain how you can install the role and use it to issue certificates to your servers and clients.&lt;br /&gt;&lt;br /&gt;Log in to the server (Windows Server 2008 R2 Server Core server) that you're going to install the Certification Authority on. You need Domain Admin or equivalent permissions on a single forest, single domain infrastructure or Enterprise Admins on a multi-domain infrastructure to be able to install AD Certificate Services correctly. The following command has to be issued on the commandline:&lt;br /&gt;&lt;blockquote&gt;Dism /online /enable-feature /featurename:CertificateServices&lt;br /&gt;&lt;/blockquote&gt;Don't forget, the DISM command is Case-Sensitive, so you should keep the Capitcal C and S in mind.&lt;br /&gt;&lt;br /&gt;Instead, if you have powershell installed on your Windows Server 2008 R2 Core machine you can also use the following commands to install the role:&lt;br /&gt;First, fire up powershell by typing &lt;strong&gt;powershell&lt;/strong&gt; in the cmd screen. When Powershell is fired up type:&lt;br /&gt;&lt;blockquote&gt;Import-Module ServerManager&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;At the top of the screen you'll see the module being imported, when it's complete you have the possibility to use the CMDLets &lt;strong&gt;Add-WindowsFeature&lt;/strong&gt;,&lt;strong&gt;Get-WindowsFeature&lt;/strong&gt; and &lt;strong&gt;Remove-WindowsFeature&lt;/strong&gt;. Install AD Certificate Services using the following command:&lt;br /&gt;&lt;blockquote&gt;Add-WindowsFeature ADCS-Cert-Authority&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Restart the server when the installation is completed to be sure that all needed information is correctly populated and login to the server again.&lt;br /&gt;&lt;br /&gt;Now, the nice folks over at the PKI blog published a nice article on how to use a VBScript to install a Certificate Authority. Check out:&lt;br /&gt;&lt;blockquote&gt;http://blogs.technet.com/pki/archive/2009/09/18/automated-ca-installs-using-vb-script-on-windows-server-2008-and-2008r2.aspx&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Download the script from above link and place it somewhere you are able to access it from the machine the CA is running on. Browse to the directory you placed the script in and execute the following command to install an Enterprise Root Certification Authority:&lt;br /&gt;&lt;blockquote&gt;Cscript setupca.vbs /ie /sn &lt;strong&gt;NameOfYourCA&lt;/strong&gt; /sk 4096 /sp "RSA#Microsoft Software Key Storage Provider" /sa SHA256&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;When you've issued above script and it completed succesfully (it'll take about a minute or so) you will be able to start your CA. Go to the Windows 7 workstation with RSAT installed and open up Computer Management. Browse to the machine your CA is running on and fire up the service &lt;strong&gt;Active Directory Certificate Services&lt;/strong&gt;. When running this from the commandline you issue the name &lt;strong&gt;CertSvc&lt;/strong&gt;.&lt;br /&gt;&lt;br /&gt;On the RSAT machine, open up the Certification Authority shortcut in the Administrative Tools folder. When you open this shortcut you'll receive the following error:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Y9qL3xVT9hA/S0zHHiREcQI/AAAAAAAAABw/eHc3Ku0RkOk/s1600-h/ca1.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" ps="true" src="http://1.bp.blogspot.com/_Y9qL3xVT9hA/S0zHHiREcQI/AAAAAAAAABw/eHc3Ku0RkOk/s320/ca1.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;This is no problem. Click on &lt;strong&gt;OK&lt;/strong&gt; and when in the MMC right click &lt;strong&gt;Certification Authority (Local)&lt;/strong&gt;. In the submenu you choose &lt;strong&gt;Retarget Certification Authority&lt;/strong&gt;. Choose &lt;strong&gt;Another Computer&lt;/strong&gt; in the wizard and fill in the hostname of the machine that is running your CA. From now on you can manage your Certification Authority from your machine with RSAT installed.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5978273702195385869-57756317069092662?l=stefanhazenbroek.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stefanhazenbroek.blogspot.com/feeds/57756317069092662/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://stefanhazenbroek.blogspot.com/2010/01/ad-certificate-services-how-to-install.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/57756317069092662'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/57756317069092662'/><link rel='alternate' type='text/html' href='http://stefanhazenbroek.blogspot.com/2010/01/ad-certificate-services-how-to-install.html' title='AD Certificate Services: How To Install on Windows Server 2008 R2 Core'/><author><name>Stefan Hazenbroek</name><uri>http://www.blogger.com/profile/02126356175626503768</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Y9qL3xVT9hA/S0zHHiREcQI/AAAAAAAAABw/eHc3Ku0RkOk/s72-c/ca1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5978273702195385869.post-4337760022130706145</id><published>2009-11-22T09:19:00.000+01:00</published><updated>2009-11-22T09:19:35.765+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Active Directory'/><title type='text'>Active Directory: Corrupt Certificate Templates</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;I was&amp;nbsp;trying to get my Windows Mobile 6.5 to work with Exchange 2010, but when I tried to request a certificate to my CA i got the following error:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;&lt;blockquote&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Eventid: 53, CertificationAuthority&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Message: Active Directory Certificate Services denied request 17 because The requested certificate template is not supported by this CA. 0x80094800 (-2146875392). The request was for CN="". Additional information: Denied by Policy Module 0x80094800, The request was for a certificate template that is not supported by the Active Directory Certificate Services policy: User.&lt;/span&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Now what? For some reason it thinks my User certificate does not exist or something? It seemed the User Certificate Template on my CA was corrupt for some reason. This is how I fixed it.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;em&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;&lt;blockquote&gt;&lt;em&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;Note: I assume you backup your CA before changing settings, because of this I'll not mention it in the Howto.&lt;/span&gt;&lt;/em&gt;&lt;/blockquote&gt;&lt;/span&gt;&lt;/em&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;1. Stop the Certificate Services Service.&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;&lt;blockquote&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;net stop CertSvc&lt;/span&gt;&lt;/blockquote&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;2. Log in to ADSI Edit and open the Configuration naming context. Then go to CN=Services,CN=Public Key Services,CN=Certificate Templates. If all is correct there should be quite a few items listed there. Empty out the CN=Certificate Templates container. This is most easily done by deleting CN=Certificate Templates and recreating it with the same name.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;3. Start the Certificate Services Service.&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;&lt;blockquote&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;net start CertSvc&lt;/span&gt;&lt;/blockquote&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;4. Open the Certification Authority Snap-In and go to Certificate Templates. You should see all templates listed with an X in front of it.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;If this is the case, right-click on Certificate Templates and choose &lt;strong&gt;Manage&lt;/strong&gt;. Windows should give a popup with a message like: "New certificate templates are found, would you like to install them?". Agree with the message and see the magic work. After&amp;nbsp;a few moments (depending on the size of your AD) you'll be able to issue certificates again.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5978273702195385869-4337760022130706145?l=stefanhazenbroek.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stefanhazenbroek.blogspot.com/feeds/4337760022130706145/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://stefanhazenbroek.blogspot.com/2009/11/active-directory-corrupt-certificate.html#comment-form' title='2 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/4337760022130706145'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/4337760022130706145'/><link rel='alternate' type='text/html' href='http://stefanhazenbroek.blogspot.com/2009/11/active-directory-corrupt-certificate.html' title='Active Directory: Corrupt Certificate Templates'/><author><name>Stefan Hazenbroek</name><uri>http://www.blogger.com/profile/02126356175626503768</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5978273702195385869.post-1939850901090777266</id><published>2009-10-16T09:37:00.000+02:00</published><updated>2009-10-16T09:37:14.573+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Exchange 2010'/><title type='text'>Exchange 2010 Certified!</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;I just recieved the following email from MS Learning:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;Congratulations on earning your Microsoft Exchange Server 2010, Configuration certification! We hope you enjoy the benefits of your certification and of membership in the Microsoft Certified Professional community.&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5978273702195385869-1939850901090777266?l=stefanhazenbroek.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stefanhazenbroek.blogspot.com/feeds/1939850901090777266/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://stefanhazenbroek.blogspot.com/2009/10/exchange-2010-certified.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/1939850901090777266'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/1939850901090777266'/><link rel='alternate' type='text/html' href='http://stefanhazenbroek.blogspot.com/2009/10/exchange-2010-certified.html' title='Exchange 2010 Certified!'/><author><name>Stefan Hazenbroek</name><uri>http://www.blogger.com/profile/02126356175626503768</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5978273702195385869.post-2933461342422819223</id><published>2009-10-10T14:39:00.001+02:00</published><updated>2009-10-10T14:40:16.300+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Active Directory'/><title type='text'>Active Directory: AD Recycle Bin GUI</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Earlier on I blogged about the AD Recycle Bin. In this blog we checked out how the AD Recycle Bin is activated and how it's used through Powershell or LDP.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;The fellows at Overall Solutions Inc. made a very nice GUI. In this GUI it's possible to see which items are deleted and also recover the deleted items.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;The download can be found &lt;a href="http://www.overall.ca/index.php?option=com_content&amp;amp;view=article&amp;amp;id=40:adrecyclebin&amp;amp;catid=15:adrecyclebinexe&amp;amp;Itemid=64"&gt;http://www.overall.ca/index.php?option=com_content&amp;amp;view=article&amp;amp;id=40:adrecyclebin&amp;amp;catid=15:adrecyclebinexe&amp;amp;Itemid=64&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana; font-size: x-small;"&gt;The GUI is built like this:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_Y9qL3xVT9hA/StB_ReIYzMI/AAAAAAAAABI/W05bjeGiFQs/s1600-h/AD+Recycle+Bin+2.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img $r="true" border="0" src="http://4.bp.blogspot.com/_Y9qL3xVT9hA/StB_ReIYzMI/AAAAAAAAABI/W05bjeGiFQs/s320/AD+Recycle+Bin+2.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5978273702195385869-2933461342422819223?l=stefanhazenbroek.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stefanhazenbroek.blogspot.com/feeds/2933461342422819223/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://stefanhazenbroek.blogspot.com/2009/10/active-directory-ad-recycle-bin-gui.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/2933461342422819223'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/2933461342422819223'/><link rel='alternate' type='text/html' href='http://stefanhazenbroek.blogspot.com/2009/10/active-directory-ad-recycle-bin-gui.html' title='Active Directory: AD Recycle Bin GUI'/><author><name>Stefan Hazenbroek</name><uri>http://www.blogger.com/profile/02126356175626503768</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Y9qL3xVT9hA/StB_ReIYzMI/AAAAAAAAABI/W05bjeGiFQs/s72-c/AD+Recycle+Bin+2.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5978273702195385869.post-1290282620859314056</id><published>2009-10-09T16:35:00.001+02:00</published><updated>2009-10-09T16:36:25.884+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Exchange 2010'/><title type='text'>Exchange 2010 RTM!</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Yesterday at TechNet Live they already had some interesting information. At the end of the day when asked the question: "When will Exchange 2010 be RTM" the only answer we got was: "Check out the Exchange Team blog tomorrow". And what have we got? Finally! Exchange 2010 got RTM'd!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;For the full announcement see: &lt;/span&gt;&lt;a href="http://msexchangeteam.com/archive/2009/10/08/452775.aspx"&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;http://msexchangeteam.com/archive/2009/10/08/452775.aspx&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;In my opinion some very good news to get on Friday!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Regards,&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Stefan Hazenbroek&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5978273702195385869-1290282620859314056?l=stefanhazenbroek.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stefanhazenbroek.blogspot.com/feeds/1290282620859314056/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://stefanhazenbroek.blogspot.com/2009/10/exchange-2010-rtm.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/1290282620859314056'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/1290282620859314056'/><link rel='alternate' type='text/html' href='http://stefanhazenbroek.blogspot.com/2009/10/exchange-2010-rtm.html' title='Exchange 2010 RTM!'/><author><name>Stefan Hazenbroek</name><uri>http://www.blogger.com/profile/02126356175626503768</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5978273702195385869.post-8573725681846104968</id><published>2009-10-05T10:41:00.002+02:00</published><updated>2009-10-05T10:48:27.706+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Active Directory'/><title type='text'>Active Directory: FSMO Roles in Windows Server 2008 R2</title><content type='html'>&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;I've been getting alot of questions and debate about FSMO roles in an Active Directory domain environment. Where should you place what role? What does a specific role do? Should I seize it if it's not available?&lt;br /&gt;&lt;br /&gt;I'll start by summing up the available roles and their task. The function of each role is defined for Windows Server 2008 R2.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Schema Master&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;There can only be one Schema Master defined per forest. The Schema Master contains the only writable copy of the schema and additions to it can only be done by a member of the Schema Admins and the Enterprise Admins security group. &lt;br /&gt;&lt;br /&gt;When this role is unavailable additions or changes to the schema&amp;nbsp; cannot be made.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Domain Naming Master&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;The Domain Naming Master is responsible for the addition or removal of domains in the forest. The Domain Naming Master is a forest-wide role, which means only one can be defined per forest.&lt;br /&gt;&lt;br /&gt;When this role is unavailable no domains can be added, removed or renamed.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Infrastructure Master&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;The Infrastructure Master is a domain-wide role, which means it is defined per domain. Logically, if you have 3 domains within your forest, you have 3 domain controllers that contain the Infrastructure Master role. The Infrastructure Master is responsible for updating links to objects in the domain to objects in other domains. There can only be one defined per domain.&lt;br /&gt;&lt;br /&gt;When the infrastructure master is unavailable changes in objects do not get replicated. However, when all domain controllers are also a Global Catalog, the Infrastructure Master does not have a function.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;RID Master&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;The RID (or Relative-ID) Master is responsible for RID-requests from all domain controllers within that domain. When the RID pool of a domain controller depletes, it requests a new pool from the RID Master. The RID Master can only be defined once per domain.&lt;br /&gt;&lt;br /&gt;When the RID Master is unavailable and a domain controller runs out of available RID's no new objects (as users, groups, computers and such) cannot be created.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;PDC Emulator&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;The PDC (or Primary Domain Controller) Emulator role is used to act as PDC when Windows NT BDC's are used. The PDC Emulator also acts as Master Browser for the domain and handles password updates for the domain. The PDC Emulator can only be defined once per domain.&lt;br /&gt;&lt;br /&gt;When the PDC Emulator is unavailable password-changes get updated with the regular replication traffic instead of right away through the PDC emulator. Also, the time (net time) will not get synced during this time, which can be an issue in a domain environment.&lt;br /&gt;&lt;br /&gt;Now, what if a domain controller is unavailable for a while and you need to seize the role? In a pre-windows 2008 R2 environment, thus: in an environment without the use of AD Powershell this can be quite the hassle. When you need to move the Schema Master you first have to load the dll for the mmc, after which you can move it. It just costs needless time.&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;blockquote&gt;Move-ADDirectoryServerOperationMasterRole -Identity ADDirectoryServer -OperationMasterRole ADOperationMasterRole []&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;For example, when you want to move the Infrastructure Master to domain controller "DC001" you'll use:&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;blockquote&gt;Move-ADDirectoryServerOperationMasterRole -Identity DC001 -OperationMasterRole InfrastructureMaster &lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Now, if the server that contains the role is unavailable you can ofcourse Seize it. This can also be done in Powershell, by adding the -Force parameter to the CMDLet. In case of seizing the Infrastructure Master to domain controller DC001 you'll use:&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;blockquote&gt;Move-ADDirectoryServerOperationMasterRole -Identity DC001 -OperationMasterRole InfrastructureMaster &lt;strong&gt;-Force&lt;/strong&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Finally, one shell to manage your complete AD in!&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;&lt;br /&gt;Stefan Hazenbroek&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5978273702195385869-8573725681846104968?l=stefanhazenbroek.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stefanhazenbroek.blogspot.com/feeds/8573725681846104968/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://stefanhazenbroek.blogspot.com/2009/10/active-directory-fsmo-roles-in-windows.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/8573725681846104968'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/8573725681846104968'/><link rel='alternate' type='text/html' href='http://stefanhazenbroek.blogspot.com/2009/10/active-directory-fsmo-roles-in-windows.html' title='Active Directory: FSMO Roles in Windows Server 2008 R2'/><author><name>Stefan Hazenbroek</name><uri>http://www.blogger.com/profile/02126356175626503768</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5978273702195385869.post-7591072269489295981</id><published>2009-09-07T17:10:00.002+02:00</published><updated>2009-09-08T08:42:42.152+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ConfigMgr'/><title type='text'>ConfigMgr: SMS Site Component Manager failed to reinstall this component on this site system.</title><content type='html'>&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;Within a ConfigMgr environment it's possible you run into the following error when running &lt;b&gt;SMS_SITE_SQL_BACKUP&lt;/b&gt; and the SQL Server runs on a remote system.&lt;/span&gt;&lt;/div&gt;&lt;blockquote style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;SMS Site Component Manager failed to reinstall this component on this site system.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;Solution: Review the previous status messages to determine the exact reason for the failure. SMS Site Component Manager will automatically retry the reinstallation in 60 minutes. To force SMS Site Component Manager to immediately retry the reinstallation, stop and restart SMS Site Component Manager using the SMS Service Manager.&lt;/span&gt;&lt;/blockquote&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;I noticed this error at home (yes, I'm running ConfigMgr 2007 SP1 + R2 at home, call me crazy ;-)) and started looking around if there's a solution available. After finding no KB-article or anything about it I started searching on. The reason for this error seems to be that the SQL Server cannot bootstrap the executable to install the service on the SQL Server. &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;Luckily, the fix is quite easy. Go to the ConfigMgr installation directory, in my case&lt;/span&gt;&lt;/div&gt;&lt;blockquote style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;C:\Program Files (x86)\Microsoft Configuration Manager\&lt;/span&gt;&lt;/blockquote&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;and open the file install.MAP with notepad. In this file you'll search for the following lines:&lt;/span&gt;&lt;/div&gt;&lt;blockquote style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;BEGIN_COMPONENT_FILELIST&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&amp;lt;SMS_SITE_SQL_BACKUP&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&amp;lt;1193&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;BEGIN_DIRECTORY&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&amp;lt;bin\i386&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&amp;lt;9&amp;gt;&amp;lt;X86&amp;gt;&amp;lt;&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;FILE &amp;lt;smssqlbkup.exe&amp;gt;&amp;lt;1&amp;gt;&amp;lt;766496&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;END_DIRECTORY&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;BEGIN_DIRECTORY&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&amp;lt;bin\x64&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&amp;lt;17\&amp;gt;&amp;lt;AMD64&amp;gt;&amp;lt;&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;FILE &amp;lt;smssqlbkup.exe&amp;gt;&amp;lt;1&amp;gt;&amp;lt;1547296&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;END_DIRECTORY&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;UNIT &amp;lt;SMS&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;END_COMPONENT_FILELIST&lt;/span&gt;&lt;/blockquote&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;Change these lines to the following&lt;/span&gt;&lt;/div&gt;&lt;blockquote style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;BEGIN_COMPONENT_FILELIST&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&amp;lt;SMS_SITE_SQL_BACKUP&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&amp;lt;1193&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;BEGIN_DIRECTORY&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&amp;lt;bin\i386&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&amp;lt;9&amp;gt;&amp;lt;X86&amp;gt;&amp;lt;&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;FILE &amp;lt;smssqlbkup.exe&amp;gt;&amp;lt;1&amp;gt;&amp;lt;766496&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;b&gt;FILE &amp;lt;srvboot.exe&amp;gt;&amp;lt;0&amp;gt;&amp;lt;219904&amp;gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;END_DIRECTORY&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;BEGIN_DIRECTORY&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&amp;lt;bin\x64&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&amp;lt;17&amp;gt;&amp;lt;AMD64&amp;gt;&amp;lt;&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;FILE &amp;lt;smssqlbkup.exe&amp;gt;&amp;lt;1&amp;gt;&amp;lt;1547296&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;END_DIRECTORY&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;UNIT &amp;lt;SMS&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;END_COMPONENT_FILELIST&lt;/span&gt;&lt;/blockquote&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;Afterwards restart the &lt;b&gt;SMS_SITE_COMPONENT_MANAGER&lt;/b&gt; at the site server and after a minute or so reopen the Components log. After changing the install.MAP and restarting the SMS_SITE_COMPONENT_MANAGER I got the following happy message:&lt;/span&gt;&lt;/div&gt;&lt;blockquote style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;SMS Site Component Manager successfully reinstalled this component on this site system.&lt;/span&gt;&lt;/blockquote&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: x-small;"&gt;I hope this helps resolve some issues.&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5978273702195385869-7591072269489295981?l=stefanhazenbroek.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stefanhazenbroek.blogspot.com/feeds/7591072269489295981/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://stefanhazenbroek.blogspot.com/2009/09/configmgr-sms-site-component-manager_07.html#comment-form' title='1 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/7591072269489295981'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/7591072269489295981'/><link rel='alternate' type='text/html' href='http://stefanhazenbroek.blogspot.com/2009/09/configmgr-sms-site-component-manager_07.html' title='ConfigMgr: SMS Site Component Manager failed to reinstall this component on this site system.'/><author><name>Stefan Hazenbroek</name><uri>http://www.blogger.com/profile/02126356175626503768</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5978273702195385869.post-8433876243781470867</id><published>2009-09-06T11:06:00.007+02:00</published><updated>2009-09-08T09:24:14.684+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Active Directory'/><title type='text'>Active Directory: Configure AD Recycle Bin</title><content type='html'>&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;Every Active Directory manager deals with it eventually, a user, a group of users or even an OU gets deleted by accident. Retrieving the objects using an authorative restore isn't the nicest job to do, because a lot of fields are stripped out when the account is deleted.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;Windows Server 2008 R2 has a solution for this, namely the Active Directory Recycle Bin. In this blogpost I will explain how you setup the AD Recycle bin and how you can retrieve items afterwards. One drawback though: There is no nice interface available from Microsoft yet.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;First off, it's necessary that the Forest Functional Level is at the level of Windows Server 2008 R2. This can be done using Active Directory Domains and Trusts, but can easily be done using Powershell.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;&lt;b&gt;Through Active Directory Domains and Trusts:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Y9qL3xVT9hA/SqNq2rnOQdI/AAAAAAAAAAQ/mz0bMqw6fm4/s1600-h/Raise+FFL.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;&lt;img border="0" lk="true" src="http://2.bp.blogspot.com/_Y9qL3xVT9hA/SqNq2rnOQdI/AAAAAAAAAAQ/mz0bMqw6fm4/s320/Raise+FFL.jpg" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;Through Powershell:&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;Set-ADForestMode -Identity domain.test -ForestMode Windows2008R2Forest&lt;/span&gt;&lt;/blockquote&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;Now that the Forest is at the right level we'll start by configuring the AD Recycle Bin. First off we load the optional module in Powershell by using the following command.&lt;/span&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;Enable-ADOptionalFeature –Identity ‘CN=Recycle Bin Feature,CN=Optional Features,CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration, DC=domain,DC=test’ –Scope ForestOrConfigurationSet –Target ‘domain.test’&lt;/span&gt;&lt;/blockquote&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;When this is done we need to make the forest aware the optional feature is installed. This can be done using LDP. Fire up LDP using Run and type: &lt;b&gt;ldp.exe&lt;/b&gt;. Open LDP and connect to the domain controller that hosts the root domain (so the firest domain). This can be done by clicking &lt;b&gt;Connection&lt;/b&gt; then choosing &lt;b&gt;Connect&lt;/b&gt; and typing in the hostname of the DC you want to connect to, after which you choose &lt;b&gt;Bind&lt;/b&gt;. In the menu bar open the menu &lt;b&gt;View&lt;/b&gt; and choose &lt;b&gt;Tree&lt;/b&gt;. In the popupbox choose Configuration BaseDN&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_Y9qL3xVT9hA/SqNu7YKBeII/AAAAAAAAAAg/E_UVYP2ZsA4/s1600-h/LDP+BaseDN.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;&lt;img border="0" lk="true" src="http://4.bp.blogspot.com/_Y9qL3xVT9hA/SqNu7YKBeII/AAAAAAAAAAg/E_UVYP2ZsA4/s320/LDP+BaseDN.jpg" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;Navigate to the CN=Partitions container, rightclick this and choose Modify&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Y9qL3xVT9hA/SqNvsBQrmBI/AAAAAAAAAAo/b_iUzUVGnb8/s1600-h/partitions+CN.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;&lt;img border="0" lk="true" src="http://1.bp.blogspot.com/_Y9qL3xVT9hA/SqNvsBQrmBI/AAAAAAAAAAo/b_iUzUVGnb8/s320/partitions+CN.jpg" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;Make sure the field &lt;b&gt;DN&lt;/b&gt; is empty and fill in the following in the other two fields:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;Edit Entry Attribute&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;enableOptionalFeature&lt;/span&gt;&lt;/blockquote&gt;&lt;b&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;Values&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;CN=Partitions,CN=Configuration,DC=domain,DC=test:766ddcd8-acd0-445e-f3b9-a7f9b6744f2a&lt;/span&gt;&lt;/blockquote&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;In the field &lt;b&gt;Operation&lt;/b&gt; choose &lt;b&gt;Add&lt;/b&gt; and click &lt;b&gt;Enter&lt;/b&gt;. The extension will now appear in the field &lt;b&gt;Entry List&lt;/b&gt;. At the bottom of the popup box choose &lt;b&gt;Run&lt;/b&gt; and then choose &lt;b&gt;Close&lt;/b&gt;. When you doubleclick on &lt;b&gt;CN=Partitions&lt;/b&gt; at the left side the following appears in the details field at the right side.&lt;/span&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;msDS-Behavior-Version: 4 = ( WIN2008R2 ); &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;msDS-EnabledFeature: CN=Recycle Bin Feature,CN=Optional Features,CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration,DC=domain,DC=test; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;name: Partitions; &lt;/span&gt;&lt;/blockquote&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;If this is the case the Recycle Bin is installed correctly and we can start using it.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;b&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;ATTENTION! From this moment on the Recycle Bin feature is activated. Any user deleted before this action cannot be retrieved using the AD Recycle Bin.&lt;/span&gt;&lt;/b&gt;&lt;/blockquote&gt;&lt;b&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;Through LDP:&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;Open up LDP again and connect and bind to the DC hosting the root domain. Click &lt;b&gt;Options&lt;/b&gt; and choose &lt;b&gt;Controls&lt;/b&gt; in the menubar.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Y9qL3xVT9hA/SqNy3lbz98I/AAAAAAAAAAw/dKXhMD1I0FU/s1600-h/LDP+Returndeleted.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;&lt;img border="0" lk="true" src="http://3.bp.blogspot.com/_Y9qL3xVT9hA/SqNy3lbz98I/AAAAAAAAAAw/dKXhMD1I0FU/s320/LDP+Returndeleted.jpg" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;When this is loaded up in choose &lt;b&gt;View&lt;/b&gt; and &lt;b&gt;Tree&lt;/b&gt; and choose the BaseDN of the Forest, in my case &lt;b&gt;DC=domain,DC=test&lt;/b&gt;. When you look at the left side, you'll see the CN &lt;b&gt;CN=Deleted Objects,DC=domain,DC=test&lt;/b&gt;. When you doubleclick this a list with all deleted users opens up at the left side. When you find the user you are looking for rightclick the user and choose &lt;b&gt;Modify&lt;/b&gt;. Make sure the popupscreen looks like the following screen:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Y9qL3xVT9hA/SqN08ixSA9I/AAAAAAAAAA4/a5HjAjrzWGg/s1600-h/LDP+Returndeleted+2.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;&lt;img border="0" lk="true" src="http://2.bp.blogspot.com/_Y9qL3xVT9hA/SqN08ixSA9I/AAAAAAAAAA4/a5HjAjrzWGg/s320/LDP+Returndeleted+2.jpg" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;Afterwards choose &lt;b&gt;Run&lt;/b&gt; and the object will be retrieved from the Recycle Bin, after which you can see this in Active Directory Users and Computers again.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;Through Powershell:&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;I know what you're thinking. We have an awesome tool called Powershell, why won't we use that? Well, that's what we're going to look at now. Because we enabled the optional feature using &lt;b&gt;Enable-ADOptionalFeature&lt;/b&gt; we have access to  the &lt;b&gt;Restore-ADObject&lt;/b&gt; CMDLet. What if, you know the username of the user you want to recover. You can see this by running the following CMDLet:&lt;/span&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;Get-ADObject -Filter {sAMAccountname -eq "test"} -IncludeDeletedObjects&lt;/span&gt;&lt;/blockquote&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;When this is executed the output will be as following:&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Y9qL3xVT9hA/SqN6Fy3KunI/AAAAAAAAABA/XUIFkrruRJI/s1600-h/Restore+AD+Recycle+Bin+Object+1.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;&lt;img border="0" lk="true" src="http://3.bp.blogspot.com/_Y9qL3xVT9hA/SqN6Fy3KunI/AAAAAAAAABA/XUIFkrruRJI/s320/Restore+AD+Recycle+Bin+Object+1.jpg" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;If this is the account you want to recover run the following CMDLet:&lt;/span&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;Get-ADObject -Filter {sAMAccountname -eq "test"} -IncludeDeletedObjects | Restore-ADObject&lt;/span&gt;&lt;/blockquote&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;That's it, the filter can be adapted to about anything you're comfortable with using Powershell. In a later blog post I'll post more information about retrieving objects or OU's.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;For more information about retrieving objects from the Recycle Bin please look at the following link:&lt;/span&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: x-small;"&gt;&lt;a href="http://technet.microsoft.com/en-us/library/dd379509%28WS.10%29.aspx"&gt;http://technet.microsoft.com/en-us/library/dd379509(WS.10).aspx&lt;/a&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5978273702195385869-8433876243781470867?l=stefanhazenbroek.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://stefanhazenbroek.blogspot.com/feeds/8433876243781470867/comments/default' title='Reacties plaatsen'/><link rel='replies' type='text/html' href='http://stefanhazenbroek.blogspot.com/2009/09/ad-recycle-bin.html#comment-form' title='0 reacties'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/8433876243781470867'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5978273702195385869/posts/default/8433876243781470867'/><link rel='alternate' type='text/html' href='http://stefanhazenbroek.blogspot.com/2009/09/ad-recycle-bin.html' title='Active Directory: Configure AD Recycle Bin'/><author><name>Stefan Hazenbroek</name><uri>http://www.blogger.com/profile/02126356175626503768</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Y9qL3xVT9hA/SqNq2rnOQdI/AAAAAAAAAAQ/mz0bMqw6fm4/s72-c/Raise+FFL.jpg' height='72' width='72'/><thr:total>0</thr:total></entry></feed>
