SS Technology Forum

SS Technology Forum

Computer Migration - Things to Consider

Here are a few points which you can consider while doing computer migration. These points are applicable to all migrations irrespective of the migration tool (ADMT, NetIQ, Quest etc)

Active Directory User Migration

Here is a graphical representation of the high level steps involved in an Active Directory migration using ADMT

User Migration and Merging Using Quest Migration Manager

Pre-creating user account in the target domain is a common scenario these days due to single-sign-on solution, HR management procedure etc

Microsoft Right Management Service (RMS)

Rights Management Service (RMS) is an add-on to many RMS aware applications. In this article my main focus is to explain how we can utilize RMS technology with Exchange 2003 and how we can take advantage of RMS technology to increase the email security

Microsoft ISA Server

I am sure we have all either encountered or heard of this "problem" one time or another if the ISA Server is part of the Active Directory Domain. Is it a problem?

Monday, April 23, 2012

Active Directory: Active Directory Upgrade – French Version

Yagmoth555, has translated my “Active Directory Upgrade – High Level Steps” Microsoft WiKi article into French. Thanks Philippe. Now you can read this article in different languages !!!

AD_Upgrade_WiKi

English Version - Active Directory: Active Directory Upgrade - High Level Steps

French Version - Mise a jour d'Active Directory - Étapes sommaire (fr-FR)

Italian Version - Panoramica di alto livello per l'upgrade di Active Directory (it-IT)

Wednesday, March 28, 2012

Active Directory: Active Directory Upgrade – Italian Version

Fabrizio Volpe, a fellow MVP,  has translated my “Active Directory Upgrade – High Level Steps” Microsoft WiKi article into Italian.  Thanks Fabrizo.   Now you can read this  article in both languages Smile

English Version - Active Directory: Active Directory Upgrade - High Level Steps

Italian Version - Panoramica di alto livello per l'upgrade di Active Directory (it-IT)

Wednesday, March 14, 2012

Active Directory Mixed Mode and Built-in Groups

Issue

If you are running your Active Directory in Mixed mode and FSMO roles are on the Windows 2000 or Windows 2003 DC, you won’t be able to see the following built-in groups:

  • Event Log Readers
  • Cryptographic Operators
  • IIS_IUSERS
  • Certificate Service DCOM Access

 

image

Some of these groups have introduced with Windows 2008 and some these groups have changed name.  For example, Certificate Service DCOM Access serves the same purpose as CERTSVC_DCOM_ACCESS in Windows 2003.

However, if you are running Active Directory in Windows 2000/2003 and Windows 2008 mixed mode and your PDC Emulator FSMO roles is not on the Windows 2008 DC, you won’t be able to see these groups.  You need to transfer the PDC Emulator FSMO role to windows 2008/Windows 2008 R2 DC (or newest OS) to resolve this issue.

 

image

Thursday, March 8, 2012

ADMT – “ ERR3:7194 Could not open input file C:\Program Files\OnePointDomainAgent ” Issue

Issue

Active Directory Migration Tool (ADMT) Security Translation Process failed with the following error message in the ADMT log file:

ERR3:7194 Could not open input file C:\Program Files\OnePointDomainAgent\AccountsXXXXX.txt

Cause

This is most likely due to a corrupted ADMT agent (OnePointdomainAgent)  installation. 

Resolution

Uninstall and reinstall the ADMT agent (OnePointdomainAgent).  If you can’t uninstall from the console or control panel, you need to perform a manual removal process. 

You can use SC command to delete the agent if needed – SC Delete "OnePointdomainAgent"

Also, make sure the HKLM\Software\Microsoft\ADMT registry key  and c:\windows\ADMT Directory are  not present after the agent removal.

Wednesday, January 11, 2012

Top 10 Scripts in Microsoft Script Repository

Microsoft Scripting Guy has announced the top 10 scripts in the Microsoft Script Gallery.  My script - List Group Members in Active Directory has ranked #8 on the list..Woo hoo Smile

At number eight, we have the List Group Members in Active Directory script written by Microsoft Directory Services MVP, Santhosh Sivarajan. This excellent script had a great following in 2011.
Santhosh's blog:
Santhosh Sivarajan's Blog

You can read the complete reports on the following website:

http://blogs.technet.com/b/heyscriptingguy/archive/2012/01/02/find-the-top-ten-scripts-submitted-to-the-script-repository.aspx?utm_source=twitterfeed&utm_medium=twitter

Sunday, January 1, 2012

Microsoft Most Valuable Professional (MVP) Award

Microsoft Most Valuable Professional (MVP) Award – Directory Services

Perfect start to my 2012.  Received the Microsoft Most Valuable Professional (MVP) award for the 2nd time.

Received the email this morning.

clip_image002
Dear Santhosh Sivarajan,


Congratulations! We are pleased to present you with the 2012 Microsoft® MVP Award! This award is given to exceptional technical community leaders who actively share their high quality, real world expertise with others. We appreciate your outstanding contributions in Directory Services technical communities during the past year.
Also in this email:

  • About your MVP Award Gift
  • How to claim your award benefits
  • Your MVP Identification Number
  • MVP Award Program Code of Conduct

The Microsoft MVP Award provides us the unique opportunity to celebrate and honor your significant contributions and say "Thank you for your technical leadership."


Nestor Portillo
Director
Community & Online Support


MVP Award News

Business Journal - http://www.bizjournals.com/houston/potmsearch/detail/submission/479181

image


Indo American News - http://www.indoamerican-news.com/?p=5487

image


Voice Of Asia - http://voiceofasiaonline.com/ShowArticle.aspx?ID=1337

image


Indus Business Journal - http://www.indusbusinessjournal.com/ME2/dirmod.asp?sid=&nm=&type=Publishing&mod=Publications%3A%3AArticle&mid=8F3A7027421841978F18BE895F87F791&tier=4&id=75AF58F24C4640F491DE5B3AEA3A4775

 

image


India West - http://www.indiawest.com/news/3435-santhosh-sivarajan-receives-microsoft-mvp-award.html

image


Sugarland Magazine - http://www.sugarlandmagazine.com/blog/sugar-land-resident-receives-microsoft-mvp-award

 

image

 


2011 Microsoft MVP Award News - http://portal.sivarajan.com/2011/01/microsoft-most-valuable-professional.html

Tuesday, December 6, 2011

Microsoft Component Architecture Posters (Updated)

Update 3/13/2012 – Updated with Windows 8 Posters

Windows Server 8

Windows Server “8” Beta Hyper-V Component Architecture Poster - http://www.microsoft.com/download/en/details.aspx?id=29189

image

Update 12/6/2011 12:21 PM – I have added a few more Component Architecture Posters to one of my old blogs - http://portal.sivarajan.com/2010/07/microsoft-component-architecture-poster.html

image

The Component Architecture Poster provides a visual reference for understanding the key services and technologies. The following are the collection of these Microsoft Component Architecture posters:

Windows Server

Windows Server 2008 Active Directory - http://www.microsoft.com/download/en/details.aspx?id=17881

Windows Server 2008 Feature Components - http://www.microsoft.com/download/en/details.aspx?id=17881

Windows Server 2008 R2 Feature - http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=7002

Windows Server 2008 R2 - Remote Desktop Services - http://www.microsoft.com/download/en/details.aspx?id=3262

Windows Server 2008 R2 - Hyper-V - http://www.microsoft.com/download/en/details.aspx?id=3501

Exchange

Exchange Server 2010 Architecture - http://www.microsoft.com/download/en/details.aspx?id=5764

Exchange Server 2010 Transport Server Role - http://www.microsoft.com/download/en/details.aspx?id=21987

Exchange Server 2007 Architecture- http://www.microsoft.com/download/en/details.aspx?id=4006

Exchange Server 2007 Transport Server Role - http://www.microsoft.com/download/en/details.aspx?id=13117

Lync Server

Lync Server 2010 Protocol Workloads - http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=6797

SharePoint

Design Sample: Corporate Portal with Classic Authentication

  • Visio (http://go.microsoft.com/fwlink/?LinkId=196969)
  • PDF (http://go.microsoft.com/fwlink/?LinkId=196970)
  • XPS (http://go.microsoft.com/fwlink/?LinkId=196971)

Design Sample: Corporate Portal with Claims-based Authentication

  • Visio (http://go.microsoft.com/fwlink/?LinkId=196972)
  • PDF (http://go.microsoft.com/fwlink/?LinkId=196973)
  • XPS (http://go.microsoft.com/fwlink/?LinkId=196974)

SharePoint 2010 Products Deployment

  • Visio (http://go.microsoft.com/fwlink/?LinkId=183024)
  • PDF (http://go.microsoft.com/fwlink/?LinkId=183025)
  • XPS (http://go.microsoft.com/fwlink/?LinkId=183026)

Services in SharePoint 2010 Products

  • Visio (http://go.microsoft.com/fwlink/?LinkID=167090)
  • PDF (http://go.microsoft.com/fwlink/?LinkID=167092)
  • XPS (http://go.microsoft.com/fwlink/?LinkID=167091)

Cross-farm Services in SharePoint 2010 Products

  • Visio (http://go.microsoft.com/fwlink/?LinkID=167093)
  • PDF (http://go.microsoft.com/fwlink/?LinkID=167095)
  • XPS (http://go.microsoft.com/fwlink/?LinkID=167094)

Topologies for SharePoint Server 2010

  • Visio (http://go.microsoft.com/fwlink/?LinkID=167087)
  • PDF (http://go.microsoft.com/fwlink/?LinkID=167089)
  • XPS (http://go.microsoft.com/fwlink/?LinkID=167088)

Extranet Topologies for SharePoint 2010 Products

  • Visio (http://go.microsoft.com/fwlink/?LinkId=187987)
  • PDF (http://go.microsoft.com/fwlink/?LinkId=187988)
  • XPS (http://go.microsoft.com/fwlink/?LinkId=187986)

Hosting Environments in SharePoint 2010 Products

  • Visio (http://go.microsoft.com/fwlink/?LinkID=167084)
  • PDF (http://go.microsoft.com/fwlink/?LinkID=167086)
  • XPS (http://go.microsoft.com/fwlink/?LinkID=167085)

Search Technologies for SharePoint 2010 Products

  • Visio (http://go.microsoft.com/fwlink/?LinkID=167731)
  • PDF (http://go.microsoft.com/fwlink/?LinkID=167733)
  • XPS (http://go.microsoft.com/fwlink/?LinkID=167732)

Search Environment Planning for Microsoft SharePoint Server 2010

  • Visio (http://go.microsoft.com/fwlink/?LinkID=167734)
  • PDF (http://go.microsoft.com/fwlink/?LinkID=167736)
  • XPS (http://go.microsoft.com/fwlink/?LinkID=167735)

Search Architectures for Microsoft SharePoint Server 2010

  • Visio (http://go.microsoft.com/fwlink/?LinkID=167737)
  • PDF (http://go.microsoft.com/fwlink/?LinkID=167739)
  • XPS (http://go.microsoft.com/fwlink/?LinkID=167738)

Design Search Architectures for Microsoft SharePoint Server 2010

  • Visio (http://go.microsoft.com/fwlink/?LinkID=167740)
  • PDF (http://go.microsoft.com/fwlink/?LinkID=167742)
  • XPS (http://go.microsoft.com/fwlink/?LinkID=167741)

Business Connectivity Services Model

  • Visio (http://go.microsoft.com/fwlink/?LinkId=165565)
  • PDF (http://go.microsoft.com/fwlink/?LinkID=165566)
  • XPS (http://go.microsoft.com/fwlink/?LinkId=165571)

Content Deployment in SharePoint Server 2010

  • Visio (http://go.microsoft.com/fwlink/?LinkID=179391&clcid=0x409)
  • PDF (http://go.microsoft.com/fwlink/?LinkID=179523&clcid=0x409)
  • XPS (http://go.microsoft.com/fwlink/?LinkID=179524&clcid=0x409)

Microsoft SharePoint Server 2010 Upgrade Planning

  • Visio (http://go.microsoft.com/fwlink/?LinkId=167098)
  • PDF (http://go.microsoft.com/fwlink/?LinkId=167099)
  • XPS (http://go.microsoft.com/fwlink/?LinkId=167100)

Microsoft SharePoint Server 2010 Upgrade Approaches

  • Visio (http://go.microsoft.com/fwlink/?LinkId=167101)
  • PDF (http://go.microsoft.com/fwlink/?LinkId=167102)
  • XPS (http://go.microsoft.com/fwlink/?LinkId=167103)

Microsoft SharePoint Server 2010 — Test Your Upgrade Process

  • Visio (http://go.microsoft.com/fwlink/?LinkId=167104)
  • PDF (http://go.microsoft.com/fwlink/?LinkId=167105)
  • XPS (http://go.microsoft.com/fwlink/?LinkId=167106)

Microsoft SharePoint Server 2010 — Services Upgrade

  • Visio (http://go.microsoft.com/fwlink/?LinkId=167107)
  • PDF (http://go.microsoft.com/fwlink/?LinkId=167108)
  • XPS (http://go.microsoft.com/fwlink/?LinkId=167109)

Microsoft SharePoint Server 2010 — Upgrading Parent and Child Farms

  • Visio (http://go.microsoft.com/fwlink/?LinkId=190984)
  • PDF (http://go.microsoft.com/fwlink/?LinkId=190985)
  • XPS (http://go.microsoft.com/fwlink/?LinkId=190986)

Getting started with business intelligence in SharePoint Server 2010

  • Visio (http://go.microsoft.com/fwlink/?LinkId=167082)
  • PDF (http://go.microsoft.com/fwlink/?LinkId=167170)
  • XPS (http://go.microsoft.com/fwlink/?LinkId=167171)

Databases That Support SharePoint 2010 Products

  • Visio (http://go.microsoft.com/fwlink/?LinkId=187970)
  • PDF (http://go.microsoft.com/fwlink/?LinkId=187969)
  • XPS (http://go.microsoft.com/fwlink/?LinkId=187971)

SharePoint 2010 Products: Virtualization Process

Tuesday, November 22, 2011

Free Microsoft Press eBooks (updated)

I am not sure if you guys are aware that a few Microsoft e-books are available for free download (originally published this blog on Sunday, September 26, 2010 8:21 PM) . Here are the details:

Moving to Visual Studio 2010

image

Download

Programming Windows Phone 7

image

Download

Office 365 - Connect and Collaborate Virtually Anywhere, Anytime

image_thumb1

Download

Windows 7 Product Guide

image

Download

Introducing SQL Server 2008 R2

clip_image002

Download

Introducing Microsoft SQL Server 2012

2

Download

Introducing Windows 2008 R2

image

Download

Understanding Microsoft Virtualization Solutions – First Edition

image

Download

Understanding Microsoft Virtualization Solutions – Second Edition

3

Download

Deploying Windows 7 - Essential Guidance

image

Download

First Look Microsoft Office 2010

image

Download

Update Your Skills with Resources and Career Ideas from Microsoft

image

Download

Security and Privacy for Microsoft Office Users

lrg

Download

Friday, November 11, 2011

Active Directory: Active Directory Domain Services (AD DS) Commands and Scripts

I have updated the “Active Directory: Active Directory Domain Services (AD DS) Commands and Scripts” TechNet Wiki article with more DS commands. Feel free to update/modify this article.  http://social.technet.microsoft.com/wiki/contents/articles/3537.aspx
User

Identify OCS enabled users in Active Directory

Dsquery * -filter (msRTCSIP-UserEnabled=TRUE) –limit 0 –attr name samaccountname

Query Password Last Set (pwdlastset) value

dsquery * -filter "&(objectClass=User)(objectCategory=Person)" -limit 0 -attr name pwdlastset

Note: Time can be convered using the w32tm /ntte command.

Search Password Never Expires Settings

Dsquery * -limit 0 “(&(objectCategory=person)(objectClass=user)(userAccountControl:1.2.840.113556.1.4.803:=65536))” –attr samaccoutname name

Password Expiring in 30 Days

dsquery * -limit 0 -filter "(&(objectCategory=person)(objectClass=user)(userAccountControl:1.2.840.113556.1.4.803:=4194304))" -attr name samaccountname

User accounts with “Do not require kerberos preauthentication” enabled

Dsquery * -limit 0 “(&(objectCategory=person)(objectClass=user)(!userAccountControl:1.2.840.113556.1.4.803:=8388608)(!userAccountControl:1.2.840.113556.1.4.803:=65536)(pwdLastSet>=129522420000000000)(pwdLastSet<=129548340000000000))” –attr samaccountname name

List all Roaming Profile users in Active Directory

dsquery * -filter "&(objectClass=User)(objectCategory=Person)(profilePath=*)" -limit 0 -name

Generate SIDHistory Report

dsquery * -filter "&(objectClass=User)(objectCategory=Person)" –attr samAccountName sidHistory

Generate SID (ObjectSID) Report

dsquery * -filter "&(objectClass=User)(objectCategory=Person)" –attr samAccountName Object

Group

Identify all Security Groups

dsquery * -filter "(&(objectCategory=group)
(groupType:1.2.840.113556.1.4.804:=2147483648))" –attr samAccountName name

Identify all Built-In Security Groups

dsquery * -filter "(&(objectCategory=group)
(groupType:1.2.840.113556.1.4.803:=2147483649))" –attr samAccountName name

Identify all Universal Security Groups

dsquery * -filter "(&(objectCategory=group)
(groupType:1.2.840.113556.1.4.803:=2147483656))" –attr samAccountName name

Identify all Gloabl Security Groups

dsquery * -filter "(&(objectCategory=group)
(groupType:1.2.840.113556.1.4.803:=2147483650))" –attr samAccountName name

Computer

Move Computer Objects Based on OS Version

Move Widnows 7 Computers

dsquery * CN=Computers,DC=santhosh,DC=lab -filter "(&(ObjectClass=computer)(objectCategory=Computer)(operatingSystemVersion=6.1))" | dsmove -newparent OU=Win7,OU=ComputerAccounts,DC=santhosh,DC=lab

Move Windows XP Computers

dsquery * CN=Computers,DC=santhosh,DC=lab -filter "(&(ObjectClass=computer)(objectCategory=Computer)(operatingSystemVersion=5.1))" | dsmove -newparent OU=WinXP,OU=ComputerAccounts,DC=santhosh,DC=lab

Domain Controller

 

Site and Subnet

List all Sites in Active Directory

Dsquery site * -name

Get Site Name from Subnet IP Address in Active Directory (For example, Site Name for Subnet 192.168.2.0/24)

Dsquery Subnet -Name 192.168.2.0/24 | Dsget Subnet -Site

Monday, October 24, 2011

Search AD, Collect Local Admin Group Info and Generate Email Alert – PowerShell Script

This is an updated version of one of my old scripts - http://portal.sivarajan.com/2011/04/list-local-administrator-group-members.html based on the discussion in the http://sivarajan.com/forum/viewthread.php?tid=59 thread. 

This updated script

  1. Searches Active Directory (Search_AD function) and collects the computer object information.  This information will be stored in the C:\Scripts\Servers.csv file. 
  2. The second function (Seach_LAdmin) uses  C:\Scripts\Servers.csv file as an input  and collects the Local Administrator Group membership details from these computers.
  3. The third function (Send_Email), generates an email alert with the output file (C:\Scripts\SGroupMemberDetails.csv).

Script

image

Output

It generates 2 output files – Servers.csv and SGroupMemberDetails.csv.  The Servers.csv contains all computer information from Active Directory (output of Seach_AD function) and SGroupMemberDetails.csv file contains the Local Admin group membership details . 

You will also see the status in the console itself. 

image

An email alert will be generated with SGroupMemberDetails.csv file (Send_Email function). 

Note

In PowerShell V2, you can use Send-MailMessage cmdlet create an email message:
http://technet.microsoft.com/en-us/library/dd347693.aspx

Download

You can download the script from the following 2 locations:

  1. www.sivarajan.com - http://www.sivarajan.com/scripts/Search_AD_Local_Admin_Email.txt
  2. Microsoft TechNet Gallery - http://gallery.technet.microsoft.com/scriptcenter/Search-AD-Collect-Local-9952be71

Popular Posts

Sociable

Share

Twitter Delicious Facebook Digg Stumbleupon Favorites More