<?xml version="1.0" encoding="utf-8"?><?xml-stylesheet type='text/xsl' href='http://elfassy.spaces.live.com/mmm2008-05-08_20.17/rsspretty.aspx?rssquery=en-US;http%3a%2f%2felfassy.spaces.live.com%2fcategory%2fActive%2bDirectory%2ffeed.rss' version='1.0'?><rss version="2.0" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:msn="http://schemas.microsoft.com/msn/spaces/2005/rss" xmlns:live="http://schemas.microsoft.com/live/spaces/2006/rss" xmlns:dcterms="http://purl.org/dc/terms/" xmlns:cf="http://www.microsoft.com/schemas/rss/core/2005" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Exchange Server 2007 / 2003 (tips and tricks) sprinkled with SMS and AD stuff...: Active Directory</title><description /><link>http://elfassy.spaces.live.com/?_c11_BlogPart_BlogPart=blogview&amp;_c=BlogPart&amp;partqs=catActive%2bDirectory</link><language>en-US</language><pubDate>Wed, 14 May 2008 03:29:14 GMT</pubDate><lastBuildDate>Wed, 14 May 2008 03:29:14 GMT</lastBuildDate><generator>Microsoft Spaces v1.1</generator><docs>http://www.rssboard.org/rss-specification</docs><ttl>60</ttl><cf:parentRSS>http://elfassy.spaces.live.com/blog/feed.rss</cf:parentRSS><live:type>blogcategory</live:type><live:identity><live:id>-188369696623034668</live:id><live:alias>elfassy</live:alias></live:identity><cf:listinfo><cf:group ns="http://schemas.microsoft.com/live/spaces/2006/rss" element="typelabel" label="Type" /><cf:group ns="http://schemas.microsoft.com/live/spaces/2006/rss" element="tag" label="Tag" /><cf:group element="category" label="Category" /><cf:sort element="pubDate" label="Date" data-type="date" default="true" /><cf:sort element="title" label="Title" data-type="string" /><cf:sort ns="http://purl.org/rss/1.0/modules/slash/" element="comments" label="Comments" data-type="number" /></cf:listinfo><item><title>Couple of little known GPO tools</title><link>http://elfassy.spaces.live.com/Blog/cns!FD62C6C24A55FED4!165.entry</link><description>&lt;p&gt;Well it's been a while since I blogged on Active Directory and I'm starting to feel a little rusty (after all, I haven't worked on AD for a month now ;)) I now have a pretty large list of tools and utilities that are less known that most. While going through that list I came across two I haven't used in a while, but had, at one time, been pretty useful. Here they are: &lt;p&gt;&lt;strong&gt;ADMX.EXE:&lt;/strong&gt; This tool allows you to extract GPO settings (from an .ADM file) to a text file, then use a file parser to compare the contents of one file with another. Usefull when MS comes up with a new .ADM template, as they do with each OS update (including Service Packs). BTW, the latest .ADM template available right now is packaged with Windows XP SP2, a new one will soon arrive with W2K3 SP1. &lt;p&gt;&lt;strong&gt;DCGPOFIX.EXE:&lt;/strong&gt; Well you screwed up the default AD gpo's (domain and domain controllers OU) and you want to restore them to their default settings. This is the tool for you. &lt;p&gt;More to come soon...&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-188369696623034668&amp;page=RSS%3a+Couple+of+little+known+GPO+tools&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=elfassy.spaces.live.com&amp;amp;GT1=elfassy"&gt;</description><comments>http://elfassy.spaces.live.com/Blog/cns!FD62C6C24A55FED4!165.entry#comment</comments><guid isPermaLink="true">http://elfassy.spaces.live.com/Blog/cns!FD62C6C24A55FED4!165.entry</guid><pubDate>Wed, 23 Feb 2005 05:11:14 GMT</pubDate><slash:comments>2</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://elfassy.spaces.live.com/blog/cns!FD62C6C24A55FED4!165/comments/feed.rss</wfw:commentRss><wfw:comment>http://elfassy.spaces.live.com/Blog/cns!FD62C6C24A55FED4!165.entry#comment</wfw:comment><dcterms:modified>2005-02-23T13:52:47Z</dcterms:modified></item><item><title>Taking DC's offline for an extended period of time</title><link>http://elfassy.spaces.live.com/Blog/cns!FD62C6C24A55FED4!146.entry</link><description>&lt;p&gt;Recently I was working on a military project where we had to configure naval ships with AD domain controllers. Each ship would have it's own domain controller, part of the military domain. (name and country has to remain private) I recieved the guarantee that DC's would synchronize through satellite communication at least every 2 months. To ensure i would not run into any problems with tombstones, I increased the tombstone lifetime to 120 days for the DC's. &lt;p&gt;I moved on to other projects and one day got a call from the client, they had issues with DC's not able to replicate domain information. Turned out the DC's had been out of sync for 6 months. It definitely wasn't a smart idea, but they applied the following registry modification to allow replication: &lt;p&gt;&lt;br&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS\Parameters &lt;br&gt;DWORD value: &lt;em&gt;(thanks for pointing that out GKressel)&lt;br&gt;&lt;/em&gt;Allow Replication With Divergent and Corrupt Partner  - Value: 1 &lt;p&gt;Replication works fine now, but what shadow/ghost object will appear? I'll keep you updated.&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-188369696623034668&amp;page=RSS%3a+Taking+DC's+offline+for+an+extended+period+of+time&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=elfassy.spaces.live.com&amp;amp;GT1=elfassy"&gt;</description><comments>http://elfassy.spaces.live.com/Blog/cns!FD62C6C24A55FED4!146.entry#comment</comments><guid isPermaLink="true">http://elfassy.spaces.live.com/Blog/cns!FD62C6C24A55FED4!146.entry</guid><pubDate>Fri, 17 Dec 2004 16:45:43 GMT</pubDate><slash:comments>3</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://elfassy.spaces.live.com/blog/cns!FD62C6C24A55FED4!146/comments/feed.rss</wfw:commentRss><wfw:comment>http://elfassy.spaces.live.com/Blog/cns!FD62C6C24A55FED4!146.entry#comment</wfw:comment><dcterms:modified>2005-03-02T03:12:45Z</dcterms:modified></item><item><title>How do you refresh the cache for Universal Group Membership?</title><link>http://elfassy.spaces.live.com/Blog/cns!FD62C6C24A55FED4!145.entry</link><description>&lt;p&gt;This new (relatively) feature in Windows Server 2003 removes the requirement of a (subsequent) logon query to the Global Catalog server. However this information only gets refreshed every 8 hours. If you want to force a refresh from the &amp;quot;caching site&amp;quot; here's the VB syntax: &lt;p&gt;set objRoot = GetObject(&lt;a&gt;LDAP://RootDSE&lt;/a&gt;) &lt;p&gt;objRoot.Put &amp;quot;UpdateCachedMemberships&amp;quot;, 1 &lt;p&gt;objRoot.SetInfo &lt;p&gt;msgbox &amp;quot;Thanks David for this nice script :)&amp;quot;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-188369696623034668&amp;page=RSS%3a+How+do+you+refresh+the+cache+for+Universal+Group+Membership%3f&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=elfassy.spaces.live.com&amp;amp;GT1=elfassy"&gt;</description><comments>http://elfassy.spaces.live.com/Blog/cns!FD62C6C24A55FED4!145.entry#comment</comments><guid isPermaLink="true">http://elfassy.spaces.live.com/Blog/cns!FD62C6C24A55FED4!145.entry</guid><pubDate>Thu, 16 Dec 2004 19:48:40 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://elfassy.spaces.live.com/blog/cns!FD62C6C24A55FED4!145/comments/feed.rss</wfw:commentRss><wfw:comment>http://elfassy.spaces.live.com/Blog/cns!FD62C6C24A55FED4!145.entry#comment</wfw:comment><dcterms:modified>2004-12-16T19:48:40Z</dcterms:modified></item><item><title>nltest is your friend...</title><link>http://elfassy.spaces.live.com/Blog/cns!FD62C6C24A55FED4!133.entry</link><description>&lt;p&gt;A couple of weeks ago I ran into an issue where a client computer was not receiving his site-linked GPO. I had just created the new site structure, so I was wondering if the client did not yet get the site information. I had used Nltest.exe before, but had never used this switch. &lt;p&gt;nltest /dsgetsite &lt;p&gt;It will return the local site membership of the client computer. I then noticed the client was reading his information from cache and force a refresh with: Nltest /dsgetdc:DOMAIN_NAME /force &lt;p&gt;GPO Applied!&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-188369696623034668&amp;page=RSS%3a+nltest+is+your+friend...&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=elfassy.spaces.live.com&amp;amp;GT1=elfassy"&gt;</description><comments>http://elfassy.spaces.live.com/Blog/cns!FD62C6C24A55FED4!133.entry#comment</comments><guid isPermaLink="true">http://elfassy.spaces.live.com/Blog/cns!FD62C6C24A55FED4!133.entry</guid><pubDate>Wed, 15 Dec 2004 15:28:42 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://elfassy.spaces.live.com/blog/cns!FD62C6C24A55FED4!133/comments/feed.rss</wfw:commentRss><wfw:comment>http://elfassy.spaces.live.com/Blog/cns!FD62C6C24A55FED4!133.entry#comment</wfw:comment><dcterms:modified>2004-12-15T15:28:42Z</dcterms:modified></item><item><title>Securing your Administrator account</title><link>http://elfassy.spaces.live.com/Blog/cns!FD62C6C24A55FED4!120.entry</link><description>&lt;p&gt;One of the things i'm starting to recommend to my students relating the built-in Administrator account is to rename it. Which that in itself is nothing new, but along with that create a new &amp;quot;fake&amp;quot; administrator account, named &amp;quot;Administrator&amp;quot; with as little user rights as possible. Set a very complex password to that account and let hacker hack away at that account.&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=-188369696623034668&amp;page=RSS%3a+Securing+your+Administrator+account&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=elfassy.spaces.live.com&amp;amp;GT1=elfassy"&gt;</description><comments>http://elfassy.spaces.live.com/Blog/cns!FD62C6C24A55FED4!120.entry#comment</comments><guid isPermaLink="true">http://elfassy.spaces.live.com/Blog/cns!FD62C6C24A55FED4!120.entry</guid><pubDate>Wed, 15 Dec 2004 01:42:11 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://elfassy.spaces.live.com/blog/cns!FD62C6C24A55FED4!120/comments/feed.rss</wfw:commentRss><wfw:comment>http://elfassy.spaces.live.com/Blog/cns!FD62C6C24A55FED4!120.entry#comment</wfw:comment><dcterms:modified>2004-12-15T01:42:11Z</dcterms:modified></item></channel></rss>