Posted by John Policelli on March 9th, 2010
As I announced back in November, Microsoft released the Exchange Server 2010 Deployment Assistant. Microsoft recently released additional content for the following upgrade scenarios:
- Upgrading from Exchange Server 2007
- Upgrading from a mixed Exchange Server 2003/2007
- New Exchange Server 2010 installation
The Exchange Server 2010 Deployment Assistant, including the abovementioned additional upgrade scenarios, can be found here: http://technet.microsoft.com/exdeploy2010
Tags: Deployment, Exchange Server 2010, Upgrade
Posted in Exchange Server | No Comments »
Posted by John Policelli on March 9th, 2010
Microsoft Released Update Rollup 2 for Exchange Server 2007 SP2. There are over 50 issues that the update rollup fixes. Details on the Update Rollup can be found at http://support.microsoft.com/kb/972076.
Tags: Exchange Server 2007, Update Rollup
Posted in Exchange Server | No Comments »
Posted by John Policelli on March 9th, 2010
A post of the MS Exchange Team Blog does a great job of providing guidance on triaging Exchange performance issues related to Active Directory performance, networking, and DNS.
The post can be found here: http://msexchangeteam.com/archive/2010/02/03/453931.aspx.
Tags: Active Directory, Exchange Server, Performance Issues, Triaging
Posted in Exchange Server | No Comments »
Posted by John Policelli on March 9th, 2010
Version 4.5 of the Mailbox Server Role Requirements Calculator, which can be found here, has been released.
Read the rest of this entry »
Tags: Exchange Server, Exchange Server 2010, Mailbox Server Role Requirements Calculator
Posted in Exchange Server | No Comments »
Posted by John Policelli on March 9th, 2010
The Exchange Pre-Deployment Analyzer (ExPDA) performs an overall topology readiness scan of your environment and provides you with a list of decisions that need to be made before you deploy Exchange Server 2010.
Read the rest of this entry »
Tags: Exchange Server 2010, ExPDA
Posted in Exchange Server | No Comments »
Posted by John Policelli on March 9th, 2010
Update Rollup 2 for Exchange Server 2010 fixes the issues that are described in the following Microsoft Knowledge Base (KB) articles:
Read the rest of this entry »
Tags: Exchange Server 2010, Update Rollup
Posted in Exchange Server | No Comments »
Posted by John Policelli on March 9th, 2010
The link below contains a listing of the official Microsoft Team Blogs and essential web feeds organised by category: http://blogs.technet.com/blogms/pages/directory-of-microsoft-team-blogs.aspx.
Posted in Misc | No Comments »
Posted by John Policelli on March 9th, 2010
Posted in AD DS | No Comments »
Posted by John Policelli on March 9th, 2010
In case you haven’t heard, Active Directory Lightweight Directory Services (AD LDS) is now available for Windows7. Here is the link to the download: http://www.microsoft.com/downloads/details.aspx?displaylang=en&FamilyID=a45059af-47a8-4c96-afe3-93dab7b5b658
Tags: AD LDS, Windows 7
Posted in AD LDS | No Comments »
Posted by John Policelli on March 9th, 2010
DCDiag.exe is an extremely useful built-in troubleshooting tool. I stumbled across a KB from Microsoft that explains that in certain environments, and under certain conditions, DCDiag.exe may take an excessive amount of time to run on computers with Windows Server 2008 R2 or Windows 7 installed. The good news is that MS has released an updated version of DCDiag.exe which fixes this issue. The KB and download can be found here: http://support.microsoft.com/?kbid=979294.
Tags: Active Directory, DCDiag
Posted in AD DS | No Comments »
Posted by John Policelli on March 9th, 2010
Microsoft has acknowledged an issue with the Active Directory garbage collection process, which may cause a domain controller to run slow or stop responding.
Read the rest of this entry »
Tags: Active Directory, Hotfix, KB
Posted in AD DS | No Comments »
Posted by John Policelli on January 21st, 2010
I ran into a situation where I needed to cluster two Hyper-V guests. I found several articles that provided guidance around setting up shared storage for this, but none of them were completely accurate. I then stumbled across the below post, which worked perfectly. It’s definitely worth a read.
Hyper-V Guest Clustering Step-by-Step Guide
Tags: Failover Clustering, Hyper-V, Windows Server 2008 R2
Posted in Hyper-V | No Comments »
Posted by John Policelli on January 3rd, 2010
I was very happy to hear that I was selected to present at TEC 2010 in Los Angeles.
TEC was previously known as DEC (Directory Experts Conference). The conference has been expanded to include training on Exchange and SharePoint, and effectively renamed to TEC. Here’s a snippet for the TEC 2010 Website:
For the 9th consecutive year, the TEC team will deliver expert-led, 400-level training on vital Microsoft technologies. In addition to its highly-acclaimed training on Microsoft Directory & Identity technologies, TEC 2010 will bring back a full agenda of Exchange training, staging the world’s leading authorities on Microsoft’s powerful messaging platform. And, this year, for the first time ever, we are pleased to introduce an entirely new TEC for SharePoint training conference!
I will be presenting in the Directory & Identity track. My session is called An In-Depth Look at AdminSDHolder, Protects Groups, and SDPROP.
Here is the abstract for my session:
Active Directory includes a number of built-in controls, which collectively provide an additional level of security for members of privileged groups. Even though these controls have been in place since the inaugural release of Active Directory a decade ago, administrators are still impacted by this functionality regularly. In this session, John Policelli will dive into the AdminSDHolder object, Protected Groups, and the Security Descriptor Propagator. Real-world examples, demos, and theory will be used to provide you with a comprehensive understanding of how these built-in controls interoperate and how you can use them to further secure members of privileged Active Directory groups.
I’ve attended DEC/TEC for several years, and it has proven invaluable each time. I have yet to find any comparable conferences. For more information on TEC 2010, please go to http://www.theexpertsconference.com/. I hope to see you there!
Tags: Active Directory, AdminSDHolder, Conferences, Directory & Identity, TEC 2010
Posted in Publications | No Comments »
Posted by John Policelli on December 16th, 2009
Microsoft recently published an article that addresses a hot topic – whether or not you should place several RODCs in the same Active Directory site. In my opinion, this article does a good job of giving you the information you’ll need to determine RODC placement. The article can be read here: http://technet.microsoft.com/en-us/library/ee522995(WS.10).aspx
Tags: Active Directory, RODCs
Posted in AD DS | No Comments »
Posted by John Policelli on December 16th, 2009
In order to enable full support, three updates are required:
More information can be found here and here.
Tags: BES, Exchange Server 2010
Posted in Exchange Server | No Comments »
Posted by John Policelli on December 16th, 2009
The Microsoft Exchange Team Blog has started a series of posts that are must reads if you plan to upgrade to Exchange Server 2010. Here’s a list of the posts they’ve published to date:
Tags: ActiveSync, CAS, Exchange Server 2010, OWA, Upgrade
Posted in Exchange Server | No Comments »
Posted by John Policelli on December 16th, 2009
A couple of months after Exchange Server 2010 was released to manufacturing, Microsoft has released Update Rollup 1. The following is a list of issues fixed in Exchange 2010 Update Rollup 1:
Read the rest of this entry »
Tags: Exchange Server 2010, Update Rollup
Posted in Exchange Server | No Comments »
Posted by John Policelli on November 29th, 2009
I have finally arrived at the point where I can say that I’m running efficiently
.
Home Network
- Windows Server 2008 R2
- Hyper-V R2
- Windows 7
- Office 2010
Mobility
Work
- Exchange Server 2010
- Windows 7
- Office 2010
It’s an efficient world after all
.
Here’s a link to Microsoft’s New Efficiency Website: http://thenewefficiency.com
Tags: Exchange Server 2010, Hyper-V R2, Office 2010, Windows 7, Windows Server 2008 R2
Posted in Windows Server | No Comments »
Posted by John Policelli on November 25th, 2009
I’ve been following the Microsoft Learning’s Born to Learn blog for some time now. I’ve seen a number of public invitations for Beta exams. There’s a great post on this blog which will give you more insight on how to get invited to take a Beta exam. It can be found here: http://borntolearn.mslearn.net/2009/09/understanding-the-beta-invite-process.
Tags: Beta Exams, Microsoft Learning
Posted in Misc | No Comments »
Posted by John Policelli on November 25th, 2009
Microsoft Released Update Rollup 1 for Exchange Server 2007 SP2. There are almost 50 issues that the update rollup fixes. Details on the Update Rollup can be found at http://support.microsoft.com/kb/971534 and http://msexchangeteam.com/archive/2009/11/21/453277.aspx.
Tags: Exchange Server 2007, Update Rollup
Posted in Exchange Server | No Comments »
Posted by John Policelli on November 6th, 2009
NOTE: I revised this article to fix some mistakes and to include new content from Windows Server 2008 R2.
Active Directory has built-in processes that exist to secure users that are members of privileged groups. These processes have been around for quite some time, but Active Directory administrators still get stumped by them regularly. What follows, is a updated look at AdminSDHolder, Protected Groups, and SDPROP. Windows Server 2008 R2 specific content has been added.
This article will provide you with the following information:
- Overview
- How AdminSDHolder Works
- Default ACL on the AdminSDHolder Object in Windows Server 2008 R2
- Default Protected Groups and Users
- Modifying How Often the AdminSDHolder Background Process Runs
- How to Determine if a User or Group is Protected by AdminSDHolder
- Orphaned AdminSDHolder Objects
- Security Descriptor Propagator
- How to Force AdminSDHolder to Run
- Additional Resources
Read the rest of this entry »
Tags: Access Control List, ACLs, Active Directory, Default ACL, Default Permissions, Privileged Accounts, Privileged Groups, Securing Active Directory, security principals
Posted in AD DS | 3 Comments »
Posted by John Policelli on November 5th, 2009
It’s official, Kevin Allison (GM Exchange Customer Experience) published a post on the Microsoft Exchange Team Blog stating that Exchange 2007 will support Windows Server 2008 R2. The catch, it’s not here yet
. There is no specific date provided in his post, but he does state “In the coming calendar year we will issue an update for Exchange 2007 enabling full support of Windows Server 2008 R2.”
Tags: Exchange Server 2007, Windows Server 2008 R2
Posted in Exchange Server | No Comments »
Posted by John Policelli on November 5th, 2009
Microsoft has made Group Policy cmdlets for Windows PowerShell available. These cmdlets, roughly 25 in total, can be used to:
- Maintain GPOs (create, remove, backup, reporting, and import)
- Associate GPOs with AD DS containers (link, update, and remove)
- Set inheritance and permissions on AD DS OUs and domains
- Configure registry-based settings and Group Policy Preferences Registry settings
Read the rest of this entry »
Tags: Active Directory, Group Policy, PowerShell, Windows Server 2008 R2
Posted in AD DS | No Comments »
Posted by John Policelli on October 28th, 2009
Microsoft started publishing the number of MCPs worldwide, broken down by credential on their Microsoft Learning site. The list can be found here: https://www.microsoft.com/learning/en/us/certification/cert-overview.aspx#tab5.
If you drill down a little further on this site, you’ll also find the number of MCAs and MCMs. Here’s the direct link for this information: https://www.microsoft.com/learning/en/us/certification/master.aspx#meet
Tags: Certification, MCA, MCM, MCP
Posted in Misc | No Comments »
Posted by John Policelli on October 27th, 2009
Microsoft recently released a KB that outlines the methods that you can use to upgrade a Windows Server 2008, that has the Hyper-V role installed, to Windows Server 2008 R2.
The following methods are discussed in the KB:
- Perform an in-place upgrade of the parent partition from Windows Server 2008 to Windows Server 2008 R2.
- Export a virtual machine from a Windows Server 2008-based computer that has Hyper-V enabled, and then import it to a server that has Windows Server 2008 R2 with Hyper-V enabled
- Using backup software that leverages the Hyper-V VSS Writer, back up a virtual machine that is running on Windows Server 2008, and restore it to Windows Server 2008 R2
As you may have heard, Windows Server 2008 R2 introduces a number of important changes and new features for Hyper-V, so if you are planning to upgrade then you should be familiar with this KB. The KB can be found here: http://support.microsoft.com/kb/957256.
Tags: Hyper-V, Windows Server 2008 R2
Posted in Hyper-V | No Comments »
Posted by John Policelli on October 27th, 2009
There’s no doubt that virtualization is hot these days. The following articles, posted on the Dirteam.com Blog, will answer virtually all (no pun intended) questions that you have when it comes to Active Directory in Hyper-V environments.
Tags: Active Directory, Hyper-V
Posted in AD DS | No Comments »
Posted by John Policelli on October 27th, 2009
I designed and implemented a fairly complex three-tier PKI, using Windows Server 2003 Certificate Services, a number of years back that proved to be a painful experience. At that time, there was not a lot of documentation available on MS Certificate Services. I recently stumbled across a couple of posts on the Ask the Directory Services Team Blog, which are worth a read of you’re dealing with PKI. They can be found here:
Tags: Active Directory Certificate Services, PKI
Posted in PKI | No Comments »
Posted by John Policelli on October 27th, 2009
As you may have heard, Microsoft is working on ADMT 3.2, which will be fully supported for Windows Server 2008 R2. However, ADMT 3.2 is still under development and there is no official release date as of yet.
In the interim, a KB has been released that discuss the use of ADMT 3.1 on Windows Server 2008 R2 DCs. The KB points out the following supported scenarios for ADMT 3.1 on Windows Server 2008 R2 DCs:
- ADMT 3.1 must be run from a Windows Server 2008-based computer. The computer must be a member server or a domain controller.
- ADMT can be installed on any computer that is running Windows Server 2008, unless the computers are Read-Only domain controllers or in a Server Core configuration.
- The target domain must be based on Windows 2000 Server, Windows Server 2003, Windows Server 2008, or Windows Server 2008 R2.
- The source domain must be based on Windows 2000 Server, Windows Server 2003, or Windows Server 2008.
- The ADMT agent, which is installed by ADMT on computers in the source domains, can operate on computers that are running Windows 2000 Professional, Windows 2000 Server, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, or Windows Server 2008 R2.
Before you go ahead and use ADMT 3.1 with Windows Server 2008 R2 DCs, you should be aware of the known issues, which can be read by going to http://support.microsoft.com/kb/976659.
Tags: Active Directory, ADMT, Windows Server 2008 R2
Posted in AD DS | 1 Comment »
Posted by John Policelli on October 22nd, 2009
The Active Directory Recycle Bin is a handy new feature in Windows Server 2008 R2. Once enabled, it is now easier to recover accidentally deleted Active Directory objects.
Read the rest of this entry »
Tags: Active Directory, Windows Server 2008 R2
Posted in Publications | No Comments »
Posted by John Policelli on September 25th, 2009
Windows Server 2008 R2, released to manufacturing in July, introduces a number of new features, including a host of new Active Directory Domain Services features. We look at the seven that pack the most powerful punch.
Read the rest of this entry »
Tags: Active Directory, Windows Server 2008 R2
Posted in Publications | No Comments »
Posted by John Policelli on September 25th, 2009
A Computer World Canada feature, Windows 7: Will you or won’t you, on Windows 7 adoption in Canada ran today following an interview with me. The story interviews a number of IT Managers across industries and business environments to present an overview of business’ approach to Windows 7.
Tags: Windows 7
Posted in Publications | No Comments »
Posted by John Policelli on September 23rd, 2009
Since the release of Exchange Server 2010 RC1, there’s been a lot of debate over some ACEs that are added to the AdminSDHolder object by /PrepareDomain in Exchange 2010 RC1. For more information on this, see Exchange 2010 Modification of AdminSDHolder ACL Can Result in Elevation of Privilege and Exchange 2010 RC1 and AdminSDHolder.
A post was added to the Microsoft Exchange Team Blog this morning that confirms that this has been resolved in the RTM version of Exchange Server 2010. More specifically:
- /PrepareDomain no longer applies ACEs granted to Exchange Windows Permissions USG on the AdminSDHolder container. If /PrepareDomain detects the ACEs granted to Exchange Windows Permissions USG on the AdminSDHolder container, /PrepareDomain will remove them.
- /PrepareDomain no longer applies the extended right ACE User-Change-Password to the Exchange Servers USG on the AdminSDHolder container. If /PrepareDomain detects this ACE granted to Exchange Servers USG on the AdminSDHolder container, /PrepareDomain will remove it.
- /PrepareDomain no longer applies the extended right ACE User-Change-Password to the Exchange Servers USG on the domain partition. If /PrepareDomain detects this ACE granted to Exchange Servers USG on the domain partition, /PrepareDomain will remove it.
- /PrepareDomain no longer applies an unscoped DeleteTree and WriteDACL ACEs on the domain partition. Instead, these ACEs are replaced by scoping them specifically to user and inetOrgPerson class objects.
Tags: Active Directory, AdminSDHolder, Exchange Server 2010, Securing Active Directory
Posted in Exchange Server | No Comments »
Posted by John Policelli on September 3rd, 2009
I compiled a list of Exchange Server 2010 resources, which are currently available. I will try to update this list as I come across additional Exchange Server 2010 resources.
Read the rest of this entry »
Tags: Exchange Server 2010
Posted in Exchange Server | 2 Comments »
Posted by John Policelli on August 31st, 2009
UPDATE: This has been resolved in the RTM version of Exchange Server 2010. Please see Exchange 2010 and Resolution of the AdminSDHolder Elevation Issue for more details.
The PrepareDomain setup phase of Exchange 2010 RC1 adds several Access Control Entries (ACEs) to the Access Control List (ACL) of the AdminSDHolder object. One of these ACEs, Write Property for member, can be used to elevate privileges from Exchange Organization Administrator to Enterprise Admins.
Read the rest of this entry »
Tags: Active Directory, AdminSDHolder, Exchange Server 2010, Securing Active Directory
Posted in Exchange Server | No Comments »
Posted by John Policelli on August 30th, 2009
I came across a great post on the Ask the Directory Services Team blog, which covers the new AD Recycling Bin (ADRB) feature that is included with Windows Server 2008 R2. The post covers the following points and is a must read for anyone wanting to learn more about this new feature:
- Understanding how ADRB works under the covers.
- What the requirements are and how to turn ADRB on.
- Using ADRB, along with some best practices.
- Troubleshooting common issues people run into with ADRB.
The post can be read by going to http://blogs.technet.com/askds/archive/2009/08/27/the-ad-recycle-bin-understanding-implementing-best-practices-and-troubleshooting.aspx
Tags: Active Directory, Recovery, Windows Server 2008 R2
Posted in AD DS | No Comments »
Posted by John Policelli on August 21st, 2009
One powerful feature in Windows Server 2008 R2 is its ability to recover objects from Active Directory, which is very handy in those "Uh oh" moments. John Policelli, author of Active Directory Domain Services 2008 How-To, explains what the Active Directory Recycle Bin does and how to use it.
Read the online article by going to: http://www.informit.com/articles/article.aspx?p=1374789
Tags: Active Directory, Windows Server 2008 R2
Posted in Publications | No Comments »
Posted by John Policelli on August 20th, 2009
Remote Server Administrations Tools (RSAT) for Windows 7 are RTM. They can be downloaded here: http://www.microsoft.com/downloads/details.aspx?FamilyID=7d2f6ad7-656b-4313-a005-4e344e43997d&displaylang=en.
Note: This only runs on Windows 7 Business, Professional, and Ultimate
Ensure you remove any previous admin tools (RSAT for Windows 7 Beta/RC, RSAT for Windows Vista, AdminPack for Windows Server 2003).
Tags: Active Directory, RSAT, Windows 7
Posted in Windows 7 | No Comments »
Posted by John Policelli on August 20th, 2009
Kurt Hudson, from the MS Active Directory Documentation Team, reminded us recently about a great article that describes how to use the Repadmin.exe tool to monitor, diagnose, and troubleshoot common replication problems in your Active Directory environment. All the information in the document applies to computers running the Windows 2000 Server and Windows Server 2003 operation systems.
The document includes the following topics:
Read the rest of this entry »
Tags: Active Directory, DS Command-Line Tools, Repadmin
Posted in AD DS | No Comments »
Posted by John Policelli on August 20th, 2009
Are you having problems with Access Control Lists and permissions? It may be related to AdminSDHolder. Learn exactly what AdminSDHolder is, how it works—and how you can tweak it to better meet your organization’s needs.
Published in the September 2009 issue of Microsoft TechNet Magazine.
Tags: Active Directory, Publications, TechNet Magazine
Posted in Publications | 2 Comments »
Posted by John Policelli on August 13th, 2009
Back in May of 2008, I posted an entry on my blog regarding the built-in automated metadata cleanup in Windows Server 2008. Microsoft added similar content to its Windows Server 2008 TechNet library.
Here are some links:
Tags: Active Directory, Metadata Cleanup, Recovery
Posted in AD DS | No Comments »
Posted by John Policelli on August 13th, 2009
I recently prepared an existing Windows Server 2003 forest for Windows Server 2008 and started to see an error reported in DCDiag. When I did some research on the error I was seeing in DCDiag, I found that it was a known issue that I could ignore.
Read the rest of this entry »
Tags: Active Directory, ADPrep, RODCs, Windows Server 2008
Posted in AD DS | No Comments »
Posted by John Policelli on July 30th, 2009
You’ve probably heard that Windows Server 2008 R2 was released to manufacturing (RTM) on July 22nd. One of the major changes in Windows Server 2008 R2 it is the first Windows operating system to be offered for only 64-bit processors. So what if you need to prepare an existing Active Directory Domain Services forest/domain for Windows Server 2008 R2, and your existing servers run 32-bit versions of Windows Server? You may think that you’re SOL, but Microsoft planned ahead on this one.
Read the rest of this entry »
Tags: Active Directory, ADPrep, ADPrep32, Windows Server 2008 R2
Posted in AD DS | 1 Comment »
Posted by John Policelli on July 27th, 2009
Mohammad Akif, National Security and Privacy Lead at Microsoft Canada, posted a blog on the Canadian IT Professionals blog announcing two critical security bulletins that were recently released. Here’s a snippet from the post:
Read the rest of this entry »
Tags: Security Bulletins, Security Risk
Posted in Misc | No Comments »
Posted by John Policelli on July 14th, 2009
Windows Server 2008 R2 includes a new server role, called Active Directory Web Services (ADWS), which is a prerequisite to use the Active Directory Module for Windows PowerShell and the Active Directory Administrative Center. Until recently, you were unable to use the Active Directory Module for Windows PowerShell and the Active Directory Administrative Center unless you were managing a Windows Server 2008 R2 machine. However, Microsoft released the Active Directory Management Gateway Service (ADWGS) in early June to extend this functionality to Windows Server 2008 SP1 (and later versions) and Windows Server 2003 SP2 (and later versions).
Read the rest of this entry »
Tags: Active Directory, AD LDS, ADMGS, ADWS
Posted in AD DS, AD LDS | 1 Comment »
Posted by John Policelli on July 14th, 2009
The Essential Business Server (EBS) team released the Microsoft IT Environment Health Scanner earlier this month. Active Directory health is one of those things that you cannot ignore. Let’s face it, Active Directory is the glue that ties virtually all Microsoft, as well as a significant number of third-party, products and technologies together. Having a good handle on your Active Directory health is a necessity.
Read the rest of this entry »
Tags: Active Directory, Microsoft Downloads, Tools
Posted in AD DS | No Comments »
Posted by John Policelli on June 24th, 2009
Does this sound familiar…you need to determine the port requirements for Active Directory and you find yourself having to refer to multiple KB articles. Well I have found myself in this situation many times, and I am happy to report that Microsoft has published a document that covers all Active Directory components (i.e. Replication, Trusts, GCs, RODCs, DNS, User and Computer Authentication, Group Policy, and Active Directory Web Services). I personally requested this whitepaper from MS, and helped the MS documentation team create it. The document can be found here: http://technet.microsoft.com/en-us/library/dd772723(WS.10).aspx.
Tags: Active Directory Web Services, DNS, GCs, Group Policy, Replication, RODCs, Trusts, User and Computer Authentication, Windows Server 2008
Posted in Publications | No Comments »
Posted by John Policelli on June 17th, 2009
In case you haven’t heard, Microsoft released security bulletin MS09-018 to address vulnerabilities in Active Directory and Active Directory Application Mode (ADAM). It is important to note that this vulnerability DOES NOT apply to Active Directory Domain Services (AD DS) or Active Directory Lightweight Directory Services (AD LDS) in Windows Server 2008.
Read the rest of this entry »
Tags: Active Directory, AD LDS, ADAM, Security Risk
Posted in AD DS | No Comments »
Posted by John Policelli on June 9th, 2009

In an ideal world, users are directed to the appropriate domain controller for Active Directory authentication, but this is not necessarily what happens in most organizations due to IP subnet information not being properly defined in Active Directory. This article presents a solution to ensure users locate the appropriate DC for authentication—a catch-all subnet to catch the authentication from clients on subnets are not defined in Active Directory.
Published in the June 2009 issue of Microsoft TechNet Magazine.
Tags: Active Directory, Publications, TechNet Magazine
Posted in Publications | No Comments »
Posted by John Policelli on June 9th, 2009

If your organization has multiple Active Directory forests, you need to manage multiple Active Directory schemas and ensure consistency between schemas. Check out our step-by-step guide to comparing and synchronizing Active Directory schemas in multi-forest environments.
Published in the April 2009 issue of Microsoft TechNet Magazine.
Tags: Active Directory, Publications, TechNet Magazine
Posted in Publications | No Comments »
Posted by John Policelli on June 9th, 2009

In conjunction with Pearson Education, Microsoft Subnet is giving away 15 copies of the hot title "Microsoft Active Directory Domain Services 2008 How-To" by John Policelli and published by Sams (a $39.99 value). Deadline for entries is June 30, 2009.
How to enter to win:
Read the rest of this entry »
Tags: Active Directory, Microsoft Subnet, Sams Publishing
Posted in Publications | No Comments »
Posted by John Policelli on May 21st, 2009
I have been asked to blog for Network World’s Microsoft Subnet community. The Network World blog I will be posting on is called Microsoft Identity and AD, and can be found here.
I added my first post on this blog, which is titled Introducing the New Active Directory Domain Services in Windows Server 2008 R2.
Here’s an excerpt from the post:
Windows Server 2008 introduced the most significant changes to Active Directory Domain Services (AD DS) since its inaugural release in Windows 2000 Server. Microsoft has continued along this path with Windows Server 2008 R2, making it the most noteworthy interim release of Windows Server.
AD DS in Windows Server 2008 R2 includes a number of important new features, including:
- Active Directory Recycle Bin
- Active Directory Module for Windows PowerShell
- Active Directory Administrative Center
- Active Directory Best Practices Analyzer
- Active Directory Web Services
- Authentication Mechanism Assurance
- Offline Domain Join
-
Managed Service Accounts
Let’s take a closer look at each of these new features
The rest the post can be read here: http://www.networkworld.com/community/node/42051.
Tags: Active Directory, Microsoft Subnet, Network World, Windows Server 2008 R2
Posted in Publications | No Comments »
Posted by John Policelli on May 12th, 2009
Windows Server 2008 R2 includes an Active Directory Module for Windows PowerShell. This new feature enables you to perform Active Directory administrative tasks by using PowerShell.
The following is a first look at the Active Directory Module for Windows PowerShell that is included with the Windows Server 2008 R2 Release Candidate.
Read the rest of this entry »
Tags: Active Directory, Beta Release, Windows Server 2008 R2, Windows Server 2008 R2 RC
Posted in AD DS | No Comments »
Posted by John Policelli on May 9th, 2009
There is a great YouTube video on the progression of information technology. It’s worth a look…http://www.youtube.com/watch?v=cL9Wu2kWwSY.
Posted in Misc | No Comments »
Posted by John Policelli on May 8th, 2009
In Windows Server 2008 R2, you can now roll back (lower) the domain functional level (DFL) and forest functional level (FFL). There are a couple of conditions and limitations to this new functionality, which I discuss below.
Read the rest of this entry »
Tags: Active Directory, Functional Levels, Windows Server 2008 R2, Windows Server 2008 R2 RC
Posted in AD DS | 1 Comment »
Posted by John Policelli on May 1st, 2009
The Active Directory Documentation Team has pointed out what “I” consider as a vulnerability with the built-in Active Directory Account Operators group, which applies to Domain Controllers. Under certain conditions, which are very common, the Account Operators group retains the Full Control permission on the computer object for a domain controller. As you could imagine, this is not desired in almost every case.
Read the rest of this entry »
Tags: Account Operators, Active Directory, Security Risk
Posted in AD DS | No Comments »
Posted by John Policelli on April 30th, 2009
Microsoft has a website called YouShapeIT, which I’ve been featured in this month.
The YouShapeIT TechNet website includes a significant amount of product information, presentations, podcasts, and resources for the theme of the month. For this month, the theme is Windows Server with a focus on Windows Server 2008 and Windows Server 2008 R2 (Beta).
I did an interview for YouShapeIT. The transcript and the MP3 audio file of the interview can be downloaded from http://www.microsoft.com/youshapeit/technet/Podcasts/2009-05/interview_johnpolicelli.aspx
Tags: Microsoft Interview, TechNet, Windows Server 2008, Windows Server 2008 R2, YouShapeIT
Posted in Publications | No Comments »
Posted by John Policelli on April 30th, 2009
Discover the most recent Active Directory Domain Services user interface improvements.
Read the rest of this entry »
Tags: Active Directory, EIT Articles, Windows Server 2008
Posted in Publications | No Comments »
Posted by John Policelli on April 28th, 2009
My second book, Active Directory Domain Services 2008 How-To, is nearing publication. Below are some details on this publication:
Specifics:
- Author: John Policelli
- Published May 18, 2009 by Sams.
- Copyright 2009
- Dimensions 5-3/8 X 8-1/4
- Pages: 528
- Edition: 1st.
- ISBN-10: 0-672-33045-8
- ISBN-13: 978-0-672-33045-2
Read the rest of this entry »
Tags: Active Directory, Books, How-to, Sams Publishing, Windows Server 2008
Posted in Publications | No Comments »
Posted by John Policelli on April 28th, 2009
Microsoft has expanded their Windows Server 2008 Active Directory Domain Services (AD DS) Planning and Architecture collection to included AD DS in the perimeter network. More specifically, the new guide covers the following:
- Determining whether AD DS is appropriate for your perimeter network
- The various models for deploying AD DS in perimeter networks
- Planning and deploying read-only domain controllers (RODCs) in perimeter networks
The guide can be downloaded by going to http://technet.microsoft.com/en-us/library/dd728034.aspx.
Tags: Active Directory, DMZs, Perimeter Network, RODCs, Windows Server 2008
Posted in AD DS | No Comments »
Posted by John Policelli on April 20th, 2009
Have you ever been in a situation where you needed the Ldap-Display-Name of an Active Directory attribute or class, but all you had was the CN? I have found myself in this scenario many times. Virtually every time, I had to use multiple sources to determine the Ldap-Display-Name of the attribute or class, which was inefficient to say the least. I finally got fed up and developed a reusable process so that I can streamline the resolution of CN to Ldap-Display-Name for Active Directory attributes and classes.
Read the rest of this entry »
Tags: Active Directory, Schema, Scripting
Posted in AD DS | No Comments »
Posted by John Policelli on April 17th, 2009
International Authority in Windows Technologies, Widely Acknowledged Networking Expert, Best-selling Author and Certification Exam Contributor, Microsoft Most Valuable Professional.
This interview was subsequently featured on a number of websites, including:
Read the rest of this entry »
Tags: Active Directory, Publications, Windows Server 2008, Windows Server 2008 R2
Posted in Publications | No Comments »
Posted by John Policelli on April 17th, 2009
I ran across a post on the Ask the Directory Services Team blog which is an important read for anyone who manages Active Directory.
The MS Directory Services team has found that Conficker infected computers are throwing bad password attempts, as many as 10,000 per minute from multiple clients, which in turn causes LSASS to consume a lot of CPU time on DCs.
The full post can be read by going to http://blogs.technet.com/askds/archive/2009/04/16/conficker-causes-lsass-to-consume-cpu-time-on-domain-controllers.aspx.
Tags: Conficker, Securing Active Directory
Posted in AD DS | No Comments »
Posted by John Policelli on April 8th, 2009
This new feature in Windows Server 2008 allows you to start, stop, and restart Active Directory Domain Services on a domain controller, thus facilitating more streamlined operations for performing offline tasks on a domain controller.
Read the rest of this entry »
Tags: Active Directory, Database Mounting, EIT Articles, Windows Server 2008
Posted in Publications | No Comments »
Posted by John Policelli on April 1st, 2009
I found out this morning that I was awarded the Microsoft Most Valuable Professional (MVP) designation for 2009. This is the second year that I have been designated as a Microsoft MVP in the Directory Services expertise. It’s truly humbling!
Below is an extract of the note that I got from the MVP program:
Read the rest of this entry »
Tags: MVP
Posted in Publications | No Comments »
Posted by John Policelli on March 25th, 2009
Recovery processes for Active Directory Domain Service and Active Directory Lightweight Directory Services have been revamped in Windows Server 2008. Major new feature include point-in-time snapshots and stored data database mounting.
To read the article, please go to http://www.enterpriseitplanet.com/networking/features/article.php/3812086.
Tags: Active Directory, Database Mounting, EIT Articles, Windows Server 2008
Posted in Publications | No Comments »
Posted by John Policelli on March 25th, 2009
The Directory Services Restore Mode (DSRM) account is used to log on to a domain controller in Directory Services Restore Mode to perform maintenance and recovery tasks. This account is often forgotten by most AD administrators, which results in a significant security risk. If exploited, this security risk can cause high impact.
I have ran Active Directory security assessments for a number of small, medium, and large sized companies over the years. In almost every case, I have identified the DSRM account as a risk, because it was not being secured adequately. I felt compelled to use this post to emphasize the importance of securing the DSRM account.
This is not a post that describes how-to change the password on a DSRM account; there’s thousands of such articles on the web. This post aims to give you a thorough understanding of the risks associated with not properly securing DSRM accounts, the impact of exploited DSRM accounts, and my recommendations to secure DSRM accounts.
Read the rest of this entry »
Tags: Active Directory, Securing Active Directory
Posted in AD DS | 3 Comments »
Posted by John Policelli on March 24th, 2009
Support for Windows Server 2003 Service Pack 1 ends on April 14th, 2009 (less than one month from now).
This means there will be no support for computers that do not have Service Pack 2 installed, and Microsoft will not distribute any hotfixes or security updates for computers that have Service Pack 1 installed.
Read the rest of this entry »
Tags: Service Packs; Windows Server 2003 SP1
Posted in Windows Server | No Comments »
Posted by John Policelli on February 24th, 2009
I stumbled across a GUI-based tool which provides the ability to manage fine-grained password and account lockout policies. I couldn’t help install the tool to take a closer look. I have to admit that this simplistic tool does a much better job than the native tools at managing fine-grained password policies.
The tool is called Specops Password Policy BASIC and is available from Special Operations Software. It can be downloaded here.
For a detailed look at using the native tools for managing fine-grained password policies, see my posts Fine-Grained Password Policies in Windows Server 2008 and Manage Shadow Groups in Windows Server 2008.
Tags: Active Directory, Fine-Grained Password Policies, Windows Server 2008
Posted in AD DS | No Comments »
Posted by John Policelli on February 24th, 2009
Windows Server 2008 R2 includes a Best Practice Analyzer (BPA) for a limited number of server roles, including DNS Server.
The following is a first look at the DNS Server Best Practice Analyzer (DNS BPA) that is included with the Windows Server 2008 R2 Beta.
Read the rest of this entry »
Tags: Best Practice Analyzer, Beta Release, DNS
Posted in Name Resolution | No Comments »
Posted by John Policelli on February 23rd, 2009
Tim Springston, from Microsoft’s Customer Services and Support division (formerly Product Support Services), published a great explanation on titled “Gauging Size Differences in AD Databases”. This is a good read for those who have wondered, or have been asked, why the size of the AD database differs between domain controllers.
Tiim’s blog entry can be found here.
Tags: Active Directory
Posted in AD DS | No Comments »
Posted by John Policelli on February 19th, 2009
Microsoft has released a new feature for Windows Server 2008 that allows you to synchronize the Directory Services Restore Mode (DSRM) password with the password of a domain user account.
Read the rest of this entry »
Tags: Active Directory, DS Command-Line Tools, DSRM
Posted in AD DS | No Comments »
Posted by John Policelli on February 18th, 2009
Discover how read-only domain controllers provide improved security, faster logon times and an expanded set of administrative roles.
To read the article, please go to http://www.enterpriseitplanet.com/networking/features/article.php/3803831
Tags: Active Directory, Database Mounting, EIT Articles, Windows Server 2008
Posted in Publications | No Comments »
Posted by John Policelli on February 3rd, 2009
With the advent of Windows Server 2008, password management made a substantial leap. Learn how to improve security and craft policies for just about any situation.
To read the article, please go to http://www.enterpriseitplanet.com/networking/features/article.php/3800436.
Tags: Active Directory, Database Mounting, EIT Articles, Windows Server 2008
Posted in Publications | No Comments »
Posted by John Policelli on February 3rd, 2009
Microsoft has created a new team that is responsible for automating the steps in KB articles and Windows Error Reporting (WER) solutions so that you can click a button and have the issue resolved.
Read the rest of this entry »
Tags: Fit It for Me
Posted in Misc | No Comments »
Posted by John Policelli on January 28th, 2009
The Windows Server 2008 R2 Beta includes a new Active Directory data management tool, called the Active Directory Administrative Center (ADAC). ADAC is a replacement of the Active Directory Users and Computers (ADUC) console. You can find more information on ADAC at my A First Look at the Active Directory Administrative Center in the Windows Server 2008 R2 Beta post.
I’ve been using ADAC as I evaluate the Windows Server 2008 R2 Beta, and what follows is a list of user interface enhancements and changes between ADAC and ADUC.
Read the rest of this entry »
Tags: Active Directory, ADAC, Beta Release, Windows Server 2008 R2
Posted in AD DS | No Comments »
Posted by John Policelli on January 27th, 2009
I stumbled across a blog post, which lists a number of Windows 7 hotkeys. The blog post can be read here.
Tags: Beta Release, Windows 7
Posted in Windows 7 | No Comments »
Posted by John Policelli on January 23rd, 2009
Windows Server 2008 R2 includes a new Recycling Bin feature for Active Directory Domain Services (AD DS) and Active Directory Lightweight Directory Services (AD LDS).
The following is a first look at the Active Directory Recycling Bin that is included with the Windows Server 2008 R2 Beta.
NOTE: Updated May 8, 2009 to include information for the RC build of Windows Server 2008 R2.
Read the rest of this entry »
Tags: Active Directory, Beta Release, Windows Server 2008 R2
Posted in AD DS | 1 Comment »
Posted by John Policelli on January 22nd, 2009
Windows Server 2008 R2 includes a Best Practice Analyzer (BPA) for a limited number of server roles, including Active Directory Domain Services.
The following is a first look at the Active Directory Domain Services Best Practice Analyzer (AD DS BPA) that is included with the Windows Server 2008 R2 Beta.
Read the rest of this entry »
Tags: Active Directory, Active Directory Best Practice Analyzer, AD DS BPA, Best Practice Analyzer, Beta Release, BPA, Windows Server 2008 R2
Posted in AD DS | 1 Comment »
Posted by John Policelli on January 22nd, 2009
Learn how the expanded auditing options offer new levels of insight, granularity and control.
To read the article, please go to http://www.enterpriseitplanet.com/networking/features/article.php/3797931
Tags: Active Directory, Database Mounting, EIT Articles, Windows Server 2008
Posted in Publications | No Comments »
Posted by John Policelli on January 22nd, 2009
Microsoft has released a new Active Directory data management tool in Windows Server 2008 R2, which is now called the Active Directory Administrative Center.
What follows is an initial look at the new Active Directory Administrative Center (ADAC).
Read the rest of this entry »
Tags: Active Directory, Beta Release, Windows Server 2008 R2
Posted in AD DS | 6 Comments »
Posted by John Policelli on January 22nd, 2009
The following is a step-by-step guide to installing Active Directory Domain Services in the Windows Server 2008 R2 Beta.
Read the rest of this entry »
Tags: Active Directory, Beta Release, Windows Server 2008 R2
Posted in AD DS | No Comments »
Posted by John Policelli on January 19th, 2009

I am profiled in the Canadian MVP Insider for the month of January.
The article is posted on the Canadian IT Pro Connection’s blog and can be read here: http://blogs.technet.com/canitpro/archive/2009/01/16/mvp-profile-john-policelli.aspx
Tags: MVP
Posted in Publications | No Comments »
Posted by John Policelli on January 15th, 2009
There are a number of new Active Directory Domain Services features in Windows Server 2008. These new features improve auditing, security, and the management of Active Directory Domain Services and show Microsoft’s commitment to evolving Active Directory Domain Services. The following is an overview of the new Active Directory Domain Services features that are in Windows Server 2008.
To read the article, please go to http://www.enterpriseitplanet.com/networking/features/article.php/3796561
Tags: Active Directory, Database Mounting, EIT Articles, Windows Server 2008
Posted in Publications | No Comments »
Posted by John Policelli on January 15th, 2009
The following is a step-by-step guide to installing the Windows Server 2008 R2 Beta on VMWare Workstation 6.5. The installation of Windows Server 2008 R2 is very similar to the Windows 7 installation.
Read the rest of this entry »
Tags: Beta Release, Windows Server 2008 R2
Posted in Windows Server | No Comments »
Posted by John Policelli on January 15th, 2009
The following is a step-by-step guide to installing the Windows 7 Beta on Microsoft Virtual PC. The installation of Windows 7 is very similar to the Windows Vista installation.
Read the rest of this entry »
Tags: Beta Release, Windows 7
Posted in Windows 7 | No Comments »
Posted by John Policelli on January 15th, 2009
As you may have heard already, Microsoft released the Beta for Windows Server 2008 R2. This is the first operating system platform that will be 64-bit only.
Read the rest of this entry »
Tags: Windows Server 2008 R2
Posted in Windows Server | No Comments »
Posted by John Policelli on January 11th, 2009
Microsoft’s Windows Server 2008 R2 Resources site contains a number of useful guides, presentations, and links to newsgroups and forums.
I stumbled across a presentation titled “Windows Server 2008 R2 Active Directory Updates” that gives a good overview on the changes to AD DS in Windows Server 2008 R2.
Tags: Active Directory, Windows Server 2008 R2
Posted in AD DS | No Comments »
Posted by John Policelli on January 9th, 2009
I’ve run across a few newsgroup posts lately where people have pointed out they cannot find Replmon.exe on Windows Server 2008. I finally got around to checking for myself and was surprised to see the tool is really gone. Read the rest of this entry »
Tags: Active Directory, Resource Kit Tools, Windows Server 2008
Posted in AD DS | No Comments »