
David Tesar:
I hope this post will act as a good reference point to be able to quickly understand the good and bad about new AD auditing enhancements and then enable you to dive deeper at will using the links in this article.
There’s nothing more exciting than auditing right? Well, check this out and hopefully it will spark some interest.
continue at source

Aniban Chakladar:
Recently I tried running Virtual Server 2005 R2 on Vista Ultimate edition, the program installed ok but I was unable to start the Virtual Server Administration site. It prompted me Open or Save vswebapp.exe
In order to fix the same you need to do the following:
· Add IIS features on an existing Windows Vista OS
· Add an IIS handler mapping so it will treat EXE files as CGI
continue at source

Microsoft Exchange Server 2007 Service Pack 1 (SP1) has been designed specifically to help meet the challenges of any business and the needs of all the different groups with a stake in the messaging system. Exchange Server 2007 SP1 is a mission-critical communications tool that enables employees to be more productive and access their information anywhere and anytime while providing a messaging system that enables rich, efficient access to e-mail, calendar items, voice mail, and contacts. For the administrator, Exchange Server 2007 SP1 provides advanced protection options against e-mail security threats, such as spam and viruses, as well as the tools to help manage internal compliance and high availability needs.
Download Exchange Server 2007 Service Pack 1

Today i was browsing the MS Learning website and noticed that Microsoft now offers a new down loadable transcript in both XPS and PDF format. Because i don't have the XPS reader installed on my workstation i was looking for the PDF version. Have a look at the following screenshot ;)

Wow ! That's a huge difference, when i want to download the file in XPS it says: "approximately a 500KB file" and when i want to download the PDF version it says:"Approximately a 10MB file"
I downloaded the file in PDF and it was 248 KB , I wonder who has a PDF of 10 MB?

Microsoft is set to release its capacity planning tool. This will help users plan deployment of products like Exchange and SharePoint.
The company said that the final beta of System Center Capacity Planner (SCCP) 2007 was now available on its website and said the final code will be completed by year-end. The SCCP 2007 "release candidate" is now publicly available. It includes capabilities for planning new server roles in Exchange 2007, selecting Exchange cluster configurations, factoring disk IO background load for mailbox servers and modeling for 64-bit processors.
SCCP 2007 will offer an Exchange 2007 model out of the box. Microsoft plans to follow with models for SharePoint Server 2007, SharePoint Services 3.0, and System Center Operations Manager 2007. The company did not offer a road map for the release of those models, but beta versions of SharePoint Server 2007 and SharePoint Services 3.0 are available at Microsoft Connect.

You are invited to take beta exam 70-401: TS: Microsoft System Center Configuration Manager 2007, Configuring. If you pass the beta exam, the exam credit will be added to your transcript and you will not need to take the exam in its released form.
By participating in beta exams, you have the opportunity to provide the Microsoft Certification program with feedback about exam content, which is integral to development of exams in their released version. We depend on the contributions of experienced IT professionals and developers as we continually improve exam content and maintain the value of Microsoft certifications.
71-401: TS: Microsoft System Center Configuration Manager 2007, Configuring counts as credit towards the following certification(s).
• Microsoft Certified Technology Specialist (MCTS): System Center Configuration Manager 2007, Configuration (
continue at source)

Windows Server 2008 holds some major key benefits in Terminal Services technology. Some of these are discussed in various articles on my site (see Related Articles section below). One of these features is Display Data Prioritization.
Display Data Prioritization in Windows Server 2008 Terminal Services allows for automatic control over the virtual channel traffic that is passed between the client (RDP 6.0) and the server (running Windows Server 2008). This enables better performance and user experience because display, keyboard typing, and mouse movement data is given a higher priority over other virtual channel traffic, such as printing, clipboard operations or file transfers. This prioritization is designed to ensure that your screen performance (user experience) is not affected by bandwidth intensive actions, such as large print jobs. (
continue at source)

If you take a look around your hard drive, you probably have noticed that a good number of operating system files hang out in the root directory of the boot drive. If you take a closer look at those files, you may notice a theme: boot.ini, NTLDR, and NTDETECT.COM are critical boot files, and hiberfil.sys is the hibernation file. These are all files that are involved in the crucial first stages of booting the operating system or, in the case of hiberfil.sys, resuming from hibernation, and they have to go into the root of the boot drive. Why can't you move them somewhere else?
My colleague Adrian Oney explained: in order to read the boot files off the disk, you need the file system driver, but the file system driver is on the disk, which you can't read until you've loaded the file system driver. Oh no, Catch-22!
The vicious cycle is broken by having a miniature file system driver built into the critical boot files. This miniature driver knows just barely enough to locate files in the root directory and load them into memory. Those files can, in turn, get the operating system off the ground, at which point the real file system driver can take over and look for files in much fancier places like subdirectories.(
continue at source)

Ever since Microsoft released Windows 2000 way back when, the options for delegating certain tasks have been available. The concepts of delegation can be a bit confusing, but in the core of what the delegation provides is essential to an efficient network. Without the use of delegations, you are stuck with only default groups that grant administrative privileges over certain tasks and objects. For example, without delegation over user and group accounts, a user must be placed in the Account Operators group to be given the ability to just manage users, groups, and computers in the domain. Of course, a user could also be placed in the Domain Admins or Enterprise Admins groups, but this would grant them far too many privileges than just managing accounts. In a similar manner, placing users in the Account Operators group also grants them too many privileges, such as modifying not only user accounts, but all administrative accounts. Delegation solves this issue, by allowing very granular delegations to objects and tasks throughout the enterprise.(
continue at source)

The Configuration Manager Documentation Library has been updated. The Documentation Library is the primary documentation for Configuration Manager 2007. The November update contains new material and fixes to documentation problems reported after Configuration Manager 2007 was released. Refer to “What's New in the Configuration Manager Documentation Library for November 2007” for a list of topics that are new or updated in this version. The updated smsv4.chm will have a date of 11/06/2007 and will overwrite the existing smsv4.chm in %systemroot%\help. This information is also available online in the
TechCenter Library.
Feature Bullet Summary:
The Documentation Library includes the following types of information:
• Setup and upgrade instructions.
• Information about new features and backwards compatibility.
• Conceptual descriptions about the technologies and features in Configuration Manager 2007.
• Procedural topics describing how to use the various features in Configuration Manager 2007
• Step-by-step topics to guide you through sample deployments
• Scenario topics to provide examples of how the technology might be used
• Security and privacy information about the features
• Troubleshooting information
Download the System Center Configuration Manager 2007 Documentation Library

Chris Wolf of Microsoft Certified Professional Magazine explains how you can tell what hypervisor type a VM is running on when you connect remotely to a VM.
The easiest way that I have found to profile a VM thus far is by querying its virtual MAC address. For example by doing a ipconfig /all in a command prompt.
To save you the step of looking up the vendor OUI prefixes, here are the OUIs of the most popular virtualization platforms:
* Microsoft: 00-03-FF
* SWsoft: 00-18-51
* Virtual Iron: 00-0F-4B
* VMware: 00-0C-29 and 00-50-56
* XenSource: 00-16-3E

Cache is used to reduce the performance impact when accessing data that resides on slower storage media. Without it your PC would crawl along and become nearly unusable. If data or code pages for a file reside on the hard disk, it can take the system 10 milliseconds to access the page. If that same page resides in physical RAM, it can take the system 10 nanoseconds to access the page. Access to physical RAM is about 1 million times faster than to a hard drive. It would be great if we could load up all the contents of the hard drive into RAM, but that scenario is cost prohibitive and dangerous. Hard disk space is far less costly and is non-volatile (the data is persistent even when disconnected from a power source).
Since we are limited with how much RAM we can stick in a box, we have to make the most of it. We have to share this crucial physical resource with all running processes, the kernel and the file system cache. You can read more about how this works
here

The Microsoft Exchange Server 2003 MSIT Basic Configuration Pack is designed to be used for managing the configuration of Exchange 2003 servers. This configuration pack defines recommended configurations based on a limited number of settings affecting the configuration of Exchange 2003 servers in the Microsoft IT environment. More extensive configuration items and settings can be obtained by downloading the Microsoft Exchange Server 2003 MSIT Intermediate and Comprehensive Configuration Packs. It is recommended that users begin by evaluating their configuration against the Basic configuration pack, and then progress to the Intermediate and Comprehensive configuration packs as desired configurations are verified.
Download the Microsoft Exchange Server 2003 MSIT Basic Configuration Pack for Configuration Manager 2007

The Office Communications Server 2007 QoE Monitoring Server Management Pack for MOM 2005 monitors the audio and video quality for Office Communications Server 2007 Server Enterprise Voice deployment. Alerts are fired when audio and video quality degrades based on network degradation such as delay and packet loss.
Feature Bullet Summary:
The management pack provides:
• Automatic notifications of audio and video quality degradation
• Automatic notifications of media connectivity failures
• Health monitoring by locations, A/V Conferencing Servers, and Mediation Servers
• Centralized management
More information and download

We are often asked about the centralized management of Internet Explorer configuration options for which there are no Group Policy settings included with the default IE GPO templates. One of the settings that we are asked about the most is the "Launching Applications and Unsafe Files" setting, since that setting is not defined in the IE Administrative Policy settings file (inetres.adm).
There are a number of different ways that you can manage this setting in an enterprise. The first is to use the Internet Explorer Maintenance Policies, which import from a source system's registry. The problem with this approach is that there is no granularity in what settings you are importing - it's an all or nothing solution, and you wind up deploying the entire collection of IE settings that are defined on the source system.(
continue at source)

When you protect a Microsoft System Center Configuration Manager 2007 site system, only clients in that boundary can access the distribution point or state migration point role on that site system. You protect these site roles to help control network utilization.
However, before protecting any distribution points, you should consider the effect on software distribution. Careful configuration of protected distribution will preserve network bandwidth, but haphazard configuration of protected distribution points might prevent clients from accessing crucial content, including software updates and operating system deployment packages.
Continue reading
here
Stefan Schörling has published a nice guide:
"I wrote a brief introduction on Desired Configuration Management (DCM), the article contains information about what DCM is and some guides for importing configuration packs and assigning them. I hope this will bring some light to thoose of you who want to get familiar with DCM."
You can read my article here:
Introduction-to-desired-configuration-management-in-configuration-manager-2007.pdf

Windows Vista may have some compatibility and reliability issues. But it also sports some pretty cool new features like a 3D window manager and animated backgrounds (if you shell out the money for the "Ultimate" edition). One Vista feature that we'd love to see more of is SideShow, but unfortunately hardware makers have been slow to create SideShow capable devices.
In a nutshell, SideShow lets you access certain Vista features from a secondary display. For example, you can check your email without opening your laptop's lid. Or you can schedule a TV recording on Windows Media Center using your case's front-panel display. You know, if you have a laptop or PC case with an external display.
If not, you're pretty much out of luck. But maybe not for long. Microsoft has just published an
SDK for SideShow with support for Bluetooth and QVGA screens: two features that many Windows Mobile devices already have. The folks at
"the unwired" speculate this could mean a Windows Mobile SideShow application is on its way. In other words, you'd be able to fire up a program on your phone or PDA that will give you control over your desktop. Your PDA could become your favorite remote control, web browser, or email tool.
Earlier this year Microsoft announced that a Windows Mobile Sideshow program
was on its way, but we've been waiting about half a year to see anything materialize. Hopefully the SDK launch means we won't have to wait much longer.

My good friend and fellow MOM-MVP,
Pete Zerger, has some more information on a new hotfix that will solve some of the problems around RMS sizing:
"I’ve spoken with several administrators complaining of high memory utilization of the Root Management Server. It has definitely impacted hardware sizing decisions for us. MS has released what may be a fix, at least for some people."
Get the fix at:
http://support.microsoft.com/kb/943706

This kind of was mentioned by
Richard and Don, but I thought I would spell it out explicitly.
According to Jeffrey Snover, PowerShell is becoming a part of the
Common Engineering Criteria (CEC) 2009 at Microsoft. Meaning that every server product released by Microsoft in their financial year 2009 (which starts July 1, 2008) needs to ship with PowerShell support.
Of course, a product can get an exemption, and of course support can vary to something as advanced as Exchange 2007 cmdlets, or as basic as
PowerShell in SQL 2008, but nevertheless this is a huge success for PowerShell. After all, it was similar requirement for MOM report packs which made Operations Manager so ubiquitous.
According to Jeffrey, there are currently 20 Microsoft teams working on PowerShell support in their products, and then there are VMware, and Citrix, and Quest, and /n Software, and PowerGadgets, and many more vendors adding PowerShell to their stuff.

The intent of this whitepaper is to provide a framework for the evaluation of System Center Configuration Manager 2007. System Center Configuration Manager—previously known as Systems Management Server—represents a tremendous advancement over its well-regarded predecessor, now providing the control necessary to more effectively manage change in today's dynamic IT infrastructures. Manage the full deployment and update lifecycle with streamlined, policy-based automation; with enhanced insight into, and control over, assets and systems compliance; and with optimization for Windows—particularly Windows Server 2008 and Windows Vista—and extensibility to customized administration experiences and third-party applications.
This whitepaper isn't published yet on Microsoft Download, but you can crab it from the blog of
Daniel Lai.
Download the System Center Configuration Manager 2007 reviewers guide

When creating a monitor or a rule for a multi instance component you need to be very careful or else you may end up with wrong monitoring logic. The two important parts are:
1. Target the rule/monitor to the correct target type
2. Specify the correct performance object, counter, and instance name.
The main improvement in SP1 to help create properly configured rules and monitors is having the ability to tell the monitor or rule to use a particular property of the multi instanced component such as the Logical Disk name rather than hard coding it. This is possible in the with the RTM build but only by editing the MP xml or using the authoring console. Given that for each one of the components listed above the syntax is a little bit different I will provide examples for each one. (
Continue at source)

DPM 2007 System Requirements provides information that you use to ensure that the DPM server and the computers and applications it is going to protect meet network and security requirements. This topic also lists the DPM supported operating systems and the recommended hardware and software requirements.
Download the System Center Data Protection Manager 2007 System Requirements

Microsoft Forefront business security products help protect client machines, server applications, and the network edge. System Center is a family of IT management solutions that helps proactively plan, deploy, manage, and optimize your IT environment. See how Forefront and System Center products integrate with each other and with your infrastructure to put you in control of your environment.
Download the Microsoft Forefront and System Center Demonstration Toolkit

EMC Corporation, the world leader in information infrastructure solutions, today announced that EMC's flagship backup and recovery solution -- EMC(R) NetWorker(R) -- will integrate with System Center Data Protection Manager 2007 to provide customers with a feature-packed and easy-to-use data protection solution capable of supporting both Windows and non-Windows environments. In addition, EMC further adds enterprise data protection capabilities by offering tested and documented best practices for using EMC CLARiiON(R) networked storage systems with DPM 2007. These new integrations advance EMC's solution-centric approach of hardware, software and services, offering customers of all sizes information management and storage solutions optimized for their Microsoft environments.
Through integration with Microsoft Volume Shadow Copy Services, NetWorker will be able to provide backup and restore functions for System Center Data Protection Manager 2007 server with assured consistent, fast and effective recovery. Combined with current NetWorker backup support for other operating environments, this provides customers with a unified backup solution for any type of data residing on heterogeneous computing and application environments.

The Operations Manager team have released a command line tool similar to the GUI tool within the MOM 2005 reskit for Operations Manager 2007. Check out the details and download here
This MOMNetChkCMd.exe tool requires .Net Framework 2.0 but can be run independently of a Management Server.
The tool checks requirements for Agent push such as required discovery info via WMI, MSXML 6 requirement, Ports 445,139,137,135,5723 enabled, Windows Installer Service started, Remote Registry enabled, responds to ICMP ping.
Invoking MOMNetChkCMd.exe -Computername <nameofcomputer>
will perform a check against a single remote computer logging details to a .log file of the same name as the machine. The log header will contain a summary of the number of Errors, Warnings and Successes followed by details of each of the test performed and the results.
To be able to perform the check against large numbers of machines before agent deployment a text file and batch file are included. The text file to contain the list of computer NetBIOS names, and the batch file to read the list and call MOMNetChkCMd.exe against each. The log files can then be scanned for Errors as discussed in the Readme.txt file.

The release candidate of SCOM 2007 service pack 1 is available for download., This release candidate is FULLY SUPPORTED by Microsoft and is recommended to address a number of issues seen in the original release of SCOM. The release candidate is available for download at
http://connect.microsoft.com/systemcenter

Many ISA firewall admins who are currently running ISA Server 2000 or 2004 will want to know why they should upgrade to ISA Server 2006. While the upgrade from ISA Server 2000 to ISA 2004 was an easy one to understand because of the major improvements and changes made between ISA Server 2000 and ISA 2004, the changes included with ISA 2006 versus ISA 2004 are more incremental and provide a much smoother transition than the upgrade from 2000 to 2004.
Most of the new features and capabilities seen in ISA 2006 compared to 2004 are difficult for the average ISA firewall admin to see if only a superficial look at the product is taken. The user interface is the same, the networking model is same, there have been no changes in terms of how the ISA firewall performs outbound access control, and there have been no changes to the core networking and traditional firewall feature set.(
continue at source)

The System Center Configuration Manager 2007 User Assistance team has created a set of quizzes to help you assess your understanding of the dependencies and requirements for key features of Configuration Manager. These quizzes are intended to raise your level of awareness of the some of the nuances of these features before you configure and use them. They can also be used to help train other Configuration Manager administrators within your organization. Each quiz consists of 10 questions that can be answered Yes or No. Regardless of your answer, the quiz will display the correct information, and include one or more links to the corresponding related content located in the Configuration Manager 2007 Documentation Library located on the Configuration Manager TechCenter. We are testing the usefulness of this format, and ask for your feedback on the format and the content contained in each quiz. Please send feedback to SMSDOCS@Microsoft.com.
The following quizzes are available:
Configuration Manager 2007 Client Installation Quiz
Configuration Manager 2007 Client Management Quiz
Configuration Manager 2007 Client Roaming Quiz
Configuration Manager 2007 Client Site Assignment Quiz
Configuration Manager 2007 Desired Configuration Management Quiz
Configuration Manager 2007 Internet-Based Client Management Quiz
Configuration Manager 2007 Native Mode Quiz
Configuration Manager 2007 Network Access Protection Quiz
Configuration Manager 2007 Wake On LAN Quiz

Microsoft System Center Virtual Machine Manager 2007 is a server application that facilitates the centralized management of a large physical and virtual system infrastructure.
Virtual Machine Manager 2007 (VMM) consists of the VMM server, the VMM Administrator Console, the VMM library, the VMM Self-Service Portal, and virtual machine hosts.

Emulex Virtual HBA Technology is First Integrated Server Virtualization Solution With Industry-Standard NPIV Support for Windows Environments
Emulex Corporation (ELX) today announced its LightPulse(r) Virtual Host Bus Adapter (HBA) technology is now available for Microsoft System Center Virtual Machine Manager 2007. This marks the first integrated storage area network (SAN) connectivity solution with industry-standard N-Port ID Virtualization (NPIV) support for Microsoft Windows Server virtualization environments.
Emulex's LightPulse Virtual HBA technology, composed of Emulex 4Gb/s Fibre Channel HBAs supporting NPIV, enables customers to effectively 'virtualize' SAN connections so that each virtual machine has independent access to its own protected storage. In addition, Emulex LightPulse Virtual HBA technology enables administrators to leverage standard SAN management tools and best practices, such as fabric zoning and LUN mapping/masking, and, enhanced management and migration of virtual machines. It also provides the most efficient utilization of the HBAs in the server while ensuring the highest level of data protection available in the industry.

This content provides information about installing and configuring Virtual Machine Manager (VMM), with all VMM components installed on a single computer or with each VMM component installed on separate computers. This content also provides step-by-step instructions for uninstalling VMM and reinstalling VMM with a database retained from a previous installation.
Download Installing and Configuring Virtual Machine Manager 2007

This content provides the minimum and recommended system requirements for installing and running Virtual Machine Manager (VMM) in the following deployment scenarios:
• All VMM components installed on a single computer.
• Each VMM component installed on a separate computer.
Download System Center Virtual Machine Manager 2007 System Requirements

In the past, there is no HA solution for SMS database, the only thing you can do is backup for any disaster. The good news is, for System Center Configuration Manager 2007 (SCCM 2007) now has an ability to support clustered SQL Server instance. Unfortunately, the documentation for how to install SCCM 2007 with clustered SQL Server is poor. Here is a walk through for how to install SCCM on clustered SQL server.
1. Install Windows 2003 Cluster
2. Install SQL 2000/2005 Cluster
3. By default, Windows will not register SQL Server virtual name in Active Directory, for successfully installing SCCM 2007 on Clustered SQL Server, you must register it. Go to step 4
4. Run setspn.exe (you can download it from Microsoft download center:
here) utility as below:
setspn MSSQLSvc/SQLSERVER1:1433
SQLSERVER1 is your SQL Server virtual name
setspn MSSQLSvc/SQLSERVER1.contoso.com:1433
SQLSERVER1.contoso.com is FQDN for SQL Server virtual name
5. Add computer account for installing SCCM 2007 to local administrators group on every SQL cluster node.
6. Add user account for installing SCCM 2007 to local administrators group on every SQL cluster node.
7. Restart computer for installing SCCM 2007, and logon with user account for setup
8. Launch SCCM 2007 installer, conduct a normal setup.
Stefan Schörling mentioned that SQL 2000 in combination with SCCM 2007 isn't supported see also
this link, keep that in mind, thanks Stefan.

On the last day of IT Forum there was a good session about some of the new features in Windows Server 2008. Stephanie Cheung presented the Session. Although a lot of the new features of Windows Server 2008 are now known like RODC, Fine grained password policies, new cluster functionality.. there is one that did not have much attention until now; it is called
SNAPSHOT EXPOSER.
The trouble that system administrators face when they need the restore a previous version of the active directory is that they don’t know which version contains the correct objects. It would be handy to look in the backup to see which version is the correct one.
With Windows server 2008 it is now possible to do this. Here how it works:
1. First of all you have to take snapshots of your Active Directory database. This can be done with the new NTDSUTIL. There is a function in NTDSUTIL which allows you to take snapshots of the Active directory database.
(more)
DCM (Desired Configuration Manager) lets you compare you IT infrastructure configuration with standards (Compliance or Microsoft IT currently available). The compliance packs come from Brabeion (MS partnership).
To read more about DCM go here: http://www.microsoft.com/systemcenter/configmgr/evaluation/configmgmt.mspx
Additionally there is now ConfigMgr2007toolikit available (this was a must-have tool in the times of SMS 2003): http://www.microsoft.com/downloads/details.aspx?familyid=948e477e-fd3b-4a09-9015-141683c7ad5f&displaylang=en&tm
Here is a list of packs my friend Tomek pointed me to. You can find them all (+any updates + links to other then MS vendor DCM packs) in the new System Center Pack catalog: https://www.microsoft.com/technet/prodtechnol/scp/configmgr07.aspx?SCPProdID=6
(more)