Migrating files from an Active Directory Domain to another, unblocking the files ?

Hi everyone

Today I will discuss a small tip used when you migrate a file server to another domain.

The goal is to prevent all user to see the warning that file can be dangerous, as the client OS detect and treat that old domain as a internet domain, not an internal’s domain when the migration is finished.

An easy way is with Unblock-File commandlet from powershell.

Naviguate into your server, and issue that powershell command:

Get-ChildItem c:\path -recurse | Unblock-File

unlockfiles

That will prevent that dialog from all the files:

1425.FilePropertiesUnblock

 

Enjoy the small tip

 

 

Advertisements
Posted in microsoft | Leave a comment

Active Directory: Reset the clock on an expired password for an account

Hi everyone

Ever wondered how to re-activate an old Active Directory account and prevent a password change directly ? Like on a return paternity / maternity leave.

It’s really easy to do or script that way 🙂

pwdLastSet attribute is used to calculate the password age.

The value is protected, and the only value you can set there is 0 or -1.

The value you look for is -1, the system will put the pwdLastSet to the current date/time. Thus the 90 days, or any defined time period, will start again from the start.

0 would do the opposite, it would expire the password right now.

You set it to 0, manually or with a script, you then set it to -1 and uncheck the Never Expire option after for the account.

An example when used:

Before

QRZy3

After

DooAx

It’s that simple 🙂

 

Thanks

 

 

Posted in microsoft | Leave a comment

OneDrive on Local Account ?

Hi everyone

Today I will share a marvelous tool to use OneDrive / SkyDrive if you use a local account, or an domain account.

The tool is named syncDriver.

3-6-2018 1-32-15 PM

A side note the login option no longer work in the application, but an alternative login work as it directly open onedrive’s website.

After that you can map a letter to the root folder you defined.

The official website is dead, as such I offer a link there to the wayback machine to download the tool.

wayback link

or home hosted

Posted in microsoft | Leave a comment

Windows Server 2016: Shared Access Database Getting Corrupt on SMB

Hi everyone

Today less and less people use msaccess, but some still, and some still use multiuser database.

In such case after Windows 2008 R2 it can cause problem with new layer of SMB version, that allow oplock to be used, thus it can cause bug from the Access GUI, or even corruption of the data file.

To disable, on the server :

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MRXSmb\Parameters\

OplocksDisabled REG_DWORD 0 or 1
Default: 0 (not disabled)

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters

EnableOplocks REG_DWORD 0 or 1
Default: 1 (enabled)

To be disabled at 100% let’s do the client’s computers too. Easily with a GPO

 

Posted in microsoft | Leave a comment

Exchange 2016 – You don’t have permission to perform this action (OWA)

Hi

If you receive the error You don’t have permission to perform this action while any user try to send an email, then you are in big trouble..

2-5-2018 10-18-14 AM

Just kidding.

Some FAQ tell to go check the server DNS setting, to be sure it’s only internal’s DNS server listed there, but I found another cause for that problem.

It can happen when you do a CU (Cummulative Update) and the service get stuck in a Inactive state. No windows event log are logged too when such happen and your receive connector can still connect on port 25, but the server just look to do nothing.

To validate please run that powershell commandlet;

Get-ServerComponentState

You can see some component in inactive state;

2-5-2018 3-54-02 PM

At this point you can put each component active, by issuing that command;

Set-ServerComponentState -Identity ServerName -Component HubTransport -State Active -Requester Functional

After all component are active it should be listed more like that;

2-5-2018 3-54-27 PM

Thanks

 

 

 

Posted in microsoft | Leave a comment

Quick tip to change the default search engine from Internet Explorer, bing to google

Hi everyone

 

Today I will show a small tip to change bing to google for your new tab in Internet Explorer.

1-3-2018 9-16-04 AM

First you go select Manage add-ons

1-3-2018 9-16-18 AM

You click Find more search provider

1-3-2018 9-16-37 AM

You select Add on Google Search

1-3-2018 9-16-50 AM

You click Add again

1-3-2018 9-16-58 AM

In the add-ons’s windows, make sure the Default is set to the one you want

1-3-2018 9-18-20 AM

 

 

Now you should be ok to change the search provider !

Posted in microsoft | Leave a comment

Meltdown / Spectre quick check and update status

A quick way to see if you are at risk for CVE-2017-5754 (Meltdown) and CVE-2017-5715 (Spectre)

PS > Install-Module SpeculationControl

PS > Get-SpeculationControlSettings

If you see those red line you are at risk;

Hardware support for branch target injection mitigation is present: False

Windows OS support for branch target injection mitigation is present: False

Windows OS support for branch target injection mitigation is enabled: False

Windows OS support for kernel VA shadow is present: False

Windows OS support for kernel VA shadow is enabled: False

 

Now on another note, the patch KB4056892 (OS Build 16299.192) break a lot of Antivirus.

If automatic updates are enabled, the January 2018 Windows security update will be offered to the devices running supported anti-virus (AV) applications. Updates can be installed in any order.

A quick and dirty tip, if the install is installed is to add that registry key for disabling the fix for the time your Antivirus get updated;

Contact your Anti-Virus AV to confirm that their software is compatible and have set the following  REGKEY on the machine

Key=”HKEY_LOCAL_MACHINE”Subkey=”SOFTWARE\Microsoft\Windows\CurrentVersion\QualityCompat”
Value Name=”cadca5fe-87d3-4b96-b7fb-a231484277cc”
Type=”REG_DWORD”
Data=”0x00000000”

Reference:

ADV180002 | Guidance to mitigate speculative execution side-channel vulnerabilities

January 3, 2018—KB4056892 (OS Build 16299.192)

 

 

Posted in microsoft | Leave a comment