Friday, December 1, 2017

Outlook 2016 to Exchange 2016 mapi connection problems.

 During my exchange 2010 to exchange 2016 migration I run in to outlook connectivity problem which made it impossible to connect.

There are hundreds of similar issues on google unfortunately none of them solved the problem until I found two solutions on separate blogs and combined them and here is my final fix:

  1. Set-MapiVirtualDirectory -identity “exchange2016\mapi (Default Web site)” -IISAuthenticationMethods NTLM
  2. this requires editing Autodiscover and EWS virtual directory using IIS server interface on the exchange 2016 server.
    Remove negotiate provider from Windows Authentication.

 

References:

  1. this is the first blog thanks to which I was able to get outlook 2016 working unfortunately only with exchange cached mode disable.
  2. this is the send blog (last post have the solution) which helped me to get outlook 2016 working on the local LAN and behind the firewall as well as with or without using exchange cached mode.
  3. In addition you need to have MAPI enabled on the exchange 2016 server which is the default but just in case here is the MS link with instructions.

Thursday, October 19, 2017

change pwdLastSet to reset user password last set in AD

 what worked for me was to change it to 0 first and then change it to -1

If set to 0 it will force user to change password on next login. (If user doesn’t have flag set to Don’t Expire Password)

If set to -1 the password change date will be set to current date and time.

 

reference:

http://ldapwiki.com/wiki/Pwd-Last-Set%20attribute

Tuesday, October 10, 2017

exchange 2010 remove users emails before specific date

If user has a lot of emails which they need to delete here is a command which can help at the server end:

 

Search-Mailbox -Identity “User Name” -SearchQuery “Received:<$(’12/31/2013′)” -DeleteContent

 

ref: https://social.technet.microsoft.com/Forums/exchange/en-US/6114adb8-7e65-46e0-b54f-704ad15ef723/command-to-delete-all-the-items-from-a-mailbox-till-a-specific-date?forum=exchange2010

Friday, October 6, 2017

exchange 2010 failed to create new GAL

error when trying to create new GAL using:

New-GlobalAddresslist “new GAL” –ConditionalCustomAttribute1 “STAFF” –IncludedRecipients “AllRecipients”

WARNING: One or more global address lists were missing from the Active Directory attribute. This is likely caused by
using legacy Exchange management tools to create global address lists.
Active Directory operation failed on server1.domain.local. This error is not retriable. Additional information: The name ref
erence is invalid.
This may be caused by replication latency between Active Directory domain controllers.
Active directory response: 000020B5: AtrErr: DSID-03152C47, #1:
0: 000020B5: DSID-03152C47, problem 1005 (CONSTRAINT_ATT_TYPE), data 0, Att 907ff (globalAddressList2)
+ CategoryInfo : NotSpecified: (0:Int32) [New-GlobalAddressList], ADConstraintViolationException
+ FullyQualifiedErrorId : 8E376CCD,Microsoft.Exchange.Management.SystemConfigurationTasks.NewGlobalAddressList

 

the most likely problem is corupted entry.

This can be tested using power shell script on AD server:


$ad = [ADSI]"LDAP://rootDSE";
$domain = $ad.rootDomainNamingContext;
$obj = New-Object System.DirectoryServices.DirectoryEntry("LDAP://CN=Microsoft Exchange,CN=Services,CN=Configuration,$domain"); 

$count = 0;
$Gals1= $obj.GlobalAddressList;
foreach($g in $Gals1)
{
   $g= $g.ToString().ToLower(); 
   if($g.Contains("cn=deleted objects"))
   {
      Write-Host $g;
      $count= $count +1;  
   }
}

Write-Host "$Count corrupted GAL entries found in property GlobalAddressList";

$count = 0;
$Gals2= $obj.GlobalAddressList2;
foreach($g in $Gals2)
{  
   $g= $g.ToString().ToLower();
   if($g.Contains("cn=deleted objects"))  
   {
      Write-Host $g;          
      $count= $count +1;  
   }
}
Write-Host "$Count corrupted GAL entries found in property GlobalAddressList2";

you will get output something like this:

cn=default global address list\0adel:cc665233-b490-477a-a972-60fdd6d991ef,cn=deleted objects,cn=configuration,dc=domain,dc=
local
1 corrupted GAL entries found in property GlobalAddressList
0 corrupted GAL entries found in property GlobalAddressList2

If you find corrupted entries (make sure to have full system backup) you will have to remove them using ADSI edit on domain controller.

Using ADSI edit connect to configuration:

configuration\ Services\ Microsoft Exchange (right click / properties)

depending on the listed corruption look for GlobalAddressList or GlobalAddressList2 and click edit.

Remove corrupted entries.

This helped me to fix creating new GAL.

 

reference:

https://social.technet.microsoft.com/Forums/exchange/en-US/52854856-f517-4827-b3d3-3e589a422672/exchange-2010-sp-2-cant-create-second-gal?forum=exchange2010hosters

https://social.msdn.microsoft.com/Forums/en-US/3210af54-d8b4-490f-9f5f-f4fc3209d324/newglobaladdresslist-fails-ad44a06f?forum=os_exchangeprotocols&forum=os_exchangeprotocols

 

https://www.experts-exchange.com/articles/12458/Failed-to-create-New-Global-Address-List-on-Exchange-2010.html

Thursday, October 5, 2017

Compress folder on macOS Sierra and windows 10

 macOS Sierra:

1. Create folder and place all the files you want to compress in it.

2. Right click on the folder and click on Compress.

 

Windows 10:

  1. Create folder and place all the files you want to compress in it.
  2. Right click on the folder and select Send to > Compressed (zipped) folder.

Friday, September 22, 2017

Spotlight not indexing after Sierra upgrade

 Looks like this helped me:

  1. first I removed all selections under System Preferences/ Spotlight/ search results
  2. restart
  3. use terminal:
    sudo launchctl unload -w /System/Library/LaunchDaemons/com.apple.metadata.mds.plist
    wait 20s
    sudo launchctl load -w /System/Library/LaunchDaemons/com.apple.metadata.mds.plist
    sudo mdutil -E /Volumes/*
    you should get a message indicating that indexing is enabled.

 

 

resources:

https://discussions.apple.com/thread/7684120?start=0&tstart=0

https://discussions.apple.com/thread/5004598?start=0&tstart=0

Monday, September 11, 2017

mac OS Sierra remove parental control using terminal

 for some reason I had parental control enabled on network user with local admin rights.

it wasn’t possible to remove them using system preferences.

to remove it I used terminal command:

sudo dscl . -mcxdelete /Users/username
sudo rm -rf /Library/Managed\ Preferences/username

Thursday, August 31, 2017

DeployStudio workflow with auto-join Active Directory

 After creating master image create workflow with these steps:

1:

restore HDD from MacBookAir2017.hfs.dmg disk image.

 

2:

Rename computer:

 

3:

Prompt for computer name during setup

 

4:

auto join computer to MS Active Directory.

 

5:

auto join computer to Open Directory Server.


Monday, August 28, 2017

Exchange 2010 export user mailbox

 using this simple exchange powershell command:

New-MailboxExportRequest -Mailbox username -FilePath “\\server\share\username.pst”

Thursday, August 17, 2017

Disable background updates on MAC

 terminal command:

sudo defaults write /Library/Preferences/com.apple.SoftwareUpdate AutomaticDownload -boolean FALSE

https://support.apple.com/en-us/HT207251

Wednesday, August 16, 2017

DEP re-enrollment without wipe

 This could help if you need to add already configured apple cumputer (DEP purchased) to Meraki or JAMF MDM management.

sudo rm /var/db/.AppleSetupDone
sudo rm -rf /var/db/ConfigurationProfiles/
sudo rm /Library/Keychains/apsd.keychain

after running these commands restart your computer and the default apple setup assistant will start. (no lost of personal data)

boot to PXE server on DELL Latitude 5480

 It is important to disable safe boot and enable legacy boot.

F2 key is to enter bios

F12 key is for one time boot menu

Tuesday, July 25, 2017

Find email address on exchange 2010 server

 

  1. Get-Recipient -Identity user@domain.com
    you can use this to find user associated with a specific email address 
  2. Get-Recipient -ANR user
    or by using -ANR (Ambiguous Name Resolution) to find using part of a user name

Friday, July 21, 2017

Purge disconnected mailbox on exchange 2010

One option is to wait for the mailbox to be purged automatically (default 30 days)

or to use Cmdlet:

Remove-StoreMailbox -Database <mailboxDatabaseName> -Identity <DisplayName> -Mailbox

Wednesday, June 28, 2017

Format HDD for exchange 2016 using ReFS

windows disk management:

  1. Initialize,GPT
  2. Format ReFS, 64K, Quick format
  3. assign drive letter: R

PowerShell: (to disable integrity streams)

  1. Format-Volume -DriveLetter r -FileSystem ReFS -AllocationUnitSize 65536 -SetIntegrityStreams $false

 

Links:
http://www.careexchange.in/creating-refs-volumes-for-exchange-20132016/

https://www.veeam.com/blog/advanced-refs-integration-coming-veeam-availability-suite.html

https://www.vladan.fr/veeam-and-refs-best-practices-and-benefits/

Tuesday, June 27, 2017

vSphere shrink hard drive on windows OS

  1. shrink HDD using windows disk management.
  2. connect to host using SSH
  3. turn off windows computer
  4. cd /vmfs/volumes/<datastore name>/<VM foldername>
  5. use cat “VM name.vmdk” (not the flat one) to make a note of the RW number#
  6. calculate new size 128GB= 128 * 1024 * 1024 * 1024 /512 = 268435456
  7. vi “VM name.vmdk” replace RW with the new number
  8. vi edit shift I is to edit text; ESC to end editing; exit and save changes shift :x; shift:q! is to exit without changes
  9. use vSphere to migrate or move VM to a temporary host (this will resize the HDD to the new size)
  10. be patient depending on the HDD size it can take some time
  11. verify size in temporary location using vSphere
  12. move back to original location

 

Links:

https://www.experts-exchange.com/articles/12938/HOW-TO-Shrink-a-VMware-Virtual-Machine-Disk-VMDK-in-15-minutes.html

Wednesday, June 21, 2017

windows 2012 R2 domain AD health check

 list of simple commands to check the health of AD

  1. DCs replication status (CMD):
    repadmin /showrepl
  2. domain replication status (CMD):
    dcdiag /v
  3. MS AD replication status tool:
    https://www.microsoft.com/en-us/download/details.aspx?id=30005

Exchange 2010 add user permissions on other user calendar

 add-MailboxFolderPermission -Identity smith@contoso.com:\calendar -User novak@contoso.com -AccessRights Reviewer

Here is MS link with additional information: https://technet.microsoft.com/en-us/library/bb124097(v=exchg.160).aspx

Tuesday, June 6, 2017

Purple screen crash on ESXi 5.5 with Windows Server 2012 R2

 the problem seems to be in the NIC driver.

https://communities.vmware.com/message/2313523

There are two reported fixes:

  1. Disable Receive-side scaling (MS article)
    1. On the virtual machine, open Device Manager (In Settings click Control Panel, and then click Device Manager).

    2. Expand Network adapters, right-click the network adapter you want to work with, and then click Properties.

    3. On the Advanced tab in the network adapter properties, locate the setting for Receive-side scaling and make sure it is disabled.

      or use powershell:

      Set-NetAdapterRSS -Name "AdapterName" -Enabled $False

       

  2. Second option is to use vmxnet3 driver instead of the E1000E
    1. Inside the windows host OS make a note of all the NIC information (IP/ MASK/Gate/DNS etc.)
    2. Remove the old NIC using the vSphere console by editing the windows 2012 server host properties (if needed copy the old MAC address and after deleting the old NIC enter it to the properties of the new NIC)
    3. Using the VMWARE vSphere client edit the virtual machine and add new NIC card (make sure to select VMXNET3 as a adapter type).
    4. Edit the new NIC properties inside the windows 2012 server host OS with the previously noted information to make the new NIC be identical to the old one.
    5. Enable the new nic and restart the windows 2012 server

 

I found some people to report that turning OFF the Receive-side scaling didn’t help.

The second option seems to be a better choice since the new VMWARE VMXNET3 driver has a better design with many improvements.

 


Friday, June 2, 2017

Switch to AHCI mode in windows 10 with BitLocker enabled

 

  1. click on start and type manage BitLocker and launch it. (requires administrative user)
  2. click on Turn off BitLocker (wait on the decryption to finish – it is indicated in the system tray)
  3. reboot your computer to make sure BitLocker is disabled.
  4. Right-click the Windows Start Menu and click on Command Prompt (Admin).
  5. Enter: bcdedit /set {current} safeboot minimal
  6. Reboot the computer in to the BIOS  (F2,Del,ESC,F12 or other key depending on the computer manufacturer).
  7. Look for SATA operation mode and change it to AHCI and save + reboot computer. (F10 key etc.)
  8. windows should start up in safemode.
  9. Right-click the Windows Start Menu and click on Command Prompt (Admin).
  10. Enter: bcdedit /deletevalue {current} safeboot
  11. reboot computer and windows should start up normally again.
  12. click on start and type manage BitLocker and launch it. (requires administrative user)
  13. click on Turn ON BitLocker you will be required to reboot computer.
  14. after reboot wait on the encryption to finish – it is indicated in the system tray

Wednesday, May 31, 2017

Disable iCloud and siri prompt when new user login

 After setting up clean install of macOS Sierra in a multi-user environment (computer lab) it is useful to disable iCloud and siri prompt at the first login.

Here is the original link with instructions and a script to disable iCloud promt:

https://derflounder.wordpress.com/2013/10/27/disabling-the-icloud-sign-in-pop-up-message-on-lion-and-later/

the script is:

#!/bin/sh

# Determine OS version
osvers=$(sw_vers -productVersion | awk -F. '{print $2}')
sw_vers=$(sw_vers -productVersion)

# Checks first to see if the Mac is running 10.7.0 or higher. 
# If so, the script checks the system default user template
# for the presence of the Library/Preferences directory.
#
# If the directory is not found, it is created and then the
# iCloud pop-up settings are set to be disabled.

if [[ ${osvers} -ge 7 ]]; then

 for USER_TEMPLATE in "/System/Library/User Template"/*
  do
    defaults write "${USER_TEMPLATE}"/Library/Preferences/com.apple.SetupAssistant DidSeeCloudSetup -bool TRUE
    defaults write "${USER_TEMPLATE}"/Library/Preferences/com.apple.SetupAssistant GestureMovieSeen none
    defaults write "${USER_TEMPLATE}"/Library/Preferences/com.apple.SetupAssistant LastSeenCloudProductVersion "${sw_vers}"
  done

 # Checks first to see if the Mac is running 10.7.0 or higher.
 # If so, the script checks the existing user folders in /Users
 # for the presence of the Library/Preferences directory.
 #
 # If the directory is not found, it is created and then the
 # iCloud pop-up settings are set to be disabled.

 for USER_HOME in /Users/*
  do
    USER_UID=`basename "${USER_HOME}"`
    if [ ! "${USER_UID}" = "Shared" ] 
    then 
      if [ ! -d "${USER_HOME}"/Library/Preferences ]
      then
        mkdir -p "${USER_HOME}"/Library/Preferences
        chown "${USER_UID}" "${USER_HOME}"/Library
        chown "${USER_UID}" "${USER_HOME}"/Library/Preferences
      fi
      if [ -d "${USER_HOME}"/Library/Preferences ]
      then
        defaults write "${USER_HOME}"/Library/Preferences/com.apple.SetupAssistant DidSeeCloudSetup -bool TRUE
        defaults write "${USER_HOME}"/Library/Preferences/com.apple.SetupAssistant GestureMovieSeen none
        defaults write "${USER_HOME}"/Library/Preferences/com.apple.SetupAssistant LastSeenCloudProductVersion "${sw_vers}"
        chown "${USER_UID}" "${USER_HOME}"/Library/Preferences/com.apple.SetupAssistant.plist
      fi
    fi
  done
fi

 

 

And here is the original link with information on how to disable siri:

https://derflounder.wordpress.com/2016/09/20/supressing-siri-pop-up-windows-on-macos-sierra/

and here is the script

#!/bin/bash

# Determine OS version
osvers=$(sw_vers -productVersion | awk -F. '{print $2}')
sw_vers=$(sw_vers -productVersion)

# Determine OS build number

sw_build=$(sw_vers -buildVersion)

# Checks first to see if the Mac is running 10.7.0 or higher. 
# If so, the script checks the system default user template
# for the presence of the Library/Preferences directory. Once
# found, the iCloud, Diagnostic and Siri pop-up settings are set 
# to be disabled.

if [[ ${osvers} -ge 7 ]]; then

 for USER_TEMPLATE in "/System/Library/User Template"/*
  do
    /usr/bin/defaults write "${USER_TEMPLATE}"/Library/Preferences/com.apple.SetupAssistant DidSeeCloudSetup -bool TRUE
    /usr/bin/defaults write "${USER_TEMPLATE}"/Library/Preferences/com.apple.SetupAssistant GestureMovieSeen none
    /usr/bin/defaults write "${USER_TEMPLATE}"/Library/Preferences/com.apple.SetupAssistant LastSeenCloudProductVersion "${sw_vers}"
    /usr/bin/defaults write "${USER_TEMPLATE}"/Library/Preferences/com.apple.SetupAssistant LastSeenBuddyBuildVersion "${sw_build}"
    /usr/bin/defaults write "${USER_TEMPLATE}"/Library/Preferences/com.apple.SetupAssistant DidSeeSiriSetup -bool TRUE      
  done
  
 # Checks first to see if the Mac is running 10.7.0 or higher.
 # If so, the script checks the existing user folders in /Users
 # for the presence of the Library/Preferences directory.
 #
 # If the directory is not found, it is created and then the
 # iCloud, Diagnostic and Siri pop-up settings are set to be disabled.

 for USER_HOME in /Users/*
  do
    USER_UID=`basename "${USER_HOME}"`
    if [ ! "${USER_UID}" = "Shared" ]; then
      if [ ! -d "${USER_HOME}"/Library/Preferences ]; then
        /bin/mkdir -p "${USER_HOME}"/Library/Preferences
        /usr/sbin/chown "${USER_UID}" "${USER_HOME}"/Library
        /usr/sbin/chown "${USER_UID}" "${USER_HOME}"/Library/Preferences
      fi
      if [ -d "${USER_HOME}"/Library/Preferences ]; then
        /usr/bin/defaults write "${USER_HOME}"/Library/Preferences/com.apple.SetupAssistant DidSeeCloudSetup -bool TRUE
        /usr/bin/defaults write "${USER_HOME}"/Library/Preferences/com.apple.SetupAssistant GestureMovieSeen none
        /usr/bin/defaults write "${USER_HOME}"/Library/Preferences/com.apple.SetupAssistant LastSeenCloudProductVersion "${sw_vers}"
        /usr/bin/defaults write "${USER_HOME}"/Library/Preferences/com.apple.SetupAssistant LastSeenBuddyBuildVersion "${sw_build}"
        /usr/bin/defaults write "${USER_HOME}"/Library/Preferences/com.apple.SetupAssistant DidSeeSiriSetup -bool TRUE
        /usr/sbin/chown "${USER_UID}" "${USER_HOME}"/Library/Preferences/com.apple.SetupAssistant.plist
      fi
    fi
  done
fi

exit 0

Monday, May 15, 2017

simple HTML page redirection

 Create page index.html (or which ever is your server default page to be loaded when you access a folder)

type:

<meta http-equiv=”refresh” content=”0;URL=’http://domain.com/page-to-be-redirected-to'” />

this way when someone opens domain.com/old-location will be redirected to domain.com/page-to-be-redirected-to

Tuesday, May 9, 2017

Grant printer admin rights on a mac to domain users

 allow administration of printers by domain users:

/usr/sbin/dseditgroup -o edit -n /Local/Default -a ‘Domain Users’ -t group _lpadmin

 

If not part of domain you can grant printer admin rights to everyone:

/usr/sbin/dseditgroup -o edit -n /Local/Default -a everyone -t group _lpadmin

Thursday, May 4, 2017

Disable spellcheck word 2016

 Here is a solution on how to disable spellcheck in word 2016 using group policy:

 

 

reference: http://www.edugeek.net/forums/windows/181129-disable-spellcheck-word-2016-a.html

Additionally we create special domain user which is blocked at the firewall level from internet content.

Free backup software for windows “Veeam Endpoint Backup FREE”

 

Veeam Endpoint Backup FREE

There are many options for desktop backup solution if you have windows 10 computer.

You can use build in file history features or classic windows 7 style backup.

It is important to have a backup and the Microsoft included solutions will work fine as long as they are setup.

If you are looking for something with more features and easy setup look at free backup solution from VEEAM.

Here is the link: https://www.veeam.com/endpoint-backup-free.html

Short list of some of the important features:

  1. You can create recovery boot disk or USB flash drive
  2. Choose bare-metal, volume or file level backup.
  3. Schedule recurring backup (Initial backup is full and then incremental)
  4. New feature to eject USB backup hard drive after successful backup to protect from ransomware CryptoLocker.
  5. Set it and forget it 🙂

There are many reasons to have a backup so please go and do it! 🙂

Wednesday, May 3, 2017

Phishing attack threat reminder!

 Here is a good article about phishing attacks.

They are always a great threat and it is best to trust no one and carefully examine links in your emails.

http://fortune.com/2017/05/03/google-docs-scam/

Thursday, April 27, 2017

Control Windows 10 power savings command line

 windows 10

https://technet.microsoft.com/en-us/library/cc748940(v=ws.10).aspx

using command line:

default power schemes (powercfg /l):

Power Scheme GUID: 381b4222-f694-41f0-9685-ff5bb260df2e  (Balanced)
Power Scheme GUID: 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c  (High performance) *
Power Scheme GUID: a1841308-3541-4fab-bc81-f71556f20b4a  (Power saver)

example to use High Performance:
powercfg /s 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c

Wednesday, April 26, 2017

WiFi doesn’t work but it did yesterday on my MacBook air

 Many times I get this question. (The user didn’t change the WiFi configuration at home)

Usually the problem is caused by resent OS update.

Many times to fix it is to reset the NVRAM (here is more info about NVRAM: https://support.apple.com/en-us/HT204063)

  1. Shutdown your computer
  2. press the power button and hold these four keys until your computer makes the chaim sound twice.

OptionplusCommandplusPplusR

3. let the computer finish booting and test the WiFi connection

Windows 10 Auto login in domain

 

Deploy using registry:
REG ADD “HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon” /v AutoAdminLogon /t REG_SZ /d 1 /f
REG ADD “HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon” /v DefaultDomainName /t REG_SZ /d *your domain* /f
—-if local domain is needed use “.” (without the “)
REG ADD “HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon” /v DefaultUserName /t REG_SZ /d *User* /f
REG ADD “HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon” /v DefaultPassword /t REG_SZ /d *password* /f
—If using special character use ^ before it

To remove:
REG delete “HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon” /v AutoAdminLogon /f
REG delete “HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon” /v DefaultDomainName /f
REG delete “HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon” /v DefaultUserName /f
REG delete “HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon” /v DefaultPassword /f

How to Fix ADSelfService Plus SSL Path Errors (GoDaddy P7B Guide)

If you manage ManageEngine ADSelfService Plus on Windows Server 2022 and rely on GoDaddy for your SSL certificates, you have likely run ...