O R G A N I C / F E R T I L I Z E R: 10.05

Oct 18, 2005

restricted groups - adding to members

for a long time, it's been thought that restricted groups in a group policy would only perform a wipe and replace of members of a local group. let's dispel this myth. what seems to be fairly unknown is that restricted groups is capable of adding members to a group without removing the existing members. for instance, let's assume we have a group called MyGroupA that needs to be in the administrators group of a set of workstations. there are two methods we can do this. the first, you're probably familiar with, which is to replace anything in the administrators group with a new set of groups or users. where is this useful? if you want to make sure that any accounts that are mysteriously added to the local admins group are removed and replaced with your set of users/groups, use this method. i won't elaborate on this since this is fairly common and understood. the other method is adding users/groups to local admins without removing the users/groups that exist. back to MyGroupA. here's how to set it up.
  1. open up the group policy you want to effect
  2. under computer configuration, navigate to windows settings\security settings
  3. locate the restricted groups folder. right-click on the folder and choose add group...
  4. add in the group - domain\MyGroupA, for instance
  5. in the configure membership for dialog, there are two panes. in the bottom pane labeled this group is a member of, click add
  6. type in administrators. click ok
  7. click ok to close the dialog
that's it. now refresh the policy on a workstation. it should have added the group specified into the administrators group.

Oct 14, 2005

exchange mp - check mailbox store availability - mapi logon test

you know, i thought... while i'm on the issue of dumb event rules, this one came up. this rule kicks off the exchange 2003 - mapi logon verification script. there's nothing wrong with the idea of this rule... the problem is wholly in the execution. for example, you probably want to know when an error occurs right? so you leave this on... the logperfdata parameter in the script allows for three different values:
  • "0" - logs success events
  • "1" - logs information into a performance counter
  • "-1" - does not log
so what's the problem? if you set this value to something other than 0, the exchange service availability report will not have any data when it runs. nice.

iis management pack - useless rules

i was running a couple of mom sql scripts that generate most common events and most common alerts. (if you're not doing this yet, you probably should make a point of doing this about once a week or so... just to make sure you're not getting any event storms.) anyway, turns out two rules were generating about 80,000 events in a 4 day window on one management group. it generated about 750,000 events on another management group. that's right - 750,000. i would categorize that as a complete and ridiculous oversight when MS was building this particular MP. these were picked up as "informational". i'm going to equate that to useless in this case. if you load up the IIS MP, i strongly suggest disabling the following two rules:
  • All HTTP 400 Errors
  • All HTTP 500 Errors
you can locate these rules under this path: microsoft windows internet information services\internet information services x.x\core services\world wide web publishing service. note that the x.x represents 5.0 and 6.0. needs to be disabled in both places.

Oct 9, 2005

interesting search engine...

i ran across this on one of my own google ads on my blog page. has anyone used this search engine? seems interesting... http://www.microsoftsearchengine.com/search/search.php/search::cat/category::4737

system center stuff is available...

it's interesting how three different products in the system center suite hit different levels of beta nearly all at once. it's actually pretty cool... unless you're beta testing all of them... got some work cut out for you. mom 2005 summary reporting pack - release candidate system center reporting manager 2005 - beta system center capacity planner 2006 - public beta summary reporting pack aggregates information that exists in your mom warehouse database and essentially improves performance. reporting manager 2005 is an integration of sms and mom data into one warehouse. i don't have much experience with this or the reporting pack yet. i'll post more of my findings as i come across them. i can probably speak to capacity planner 2006 best. i attended the airlift in redmond and saw the product, talked to the product group, and in general had a very good experience over all. this version works for planning mom and exchange deployments. essentially, it comes with lots of performance statistics. you supply the infrastructure and data about your environment or potential environment... the planner tells you if it's going to work. there's a certain bit of fluff you have to accommodate for, obviously. it takes you a long way from having to plan this stuff on paper, basically guessing at the stuff... happy planning.

Oct 6, 2005

john hann's articles resurface

looks like some of hann's articles are coming back ... on his blog. here's the post... maybe i won't have to repost his stuff. :)

Availability MP

so it turns out (sorry been in seattle too long where every sentence starts with "so") the availability mp has some issues. hence it's been pulled from the microsoft website. if you have the exchange mp installed, do not install the availability mp (yet). It's going to be updated soon, though... keep your eyes open. anyway, the current version pulls out the following groups:
  • Microsoft Exchange Server 2000 Backend
  • Microsoft Exchange Server 2003 Backend
it replaces it with the following groups:
  • Microsoft Exchange Server 2000
  • Microsoft Exchange Server 2003
the only workaround right now is to re-import the exchange mp. fun.