вторник, 31 декабря 2019 г.
понедельник, 16 декабря 2019 г.
воскресенье, 1 декабря 2019 г.
понедельник, 11 ноября 2019 г.
четверг, 3 октября 2019 г.
Windows 10 set logon/lockscreen background gpo
Положить backgroundDefault.jpg в netlogon.
%policyname%\Computer configuration\Preferences\Windows Settings\Files
sourse:
\\domain.locall\NETLOGON\info\backgroundDefault.jpg
dest:
%windir%\System32\oobe\info\backgrounds\backgroundDefault.jpg
Добавить:
Common -> Item-level Targeting -> OS = Windows7, 8, 10
%policyname%\Computer configuration\Preferences\Windows Settings\Registry
Добавить раздел PersonalizationCSP и 3 параметра внутрь
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\PersonalizationCSP
LockScreenImagePath
(REG_SZ)
c:\Windows\System32\oobe\info\backgrounds\backgroundDefault.jpg
LockScreenImageStatus
(REG_DWORD)
1
LockScreenImageUrl
(REG_SZ)
c:\Windows\System32\oobe\info\backgrounds\backgroundDefault.jpg
Добавить:
Common -> Item-level Targeting -> OS = Windows10
Источник
%policyname%\Computer configuration\Preferences\Windows Settings\Files
sourse:
\\domain.locall\NETLOGON\info\backgroundDefault.jpg
dest:
%windir%\System32\oobe\info\backgrounds\backgroundDefault.jpg
Добавить:
Common -> Item-level Targeting -> OS = Windows7, 8, 10
%policyname%\Computer configuration\Preferences\Windows Settings\Registry
Добавить раздел PersonalizationCSP и 3 параметра внутрь
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\PersonalizationCSP
LockScreenImagePath
(REG_SZ)
c:\Windows\System32\oobe\info\backgrounds\backgroundDefault.jpg
LockScreenImageStatus
(REG_DWORD)
1
LockScreenImageUrl
(REG_SZ)
c:\Windows\System32\oobe\info\backgrounds\backgroundDefault.jpg
Добавить:
Common -> Item-level Targeting -> OS = Windows10
Источник
понедельник, 10 июня 2019 г.
Exchange 2010, отправка от имени с сохранием сообщения в общий почтовый ящик
https://techcommunity.microsoft.com/t5/Exchange-Team-Blog/Want-more-control-over-Sent-Items-when-using-shared-mailboxes/ba-p/611106
https://support.microsoft.com/en-us/help/2632409/messages-that-are-sent-by-using-the-send-as-and-send-on-behalf-permiss
Get-MailboxSentItemsConfiguration alias
Set-MailboxSentItemsConfiguration alias -SendAsItemsCopiedTo:SenderAndFrom
https://support.microsoft.com/en-us/help/2632409/messages-that-are-sent-by-using-the-send-as-and-send-on-behalf-permiss
Get-MailboxSentItemsConfiguration alias
Set-MailboxSentItemsConfiguration alias -SendAsItemsCopiedTo:SenderAndFrom
воскресенье, 19 мая 2019 г.
понедельник, 1 апреля 2019 г.
пятница, 18 января 2019 г.
Adobe acrobat reader DC. msi, mst, gpo. Ver.19.10 (2019.010.20069)
Собрал актуальную, на текущую дату версию в msi.
Ссылка.
При развертывании через гп, добавить ardc.mst из корня как модификацию.
Ссылка.
При развертывании через гп, добавить ardc.mst из корня как модификацию.
суббота, 5 января 2019 г.
MS SQL reset sa password / add access to new admin
Copy-paste:
Here is another workaround:
Run the SQL Server Management Studio as the system account. This can be done easily with the PsExec program. Download PsExec from Sysinternals website. Extract the PsExec.exe program and save it to a folder on your computer such as C:.
Open an elevated Command Prompt and run the following command:
C:\PsExec.exe -s -i "C:\Program Files (x86)\Microsoft SQL Server\110\Tool\Binn\ManagementStudio\Ssms.exe"
It will start SQL Server Management Studio as the system account. You’ll see that the username is shown as "NT AUTHORITY\SYSTEM". Simply choose the Windows Authentication mode and click on the Connect button.
Once you connect, you can reset SA password with ease.
If this also doesn't work, the last resort is try some third-party software such as SQL Server Password Changer, or reinstall your SQL Server.
источник
Here is another workaround:
Run the SQL Server Management Studio as the system account. This can be done easily with the PsExec program. Download PsExec from Sysinternals website. Extract the PsExec.exe program and save it to a folder on your computer such as C:.
Open an elevated Command Prompt and run the following command:
C:\PsExec.exe -s -i "C:\Program Files (x86)\Microsoft SQL Server\110\Tool\Binn\ManagementStudio\Ssms.exe"
It will start SQL Server Management Studio as the system account. You’ll see that the username is shown as "NT AUTHORITY\SYSTEM". Simply choose the Windows Authentication mode and click on the Connect button.
Once you connect, you can reset SA password with ease.
If this also doesn't work, the last resort is try some third-party software such as SQL Server Password Changer, or reinstall your SQL Server.
источник
пятница, 14 декабря 2018 г.
Перенос почты ящиков imap (yandex) -> exchange. Убрать фильтры imap.
После переноса pst в exchange - активны фильтры imap.
Как лечить:
Как лечить:
четверг, 6 декабря 2018 г.
Изменить расположение профиля пользователя на терминальном сервере
Open REGEDIT from START->RUN
Change the value for the registry string value "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNTCurrentVersion\ProfileList\ProfilesDirectory"
From Default value = "%SystemDrive%\Documents and Settings" to New Value = "DriveLetter\Documents and Settings" For example F:\Profiles
Restart the server
источник
Change the value for the registry string value "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNTCurrentVersion\ProfileList\ProfilesDirectory"
From Default value = "%SystemDrive%\Documents and Settings" to New Value = "DriveLetter\Documents and Settings" For example F:\Profiles
Restart the server
источник
четверг, 30 августа 2018 г.
MS Office vs %temp%
Есть скрипт, грохающий при логоне, "%LOCALAPPDATA%\Temp", "%HOMEPATH%\Local Settings\Temp", "%HOMEPATH%\Local Settings\Application Data\Temp". А вот почему-то перестали открываться документы xls, doc и пр. Но xlsx, docx - живы.
Подсказка была найдена на http://forum.oszone.net в виду запуска от админа и проверки - откроет/не откроет. Таки открыл! В чем таки был сабж - иначе надо темпы чистить, если пользуны смотрят старые форматы. И при обращении %temp% нас выкидавает в %appdata%\local\temp\random_folder_name
Подсказка была найдена на http://forum.oszone.net в виду запуска от админа и проверки - откроет/не откроет. Таки открыл! В чем таки был сабж - иначе надо темпы чистить, если пользуны смотрят старые форматы. И при обращении %temp% нас выкидавает в %appdata%\local\temp\random_folder_name
вторник, 22 мая 2018 г.
Создание pfx из crt и key
Используя openssl
"C:\Program Files\OpenVPN\bin\openssl.exe" pkcs12 -export -out "C:\Program Files\OpenVPN\bin\company.ru.pfx" -inkey "C:\Program Files\OpenVPN\bin\private_key.key" -in "C:\Program Files\OpenVPN\bin\company.ru.crt"
"C:\Program Files\OpenVPN\bin\openssl.exe" pkcs12 -export -out "C:\Program Files\OpenVPN\bin\company.ru.pfx" -inkey "C:\Program Files\OpenVPN\bin\private_key.key" -in "C:\Program Files\OpenVPN\bin\company.ru.crt"
четверг, 21 декабря 2017 г.
Наследование разрешений на томе файлопомойки
Можно изменить способ обработки разрешений проводником Windows при копировании или перемещении объектов на другой том NTFS. При копировании или перемещение объекта в другой том, объект наследует разрешения для новой папки. Тем не менее если вы хотите изменить это поведение для сохранения исходных разрешения, измените реестр следующим образом.
Важно. Этот раздел, метод или задача содержат действия, содержащие указания по изменению реестра. Однако, при некорректных изменениях реестра могут возникнуть серьезные проблемы. Поэтому выполняйте следующие действия внимательно. Для дополнительной защиты сделайте резервную копию реестра перед внесением изменений. В таком случае при возникновении неполадок можно будет восстановить реестр. Чтобы узнать дополнительные сведения о резервном копировании и восстановлении реестра, щелкните следующий номер статьи базы знаний Майкрософт:
322756 как резервное копирование и восстановление реестра Windows
Нажмите кнопку Пуск, выберите пункт выполнить, в поле Открыть введите команду regedit и нажмите клавишу ВВОД.
Найдите и щелкните следующий раздел реестра:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer
В меню Правка выберите пункт Добавить значениеи добавьте следующий параметр реестра:
Имя значения: ForceCopyAclwithFile
Тип данных: DWORD
Значение: 1
Закройте редактор реестра.
Можно изменять как проводник Windows обрабатывает разрешения при перемещении объектов в том же томе NTFS. Как уже упоминалось, при перемещении объекта в пределах одного тома, объект сохраняет его разрешения по умолчанию. Тем не менее если вы хотите изменить это поведение так, чтобы объект наследует разрешения от родительской папки, измените реестр следующим образом:
Нажмите кнопку Пуск, выберите пункт Выполнить, введите команду regedit и нажмите клавишу ВВОД.
Найдите и выделите следующий подраздел реестра:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
В меню Правка выберите пункт Добавить значениеи добавьте следующий параметр реестра:
Имя значения: MoveSecurityAttributes
Тип данных: DWORD
Значение: 0
Закройте редактор реестра.
Убедитесь, что учетная запись пользователя, используемый для перемещения объекта имеет набор разрешений Изменить разрешения . Если разрешение не задано, предоставьте Изменение разрешений учетной записи пользователя.
Примечание. Значение параметра реестра MoveSecurityAttributes применяется только для Windows XP и Windows Server 2003. Значение не влияет на Windows 2000.
Источник
Важно. Этот раздел, метод или задача содержат действия, содержащие указания по изменению реестра. Однако, при некорректных изменениях реестра могут возникнуть серьезные проблемы. Поэтому выполняйте следующие действия внимательно. Для дополнительной защиты сделайте резервную копию реестра перед внесением изменений. В таком случае при возникновении неполадок можно будет восстановить реестр. Чтобы узнать дополнительные сведения о резервном копировании и восстановлении реестра, щелкните следующий номер статьи базы знаний Майкрософт:
322756 как резервное копирование и восстановление реестра Windows
Нажмите кнопку Пуск, выберите пункт выполнить, в поле Открыть введите команду regedit и нажмите клавишу ВВОД.
Найдите и щелкните следующий раздел реестра:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer
В меню Правка выберите пункт Добавить значениеи добавьте следующий параметр реестра:
Имя значения: ForceCopyAclwithFile
Тип данных: DWORD
Значение: 1
Закройте редактор реестра.
Можно изменять как проводник Windows обрабатывает разрешения при перемещении объектов в том же томе NTFS. Как уже упоминалось, при перемещении объекта в пределах одного тома, объект сохраняет его разрешения по умолчанию. Тем не менее если вы хотите изменить это поведение так, чтобы объект наследует разрешения от родительской папки, измените реестр следующим образом:
Нажмите кнопку Пуск, выберите пункт Выполнить, введите команду regedit и нажмите клавишу ВВОД.
Найдите и выделите следующий подраздел реестра:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
В меню Правка выберите пункт Добавить значениеи добавьте следующий параметр реестра:
Имя значения: MoveSecurityAttributes
Тип данных: DWORD
Значение: 0
Закройте редактор реестра.
Убедитесь, что учетная запись пользователя, используемый для перемещения объекта имеет набор разрешений Изменить разрешения . Если разрешение не задано, предоставьте Изменение разрешений учетной записи пользователя.
Примечание. Значение параметра реестра MoveSecurityAttributes применяется только для Windows XP и Windows Server 2003. Значение не влияет на Windows 2000.
Источник
понедельник, 6 ноября 2017 г.
Exchange Dynamic Distribution Group + Multiple OUs
Либо воспользоваться дополнительными атрибутами, либо, включить динамические группы рассылки в статичную группу рассылки.
четверг, 26 октября 2017 г.
Exchange. Отключить activesync / owa на базу
Get-Mailbox -Database DBName | Set-CasMailbox -ActiveSyncEnabled $false
Get-Mailbox -Database DBName | Set-CasMailbox -OWAforDevicesEnabled $false
Читать тут
Get-Mailbox -Database DBName | Set-CasMailbox -OWAforDevicesEnabled $false
Читать тут
пятница, 20 октября 2017 г.
Проверка получателей, exchange 2013/2016
https://helpdesk.spamtitan.com/support/solutions/articles/4000003763-dynamic-recipient-verification-using-exchange-2013-and-2016
четверг, 19 октября 2017 г.
vSphere client 6.5 Shockwave Flash has crashed
http://www.virtuallyghetto.com/2017/10/shockwave-flash-has-crashed-workaround-for-vsphere-web-flash-client.html
http://www.jonkensy.com/vsphere-web-client-shockwave-flash-has-crashed/
https://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=2151945
http://www.jonkensy.com/vsphere-web-client-shockwave-flash-has-crashed/
https://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=2151945
вторник, 19 сентября 2017 г.
воскресенье, 17 сентября 2017 г.
MS SQL Server. DBMail error [474] Microsoft.SqlServer.Management.SqlIMail.Server.Common.BaseException: Mail configuration information could not be read from the database. ---> System.InvalidCastException
Дата 17.09.2017 19:14:16
Журнал Агент SQL Server (Текущий - 17.09.2017 19:14:00)
Сообщение
[474] Unable to refresh Database Mail profile notify@extdomain.com. (reason: Microsoft.SqlServer.Management.SqlIMail.Server.Common.BaseException: Mail configuration information could not be read from the database. ---> System.InvalidCastException: Не удалось привести тип объекта "System.DBNull" к типу "System.Byte[]".
в Microsoft.SqlServer.Management.SqlIMail.Server.DataAccess.DataAccessAdapter.GetAccount(Int32 accountID)
--- Конец трассировки внутреннего стека исключений ---
в Microsoft.SqlServer.Management.SqlIMail.Server.DataAccess.DataAccessAdapter.GetAccount(Int32 )
Для решения читать этот пост.
В SQL убрана поддержка TLS 1.0
Копипаста:
Enabling FIPS in local group policy fixed the database mail issue:
Open gpedit.msc. In the Local Group Policy Editor, double-click Windows Settings under the Computer Configuration node, and then double-click Security Settings.
Under the Security Settings node, double-click Local Policies, and then click Security Options.
In the details pane, double-click System cryptography: Use FIPS-compliant algorithms for encryption, hashing, and signing.
In the System cryptography: Use FIPS-compliant algorithms for encryption, hashing, and signing dialog box, click Enabled, and then click OK to close the dialog box. Close the Local Group Policy Editor.
Restart SQL Server machine for this change to take affect.
Журнал Агент SQL Server (Текущий - 17.09.2017 19:14:00)
Сообщение
[474] Unable to refresh Database Mail profile notify@extdomain.com. (reason: Microsoft.SqlServer.Management.SqlIMail.Server.Common.BaseException: Mail configuration information could not be read from the database. ---> System.InvalidCastException: Не удалось привести тип объекта "System.DBNull" к типу "System.Byte[]".
в Microsoft.SqlServer.Management.SqlIMail.Server.DataAccess.DataAccessAdapter.GetAccount(Int32 accountID)
--- Конец трассировки внутреннего стека исключений ---
в Microsoft.SqlServer.Management.SqlIMail.Server.DataAccess.DataAccessAdapter.GetAccount(Int32 )
Для решения читать этот пост.
В SQL убрана поддержка TLS 1.0
Копипаста:
Enabling FIPS in local group policy fixed the database mail issue:
Open gpedit.msc. In the Local Group Policy Editor, double-click Windows Settings under the Computer Configuration node, and then double-click Security Settings.
Under the Security Settings node, double-click Local Policies, and then click Security Options.
In the details pane, double-click System cryptography: Use FIPS-compliant algorithms for encryption, hashing, and signing.
In the System cryptography: Use FIPS-compliant algorithms for encryption, hashing, and signing dialog box, click Enabled, and then click OK to close the dialog box. Close the Local Group Policy Editor.
Restart SQL Server machine for this change to take affect.
Подписаться на:
Сообщения (Atom)
