<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-21992565</id><updated>2012-04-23T10:12:19.796+02:00</updated><category term='it-experts.dk'/><category term='block'/><category term='public beta'/><category term='group policies'/><category term='SQL'/><category term='regional options'/><category term='Outlook'/><category term='Patching'/><category term='SQL Injection'/><category term='registry'/><category term='mdop'/><category term='Security Guide'/><category term='Windows Server 2008'/><category term='software restriction policies'/><category term='updates'/><category term='whitepaper'/><category term='generalize'/><category term='dop'/><category term='terminal services'/><category term='group policy preferences'/><category term='online scanner'/><category term='encryption'/><category term='MSDN'/><category term='admx'/><category term='group policy'/><category term='softgrid'/><category term='windows xp'/><category term='webcast'/><category term='RSAT'/><category term='rdp'/><category term='language pack'/><category term='WMI Filters'/><category term='Mac'/><category term='runas'/><category term='Longhorn'/><category term='technet magazine'/><category term='mlgpo'/><category term='security id'/><category term='mstsc'/><category term='GPDBPA'/><category term='Shared Computer Toolkit'/><category term='xp'/><category term='x64'/><category term='gpo'/><category term='backup'/><category term='adml'/><category term='scripting'/><category term='Shadow Groups'/><category term='orlando'/><category term='windows server 2003'/><category term='Windows Vista'/><category term='specops'/><category term='Security Descriptors'/><category term='sysvol'/><category term='srp'/><category term='webinar'/><category term='security'/><category term='guid'/><category term='Microsoft Application Virtualization'/><category term='Activation'/><category term='MVP'/><category term='policy'/><category term='language'/><category term='best practice analyzer'/><category term='anti-malware'/><category term='wsus'/><category term='gui'/><category term='TechEd'/><category term='service pack'/><category term='hacker'/><category term='beta'/><category term='VBA'/><category term='Jeremy Moskowitz'/><category term='SteadyState'/><category term='UAC'/><category term='software'/><category term='BPA'/><category term='remote desktop'/><category term='network'/><category term='release'/><category term='Darren Mar-Elia'/><category term='exploit'/><category term='anti-virus'/><category term='vista'/><category term='agpm'/><category term='Core'/><category term='Unix'/><category term='display language'/><category term='virtualization'/><category term='starter gpo'/><category term='cab'/><category term='language interface packs'/><category term='public'/><category term='mav'/><category term='kb'/><category term='group policy extensions'/><category term='Powershell'/><category term='connection'/><category term='64bit'/><category term='PolicyMaker'/><category term='OU Filtering'/><category term='hacking'/><category term='endpointsecurity'/><category term='template'/><category term='Oracle'/><category term='mmc'/><category term='The onion ring'/><category term='mui'/><category term='CEH'/><category term='gpanswers.com'/><category term='gp preferences'/><category term='windowsecurity.com'/><category term='download'/><category term='Tor'/><category term='technet'/><category term='ISA'/><category term='online scanners'/><category term='script'/><category term='posters'/><category term='windows'/><category term='newsid'/><category term='starter gpos'/><category term='central store'/><category term='gfi'/><category term='VM Ware'/><category term='database'/><category term='Windows 7'/><category term='baseline'/><category term='gpmc'/><category term='Certified Ethical Hacker'/><category term='Fine-Grained Password Policies'/><category term='radio'/><category term='Certification'/><category term='knowledge base'/><category term='connect'/><category term='Site Filtering'/><category term='AppLocker'/><category term='Granular Password Settings'/><category term='deployment'/><category term='videos'/><category term='gpedit.msc'/><category term='Security Filtering'/><category term='Client Side Extensions'/><category term='virtual server'/><category term='Solution Accelerator'/><category term='desktop optimization pack'/><category term='sysprep'/><category term='multilingual'/><category term='gpoguy.com'/><category term='sid'/><category term='ctp'/><category term='Linux'/><category term='gpedit'/><category term='server'/><category term='microsoft'/><category term='DesktopStandards'/><category term='multihomed'/><category term='article'/><category term='administrative templates'/><category term='u2'/><category term='password'/><category term='problem'/><category term='BitLocker'/><title type='text'>heidelbergit</title><subtitle type='html'>Jakob H. Heidelberg it an IT specialist with focus on security, scripting and the Microsoft world. He's an MCSE:M/S, MCDST, MCTS, MCITP, MCT, CEH &amp; MVP- and an author on www.windowsecurity.com.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.heidelbergit.dk/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default'/><link rel='alternate' type='text/html' href='http://www.heidelbergit.dk/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default?start-index=26&amp;max-results=25'/><author><name>Jakob H. Heidelberg</name><uri>http://www.blogger.com/profile/05947807953068058636</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>105</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-21992565.post-1641117236127099269</id><published>2011-10-14T08:45:00.003+02:00</published><updated>2011-10-14T08:52:29.248+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='registry'/><category scheme='http://www.blogger.com/atom/ns#' term='script'/><category scheme='http://www.blogger.com/atom/ns#' term='scripting'/><title type='text'>RegistryProfileCleanup - cleartext</title><content type='html'>&lt;br /&gt;Several people have asked me for the VBS code to my "Efficient Registry Cleanup" script, since the link went down. I'm not using any time on this blog these days, so this is just a quick &amp;amp; dirty fix:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://dl.dropbox.com/u/11617172/RegistryProfileCleanup.txt"&gt;http://dl.dropbox.com/u/11617172/RegistryProfileCleanup.txt&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Also the "Get User Profile Dirs From Registry" script is here:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://dl.dropbox.com/u/11617172/GetUserProfileDirsFromRegistry.txt"&gt;http://dl.dropbox.com/u/11617172/GetUserProfileDirsFromRegistry.txt&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Cya!&lt;br /&gt;Jakob&lt;br /&gt;&lt;br /&gt;P.S. The article is still here:&amp;nbsp;&lt;a href="http://www.windowsecurity.com/articles/efficient-registry-cleanup.html" target="_blank"&gt;http://www.windowsecurity.com/articles/efficient-registry-cleanup.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21992565-1641117236127099269?l=www.heidelbergit.dk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.heidelbergit.dk/feeds/1641117236127099269/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21992565&amp;postID=1641117236127099269' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/1641117236127099269'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/1641117236127099269'/><link rel='alternate' type='text/html' href='http://www.heidelbergit.dk/2011/10/registryprofilecleanup-cleartext.html' title='RegistryProfileCleanup - cleartext'/><author><name>Jakob H. Heidelberg</name><uri>http://www.blogger.com/profile/05947807953068058636</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21992565.post-8614676959396223660</id><published>2011-10-14T08:41:00.000+02:00</published><updated>2011-10-14T08:41:02.852+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='group policy'/><category scheme='http://www.blogger.com/atom/ns#' term='group policies'/><category scheme='http://www.blogger.com/atom/ns#' term='group policy extensions'/><category scheme='http://www.blogger.com/atom/ns#' term='group policy preferences'/><category scheme='http://www.blogger.com/atom/ns#' term='script'/><category scheme='http://www.blogger.com/atom/ns#' term='scripting'/><title type='text'>InstallGPPCSE - cleartext</title><content type='html'>&lt;br /&gt;Several people have asked me for the VBS code to my GPP CSE Install script since the link went down. I'm not using any time on this blog these days, so this is just a quick &amp;amp; dirty fix:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://dl.dropbox.com/u/11617172/InstallGPPCSE.txt"&gt;http://dl.dropbox.com/u/11617172/InstallGPPCSE.txt&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Cya!&lt;br /&gt;Jakob&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21992565-8614676959396223660?l=www.heidelbergit.dk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.heidelbergit.dk/feeds/8614676959396223660/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21992565&amp;postID=8614676959396223660' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/8614676959396223660'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/8614676959396223660'/><link rel='alternate' type='text/html' href='http://www.heidelbergit.dk/2011/10/installgppcse-cleartext.html' title='InstallGPPCSE - cleartext'/><author><name>Jakob H. Heidelberg</name><uri>http://www.blogger.com/profile/05947807953068058636</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21992565.post-3667594422499316078</id><published>2011-06-24T20:38:00.001+02:00</published><updated>2011-06-24T20:38:56.926+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='script'/><category scheme='http://www.blogger.com/atom/ns#' term='scripting'/><title type='text'>FlexCommand - cleartext</title><content type='html'>Several people have asked me for the HTA code to my FlexCommand tool since the link went down. I'm not using any time on this blog these days, so this is just a quick &amp;amp; dirty fix:&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://dl.dropbox.com/u/11617172/FLEXCOMMAND.txt"&gt;http://dl.dropbox.com/u/11617172/FLEXCOMMAND.txt&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Cya!&lt;/div&gt;&lt;div&gt;Jakob&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21992565-3667594422499316078?l=www.heidelbergit.dk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.heidelbergit.dk/feeds/3667594422499316078/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21992565&amp;postID=3667594422499316078' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/3667594422499316078'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/3667594422499316078'/><link rel='alternate' type='text/html' href='http://www.heidelbergit.dk/2011/06/flexcommand-cleartext.html' title='FlexCommand - cleartext'/><author><name>Jakob H. Heidelberg</name><uri>http://www.blogger.com/profile/05947807953068058636</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21992565.post-6586919536619604025</id><published>2009-05-24T10:25:00.022+02:00</published><updated>2009-05-24T13:40:29.949+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='group policy'/><category scheme='http://www.blogger.com/atom/ns#' term='password'/><category scheme='http://www.blogger.com/atom/ns#' term='group policies'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='group policy preferences'/><category scheme='http://www.blogger.com/atom/ns#' term='script'/><category scheme='http://www.blogger.com/atom/ns#' term='scripting'/><title type='text'>Unique passwords on local user accounts using VBS and Group Policy</title><content type='html'>The purpose of the script (&lt;a href="http://it-experts.dk/cfs-file.ashx/__key/CommunityServer.Components.PostAttachments/00.00.00.43.31/SetLocalPassword.v2.txt" target="_blank"&gt;SetLocalPassword.v2.txt&lt;/a&gt; - just rename to "SetLocalPassword.vbs") is, to ensure assignment of unique and complex password to a specific local user account (typically the local administrator account) on a Windows client in an Active Directory (AD) domain environment.&lt;br /&gt;&lt;br /&gt;The script can be used, if you (for one reason or another) want a specified local user account (e.g. administrator) to be active, but you still want to ensure, that the password used is unique for each computer, that the password is changed regularly (a given period of time) and that you are able to logon using the password at any time. Usually I would recommend customers to just deactivate the local administrator account, or set the password using Group Policy Preferences (preferably different passwords on different security areas), but if these solutions aren’t usable in the environment, “ChangeLocalPassword.vbs” could be the right solution.&lt;br /&gt;&lt;br /&gt;The intention is to execute the script as a "Startup Script” within a Group Policy Object (GPO), which is aimed at the relevant computer accounts in AD (as you probably know GPO’s can be filtered by AD security groups, WMI filters, Organizational Units (OU), domain and/or site). This way we ensure that the script is executed in ”SYSTEM" context, in which we can pretty much do anything on the local computer(s). Furthermore, SYSTEM can access network resources on behalf of the computer, as long as the resource in question (a file share in this case) allows “Domain Computers”, the specific AD computer account og “Authenticated Users” to gain access.&lt;br /&gt;&lt;br /&gt;It is crucial that the group ”Authenticated Users” is NOT given access to the network share – in that case all users within the domain will be able to read which passwords are used on all computers hit by the GPO. Share permissions (could be a hidden share$) can of course be set to Everyone Full Control, but NTFS must be set to allow only members of the group "Domain Computers" to read and write - domain administrators, and other relevant groups (e.g. helpdesk, supporters, backup account etc.) should also have read access. If you have a Distributed File System (DFS) up and running it could be used as the network share.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;u&gt;This illustrates the scripts cycle:&lt;/u&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://it-experts.dk/cfs-filesystemfile.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/zilent/7178.SetLocalPassword.v2.jpg"&gt;&lt;img style="WIDTH: 400px; HEIGHT: 240px; CURSOR: hand" border="0" alt="" src="http://it-experts.dk/cfs-filesystemfile.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/zilent/7178.SetLocalPassword.v2.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;1. The SYSTEM account is used by the computer during the boot process&lt;br /&gt;2. DNS and AD is contacted, and Group Policies are processed (machine policies)&lt;br /&gt;3. The GPO with the Startup Script is loaded&lt;br /&gt;4. The VBS script is executed (also in SYSTEM context)&lt;br /&gt;5. All activity is logged to a local log file (strLocalLog)&lt;br /&gt;6. Some preliminary checks are performed, this includes last modification of strLocalStamp and network access (strNetShare)&lt;br /&gt;7. A password (strNewPassword) is generated from 4 different criteras (intPasswordLength, intWantNumber, intWantLcase and intWantUcase)&lt;br /&gt;8. The username and password (clear text) is logged in a central log file (strnetFile)&lt;br /&gt;9. The chosen local user account (strLocalUser) is assigned the newly generated password (only if 8 was completed without any errors)&lt;br /&gt;10. A local timestamp file is created or modified if 9 was successfully completed&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;u&gt;Some important notes...&lt;/u&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;First and foremost one must ensure, that the script file the GPO is pointing to cannot be modified by others than the relevant administrators. If a user gets write access to that file, he or she can do anything (locally) on all machines executing the code. This is of course true for any GPO Startup Script used.&lt;br /&gt;&lt;br /&gt;Another important thing to note is, that if your users have local admin rights (I hope not), they will be able to “hack” the solution in a couple of ways. First of all they will of course be able to reset passwords for all local user accounts, but if they are a bit clever, they will also be able to take over the SYSTEM account (hint: AT command or PSEXEC) and access the network share we are using – and thus read or modify the log files with all the clear text passwords. But who in the world would allow users to be local administrators in the fist place, right?&lt;br /&gt;&lt;br /&gt;A Startup Script will time out if the script takes too long to execute, but we should not have such a problem with this script (normally executed in less than a second). Startup Scripts react differently depending on whether the “Always wait for the network at computer startup and logo” setting is set or not - the script should work in both cases though.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;u&gt;Let’s take a look at the customizable variables.&lt;/u&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;intDays&lt;/strong&gt; = 60&lt;br /&gt;- default: 60 days between password change&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;strNetShare&lt;/strong&gt; = "\\SERVER\SHARE\"&lt;br /&gt;- define as a share with the correct NTFS permissions set&lt;br /&gt;- is could be a hidden share, perhaps on a DFS&lt;br /&gt;- remember a trailing backslash (\) or the script will fail!&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;strLocalLog&lt;/strong&gt; = "C:\admpwd.log"&lt;br /&gt;- placement of the local log file of all activity (except for the password itself)&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;strLocalStamp&lt;/strong&gt; = "C:\admpwd.stp"&lt;br /&gt;- placement of the file used as a timestamp&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;strLocalUser&lt;/strong&gt; = "test-user"&lt;br /&gt;- name the user account to control (e.g. "administrator")&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;intPasswordLength&lt;/strong&gt; = 12&lt;br /&gt;- the number of characters the password should have (exactly)&lt;br /&gt;- must be at least the same as the domains minimum password length&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;intWantNumbers&lt;/strong&gt; = 1&lt;br /&gt;- set whether or not the password should contain numbers (complexity requirement)&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;intWantLcase&lt;/strong&gt; = 1&lt;br /&gt;- set whether or not the password should contain lowercase letters (complexity requirement)&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;intWantUcase&lt;/strong&gt; = 1&lt;br /&gt;- set whether or not the password should contain UPPERCASE letters (complexity requirement)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;u&gt;An example of the strLocalLog (default "c:\admpwd.log") local log file:&lt;br /&gt;&lt;/u&gt;&lt;/strong&gt;&lt;br /&gt;2009-05-22 13:20:26 [STARTED]&lt;br /&gt;2009-05-22 13:20:26 [VARIABLES - A]&lt;br /&gt;2009-05-22 13:20:26 - intDays : 1&lt;br /&gt;2009-05-22 13:20:26 - strNetShare : '\\SERVER\SHARE\'&lt;br /&gt;2009-05-22 13:20:26 - strLocalLog : 'C:\admpwd.log'&lt;br /&gt;2009-05-22 13:20:26 - strLocalStamp : 'C:\admpwd.stp'&lt;br /&gt;2009-05-22 13:20:26 - strLocalUser : 'test-user'&lt;br /&gt;2009-05-22 13:20:26 - strComputer : 'COMPUTER1'&lt;br /&gt;2009-05-22 13:20:26 - strNetFile : '\\SERVER\SHARE\COMPUTER1.log'&lt;br /&gt;2009-05-22 13:20:26 STATUS - No local stamp file, probably first run&lt;br /&gt;2009-05-22 13:20:26 SUCCESS - ALIVE:\\SERVER\SHARE\&lt;br /&gt;2009-05-22 13:20:26 [VARIABLES - B]&lt;br /&gt;2009-05-22 13:20:26 - intPasswordLength: 12&lt;br /&gt;2009-05-22 13:20:26 - intWantNumbers : 1&lt;br /&gt;2009-05-22 13:20:26 - intWantLcase : 1&lt;br /&gt;2009-05-22 13:20:26 - intWantUcase : 1&lt;br /&gt;2009-05-22 13:20:26 SUCCESS - PWD SET for: 'test-user'&lt;br /&gt;2009-05-22 13:20:26 SUCCESS - PWD written to: '\\SERVER\SHARE\COMPUTER1.log'&lt;br /&gt;2009-05-22 13:20:26 SUCCESS - TIME written to: 'C:\admpwd.stp'&lt;br /&gt;2009-05-22 13:20:26 [COMPLETED]&lt;br /&gt;&lt;br /&gt;2009-05-22 13:27:45 [STARTED]&lt;br /&gt;2009-05-22 13:27:45 [VARIABLES - A]&lt;br /&gt;2009-05-22 13:27:45 - intDays : 1&lt;br /&gt;2009-05-22 13:27:45 - strNetShare : '\\SERVER\SHARE\'&lt;br /&gt;2009-05-22 13:27:45 - strLocalLog : 'C:\admpwd.log'&lt;br /&gt;2009-05-22 13:27:45 - strLocalStamp : 'C:\admpwd.stp'&lt;br /&gt;2009-05-22 13:27:45 - strLocalUser : 'test-user'&lt;br /&gt;2009-05-22 13:27:45 - strComputer : 'COMPUTER1'&lt;br /&gt;2009-05-22 13:27:45 - strNetFile : '\\SERVER\SHARE\COMPUTER1.log'&lt;br /&gt;2009-05-22 13:27:45 STATUS - STAMP last modified: 22-05-2009 13:20:26&lt;br /&gt;2009-05-22 13:27:45 STATUS - STAMP younger than: 1 days!&lt;br /&gt;2009-05-22 13:27:45 [COMPLETED]&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;u&gt;An example of the strNetFile (named [computername].log) network log file:&lt;br /&gt;&lt;/u&gt;&lt;/strong&gt;&lt;br /&gt;2009-05-20 13:20:26 test-user : 'W57Ja6c5Xcus'&lt;br /&gt;2009-05-22 08:10:39 test-user : 'sdEc7s9Gbba8'&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;u&gt;Final note:&lt;/u&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;The code could most definitely be more optimized (and prettier), but it works like a charm (and pretty fast too) on Windows 2000, Windows XP, Windows Vista, Windows Server 2003, Windows Server 2008 and Windows 7.&lt;br /&gt;&lt;br /&gt;I hope it will turn out to be useful to someone out there - enjoy!&lt;br /&gt;&lt;br /&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21992565-6586919536619604025?l=www.heidelbergit.dk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.heidelbergit.dk/feeds/6586919536619604025/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21992565&amp;postID=6586919536619604025' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/6586919536619604025'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/6586919536619604025'/><link rel='alternate' type='text/html' href='http://www.heidelbergit.dk/2009/05/unique-passwords-on-local-useraccounts.html' title='Unique passwords on local user accounts using VBS and Group Policy'/><author><name>Jakob H. Heidelberg</name><uri>http://www.blogger.com/profile/05947807953068058636</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21992565.post-3909029613609180578</id><published>2009-01-09T10:52:00.005+01:00</published><updated>2009-01-09T11:12:56.676+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='VBA'/><category scheme='http://www.blogger.com/atom/ns#' term='Outlook'/><category scheme='http://www.blogger.com/atom/ns#' term='microsoft'/><category scheme='http://www.blogger.com/atom/ns#' term='script'/><category scheme='http://www.blogger.com/atom/ns#' term='scripting'/><title type='text'>Get email address of all users from all mails in an Outlook Folder</title><content type='html'>Hi,&lt;br /&gt;Ever had the need to extract all email adresses from a folder in Outlook?&lt;br /&gt;&lt;br /&gt;Let's say you want to make a reply to a lot of people who are not in your addressbook (contacts), but who have sent you an email which you have archived in a specific folder (or from your Sent items).&lt;br /&gt;&lt;br /&gt;I archive my emails all the time using one folder pr. "case", "customer" etc. - and sometimes it's ery useful to be able to write to everyone who had to do with the specific case. This is when it get's a bit frustrating - you have to find a way to get all the email-adresses, and only once!&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;u&gt;This is how to do it the easy way:&lt;/u&gt;&lt;/strong&gt;&lt;br /&gt;1. In Outlook press &lt;strong&gt;ALT+F11&lt;/strong&gt; (opens Microsoft Visual Basic console)&lt;br /&gt;2. Open "&lt;strong&gt;ThisOutlookSession&lt;/strong&gt;" from the Project tree (left menubar)&lt;br /&gt;3. &lt;strong&gt;Paste &lt;/strong&gt;the code below into the project (right window)&lt;br /&gt;4. Press &lt;strong&gt;F5 &lt;/strong&gt;to Run the code (execute)&lt;br /&gt;5. &lt;strong&gt;Select the folder&lt;/strong&gt; you want to use and hit OK (might take some time to complete)&lt;br /&gt;6. Press &lt;strong&gt;ALT+G&lt;/strong&gt; and then copy the email-addresses from the "immediate" window (debug window)&lt;br /&gt;&lt;br /&gt;Oh, and remember to use the &lt;strong&gt;BCC field&lt;/strong&gt; if they shouldn't see eachothers email addresses (in the case you want to send an email to all of them).&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;u&gt;CODE:&lt;/u&gt;&lt;/strong&gt;&lt;br /&gt;&lt;em&gt;Sub GetEmailAddressesInFolder()&lt;br /&gt;Dim objFolder As MAPIFolder&lt;/em&gt;&lt;br /&gt;&lt;em&gt;Dim strEmail As String&lt;/em&gt;&lt;br /&gt;&lt;em&gt;Dim strEmails As String&lt;/em&gt;&lt;br /&gt;&lt;em&gt;Dim objItem As Object&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;em&gt;Set objFolder = Application.GetNamespace("Mapi").PickFolder&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;em&gt;For Each objItem In objFolder.Items&lt;/em&gt;&lt;br /&gt;&lt;em&gt;If objItem.Class = olMail Then&lt;/em&gt;&lt;br /&gt;&lt;em&gt;strEmail = objItem.SenderEmailAddress&lt;/em&gt;&lt;br /&gt;&lt;em&gt;If InStr(strEmails, strEmail) = 0 Then strEmails = strEmails + strEmail + ";"&lt;/em&gt;&lt;br /&gt;&lt;em&gt;End If&lt;/em&gt;&lt;br /&gt;&lt;em&gt;Next&lt;/em&gt;&lt;br /&gt;&lt;em&gt;Debug.Print strEmails&lt;/em&gt;&lt;br /&gt;&lt;em&gt;End Sub&lt;/em&gt;&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;The above code is tested on Microsoft Outlook 2007, but should work on older Office systems too.&lt;br /&gt;&lt;br /&gt;Original source &lt;a href="http://msmvps.com/blogs/omar/archive/2006/08/09/get-email-address-of-all-users-from-all-mails-in-outlook-folder.aspx"&gt;here&lt;/a&gt; - I just had to modify the code a bit.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Bye for now!&lt;br /&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21992565-3909029613609180578?l=www.heidelbergit.dk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.heidelbergit.dk/feeds/3909029613609180578/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21992565&amp;postID=3909029613609180578' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/3909029613609180578'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/3909029613609180578'/><link rel='alternate' type='text/html' href='http://www.heidelbergit.dk/2009/01/get-email-address-of-all-users-from-all.html' title='Get email address of all users from all mails in an Outlook Folder'/><author><name>Jakob H. Heidelberg</name><uri>http://www.blogger.com/profile/05947807953068058636</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21992565.post-2173400249826051521</id><published>2008-11-05T12:21:00.001+01:00</published><updated>2008-11-05T12:21:08.727+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TechEd'/><category scheme='http://www.blogger.com/atom/ns#' term='group policy'/><category scheme='http://www.blogger.com/atom/ns#' term='srp'/><category scheme='http://www.blogger.com/atom/ns#' term='microsoft'/><category scheme='http://www.blogger.com/atom/ns#' term='AppLocker'/><title type='text'>Software Restriction in Windows 7</title><content type='html'>&lt;p&gt;&lt;em&gt;These are some quick notes from a session on AppLocker by Paul A. Cooke, Tech-Ed EMEA 2008:&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;As you may have seen, I’ve written a few articles on Software Restriction Policy (SRP) under Windows XP and Windows Vista for &lt;a href="http://www.windowsecurity.com" target="_blank"&gt;www.windowsecurity.com&lt;/a&gt; (see below). I’m very happy to tell you, that Microsoft now improved this functionality and renamed it into: &lt;strong&gt;AppLocker&lt;/strong&gt;!&lt;/p&gt;  &lt;p&gt;Unfortunately I cannot bring you any screenshots (because of NDA), but I can tell you a few things about the basic functionality. With AppLocker you can more easily eliminate unwanted and unknown applications in your Windows (7) environment. You can enforce application standardization – both from a security (malware), and from a management point of view (licensing &amp;amp; user control).&lt;/p&gt;  &lt;p&gt;What most organizations try to do these days, it to limit users to be standard users (non-administrators) on their local machines – however this is actually not enough to feel secure as an IT administrator. Running as standard user is &lt;u&gt;not&lt;/u&gt; the solution to all of our problems. Many applications can do bad stuff, even within user context – like stealing data, deleting data, manipulating data, encrypting data, creating bot-nets, send spam, social engineering etc. etc. This is true for applications that install in user context (like Google Chrome), or regular executables that don’t actually install – they just run!&lt;/p&gt;  &lt;p&gt;If you want to control applications like that, what can run and what cannot – then you need another approach. AppLocker comes to the rescue!&lt;/p&gt;  &lt;p&gt;   &lt;br /&gt;AppLocker has been build around digital signatures – signing of software executables and DLLs. This was also an option in SRP under Windows XP, were we had path, filename, HASH &amp;amp; certificate rule, but it was pretty hard to manage and enforce back then. With Windows 7, a new GUI has been added to the group policy editor to support easy creation of software rules. We have 3 types of rules:     &lt;br /&gt;- &lt;strong&gt;Allow rules&lt;/strong&gt;: same as Whitelisting (‘known good’ software)     &lt;br /&gt;- &lt;strong&gt;Deny rules&lt;/strong&gt;: same as Blacklisting (‘known bad’ software)     &lt;br /&gt;- &lt;strong&gt;Exceptions&lt;/strong&gt;: exclusion from allow or deny rules&lt;/p&gt;  &lt;p&gt;Allow rules are of course the recommended approach – the “&lt;strong&gt;default deny all applications&lt;/strong&gt;” rule (Whitelisting), but with specific applications the network administrators wants to allow users to run. As an administrator, you get granular control of specific applications, enforcing who can run and/or install them (if they have the appropriate rights and permissions).&lt;/p&gt;  &lt;p&gt;The administration is done by group policy under &lt;em&gt;&lt;strong&gt;Computer Configuration &amp;gt; Application Control Policies&lt;/strong&gt;&lt;/em&gt;, but strangely enough you have to put in affected users and groups (still unclear whether or not the SYSTEM account is still excluded from SRP checks). So this is actually Computer policies that are able to hit users, like loopback or group policy preferences.&lt;/p&gt;  &lt;p&gt;You can create &lt;strong&gt;multiple rule sets&lt;/strong&gt; and take advantage of specific attributes, like app version (equal/above/below X.0.0.0), filename (executable name), product publisher (the valid root certificate used to sign), product suite (like “Microsoft Office 2007”) – and wildcards seems to be supported still. &lt;/p&gt;  &lt;p&gt;You can control executables, installers (MSI), scripts, and DLLs, using certificates (publisher), HASH or path rules. The disadvantage of using HASH rules is, that the HASH will change if the application is updated, certificate/publisher rules are much more flexible because the signature is still going to be there (unless the developers totally mess up). So always try to go for publisher rules, certificates are here to stay :)&lt;/p&gt;  &lt;p&gt;Can be run in 3 modes: Enforce policy, Enforce Policy using Group Policy Inheritance&amp;#160; and Audit Only mode! The latter is pretty cool, as you can configure a Software Restriction Policy, and test it out before you go “live”.&lt;/p&gt;  &lt;p&gt;AppLocker supports import and export of rules, which can be very useful, but one of the best new features is, that there’s no need to create all the rules manually – you have the option to “automatically generate rule”, this feature will analyze a “reference machine” (not sure if this has to be the local machine yet) and files in a given folder on that machine (not sure if this can be a share yet). You can compare this to a “snapshot” feature, take all files in this folder (and subfolders), and make an allow rule from that (certificate based preferably).&lt;/p&gt;  &lt;p&gt;The new rule creation tools and wizards seem pretty straight forward – but you really need to think about the SRP design before you go for it, and test intensively, or else you’ll end up in serious trouble ;-)&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;I just can’t wait to test this deeply and bring you more information!&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;u&gt;&lt;strong&gt;Previous article series on SRP:&lt;/strong&gt;&lt;/u&gt;     &lt;br /&gt;&lt;a title="Default Deny All Applications (Part 1)" href="http://www.windowsecurity.com/articles/Default-Deny-All-Applications-Part1.html" target="_blank"&gt;Default Deny All Applications (Part 1)&lt;/a&gt;     &lt;br /&gt;&lt;a title="Default Deny All Applications (Part 2)" href="http://www.windowsecurity.com/articles/Default-Deny-All-Applications-Part2.html" target="_blank"&gt;Default Deny All Applications (Part 2)&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;u&gt;&lt;strong&gt;Microsoft AppLocker description:&lt;/strong&gt;&lt;/u&gt;     &lt;br /&gt;&lt;a title="http://www.microsoft.com/windows/products/windowsvista/enterprise/windows7.mspx?Tab=AppLocker" href="http://www.microsoft.com/windows/products/windowsvista/enterprise/windows7.mspx?Tab=AppLocker" target="_blank"&gt;http://www.microsoft.com&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21992565-2173400249826051521?l=www.heidelbergit.dk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.heidelbergit.dk/feeds/2173400249826051521/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21992565&amp;postID=2173400249826051521' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/2173400249826051521'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/2173400249826051521'/><link rel='alternate' type='text/html' href='http://www.heidelbergit.dk/2008/11/software-restriction-in-windows-7.html' title='Software Restriction in Windows 7'/><author><name>Jakob H. Heidelberg</name><uri>http://www.blogger.com/profile/05947807953068058636</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21992565.post-7104071634525750149</id><published>2008-11-05T11:07:00.001+01:00</published><updated>2008-11-05T11:07:29.930+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TechEd'/><category scheme='http://www.blogger.com/atom/ns#' term='group policy'/><category scheme='http://www.blogger.com/atom/ns#' term='BitLocker'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows 7'/><category scheme='http://www.blogger.com/atom/ns#' term='microsoft'/><category scheme='http://www.blogger.com/atom/ns#' term='UAC'/><title type='text'>User Account Control in Windows 7</title><content type='html'>&lt;p&gt;&lt;em&gt;These are some quick notes from a session on UAC by Paul A. Cooke, Tech-Ed EMEA 2008:&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;&lt;em&gt;&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;Microsoft Windows 7 will reduce the number of OS applications and tasks, that require elevation – this has been done by re-factoring apps and tasks into elevated and non-elevated pieces.&lt;/p&gt;  &lt;p&gt;UAC v2 will provide a more flexible prompt behavior for administrators, also administrators will see less UAC elevation prompts.&lt;/p&gt;  &lt;p&gt;Users can do even more as standard user (eg. parts of Bitlocker, Windows Update etc.), they will also be able to ‘read’ system settings without needing to elevate.&lt;/p&gt;  &lt;p&gt;Windows 7 will be better spotting human vs. application changes, this way “human administrator” changes will be allowed without too many prompts.&lt;/p&gt;  &lt;p&gt;UAC can now easily be graduated into 4 levels (from the strict Vista default to totally off) - everything can of course be handled using group policy.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;To me this is all pretty cool – but to be honest, I’m one of those weird guys, who don’t care about Vista UAC prompts… I just press ALT+C… How hard can it be? ;-)&lt;/p&gt;  &lt;p&gt;.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21992565-7104071634525750149?l=www.heidelbergit.dk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.heidelbergit.dk/feeds/7104071634525750149/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21992565&amp;postID=7104071634525750149' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/7104071634525750149'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/7104071634525750149'/><link rel='alternate' type='text/html' href='http://www.heidelbergit.dk/2008/11/user-account-control-in-windows-7.html' title='User Account Control in Windows 7'/><author><name>Jakob H. Heidelberg</name><uri>http://www.blogger.com/profile/05947807953068058636</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21992565.post-1543684766442405651</id><published>2008-10-20T10:01:00.002+02:00</published><updated>2008-10-20T10:03:54.200+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='script'/><category scheme='http://www.blogger.com/atom/ns#' term='scripting'/><title type='text'>I just love sharing!</title><content type='html'>Just found this - using Google Alerts of course :)&lt;br /&gt;&lt;br /&gt;&lt;em&gt;I made little modifications on this script created by Jakob Heidelberg to search for printers manually created on user profiles. This is very usefull when you wanna ensure that eveybody has only auto created printers, from Citrix or ThinPrint.&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;em&gt;This script load ntuser.dat on each profile, check some registry keys, write a log and unload ntuser.dat. Some users can have problems to load their profiles if you use this script on the same time that they try logon.&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.robertoalves.com/?p=58"&gt;http://www.robertoalves.com/?p=58&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I just love sharing!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21992565-1543684766442405651?l=www.heidelbergit.dk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.heidelbergit.dk/feeds/1543684766442405651/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21992565&amp;postID=1543684766442405651' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/1543684766442405651'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/1543684766442405651'/><link rel='alternate' type='text/html' href='http://www.heidelbergit.dk/2008/10/i-just-love-sharing.html' title='I just love sharing!'/><author><name>Jakob H. Heidelberg</name><uri>http://www.blogger.com/profile/05947807953068058636</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21992565.post-2502838474519772369</id><published>2008-10-12T17:48:00.001+02:00</published><updated>2008-10-12T17:50:59.285+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='windows'/><title type='text'>Why does standby overrule shutdown?</title><content type='html'>&lt;p&gt;Well, I’m a Microsoft kinda guy – but I do have a problem with one “feature” which has been part of the Windows OS for some time…&lt;/p&gt;  &lt;p&gt;Normally I change the default behavior under Power Setting, so that Windows does NOT start a STANDBY process when I close the lid of my laptops – but I haven’t done it on all of my machines, and under every user profile I have (and customers have the same issue).&lt;/p&gt;  &lt;p&gt;So, what happens is, that you are done for the day, and then you start a SHUTDOWN process like normally, and then you close the laptops lid – a STANDBY process then starts – Doh!&lt;/p&gt;  &lt;p&gt;That means, the SHUTDOWN process is put into STANDBY mode, and the next time you boot your laptop, the machine state resumes, just to finalize the SHUTDOWN process… And then you have to boot you machine to get started – hmmm, I definitely don’t like it!&lt;/p&gt;  &lt;p&gt;So what should happen? Well, when a SHUTDOWN process had started, a STANDBY process should NOT be able to “take over” – just let me close the laptop lid and continue the already started SHUTDOWN process, thanx :)&lt;/p&gt;  &lt;p&gt;OK, I admit that it’s only a problem when I haven’t changed the default Power Settings, but I can’t be the only human being in this world with that particular problem!?!? Why would you EVER want a SHUTDOWN process to be put into STANDBY mode?&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;BTW – I have seen, that Mac and Ubuntu people have the same issue on some version – don’t know if it has been fixed on those OS – I have the problem on all the different Windows systems I run on laptops.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21992565-2502838474519772369?l=www.heidelbergit.dk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.heidelbergit.dk/feeds/2502838474519772369/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21992565&amp;postID=2502838474519772369' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/2502838474519772369'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/2502838474519772369'/><link rel='alternate' type='text/html' href='http://www.heidelbergit.dk/2008/10/why-does-standby-overrule-shutdown.html' title='Why does standby overrule shutdown?'/><author><name>Jakob H. Heidelberg</name><uri>http://www.blogger.com/profile/05947807953068058636</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21992565.post-5323401415988259299</id><published>2008-10-02T13:05:00.000+02:00</published><updated>2008-10-02T13:07:16.322+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='technet'/><category scheme='http://www.blogger.com/atom/ns#' term='microsoft'/><category scheme='http://www.blogger.com/atom/ns#' term='it-experts.dk'/><title type='text'>Microsoft: IT-experts.dk online forum er nu opdateret</title><content type='html'>&lt;p&gt;Citat:&lt;/p&gt;&lt;p&gt;&lt;em&gt;Microsoft Danmark tror meget på lokale danske it netværk.  Vi vil gerne hjælpe danske it professionelle med at knytte professionelle forbindelser og have et forum for tekniske spørgsmål og svar, hvor ikke-Microsoft ansatte bidrager med deres perspektiver.&lt;br /&gt;&lt;br /&gt;IT-experts.dk er et gratis online forum for danske IT professionelle. Sitet har haft stor succes med en åben stil, hvor alle medlemmer kan stille tekniske spørgsmål og dele sin viden med andre. Efter en nylig opdatering af sitet er der kommet rigtig mange nye features til, såsom RSS feeds i utallige afskygninger, blogs, OpenID og meget andet. Hvis du ikke allerede er oprettet som bruger på den nye platform, så gør det nu og her: &lt;/em&gt;&lt;a href="http://it-experts.dk/medlem"&gt;&lt;em&gt;http://it-experts.dk/medlem&lt;/em&gt;&lt;/a&gt;&lt;em&gt;.&lt;br /&gt;&lt;br /&gt;De typiske brugere er professionelle IT konsulenter, specialister, administratorer, supportere og arkitekter indenfor messaging, sikkerhed, infrastruktur, virtualisering, terminal services og lignende. Der er en overvejende hovedvægt på Microsoft platformen, men der er bestemt også plads til fokus på andre områder indenfor IT verdenen.&lt;br /&gt;&lt;br /&gt;Bag IT-experts.dk står en række dygtige danske IT konsulenter, MVP’ere og Microsoft Technet Influenters, som yder en stor indsats for at holde sitet kørende, besvare spørgsmål, blogge, skrive artikler og lignende, alt på frivillig basis.&lt;br /&gt;&lt;br /&gt;Vi ønsker IT-experts.dk tillykke med den nye platform og vil hermed opfordre til at deltage i det største danske Microsoft community for IT professionelle: &lt;/em&gt;&lt;a href="http://www.it-experts.dk/"&gt;&lt;em&gt;www.it-experts.dk&lt;/em&gt;&lt;/a&gt;&lt;em&gt;.&lt;/em&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Kilde: &lt;a href="http://blogs.technet.com/dkitpro/archive/2008/10/02/it-experts-dk-online-forum-er-nu-opdateret.aspx"&gt;http://blogs.technet.com/dkitpro&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21992565-5323401415988259299?l=www.heidelbergit.dk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.heidelbergit.dk/feeds/5323401415988259299/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21992565&amp;postID=5323401415988259299' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/5323401415988259299'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/5323401415988259299'/><link rel='alternate' type='text/html' href='http://www.heidelbergit.dk/2008/10/microsoft-it-expertsdk-online-forum-er.html' title='Microsoft: IT-experts.dk online forum er nu opdateret'/><author><name>Jakob H. Heidelberg</name><uri>http://www.blogger.com/profile/05947807953068058636</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21992565.post-8529127826234437031</id><published>2008-07-06T16:45:00.001+02:00</published><updated>2008-07-06T16:45:22.679+02:00</updated><title type='text'>Windows SteadyState 2.5 is out there!</title><content type='html'>&lt;p&gt;This is great news - I've been writing a few articles on this baby, but now we have a brand new version available for download!!!&lt;/p&gt;  &lt;p&gt;   &lt;br /&gt;Go ahead and read some more:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.windowsecurity.com/articles/Protect-Public-Computers-Windows-SteadyState-Part1.html" target="_blank"&gt;Protect Public Computers with Windows SteadyState, Part 1&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.windowsecurity.com/articles/Protect-Public-Computers-Windows-SteadyState-Part2.html" target="_blank"&gt;Protect Public Computers with Windows SteadyState, Part 2&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=6d130662-c084-4356-906f-426bc814582a&amp;amp;DisplayLang=en" target="_blank"&gt;Windows SteadyState 2.5 Technical FAQ&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=f829bb8b-c7a9-426b-a7a4-2b504a6238d2&amp;amp;DisplayLang=en" target="_blank"&gt;Windows SteadyState 2.5 Handbook&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Download Windows SteadyState 2.5 &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=d077a52d-93e9-4b02-bd95-9d770ccdb431&amp;amp;DisplayLang=en" target="_blank"&gt;right here!&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;em&gt;Enjoy!&lt;/em&gt;    &lt;br /&gt;&lt;/p&gt;  &lt;p&gt;.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21992565-8529127826234437031?l=www.heidelbergit.dk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.heidelbergit.dk/feeds/8529127826234437031/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21992565&amp;postID=8529127826234437031' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/8529127826234437031'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/8529127826234437031'/><link rel='alternate' type='text/html' href='http://www.heidelbergit.dk/2008/07/windows-steadystate-25-is-out-there.html' title='Windows SteadyState 2.5 is out there!'/><author><name>Jakob H. Heidelberg</name><uri>http://www.blogger.com/profile/05947807953068058636</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21992565.post-6025387624072891736</id><published>2008-05-27T07:02:00.007+02:00</published><updated>2008-05-27T07:13:36.112+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Windows Vista'/><category scheme='http://www.blogger.com/atom/ns#' term='BitLocker'/><category scheme='http://www.blogger.com/atom/ns#' term='vista'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Great Vista hack... Somebody call Mr. Bitlocker!</title><content type='html'>We've seen hacks like this before, no doubt about it - but it's a really nice trick which you gotta love (and hate) - &lt;a href="http://www.offensive-security.com/movies/vistahack/vistahack.html"&gt;check it out here&lt;/a&gt;!&lt;br /&gt;&lt;br /&gt;So, basically this hack requires &lt;a href="http://www.microsoft.com/technet/archive/community/columns/security/essays/10imlaws.mspx?mfr=true"&gt;PHYSICAL ACCESS&lt;/a&gt; to the harddrive, using BackTrack (or some other boot utility capable of reading/writing NTFS) the file Utilman.Exe in \Windows\System32 is replaced with Cmd.exe - after a reboot, at the logon screen, if Utilman is called (by hitting Win-key + U) you'll get a nice command prompt running under SYSTEM credentials - pretty powerfull... From there the only limit is your imagination!&lt;br /&gt;&lt;br /&gt;Yes, Bitlocker protects us from attacks like these - so somebody please call Mr. Bitlocker!&lt;br /&gt;&lt;br /&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21992565-6025387624072891736?l=www.heidelbergit.dk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.heidelbergit.dk/feeds/6025387624072891736/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21992565&amp;postID=6025387624072891736' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/6025387624072891736'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/6025387624072891736'/><link rel='alternate' type='text/html' href='http://www.heidelbergit.dk/2008/05/great-vista-hack-somebody-call-mr.html' title='Great Vista hack... Somebody call Mr. Bitlocker!'/><author><name>Jakob H. Heidelberg</name><uri>http://www.blogger.com/profile/05947807953068058636</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21992565.post-1211934769853596339</id><published>2008-04-29T09:13:00.001+02:00</published><updated>2008-04-29T09:13:37.503+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='group policy'/><category scheme='http://www.blogger.com/atom/ns#' term='microsoft'/><title type='text'>Group Policy Survival Guide</title><content type='html'>&lt;p&gt;Yes, it's true - there's a new GP guide out there from Microsoft...&lt;/p&gt;  &lt;p&gt;Check it out &lt;a href="http://go.microsoft.com/fwlink/?LinkId=117638" target="_blank"&gt;here&lt;/a&gt; - it's pretty cool!&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/grouppolicy/archive/2008/04/28/you-will-survive.aspx" target="_blank"&gt;&amp;lt;source&amp;gt;&lt;/a&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21992565-1211934769853596339?l=www.heidelbergit.dk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.heidelbergit.dk/feeds/1211934769853596339/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21992565&amp;postID=1211934769853596339' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/1211934769853596339'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/1211934769853596339'/><link rel='alternate' type='text/html' href='http://www.heidelbergit.dk/2008/04/group-policy-survival-guide.html' title='Group Policy Survival Guide'/><author><name>Jakob H. Heidelberg</name><uri>http://www.blogger.com/profile/05947807953068058636</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21992565.post-7732728603873763180</id><published>2008-04-22T14:47:00.001+02:00</published><updated>2008-04-22T14:47:11.319+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='group policy'/><category scheme='http://www.blogger.com/atom/ns#' term='MVP'/><category scheme='http://www.blogger.com/atom/ns#' term='microsoft'/><title type='text'>No place like 127.0.0.1</title><content type='html'>&lt;p&gt;So, I'm back home from a great trip to Seattle, Washington, US. The MVP Summit 2008 was a cool experience with lots of info and room for dialog with the product teams at the Microsoft Campus in Redmond.&lt;/p&gt;  &lt;p&gt;We had some awesome talks on the future of Group Policy and I would really like to share it with you, but because of Non-Disclosure Agreements 'n' stuff I can't really say anything - yet.&lt;/p&gt;  &lt;p&gt;Seattle is a very interesting city with a lot of great restaurants, nice architecture and friendly people. I had 2&amp;#189; day to spend after the summit and even though I was missing my family Seattle took great care of me :)&lt;/p&gt;  &lt;p&gt;Anyway, I hope to go back there next year - better prepared for jetlag (which basically means I'll travel a few days before the event next time) - but, that all depends on how much time I get to share information with you guys/girls out there... No sharing, no MVP award - that's the rule ya' know ;-)&lt;/p&gt;  &lt;p&gt;Thanx to the GP team and the other MVPs for a great experience!&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21992565-7732728603873763180?l=www.heidelbergit.dk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.heidelbergit.dk/feeds/7732728603873763180/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21992565&amp;postID=7732728603873763180' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/7732728603873763180'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/7732728603873763180'/><link rel='alternate' type='text/html' href='http://www.heidelbergit.dk/2008/04/no-place-like-127001.html' title='No place like 127.0.0.1'/><author><name>Jakob H. Heidelberg</name><uri>http://www.blogger.com/profile/05947807953068058636</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21992565.post-7029008372084218310</id><published>2008-04-10T23:43:00.001+02:00</published><updated>2008-04-10T23:43:15.335+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SteadyState'/><category scheme='http://www.blogger.com/atom/ns#' term='windowsecurity.com'/><category scheme='http://www.blogger.com/atom/ns#' term='article'/><category scheme='http://www.blogger.com/atom/ns#' term='microsoft'/><title type='text'>Protect Public Computers with Windows SteadyState (Part 2)</title><content type='html'>&lt;p&gt;&lt;a href="http://www.windowsecurity.com/articles/Protect-Public-Computers-Windows-SteadyState-Part2.html" target="_blank"&gt;This&lt;/a&gt; is my 2nd article that deals with the Windows SteadyState product and how use it to protect public computers!&lt;/p&gt;  &lt;p&gt;If you haven't read part 1, please read it &lt;a href="http://windowsecurity.com/articles/Protect-Public-Computers-Windows-SteadyState-Part1.html" target="_blank"&gt;here&lt;/a&gt;...&lt;/p&gt;  &lt;p&gt;Enjoy!&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21992565-7029008372084218310?l=www.heidelbergit.dk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.heidelbergit.dk/feeds/7029008372084218310/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21992565&amp;postID=7029008372084218310' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/7029008372084218310'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/7029008372084218310'/><link rel='alternate' type='text/html' href='http://www.heidelbergit.dk/2008/04/protect-public-computers-with-windows.html' title='Protect Public Computers with Windows SteadyState (Part 2)'/><author><name>Jakob H. Heidelberg</name><uri>http://www.blogger.com/profile/05947807953068058636</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21992565.post-7356179512407069443</id><published>2008-04-09T09:02:00.001+02:00</published><updated>2008-04-09T09:02:39.186+02:00</updated><title type='text'>StarterGPOs available for download</title><content type='html'>&lt;p&gt;Microsoft introduced the concept of StarterGPOs with GPMC version 2.0 in Vista SP1 + RSAT and Windows Server 2008. The idea is that it should be easy to share Group Policy settings, read more &lt;a href="http://www.windowsecurity.com/articles/Group-Policy-related-changes-Windows-Server-2008-Part1.html" target="_blank"&gt;here&lt;/a&gt;!&lt;/p&gt;  &lt;p&gt;The GREAT thing is that Microsoft has now released some StarterGPO samples - go download the first shipment &lt;a href="http://go.microsoft.com/fwlink/?LinkId=115690" target="_blank"&gt;here&lt;/a&gt;!&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21992565-7356179512407069443?l=www.heidelbergit.dk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.heidelbergit.dk/feeds/7356179512407069443/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21992565&amp;postID=7356179512407069443' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/7356179512407069443'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/7356179512407069443'/><link rel='alternate' type='text/html' href='http://www.heidelbergit.dk/2008/04/startergpos-available-for-download.html' title='StarterGPOs available for download'/><author><name>Jakob H. Heidelberg</name><uri>http://www.blogger.com/profile/05947807953068058636</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21992565.post-9179100241573936261</id><published>2008-04-05T09:34:00.001+02:00</published><updated>2008-04-05T09:34:11.865+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='microsoft'/><title type='text'>Security White Papers &amp; Guides for download</title><content type='html'>&lt;p&gt;This post gives you some links to online available White Papers and Guides from the Microsoft download site - I hope you can use some of it to analyze and protect your own network(s)!&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;New Security White Paper of April 2008:&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;em&gt;&amp;quot;The Microsoft US National Security Team is composed of strategic security advisors who work with Microsoft customers, partners, MS internal constituencies and the information security industry to promote the adoption of security processes and technologies. The NST also focuses on driving vertical security solutions for a wide range of industries. To this end, the NST has produced a number of white papers that address the specific security needs of particular industries, such as the professional services and financial services industries.&amp;quot;&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;You will find these papers:&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;- Electronic Signature Assurance and the Digital Chain-of-Evidence   &lt;br /&gt;- Enabling Secure Collaboration for Professional Services Firms    &lt;br /&gt;- Establishing the Foundation of Authenticity for Electronically Stored Information    &lt;br /&gt;- Information Protection Strategies For Financial Services    &lt;br /&gt;- Optimizing Branch Office Security and Productivity in the Financial Services Sector    &lt;br /&gt;- Secure Software Development for the Financial Services Industry    &lt;br /&gt;- Securing the Retail Store-Securing the Data&lt;/p&gt;  &lt;p&gt;Go get them &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=4cd29b01-eed8-45f5-ab1e-ff1e1aef7b22&amp;amp;DisplayLang=en" target="_blank"&gt;here&lt;/a&gt;!&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Also, go check out the &amp;quot;&lt;strong&gt;Fundamental Computer Investigation Guide for Windows&lt;/strong&gt;&amp;quot;:&lt;/p&gt;  &lt;p&gt;&lt;em&gt;&amp;quot;The Fundamental Computer Investigation Guide for Windows Solution Accelerator is intended for IT professionals who need to effectively conduct investigations of Microsoft&amp;#174; Windows&amp;#174;&amp;#8211;based computers in their organizations. It provides a computer investigation model as well as process and best practice information. The guide also provides a fictitious example of an investigation that involves unauthorized access to confidential information. This investigation uses the provided guidance and demonstrates the use of numerous tools. Information is also included about how to configure a lab to create the example scenario. An appendix provides information about how to prepare for computer investigations, sample worksheets, contact information for reporting different types of computer-related crimes to appropriate law enforcement agencies, and lists of useful tools.&amp;quot;&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;Go get that document right &lt;a href="http://www.microsoft.com/downloads/details.aspx?familyid=71B986EC-B3F1-4C14-AC70-EC0EB8ED9D57&amp;amp;displaylang=en" target="_blank"&gt;here&lt;/a&gt;!&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;And finally, what about checking out the &amp;quot;&lt;strong&gt;The Security Risk Management Guide&lt;/strong&gt;&amp;quot;?:&lt;/p&gt;  &lt;p&gt;&lt;em&gt;&amp;quot;The Security Risk Management Guide explains how to conduct each phase of a security risk management project and create an ongoing process that drives the organization towards the most useful and cost-effective controls to mitigate security risks. It incorporates real-world experiences from Microsoft IT and also includes input from Microsoft customers and partners.      &lt;br /&gt;This guide references many industry accepted standards for managing security risks. It is an important example of Microsoft's commitment to delivering quality guidance to help customers secure their IT infrastructures.&lt;/em&gt;&amp;quot; &lt;/p&gt;  &lt;p&gt;That document is available right &lt;a href="http://www.microsoft.com/downloads/details.aspx?familyid=C782B6D3-28C5-4DDA-A168-3E4422645459&amp;amp;displaylang=en" target="_blank"&gt;here&lt;/a&gt;!&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Enjoy...&lt;/p&gt;  &lt;p&gt;.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21992565-9179100241573936261?l=www.heidelbergit.dk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.heidelbergit.dk/feeds/9179100241573936261/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21992565&amp;postID=9179100241573936261' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/9179100241573936261'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/9179100241573936261'/><link rel='alternate' type='text/html' href='http://www.heidelbergit.dk/2008/04/security-white-papers-guides-for.html' title='Security White Papers &amp;amp; Guides for download'/><author><name>Jakob H. Heidelberg</name><uri>http://www.blogger.com/profile/05947807953068058636</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21992565.post-1391746328673917022</id><published>2008-04-01T19:25:00.001+02:00</published><updated>2008-04-05T11:52:32.202+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='MVP'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='microsoft'/><title type='text'>MVP:Enterprise Security</title><content type='html'>&lt;p&gt;Yup, a wish came through - I'm now an MVP!&lt;/p&gt;  &lt;p&gt;Receiving the Microsoft Most Valuable Professional Award is a great honor and much appreciated - thank you.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.heidelbergit.dk/Screenshots/MVPEnterpriseSecurity_1112D/MVP_Horizontal_FullColor_small.png"&gt;&lt;img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="59" alt="MVP_Horizontal_FullColor_small" src="http://www.heidelbergit.dk/Screenshots/MVPEnterpriseSecurity_1112D/MVP_Horizontal_FullColor_small_thumb.png" width="144" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;Sharing Rocks - Information wants to be free!&lt;/p&gt;  &lt;p&gt;&lt;em&gt;Time to get a beer :-)&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21992565-1391746328673917022?l=www.heidelbergit.dk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.heidelbergit.dk/feeds/1391746328673917022/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21992565&amp;postID=1391746328673917022' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/1391746328673917022'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/1391746328673917022'/><link rel='alternate' type='text/html' href='http://www.heidelbergit.dk/2008/04/mvpenterprise-security.html' title='MVP:Enterprise Security'/><author><name>Jakob H. Heidelberg</name><uri>http://www.blogger.com/profile/05947807953068058636</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21992565.post-4340897892639126934</id><published>2008-04-01T00:03:00.000+02:00</published><updated>2008-04-01T00:08:00.037+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='download'/><category scheme='http://www.blogger.com/atom/ns#' term='Core'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows Server 2008'/><title type='text'>Core with a GUI</title><content type='html'>&lt;p&gt;If you have messed around in Windows Server 2008 Core installation you've probably had some challenges along the way - like: how do I join a computer to the domain using a command prompt, how can I add Features, tweak the firewall etc. Well, a nice and very useful solution to many of the basic configuration tasks is out there - and it's free of course!&lt;/p&gt;  &lt;p&gt;Go check out &lt;a href="http://blogs.microsoft.co.il/blogs/guyt/archive/2008/03/22/windows-server-core-coreconfigurator-to-the-rescue.aspx" target="_blank"&gt;CoreConfigurator&lt;/a&gt; (Server Core Configurator) written by Guy Teverovsky - look how easy it is and stop acting like a geek sent back to the early 90s :-)&lt;/p&gt;  &lt;p&gt;&lt;img src="http://blogs.microsoft.co.il/blogs/guyt/WindowsLiveWriter/ConfiguringWindowsServerCoreCoreConfigur_118D3/main.jpg" /&gt; &lt;/p&gt;  &lt;p&gt;Download &lt;a href="http://blogs.microsoft.co.il/files/folders/guyt/entry68860.aspx" target="_blank"&gt;here&lt;/a&gt; and enjoy!&lt;/p&gt;  &lt;p&gt;.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21992565-4340897892639126934?l=www.heidelbergit.dk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.heidelbergit.dk/feeds/4340897892639126934/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21992565&amp;postID=4340897892639126934' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/4340897892639126934'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/4340897892639126934'/><link rel='alternate' type='text/html' href='http://www.heidelbergit.dk/2008/04/core-with-gui.html' title='Core with a GUI'/><author><name>Jakob H. Heidelberg</name><uri>http://www.blogger.com/profile/05947807953068058636</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21992565.post-7977405309565815729</id><published>2008-03-25T22:51:00.001+01:00</published><updated>2008-03-25T23:06:46.218+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='RSAT'/><category scheme='http://www.blogger.com/atom/ns#' term='gp preferences'/><category scheme='http://www.blogger.com/atom/ns#' term='group policy preferences'/><title type='text'>Remote Server Administration Tools Available!</title><content type='html'>&lt;p&gt;You can now download the RSAT toolkit for Windows Vista - go get the package right &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=9FF6E897-23CE-4A36-B7FC-D52065DE9960&amp;amp;displaylang=en" target="_blank"&gt;HERE (32-bit)&lt;/a&gt; or &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=d647a60b-63fd-4ac5-9243-bd3c497d2bc5&amp;amp;DisplayLang=en" target="_blank"&gt;HERE (64-bit)&lt;/a&gt;...&lt;/p&gt;  &lt;p&gt;Time to get Group Policy Preferences and all those other goodies up and running - cool stuff!&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21992565-7977405309565815729?l=www.heidelbergit.dk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.heidelbergit.dk/feeds/7977405309565815729/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21992565&amp;postID=7977405309565815729' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/7977405309565815729'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/7977405309565815729'/><link rel='alternate' type='text/html' href='http://www.heidelbergit.dk/2008/03/remote-server-administration-tools.html' title='Remote Server Administration Tools Available!'/><author><name>Jakob H. Heidelberg</name><uri>http://www.blogger.com/profile/05947807953068058636</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21992565.post-6737421705825082733</id><published>2008-03-20T08:49:00.001+01:00</published><updated>2008-03-20T08:49:43.368+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Windows Vista'/><category scheme='http://www.blogger.com/atom/ns#' term='service pack'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='microsoft'/><title type='text'>What's inside Vista Service Pack 1</title><content type='html'>&lt;p&gt;Well - in regards to Hotfixes and Security Updates, check out &lt;a href="http://technet2.microsoft.com/WindowsVista/en/library/20184cb6-7038-4e82-a32c-4bc10ffe56ab1033.mspx?mfr=true" target="_blank"&gt;this&lt;/a&gt; TechNet article. To get the complete overview, read this &lt;a href="http://technet2.microsoft.com/WindowsVista/en/library/20184cb6-7038-4e82-a32c-4bc10ffe56ab1033.mspx?mfr=true" target="_blank"&gt;one&lt;/a&gt;. The &amp;quot;notable changes&amp;quot; can be found &lt;a href="http://technet2.microsoft.com/WindowsVista/en/library/20184cb6-7038-4e82-a32c-4bc10ffe56ab1033.mspx?mfr=true" target="_blank"&gt;here&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;&lt;em&gt;That should be enough info to get safely through Eastern &lt;/em&gt;:-)&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21992565-6737421705825082733?l=www.heidelbergit.dk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.heidelbergit.dk/feeds/6737421705825082733/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21992565&amp;postID=6737421705825082733' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/6737421705825082733'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/6737421705825082733'/><link rel='alternate' type='text/html' href='http://www.heidelbergit.dk/2008/03/what-inside-vista-service-pack-1.html' title='What&amp;#39;s inside Vista Service Pack 1'/><author><name>Jakob H. Heidelberg</name><uri>http://www.blogger.com/profile/05947807953068058636</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21992565.post-6272111822827660614</id><published>2008-03-19T22:48:00.001+01:00</published><updated>2008-03-19T22:48:54.114+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Fine-Grained Password Policies'/><category scheme='http://www.blogger.com/atom/ns#' term='specops'/><category scheme='http://www.blogger.com/atom/ns#' term='Granular Password Settings'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows Server 2008'/><category scheme='http://www.blogger.com/atom/ns#' term='microsoft'/><title type='text'>Configuring Granular Password Settings in Windows Server 2008 – The Easy Way!</title><content type='html'>&lt;p&gt;&lt;u&gt;&lt;a href="http://www.windowsecurity.com/articles/Configuring-Granular-Password-Settings-Windows-Server-2008.html" target="_blank"&gt;This article&lt;/a&gt;&lt;/u&gt; will demonstrate &amp;#8220;The Easy Way&amp;#8221; of how to handle Granular Password Policies &amp;#8211; also known as Fine-Grained Password Policies - in a Windows Server 2008 domain environment.&lt;/p&gt;  &lt;p&gt;In the article series &amp;#8220;Configuring Granular Password Settings&amp;#8221; (&lt;a href="http://www.windowsecurity.com/articles/Configuring-Granular-Password-Settings-Windows-Server-2008-Part-1.html" target="_blank"&gt;part 1&lt;/a&gt; &amp;amp; &lt;a href="http://www.windowsecurity.com/articles/Configuring-Granular-Password-Settings-Windows-Server-2008-Part2.html" target="_blank"&gt;part 2&lt;/a&gt;) I demonstrated how to configure Granular Password Settings for individual users or global security groups in a Windows Server 2008 Active Directory environment, using built-in methods. This article will demonstrate &amp;#8220;The Easy Way&amp;#8221; of how to handle these additional password policies in your Windows Server 2008 domain environment... Using &lt;a href="http://www.specopssoft.com/wiki/index.php/SpecopsPasswordPolicyBasic/SpecopsPasswordPolicyBasic"&gt;Specops Password Policy Basic&lt;/a&gt;!&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Enjoy!&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21992565-6272111822827660614?l=www.heidelbergit.dk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.heidelbergit.dk/feeds/6272111822827660614/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21992565&amp;postID=6272111822827660614' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/6272111822827660614'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/6272111822827660614'/><link rel='alternate' type='text/html' href='http://www.heidelbergit.dk/2008/03/configuring-granular-password-settings.html' title='Configuring Granular Password Settings in Windows Server 2008 – The Easy Way!'/><author><name>Jakob H. Heidelberg</name><uri>http://www.blogger.com/profile/05947807953068058636</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21992565.post-966665409808215377</id><published>2008-03-18T08:34:00.001+01:00</published><updated>2008-03-18T08:34:08.563+01:00</updated><title type='text'>Easily leave users with the Least Privilege possible</title><content type='html'>&lt;p&gt;A new and shiny - &lt;em&gt;free!&lt;/em&gt; - tool from &lt;a href="http://www.beyondtrust.com" target="_blank"&gt;BeyondTrust&lt;/a&gt; makes it possible for admins around the world to figure out exactly what rights different applications in the environment need to run. This kind of info is essential for removing administrative rights from users and running a &amp;quot;principle of least privilege&amp;quot; environment!&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.beyondtrust.com/products/ApplicationRightsAuditor.aspx" target="_blank"&gt;BeyondTrust&amp;#174; Application Rights Auditor&lt;/a&gt; is a totally FREE tool which profiles applications and seamlessly identifies the required permissions - very easy to implement, use and manage.&lt;/p&gt;  &lt;p&gt;We all know, that administrative rights allow users to circumvent security policies, install unauthorized applications and make unauthorized modifications to a standard desktop configuration - let's move away from those risks... Just register, download and test out this free application - this is &amp;quot;low hanging fruit&amp;quot; giving your environment a needed security-vitamin injection!&lt;/p&gt;  &lt;p&gt;Download the &lt;a href="http://www.beyondtrust.com/documentation/dataSheets/DS_ARA.pdf" target="_blank"&gt;Product Sheet (PDF) right here&lt;/a&gt;!&lt;/p&gt;  &lt;p&gt;A desktop component can be installed on multiple computers to transparently examine applications during execution. The reporting console gives a nice overview of applications the environment from a central point.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Reporting Console Prerequisites:     &lt;br /&gt;&lt;/strong&gt;Microsoft .NET Framework 3.0 SP 1 and     &lt;br /&gt;Microsoft Management Console 3.0&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;em&gt;Go for it !&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21992565-966665409808215377?l=www.heidelbergit.dk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.heidelbergit.dk/feeds/966665409808215377/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21992565&amp;postID=966665409808215377' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/966665409808215377'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/966665409808215377'/><link rel='alternate' type='text/html' href='http://www.heidelbergit.dk/2008/03/easily-leave-users-with-least-privilege.html' title='Easily leave users with the Least Privilege possible'/><author><name>Jakob H. Heidelberg</name><uri>http://www.blogger.com/profile/05947807953068058636</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21992565.post-752518711022565196</id><published>2008-03-01T09:21:00.001+01:00</published><updated>2008-03-01T09:21:00.157+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Solution Accelerator'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows Server 2008'/><category scheme='http://www.blogger.com/atom/ns#' term='Security Guide'/><category scheme='http://www.blogger.com/atom/ns#' term='microsoft'/><title type='text'>Windows Server 2008 Security Guide and the new GPOAccelerator tool is out there!</title><content type='html'>&lt;p&gt;I participated in creation of this great guide around security on Windows Server 2008 - really, you gotta see this... Also check out the new and shiny Solution Accelerator called &amp;quot;GPOAccelerator&amp;quot; - it really &lt;em&gt;rocks!&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Info from Microsoft:     &lt;br /&gt;&lt;/strong&gt;The primary purposes of this guide are to enable you to do the following: &lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Use the solution guidance to efficiently create and apply tested security baseline configurations using Group Policy. &lt;/li&gt;    &lt;li&gt;Understand the reasoning for the security setting recommendations in the baseline configurations that the guide prescribes, and their implications. &lt;/li&gt;    &lt;li&gt;Identify and consider common security scenarios, and then use specific security features in Windows Server 2008 to help you manage them in your environment. &lt;/li&gt;    &lt;li&gt;Understand role based security for different workloads in Windows Server 2008. &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;strong&gt;Hardening:     &lt;br /&gt;&lt;/strong&gt;The WS2008 Security Guide also includes information on how to harden the following server roles and the role services that they provide:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;em&gt;Active Directory Domain Services (AD DS)&lt;/em&gt;&lt;/li&gt;    &lt;li&gt;&lt;em&gt;Dynamic Host Configuration Protocol (DHCP) Server&lt;/em&gt;&lt;/li&gt;    &lt;li&gt;&lt;em&gt;Domain Name System (DNS) Server&lt;/em&gt;&lt;/li&gt;    &lt;li&gt;&lt;em&gt;Web Server (IIS)&lt;/em&gt;&lt;/li&gt;    &lt;li&gt;&lt;em&gt;File Services&lt;/em&gt;&lt;/li&gt;    &lt;li&gt;&lt;em&gt;Print Services&lt;/em&gt;&lt;/li&gt;    &lt;li&gt;&lt;em&gt;Active Directory Certificate Services (AD CS)&lt;/em&gt;&lt;/li&gt;    &lt;li&gt;&lt;em&gt;Network Policy and Access Services&lt;/em&gt;&lt;/li&gt;    &lt;li&gt;&lt;em&gt;Terminal Services&lt;/em&gt;&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;strong&gt;The &amp;quot;complete solution&amp;quot; from Microsoft:     &lt;br /&gt;&lt;/strong&gt;The Solution Accelerator for the Windows Server 2008 Security Guide includes the following components: &lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;strong&gt;Executive Overview&lt;/strong&gt;. A summary for business and technical managers that briefly explains how you can use the guidance and the tool for this Solution Accelerator. &lt;/li&gt;    &lt;li&gt;&lt;strong&gt;Security Guide&lt;/strong&gt;. Recommended guidelines and best practices in a series of chapters that offer detailed guidance on how to harden servers running Windows Server 2008 that handle different workloads (&lt;em&gt;see above&lt;/em&gt;).&lt;/li&gt;    &lt;li&gt;&lt;strong&gt;Security Settings Recommendation Appendix&lt;/strong&gt;. A comprehensive technical reference that explains every prescribed security setting in the security guide. &lt;/li&gt;    &lt;li&gt;&lt;strong&gt;Security Settings Workbook&lt;/strong&gt;. A resource that lists all prescribed settings for each of the preconfigured security baselines provided by the guide.&lt;/li&gt;    &lt;li&gt;&lt;strong&gt;Attack Surface Reference Workbook&lt;/strong&gt;. A resource that lists the changes that installed server roles introduce in Windows Server 2008. &lt;/li&gt;    &lt;li&gt;&lt;strong&gt;GPOAccelerator&lt;/strong&gt;. A tool that you can use to automatically create Group Policy objects (GPOs) recommended by the guide, which is available as a separate download. To learn more about the GPOAccelerator and download the tool, click here. &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;strong&gt;Where can I get this?&lt;/strong&gt;    &lt;br /&gt;&lt;a href="http://technet.microsoft.com/en-us/library/cc264463.aspx" target="_blank"&gt;Windows Server 2008 Security Guide&lt;/a&gt; (online version)    &lt;br /&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=92552" target="_blank"&gt;Get the Windows Server 2008 Security Guide&lt;/a&gt;    &lt;br /&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=107264" target="_blank"&gt;Get the GPOAccelerator&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Enjoy!&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;.   &lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21992565-752518711022565196?l=www.heidelbergit.dk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.heidelbergit.dk/feeds/752518711022565196/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21992565&amp;postID=752518711022565196' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/752518711022565196'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/752518711022565196'/><link rel='alternate' type='text/html' href='http://www.heidelbergit.dk/2008/03/windows-server-2008-security-guide-and.html' title='Windows Server 2008 Security Guide and the new GPOAccelerator tool is out there!'/><author><name>Jakob H. Heidelberg</name><uri>http://www.blogger.com/profile/05947807953068058636</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-21992565.post-4746901372161652365</id><published>2008-03-01T01:34:00.001+01:00</published><updated>2011-10-14T08:43:03.330+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Windows Vista'/><category scheme='http://www.blogger.com/atom/ns#' term='group policy'/><category scheme='http://www.blogger.com/atom/ns#' term='download'/><category scheme='http://www.blogger.com/atom/ns#' term='windows xp'/><category scheme='http://www.blogger.com/atom/ns#' term='gp preferences'/><category scheme='http://www.blogger.com/atom/ns#' term='group policy extensions'/><category scheme='http://www.blogger.com/atom/ns#' term='Client Side Extensions'/><category scheme='http://www.blogger.com/atom/ns#' term='group policy preferences'/><category scheme='http://www.blogger.com/atom/ns#' term='windows server 2003'/><category scheme='http://www.blogger.com/atom/ns#' term='microsoft'/><category scheme='http://www.blogger.com/atom/ns#' term='scripting'/><category scheme='http://www.blogger.com/atom/ns#' term='Jeremy Moskowitz'/><title type='text'>How to install GPP CSEs using a Startup Script</title><content type='html'>When you have the &lt;strong&gt;Group Policy Preference (GPP) Client Side Extensions (CSE)&lt;/strong&gt; downloaded you'll notice that they are not (yet) in the &lt;strong&gt;.MSI&lt;/strong&gt; format - so using &lt;strong&gt;Group Policy Software Installation (GPSI)&lt;/strong&gt; is not possible. Bummer, right!?&lt;br /&gt;We have &lt;strong&gt;.EXE&lt;/strong&gt; files for Windows XP/2003 and &lt;strong&gt;.MSU&lt;/strong&gt; files for Windows Vista... But that's not the only thing we need to think about. Before "deploying" these things to the clients on the network we need to know the OS &lt;strong&gt;version&lt;/strong&gt; (XP/2003/Vista), the OS &lt;strong&gt;architecture&lt;/strong&gt; (32 or 64 bit), the &lt;strong&gt;Service Pack Level&lt;/strong&gt;, and whether or not the Group Policy Preference &lt;strong&gt;Pre-requisites&lt;/strong&gt; (WmlLite - &lt;a href="http://support.microsoft.com/kb/914783/en-us" title="http://support.microsoft.com/kb/914783/en-us"&gt;http://support.microsoft.com/kb/914783/en-us&lt;/a&gt;) are installed.&lt;br /&gt;To make all this pretty easy I've created a "demo" &lt;strong&gt;script&lt;/strong&gt; for deploying the GPP CSEs using Startup Script - or a manual launch (in admin context). My good friend &lt;em&gt;Jeremy Moskowitz&lt;/em&gt; asked me to do this - so, a couple of hours later the "demo" - or "&lt;em&gt;beta&lt;/em&gt;" - script is public (download below)...&lt;br /&gt;&lt;strong&gt;Note:&lt;/strong&gt; I haven't been able to test in all scenarios yet, but I *&lt;em&gt;think&lt;/em&gt;* they are all covered pretty well by now. &lt;strong&gt;Please report back&lt;/strong&gt; if you find any problems - any &lt;strong&gt;feedback&lt;/strong&gt; is welcome!&lt;br /&gt;&lt;strong&gt;&lt;a href="http://www.heidelbergit.dk/2011/10/installgppcse-cleartext.html" target="_blank"&gt;Download the VBS script right here!&lt;/a&gt;&lt;/strong&gt;&lt;br /&gt;NB! You might need other &lt;strong&gt;language&lt;/strong&gt; version for the &lt;strong&gt;XmlLite&lt;/strong&gt; GPP CSE Pre-requisites, so watch out!&lt;br /&gt;&lt;em&gt;Running the script in your production network is on your own risk. The code is delivered "As Is" - totally free of any charge. No strings attached.&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;I hope this works out nicely for you!&lt;br /&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/21992565-4746901372161652365?l=www.heidelbergit.dk' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.heidelbergit.dk/feeds/4746901372161652365/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=21992565&amp;postID=4746901372161652365' title='16 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/4746901372161652365'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/posts/default/4746901372161652365'/><link rel='alternate' type='text/html' href='http://www.heidelbergit.dk/2008/03/how-to-install-gpp-cses-using-startup.html' title='How to install GPP CSEs using a Startup Script'/><author><name>Jakob H. Heidelberg</name><uri>http://www.blogger.com/profile/05947807953068058636</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>16</thr:total></entry></feed>
