<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Lars Jostein Silihagen &#187; Active Directory</title>
	<atom:link href="http://blog.silihagen.net/tag/active-directory/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.silihagen.net</link>
	<description>[System.Media.SystemSounds]::Beep.Play();</description>
	<lastBuildDate>Sat, 01 May 2010 12:13:15 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Ukens blog lesning</title>
		<link>http://blog.silihagen.net/2009/11/ukens-blog-lesning/</link>
		<comments>http://blog.silihagen.net/2009/11/ukens-blog-lesning/#comments</comments>
		<pubDate>Sun, 01 Nov 2009 23:39:22 +0000</pubDate>
		<dc:creator>Lars Jostein</dc:creator>
				<category><![CDATA[Sikkerhet]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[Windows Server 2008]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Hyper-V]]></category>
		<category><![CDATA[SCCM]]></category>
		<category><![CDATA[System Center]]></category>
		<category><![CDATA[VMware]]></category>
		<category><![CDATA[vSphere]]></category>

		<guid isPermaLink="false">http://blog.silihagen.net/?p=277</guid>
		<description><![CDATA[Etter noen dager med fravær fra jobben pga sykdom og påfølgende innedager i helga, fikk jeg tid til å lese noen interessante blogger. Tok vare på noen linker. Se spesielt de som er merket rødt!
Sikkerhet:
More secure alternative to VPN og  VPNs and IPsec
Security Baselines for Windows 7 and Internet Explorer 8
Using ILM for DMZ Account Management
How <a href="http://blog.silihagen.net/2009/11/ukens-blog-lesning/" class="more-link">Mer &#62;</a>]]></description>
			<content:encoded><![CDATA[<p>Etter noen dager med fravær fra jobben pga sykdom og påfølgende innedager i helga, fikk jeg tid til å lese noen interessante blogger. Tok vare på noen linker. Se spesielt de som er merket rødt!</p>
<p><strong>Sikkerhet:<br />
</strong><a href="http://www.theemailadmin.com/2009/10/more-secure-alternative-to-vpn/" target="_blank"><span style="color: #ff0000;">More secure alternative to VPN</span></a><span style="color: #ff0000;"> og  </span><a href="http://www.theemailadmin.com/2008/11/vpns-and-ipsec/" target="_blank"><span style="color: #ff0000;">VPNs and IPsec</span></a><br />
<a href="http://windowsteamblog.com/blogs/springboard/archive/2009/10/29/now-available-security-baselines-for-windows-7-and-internet-explorer-8.aspx" target="_blank">Security Baselines for Windows 7 and Internet Explorer 8</a><br />
<a href="http://msgoodies.blogspot.com/2009/10/using-ilm-for-dmz-account-management.html" target="_blank"><span style="color: #ff0000;">Using ILM for DMZ Account Management</span></a><br />
<a href="http://www.expta.com/2009/10/how-to-convert-local-and-global-groups.html" target="_blank">How to convert local and global groups to universal groups</a><br />
<span style="color: #ff0000;"><a href="http://itriskspace.com/2009/10/24/1256409240000.html" target="_blank"><span style="color: #ff0000;">What I Look for When Hiring IT Security Staff</span></a></span><br />
<a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=5534bee1-3cad-4bf0-b92b-a8e545573a3e&amp;displaylang=en" target="_blank">Security Compliance Management Toolkit Series</a></p>
<p><strong>Backup:<br />
</strong><a href="http://blogs.technet.com/filecab/archive/2009/10/31/learn-more-about-system-image-backup.aspx" target="_blank"><span style="color: #ff0000;">Learn more about system image backup </span><br />
</a><br />
<strong>Exchange:</strong><br />
<a href="http://blogs.technet.com/msukucc/archive/2009/10/16/automating-exchange-2010-pre-requisites-on-windows-server-20008-r2.aspx" target="_blank">Automating Exchange 2010 Pre-Requisits on Windows Server 2008</a> <br />
<a href="http://www.expta.com/2009/10/exchange-server-2010-rtm-upgrade-and.html" target="_blank">Exchange Server 2010 RTM Upgrade and Installation Notes</a></p>
<p><strong>System Center:</strong><br />
<a href="http://blogs.technet.com/configurationmgr/archive/2009/10/27/renaming-the-configuration-manager-2007-database.aspx" target="_blank">Renaming the Configuration Manager 2007 Database</a></p>
<p><strong>Virtualisering:</strong> <br />
<a href="http://www.emc.com/collateral/software/white-papers/h6533-performance-optimization-vmware-powerpath-ve-wp.pdf" target="_blank"><span style="color: #ff0000;">EMC Whitepaper Powerpath/VE beskriver forskjellene mellom Powerpath/VE og MRU, Fixed og Round Robin (EMC Performance Optimazion for VMware)</span></a><br />
<a href="http://blogs.cisco.com/datacenter/comments/so_what_exactly_is_a_nexus_4000_--_the_answer" target="_blank"><span style="color: #ff0000;">So What Exactly is a Nexus 4000</span></a><br />
<a href="http://www-01.ibm.com/common/ssi/ShowDoc.jsp?docURL=/common/ssi/rep_ca/5/877/ENUSZG09-0635/index.html&amp;ampbreadCrum=DET001PT022&amp;ampurl=buttonpressed=DET001PT116&amp;amppage=1000&amp;amppaneltext1=DET001PEF011&amp;ampuser+type=EXT&amp;amplang=en_GB&amp;ampInfoType=AN&amp;ampInfoSubType=CA&amp;ampInfoDesc=Announcement+Letters&amp;amppanelurl=index.wss%3Fbuttonpressed%3DDET001PT116%26page%3D1000%26paneltext1%3DDET001PEF011%26user%2Btype%3DEXT&amp;amppaneltext=Announcement%20letter%20search" target="_blank">Cisco Nexus 4001I Switch Module for IBM BladeCenter</a> og <a href="http://blogs.cisco.com/datacenter/comments/cisco_nexus_4001i_switch_module_for_ibm_bladecenter/" target="_blank">Cisco</a><br />
<a href="http://www.vmware.com/resources/techresources/10059" target="_blank">Vmware vSphere 4 the CPU Cheduler</a><br />
<a href="http://blogs.technet.com/tonyso/archive/2009/10/29/script-center-gallery-hits.aspx" target="_blank">Nyttige Hyper-V PowerShell script</a><br />
<a href="http://www.simple-talk.com/sysadmin/virtualization/increasing-the-availability-of-virtualised-applications-and-services/" target="_blank"><span style="color: #ff0000;">Increasing the Availability of Virtualised Applications and Services</span></a></p>
<p><strong>Microsoft Deployment Toolkit 2010<br />
</strong>Windows 7 Deployment Tools part 1 &#8211; <a href="http://technet.microsoft.com/en-us/windows/ee530017.aspx">http://technet.microsoft.com/en-us/windows/ee530017.aspx</a><br />
Windows 7 Deployment Tools part 2 &#8211; <a href="http://technet.microsoft.com/en-us/windows/ee524789.aspx">http://technet.microsoft.com/en-us/windows/ee524789.aspx</a><br />
Windows 7 Deployment Tools part 3 &#8211; <a href="http://technet.microsoft.com/en-us/windows/ee529974.aspx">http://technet.microsoft.com/en-us/windows/ee529974.aspx</a><br />
Windows 7 Deployment Tools part 4 &#8211; <a href="http://technet.microsoft.com/en-us/windows/ee530027.aspx">http://technet.microsoft.com/en-us/windows/ee530027.aspx</a></p>
<p><a href="http://blog.crayon.no/blogs/ragnar/archive/2009/10/18/litt-om-lisensn-248-kler-mak-og-kms.aspx" target="_blank">Litt om  lisensnøkler – MAK og KMS</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.silihagen.net/2009/11/ukens-blog-lesning/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Active Directory Rights Management Service &#8211; Service Bulk Protection Tool</title>
		<link>http://blog.silihagen.net/2009/11/active-directory-rights-management-service-bulk-protection-tool/</link>
		<comments>http://blog.silihagen.net/2009/11/active-directory-rights-management-service-bulk-protection-tool/#comments</comments>
		<pubDate>Sun, 01 Nov 2009 20:25:37 +0000</pubDate>
		<dc:creator>Lars Jostein</dc:creator>
				<category><![CDATA[Sikkerhet]]></category>
		<category><![CDATA[Windows Server 2008]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[AD RMS]]></category>

		<guid isPermaLink="false">http://blog.silihagen.net/?p=271</guid>
		<description><![CDATA[AD RMS Bulk Protection Tool er et kommandolinjeverktøy for å bulk kryptere eller dekryptere AD RMS beskyttede filer. Kjekt verktøy i forbindelse med tvister eller revisjonsformål. Verktøyet fungerer også bra sammen med funksjonaliteten i File Classification Infrastructure i Windows Server 2008 R2 for å klassifisere og beskytte sensitive bedriftsdata.
AD RMS Bulk Protection Tool: http://www.microsoft.com/downloads/details.aspx?FamilyID=f9fbe58f-c175-41d0-afdc-6f160ab809cd&#38;displayLang=en
For mer <a href="http://blog.silihagen.net/2009/11/active-directory-rights-management-service-bulk-protection-tool/" class="more-link">Mer &#62;</a>]]></description>
			<content:encoded><![CDATA[<p>AD RMS Bulk Protection Tool er et kommandolinjeverktøy for å bulk kryptere eller dekryptere AD RMS beskyttede filer. Kjekt verktøy i forbindelse med tvister eller revisjonsformål. Verktøyet fungerer også bra sammen med funksjonaliteten i <a href="http://www.microsoft.com/windowsserver2008/en/us/fci.aspx" target="_blank">File Classification Infrastructure</a> i Windows Server 2008 R2 for å klassifisere og beskytte sensitive bedriftsdata.</p>
<p>AD RMS Bulk Protection Tool: <a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=f9fbe58f-c175-41d0-afdc-6f160ab809cd&amp;displayLang=en">http://www.microsoft.com/downloads/details.aspx?FamilyID=f9fbe58f-c175-41d0-afdc-6f160ab809cd&amp;displayLang=en</a></p>
<p><strong>For mer om AD RMS: </strong></p>
<ul>
<li style="text-align: justify;"><a href="http://en.wikipedia.org/wiki/Rights_Management_Services" target="_blank"> Wiki – Rights Management Services</a></li>
<li style="text-align: justify;"><a href="http://technet.microsoft.com/en-us/library/cc753531(WS.10).aspx" target="_blank">AD RMS Step-by-Step guide</a></li>
<li style="text-align: justify;"><a href="http://blogs.msdn.com/rms/archive/2009/07/23/microsoft-s-ad-rms-rights-policy-templates.aspx" target="_blank">Microsoft AD RMS Rights Policy Templates</a></li>
<li style="text-align: justify;"><a href="http://technet.microsoft.com/en-us/library/dd772711(WS.10).aspx" target="_blank">AD RMS Documentation Roadmap</a></li>
<li style="text-align: justify;"><a href="http://technet.microsoft.com/en-us/library/dd941633(WS.10).aspx" target="_blank">AD RMS Best Practices</a> og <a href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032410164&amp;EventCategory=5&amp;culture=en-US&amp;CountryCode=US" target="_blank">AD RMD Best Practices WEBcast</a></li>
<li style="text-align: justify;"><a href="http://www.ilmbestpractices.com/blog/2009/08/ad-rms-on-r2-new-federation-features.html" target="_blank">AD RMS on R2 – new Federation Features</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://blog.silihagen.net/2009/11/active-directory-rights-management-service-bulk-protection-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fikk spørsmål om Shadow Group i Active Directory 2008 – hva er det?</title>
		<link>http://blog.silihagen.net/2009/09/fikk-sp%c3%b8rsmal-om-shadow-group-i-active-directory-2008-%e2%80%93-hva-er-det/</link>
		<comments>http://blog.silihagen.net/2009/09/fikk-sp%c3%b8rsmal-om-shadow-group-i-active-directory-2008-%e2%80%93-hva-er-det/#comments</comments>
		<pubDate>Sun, 06 Sep 2009 23:12:02 +0000</pubDate>
		<dc:creator>Lars Jostein</dc:creator>
				<category><![CDATA[Windows Server 2008]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[WS2008]]></category>

		<guid isPermaLink="false">http://blog.silihagen.net/?p=265</guid>
		<description><![CDATA[Jeg hadde ingen god forklaring der og da, så jeg fant ut at her måtte jeg spørre en kompis som heter Google. Google ga heller ikke noe klart svar og Googles (u)venn Bing likeså. Fant derfor ut at jeg måtte gjøre et dypdykk og tror jeg til slutt klarte å finne rett tolkning av Shadow <a href="http://blog.silihagen.net/2009/09/fikk-sp%c3%b8rsmal-om-shadow-group-i-active-directory-2008-%e2%80%93-hva-er-det/" class="more-link">Mer &#62;</a>]]></description>
			<content:encoded><![CDATA[<p>Jeg hadde ingen god forklaring der og da, så jeg fant ut at her måtte jeg spørre en kompis som heter Google. Google ga heller ikke noe klart svar og Googles (u)venn Bing likeså. Fant derfor ut at jeg måtte gjøre et dypdykk og tror jeg til slutt klarte å finne rett tolkning av Shadow Group.</p>
<p> -          Først litt om “<strong>Fine-Grained Password Policies</strong>” (domain functional level Windows Server 2008)</p>
<ul>
<li>ØNSKE: De fleste har en gruppe brukerer i  AD som de ønsker å kunne tilegne egne passordregler med høyere eller lavere krav i forhold til andre brukergrupper. (Administrator kontoer etc..)</li>
<li>FØR: I AD før WS2008 functional level ble regler for passord på brukerobjekter i domenet satt gjennom “Default Domain Policy GPO”. Samtlige brukere i domenet har da samme policy for passordregler og “account lockout”. (Det er mulig å få til løsninger rundt dette også i eldre AD, men ingen gode løsninger)</li>
<li>NÅ:  I WS2008 AD DS kan man bruke Fine-Grained Password Policies for å sette forskjellige passordregler.
<ul>
<li>Krav for å ta i bruk Fine-Grained password policies:
<ul>
<li>Domain functional lever WS2008</li>
<li>Fine-Grained Password Policies kan bare settes på bruker objekter og globale sikkerhetsgrupper</li>
<li>Man kan ikke legge en Fine-Grained Password Policy på en OU.</li>
</ul>
</li>
</ul>
</li>
</ul>
<p>De fleste har brukerkontoer fordelt i forskjellige OUer. Siden man ikke kan sette Fine-Grained Password Policy på en OU er det <span style="text-decoration: underline;">beste praksis å opprette en global sikkerhetsgruppe med samme navn som OUen</span>, for så å tilegne denne gruppa Fine-Grained Password Policy og melde bruker objekter fra OUen inn i denne gruppa. <strong>Denne type gruppe kalles for en SHADOW GROUP. </strong></p>
<p>Hva må man tenke på før man planlegger bruk av Fine-Grained Password Policies:</p>
<ul>
<li>Hvor mange forskjellige passord policies er det behov for?</li>
<li>Hvilke spesielle passord egenskaper  og “account lockout” regler er det behov for?</li>
<li>Hvilke sikkerhetsgrupper skal man linke de nye passord reglene til?</li>
</ul>
<p> <img class="alignnone" title="ShadowGroups" src="http://www.silihagen.net/blog/wp-content/ShadowGroup.jpg" alt="" width="805" height="483" /></p>
<p>For å bestemme egenskapene til passordene som skal brukes opprettes “Password Settings Object” (PSO) i konteineren “Password Settings Container” under “System”. Opprettelsen av PSO gjøres i ADSI edit eller skriptes med Ldifde kommandoer. I skjermbildet over er den golbale sikkerhetsgruppen “Brukere Lillehammer” en Shadow Group.</p>
<p>Dersom man ikke linker inn en PSO mot et brukerobjekt eller gruppe, blir “default domain policy GPO” benyttet.</p>
<p>For å se resultatet av en PSO for en bruker kan man bruke kommandoen:<br />
dsget user &lt;User-DN&gt; -effectivepso</p>
<p>Se tabell for egenskaper som kan settes i en PSO her: <a href="http://technet.microsoft.com/en-us/library/cc754461(WS.10).aspx">http://technet.microsoft.com/en-us/library/cc754461(WS.10).aspx</a> Se spessielt  “msDS-PasswordSettingsPrecedence” som sier noe om hvilken PSO som skal få prioritet dersom et objekt har flere tildelte PSO.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.silihagen.net/2009/09/fikk-sp%c3%b8rsmal-om-shadow-group-i-active-directory-2008-%e2%80%93-hva-er-det/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
