<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Lars Jostein Silihagen &#187; WS2008</title>
	<atom:link href="http://blog.silihagen.net/tag/ws2008/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.silihagen.net</link>
	<description>[System.Media.SystemSounds]::Beep.Play();</description>
	<lastBuildDate>Sat, 01 May 2010 12:13:15 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Hyper-V Diaster Recovery</title>
		<link>http://blog.silihagen.net/2009/11/hyper-v-diaster-recovery/</link>
		<comments>http://blog.silihagen.net/2009/11/hyper-v-diaster-recovery/#comments</comments>
		<pubDate>Wed, 04 Nov 2009 23:12:48 +0000</pubDate>
		<dc:creator>Lars Jostein</dc:creator>
				<category><![CDATA[Data Protection Manager 2007]]></category>
		<category><![CDATA[Hyper-V]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[Vitual Machine Manager 2008]]></category>
		<category><![CDATA[Windows Server 2008]]></category>
		<category><![CDATA[SC DPM]]></category>
		<category><![CDATA[SC VMM]]></category>
		<category><![CDATA[Sikkerhet]]></category>
		<category><![CDATA[WS2008]]></category>

		<guid isPermaLink="false">http://blog.silihagen.net/?p=301</guid>
		<description><![CDATA[Jim Scwartz (Director of Virtualization Solution, Microsoft) publiserte i går ett innlegg på Microsoft Vitualization Blog som omhandler Microsoft Site Recovery Solution basert på Microsoft Hyper-V.
Her er noen nyttige ressurser om Hyper-V og Diaster Recovery:

Disaster Recovery with Iron Mountain and Microsoft System Center Data Protection Manager 2007
Whitepaper &#8211; Improving efficiency and availability using Microsoft Hyper-V <a href="http://blog.silihagen.net/2009/11/hyper-v-diaster-recovery/" class="more-link">Mer &#62;</a>]]></description>
			<content:encoded><![CDATA[<p>Jim Scwartz (Director of Virtualization Solution, Microsoft) publiserte i går ett innlegg på <a href="http://blogs.technet.com/virtplanet/archive/2009/11/03/microsoft-site-recovery-solution-launch.aspx" target="_blank">Microsoft Vitualization Blog</a> som omhandler <strong>Microsoft Site Recovery Solution</strong> basert på Microsoft Hyper-V.</p>
<p>Her er noen nyttige ressurser om Hyper-V og Diaster Recovery:</p>
<ul>
<li><a href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?culture=en-US&amp;EventID=1032410563" target="_blank">Disaster Recovery with Iron Mountain and Microsoft System Center Data Protection Manager 2007</a></li>
<li>Whitepaper &#8211; <a href="http://www-download.netapp.com/edm/TT/docs/Seattle_Retail_Report_040909.pdf" target="_blank">Improving efficiency and availability using Microsoft Hyper-V and NetApp Storage</a></li>
<li>Whitepaper &#8211; <a href="http://www.doubletake.com/Documents/Hyper-V/DBTK_MSFT_HyperV_Solution_Sheet_GC-Product-Overview-0607.pdf" target="_blank">DoubleTake: Disaster Recovery for Hyper-V</a></li>
<li>Whitepaper &#8211; <a href="http://www.hds.com/assets/pdf/hitachi-storage-cluster-for-microsoft-hyper-v.pdf" target="_blank">Hitachi Storage Cluster for Microsoft Hyper-V: Optimizing Business Continuity and Disaster Recovery in Microsoft Hyper-V Environments</a></li>
<li>Whitepaper &#8211; <a href="http://www.emc.com/collateral/software/white-papers/h6346-disaster-recovery-geographically-dispersed-cross-site-virtual-environment-wp.pdf" target="_blank">EMC&#8221;2: Disaster recovery in a geographically dispersed cross-site virtual environment</a></li>
<li>Whitepaper &#8211; <a href="http://h20195.www2.hp.com/V2/GetPDF.aspx/4AA2-6905ENW.pdf" target="_blank">HP: Disaster Tolerant Virtualization Architecture with HP StorageWorks Cluster Extension and Microsoft Hyper-V</a></li>
<li><a href="http://www.microsoft.com/virtualization/en/us/solution-continuity.aspx" target="_blank">Microsoft Virtualization: Continuity</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://blog.silihagen.net/2009/11/hyper-v-diaster-recovery/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fikk spørsmål om Shadow Group i Active Directory 2008 – hva er det?</title>
		<link>http://blog.silihagen.net/2009/09/fikk-sp%c3%b8rsmal-om-shadow-group-i-active-directory-2008-%e2%80%93-hva-er-det/</link>
		<comments>http://blog.silihagen.net/2009/09/fikk-sp%c3%b8rsmal-om-shadow-group-i-active-directory-2008-%e2%80%93-hva-er-det/#comments</comments>
		<pubDate>Sun, 06 Sep 2009 23:12:02 +0000</pubDate>
		<dc:creator>Lars Jostein</dc:creator>
				<category><![CDATA[Windows Server 2008]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[WS2008]]></category>

		<guid isPermaLink="false">http://blog.silihagen.net/?p=265</guid>
		<description><![CDATA[Jeg hadde ingen god forklaring der og da, så jeg fant ut at her måtte jeg spørre en kompis som heter Google. Google ga heller ikke noe klart svar og Googles (u)venn Bing likeså. Fant derfor ut at jeg måtte gjøre et dypdykk og tror jeg til slutt klarte å finne rett tolkning av Shadow <a href="http://blog.silihagen.net/2009/09/fikk-sp%c3%b8rsmal-om-shadow-group-i-active-directory-2008-%e2%80%93-hva-er-det/" class="more-link">Mer &#62;</a>]]></description>
			<content:encoded><![CDATA[<p>Jeg hadde ingen god forklaring der og da, så jeg fant ut at her måtte jeg spørre en kompis som heter Google. Google ga heller ikke noe klart svar og Googles (u)venn Bing likeså. Fant derfor ut at jeg måtte gjøre et dypdykk og tror jeg til slutt klarte å finne rett tolkning av Shadow Group.</p>
<p> -          Først litt om “<strong>Fine-Grained Password Policies</strong>” (domain functional level Windows Server 2008)</p>
<ul>
<li>ØNSKE: De fleste har en gruppe brukerer i  AD som de ønsker å kunne tilegne egne passordregler med høyere eller lavere krav i forhold til andre brukergrupper. (Administrator kontoer etc..)</li>
<li>FØR: I AD før WS2008 functional level ble regler for passord på brukerobjekter i domenet satt gjennom “Default Domain Policy GPO”. Samtlige brukere i domenet har da samme policy for passordregler og “account lockout”. (Det er mulig å få til løsninger rundt dette også i eldre AD, men ingen gode løsninger)</li>
<li>NÅ:  I WS2008 AD DS kan man bruke Fine-Grained Password Policies for å sette forskjellige passordregler.
<ul>
<li>Krav for å ta i bruk Fine-Grained password policies:
<ul>
<li>Domain functional lever WS2008</li>
<li>Fine-Grained Password Policies kan bare settes på bruker objekter og globale sikkerhetsgrupper</li>
<li>Man kan ikke legge en Fine-Grained Password Policy på en OU.</li>
</ul>
</li>
</ul>
</li>
</ul>
<p>De fleste har brukerkontoer fordelt i forskjellige OUer. Siden man ikke kan sette Fine-Grained Password Policy på en OU er det <span style="text-decoration: underline;">beste praksis å opprette en global sikkerhetsgruppe med samme navn som OUen</span>, for så å tilegne denne gruppa Fine-Grained Password Policy og melde bruker objekter fra OUen inn i denne gruppa. <strong>Denne type gruppe kalles for en SHADOW GROUP. </strong></p>
<p>Hva må man tenke på før man planlegger bruk av Fine-Grained Password Policies:</p>
<ul>
<li>Hvor mange forskjellige passord policies er det behov for?</li>
<li>Hvilke spesielle passord egenskaper  og “account lockout” regler er det behov for?</li>
<li>Hvilke sikkerhetsgrupper skal man linke de nye passord reglene til?</li>
</ul>
<p> <img class="alignnone" title="ShadowGroups" src="http://www.silihagen.net/blog/wp-content/ShadowGroup.jpg" alt="" width="805" height="483" /></p>
<p>For å bestemme egenskapene til passordene som skal brukes opprettes “Password Settings Object” (PSO) i konteineren “Password Settings Container” under “System”. Opprettelsen av PSO gjøres i ADSI edit eller skriptes med Ldifde kommandoer. I skjermbildet over er den golbale sikkerhetsgruppen “Brukere Lillehammer” en Shadow Group.</p>
<p>Dersom man ikke linker inn en PSO mot et brukerobjekt eller gruppe, blir “default domain policy GPO” benyttet.</p>
<p>For å se resultatet av en PSO for en bruker kan man bruke kommandoen:<br />
dsget user &lt;User-DN&gt; -effectivepso</p>
<p>Se tabell for egenskaper som kan settes i en PSO her: <a href="http://technet.microsoft.com/en-us/library/cc754461(WS.10).aspx">http://technet.microsoft.com/en-us/library/cc754461(WS.10).aspx</a> Se spessielt  “msDS-PasswordSettingsPrecedence” som sier noe om hvilken PSO som skal få prioritet dersom et objekt har flere tildelte PSO.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.silihagen.net/2009/09/fikk-sp%c3%b8rsmal-om-shadow-group-i-active-directory-2008-%e2%80%93-hva-er-det/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WS2008 R2 RTM</title>
		<link>http://blog.silihagen.net/2009/08/ws2008-r2-rtm/</link>
		<comments>http://blog.silihagen.net/2009/08/ws2008-r2-rtm/#comments</comments>
		<pubDate>Sun, 16 Aug 2009 15:42:58 +0000</pubDate>
		<dc:creator>Lars Jostein</dc:creator>
				<category><![CDATA[Windows Server 2008]]></category>
		<category><![CDATA[WS2008]]></category>

		<guid isPermaLink="false">http://blog.silihagen.net/?p=245</guid>
		<description><![CDATA[Windows Server 2008 R2 RTM er lagt ut for nedlasting fra MSDN/TechNet: http://blogs.technet.com/tommy_pedersen/archive/2009/08/16/last-ned-windows-server-2008-r2.aspx
]]></description>
			<content:encoded><![CDATA[<p>Windows Server 2008 R2 RTM er lagt ut for nedlasting fra MSDN/TechNet: <a href="http://blogs.technet.com/tommy_pedersen/archive/2009/08/16/last-ned-windows-server-2008-r2.aspx">http://blogs.technet.com/tommy_pedersen/archive/2009/08/16/last-ned-windows-server-2008-r2.aspx</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.silihagen.net/2009/08/ws2008-r2-rtm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MCITP Windows 2008 Server Administrator</title>
		<link>http://blog.silihagen.net/2008/12/mcitp-windows-2008-server-administrator/</link>
		<comments>http://blog.silihagen.net/2008/12/mcitp-windows-2008-server-administrator/#comments</comments>
		<pubDate>Mon, 22 Dec 2008 23:24:32 +0000</pubDate>
		<dc:creator>Lars Jostein</dc:creator>
				<category><![CDATA[Windows Server 2008]]></category>
		<category><![CDATA[WS2008]]></category>

		<guid isPermaLink="false">http://blog.silihagen.net/?p=112</guid>
		<description><![CDATA[December 15th I passed the 70-646 MCITP Windows 2008 Server Administrator, and today I passed the 70-643 WS2008 Application Infrastructure.
Finally, well-deserved Christmas holidays!
]]></description>
			<content:encoded><![CDATA[<p>December 15th I passed the 70-646 MCITP Windows 2008 Server Administrator, and today I passed the 70-643 WS2008 Application Infrastructure.</p>
<p>Finally, well-deserved Christmas holidays!</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.silihagen.net/2008/12/mcitp-windows-2008-server-administrator/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TS: Windows Server 2008 Active Directory, Configuring (70-640)</title>
		<link>http://blog.silihagen.net/2008/12/ts-windows-server-2008-active-directory-configuring-70-640/</link>
		<comments>http://blog.silihagen.net/2008/12/ts-windows-server-2008-active-directory-configuring-70-640/#comments</comments>
		<pubDate>Mon, 01 Dec 2008 11:39:44 +0000</pubDate>
		<dc:creator>Lars Jostein</dc:creator>
				<category><![CDATA[Windows Server 2008]]></category>
		<category><![CDATA[WS2008]]></category>

		<guid isPermaLink="false">http://blog.silihagen.net/?p=109</guid>
		<description><![CDATA[Today, at the first day of Advent, I passed the Windows Server 2008 Active Directory configuring (70-640). Very happy with it!
]]></description>
			<content:encoded><![CDATA[<p>Today, at the first day of Advent, I passed the Windows Server 2008 Active Directory configuring (70-640). Very happy with it!</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.silihagen.net/2008/12/ts-windows-server-2008-active-directory-configuring-70-640/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Face of Windows Server 2008</title>
		<link>http://blog.silihagen.net/2008/08/the-face-of-windows-server-2008/</link>
		<comments>http://blog.silihagen.net/2008/08/the-face-of-windows-server-2008/#comments</comments>
		<pubDate>Mon, 11 Aug 2008 19:29:28 +0000</pubDate>
		<dc:creator>Lars Jostein</dc:creator>
				<category><![CDATA[Windows Server 2008]]></category>
		<category><![CDATA[WS2008]]></category>

		<guid isPermaLink="false">http://blog.silihagen.net/?p=14</guid>
		<description><![CDATA[
]]></description>
			<content:encoded><![CDATA[<p><img class="aligncenter" title="Face of Windows Server 2008" src="http://silihagen.net/face.jpg" alt="" width="400" height="361" /><a href="http://blog.silihagen.net/wp-content/uploads/face.jpg" class="highslide-image" onclick="return hs.expand(this);"></a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.silihagen.net/2008/08/the-face-of-windows-server-2008/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
