MaxTokenSize and Windows 8 and Windows Server 2012

Hello AskDS Populous, Mike here and I want to share with you some of the excellent enhancements we accomplished in Windows 8 and Windows Server 2012 around MaxTokenSize. Let’s review MaxTokenSize and its symptoms before we jump in to wonderful world of Windows 8 (say that three times fast). Wonderful World of Windows 8 Wonderful… Read more

Monthly Mail Sack: Yes, I Finally Admit It Edition

Heya folks, Ned here again. Rather than continue the lie that this series comes out every Friday like it once did, I am taking the corporate approach and rebranding the mail sack. Maybe we’ll have the occasional Collector’s Edition versions. This week month, I answer your questions on: The semi-myth of Kerberos time skew Finding… Read more

New Slow Logon, Slow Boot Troubleshooting Content

Hi all, Ned here again. We get emailed here all the time about issues involving delays in user logons. Often enough that, a few years back, Bob wrote a multi-part article on the subject. Taking it to the next level, some of my esteemed colleagues have created a multi-part TechNet Wiki series on understanding, analyzing,… Read more

Friday Mail Sack: Get Off My Lawn Edition

Hi folks, Ned here again. I know this is supposed to be the Friday Mail Sack but things got a little hectic and… ah heck, it doesn’t need explaining, you’re in IT. This week – with help from the ever-crotchety Jonathan Stephens – we talk about: Multiple WMI Filters LDAP MaxPoolThreads Many-to-one certificate mappings LinkID… Read more

Friday Mail Sack: Guest Reply Edition

Hi folks, Ned here again. This week we talk: CA migration from 1 to 2 tier ADAM/ADLDS P2V ABC 123 Managing AGPM security filters Multiple IIS App pools and Kerberos AGPM multi-domain comparison ADUC domain password weirdness DFSR deletion conflict handling Stale account deletion ad nauseum AD PowerShell, Get-Acl, and the missing objects that aren’t… Read more

Friday Mail Sack: Charlotte Edition

Hiya folks, Ned back with a palette-cleansing Mail Sack after this monstrosity. This week we talk about: To customize AD schema or not DC and root hints USMT and the case of the missing apps DFSR and %SYSTEMROOT% More fun with DC Same As Parent domain zone records Speeding up DFSN client failover AD/LDS and… Read more

Friday Mail Sack: Anchors Aweigh Edition

Hiya folks, Ned here again. I finally have an editor that allows anchors on all the questions, so I am adding a quasi “table of contents” for these posts that allow easier navigation and linking. I’ll retrofit all the old mail sack articles too… eventually. This week we discuss – eh – let’s have the… Read more

Friday Mail Sack: LeBron is not Jordan Edition

Hi folks, Ned here again. Today we discuss trusts rules around domain names, attribute uniqueness, the fattest domains we’ve ever seen, USMT data-only migrations, kicking FRS while it’s down, and a few amusing side topics. Scottie, don’t be that way. Go Mavs. Creating trusts between forests with duplicate names Enforcing sAMAccountName uniqueness The biggest domain… Read more

RSA SecurID Do Over

Ned here. If you are using RSA SecurID, you’re probably aware they were compromised several months ago. You may also have heard that since then, hackers have been using that stolen info to attack or compromise various organizations. What you may not know is RSA is now issuing replacement tokens for their customers. The catch… Read more