KMS Activation in Windows Server 2019

Hi! I’m Graeme Bray and you may remember me from previous articles such as KMS Activation for Windows Server 2016.  Today’s installment will coincide with a new Windows Server release.  I’m going to focus on getting you to enable AD Based Activation for those of you who have not yet done so.  The location for… Read more

CredSSP, RDP and Raven

Welcome to another edition of AskPFEPlat, this is Paul Bergson and Graeme Bray bringing up the topic of CredSSP when in use with the Remote Desktop Protocol. This topic became an internal discussion around Premier Field Engineering and customers like you as to how this would impact accessing systems via RDP starting in May. This… Read more

Delegate WMI Access to Domain Controllers

Hi everyone! Graeme Bray back with you today with a post around delegating WMI access to Domain Controllers. Continuing the tradition of security themed posts that we’ve had recently on AskPFEPlat, I thought I’d throw this one together for you. This post originally came about after several customers asked how to remove users accounts from… Read more

10 Tips and Tricks from the Field

Hello All. The AskPFEPlat team is here today with you in force. Recently we put together 10 Tips and Tricks from the Field – a collection of tips and tricks in our tool belt that we use on occasion. We wanted share these with all our readers in-an-effort to make your day a little easier…. Read more

Using Group Policy Preferences to Manage the Local Administrator Group

Hello Everyone! Graeme Bray back with you today to talk about how you can reduce the audit and risk surface within your environment. If you can’t tell, Microsoft has taken a strong stance towards security. In a previous life, I was responsible for providing results for audit requests from multiple sources. One risk (and management… Read more

Using Computer Name Aliases in place of DNS CNAME Records

Hi everyone. Graeme Bray here with an article around using Computer Name Aliases instead of DNS CName records.  In the past, we used to set the registry key DisableStrictNameChecking to be able to add a DNS alias to connect via a name (such as fileserver.contoso.com).  Starting with Windows Server 2008, we added functionality to be… Read more

KMS Activation for Windows Server 2016

Hi everyone.  Graeme Bray here with a quick article around KMS and Server 2016.  KMS and Server 2016 you say?  Shouldn’t I be using Active Directory Based Activation?  Yes, you should, but in case you are not, let’s go over the pre-requisites to activate Windows Server 2016 via KMS. ********* UPDATE (5/5/17)***************** The requirements have… Read more