<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.dirteam.com/utility/FeedStylesheets/atom.xsl" media="screen"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en"><title type="html">Paul Bergson (MVP - Directory Services)</title><subtitle type="html" /><id>http://blogs.dirteam.com/blogs/paulbergson/atom.aspx</id><link rel="alternate" type="text/html" href="http://blogs.dirteam.com/blogs/paulbergson/default.aspx" /><link rel="self" type="application/atom+xml" href="http://blogs.dirteam.com/blogs/paulbergson/atom.aspx" /><generator uri="http://communityserver.org" version="2.1.20423.1">Community Server</generator><updated>2011-01-31T07:48:00Z</updated><entry><title>Unexplained dcDiag Errors</title><link rel="alternate" type="text/html" href="http://blogs.dirteam.com/blogs/paulbergson/archive/2013/06/14/unedxplained-dcdiag-errors.aspx" /><id>http://blogs.dirteam.com/blogs/paulbergson/archive/2013/06/14/unedxplained-dcdiag-errors.aspx</id><published>2013-06-14T18:23:00Z</published><updated>2013-06-14T18:23:00Z</updated><content type="html">&lt;P&gt;So I have been banging my head against a wall trying to figure out why I have been getting these crazy errors in dcDiag.&amp;nbsp; From all that I can tell replication is working as expected but yet I am getting errors that are mostly undocumented and difficult to find out any real information on.&lt;/P&gt;
&lt;P&gt;Starting test: VerifyReplicas&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; For the partition&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (DC=ForestDnsZones,DC=Domain,DC=COM) we encountered&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; the following error retrieving the cross-ref's&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (CN=78c43cf5-2740-4337-a139-341965555f1,CN=Partitions,CN=Configuration,DC=Domain,DC=COM)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; information: &lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LDAP Error 0x52b (1323).&lt;BR&gt;......................... DC-02 failed test VerifyReplicas&lt;/P&gt;
&lt;P&gt;Starting test: VerifyEnterpriseReferences&lt;BR&gt;&amp;nbsp;&amp;nbsp; Can't determine the age of the cross-ref&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; CN=78c43cf5-2740-4337-a139-341965555f1,CN=Partitions,CN=Configuration,DC=Domain,DC=COM&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; for the partition DC=ForestDnsZones,DC=Domain,DC=COM, so&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; following errors relating to this cross-ref/partition may disappear&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; after replication&amp;nbsp; coalesces.&amp;nbsp; Please ensure that replication is&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; working from the Domain Naming FSMO to this DC, and retry this test to&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; see if errors continue. &lt;BR&gt;&amp;nbsp;&amp;nbsp; Can't determine the age of the cross-ref&lt;BR&gt;......................... DC-02 failed test VerifyEnterpriseReferences&lt;/P&gt;
&lt;P&gt;Starting test: CutoffServers&lt;BR&gt;&amp;nbsp;&amp;nbsp; * Configuration Topology Aliveness Check&lt;BR&gt;&amp;nbsp;&amp;nbsp; * Analyzing the alive system replication topology for DC=ForestDnsZones,DC=Domain,DC=COM.&lt;BR&gt;&amp;nbsp;&amp;nbsp; * Performing upstream (of target) analysis.&lt;BR&gt;&amp;nbsp;&amp;nbsp; DsReplicaSyncAllW failed with error The naming context specified for this replication operation is invalid..&lt;BR&gt;&amp;nbsp;&amp;nbsp; * Performing downstream (of target) analysis.&lt;BR&gt;&amp;nbsp;&amp;nbsp; DsReplicaSyncAllW failed with error The naming context specified for this replication operation is invalid..&lt;BR&gt;.........................&amp;nbsp;DC-02 passed test CutoffServers&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I went through and verified i&amp;nbsp;was in the Domain Admins group, I verified that the Domain Admins security group had full permissions to&amp;nbsp;the objects in error.&amp;nbsp; Did extensive research on the internet in a number of different Bing searches to try and come up with even a hint as to what the problem was.&amp;nbsp; Still nothing.&amp;nbsp; I posed the question to DS MVP colleagues and the one thing Jorge pointed out was this was some type of password issue related to the 0x52b error.&amp;nbsp; I had run across something on the internet as well related to password and had been why I checked into the permissions on the objects.&lt;/P&gt;
&lt;P&gt;Finally a thought crossed my mind... I was using a trusted administrator user account from a User Forest, so out of desperation I logged on as a local admin.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; BAM!!!!!!&amp;nbsp; All the errors went away.&amp;nbsp; So the password error was probably some how related, but I couldn't explain why...&lt;/P&gt;
&lt;P&gt;Long story short - &lt;STRONG&gt;When running dcDiag always use a domain local admin account.&lt;/STRONG&gt;&lt;/P&gt;&lt;img src="http://blogs.dirteam.com/aggbug.aspx?PostID=7010" width="1" height="1"&gt;</content><author><name>pbbergs</name><uri>http://blogs.dirteam.com/members/pbbergs.aspx</uri></author><category term="dcDiag &amp;quot;LDAP Error 0x52b&amp;quot; VerifyEnterpriseReferences VerifyReplicas" scheme="http://blogs.dirteam.com/blogs/paulbergson/archive/tags/dcDiag+_2600_quot_3B00_LDAP+Error+0x52b_2600_quot_3B00_+VerifyEnterpriseReferences+VerifyReplicas/default.aspx" /></entry><entry><title>How to Build an AD Replication Delay (Lag) Site</title><link rel="alternate" type="text/html" href="http://blogs.dirteam.com/blogs/paulbergson/archive/2013/05/14/how-to-build-an-ad-replication-delay-lag-site.aspx" /><id>http://blogs.dirteam.com/blogs/paulbergson/archive/2013/05/14/how-to-build-an-ad-replication-delay-lag-site.aspx</id><published>2013-05-14T11:58:00Z</published><updated>2013-05-14T11:58:00Z</updated><content type="html">&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;To prevent having to restore objects from Active Directory due to accidentally deleting an object, you can have a remote DC which only sends/receives replication on a limited basis.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;You also want to prevent users from authenticating against, as well as services being used by other machines, since the metadata on this DC is aging away w/o replication keeping it up to date&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;Because of this you want to remove all advertised services via dns lookup.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;To do this, this DC must be isolated from other DC’s and all replication controlled.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;For that reason a separate site is required to control &lt;A href="http://technet2.microsoft.com/windowsserver/en/library/8fdb8bc9-bf93-4e6b-b350-f812c7607f7d1033.mspx?mfr=true" target=_blank&gt;&lt;FONT color=#0000ff&gt;Intersite Replication&lt;/FONT&gt;&lt;/A&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;The following are the steps taken to create a single lag site dc.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;If you would like to have more than one time frame to fall back upon, all you need do is repeat these steps for a different DC.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL style="MARGIN-TOP:0in;"&gt;
&lt;LI style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;mso-list:l2 level1 lfo1;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;Promote a member server to a DC and allow replication to complete&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; &lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;UL style="MARGIN-TOP:0in;"&gt;
&lt;LI style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;mso-list:l2 level2 lfo1;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;Don’t load any unnecessary services&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; &lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;mso-list:l2 level2 lfo1;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;Don’t load WINS nor make this a WINS client &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;LI style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;mso-list:l2 level1 lfo1;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;Create a separate site and site link (I use “Lag” as part of the name to help document it)&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; &lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;UL style="MARGIN-TOP:0in;"&gt;
&lt;LI style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;mso-list:l2 level2 lfo1;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;Create a new site &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;mso-list:l2 level2 lfo1;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;Create a new site link, including the source and the Lag sites.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;If you notice I have set the Site Link Replication Frequency (Replicate Every) to 15 minutes.&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; &lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt 1in;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL style="MARGIN-TOP:0in;"&gt;
&lt;UL style="MARGIN-TOP:0in;"&gt;
&lt;LI style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;mso-list:l2 level2 lfo1;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;Click on the “Change Schedule” button to set the replication schedule to a time frame that fits for your enterprise.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;In this example, I have set the replication schedule for Saturday morning from the hours of 12:00 am to 2:00 am.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;So this site should allow replication updates to occur every 15 minutes, on Saturday’s, from the hours of 12:00 am until 2:00 am.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;Once a replication cycle starts it will continue until complete, which can go beyond the 2:00 am time frame, but no new cycles will start after 2:00 am.&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; &lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL style="MARGIN-TOP:0in;"&gt;
&lt;LI style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;mso-list:l2 level1 lfo1;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;Define the subnet and link it to a site&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; &lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;UL style="MARGIN-TOP:0in;"&gt;
&lt;LI style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;mso-list:l2 level2 lfo1;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;Borrowing some knowledge from a &lt;A href="http://briandesmond.com/blog/archive/2007/01/30/subnet-definitions-in-active-directory.aspx?CommentPosted=true#commentmessage" target=_blank&gt;&lt;FONT color=#0000ff&gt;blog from Brian Desmond&lt;/FONT&gt;&lt;/A&gt;, I have created a separate single host site sub-net.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;I have reserved the address for the dc in dhcp (I reserved .240) and then defined the subnet as a /32 ip mask.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;The most precisely defined subnet in sites and services is considered the subnet location.&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; &lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt 0.75in;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL style="MARGIN-TOP:0in;"&gt;
&lt;LI style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;mso-list:l0 level1 lfo2;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;Move the new dc to the newly defined site (Lag Site)&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; &lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;Now that the DC has been placed in its own site and is no longer receiving regular AD replication updates, it needs to no longer advertise itself as a usable DC.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;To do this, a Group Policy Object will be created and linked to this new site.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL style="MARGIN-TOP:0in;"&gt;
&lt;LI style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;mso-list:l0 level1 lfo2;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;Create a new GPO, but do not link it to any OU or Site at this time&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; &lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;mso-list:l0 level1 lfo2;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;Edit the Policy DC Locator DNS records not registered by the DCs.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;This is located at Computer Configuration / Administrative Templates / System / Net Logon / DC Locator DNS Records.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;The following mnemonics should be entered into the entry box:&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; &lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;UL style="MARGIN-TOP:0in;"&gt;
&lt;LI style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;mso-list:l0 level2 lfo2;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;Ldap LdapAtSite Pdc Gc GcAtSite GcIpAddress DcByGuid Kdc KdcAtSite Dc DcAtSite Rfc1510Kdc Rfc1510KdcAtSite GenericGc GenericGcAtSite Rfc1510UdpKdc Rfc1510Kpwd Rfc1510UdpKpwd&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; &lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;
&lt;UL style="MARGIN-TOP:0in;"&gt;
&lt;LI style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;mso-list:l0 level1 lfo2;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;Link this new Group Policy to the “Lag” site, where the new DC resides&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; &lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;UL style="MARGIN-TOP:0in;"&gt;
&lt;LI style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;mso-list:l0 level2 lfo2;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;Change the policy to allow authenticated users to read and remove (Don’t deny) the right to apply&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; &lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;mso-list:l0 level2 lfo2;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;Add the computer name of the new DC and grant it Read and Apply.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;This will help prevent the wrong DC’s from having policy applied against.&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; &lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;LI style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;mso-list:l0 level1 lfo2;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;Shut down the new Lag site DC&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; &lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;UL style="MARGIN-TOP:0in;"&gt;
&lt;LI style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;mso-list:l0 level2 lfo2;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;Open up the dns zone _msdcs and remove all of the new DC’s dns service records&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; &lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;UL style="MARGIN-TOP:0in;"&gt;
&lt;LI style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;mso-list:l0 level3 lfo2;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;Do not remove the Alias (CNAME) record at the root of the zone&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; &lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;LI style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;mso-list:l0 level2 lfo2;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;Power the DC backup&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; &lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;UL style="MARGIN-TOP:0in;"&gt;
&lt;LI style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;mso-list:l0 level3 lfo2;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;During the reboot any dns records that would be needed will be rebuilt&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; &lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;/UL&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;Run dcdiag, repadmin and dnslint in verbose mode.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL style="MARGIN-TOP:0in;"&gt;
&lt;LI style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;mso-list:l1 level1 lfo3;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;DCDIAG /V /C /D /E /s:yourdcname &amp;gt; c:\dcdiag.log&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; &lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;mso-list:l1 level1 lfo3;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;repadmin.exe /showrepl dc* /verbose /all /intersite &amp;gt; c:\repl.txt&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; &lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;mso-list:l1 level1 lfo3;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;dnslint /ad /s&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;"ip address of your dc" &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;**Note 1: Using the /E switch in dcdiag will run diagnostics against ALL dc's in the forest.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;If you have significant numbers of DC's this test could generate significant detail and take a long time.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;You also want to take into account slow links to dc's which will also add to the time.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;**Note 2: There are certain errors to expect, since the lag site DC won’t be advertising as a KDC you will be warned about this, etc…&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;But, replication should be error free.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;**Note 3: Forced replication will still occur, this model only prevents scheduled replication.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.dirteam.com/aggbug.aspx?PostID=6861" width="1" height="1"&gt;</content><author><name>pbbergs</name><uri>http://blogs.dirteam.com/members/pbbergs.aspx</uri></author></entry><entry><title>Upgrading AD from 2003 to 2008 </title><link rel="alternate" type="text/html" href="http://blogs.dirteam.com/blogs/paulbergson/archive/2013/04/25/upgrading-ad-from-2003-to-2008.aspx" /><id>http://blogs.dirteam.com/blogs/paulbergson/archive/2013/04/25/upgrading-ad-from-2003-to-2008.aspx</id><published>2013-04-25T11:53:00Z</published><updated>2013-04-25T11:53:00Z</updated><content type="html">&lt;DIV class=Section1&gt;
&lt;P style="TEXT-ALIGN:center;" class=MsoNormal align=center&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:20pt;"&gt;Upgrading Active Directory from 2003 to 2008&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:14pt;"&gt;&lt;o:p&gt;---&amp;nbsp;(Note: This is a copy from another site and at this time my snapshots are missing)---&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="mso-list:l1 level1 lfo2;" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Symbol;FONT-SIZE:14pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:14pt;"&gt;Microsoft’s &lt;A href="http://technet.microsoft.com/en-us/library/cc771954(WS.10).aspx"&gt;&lt;FONT color=#0000ff&gt;Preupgrade&lt;/FONT&gt;&lt;/A&gt; check list&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="mso-list:l1 level1 lfo2;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Symbol;FONT-SIZE:14pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:14pt;"&gt;Before upgrading AD verify all current applications are compatible&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:1in;mso-list:l1 level2 lfo2;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:14pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:14pt;"&gt;Verify you are on the correct version for 2008&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:1.5in;mso-list:l1 level3 lfo2;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Wingdings;FONT-SIZE:14pt;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;§&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:14pt;"&gt;For example, does your SAN at its current release support 2008&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-LEFT:1.5in;mso-list:l1 level3 lfo2;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY:Wingdings;FONT-SIZE:14pt;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;§&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Does the version of Exchange you are running support 2008&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-LEFT:1in;mso-list:l1 level2 lfo2;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY:'Courier New';FONT-SIZE:14pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Ensure all dc’s Windows 2000 dc’s are at least at SP4 &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-LEFT:1.5in;mso-list:l1 level3 lfo2;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY:Wingdings;FONT-SIZE:14pt;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;§&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;From a command prompt run&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:150%;MARGIN-LEFT:2in;mso-list:l1 level4 lfo2;tab-stops:list 2.0in;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:150%;FONT-FAMILY:Wingdings;FONT-SIZE:14pt;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;Ø&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN style="LINE-HEIGHT:150%;FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:12pt;"&gt;repadmin/showattr&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="LINE-HEIGHT:150%;FONT-SIZE:14pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="mso-list:l1 level1 lfo2;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Symbol;FONT-SIZE:14pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:14pt;"&gt;Verify that your Active Directory forest is healthy&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:1in;mso-list:l1 level2 lfo2;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:14pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:14pt;"&gt;DCDIAG /V /C /D /E /s:yourdcname &amp;gt; c:\dcdiag.log&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:1in;mso-list:l1 level2 lfo2;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:14pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:14pt;"&gt;netdiag.exe /v &amp;gt; c:\netdiag.log (On each dc)&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:1in;mso-list:l1 level2 lfo2;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:14pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:14pt;"&gt;repadmin.exe /showrepl dc* /verbose /all /intersite &amp;gt; c:\repl.txt&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:1in;mso-list:l1 level2 lfo2;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:14pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:14pt;"&gt;ntfrsutl ds your_dc_name &amp;gt; c:\sysvol.log&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:150%;MARGIN-LEFT:1in;mso-list:l1 level2 lfo2;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:150%;FONT-FAMILY:'Courier New';FONT-SIZE:14pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:150%;FONT-SIZE:14pt;"&gt;dnslint /ad /s "ip address of your dc"&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:150%;mso-list:l1 level1 lfo2;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:150%;FONT-FAMILY:Symbol;FONT-SIZE:14pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:150%;FONT-SIZE:14pt;"&gt;Get a backup up of at least two separate dc’s, including your PDCe&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="mso-list:l1 level1 lfo2;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Symbol;FONT-SIZE:14pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:14pt;"&gt;Although you can upgrade, I would strongly urge you to do fresh install on all new 2008 installations&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:1in;mso-list:l1 level2 lfo2;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:14pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:14pt;"&gt;Upgrading&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:1.5in;mso-list:l1 level3 lfo2;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Wingdings;FONT-SIZE:14pt;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;§&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:14pt;"&gt;Verify that the hardware will be compatible with 2008&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:1.5in;mso-list:l1 level3 lfo2;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Wingdings;FONT-SIZE:14pt;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;§&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:14pt;"&gt;You cannot directly upgrade from W2K to W2K8, you must go W2K to W2K3 and then W2K3 to W2K8&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:1.5in;mso-list:l1 level3 lfo2;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Wingdings;FONT-SIZE:14pt;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;§&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:14pt;"&gt;The bloat associated with patching, etc… just is a waste of space&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2in;mso-list:l1 level4 lfo2;tab-stops:list 2.0in;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Wingdings;FONT-SIZE:14pt;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;Ø&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:14pt;"&gt;Verify you have plenty of disk space available&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2in;mso-list:l1 level4 lfo2;tab-stops:list 2.0in;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Wingdings;FONT-SIZE:14pt;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;Ø&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:14pt;"&gt;If you don’t have a good 20gb of free space, you are probably going to run into space issues, trust me on this.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;All future patches, etc… that roll into the o/s are kept in the system folder and slowly over time start to chew your volume.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-LEFT:1.5in;mso-list:l1 level3 lfo2;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY:Wingdings;FONT-SIZE:14pt;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;§&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;verify that the machine upgrading holds the FSMO role of operations Master (&lt;A href="http://technet.microsoft.com/en-us/library/cc732085(WS.10).aspx"&gt;&lt;FONT color=#0000ff&gt;Upgrade DC order&lt;/FONT&gt;&lt;/A&gt;)&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-LEFT:1in;mso-list:l1 level2 lfo2;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY:'Courier New';FONT-SIZE:14pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Fresh install &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-LEFT:1.5in;mso-list:l1 level3 lfo2;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY:Wingdings;FONT-SIZE:14pt;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;§&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Ensure you had at least a 50gb system partition&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:150%;MARGIN-LEFT:1.5in;mso-list:l1 level3 lfo2;mso-add-space:auto;" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="LINE-HEIGHT:150%;FONT-FAMILY:Wingdings;FONT-SIZE:14pt;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;§&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:150%;FONT-SIZE:14pt;"&gt;Consider using x64, all future Windows server operating systems are going to x64 bit, starting with 2008 R2&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:150%;MARGIN-LEFT:0.5in;" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT:150%;FONT-SIZE:16pt;"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/cc771461(WS.10).aspx"&gt;&lt;FONT color=#0000ff&gt;Prep&lt;/FONT&gt;&lt;/A&gt; the forest, domain and dns zones&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;mso-list:l1 level1 lfo2;" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="FONT-FAMILY:Symbol;FONT-SIZE:14pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Prep your forest&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:1in;mso-list:l1 level2 lfo2;mso-add-space:auto;" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:14pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:14pt;"&gt;Copy the adprep folder to a local folder on your dc or run from the cd&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:0.5in;" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:14pt;mso-no-proof:yes;"&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:14pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:1in;mso-list:l1 level2 lfo2;mso-add-space:auto;" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:14pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:14pt;"&gt;Make sure that you can log on to the schema master with an account that has sufficient credentials to run &lt;B&gt;adprep /forestprep&lt;/B&gt;. You must be a member of the Schema Admins group, the Enterprise Admins group, and the Domain Admins group of the domain that hosts the schema master, which is, by default, the forest root domain.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:1in;mso-list:l1 level2 lfo2;mso-add-space:auto;" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:14pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:14pt;"&gt;Execute adprep&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;(See &lt;A href="http://technet.microsoft.com/en-us/library/cc753437(WS.10).aspx"&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:11pt;"&gt;&lt;FONT color=#0000ff&gt;KB753437&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;, &lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:12pt;"&gt;Be sure this is run on the Schema master, otherwise it will not run&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:14pt;"&gt;)&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;" class=MsoNormal&gt;&lt;SPAN style="COLOR:#c00000;FONT-SIZE:14pt;"&gt;C:\adprep&amp;gt;adprep /forestprep&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE:12pt;"&gt;&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;" class=MsoNormal&gt;&lt;SPAN style="FONT-SIZE:12pt;"&gt;ADPREP WARNING:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;" class=MsoNormal&gt;&lt;SPAN style="FONT-SIZE:12pt;"&gt;Before running adprep, all Windows 2000 Active Directory Domain Controllers in the forest should be upgraded to Windows 2000 Service Pack 4 (SP4) or later.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;" class=MsoNormal&gt;&lt;SPAN style="FONT-SIZE:12pt;"&gt;[User Action]&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;" class=MsoNormal&gt;&lt;SPAN style="FONT-SIZE:12pt;"&gt;If ALL your existing Windows 2000 Active Directory Domain Controllers meet this requirement, type C and then press ENTER to continue. Otherwise, type any other key and press ENTER to quit.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;" class=MsoNormal&gt;&lt;SPAN style="COLOR:#c00000;FONT-SIZE:14pt;"&gt;c&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;" class=MsoNormal&gt;&lt;SPAN style="FONT-SIZE:12pt;"&gt;Opened Connection to DCTEST&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;" class=MsoNormal&gt;&lt;SPAN style="FONT-SIZE:12pt;"&gt;SSPI Bind succeeded&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;" class=MsoNormal&gt;&lt;SPAN style="FONT-SIZE:12pt;"&gt;Current Schema Version is 30&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;" class=MsoNormal&gt;&lt;SPAN style="FONT-SIZE:12pt;"&gt;Upgrading schema to version 44&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;" class=MsoNormal&gt;&lt;SPAN style="FONT-SIZE:12pt;"&gt;Connecting to "DCTEST"&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;" class=MsoNormal&gt;&lt;SPAN style="FONT-SIZE:12pt;"&gt;Logging in as current user using SSPI&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;" class=MsoNormal&gt;&lt;SPAN style="FONT-SIZE:12pt;"&gt;Importing directory from file "C:\WINDOWS\system32\sch31.ldf"&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;" class=MsoNormal&gt;&lt;SPAN style="FONT-SIZE:12pt;"&gt;Loading entries............................................................................................................................................&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;" class=MsoNormal&gt;&lt;SPAN style="FONT-SIZE:12pt;"&gt;139 entries modified successfully.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;" class=MsoNormal&gt;&lt;SPAN style="FONT-SIZE:12pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;" class=MsoNormal&gt;&lt;SPAN style="FONT-SIZE:12pt;"&gt;You should see multiple entries similar to above.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;Just let the system spin and you can go take a break while waiting.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;At the end you will see the following (Hopefully!).&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;" class=MsoNormal&gt;&lt;SPAN style="FONT-SIZE:12pt;"&gt;................................................................................&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;" class=MsoNormal&gt;&lt;SPAN style="FONT-SIZE:12pt;"&gt;................................................................................&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;" class=MsoNormal&gt;&lt;SPAN style="FONT-SIZE:12pt;"&gt;................................................................................&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;" class=MsoNormal&gt;&lt;SPAN style="FONT-SIZE:12pt;"&gt;................................................................................&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;" class=MsoNormal&gt;&lt;SPAN style="FONT-SIZE:12pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;" class=MsoNormal&gt;&lt;SPAN style="COLOR:#c00000;FONT-SIZE:14pt;"&gt;Adprep successfully updated the forest-wide information.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;" class=MsoNormal&gt;&lt;SPAN style="FONT-SIZE:12pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-LEFT:1in;mso-list:l1 level2 lfo2;mso-add-space:auto;" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="FONT-FAMILY:'Courier New';FONT-SIZE:14pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Although this dc has completed the schema upgrade, you must wait until ALL dc’s in your forest receive this change via replication (Converge).&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-LEFT:1.5in;mso-list:l1 level3 lfo2;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY:Wingdings;FONT-SIZE:14pt;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;§&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Depending on your forest this could be in a few minutes to possibly days&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-LEFT:1.5in;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-SIZE:12pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;mso-list:l1 level1 lfo2;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY:Symbol;FONT-SIZE:14pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Once the proper amount of time has passed, the domain’s should now also be ready to be prep’ped&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-LEFT:1in;mso-list:l1 level2 lfo2;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY:'Courier New';FONT-SIZE:14pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;If you would like to verify that the forest has been upgraded&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-LEFT:1.5in;mso-list:l1 level3 lfo2;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY:Wingdings;FONT-SIZE:14pt;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;§&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Start up ADSIEdit&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-LEFT:3in;mso-list:l1 level6 lfo2;tab-stops:list 3.0in;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-SIZE:14pt;mso-bidi-font-family:Calibri;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;1.&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Connect to Configuration / Configuration / ForestUpdates / ActiveDirectoryUpdate&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-LEFT:3.5in;mso-list:l1 level7 lfo2;tab-stops:list 3.5in;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-SIZE:14pt;mso-bidi-font-family:Calibri;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;1.&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Right Click and select Properties&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-LEFT:4in;mso-list:l1 level8 lfo2;tab-stops:list 4.0in;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-SIZE:14pt;mso-bidi-font-family:Calibri;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;1.&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Revision = 2&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-LEFT:2in;mso-list:l1 level4 lfo2;tab-stops:list 2.0in;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY:Wingdings;FONT-SIZE:14pt;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;Ø&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Connect to Schema / Schema&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-LEFT:2.5in;mso-list:l1 level5 lfo2;tab-stops:list 2.5in;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY:Symbol;FONT-SIZE:14pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;&amp;nbsp;&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Right click and select properties&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-LEFT:3in;mso-list:l1 level6 lfo2;tab-stops:list 3.0in;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-SIZE:14pt;mso-bidi-font-family:Calibri;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;1.&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;ObjectVersion = 44&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-LEFT:1in;mso-list:l1 level2 lfo2;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY:'Courier New';FONT-SIZE:14pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Adprep /domainprep&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;(Domain must be in Native Mode 2003)&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-LEFT:1.5in;mso-list:l1 level3 lfo2;mso-add-space:auto;" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="FONT-FAMILY:Wingdings;FONT-SIZE:14pt;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;§&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Adprep /domainprep /gpprep&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;(Use this command line if upgrading from Windows 2000, Windows must be in Native Mode 2000)&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;" class=MsoNormal&gt;&lt;SPAN style="COLOR:#c00000;FONT-SIZE:14pt;"&gt;C:\adprep&amp;gt;adprep /domainprep&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;" class=MsoNormal&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Running domainprep ...&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;" class=MsoNormal&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Adprep successfully updated the domain-wide information.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;" class=MsoNormal&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;The new cross domain planning functionality for Group Policy, RSOP Planning Mode, requires file system and Active Directory Domain Services permissions to be updated for existing Group Policy Objects (GPOs). You can enable this functionality at any time by running "adprep.exe /domainprep /gpprep" on the Active Directory Domain Controller that holds the infrastructure operations master role.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;" class=MsoNormal&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;This operation will cause all GPOs located in the policies folder of the SYSVOL to be replicated once between the AD DCs in this domain.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;Microsoft recommends reading KB Q324392, particularly if you have a large number of Group policy Objects.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-LEFT:1in;mso-list:l1 level2 lfo2;mso-add-space:auto;" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="FONT-FAMILY:'Courier New';FONT-SIZE:14pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Although this dc has completed the domain prep upgrade, you must wait until ALL dc’s in this domain receive this change via replication (Converge).&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-LEFT:1.5in;mso-list:l1 level3 lfo2;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY:Wingdings;FONT-SIZE:14pt;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;§&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Depending on your domain this could be in a few minutes to possibly days&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-LEFT:1.5in;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;mso-list:l1 level1 lfo2;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY:Symbol;FONT-SIZE:14pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Once the proper amount of time has passed&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-LEFT:1in;mso-list:l1 level2 lfo2;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY:'Courier New';FONT-SIZE:14pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;If you would like to verify that the domain has been upgraded&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-LEFT:1.5in;mso-list:l1 level3 lfo2;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY:Wingdings;FONT-SIZE:14pt;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;§&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Start up ADSIEdit&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-LEFT:2in;mso-list:l1 level4 lfo2;tab-stops:list 2.0in;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY:Wingdings;FONT-SIZE:14pt;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;Ø&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Connect to Configuration / Configuration / ForestUpdates / ActiveDirectoryUpdate&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-LEFT:0.25in;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="mso-list:l1 level1 lfo2;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Symbol;FONT-SIZE:14pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:14pt;"&gt;If there are any near or far term plans to install RODC’s, prep your dns zones&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:1in;mso-list:l1 level2 lfo2;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:14pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:14pt;"&gt;Adprep /rodcprep&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:1.5in;mso-list:l1 level3 lfo2;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Wingdings;FONT-SIZE:14pt;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;§&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:14pt;"&gt;This will traverse through the separate partitions and update the permissions&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2in;mso-list:l1 level4 lfo2;tab-stops:list 2.0in;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Wingdings;FONT-SIZE:14pt;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;Ø&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:14pt;"&gt;Verify that the prep completed without error&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2.5in;mso-list:l1 level5 lfo2;tab-stops:list 2.5in;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Symbol;FONT-SIZE:14pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;&amp;nbsp;&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;COLOR:red;FONT-SIZE:14pt;"&gt;Adprep completed without errors.&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:14pt;"&gt; All partitions are updated. See the ADPrep.log in directory C:\WINDOWS\debug\adprep\logs\yyyymmdd999999 for more information.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="mso-list:l1 level1 lfo2;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Symbol;FONT-SIZE:14pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:14pt;"&gt;Prep your domain &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:1in;mso-list:l1 level2 lfo2;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:14pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:14pt;"&gt;Connect to the FSMO Infrastructure Master role holder&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:1in;mso-list:l1 level2 lfo2;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:14pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:14pt;"&gt;From the cd either copy the \sources\adprep or run the following:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:1.5in;mso-list:l1 level3 lfo2;mso-add-space:auto;" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Wingdings;FONT-SIZE:14pt;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;§&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:14pt;"&gt;Adprep /domainprep /gpprep&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:14pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:0.25in;" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;Begin the actual installation&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="mso-list:l0 level1 lfo4;" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Symbol;FONT-SIZE:16pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;New 2008 DC&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:1in;mso-list:l0 level2 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:16pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;Verify that the AD DS role has been installed on your 2008 member server&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:1in;mso-list:l0 level2 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:16pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;From an elevated command prompt promote this new DC&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:1.5in;mso-list:l0 level3 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Wingdings;FONT-SIZE:16pt;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;§&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;Dcpromo&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2in;mso-list:l0 level4 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Symbol;FONT-SIZE:16pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;mso-no-proof:yes;"&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:0in;" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2in;mso-list:l0 level4 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Symbol;FONT-SIZE:16pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;The following will pop up&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2.5in;mso-list:l0 level5 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:16pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;mso-no-proof:yes;"&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:0in;MARGIN-LEFT:2in;" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2in;mso-list:l0 level4 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Symbol;FONT-SIZE:16pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;Followed by, Select Next&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2.5in;mso-list:l0 level5 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:16pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;mso-no-proof:yes;"&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:0in;MARGIN-LEFT:2in;" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2in;mso-list:l0 level4 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Symbol;FONT-SIZE:16pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;Read the description on new secure channel controls and verify that you understand its impact and then select next&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2.5in;mso-list:l0 level5 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:16pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;A href="http://support.microsoft.com/?id=942564"&gt;&lt;FONT color=#0000ff&gt;KB942564&lt;/FONT&gt;&lt;/A&gt; explains in greater details its impact within your organization&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2.5in;mso-list:l0 level5 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:16pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;mso-no-proof:yes;"&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:0in;MARGIN-LEFT:2in;" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2in;mso-list:l0 level4 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Symbol;FONT-SIZE:16pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;Select Existing Forest and click next&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2.5in;mso-list:l0 level5 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:16pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;mso-no-proof:yes;"&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:0in;MARGIN-LEFT:2in;" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2in;mso-list:l0 level4 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Symbol;FONT-SIZE:16pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;Verify the forest and credentials are properly set and click next&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2.5in;mso-list:l0 level5 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:16pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;mso-no-proof:yes;"&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:0in;MARGIN-LEFT:2in;" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2in;mso-list:l0 level4 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Symbol;FONT-SIZE:16pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;Select a domain for this additional domain controller and click next&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2.5in;mso-list:l0 level5 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:16pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;mso-no-proof:yes;"&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:0in;MARGIN-LEFT:2in;" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2in;mso-list:l0 level4 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Symbol;FONT-SIZE:16pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;Select the site where you would like the new dc to be placed in and click next&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2.5in;mso-list:l0 level5 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:16pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;mso-no-proof:yes;"&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:0in;MARGIN-LEFT:2in;" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2in;mso-list:l0 level4 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Symbol;FONT-SIZE:16pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;Select those additional services you would require this dc to have and click next&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2.5in;mso-list:l0 level5 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:16pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;mso-no-proof:yes;"&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:0in;MARGIN-LEFT:2in;" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2in;mso-list:l0 level4 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Symbol;FONT-SIZE:16pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;If the following pop up box appears&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2.5in;mso-list:l0 level5 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:16pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;mso-no-proof:yes;"&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:0in;MARGIN-LEFT:2in;" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:3in;mso-list:l0 level6 lfo4;mso-add-space:auto;" class=MsoListParagraph&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Wingdings;FONT-SIZE:16pt;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;§&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;If you are installing an additional domain controller in either the forest root domain or a tree root domain, you do not have to create the DNS delegation. In this case, click &lt;B&gt;Yes&lt;/B&gt; and disregard the message.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:0in;MARGIN-LEFT:2.5in;" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2in;mso-list:l0 level4 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Symbol;FONT-SIZE:16pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;Verify the default locations are as expected and click Next&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2.5in;mso-list:l0 level5 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:16pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;mso-no-proof:yes;"&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:0in;MARGIN-LEFT:2in;" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2in;mso-list:l0 level4 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Symbol;FONT-SIZE:16pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;Enter the AD DS password and click Next&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2.5in;mso-list:l0 level5 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:16pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;mso-no-proof:yes;"&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:0in;MARGIN-LEFT:2in;" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2in;mso-list:l0 level4 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Symbol;FONT-SIZE:16pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;On the Summary dialog box, verify all settings are correct and hit Next&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2.5in;mso-list:l0 level5 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:16pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;mso-no-proof:yes;"&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:0in;MARGIN-LEFT:2in;" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2in;mso-list:l0 level4 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Symbol;FONT-SIZE:16pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;The following box will appear while the promotion advances.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;Please be patient during this process, depending on the size of your AD environment this could take a few minutes to multiple hours.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2.5in;mso-list:l0 level5 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:16pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;mso-no-proof:yes;"&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:0in;MARGIN-LEFT:2in;" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2in;mso-list:l0 level4 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Symbol;FONT-SIZE:16pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;Once the promotion is complete, click Finish and Restart the newly promoted dc&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2.5in;mso-list:l0 level5 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:16pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;mso-no-proof:yes;"&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:0in;MARGIN-LEFT:2in;" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2.5in;mso-list:l0 level5 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:16pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;mso-no-proof:yes;"&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:0in;MARGIN-LEFT:2in;" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="mso-list:l0 level1 lfo4;" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Symbol;FONT-SIZE:16pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;Once complete allow all DC’s to properly replicate all changes within the infrastructure&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="mso-list:l0 level1 lfo4;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Symbol;FONT-SIZE:16pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;Microsoft recommends moving the FSMO roles to a 2008 DC&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:1in;mso-list:l0 level2 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:16pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;From Active Directory Users and Computers (ADUC) right click on the domain and select Operations Masters&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:1.5in;mso-list:l0 level3 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Wingdings;FONT-SIZE:16pt;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;§&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;mso-no-proof:yes;"&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:0in;MARGIN-LEFT:1in;" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:1in;mso-list:l0 level2 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:16pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;From each of the three tabs (RID, PDC and Infrastructure) change to a 2008 DC&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:1.5in;mso-list:l0 level3 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Wingdings;FONT-SIZE:16pt;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;§&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;mso-no-proof:yes;"&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:0in;MARGIN-LEFT:1in;" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:1.5in;mso-list:l0 level3 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Wingdings;FONT-SIZE:16pt;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;§&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;If your destination IM is also a GC, make sure all other dc’s are gc’s or that this is a single domain forest.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;Otherwise you can create phantom object problems.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:1in;mso-list:l0 level2 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:16pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;From Active Directory Domain and Trusts&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:1.5in;mso-list:l0 level3 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Wingdings;FONT-SIZE:16pt;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;§&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;Verify you are connected to the DC you want to transfer the Domain Naming role to&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:1.5in;mso-list:l0 level3 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Wingdings;FONT-SIZE:16pt;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;§&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;Right click and select Operations Manager&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:1.5in;mso-list:l0 level3 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Wingdings;FONT-SIZE:16pt;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;§&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;mso-no-proof:yes;"&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:0in;MARGIN-LEFT:1in;" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:1in;mso-list:l0 level2 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:16pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;From Schema Management&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:1.5in;mso-list:l0 level3 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Wingdings;FONT-SIZE:16pt;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;§&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;If you haven’t already, register the schema management&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2in;mso-list:l0 level4 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Symbol;FONT-SIZE:16pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;From a command prompt&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2.5in;mso-list:l0 level5 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:16pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;regsvr32 schmmgmt.dll&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2in;mso-list:l0 level4 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Symbol;FONT-SIZE:16pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;In the mmc console add the Schema management&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2in;mso-list:l0 level4 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Symbol;FONT-SIZE:16pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;Select the Schema management console and connect to the DC you want to move the FSMO role to&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2in;mso-list:l0 level4 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Symbol;FONT-SIZE:16pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;Right click on Schema management and Select operations Management&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:2.5in;mso-list:l0 level5 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:16pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;mso-no-proof:yes;"&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:0in;MARGIN-LEFT:2in;" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:1in;mso-list:l0 level2 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:'Courier New';FONT-SIZE:16pt;mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;To verify all fsmo roles have been transferred run the following from a command prompt&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:1.5in;mso-list:l0 level3 lfo4;mso-add-space:auto;" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-FAMILY:Wingdings;FONT-SIZE:16pt;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;§&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:16pt;"&gt;Netdom query fsmo&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:0.25in;" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT:115%;FONT-SIZE:14pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;img src="http://blogs.dirteam.com/aggbug.aspx?PostID=6837" width="1" height="1"&gt;</content><author><name>pbbergs</name><uri>http://blogs.dirteam.com/members/pbbergs.aspx</uri></author><category term="Active Directory upgrade 2003 2008" scheme="http://blogs.dirteam.com/blogs/paulbergson/archive/tags/Active+Directory+upgrade+2003+2008/default.aspx" /></entry><entry><title>Preventing Spoke DC’s from Advertising in the Hub Site for Authentication Availability</title><link rel="alternate" type="text/html" href="http://blogs.dirteam.com/blogs/paulbergson/archive/2013/01/02/preventing-spoke-dc-s-from-advertising-in-the-hub-site-for-authentication-availability.aspx" /><id>http://blogs.dirteam.com/blogs/paulbergson/archive/2013/01/02/preventing-spoke-dc-s-from-advertising-in-the-hub-site-for-authentication-availability.aspx</id><published>2013-01-02T20:21:00Z</published><updated>2013-01-02T20:21:00Z</updated><content type="html">&lt;P class=MsoNormal&gt;If you have a hub and spoke site topology, it may not be a good idea for certain (Or all) spoke dc’s to be advertising, via &lt;SPAN class=SpellE&gt;dns&lt;/SPAN&gt; services, the ability to provide authentications services.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;If you have a remote site with a dc that fails it is usually best that the spoke send its users to the hub for authentication purposes.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;By default Active Directory (AD) doesn’t act this way.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;If you would like set up your spokes to only advertised in its own site then you will want to configure a group policy (Windows 2003 and above) to prevent these spoke dc’s from advertising.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;For machines running Windows 2000 you will need to do a &lt;SPAN class=SpellE&gt;reg&lt;/SPAN&gt; hack (KB article defined later).&lt;/P&gt;
&lt;P class=MsoNormal&gt;You will need to create a new group policy and define which DC’s will have read and apply policy.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;Make sure to remove the authenticated users apply permission otherwise ALL dc’s will have this policy applied once it is link to the Domain Controllers &lt;SPAN class=SpellE&gt;ou&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:-0.25in;mso-list:l0 level1 lfo2;" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="FONT-FAMILY:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;Open up Group Policy Management and create a new Policy&lt;/P&gt;
&lt;P style="TEXT-INDENT:-0.25in;mso-list:l0 level1 lfo2;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;Select this new Policy and click on the Delegation tab&lt;/P&gt;
&lt;P style="TEXT-INDENT:-0.25in;MARGIN-LEFT:1in;mso-add-space:auto;mso-list:l0 level2 lfo2;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY:'Courier New';mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;Select the Advanced button&lt;/P&gt;
&lt;P style="TEXT-INDENT:-0.25in;MARGIN-LEFT:1.5in;mso-add-space:auto;mso-list:l0 level3 lfo2;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;§&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;Remove the apply permission to the Authenticated users&lt;/P&gt;
&lt;P style="TEXT-INDENT:-0.25in;MARGIN-LEFT:1.5in;mso-add-space:auto;mso-list:l0 level3 lfo2;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;§&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;Add each DC you would like to apply this policy to&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;and provide read and apply permissions&lt;/P&gt;
&lt;P style="TEXT-INDENT:-0.25in;mso-list:l0 level1 lfo2;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;Right click on the policy and select Edit&lt;/P&gt;
&lt;P style="TEXT-INDENT:-0.25in;MARGIN-LEFT:1in;mso-add-space:auto;mso-list:l0 level2 lfo2;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY:'Courier New';mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;Computer Configuration / Administrative Templates / System / Net Logon / DC Locator DNS records&lt;/P&gt;
&lt;P style="TEXT-INDENT:-0.25in;MARGIN-LEFT:1.5in;mso-add-space:auto;mso-list:l0 level3 lfo2;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;§&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;Double click on DC Locator DNS records not registered by the DCs&lt;/P&gt;
&lt;P style="TEXT-INDENT:-0.25in;MARGIN-LEFT:2in;mso-add-space:auto;mso-list:l0 level4 lfo2;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;Key in the Mnemonics below (Copy and paste)&lt;/P&gt;
&lt;P style="TEXT-INDENT:0.5in;MARGIN-LEFT:1.5in;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;DC &lt;SPAN class=SpellE&gt;DcByGuid&lt;/SPAN&gt; &lt;SPAN class=SpellE&gt;&lt;SPAN class=GramE&gt;Gc&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=SpellE&gt;GcIpAddress&lt;/SPAN&gt; &lt;SPAN class=SpellE&gt;GenericGC&lt;/SPAN&gt; &lt;SPAN class=SpellE&gt;Kdc&lt;/SPAN&gt; &lt;SPAN class=SpellE&gt;Ldap&lt;/SPAN&gt; &lt;SPAN class=SpellE&gt;LdapIpAddress&lt;/SPAN&gt; Rfc1510Kdc Rfc1510Kpwd Rfc1510UpdKdc Rfc1510UdpKpwd&lt;/P&gt;
&lt;P style="TEXT-INDENT:-0.25in;MARGIN-LEFT:2.75in;mso-add-space:auto;mso-list:l2 level1 lfo4;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;See below for Mnemonics definitions&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:0in;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;Wait for/or force replication and then from a command prompt on each dc in question key in the following:&lt;/P&gt;
&lt;P style="TEXT-INDENT:-0.25in;mso-list:l1 level1 lfo6;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=SpellE&gt;Gpupdate&lt;/SPAN&gt; /force&lt;/P&gt;
&lt;P style="TEXT-INDENT:-0.25in;MARGIN-LEFT:1in;mso-add-space:auto;mso-list:l1 level2 lfo6;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY:'Courier New';mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;This will apply the new policy&lt;/P&gt;
&lt;P style="TEXT-INDENT:-0.25in;mso-list:l1 level1 lfo6;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;Restart the &lt;SPAN class=SpellE&gt;NetLogon&lt;/SPAN&gt; service (Or run &lt;SPAN class=SpellE&gt;netdiag&lt;/SPAN&gt; /fix)&lt;/P&gt;
&lt;P style="TEXT-INDENT:-0.25in;MARGIN-LEFT:1in;mso-add-space:auto;mso-list:l1 level2 lfo6;" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="FONT-FAMILY:'Courier New';mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;This will update the &lt;SPAN class=SpellE&gt;dns&lt;/SPAN&gt; records.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;Make sure when you check that you verify on the server this dc is attached to or wait for replication to take place.&lt;/P&gt;
&lt;P style="MARGIN-LEFT:0in;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:0in;mso-add-space:auto;" class=MsoListParagraphCxSpMiddle&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:0in;mso-add-space:auto;" class=MsoListParagraphCxSpLast&gt;The following table was taken from the KB article &lt;A href="http://support.microsoft.com/kb/306602"&gt;KB306602&lt;/A&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:18pt;MARGIN-BOTTOM:3.75pt;mso-outline-level:5;" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:9pt;mso-fareast-font-family:'Times New Roman';"&gt;Reference Tables&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:18pt;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:9pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;The following tables contain mnemonics, types, and the owner names of the domain controller locator DNS records that should not be registered by the satellite domain controllers and global catalogs to optimize the domain controller location.&lt;BR&gt;&lt;BR&gt;&lt;B&gt;Domain Controller-Specific Records&lt;/B&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:18pt;MARGIN-BOTTOM:7.5pt;VERTICAL-ALIGN:middle;" class=MsoNormal&gt;&lt;SPAN style="DISPLAY:none;FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';mso-hide:all;mso-bidi-font-size:11.0pt;"&gt;Collapse this tableExpand this table&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;TABLE style="mso-cellspacing:.7pt;mso-yfti-tbllook:1184;mso-padding-alt:0in 5.4pt 0in 5.4pt;" class=MsoNormalTable cellSpacing=1 cellPadding=0&gt;

&lt;TR style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#cecfce;PADDING-TOP:3.75pt;"&gt;
&lt;P style="TEXT-ALIGN:center;LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal align=center&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;Mnemonic&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#cecfce;PADDING-TOP:3.75pt;"&gt;
&lt;P style="TEXT-ALIGN:center;LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal align=center&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;Type&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#cecfce;PADDING-TOP:3.75pt;"&gt;
&lt;P style="TEXT-ALIGN:center;LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal align=center&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;DNS Record&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:1;"&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#f7f7ff;PADDING-TOP:3.75pt;" vAlign=top&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;SPAN class=SpellE&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;LdapIpAddress&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#f7f7ff;PADDING-TOP:3.75pt;" vAlign=top&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;A&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#f7f7ff;PADDING-TOP:3.75pt;" vAlign=top&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;&amp;lt;&lt;SPAN class=SpellE&gt;DnsDomainName&lt;/SPAN&gt;&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:2;"&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#f7f7ff;PADDING-TOP:3.75pt;" vAlign=top&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;SPAN class=SpellE&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;Ldap&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#f7f7ff;PADDING-TOP:3.75pt;" vAlign=top&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;SRV&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#f7f7ff;PADDING-TOP:3.75pt;" vAlign=top&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;_&lt;SPAN class=SpellE&gt;ldap._tcp&lt;/SPAN&gt;.&amp;lt;&lt;SPAN class=SpellE&gt;DnsDomainName&lt;/SPAN&gt;&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:3;"&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#f7f7ff;PADDING-TOP:3.75pt;" vAlign=top&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;SPAN class=SpellE&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;DcByGuid&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#f7f7ff;PADDING-TOP:3.75pt;" vAlign=top&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;SRV&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#f7f7ff;PADDING-TOP:3.75pt;" vAlign=top&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;_&lt;SPAN class=SpellE&gt;ldap._tcp&lt;/SPAN&gt;.&amp;lt;&lt;SPAN class=SpellE&gt;DomainGuid&lt;/SPAN&gt;&amp;gt;.&lt;SPAN class=SpellE&gt;domains._msdcs&lt;/SPAN&gt;.&amp;lt;&lt;SPAN class=SpellE&gt;DnsForestName&lt;/SPAN&gt;&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:4;"&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#f7f7ff;PADDING-TOP:3.75pt;" vAlign=top&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;SPAN class=SpellE&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;Kdc&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#f7f7ff;PADDING-TOP:3.75pt;" vAlign=top&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;SRV&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#f7f7ff;PADDING-TOP:3.75pt;" vAlign=top&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;_&lt;SPAN class=SpellE&gt;kerberos._tcp.dc._msdcs&lt;/SPAN&gt;.&amp;lt;&lt;SPAN class=SpellE&gt;DnsDomainName&lt;/SPAN&gt;&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:5;"&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#f7f7ff;PADDING-TOP:3.75pt;" vAlign=top&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;Dc&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#f7f7ff;PADDING-TOP:3.75pt;" vAlign=top&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;SRV&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#f7f7ff;PADDING-TOP:3.75pt;" vAlign=top&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;_&lt;SPAN class=SpellE&gt;ldap._tcp.dc._msdcs&lt;/SPAN&gt;.&amp;lt;&lt;SPAN class=SpellE&gt;DnsDomainName&lt;/SPAN&gt;&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:6;"&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#f7f7ff;PADDING-TOP:3.75pt;" vAlign=top&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;Rfc1510Kdc&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#f7f7ff;PADDING-TOP:3.75pt;" vAlign=top&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;SRV&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#f7f7ff;PADDING-TOP:3.75pt;" vAlign=top&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;_&lt;SPAN class=SpellE&gt;kerberos._tcp&lt;/SPAN&gt;.&amp;lt;&lt;SPAN class=SpellE&gt;DnsDomainName&lt;/SPAN&gt;&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:7;"&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#f7f7ff;PADDING-TOP:3.75pt;" vAlign=top&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;Rfc1510UdpKdc&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#f7f7ff;PADDING-TOP:3.75pt;" vAlign=top&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;SRV&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#f7f7ff;PADDING-TOP:3.75pt;" vAlign=top&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;_&lt;SPAN class=SpellE&gt;kerberos._udp&lt;/SPAN&gt;.&amp;lt;&lt;SPAN class=SpellE&gt;DnsDomainName&lt;/SPAN&gt;&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:8;"&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#f7f7ff;PADDING-TOP:3.75pt;" vAlign=top&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;Rfc1510Kpwd&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#f7f7ff;PADDING-TOP:3.75pt;" vAlign=top&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;SRV&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#f7f7ff;PADDING-TOP:3.75pt;" vAlign=top&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;_&lt;SPAN class=SpellE&gt;kpasswd._tcp&lt;/SPAN&gt;.&amp;lt;&lt;SPAN class=SpellE&gt;DnsDomainName&lt;/SPAN&gt;&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:9;mso-yfti-lastrow:yes;"&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#f7f7ff;PADDING-TOP:3.75pt;" vAlign=top&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;Rfc1510UdpKpwd&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#f7f7ff;PADDING-TOP:3.75pt;" vAlign=top&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;SRV&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#f7f7ff;PADDING-TOP:3.75pt;" vAlign=top&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;_&lt;SPAN class=SpellE&gt;kpasswd._udp&lt;/SPAN&gt;.&amp;lt;&lt;SPAN class=SpellE&gt;DnsDomainName&lt;/SPAN&gt;&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TABLE&gt;
&lt;P style="LINE-HEIGHT:18pt;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;Global Catalog-Specific Records&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:18pt;MARGIN-BOTTOM:7.5pt;VERTICAL-ALIGN:middle;" class=MsoNormal&gt;&lt;SPAN style="DISPLAY:none;FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';mso-hide:all;mso-bidi-font-size:11.0pt;"&gt;Collapse this tableExpand this table&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;TABLE style="mso-cellspacing:.7pt;mso-yfti-tbllook:1184;mso-padding-alt:0in 5.4pt 0in 5.4pt;" class=MsoNormalTable cellSpacing=1 cellPadding=0&gt;

&lt;TR style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#cecfce;PADDING-TOP:3.75pt;"&gt;
&lt;P style="TEXT-ALIGN:center;LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal align=center&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;Mnemonic&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#cecfce;PADDING-TOP:3.75pt;"&gt;
&lt;P style="TEXT-ALIGN:center;LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal align=center&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;Type&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#cecfce;PADDING-TOP:3.75pt;"&gt;
&lt;P style="TEXT-ALIGN:center;LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal align=center&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;DNS Record&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:1;"&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#f7f7ff;PADDING-TOP:3.75pt;" vAlign=top&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;SPAN class=SpellE&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;Gc&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#f7f7ff;PADDING-TOP:3.75pt;" vAlign=top&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;SRV&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#f7f7ff;PADDING-TOP:3.75pt;" vAlign=top&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;_&lt;SPAN class=SpellE&gt;ldap._tcp.gc._msdcs&lt;/SPAN&gt;.&amp;lt;&lt;SPAN class=SpellE&gt;DnsForestName&lt;/SPAN&gt;&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:2;"&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#f7f7ff;PADDING-TOP:3.75pt;" vAlign=top&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;SPAN class=SpellE&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;GcIpAddress&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#f7f7ff;PADDING-TOP:3.75pt;" vAlign=top&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;A&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#f7f7ff;PADDING-TOP:3.75pt;" vAlign=top&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;SPAN class=SpellE&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;gc._msdcs&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;.&amp;lt;&lt;SPAN class=SpellE&gt;DnsForestName&lt;/SPAN&gt;&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:3;mso-yfti-lastrow:yes;"&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#f7f7ff;PADDING-TOP:3.75pt;" vAlign=top&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;SPAN class=SpellE&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;GenericGc&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#f7f7ff;PADDING-TOP:3.75pt;" vAlign=top&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;SRV&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="PADDING-BOTTOM:3.75pt;PADDING-LEFT:3.75pt;PADDING-RIGHT:3.75pt;BACKGROUND:#f7f7ff;PADDING-TOP:3.75pt;" vAlign=top&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN-BOTTOM:0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Verdana','sans-serif';COLOR:black;FONT-SIZE:8.5pt;mso-fareast-font-family:'Times New Roman';"&gt;_&lt;SPAN class=SpellE&gt;gc._tcp&lt;/SPAN&gt;.&amp;lt;&lt;SPAN class=SpellE&gt;DnsForestName&lt;/SPAN&gt;&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TABLE&gt;&lt;img src="http://blogs.dirteam.com/aggbug.aspx?PostID=6738" width="1" height="1"&gt;</content><author><name>pbbergs</name><uri>http://blogs.dirteam.com/members/pbbergs.aspx</uri></author></entry><entry><title>How to Decommission a Domain Controller</title><link rel="alternate" type="text/html" href="http://blogs.dirteam.com/blogs/paulbergson/archive/2012/07/25/how-to-decommission-a-domain-controller.aspx" /><id>http://blogs.dirteam.com/blogs/paulbergson/archive/2012/07/25/how-to-decommission-a-domain-controller.aspx</id><published>2012-07-25T12:01:00Z</published><updated>2012-07-25T12:01:00Z</updated><content type="html">&lt;P class=MsoNormal&gt;Decommissioning a dc requires all domain services that currently reside on a server need to be moved to other &lt;SPAN class=GramE&gt;dc’s&lt;/SPAN&gt;.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;UL style="MARGIN-TOP:0in;"&gt;
&lt;LI style="mso-list:l0 level1 lfo3;tab-stops:list .5in;" class=MsoNormal&gt;You need to move any fsmo roles from this dc to another dc &lt;A href="http://support.microsoft.com/default.aspx?scid=kb;en-us;255690&amp;amp;Product=win2000"&gt;&lt;FONT color=#0000ff&gt;(KB255960)&lt;/FONT&gt;&lt;/A&gt; 
&lt;UL style="MARGIN-TOP:0in;"&gt;
&lt;LI style="mso-list:l0 level2 lfo3;tab-stops:list 1.0in;" class=MsoNormal&gt;To learn where the roles reside run the command&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN class=SpellE&gt;netdom&lt;/SPAN&gt; query fsmo 
&lt;LI style="mso-list:l0 level2 lfo3;tab-stops:list 1.0in;" class=MsoNormal&gt;If the &lt;SPAN class=SpellE&gt;PDCe&lt;/SPAN&gt; fsmo role resided on this DC then you need to reconfigure the new holder of the &lt;SPAN class=SpellE&gt;PDCe&lt;/SPAN&gt; to either use the internal hardware clock or an external source.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;I would recommend using an external source &lt;A href="http://support.microsoft.com/kb/816042/"&gt;&lt;FONT color=#0000ff&gt;KB816042&lt;/FONT&gt;&lt;/A&gt;. &lt;/LI&gt;&lt;/UL&gt;
&lt;LI style="mso-list:l0 level1 lfo3;tab-stops:list .5in;" class=MsoNormal&gt;There needs to be at least one Global Catalog (GC) in each domain and it is recommended that there is one in each site &lt;A href="http://192.168.0.1/cgi-bin/webcm"&gt;&lt;FONT color=#0000ff&gt;(KB313994)&lt;/FONT&gt;&lt;/A&gt; 
&lt;LI style="mso-list:l0 level1 lfo3;tab-stops:list .5in;" class=MsoNormal&gt;Move DNS services to other DC’s if this DC is a DNS provider.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;Also point all clients that use this server for DNS to the new DNS server 
&lt;UL style="MARGIN-TOP:0in;"&gt;
&lt;LI style="mso-list:l0 level2 lfo3;tab-stops:list 1.0in;" class=MsoNormal&gt;If AD integrated simply installing DNS on a member server prior to promotion will bring up a new DNS server 
&lt;LI style="mso-list:l0 level2 lfo3;tab-stops:list 1.0in;" class=MsoNormal&gt;If not AD integrated and this is a primary server then a new primary server will need to be brought &lt;SPAN class=GramE&gt;online.&lt;/SPAN&gt;&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;From DNS server manager the server needs to be promoted to primary 
&lt;LI style="mso-list:l0 level2 lfo3;tab-stops:list 1.0in;" class=MsoNormal&gt;If a secondary server then make the new dc a new secondary server &lt;/LI&gt;&lt;/UL&gt;
&lt;LI style="mso-list:l0 level1 lfo3;tab-stops:list .5in;" class=MsoNormal&gt;If a &lt;SPAN class=SpellE&gt;dhcp&lt;/SPAN&gt; server then the &lt;SPAN class=SpellE&gt;dhcp&lt;/SPAN&gt; &lt;SPAN class=GramE&gt;servers&lt;/SPAN&gt; database needs to be backed up and copied to the new &lt;SPAN class=SpellE&gt;dhcp&lt;/SPAN&gt; server.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;The old &lt;SPAN class=SpellE&gt;dhcp&lt;/SPAN&gt; server &lt;SPAN class=SpellE&gt;deauthorized&lt;/SPAN&gt; and the new &lt;SPAN class=SpellE&gt;dhcp&lt;/SPAN&gt; server authorized &lt;A href="http://support.microsoft.com/kb/325473/en-us"&gt;&lt;FONT color=#0000ff&gt;(KB325473)&lt;/FONT&gt;&lt;/A&gt; 
&lt;LI style="mso-list:l0 level1 lfo3;tab-stops:list .5in;" class=MsoNormal&gt;If you have Encryption File System (EFS) enabled you will need to move the private key if it resides on this dc &lt;SPAN class=MsoHyperlink&gt;&lt;U&gt;&lt;FONT color=#0000ff&gt;(&lt;/FONT&gt;&lt;/U&gt;&lt;A href="http://support.microsoft.com/Default.aspx?scid=kb;en-us;241201&amp;amp;x=5&amp;amp;y=13"&gt;&lt;FONT color=#0000ff&gt;KB241201&lt;/FONT&gt;&lt;/A&gt;&lt;U&gt;&lt;FONT color=#0000ff&gt;)&lt;/FONT&gt;&lt;/U&gt;&lt;/SPAN&gt;.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;You use the recovery agent's private key to recover data in situations when the copy of the EFS private key that is located on the local computer is lost 
&lt;LI style="mso-list:l0 level1 lfo3;tab-stops:list .5in;" class=MsoNormal&gt;If this server manages Terminal Server Licensing (TSL) then it will have to be moved to a new DC.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;From Add/Remove programs you will need to add a new TSL.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;You can then restore the licenses by using the TS License Manager tool with the Telephone activation mechanism. You can switch to the Telephone mechanism by right clicking on the server in TS License Manager, and then selecting properties from the menu. &lt;A href="http://www.microsoft.com/windowsserver2003/community/centers/terminal/terminal_faq.mspx"&gt;&lt;FONT color=#0000ff&gt;(TS FAQ)&lt;/FONT&gt;&lt;/A&gt; &lt;/LI&gt;&lt;/UL&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;Finally once this is all accomplished go ahead and demote the dc to a member server &lt;A href="http://support.microsoft.com/kb/238369/EN-US/"&gt;&lt;FONT color=#0000ff&gt;(KB238369)&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;&lt;img src="http://blogs.dirteam.com/aggbug.aspx?PostID=6155" width="1" height="1"&gt;</content><author><name>pbbergs</name><uri>http://blogs.dirteam.com/members/pbbergs.aspx</uri></author><category term="dcpromo &amp;quot;active directory&amp;quot; fsmo" scheme="http://blogs.dirteam.com/blogs/paulbergson/archive/tags/dcpromo+_2600_quot_3B00_active+directory_2600_quot_3B00_+fsmo/default.aspx" /></entry><entry><title>Create A Test Domain (Old Style)</title><link rel="alternate" type="text/html" href="http://blogs.dirteam.com/blogs/paulbergson/archive/2012/07/03/create-a-test-domain-old-style.aspx" /><id>http://blogs.dirteam.com/blogs/paulbergson/archive/2012/07/03/create-a-test-domain-old-style.aspx</id><published>2012-07-03T22:04:00Z</published><updated>2012-07-03T22:04:00Z</updated><content type="html">&lt;p style="mso-pagination:none;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;span style="font-size:14pt;"&gt;This document was prepared for the 
building of a copy of the production Active Directory.&lt;span style="mso-spacerun:yes;"&gt;  &lt;/span&gt;Following these steps will define how to 
rebuild the entire Microsoft Active Directory for a test domain.&lt;span style="mso-spacerun:yes;"&gt;  &lt;/span&gt;&lt;b&gt;*** Be careful 
***&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p style="mso-pagination:none;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;i&gt;The first set of steps is to get a good pc into the 
production domain.&lt;span style="mso-spacerun:yes;"&gt;  &lt;/span&gt;Once this pc is a 
member it needs to be promoted and be a healthy participant in the network.&lt;span style="mso-spacerun:yes;"&gt;  &lt;/span&gt;The new DC then needs to be removed from the 
network before it is restarted (From its restore) to prevent any replication 
activity from damaging the production system.&lt;span style="mso-spacerun:yes;"&gt;  
&lt;/span&gt;Reconnection to the production system will create major problems in the 
production system&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/p&gt;

&lt;p style="text-indent:-0.5in;margin-left:0.5in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l2 level1 lfo2;" class="MsoNormal"&gt;1.&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;                  
&lt;/span&gt;Shutdown &lt;b&gt;ALL&lt;/b&gt; pc’s within the test sub-net &lt;span style="mso-spacerun:yes;"&gt; &lt;/span&gt;(For this document it will be 192.168.1.x, 
gateway = 192.168.1.250), mask = 255.255.255.0&lt;/p&gt;
&lt;p style="text-indent:-0.5in;margin-left:0.5in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l2 level1 lfo3;" class="MsoNormal"&gt;2.&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;                  
&lt;/span&gt;Remove the physical cable for the new pc and build the member server 
(This all should reside within the test domain) in production&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Install DNS (AD 
Integrated needed for this document)&lt;/p&gt;
&lt;p style="text-indent:-0.5in;margin-left:0.5in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l2 level1 lfo4;" class="MsoNormal"&gt;3.&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;                  
&lt;/span&gt;Re-connect the cable and join the Domain_Name.com domain&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Select the IP Address 
192.168.1.101&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Select the mask to 
255.255.255.0&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Select the Gateway 
192.168.1.250&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Point the DNS services 
to a production AD DNS server&lt;/p&gt;
&lt;p style="text-indent:-0.5in;margin-left:0.5in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l2 level1 lfo7;" class="MsoNormal"&gt;4.&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;                  
&lt;/span&gt;Promote the server to a Domain Controller (DC) via dcpromo.exe&lt;/p&gt;
&lt;p style="text-indent:-0.5in;margin-left:0.5in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l2 level1 lfo8;" class="MsoNormal"&gt;5.&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;                  
&lt;/span&gt;Promote the server to a Global Catalog Server&lt;/p&gt;
&lt;p style="text-indent:-0.5in;margin-left:0.5in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l2 level1 lfo9;" class="MsoNormal"&gt;6.&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;                  
&lt;/span&gt;Let the system sit idle (2 hours) for Replication to sync up&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Point the DNS services 
to itself&lt;/p&gt;
&lt;p style="text-indent:-0.5in;margin-left:0.5in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l2 level1 lfo10;" class="MsoNormal"&gt;7.&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;                  
&lt;/span&gt;Open up a command prompt&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;dcdiag /v 
/test:ridmanager&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:1in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:1.0in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Make sure no errors 
with the rid manager&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Create an object on 
the new DC&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:1in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:1.0in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Physically disconnect 
the cable&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:1in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:1.0in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Bring up “Active 
Directory Users and Computers”&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:1.25in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:1.25in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;By disconnecting you 
force the system to attach locally&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:1in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:1.0in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Create a test user 
with the account disabled&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:1in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:1.0in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Reconnect the physical 
cable&lt;/p&gt;
&lt;p style="text-indent:-0.5in;margin-left:0.5in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l2 level1 lfo11;tab-stops:.5in;" class="MsoNormal"&gt;8.&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;                  
&lt;/span&gt;At&lt;span style="mso-spacerun:yes;"&gt;  &lt;/span&gt;a command prompt type in 
NTBACKUP and do a system state backup saving the file to the local server&lt;/p&gt;
&lt;p style="text-indent:-0.5in;margin-left:0.5in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l2 level1 lfo12;tab-stops:.5in;" class="MsoNormal"&gt;9.&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;                  
&lt;/span&gt;Demote this server to a member server with in the production domain 
(DCPROMO)&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Remove the NS record 
in the production environment&lt;/p&gt;
&lt;p style="text-indent:-0.5in;margin-left:0.5in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l2 level1 lfo13;tab-stops:.5in;" class="MsoNormal"&gt;10.&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;              
&lt;/span&gt;Physically disconnect the server from the network by unplugging the cable 
from the hub&lt;/p&gt;
&lt;p style="text-indent:-0.5in;margin-left:0.5in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l2 level1 lfo14;" class="MsoNormal"&gt;11.&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;              
&lt;/span&gt;&lt;b&gt;Move the server to &lt;/b&gt;the test domain&lt;/p&gt;
&lt;p style="text-indent:-0.5in;margin-left:0.5in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l2 level1 lfo15;" class="MsoNormal"&gt;12.&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;              
&lt;/span&gt;Re-Promote once this system has been disconnected and the ip changed&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Dcpromo&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:1in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Domain Name = 
Domain_Name.com&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:1in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;NetBios Name = 
NetBIOS_Name&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:1in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Allow the promotion to 
create the DNS domain&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:1.25in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Once this DC is 
brought online (The DNS services on the member server can be shut down), define 
it with Integrated Active Directory DNS and all name space records will be 
restored.&lt;span style="mso-spacerun:yes;"&gt;  &lt;/span&gt;Make sure to bring up DNS and 
select reload to refresh all data&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:1.25in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:1.0in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Active Directory 
Integrated&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:1.25in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:1.0in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Only Secure 
Updates &lt;/p&gt;
&lt;p style="text-indent:-0.5in;margin-left:0.5in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l2 level1 lfo15;" class="MsoNormal"&gt;13.&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;              
&lt;/span&gt;Reboot this server and After the POST Select F8 &lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Scroll down and select 
the option&lt;/p&gt;
&lt;p style="margin-left:0.5in;mso-pagination:none;mso-layout-grid-align:none;" class="MsoNormal"&gt;“Directory Services Restore Mode (Windows 200x domain 
controllers only)”&lt;/p&gt;
&lt;p style="text-indent:-0.5in;margin-left:0.5in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l2 level1 lfo15;" class="MsoNormal"&gt;14.&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;              
&lt;/span&gt;Log on as the administrator (This is within the old SAM account)&lt;/p&gt;
&lt;p style="text-indent:-0.5in;margin-left:0.5in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l2 level1 lfo15;" class="MsoNormal"&gt;15.&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;              
&lt;/span&gt;Restore the System State from the previous NTBACKUP&lt;/p&gt;
&lt;p style="text-indent:-0.5in;margin-left:0.5in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l2 level1 lfo15;" class="MsoNormal"&gt;16.&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;              
&lt;/span&gt;Re-boot the Domain Controller (DC)&lt;/p&gt;

&lt;p style="mso-pagination:none;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;i&gt;Now that the DC is restored it needs to take control of all 
Flexible Single Master Operation roles (FSMO and the File Replication 
service).&lt;span style="mso-spacerun:yes;"&gt;  &lt;/span&gt;Because of this utilities need 
to be loaded off of the Windows 200x install CD.&lt;span style="mso-spacerun:yes;"&gt;  &lt;/span&gt;NTDSUTIL will perform most of these 
steps.&lt;span style="mso-spacerun:yes;"&gt;  &lt;/span&gt;Since this is the first DC it 
needs to be a Global Catalog server and validate that it is the primary server 
in the domain.&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/p&gt;

&lt;p style="text-indent:-0.5in;margin-left:0.5in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l2 level1 lfo15;" class="MsoNormal"&gt;17.&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;              
&lt;/span&gt;After the POST Select F8 &lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Scroll down and select 
the option&lt;/p&gt;
&lt;p style="margin-left:0.5in;mso-pagination:none;mso-layout-grid-align:none;" class="MsoNormal"&gt;“Directory Services Restore Mode (Windows 200x domain 
controllers only)”&lt;/p&gt;
&lt;p style="text-indent:-0.5in;margin-left:0.5in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l2 level1 lfo15;" class="MsoNormal"&gt;18.&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;              
&lt;/span&gt;Log on as the administrator (This is within the old SAM account)&lt;/p&gt;
&lt;p style="text-indent:-0.5in;margin-left:0.5in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l2 level1 lfo15;" class="MsoNormal"&gt;19.&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;              
&lt;/span&gt;Install the Windows 200x Active Directory Administration Tools from the 
server cd&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;D:\i386\ 
Adminpak.msi&lt;/p&gt;
&lt;p style="text-indent:-0.5in;margin-left:0.5in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l2 level1 lfo15;" class="MsoNormal"&gt;20.&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;              
&lt;/span&gt;Install the Windows 200x Server Resource Kit from the server cd&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        
&lt;/span&gt;&lt;/span&gt;D:\support\tools\200xrkst.msi&lt;/p&gt;
&lt;p style="text-indent:-0.5in;margin-left:0.5in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l2 level1 lfo15;" class="MsoNormal"&gt;21.&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;              
&lt;/span&gt;Re-boot the Domain Controller (DC)&lt;/p&gt;
&lt;p style="text-indent:-0.5in;margin-left:0.5in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l2 level1 lfo15;" class="MsoNormal"&gt;22.&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;              
&lt;/span&gt;Log on as the administrator (This is with the AD account)&lt;/p&gt;
&lt;p style="text-indent:-0.5in;margin-left:0.5in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l2 level1 lfo15;" class="MsoNormal"&gt;23.&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;              
&lt;/span&gt;Reset the ip address to the test domain, the restore resets the ip 
address.&lt;span style="mso-spacerun:yes;"&gt;  &lt;/span&gt;Make sure to also point the dns 
server to itself as well&lt;/p&gt;
&lt;p style="text-indent:-0.5in;margin-left:0.5in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l2 level1 lfo15;" class="MsoNormal"&gt;24.&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;              
&lt;/span&gt;Set this server as a Global Catalog (Ignore this step in a multi-domain 
environment and this DC holds the Infrastructure Master Role)&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Click Start, click 
Run, type mmc, and then click OK&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;On the Console menu, 
click Add/Remove Snap-in, click Add, double-click Active Directory Sites and 
Services, click Close, and then click OK&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Double Click Active 
Directory Sites and Services&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Double Click Sites&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Double Click 
MP-Default-Site&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Double Click 
Servers&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Double Click the 
DC&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Right Click on NTDS 
Settings and Select Properties&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;If the “Global 
Catalog” check box is not checked, check it&lt;/p&gt;
&lt;p style="text-indent:-0.5in;margin-left:0.5in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l2 level1 lfo15;" class="MsoNormal"&gt;25.&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;              
&lt;/span&gt;All Flexible Single Master Operations (FSMO) roles need to reside on this 
DC&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Seize the PDC&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:1in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:1.0in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Click Start and then 
click Run&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:1in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:1.0in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;In the Open text box, 
type ntdsutil&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:1in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:1.0in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Type &lt;b&gt;roles&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:1in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:1.0in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Type 
&lt;b&gt;connections&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:1in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:1.0in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Type &lt;b&gt;connect to 
server&lt;span style="mso-spacerun:yes;"&gt;  &lt;/span&gt;&lt;i&gt;&amp;lt;DC name&amp;gt;&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:1in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:1.0in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Type &lt;b&gt;q&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:1in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:1.0in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Type &lt;b&gt;seize 
pdc&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:1in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:1.0in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Click “Yes”&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Seize the 
Infrastructure master role&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:1in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:1.0in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Type &lt;b&gt;seize 
infrastructure master&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:1in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:1.0in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;font-size:10pt;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;         &lt;/span&gt;&lt;/span&gt;Click “Yes”&lt;span style="font-size:10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;font-size:10pt;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;         &lt;/span&gt;&lt;/span&gt;Seize the Domain 
Naming master role&lt;span style="font-size:10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:1in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:1.0in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Type &lt;b&gt;seize domain 
naming master&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:1in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:1.0in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Click “Yes”&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Seize the schema 
master role&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:1in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:1.0in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Type &lt;b&gt;seize schema 
master&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:1in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:1.0in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Click “Yes”&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Seize the RID Master 
Role&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:1in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:1.0in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Type &lt;b&gt;seize rid 
master&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:1in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:1.0in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Click “Yes”&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:1in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:1.0in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Type &lt;b&gt;q&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:1in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:1.0in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Type&lt;b&gt; q&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-indent:-0.5in;margin-left:0.5in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l2 level1 lfo15;" class="MsoNormal"&gt;26.&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;              
&lt;/span&gt;Remove all other DC server objects &lt;b&gt;(Repeat this step for each DC) &lt;a href="http://support.microsoft.com/kb/216498/en-us"&gt;&lt;font color="#0000ff"&gt;KB216498&lt;/font&gt;&lt;/a&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Click Start and then 
click Run&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;In the Open text box, 
type &lt;b&gt;ntdsutil&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;font-size:10pt;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;         &lt;/span&gt;&lt;/span&gt;Type &lt;b&gt;metadata 
cleanup&lt;/b&gt;&lt;span style="font-size:10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Type 
&lt;b&gt;connections&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Type&lt;b&gt; connect to 
server &lt;i&gt;&amp;lt;DC&amp;gt;&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Type &lt;b&gt;q&lt;/b&gt; (The 
metadata cleanup prompt should now show)&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Type &lt;b&gt;select 
operation target&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Type &lt;b&gt;list domains 
&lt;/b&gt;(A list of domains should be displayed)&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Type &lt;b&gt;select domain 
&amp;lt;&lt;i&gt;#&amp;gt; &lt;/i&gt;&lt;/b&gt;(This is the domain of the server to be pruned)&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Type &lt;b&gt;list sites&lt;/b&gt; 
(A list of sites should be displayed)&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Type &lt;b&gt;select site 
&amp;lt;&lt;i&gt;#&amp;gt; &lt;/i&gt;&lt;/b&gt;(This is the site of the server to be pruned)&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Type &lt;b&gt;list servers 
in site &lt;/b&gt;(A list of servers should be displayed)&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Type &lt;b&gt;select server 
&amp;lt;&lt;i&gt;#&amp;gt;&lt;/i&gt;&lt;/b&gt; (This is the server to be pruned)&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Type &lt;b&gt;q&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Type &lt;b&gt;remove 
selected server&lt;/b&gt; (You should get confirmation of the removal)&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Type &lt;b&gt;q&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Type &lt;b&gt;q&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-indent:-0.5in;margin-left:0.5in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l2 level1 lfo15;" class="MsoNormal"&gt;27.&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;              
&lt;/span&gt;Remove all other DC orphaned records in Active Directory &lt;b&gt;(Repeat this 
step for each DC) &lt;a href="http://support.microsoft.com/kb/216498/en-us"&gt;&lt;font color="#0000ff"&gt;KB216498&lt;/font&gt;&lt;/a&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Click Start - Programs 
- Windows 200x Support Tools - Tools - ADSI Edit&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;font-size:10pt;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;         &lt;/span&gt;&lt;/span&gt;Delete the computer 
account in &lt;span style="font-size:10pt;"&gt;OU=Domain Controllers, 
DC=Domain_Name,DC=com&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Delete the FRS member 
object in &lt;span style="font-size:10pt;"&gt;CN=Domain System Volume (SYSVOL 
share),CN=File Replication Service,CN=System,DC=Domain_Name,DC=com&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-indent:-0.5in;margin-left:0.5in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l2 level1 lfo15;" class="MsoNormal"&gt;28.&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;              
&lt;/span&gt;Remove all other DC orphaned records in DNS&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Click Start - Programs 
- Administrative Tools - DNS&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Click 
&amp;lt;DC&amp;gt;.Domain_Name.com - Forward Lookup Zones - Domain_Name.com&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Delete the cname 
(alias) of all other DC’s&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Delete the a record of 
all other DC’s&lt;/p&gt;
&lt;p style="text-indent:-0.5in;margin-left:0.5in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l2 level1 lfo15;" class="MsoNormal"&gt;29.&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;              
&lt;/span&gt;This DC needs to be the File Replication Service Master&lt;span style="mso-spacerun:yes;"&gt;  &lt;/span&gt;&lt;b&gt;(&lt;a href="http://support.microsoft.com/kb/316790/en-us"&gt;&lt;font color="#0000ff"&gt;KB316790&lt;/font&gt;&lt;/a&gt;)&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Stop the File 
Replication service on the DC&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Make sure the 
following folders exist, if not create them&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;&lt;span style="mso-tab-count:1;"&gt;      &lt;/span&gt;C:\WINNT\SYSVOL\staging&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;&lt;span style="mso-tab-count:1;"&gt;      &lt;/span&gt;C:\WINNT\SYSVOL\sysvol&lt;span style="mso-spacerun:yes;"&gt;  &lt;/span&gt;(Share as SYSVOL)&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;&lt;span style="mso-tab-count:1;"&gt;      &lt;/span&gt;C:\WINNT\SYSVOL\sysvol\Domain_Name.com&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;&lt;span style="mso-tab-count:2;"&gt;                  &lt;/span&gt;copy the contents of 
C:\WINNT\SYSVOL\domain to this folder&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Start Registry Editor 
(Regedt32.exe)&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Locate and then click 
the &lt;b&gt;BurFlags&lt;/b&gt; value under the following key in the registry:&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:1in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:1.0in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        
&lt;/span&gt;&lt;/span&gt;&lt;b&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NtFrs\Parameters\Backup/Restore\Process 
at Startup&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;On the &lt;b&gt;Edit&lt;/b&gt; 
menu, click &lt;b&gt;DWORD&lt;/b&gt;, click &lt;b&gt;Hex&lt;/b&gt;, type &lt;b&gt;&lt;span&gt;D2&lt;/span&gt;&lt;/b&gt;, and then click &lt;b&gt;OK&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Quit Registry 
Editor&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Restart the File 
Replication Service&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Check the FRS event 
viewer to see if the system states that the sysvol is now being shared and 
defines all the paths&lt;/p&gt;
&lt;p style="text-indent:-0.5in;margin-left:0.5in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l2 level1 lfo15;" class="MsoNormal"&gt;30.&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;              
&lt;/span&gt;Ensure that the DC has registered the proper computer role&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:0.75in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:.75in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;Enter &lt;b&gt;net 
accounts&lt;/b&gt; at a dos prompt&lt;/p&gt;
&lt;p style="text-indent:-0.25in;margin-left:1in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l0 level1 lfo6;tab-stops:1.0in;" class="MsoNormal"&gt;&lt;span style="font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;        &lt;/span&gt;&lt;/span&gt;The computer role 
should say "primary”&lt;/p&gt;

&lt;p style="mso-pagination:none;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;i&gt;Finally any information related to the old DC’s need to be 
purged from AD.&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/p&gt;

&lt;p style="text-indent:-0.5in;margin-left:0.5in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l2 level1 lfo15;" class="MsoNormal"&gt;31.&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;              
&lt;/span&gt;Re-boot the Authoritatively restored DC&lt;/p&gt;
&lt;p style="text-indent:-0.5in;margin-left:0.5in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l2 level1 lfo15;" class="MsoNormal"&gt;32.&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;              
&lt;/span&gt;Within the production system delete the test user and computer 
account&lt;/p&gt;
&lt;p style="text-indent:-0.5in;margin-left:0.5in;mso-pagination:none;mso-layout-grid-align:none;mso-list:l2 level1 lfo15;" class="MsoNormal"&gt;33.&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;              
&lt;/span&gt;Within the production system delete the server object within the site 
that it was placed into for replication&lt;/p&gt;

&lt;p style="mso-pagination:none;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size:10pt;"&gt;Note: The File Replication 
Service can prevent the computer from becoming a Domain Controller (See 
below).&lt;span style="mso-spacerun:yes;"&gt;  &lt;/span&gt;If when doing a dcdiag a message 
states that the rid pool is corrupt, what is probably happening is there are 
problems with replication.&lt;span style="mso-spacerun:yes;"&gt;  &lt;/span&gt;Check the 
“File Replication Service” Event Log.&lt;span style="mso-spacerun:yes;"&gt;  
&lt;/span&gt;Also make sure that all sub-folders are available within 
c:\winnt\sysvol.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;
&lt;p style="mso-pagination:none;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size:10pt;"&gt;To re-test just the rid 
pool:&lt;span style="mso-tab-count:2;"&gt;                                
&lt;/span&gt;dcdiag /v test:ridmanager&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;
&lt;p style="mso-pagination:none;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size:10pt;"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;
&lt;p style="mso-pagination:none;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size:10pt;"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;
&lt;p style="mso-pagination:none;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size:10pt;"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;
&lt;p style="mso-pagination:none;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-size:16pt;"&gt;Never again connect this server 
to the production system!!!&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="mso-pagination:none;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-size:16pt;"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="mso-pagination:none;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size:10pt;"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;
&lt;p style="mso-pagination:none;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;i&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/p&gt;
&lt;p style="mso-pagination:none;mso-layout-grid-align:none;" class="MsoNormal"&gt;When you restore a domain controller from backup (or when you 
restore the System State), the FRS database is not restored because the most 
up-to-date state exists on a current replica instead of in the restored 
database. When FRS starts, it enters a "seeding" state and then tries to locate 
a replica with which it can synchronize. Until FRS completes replication, it 
cannot share Sysvol and Netlogon.&lt;br&gt;&lt;br&gt;If you restore all of the domain 
controllers in the domain backup, all the domain controllers enter the seeding 
state for FRS and try to synchronize with an online replica. This replication 
does not occur because all of the domain controllers are in the same seeding 
state. Setting the primary domain controller FSMO role holder to be 
authoritative forces the domain controller to rebuild its database based on the 
current contents of the system volume. When that task is completed, the Sysvol 
and Netlogon shares are shared. All the other domain controllers can then start 
synchronizing from the online replica&lt;span style="font-size:10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="mso-pagination:none;mso-layout-grid-align:none;" class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size:10pt;"&gt;(See - &lt;b&gt;&lt;a href="http://support.microsoft.com/kb/316790/en-us"&gt;&lt;font color="#0000ff"&gt;KB&lt;span style="font-style:normal;"&gt;316790&lt;/span&gt;&lt;/font&gt;&lt;/a&gt;&lt;/b&gt;&lt;/span&gt;&lt;/i&gt;&lt;b&gt;&lt;span style="font-size:10pt;"&gt;)&lt;/span&gt;&lt;/b&gt;&lt;i&gt;&lt;span style="font-size:10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;&lt;img src="http://blogs.dirteam.com/aggbug.aspx?PostID=6138" width="1" height="1"&gt;</content><author><name>pbbergs</name><uri>http://blogs.dirteam.com/members/pbbergs.aspx</uri></author></entry><entry><title>Windows 2000/2003 Replication through a Firewall</title><link rel="alternate" type="text/html" href="http://blogs.dirteam.com/blogs/paulbergson/archive/2012/05/15/windows-2000-2003-replication-through-a-firewall.aspx" /><id>http://blogs.dirteam.com/blogs/paulbergson/archive/2012/05/15/windows-2000-2003-replication-through-a-firewall.aspx</id><published>2012-05-15T18:39:00Z</published><updated>2012-05-15T18:39:00Z</updated><content type="html">&lt;P class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Configuring Domain Controller Ports&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;To establish secure communications between DC’s defined and variable ports (High Ports) need to be able to communicate.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;In the scenario defined below the internal dc’s have no outbound restrictions, inbound is restricted to a need to have with the restriction of 200 RPC ports are set for on demand need.&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;The following port definitions should be defined on &lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;U&gt;ALL DC's&lt;/U&gt;&lt;/B&gt; within the DMZ that could be replicating to external DC’s.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;These define which ports will be made available to there requesting DC's.&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;Start Registry Editor (Regedt32.exe).&lt;/P&gt;
&lt;P style="TEXT-INDENT:0.5in;" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:0.5in;" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Restrict FRS Traffic to a &lt;/SPAN&gt;&lt;/B&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Specific&lt;/SPAN&gt;&lt;/B&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt; &lt;/SPAN&gt;&lt;/B&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Static&lt;/SPAN&gt;&lt;/B&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt; &lt;/SPAN&gt;&lt;/B&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Port&lt;/SPAN&gt;&lt;/B&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt; - &lt;A href="http://support.microsoft.com/kb/319553/en-us"&gt;&lt;FONT color=#0000ff&gt;KB319553&lt;/FONT&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:0.5in;MARGIN-LEFT:0.5in;" class=MsoNormal&gt;Locate and then click the following key in the registry:&lt;/P&gt;
&lt;P style="TEXT-INDENT:0.5in;MARGIN-LEFT:1in;" class=MsoNormal&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTFRS\Parameters &lt;/P&gt;
&lt;P style="MARGIN-LEFT:1.5in;" class=MsoNormal&gt;New &lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;=&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN class=SpellE&gt;Reg_DWORD&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:1.5in;" class=MsoNormal&gt;Name&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;=&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;RPC TCP/IP Port Assignment&lt;/P&gt;
&lt;P style="TEXT-INDENT:0.5in;MARGIN-LEFT:1in;" class=MsoNormal&gt;Value&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;=&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;10000&lt;SPAN style="mso-tab-count:2;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;(Decimal)&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:0.5in;" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Restricting AD replication traffic to a single port - &lt;A href="http://support.microsoft.com/kb/224196/en-us"&gt;&lt;FONT color=#0000ff&gt;KB224196&lt;/FONT&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:0.5in;MARGIN-LEFT:0.5in;" class=MsoNormal&gt;Locate and then click the following key in the registry:&lt;/P&gt;
&lt;P style="TEXT-INDENT:0.5in;MARGIN-LEFT:1in;" class=MsoNormal&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS\Parameters&lt;/P&gt;
&lt;P style="TEXT-INDENT:0.5in;MARGIN-LEFT:1in;" class=MsoNormal&gt;New&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;=&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;REG_DWORD&lt;/P&gt;
&lt;P style="TEXT-INDENT:0.5in;MARGIN-LEFT:1in;" class=MsoNormal&gt;Name&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;=&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;TCP/IP Port&lt;/P&gt;
&lt;P style="TEXT-INDENT:0.5in;MARGIN-LEFT:1in;" class=MsoNormal&gt;Data&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;=&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;10001&lt;SPAN style="mso-tab-count:2;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;(Decimal)&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:0.5in;" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;RPC dynamic port allocation - &lt;A href="http://support.microsoft.com/kb/154596/en-us"&gt;&lt;FONT color=#0000ff&gt;KB154596&lt;/FONT&gt;&lt;/A&gt; &lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (Only allow ports 10002 - 10200 for RPC from other machines)&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:0.5in;MARGIN-LEFT:0.5in;" class=MsoNormal&gt;Locate and then click the following key in the registry: &lt;/P&gt;
&lt;P style="TEXT-INDENT:0.5in;MARGIN-LEFT:1in;" class=MsoNormal&gt;HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\ &lt;/P&gt;
&lt;P style="TEXT-INDENT:0.5in;MARGIN-LEFT:1in;" class=MsoNormal&gt;Create a New Key = Internet&lt;/P&gt;
&lt;P style="TEXT-INDENT:0.5in;MARGIN-LEFT:0.5in;" class=MsoNormal&gt;Locate and then click the following key in the registry:&lt;/P&gt;
&lt;P style="TEXT-INDENT:0.5in;MARGIN-LEFT:1in;" class=MsoNormal&gt;HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Internet\&lt;/P&gt;
&lt;P style="TEXT-INDENT:0.5in;MARGIN-LEFT:1in;" class=MsoNormal&gt;Add the values &lt;/P&gt;
&lt;P style="TEXT-INDENT:0.5in;MARGIN-LEFT:1.5in;" class=MsoNormal&gt;"Ports" (MULTI_SZ)&lt;SPAN style="mso-tab-count:3;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;=&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;10002-10200&lt;/P&gt;
&lt;P style="TEXT-INDENT:0.5in;MARGIN-LEFT:1.5in;" class=MsoNormal&gt;"&lt;SPAN class=SpellE&gt;PortsInternetAvailable&lt;/SPAN&gt;" (REG_SZ)&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;=&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;Y&lt;/P&gt;
&lt;P style="TEXT-INDENT:0.5in;MARGIN-LEFT:1.5in;" class=MsoNormal&gt;"&lt;SPAN class=SpellE&gt;UseInternetPorts&lt;/SPAN&gt;" (REG_SZ)&lt;SPAN style="mso-tab-count:2;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;=&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;Y&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Configure 2003 Firewall Ports – &lt;A href="http://support.microsoft.com/kb/179442/en-us"&gt;&lt;FONT color=#0000ff&gt;KB179442&lt;/FONT&gt;&lt;/A&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:0.5in;" class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;TABLE style="BORDER-BOTTOM:medium none;BORDER-LEFT:medium none;BORDER-COLLAPSE:collapse;BORDER-TOP:medium none;BORDER-RIGHT:medium none;mso-border-alt:solid windowtext .5pt;mso-yfti-tbllook:480;mso-padding-alt:0in 5.4pt 0in 5.4pt;mso-border-insideh:.5pt solid windowtext;mso-border-insidev:.5pt solid windowtext;" class=MsoTableGrid cellSpacing=0 cellPadding=0&gt;

&lt;TR style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:1.2in;PADDING-RIGHT:5.4pt;BORDER-TOP:windowtext 1pt solid;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;135&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:windowtext 1pt solid;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;TCP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:windowtext 1pt solid;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;RPC&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:3.7in;PADDING-RIGHT:5.4pt;BORDER-TOP:windowtext 1pt solid;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;RPC Connector Helper (Machines connect to find out what high port to use)&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:1;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:1.2in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;137&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;TCP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;UDP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:3.7in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;NetBIOS Name&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:2;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:1.2in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;138&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;UDP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:3.7in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;NetBIOS &lt;SPAN class=SpellE&gt;Netlogon&lt;/SPAN&gt; and Browsing&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:3;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:1.2in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;139&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;TCP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:3.7in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;NetBIOS Session&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:4;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:1.2in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;123&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;UDP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:3.7in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;NTP&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:5;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:1.2in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;389&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;TCP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;UDP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:3.7in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;LDAP&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:6;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:1.2in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;636&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;TCP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:3.7in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;LDAP SSL&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:7;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:1.2in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;3268&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;TCP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:3.7in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;LDAP GC&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:8;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:1.2in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;3269&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;TCP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:3.7in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;LDAP GC SSL&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:9;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:1.2in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;42&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;TCP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:3.7in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;WINS Replication&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:10;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:1.2in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;53&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;TCP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;UDP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:3.7in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;DNS&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:11;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:1.2in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;88&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;TCP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;UDP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:3.7in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;Kerberos&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:12;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:1.2in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;445&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;TCP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;UDP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:3.7in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;SMB over IP (Microsoft-DS)&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:13;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:1.2in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;123&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;UDP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:3.7in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;NTP&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:14;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:1.2in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;10000&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;TCP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:3.7in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;RPC NTFRS&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:15;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:1.2in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;10001&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;TCP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:3.7in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;RPC NTDS&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:16;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:1.2in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;10002 –10200&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;TCP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:3.7in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;RPC – Dynamic High Open Ports&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:17;mso-yfti-lastrow:yes;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:1.2in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;ICMP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:3.7in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TABLE&gt;
&lt;P style="TEXT-INDENT:0.5in;MARGIN-LEFT:1.5in;" class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:0.5in;MARGIN-LEFT:1.5in;" class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;If you would like to test connectivity to validate FRS communication &lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;NTFRSUTL version &lt;/B&gt;&lt;SPAN class=SpellE&gt;&lt;I style="mso-bidi-font-style:normal;"&gt;server_name&lt;/I&gt;&lt;/SPAN&gt;&lt;I style="mso-bidi-font-style:normal;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;I style="mso-bidi-font-style:normal;"&gt;&lt;SPAN style="mso-tab-count:2;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/I&gt;If the two can communicate through the firewall via FRS the response will provide the current version number&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;If you would like to validate connectivity between DC’s use the tool PortQryUI&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;Download &lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyID=8355e537-1ea6-4569-aabb-f248f4bd91d0&amp;amp;DisplayLang=en"&gt;&lt;FONT color=#0000ff&gt;PortQryUI&lt;/FONT&gt;&lt;/A&gt;&lt;/B&gt; and run the tool&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;Select the destination DC or PDC&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;Select Domains and Trusts&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style="mso-tab-count:2;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;Validate the ports that should be open in fact are via the output provided by the tool.&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style="mso-tab-count:3;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;For additional info on this tool see&lt;B style="mso-bidi-font-weight:normal;"&gt; &lt;A href="http://support.microsoft.com/kb/832919/"&gt;&lt;FONT color=#0000ff&gt;&lt;SPAN class=SpellE&gt;PortQry&lt;/SPAN&gt; features&lt;/FONT&gt;&lt;/A&gt;&lt;/B&gt;, this is the backend tool for PortQryUI&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:0.5in;" class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;img src="http://blogs.dirteam.com/aggbug.aspx?PostID=6107" width="1" height="1"&gt;</content><author><name>pbbergs</name><uri>http://blogs.dirteam.com/members/pbbergs.aspx</uri></author><category term="&amp;quot;Active directory&amp;quot; firewall ports 2000 2003 &amp;quot;domain controller&amp;quot;" scheme="http://blogs.dirteam.com/blogs/paulbergson/archive/tags/_2600_quot_3B00_Active+directory_2600_quot_3B00_+firewall+ports+2000+2003+_2600_quot_3B00_domain+controller_2600_quot_3B00_/default.aspx" /></entry><entry><title>How to Remotely Promote Server Core to a Read Only Domain Controller (RODC)</title><link rel="alternate" type="text/html" href="http://blogs.dirteam.com/blogs/paulbergson/archive/2012/05/03/how-to-remotely-promote-server-core-to-a-read-only-domain-controller-rodc.aspx" /><id>http://blogs.dirteam.com/blogs/paulbergson/archive/2012/05/03/how-to-remotely-promote-server-core-to-a-read-only-domain-controller-rodc.aspx</id><published>2012-05-03T11:51:00Z</published><updated>2012-05-03T11:51:00Z</updated><content type="html">&lt;P&gt;If you would like to promote a Windows 2008 server core o/s to a RODC but the server is at a remote location, you can run into multiple road blocks. Firewall ports need to be opened, remote management needs to be enabled plus you need configuration information configured. The following text should help assist you in building this remote installation. &lt;/P&gt;
&lt;P&gt;By default Server core has the firewall enabled. To open up the ports on the Firewall requires either setting up group policy if a domain machine or logging locally and configuring. By default, when a server role is installed, the correct ports are automatically configured to allow the role to function as well as to allow remote management, so no additional work is required. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Configuring the firewall:&lt;/STRONG&gt; &lt;BR&gt;To open the firewall for remote management, as a local admin from a command prompt on server core, key in the following: &lt;BR&gt;&lt;STRONG&gt;netsh advfirewall firewall set rule group="Remote Administration" new enable=yes &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Enabling Remote Management:&lt;/STRONG&gt; &lt;BR&gt;To enable remote management via the Remote Shell, as a local admin from a command prompt on server core key in the following: &lt;BR&gt;&lt;STRONG&gt;Winrm quickconfig &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;If you want to run this on a secure channel you can open an HTTPS listener, as a local admin from a command prompt on server core key in the following: &lt;BR&gt;&lt;STRONG&gt;winrm quickconfig -transport:https &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Installing the DNS role:&lt;/STRONG&gt; &lt;BR&gt;To install DNS, from a command prompt on the remote workstation key in the following (Be sure to replace servercore = Remotely Managed Server): &lt;BR&gt;&lt;STRONG&gt;Winrs -r:servercore start /w ocsetup DNS-Server-Core-Role&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Promoting to an RODC:&lt;/STRONG&gt; (Performing a Staged RODC Installation) &lt;/P&gt;
&lt;P&gt;Start by pre-creating the server account (From Microsoft’s pre-staged deployment): &lt;/P&gt;
&lt;P&gt;Save the text below and execute the following command to pre-create the RODC account (Note: Be sure to replace DomainName with your Domain Name) &lt;BR&gt;&lt;STRONG&gt;dcpromo.exe /CreateDCAccount /ReplicaDomainDNSName:DomainName.com /unattend:\\longhorn\netlogon\precreate.txt &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;The next line is the start of pre-create RODC unattended text file&lt;/U&gt; &lt;BR&gt;&lt;/STRONG&gt;; DCPROMO unattend file &lt;BR&gt;; Usage: &lt;BR&gt;; dcpromo.exe /CreateDCAccount /ReplicaDomainDNSName:pbbergs.com /unattend:\\longhorn\netlogon\precreate.txt &lt;BR&gt;; &lt;BR&gt;[DCInstall] &lt;BR&gt;; Read-Only Replica DC promotion (stage 1) &lt;BR&gt;DCAccountName=servercore &lt;BR&gt;; RODC Password Replication Policy &lt;BR&gt;PasswordReplicationDenied="BUILTIN\Administrators" &lt;BR&gt;PasswordReplicationDenied="BUILTIN\Server Operators" &lt;BR&gt;PasswordReplicationDenied="BUILTIN\Backup Operators" &lt;BR&gt;PasswordReplicationDenied="BUILTIN\Account Operators" &lt;BR&gt;PasswordReplicationDenied="PBBERGS\Denied &lt;BR&gt;RODC Password Replication Group" &lt;BR&gt;PasswordReplicationAllowed="PBBERGS\Allowed RODC &lt;BR&gt;Password Replication Group" &lt;BR&gt;SiteName=Default-First-Site-Name &lt;BR&gt;InstallDNS=Yes &lt;BR&gt;ConfirmGc=Yes &lt;BR&gt;ReplicationSourceDC=Longhorn.pbbergs.com &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;The end of the pre-create RODC unattended file&lt;/STRONG&gt; &lt;/P&gt;
&lt;P&gt;To install the Domain Services role and promote the server core to a Domain Controller, from a command prompt on the remote workstation key in the following: &lt;BR&gt;&lt;STRONG&gt;Winrs -r:servercore dcpromo /unattend:c:\unattended\promote.txt &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;The next line is the start of the dcpromo RODC unattended text file &lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;; DCPROMO unattend file (automatically generated by dcpromo) &lt;BR&gt;; Usage: &lt;BR&gt;; dcpromo.exe /unattend: &lt;A&gt;\\longhorn\netlogon\answer.txt&lt;/A&gt; &lt;BR&gt;; &lt;BR&gt;[DCInstall] &lt;BR&gt;; &lt;BR&gt;ReplicaOrNewDomain=Replica &lt;BR&gt;ReplicationSourceDC:"pbbergs.com" &lt;BR&gt;InstallDNS=Yes &lt;BR&gt;ConfirmGc=Yes &lt;BR&gt;CriticalReplicationOnly=Yes &lt;BR&gt;DatabasePath="C:\Windows\NTDS" &lt;BR&gt;LogPath="C:\Windows\NTDS" &lt;BR&gt;SYSVOLPath="C:\Windows\SYSVOL" &lt;BR&gt;; Set SafeModeAdminPassword to the correct value prior to using the unattend file &lt;BR&gt;SafeModeAdminPassword=pa$$w0rd &lt;BR&gt;; Run-time flags (optional) &lt;BR&gt;RebootOnCompletion=Yes &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;The end of the dcpromo RODC unattended text file &lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Hopefully this article has helped you to get started, it is not trivial, and it took me multiple attempts on many steps to get it correct and working. &lt;/P&gt;
&lt;P&gt;I would love to hear feedback on your success or problems that may have arisen in your attempt to remotely promote a server core to a RODC. You can write to me at pbbergs@msn.com. &lt;/P&gt;&lt;img src="http://blogs.dirteam.com/aggbug.aspx?PostID=6101" width="1" height="1"&gt;</content><author><name>pbbergs</name><uri>http://blogs.dirteam.com/members/pbbergs.aspx</uri></author><category term="core &amp;quot;active directory&amp;quot; unattended rodc" scheme="http://blogs.dirteam.com/blogs/paulbergson/archive/tags/core+_2600_quot_3B00_active+directory_2600_quot_3B00_+unattended+rodc/default.aspx" /></entry><entry><title>External Forest Trust Configuration with a Firewall - Windows 2003 and NT4</title><link rel="alternate" type="text/html" href="http://blogs.dirteam.com/blogs/paulbergson/archive/2012/05/01/external-forest-trust-configuration-with-a-firewall-windows-2003-and-nt4.aspx" /><id>http://blogs.dirteam.com/blogs/paulbergson/archive/2012/05/01/external-forest-trust-configuration-with-a-firewall-windows-2003-and-nt4.aspx</id><published>2012-05-01T13:48:00Z</published><updated>2012-05-01T13:48:00Z</updated><content type="html">&lt;P class=MsoNormal&gt;An external forest trust relies on NetBIOS name resolution, &lt;SPAN style="COLOR:red;"&gt;dns is not involved.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;All trust communication traffic flows between the &lt;SPAN style="COLOR:red;"&gt;Windows 2003 PDCe and the PDC.&lt;/SPAN&gt;&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;It doesn’t matter how you have your &lt;SPAN class=SpellE&gt;LMHosts&lt;/SPAN&gt; table setup or your firewall setup the trust is only going to work with these two being able to talk to one another.&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="FONT-SIZE:16pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="FONT-SIZE:16pt;"&gt;WINS Configuration&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;Using the web site &lt;A href="http://bflinux.slu.edu/LSI/tools/lmhosts.html"&gt;&lt;FONT color=#0000ff&gt;&lt;SPAN class=SpellE&gt;LMHost&lt;/SPAN&gt; Creator&lt;/FONT&gt;&lt;/A&gt; create the lmhost files for the trust for name resolution. (Per &lt;A href="http://support.microsoft.com/kb/180094/en-us"&gt;&lt;FONT color=#0000ff&gt;KB180094&lt;/FONT&gt;&lt;/A&gt;)&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style="mso-tab-count:2;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="COLOR:red;"&gt;I highly recommend using this site to generate the &lt;SPAN class=SpellE&gt;LMHosts&lt;/SPAN&gt; file!!!&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Windows 2003&lt;BR&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;/B&gt;10.0.0.1&lt;SPAN style="mso-tab-count:2;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;NT4_Server&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;#PRE #DOM:NT4_Domain&lt;SPAN style="mso-tab-count:2;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:Wingdings;mso-ascii-font-family:'Times New Roman';mso-hansi-font-family:'Times New Roman';mso-char-type:symbol;mso-symbol-font-family:Wingdings;"&gt;&lt;SPAN style="mso-char-type:symbol;mso-symbol-font-family:Wingdings;"&gt;ß&lt;/SPAN&gt;&lt;/SPAN&gt; The name NT4_Server should be your PDC&lt;BR&gt;10.0.0.1&lt;SPAN style="mso-tab-count:2;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;"NT4_DOMAIN&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;\0x1b" #PRE&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;&lt;SPAN style="mso-tab-count:1;"&gt;&lt;/SPAN&gt;NT4&lt;BR&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;/B&gt;10.0.0.1&lt;SPAN style="mso-tab-count:2;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;2003_Server&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;#PRE #DOM:2003_Domain&lt;SPAN style="mso-tab-count:2;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:Wingdings;mso-ascii-font-family:'Times New Roman';mso-hansi-font-family:'Times New Roman';mso-char-type:symbol;mso-symbol-font-family:Wingdings;"&gt;&lt;SPAN style="mso-char-type:symbol;mso-symbol-font-family:Wingdings;"&gt;ß&lt;/SPAN&gt;&lt;/SPAN&gt;The name 2003_Server should be your PDCe&lt;BR&gt;10.0.0.1&lt;SPAN style="mso-tab-count:2;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;"2003_DOMAIN&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;\0x1b" #PRE&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY:Verdana;FONT-SIZE:8.5pt;"&gt;Note&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-FAMILY:Verdana;FONT-SIZE:8.5pt;"&gt; The domain name in this entry is case sensitive. Make sure that you use uppercase characters for the domain name. If you use lowercase characters for the domain name, &lt;SPAN class=SpellE&gt;NetBT&lt;/SPAN&gt; does not recognize the name.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY:Verdana;FONT-SIZE:8.5pt;"&gt;Note&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-FAMILY:Verdana;FONT-SIZE:8.5pt;"&gt; Make sure that you space these entries correctly. Replace 10.0.0.1 with the IP address of your primary domain controller (PDC). Replace &lt;SPAN class=SpellE&gt;PDCName&lt;/SPAN&gt; with the NetBIOS name of your PDC, and replace domain with your Windows NT domain name. There must be a total of 20 characters within the quotations (the domain name plus the appropriate number of spaces to pad up to 15 characters, plus the backslash, plus the NetBIOS hex representation of the service type). &lt;BR&gt;&lt;BR&gt;To help determine where the sixteenth character is, copy the following line to your &lt;SPAN class=SpellE&gt;Lmhosts&lt;/SPAN&gt; file:&lt;BR&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Courier New';COLOR:black;FONT-SIZE:10pt;"&gt;# IP Address "123456789012345*7890" &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:Verdana;FONT-SIZE:8.5pt;"&gt;Line up the double quotation marks (") by adding or removing spaces from the comment line, and put the \ on the sixteenth column (the column marked with the asterisk). You must use spaces after the name and before the \, not a tab.&lt;/SPAN&gt;&lt;SPAN style="mso-tab-count:2;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="FONT-SIZE:16pt;"&gt;Name Resolution Tests&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Windows 2003&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN class=SpellE&gt;Nbtstat&lt;/SPAN&gt; –R&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;-&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;Purges and reloads the remote cache name table&lt;BR&gt;&lt;SPAN class=SpellE&gt;Nbtstat&lt;/SPAN&gt;&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;-c&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;-&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;Lists &lt;SPAN class=SpellE&gt;NBT's&lt;/SPAN&gt; cache of remote [machine] names and their IP addresses&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;NT4&lt;BR&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN class=SpellE&gt;Nbtstat&lt;/SPAN&gt; –R&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;-&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;Purges and reloads the remote cache name table&lt;BR&gt;&lt;SPAN class=SpellE&gt;Nbtstat&lt;/SPAN&gt;&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;-C&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;-&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;Lists &lt;SPAN class=SpellE&gt;NBT's&lt;/SPAN&gt; cache of remote [machine] names and their IP addresses&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY:Verdana;FONT-SIZE:8.5pt;"&gt;Note&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-FAMILY:Verdana;FONT-SIZE:8.5pt;"&gt; The -c is case sensitive and must be lowercase (Uppercase for NT4). After you type this text, you should receive a display that is similar to the following: &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:Verdana;FONT-SIZE:8.5pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Courier New';COLOR:black;FONT-SIZE:10pt;"&gt;Node &lt;SPAN class=SpellE&gt;IpAddress&lt;/SPAN&gt;: [10.0.0.5] Scope Id: [] &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 12.25pt 0pt;BACKGROUND:#eeeeee;tab-stops:45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Courier New';COLOR:black;FONT-SIZE:10pt;"&gt;&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;NetBIOS Remote Cache Name Table &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 12.25pt 0pt;BACKGROUND:#eeeeee;tab-stops:45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Courier New';COLOR:black;FONT-SIZE:10pt;"&gt;&lt;SPAN style="mso-tab-count:2;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;Name Type Host Address Life [sec] ---------------------------------------------------------- &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 12.25pt 0pt;BACKGROUND:#eeeeee;tab-stops:45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Courier New';COLOR:black;FONT-SIZE:10pt;"&gt;&lt;SPAN style="mso-tab-count:2;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN class=SpellE&gt;PDCName&lt;/SPAN&gt; &amp;lt;03&amp;gt; UNIQUE 10.0.0.1 -1 &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 12.25pt 0pt;BACKGROUND:#eeeeee;tab-stops:45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Courier New';COLOR:black;FONT-SIZE:10pt;"&gt;&lt;SPAN style="mso-tab-count:2;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN class=SpellE&gt;PDCName&lt;/SPAN&gt; &amp;lt;00&amp;gt; UNIQUE 10.0.0.1 -1 &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 12.25pt 0pt;BACKGROUND:#eeeeee;tab-stops:45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Courier New';COLOR:black;FONT-SIZE:10pt;"&gt;&lt;SPAN style="mso-tab-count:2;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN class=SpellE&gt;PDCName&lt;/SPAN&gt; &amp;lt;20&amp;gt; UNIQUE 10.0.0.1 -1 &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 12.25pt 0pt;BACKGROUND:#eeeeee;tab-stops:45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Courier New';COLOR:black;FONT-SIZE:10pt;"&gt;&lt;SPAN style="mso-tab-count:2;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;Domain&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;1B&amp;gt; UNIQUE 10.0.0.1 -1 &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Configuring Domain Controller Ports&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;The following port definitions should be defined on &lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;U&gt;ALL DC's&lt;/U&gt;&lt;/B&gt; within the DMZ that could be replicating to external DC’s.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;These define which ports will be made available to there requesting DC's.&lt;/P&gt;
&lt;P class=MsoNormal&gt;Start Registry Editor (Regedt32.exe).&lt;BR&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;&lt;BR&gt;Restrict FRS Traffic to a Specific Static Port - &lt;A href="http://support.microsoft.com/kb/319553/en-us"&gt;&lt;FONT color=#0000ff&gt;KB319553&lt;/FONT&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;BR&gt;Locate and then click the following key in the registry:&lt;BR&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTFRS\Parameters &lt;BR&gt;New &lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;=&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN class=SpellE&gt;Reg_DWORD&lt;BR&gt;&lt;/SPAN&gt;Name&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;=&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;RPC TCP/IP Port Assignment&lt;BR&gt;Value&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;=&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;10000&lt;SPAN style="mso-tab-count:2;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;(Decimal)&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Restricting Active Directory replication traffic to a specific port - &lt;A href="http://support.microsoft.com/kb/224196/en-us"&gt;&lt;FONT color=#0000ff&gt;KB224196&lt;/FONT&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;BR&gt;Locate and then click the following key in the registry:&lt;BR&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS\Parameters&lt;BR&gt;New&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;=&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;REG_DWORD&lt;BR&gt;Name&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;=&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;TCP/IP Port&lt;BR&gt;Data&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;=&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;10001&lt;SPAN style="mso-tab-count:2;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;(Decimal)&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;RPC dynamic port allocation - &lt;A href="http://support.microsoft.com/kb/154596/en-us"&gt;&lt;FONT color=#0000ff&gt;KB154596&lt;/FONT&gt;&lt;/A&gt; (Only allow ports 10002 - 10200 for RPC from other machines)&lt;BR&gt;&lt;/SPAN&gt;&lt;/B&gt;Locate and then click the following key in the registry: &lt;BR&gt;HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\ &lt;BR&gt;Create a New Key = Internet&lt;BR&gt;&lt;BR&gt;Locate and then click the following key in the registry:&lt;BR&gt;HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Internet\&lt;BR&gt;Add the values &lt;BR&gt;"Ports" (MULTI_SZ)&lt;SPAN style="mso-tab-count:3;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;=&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;10002-10200&lt;BR&gt;"&lt;SPAN class=SpellE&gt;PortsInternetAvailable&lt;/SPAN&gt;" (REG_SZ)&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;=&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;Y&lt;BR&gt;"&lt;SPAN class=SpellE&gt;UseInternetPorts&lt;/SPAN&gt;" (REG_SZ)&lt;SPAN style="mso-tab-count:2;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;=&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;Y&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;If you would like to test connectivity to validate FRS communication &lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;(This communication is for Windows 2003 to Windows 2003 communications only)&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&lt;/SPAN&gt;NTFRSUTL version &lt;/B&gt;&lt;SPAN class=SpellE&gt;&lt;I style="mso-bidi-font-style:normal;"&gt;server_name&lt;/I&gt;&lt;/SPAN&gt;&lt;I style="mso-bidi-font-style:normal;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;I style="mso-bidi-font-style:normal;"&gt;&lt;SPAN style="mso-tab-count:2;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/I&gt;If the two can communicate through the firewall via FRS the response will provide the current version number&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;If you would like to validate connectivity between the NT4 and PDCe use the tool PortQryUI&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;Download &lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyID=8355e537-1ea6-4569-aabb-f248f4bd91d0&amp;amp;DisplayLang=en"&gt;&lt;FONT color=#0000ff&gt;PortQryUI&lt;/FONT&gt;&lt;/A&gt;&lt;/B&gt; and run the tool&lt;BR&gt;Select the destination DC or PDC&lt;BR&gt;Select Domains and Trusts&lt;BR&gt;Validate the ports that should be open in fact are via the output provided by the tool.&lt;/P&gt;
&lt;P class=MsoNormal&gt;For additional info on this tool see&lt;B style="mso-bidi-font-weight:normal;"&gt; &lt;A href="http://support.microsoft.com/kb/832919/"&gt;&lt;FONT color=#0000ff&gt;&lt;SPAN class=SpellE&gt;PortQry&lt;/SPAN&gt; features&lt;/FONT&gt;&lt;/A&gt;&lt;/B&gt;, this is the backend tool for PortQryUI&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Configure 2003 Firewall Ports – &lt;A href="http://support.microsoft.com/kb/179442/en-us"&gt;&lt;FONT color=#0000ff&gt;KB179442&lt;/FONT&gt;&lt;/A&gt; (This is between a &lt;SPAN class=SpellE&gt;dmz’d&lt;/SPAN&gt; DC and an internal DC, &lt;SPAN style="COLOR:red;"&gt;these settings are for &lt;A href="http://www.microsoft.com/technet/prodtechnol/windows2000serv/technologies/activedirectory/deploy/confeat/adrepfir.mspx"&gt;&lt;FONT color=#0000ff&gt;AD replication&lt;/FONT&gt;&lt;/A&gt; as well&lt;/SPAN&gt;)&lt;/SPAN&gt;&lt;/B&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;TABLE style="BORDER-BOTTOM:medium none;BORDER-LEFT:medium none;BORDER-COLLAPSE:collapse;BORDER-TOP:medium none;BORDER-RIGHT:medium none;mso-border-alt:solid windowtext .5pt;mso-yfti-tbllook:480;mso-padding-alt:0in 5.4pt 0in 5.4pt;mso-border-insideh:.5pt solid windowtext;mso-border-insidev:.5pt solid windowtext;" class=MsoTableGrid cellSpacing=0 cellPadding=0&gt;

&lt;TR style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:1.2in;PADDING-RIGHT:5.4pt;BORDER-TOP:windowtext 1pt solid;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;135&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:windowtext 1pt solid;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;TCP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:windowtext 1pt solid;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;RPC&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:3.7in;PADDING-RIGHT:5.4pt;BORDER-TOP:windowtext 1pt solid;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;RPC Connector Helper (Machines connect to find out what high port to use)&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:1;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:1.2in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;137&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;TCP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;UDP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:3.7in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;NetBIOS Name&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:2;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:1.2in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;138&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;UDP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:3.7in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;NetBIOS &lt;SPAN class=SpellE&gt;Netlogon&lt;/SPAN&gt; and Browsing&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:3;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:1.2in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;139&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;TCP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:3.7in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;NetBIOS Session&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:4;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:1.2in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;123&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;UDP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:3.7in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;NTP&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:5;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:1.2in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;389&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;TCP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;UDP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:3.7in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;LDAP&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:6;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:1.2in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;636&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;TCP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:3.7in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;LDAP SSL&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:7;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:1.2in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;3268&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;TCP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:3.7in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;LDAP GC&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:8;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:1.2in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;3269&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;TCP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:3.7in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;LDAP GC SSL&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:9;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:1.2in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;42&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;TCP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:3.7in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;WINS Replication&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:10;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:1.2in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;53&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;TCP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;UDP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:3.7in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;DNS&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:11;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:1.2in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;88&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;TCP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;UDP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:3.7in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;Kerberos&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:12;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:1.2in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;445&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;TCP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;UDP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:3.7in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;SMB over IP (Microsoft-DS)&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:13;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:1.2in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;123&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;UDP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:3.7in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;NTP&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:14;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:1.2in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;10000&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;TCP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:3.7in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;RPC NTFRS&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:15;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:1.2in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;10001&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;TCP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:3.7in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;RPC NTDS&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:16;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:1.2in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;10002 –10200&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;TCP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:3.7in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;RPC – Dynamic High Open Ports&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:17;mso-yfti-lastrow:yes;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:1.2in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;ICMP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:3.7in;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TABLE&gt;
&lt;P style="TEXT-INDENT:0.5in;" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Configure NT4 Firewall Ports (If there is only an NT4 box outside the firewall than the previous is unneeded)&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;TABLE style="BORDER-BOTTOM:medium none;BORDER-LEFT:medium none;BORDER-COLLAPSE:collapse;BORDER-TOP:medium none;BORDER-RIGHT:medium none;mso-border-alt:solid windowtext .5pt;mso-yfti-tbllook:480;mso-padding-alt:0in 5.4pt 0in 5.4pt;mso-border-insideh:.5pt solid windowtext;mso-border-insidev:.5pt solid windowtext;" class=MsoTableGrid cellSpacing=0 cellPadding=0&gt;

&lt;TR style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:89.6pt;PADDING-RIGHT:5.4pt;BORDER-TOP:windowtext 1pt solid;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;135&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:windowtext 1pt solid;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;TCP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:windowtext 1pt solid;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;UDP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:263.2pt;PADDING-RIGHT:5.4pt;BORDER-TOP:windowtext 1pt solid;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;RPC Connector Helper&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:1;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:89.6pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;137&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;TCP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;UDP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:263.2pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;NetBIOS Name&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:2;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:89.6pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;138&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;UDP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:263.2pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;NetBIOS &lt;SPAN class=SpellE&gt;Netlogon&lt;/SPAN&gt; and Browsing&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:3;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:89.6pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;139&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;TCP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:263.2pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;NetBIOS Session&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:4;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:89.6pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;42&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;TCP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:263.2pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;WINS Replication&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:5;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:89.6pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;123&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;UDP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:263.2pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;NTP&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow:6;mso-yfti-lastrow:yes;"&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:windowtext 1pt solid;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:89.6pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;10000 – 10200&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;TCP&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:45pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM:windowtext 1pt solid;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:5.4pt;WIDTH:263.2pt;PADDING-RIGHT:5.4pt;BORDER-TOP:medium none;BORDER-RIGHT:windowtext 1pt solid;PADDING-TOP:0in;mso-border-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;mso-border-top-alt:solid windowtext .5pt;" vAlign=top&gt;
&lt;P class=MsoNormal&gt;RPC – Dynamic High Open Ports&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TABLE&gt;
&lt;P style="TEXT-INDENT:0.5in;" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Made following Changes in Default Domain Controller Group Policy&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;Computer Configuration \ Windows Settings \ Security Settings \ Security Options&lt;/B&gt;&lt;SPAN style="COLOR:black;FONT-SIZE:7.5pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="COLOR:black;"&gt;Microsoft network client: Digitally sign communications (always) DISABLED&amp;nbsp; &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN style="COLOR:navy;"&gt;(Default ENABLED&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;STRONG&gt;&lt;SPAN style="COLOR:navy;FONT-SIZE:7.5pt;"&gt;)&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="COLOR:black;"&gt;Microsoft network client: Digitally sign communications (if server agrees) ENABLED&amp;nbsp; &lt;STRONG&gt;(Default ENABLED)&lt;/STRONG&gt;&amp;nbsp;&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="COLOR:black;"&gt;Microsoft network server: Digitally sign communications (always) DISABLED&amp;nbsp; &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN style="COLOR:navy;"&gt;(Default ENABLED) &lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="COLOR:black;"&gt;Microsoft network server: Digitally sign communications (if client agrees) ENABLED&amp;nbsp; &lt;STRONG&gt;(Default ENABLED)&lt;/STRONG&gt; &lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="COLOR:black;"&gt;Domain member: Digitally encrypt or sign secure channel data (always) DISABLED&amp;nbsp; &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN style="COLOR:navy;"&gt;(Default ENABLED)&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="COLOR:black;"&gt; &lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="COLOR:black;"&gt;Domain member: Digitally encrypt secure channel data (when it is possible) ENABLED&amp;nbsp;&lt;STRONG&gt; (Default ENABLED)&lt;/STRONG&gt; &lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="COLOR:black;"&gt;Domain member: Digitally sign secure channel data (when it is possible) ENABLED&amp;nbsp; &lt;STRONG&gt;(Default ENABLED)&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR:black;"&gt;Network access: &lt;A title=#h4 name=#h4&gt;&lt;/A&gt;Restrict anonymous access to Named Pipes and shares&amp;nbsp;DISABLED &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN style="COLOR:navy;"&gt;(Default ENABLED)&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="COLOR:black;"&gt;Network access: Do not allow anonymous enumeration of SAM accounts and shares DISABLED &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN style="COLOR:navy;"&gt;(Default ENABLED)&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="COLOR:black;"&gt;Network access: Do not allow anonymous enumeration of SAM accounts&amp;nbsp; DISABLED &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN style="COLOR:navy;"&gt;(Default ENABLED)&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="COLOR:black;"&gt;Network access: Allow anonymous SID/Name translation&amp;nbsp;&amp;nbsp;ENABLED&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN style="COLOR:navy;"&gt;(Default DISABLED)&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="COLOR:black;"&gt;Domain member: Digitally encrypt or sign secure channel data (always) DISABLED&lt;STRONG&gt;&amp;nbsp; &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN style="COLOR:navy;"&gt;(Default ENABLED)&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="COLOR:black;"&gt;Domain member: Require strong (Windows 2000 or later) session key DISABLED&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN style="COLOR:navy;"&gt;(Default ENABLED)&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="COLOR:black;"&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;Made following Changed in Registry of 2003 PDCe&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp;&amp;nbsp;&lt;BR&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="COLOR:black;"&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\EveryoneIncludesAnonymous 1 &lt;STRONG&gt;(default 0)&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR:black;"&gt;HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\lanmanserver\parameters\restrictnullsessaccess 0 &lt;STRONG&gt;(default 1)&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR:black;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="COLOR:black;FONT-SIZE:16pt;"&gt;Once all these steps have been completed the Trust can now be established&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="COLOR:black;FONT-SIZE:16pt;"&gt;&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;A href="http://support.microsoft.com/kb/325874/en-us"&gt;&lt;FONT color=#0000ff&gt;How to establish trusts with a Windows NT-based domain in Windows Server 2003&lt;/FONT&gt;&lt;/A&gt;&lt;B style="mso-bidi-font-weight:normal;"&gt;&lt;SPAN style="FONT-SIZE:18pt;"&gt;&lt;BR&gt;&lt;BR&gt;There is a complete set of troubleshooting options available on &lt;A href="http://support.microsoft.com/kb/889030/en-us"&gt;&lt;FONT color=#0000ff&gt;KB889030&lt;/FONT&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;img src="http://blogs.dirteam.com/aggbug.aspx?PostID=6096" width="1" height="1"&gt;</content><author><name>pbbergs</name><uri>http://blogs.dirteam.com/members/pbbergs.aspx</uri></author><category term="&amp;quot;NT4 trust&amp;quot; &amp;quot;Active Directory&amp;quot; firewall ports portqryui" scheme="http://blogs.dirteam.com/blogs/paulbergson/archive/tags/_2600_quot_3B00_NT4+trust_2600_quot_3B00_+_2600_quot_3B00_Active+Directory_2600_quot_3B00_+firewall+ports+portqryui/default.aspx" /></entry><entry><title>User Account Lockout Troubleshooting</title><link rel="alternate" type="text/html" href="http://blogs.dirteam.com/blogs/paulbergson/archive/2012/04/23/user-account-lockout-troubleshooting.aspx" /><id>http://blogs.dirteam.com/blogs/paulbergson/archive/2012/04/23/user-account-lockout-troubleshooting.aspx</id><published>2012-04-23T12:04:00Z</published><updated>2012-04-23T12:04:00Z</updated><content type="html">&lt;P class=MsoNormal&gt;Do any of these symptoms sound familiar?&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;A users account keeps getting locked out, even though they haven’t even had to enter their credentials except to maybe unlock their screensaver&lt;BR&gt;&lt;SPAN style="FONT-FAMILY:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;A scheduled task quit working, such as a night backup job&lt;BR&gt;&lt;SPAN style="FONT-FAMILY:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;Services that used to start up at boot up will no longer start even if attempted manually&lt;BR&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;These are typical symptoms of a recently changed password where other resources are using this same account but are unaware of the recent password change.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;Things to check to assist in this troubleshooting are:&lt;BR&gt;&lt;SPAN style="FONT-FAMILY:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;Is the account logged onto more than one machine&lt;BR&gt;&lt;SPAN style="FONT-FAMILY:'Courier New';mso-fareast-font-family:'Courier New';"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; o&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;A user could have mapped drives to a resource from one machine, on a different machine he changes his password and then the first machine attempts to stay mapped to a drive and the password is no longer correct and eventually locks the user out.&lt;BR&gt;&lt;SPAN style="FONT-FAMILY:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;If a service is running that is attempting to authenticate and has an invalid password, it may attempt multiple times and lockout the account&lt;/P&gt;
&lt;P class=MsoNormal&gt;Also ensure to review any mobile devices that your user might be using.&amp;nbsp; If they have a cell phone/tablet with an embedded password the handheld maybe attempting to authenticate.&amp;nbsp; This error will show up in the event logs and may the hardware may show up as a router or switch.&lt;/P&gt;
&lt;P class=MsoNormal&gt;To help try and track down where the account is getting locked out use eventcombMT.exe from the &lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyID=7AF2E69C-91F3-4E63-8629-B999ADDE0B9E&amp;amp;displaylang=en" target=_blank&gt;&lt;FONT color=#0000ff&gt;Account Lockout tools&lt;/FONT&gt;&lt;/A&gt; found out Microsoft's website.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;Use the built in search &lt;SPAN class=SpellE&gt;AccountLockouts&lt;/SPAN&gt;.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;Once the Event logs have been inspected and a new text file has been created, search within this text file for the locked account in question.&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;You can also set the debug flag on &lt;SPAN class=SpellE&gt;NetLogon&lt;/SPAN&gt; to track authentication.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;"This creates a text file on the PDC that can be examined to determine which clients are generating the bad password attempts."&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;A href="http://support.microsoft.com/kb/189541"&gt;http://support.microsoft.com/kb/189541&lt;/A&gt;&lt;BR&gt;&lt;A href="http://support.microsoft.com/kb/109626"&gt;http://support.microsoft.com/kb/109626&lt;/A&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.dirteam.com/aggbug.aspx?PostID=6092" width="1" height="1"&gt;</content><author><name>pbbergs</name><uri>http://blogs.dirteam.com/members/pbbergs.aspx</uri></author><category term="&amp;quot;Account Lockout&amp;quot; &amp;quot;Active Directory&amp;quot;" scheme="http://blogs.dirteam.com/blogs/paulbergson/archive/tags/_2600_quot_3B00_Account+Lockout_2600_quot_3B00_+_2600_quot_3B00_Active+Directory_2600_quot_3B00_/default.aspx" /></entry><entry><title>Configuring IPv4 as Default over IPv6</title><link rel="alternate" type="text/html" href="http://blogs.dirteam.com/blogs/paulbergson/archive/2011/06/30/configuring-ipv4-as-default-over-ipv6.aspx" /><id>http://blogs.dirteam.com/blogs/paulbergson/archive/2011/06/30/configuring-ipv4-as-default-over-ipv6.aspx</id><published>2011-07-01T02:21:00Z</published><updated>2011-07-01T02:21:00Z</updated><content type="html">&lt;font size="3" face="Times New Roman"&gt;

&lt;/font&gt;&lt;font size="3" face="Times New Roman"&gt;
&lt;/font&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;&lt;span style="line-height:115%;font-size:12pt;"&gt;&lt;font face="Calibri"&gt;Starting
with Windows Vista and Server 2008, IPv6 is the default over IPv4.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;This can be annoying if your enterprise
network isn’t prepared to support this.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;You
can modify this default behavior by OR’ing and registry setting on your
machine.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;font size="3" face="Times New Roman"&gt;

&lt;/font&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;&lt;span style="line-height:115%;font-size:12pt;"&gt;&lt;font face="Calibri"&gt;The registry
setting is the DisabledComponents registry value and it controls a series of
bit flags as defined below:&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;font size="3" face="Times New Roman"&gt;

&lt;/font&gt;&lt;p style="margin:0in 0in 0pt 0.5in;text-indent:-0.25in;mso-list:l0 level1 lfo1;" class="MsoListParagraphCxSpFirst"&gt;&lt;span style="line-height:115%;font-family:Symbol;font-size:12pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;strong&gt;&lt;span style="line-height:115%;font-size:8pt;mso-bidi-theme-font:minor-bidi;"&gt;Bit 0&lt;/span&gt;&lt;/strong&gt;&lt;span style="line-height:115%;font-size:8pt;"&gt; Set to 1 to disable all IPv6 tunnel interfaces, including ISATAP,
6to4, and Teredo tunnels. Default value is 0&lt;/span&gt;&lt;span style="line-height:115%;font-size:12pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;font size="3" face="Times New Roman"&gt;

&lt;/font&gt;&lt;p style="margin:0in 0in 0pt 0.5in;text-indent:-0.25in;mso-list:l0 level1 lfo1;" class="MsoListParagraphCxSpMiddle"&gt;&lt;span style="line-height:115%;font-family:Symbol;font-size:12pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;strong&gt;&lt;span style="line-height:115%;font-size:8pt;mso-bidi-theme-font:minor-bidi;"&gt;Bit 1&lt;/span&gt;&lt;/strong&gt;&lt;span style="line-height:115%;font-size:8pt;"&gt; Set to 1 to disable all 6to4-based interfaces. Default value is 0&lt;/span&gt;&lt;span style="line-height:115%;font-size:12pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;font size="3" face="Times New Roman"&gt;

&lt;/font&gt;&lt;p style="margin:0in 0in 0pt 0.5in;text-indent:-0.25in;mso-list:l0 level1 lfo1;" class="MsoListParagraphCxSpMiddle"&gt;&lt;span style="line-height:115%;font-family:Symbol;font-size:12pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;strong&gt;&lt;span style="line-height:115%;font-size:8pt;mso-bidi-theme-font:minor-bidi;"&gt;Bit 2&lt;/span&gt;&lt;/strong&gt;&lt;span style="line-height:115%;font-size:8pt;"&gt; Set to 1 to disable all ISATAP-based interfaces. Default value is
0&lt;/span&gt;&lt;span style="line-height:115%;font-size:12pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;font size="3" face="Times New Roman"&gt;

&lt;/font&gt;&lt;p style="margin:0in 0in 0pt 0.5in;text-indent:-0.25in;mso-list:l0 level1 lfo1;" class="MsoListParagraphCxSpMiddle"&gt;&lt;span style="line-height:115%;font-family:Symbol;font-size:12pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;strong&gt;&lt;span style="line-height:115%;font-size:8pt;mso-bidi-theme-font:minor-bidi;"&gt;Bit 3&lt;/span&gt;&lt;/strong&gt;&lt;span style="line-height:115%;font-size:8pt;"&gt; Set to 1 to disable all Teredo-based interfaces. Default value is
0&lt;/span&gt;&lt;span style="line-height:115%;font-size:12pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;font size="3" face="Times New Roman"&gt;

&lt;/font&gt;&lt;p style="margin:0in 0in 0pt 0.5in;text-indent:-0.25in;mso-list:l0 level1 lfo1;" class="MsoListParagraphCxSpMiddle"&gt;&lt;span style="line-height:115%;font-family:Symbol;font-size:12pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;strong&gt;&lt;span style="line-height:115%;font-size:8pt;mso-bidi-theme-font:minor-bidi;"&gt;Bit 4&lt;/span&gt;&lt;/strong&gt;&lt;span style="line-height:115%;font-size:8pt;"&gt; Set to 1 to disable IPv6 over all non-tunnel interfaces,
including LAN interfaces and Point-to-Point Protocol (PPP)-based interfaces.
Default value is 0&lt;/span&gt;&lt;span style="line-height:115%;font-size:12pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;font size="3" face="Times New Roman"&gt;

&lt;/font&gt;&lt;p style="margin:0in 0in 10pt 0.5in;text-indent:-0.25in;mso-list:l0 level1 lfo1;" class="MsoListParagraphCxSpLast"&gt;&lt;span style="line-height:115%;font-family:Symbol;font-size:12pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;strong&gt;&lt;span style="line-height:115%;font-size:8pt;mso-bidi-theme-font:minor-bidi;"&gt;Bit 5&lt;/span&gt;&lt;/strong&gt;&lt;span style="line-height:115%;font-size:8pt;"&gt; Set to 1 to modify the default prefix policy table to prefer IPv4
to IPv6 when attempting connections. Default value is 0&lt;/span&gt;&lt;span style="line-height:115%;font-size:12pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;font size="3" face="Times New Roman"&gt;

&lt;/font&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;&lt;strong&gt;&lt;span style="line-height:115%;font-size:8pt;mso-bidi-theme-font:minor-bidi;"&gt;Note&lt;/span&gt;&lt;/strong&gt;&lt;span style="line-height:115%;font-size:8pt;"&gt; Bits beyond Bit 5 are not used at this time&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;font size="3" face="Times New Roman"&gt;

&lt;/font&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;&lt;span style="line-height:115%;font-size:8pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;font size="3" face="Times New Roman"&gt;

&lt;/font&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;&lt;span style="line-height:115%;font-size:8pt;"&gt;A single byte consists of 8 bits, these
bits can have a value of 1 or 0.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;In the
DisabledComponents instance each of the first five bits refer to a switch, with
1 being on a 0 being off.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;This can also
be thought of as either true/false or on/off.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;font size="3" face="Times New Roman"&gt;

&lt;/font&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;&lt;span style="line-height:115%;font-size:8pt;"&gt;The zero bit refers to 0 or 1&lt;br&gt;
The one bit refers to 0 or 2&lt;br&gt;
The two bit refers to 0 or 4&lt;br&gt;
The three bit refers to 0 or 8&lt;br&gt;
The four bit refers to 0 or 16&lt;br&gt;
The five bit refers to 0 or 32&lt;br&gt;
The six bit refers to 0 or 64&lt;br&gt;
The seven bit refers to 0 or 128&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;font size="3" face="Times New Roman"&gt;

&lt;/font&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;&lt;span style="line-height:115%;font-size:8pt;"&gt;If you add all the bits up when set to a
one the maximum value is 255.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;Why do I
bring this up?&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;In order to modify a bit
you need to not modify the bits around it.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;
&lt;/span&gt;So first off you realize that the last three bits aren’t used so the
maximum value will be – 1 + 2 + 4 + 8 + 16 + 0 + 0 + 0 = 31.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;So the largest this key can ever be (Barring disabling
IPv6 which will be set to the DWord of 0xFFFFFFFF).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;font size="3" face="Times New Roman"&gt;

&lt;/font&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;&lt;span style="line-height:115%;font-size:8pt;"&gt;So on to setting the default of IPv4 over
IPv6 is to examine the fifth bit if it is zero then you need to modify the
value by adding 16.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;If the current value
is equal to or greater than 16 than you know that the fifth bit is already set.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;font size="3" face="Times New Roman"&gt;

&lt;/font&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;&lt;span style="line-height:115%;font-size:8pt;"&gt;To take an example:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;font size="3" face="Times New Roman"&gt;

&lt;/font&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;&lt;span style="line-height:115%;font-size:8pt;"&gt;If the key is equal to 10, then you can see
that:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;font size="3" face="Times New Roman"&gt;

&lt;/font&gt;&lt;p style="margin:0in 0in 0pt 0.5in;text-indent:-0.25in;mso-list:l1 level1 lfo2;" class="MsoListParagraphCxSpFirst"&gt;&lt;span style="color:black;line-height:115%;font-family:Symbol;font-size:8pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height:115%;font-size:8pt;"&gt;6to4-based interfaces is
disabled&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;font size="3" face="Times New Roman"&gt;

&lt;/font&gt;&lt;p style="margin:0in 0in 10pt 0.5in;text-indent:-0.25in;mso-list:l1 level1 lfo2;" class="MsoListParagraphCxSpLast"&gt;&lt;span style="color:black;line-height:115%;font-family:Symbol;font-size:8pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore;"&gt;·&lt;span style="font-size-adjust:none;font-stretch:normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height:115%;font-size:8pt;"&gt;Teredo-based interfaces is
disabled&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;font size="3" face="Times New Roman"&gt;

&lt;/font&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;&lt;span style="line-height:115%;font-size:8pt;"&gt;By adding (Or’ing 00010000) 16 to the key you
end up with 26 which says, bits 1,&amp;nbsp;3 and&amp;nbsp;4 are all set to a 1 (Or are true).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="3" face="Times New Roman"&gt;

&lt;/font&gt;&lt;span style="line-height:115%;font-size:8pt;mso-fareast-font-family:Calibri;mso-bidi-theme-font:minor-bidi;mso-fareast-theme-font:minor-latin;mso-ansi-language:EN-US;mso-fareast-language:EN-US;mso-bidi-language:AR-SA;"&gt;For additional
details refer to the technet article:&lt;br&gt;
&lt;a href="http://technet.microsoft.com/en-us/library/bb878057.aspx"&gt;&lt;font color="#0000ff"&gt;http://technet.microsoft.com/en-us/library/bb878057.aspx&lt;/font&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="line-height:115%;font-size:8pt;mso-fareast-font-family:Calibri;mso-bidi-theme-font:minor-bidi;mso-fareast-theme-font:minor-latin;mso-ansi-language:EN-US;mso-fareast-language:EN-US;mso-bidi-language:AR-SA;"&gt;I have a seperate Blog on disabling IPv6&lt;br&gt;&lt;a href="http://blogs.dirteam.com/blogs/paulbergson/archive/2009/03/19/disabling-ipv6-on-windows-2008.aspx"&gt;http://blogs.dirteam.com/blogs/paulbergson/archive/2009/03/19/disabling-ipv6-on-windows-2008.aspx&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="line-height:115%;font-size:8pt;mso-fareast-font-family:Calibri;mso-bidi-theme-font:minor-bidi;mso-fareast-theme-font:minor-latin;mso-ansi-language:EN-US;mso-fareast-language:EN-US;mso-bidi-language:AR-SA;"&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://blogs.dirteam.com/aggbug.aspx?PostID=5847" width="1" height="1"&gt;</content><author><name>pbbergs</name><uri>http://blogs.dirteam.com/members/pbbergs.aspx</uri></author><category term="Windows IPv6 IPv4 DisabledComponents" scheme="http://blogs.dirteam.com/blogs/paulbergson/archive/tags/Windows+IPv6+IPv4+DisabledComponents/default.aspx" /></entry><entry><title>How to Create an Active Directory User Provisioning System</title><link rel="alternate" type="text/html" href="http://blogs.dirteam.com/blogs/paulbergson/archive/2011/04/27/how-to-create-a-new-active-directory-user.aspx" /><id>http://blogs.dirteam.com/blogs/paulbergson/archive/2011/04/27/how-to-create-a-new-active-directory-user.aspx</id><published>2011-04-28T02:29:00Z</published><updated>2011-04-28T02:29:00Z</updated><content type="html">&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;This blog will detail how I created an Active Directory (AD) user provisioning tool with PowerShell.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;It probably won’t be what you expect; the amount of front end entry is almost non-existent. The key to consistency within your enterprise is to take as much of the human element out of the picture as possible.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;Without proper edit and control, organizations will find two user objects created by the same employee won’t hold to a standard of entry.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;There in lies the key to this project.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;o:p&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;Although the code and the process in this endeavor is new, the original project itself is a rewrite.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;Previous team members Steve Laskowski, Richard Narum and Dale Peterson have all written Perl or VB.Net in different forms to create an user object.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;This newest process was created in Powershell.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;The GUI was developed using Primal Forms by &lt;/FONT&gt;&lt;A href="http://www.sapien.com/"&gt;&lt;FONT size=3 face="Times New Roman"&gt;Sapien&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face="Times New Roman"&gt;.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;There is both a freeware tool as well as a full version, I opted for the full version.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;Primal Forms generated all the lines of code for me, I am by no means a .Net developer but this development tool allowed me to create a tool rather quickly. &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;The jr admin running this front end script does not have to have any special permissions within AD.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;The user just needs the ability to run the script and be able to save an XML file created by the script to a pre-defined location (Queue).&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;Once this file has been saved, a backend scheduled task (I execute it every minute from 6:00 am to 6:00 pm) to inspect the folder for a new file specially named as defined below.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;The file has a random number built into the system to ensure that duplicate names can be created (Even though you can’t create duplicates) and multiple users can create files at the same time, so as you will see the real power is being able to have a secondary process drop XML files into the queue and the process can process them as required.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;This will allow an administrator to run a script and drop all the users they need into a folder and generate as many users as needed.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;That was the emphasis behind this project, our Human Resources (HR) synchronization process currently when a user is discovered missing within AD a report is generated, with this new process the user can be created without any intervention on the AD side.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;One this is complete, we can then examine synchronizing other LDAP systems such as secondary Oracle db’s.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;I have provided the Primal Forms so you can modify the form and the attirbutes passed within the xml.&amp;nbsp; So whatever you want to pass, you can but we went to the absolute minimums so as to keep things consistents as possible.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;All of the scripts, xml files and cmd file all reside in the same location.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;When the GUI is started, there is a cmd file which verifies that PowerShell has been loaded.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;The code is displayed below.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;As you can see the check is to see if the Powershell executable exists, if not a message is displayed, if so then call frontEndForm.ps1&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;########################################################################&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;@echo off&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;Rem Verify that Powershell is loaded on this desktop before proceeding&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;if not exist "%systemroot%\system32\Window~1\v1.0\powershell.exe" goto noPowershell&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;Rem Start up the GUI&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;net use v: \\server\share\newADUser&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;v:&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;cd \&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;powershell -ExecutionPolicy Unrestricted -command .\frontEndForm.ps1&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;c:&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;net use v: /del /y&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;Goto End&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;Rem Can't Proceed, Powershell needs to exist to run the front end script&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;:NoPowershell&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;Echo.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;Echo.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;Echo Powershell not loaded on this workStation&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;Echo Script aborted&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;Echo.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;Echo.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;Pause&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;:End&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;########################################################################&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;Once the newUser script is called the form has to be built.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;There are several drop down boxes that need to be populated, two by XML files and a third by the user objects within AD.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;&lt;IMG src="http://blogs.dirteam.com/photos/paulbergson/images/5741/original.aspx"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE:14pt;"&gt;&lt;FONT face="Times New Roman"&gt;Front End:&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;There are only four fields for user data entry; User Id, First Name, Middle Initial and Last Name.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;Along with this there are eight additional selections; three drop downs and five check boxes.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;The drop down boxes Business Unit and Account Type are built from xml files.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;B&gt;&lt;o:p&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;B&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;Business Unit:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;The drop down box is populated by the attribute businessUnitNameX and the attribute businessUnitDNX will be used in the backend process to place the new user object in the defined OU.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;A partially defined XML file is shown below: &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;lt;?xml version="1.0"?&amp;gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;lt;!-- Below is the configuration settings for the newuser Powershell Script&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;businessUnitX&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- Company the new user is defined to work for&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;businessUnitNameX - Complete Company Name&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;businessSMTPX&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- E-Mail Domain Name&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;businessUnitDNX&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- Distinguished Name of the OU where the new user will be placed&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;--&amp;gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;lt;Configuration&amp;gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;row&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;businessUnitX&amp;gt;acme&amp;lt;/businessUnitX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;businessUnitNameX&amp;gt;Acme&amp;lt;/businessUnitNameX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;businessSMTPX&amp;gt;acme.com&amp;lt;/businessSMTPX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;businessUnitDNX&amp;gt;OU=Acme,OU=Employees,OU=Users,DC=acme,DC=com&amp;lt;/businessUnitDNX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;/row&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;row&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;businessUnitX&amp;gt;apu&amp;lt;/businessUnitX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;businessUnitNameX&amp;gt;Acme Pencil Unit&amp;lt;/businessUnitNameX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;businessSMTPX&amp;gt;acme.com&amp;lt;/businessSMTPX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;businessUnitDNX&amp;gt;OU=APU,OU=Employees,OU=Users,DC=acme,DC=com&amp;lt;/businessUnitDNX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;/row&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;B&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;Account Type:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;The drop down box is populated by the attribute accountTypeX which will be used in the backend process to prepend the value, along with other values discussed later, on the user account description attribute.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;A defined XML file is shown below: &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;B&gt;&lt;o:p&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;lt;?xml version="1.0"?&amp;gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;lt;!-- Below is the configuration settings for the newuser Powershell Script&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;accountTypeX&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- Descriptive value used for association the user type being created&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;--&amp;gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;lt;Configuration&amp;gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;row&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;accountTypeX&amp;gt;Local Administrator&amp;lt;/accountTypeX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;/row&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;row&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;accountTypeX&amp;gt;Permanent Employee&amp;lt;/accountTypeX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;/row&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;row&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;accountTypeX&amp;gt;Service Account&amp;lt;/accountTypeX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;/row&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;row&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;accountTypeX&amp;gt;Temporary Employee&amp;lt;/accountTypeX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;/row&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;lt;/Configuration&amp;gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;B&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;Account Requested By:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;This drop down box is populated by all the user accounts, within AD, that exist from a base defined in the XML configuration file.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;This leads me into the XML Configuration file, my goal was to allow this script to be installed by just modifying the four XML files.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;The values within the Configuration file are &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;B&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;Configuration.xml&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;lt;?xml version="1.0"?&amp;gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;lt;!-- Below is the configuration settings for the newuser Powershell Script&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;Description&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- Description to be placed in user attribute&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;OrganizationalUnit - Distinguished name where to place newly created user&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;Description&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- Value to be placed in the new user's description attribute&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;Root&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- Root location of where share is to be created for the new user&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;ScriptPath&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- Executable for the logon script for the new user&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;HomeDrive&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- Drive letter for the home drive for the new user&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;xmlLocation&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- Location of xml files that contain the request for the new user .\ = same location as configuration files (Must end with a \)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;expirationLength&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- Length of time in days, before the account is expired&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;sqlServerX&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- Optional SQL Server Database, if populated then script expects to write to sqlDataBaseX audit details&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;sqlDataBaseX&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- SQL database&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;--&amp;gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;lt;Configuration&amp;gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;row&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;descriptionX&amp;gt;User Account Created by Powershell Script&amp;lt;/descriptionX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;rootX&amp;gt;\\usera\useradmin$\user&amp;lt;/rootX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;scriptPathX&amp;gt;logonScript.cmd&amp;lt;/scriptPathX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;homeDriveX&amp;gt;z&amp;lt;/homeDriveX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;xmlLocationX&amp;gt;\\server\share\newADUser\queue\&amp;lt;/xmlLocationX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;userBaseX&amp;gt;OU=Employees,OU=Users,DC=acme,DC=com&amp;lt;/userBaseX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;expirationLengthX&amp;gt;90&amp;lt;/expirationLengthX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;smtpServerX&amp;gt;smtp.acme.com&amp;lt;/smtpServerX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;emailFromX&amp;gt;adAdmin@acme.com&amp;lt;/emailFromX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;emailToX&amp;gt;NewActiveDirectoryUserDL@acme.com&amp;lt;/emailToX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;sqlServerX&amp;gt;sqlServer&amp;lt;/sqlServerX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;sqlDatabaseX&amp;gt;adAuditDB&amp;lt;/sqlDatabaseX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;/row&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;lt;/Configuration&amp;gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT size=3 face="Times New Roman"&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;B&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;StorageGroups.xml&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;lt;?xml version="1.0"?&amp;gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;lt;!-- Below are the server/storage group/Database's that are randomly selected to where a new user will be created&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;By duplicating targets you can weight updates to go more often to those if so needed&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;Pattern is ExchangeServer\StorageGroup\Database&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;To list out all db's in you enterprise bring up the Exchange Management shell as an admin and key in the following&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;get-mailboxDatabase&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;--&amp;gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;lt;Databases&amp;gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;target&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;xmlSGX&amp;gt;exchangeServer\StorageGroup1\MailBox1&amp;lt;/xmlSGX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;/target&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;target&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;xmlSGX&amp;gt;exchangeServer\StorageGroup2\MailBox1&amp;lt;/xmlSGX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;/target&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;lt;/Databases&amp;gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;After “Ok” is selected, the xml file NewUser_UserName_RandomNumber.xml is built via userTemplate.xml from data entered by the jr admin running the gui script.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;B&gt;userTemplate.xml&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;?xml version="1.0"?&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;lt;!-- Below is the configuration settings for the newuser Powershell Script form that is created&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;aliasX&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- UserId&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;(Free form entered)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;firstNameX&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- First name of newly created user&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;(Free form entered)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;mInitialX&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- Middle initial of newly created user&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;(Free form entered)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;lastNameX&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- Last name of newly created user&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;(Free form entered)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;createdByX&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- Computer and User running this tool that created this file&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;(From WMI call)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;requestedByX&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- Person who requested this new user be created&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;(From Drop Down)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;businessUnitX&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- Business Unit the new user belongs to&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;(From Drop Down)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;accountTypeX&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- Type of account this new user is&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;(From Drop Down)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;emailFlgX&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- Should this new user not be given an email mailbox&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;(Check box - True or False)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;postiniFlgX&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- Should this new user not be added to Postini for external email inbound (Check box - True or False)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;enableAcctFlg&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- Should this new user's account be enabled&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;(Check box - True or False)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;expireAcctFlg&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- Should this new user's account expire after 90 days &lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;(Check box - True or False)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;folderFlgX&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- Should this new user not be given an home folder&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;(Check box - True or False)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;lt;employee&amp;gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;row&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;aliasX&amp;gt;&amp;lt;/aliasX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;firstNameX&amp;gt;&amp;lt;/firstNameX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;mInitialX&amp;gt;&amp;lt;/mInitialX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;lastNameX&amp;gt;&amp;lt;/lastNameX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;createdByX&amp;gt;&amp;lt;/createdByX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;requestedByX&amp;gt;&amp;lt;/requestedByX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;businessUnitNameX&amp;gt;&amp;lt;/businessUnitNameX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;accountTypeX&amp;gt;&amp;lt;/accountTypeX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;emailFlgX&amp;gt;&amp;lt;/emailFlgX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;postiniFlgX&amp;gt;&amp;lt;/postiniFlgX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;enableAcctFlgX&amp;gt;&amp;lt;/enableAcctFlgX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;expireAcctFlgX&amp;gt;&amp;lt;/expireAcctFlgX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;folderFlgX&amp;gt;&amp;lt;/folderFlgX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;/row&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;/employee&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;B&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;B&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;Example:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;B&gt;newUser_pbbergs_1175854108.xml&lt;/B&gt;&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;?xml version="1.0"?&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;lt;!-- Below is the configuration settings for the newuser Powershell Script form that is created&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;aliasX&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- UserId&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;(Free form entered)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;firstNameX&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- First name of newly created user&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;(Free form entered)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;mInitialX&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- Middle initial of newly created user&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;(Free form entered)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;lastNameX&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- Last name of newly created user&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;(Free form entered)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;createdByX&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- Computer and User running this tool that created this file&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;(From WMI call)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;requestedByX&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- Person who requested this new user be created&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;(From Drop Down)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;businessUnitX&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- Business Unit the new user belongs to&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;(From Drop Down)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;accountTypeX&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- Type of account this new user is&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;(From Drop Down)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;emailFlgX&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- Should this new user not be given an email mailbox&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;(Check box - True or False)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;postiniFlgX&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- Should this new user not be added to Postini for external email inbound (Check box - True or False)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;enableAcctFlg&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- Should this new user's account be enabled&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;(Check box - True or False)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;expireAcctFlg&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- Should this new user's account expire after 90 days&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;(Check box - True or False)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;folderFlgX&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- Should this new user not be given an home folder&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;(Check box - True or False)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;SPAN&gt;&lt;FONT size=3 face="Times New Roman"&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;--&amp;gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;lt;employee&amp;gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;row&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;aliasX&amp;gt;pbbergs&amp;lt;/aliasX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;firstNameX&amp;gt;Paul&amp;lt;/firstNameX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;mInitialX&amp;gt;B&amp;lt;/mInitialX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;lastNameX&amp;gt;Bergson&amp;lt;/lastNameX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;createdByX&amp;gt;Computer:pbbergsDesktop&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;User:acme\adminpbbergs&amp;lt;/createdByX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;requestedByX&amp;gt;Joe Smith&amp;lt;/requestedByX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;businessUnitNameX&amp;gt;Acme Pencil Unit&amp;lt;/businessUnitNameX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;accountTypeX&amp;gt;Permanent Employee&amp;lt;/accountTypeX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;emailFlgX&amp;gt;False&amp;lt;/emailFlgX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;postiniFlgX&amp;gt;False&amp;lt;/postiniFlgX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;enableAcctFlgX&amp;gt;True&amp;lt;/enableAcctFlgX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;expireAcctFlgX&amp;gt;False&amp;lt;/expireAcctFlgX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;folderFlgX&amp;gt;False&amp;lt;/folderFlgX&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;/row&amp;gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt 0.5in;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;lt;/employee&amp;gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;Now that the form is loaded the user can begin to enter data.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;The first field is the &lt;B&gt;User Id&lt;/B&gt;, once entered the script will verify that the Id doesn’t currently exist.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;Both the &lt;B&gt;First&lt;/B&gt; and &lt;B&gt;Last Name&lt;/B&gt; field are required and once landing on the field a value is required before you can exit.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;B&gt;Middle Initial&lt;/B&gt; is an optional field.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;The rest of the fields are:&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;B&gt;Business Unit&lt;/B&gt; drop down allows you to select the company or business unit within the company the new user works for.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;This field is associated with an OU, which points to the location where the new user will be placed.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;B&gt;Account Type&lt;/B&gt; drop down allows you to define the type of account being created.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;This value is used to populate part of the description field for human documentation.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;B&gt;Requested By&lt;/B&gt; drop down allows you to select who was the manager that requested the account be created, this also is used to help populate the description field for human documentation.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;B&gt;Create Mailbox&lt;/B&gt; check box allows you to choose whether or not to create a mailbox with the new user&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;B&gt;Add Account to&lt;/B&gt; Postini check box is a field that prompts a manual process that notifies whether or not the account is to be allowed to receive external e-mail&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;B&gt;Enable Account&lt;/B&gt; check box allows you to choose whether or not to enable account&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;B&gt;Expire Account After 90&lt;/B&gt; &lt;B&gt;Days&lt;/B&gt; check box allows you to choose whether or not to expire account after 90 days&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;B&gt;Create Home&lt;/B&gt; &lt;B&gt;Folder&lt;/B&gt; check box allows you to choose whether or not to create a home folder for the user&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;When the form entry is completed and the OK button is selected, edit checks are rerun against the forms entered values.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;The first, middle and last names first character are capitalized and all the drop down boxes have had a value populated in them, the user created xml file is created and dropped into the location defined by the &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;Once the file has been dropped (xmlLocationL) there is the backend process that will use these same xml files to process the dropped file.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;The powershell process is setup to run every minute, via a scheduled task.&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;If no file exists the process quits, else edit checks are run and if passed the user is created.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face="Times New Roman"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face="Times New Roman"&gt;The scheduled task is just a basic, per minute task defined in the photos below:&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;o:p&gt;&lt;/o:p&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;o:p&gt;&lt;/o:p&gt;&amp;nbsp;&lt;IMG style="WIDTH:1028px;HEIGHT:180px;" src="http://blogs.dirteam.com/photos/paulbergson/images/5682/original.aspx" width=1028 height=180&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face="Times New Roman"&gt;&lt;/FONT&gt;&lt;/o:p&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;o:p&gt;&lt;IMG src="http://blogs.dirteam.com/photos/paulbergson/images/5687/original.aspx"&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;o:p&gt;&lt;/o:p&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&amp;nbsp;&lt;IMG src="http://blogs.dirteam.com/photos/paulbergson/images/5685/original.aspx"&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;IMG src="http://blogs.dirteam.com/photos/paulbergson/images/5684/original.aspx"&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;IMG src="http://blogs.dirteam.com/photos/paulbergson/images/5689/original.aspx"&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;IMG src="http://blogs.dirteam.com/photos/paulbergson/images/5688/original.aspx"&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;IMG src="http://blogs.dirteam.com/photos/paulbergson/images/5686/original.aspx"&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;Once the task has been created the service account running the task needs to have enough permissions to create the user account, the mailbox (If selected) and the home folder (If selected).&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;The location to store the code can be anywhere but the folder structure will need to be as illustrated below (&lt;B style="mso-bidi-font-weight:normal;"&gt;Note:&lt;/B&gt; Disregard the colored green and orange circles they are part of Carbonite, my cloud based backup system).&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;The users that will be running the gui will require read only permissions for the folder newADUser since this is where the code repository resides.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;The only elevated permissions needed for the folder will be read/write for the queue folder.&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;This is where the gui drops the xml file for processing.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;IMG src="http://blogs.dirteam.com/photos/paulbergson/images/5746/original.aspx"&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;With the storage of the files, as follows:&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;IMG src="http://blogs.dirteam.com/photos/paulbergson/images/5748/original.aspx"&gt;&lt;/P&gt;
&lt;P style="MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;FONT size=3 face="Times New Roman"&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;To download the content (In zipped format), click on the zipped link below. I don't like to present zip'd files but I have too many files to be downloaded individually plus I want to ensure the folder structure is properly configured.&amp;nbsp; Just remember to limit access to this structure.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;A href="https://skydrive.live.com/?cid=3B55FC84ED3C1576#cid=3B55FC84ED3C1576&amp;amp;id=3B55FC84ED3C1576%21655"&gt;https://skydrive.live.com/?cid=3B55FC84ED3C1576#cid=3B55FC84ED3C1576&amp;amp;id=3B55FC84ED3C1576%21655&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;In order to allow the task to run properly you will need to load Powershell v 2.0, this will depend on what o/s you are going to run the scheduled task on. I run it on Windows 2008 R2 which was installed through "Features". To learn how to install this you will need to do a Bing search for your o/s.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;Next you will need the Active Directory module, again since I am running the script on a 2008 R2 box it is handled via Active Directory Web Services (ADWS). If not using 2008 R2 then you will need to use the Active Directory Management Gateway Service. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;Active Directory Administration with Windows Powershell&lt;BR&gt;&lt;A href="http://technet.microsoft.com/en-us/library/dd378937(WS.10).aspx"&gt;&lt;SPAN style="COLOR:blue;"&gt;http://technet.microsoft.com/en-us/library/dd378937(WS.10).aspx&lt;/SPAN&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;Finally, you will need to install the Exchange Management tools. When this was written I used Exchange 2007, so the link below references this version:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT:normal;MARGIN:0in 0in 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Times New Roman','serif';FONT-SIZE:12pt;mso-fareast-font-family:'Times New Roman';"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/bb232090(EXCHG.80).aspx"&gt;&lt;SPAN style="COLOR:blue;"&gt;http://technet.microsoft.com/en-us/library/bb232090(EXCHG.80).aspx&lt;/SPAN&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.dirteam.com/aggbug.aspx?PostID=5742" width="1" height="1"&gt;</content><author><name>pbbergs</name><uri>http://blogs.dirteam.com/members/pbbergs.aspx</uri></author><category term="Active Directory" scheme="http://blogs.dirteam.com/blogs/paulbergson/archive/tags/Active+Directory/default.aspx" /><category term="powershell" scheme="http://blogs.dirteam.com/blogs/paulbergson/archive/tags/powershell/default.aspx" /><category term="&amp;quot;User Provisioning&amp;quot; &amp;quot;new user&amp;quot; &amp;quot;powershell&amp;quot; &amp;quot;active directory&amp;quot; gui" scheme="http://blogs.dirteam.com/blogs/paulbergson/archive/tags/_2600_quot_3B00_User+Provisioning_2600_quot_3B00_+_2600_quot_3B00_new+user_2600_quot_3B00_+_2600_quot_3B00_powershell_2600_quot_3B00_+_2600_quot_3B00_active+directory_2600_quot_3B00_+gui/default.aspx" /></entry><entry><title>Active Directory Replication Types</title><link rel="alternate" type="text/html" href="http://blogs.dirteam.com/blogs/paulbergson/archive/2011/04/06/active-directory-replication-types.aspx" /><id>http://blogs.dirteam.com/blogs/paulbergson/archive/2011/04/06/active-directory-replication-types.aspx</id><published>2011-04-07T02:01:00Z</published><updated>2011-04-07T02:01:00Z</updated><content type="html">&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;&lt;span style="line-height:115%;font-size:12pt;"&gt;&lt;font face="Calibri"&gt;&lt;font face="Times New Roman"&gt;

&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;font face="Calibri"&gt;&lt;font face="Times New Roman"&gt;&lt;p style="margin:0in 0in 10pt;line-height:normal;" class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Calibri;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;"&gt;&lt;font face="Calibri"&gt;I find myself quite
often trying to keep straight all the different replication activities that can
occur within an Active Directory (AD) domain.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;

&lt;font face="Calibri"&gt;&lt;span style="mso-bidi-font-family:Calibri;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;"&gt;There
is:&lt;/span&gt;&lt;span style="font-size:10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;

&lt;span style="font-family:Symbol;font-size:12pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;/span&gt;&lt;span style="font-size:7pt;mso-fareast-font-family:Symbol;"&gt; &lt;/span&gt;&lt;span style="mso-bidi-font-family:Calibri;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;"&gt;&lt;font face="Calibri"&gt;Intrasite
Replication&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;

&lt;span style="font-family:Symbol;font-size:12pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;/span&gt;&lt;span style="font-size:7pt;mso-fareast-font-family:Symbol;"&gt; &lt;/span&gt;&lt;span style="mso-bidi-font-family:Calibri;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;"&gt;&lt;font face="Calibri"&gt;Urgent
Replication&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;

&lt;span style="font-family:Symbol;font-size:12pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;/span&gt;&lt;span style="font-size:7pt;mso-fareast-font-family:Symbol;"&gt; &lt;/span&gt;&lt;font face="Calibri"&gt;&lt;span style="mso-bidi-font-family:Calibri;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;"&gt;Intersite
Replication&lt;/span&gt;&lt;span style="font-size:10pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;

&lt;span style="font-family:Symbol;font-size:12pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;/span&gt;&lt;span style="font-size:7pt;mso-fareast-font-family:Symbol;"&gt; &lt;/span&gt;&lt;span style="mso-bidi-font-family:Calibri;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;"&gt;&lt;font face="Calibri"&gt;Intersite
Change Notification Replication&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;

&lt;span style="font-family:Symbol;font-size:12pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;/span&gt;&lt;span style="font-size:7pt;mso-fareast-font-family:Symbol;"&gt; &lt;/span&gt;&lt;span style="mso-bidi-font-family:Calibri;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;"&gt;&lt;font face="Calibri"&gt;Reciprocal
Replication&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;

&lt;span style="font-family:Symbol;font-size:12pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;/span&gt;&lt;span style="font-size:7pt;mso-fareast-font-family:Symbol;"&gt; &lt;/span&gt;&lt;span style="mso-bidi-font-family:Calibri;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;"&gt;&lt;font face="Calibri"&gt;Immediate
Replication&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;

&lt;span style="font-family:Symbol;font-size:12pt;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;·&lt;/span&gt;&lt;span style="font-size:7pt;mso-fareast-font-family:Symbol;"&gt; &lt;/span&gt;&lt;span style="mso-bidi-font-family:Calibri;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;"&gt;&lt;font face="Calibri"&gt;Manual
Replication&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;

&lt;span style="mso-bidi-font-family:Calibri;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;"&gt;&lt;font face="Calibri"&gt;Replication between
Domain Controllers (DC’s) occurs without administrative intervention.
Replication provides the multimaster database that AD uses to allow all DC’s to
have equivalent objects within a given time frame so an object modified at one
location can be stored and forwarded to all other DC’s in its domain. How
quickly objects are replicated to the rest of the domain, by an individual dc,
is computed by the replication rules that exist and/or applied against them.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;

&lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;span style="mso-bidi-font-family:Calibri;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;"&gt;&lt;font face="Calibri"&gt;Intrasite
Replication:&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;

&lt;span style="mso-bidi-font-family:Calibri;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;"&gt;&lt;font face="Calibri"&gt;Replication between
DC’s within a site don’t need to worry about connectivity speed, so the
connections between dc’s are optimized for speed. Intrasite Replication within
a site notifies a partner DC 15 seconds after a change has occurred and all
subsequent DC’s it communicates are delayed by 3 seconds. For Windows 2000’s
partners the initial time delay was 300 seconds (5 minutes) and subsequent
partners was 30 seconds. So after the delay a partner DC is notified that the
notifier has an update. It is up to this partner DC to request the
modification. The notifying DC only notifies, it doesn’t push the change. It is
up to the notified DC to pull the change. Also, all DC’s within a site are
never more than 3 hops away from all other DC’s due to the KCC generating a
bidirectional ring topology. This also ensures a quicker convergence within a
site.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;

&lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;span style="mso-bidi-font-family:Calibri;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;"&gt;&lt;font face="Calibri"&gt;Urgent Replication:&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;

&lt;span style="mso-bidi-font-family:Calibri;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;"&gt;&lt;font face="Calibri"&gt;Urgent notification
is just that, it is not bound by the 15 second (Or 5 minutes) time delay of
Intrasite Replication. Partner DC’s are immediately notified of changes, this
only holds true for intrasite DC’s except if change site notification is
enabled.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;

&lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;span style="mso-bidi-font-family:Calibri;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;"&gt;&lt;font face="Calibri"&gt;Intersite
Replication:&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;

&lt;span style="mso-bidi-font-family:Calibri;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;"&gt;&lt;font face="Calibri"&gt;DC’s between sites
don’t follow the same set of rules that intrasite replication does. Changes
between sites are setup on a schedule. The schedule is broken up in 15 minute
increments, this schedule can also be set to only allow changes to occur at
certain times of the day, thereby saving bandwidth at key points of time. The
shortest time span for intersite to occur is 15 minutes and the longest is once
a week. Note once replication begins between DC’s, the process will not stop
until complete. So you won’t have to worry about incomplete replication activity
due to time constraints. &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;

&lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;span style="mso-bidi-font-family:Calibri;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;"&gt;&lt;font face="Calibri"&gt;Intersite Change
Notification Replication:&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;

&lt;span style="mso-bidi-font-family:Calibri;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;"&gt;&lt;font face="Calibri"&gt;With bandwidth
pipes becoming cheaper and available, many organizations are becoming more well
connected, 15 minutes can be a long time. Imagine having to wait for a password
unlock not being reset in the proper site and having to wait 15 minutes for
replication to occur. Obviously you can force replication but the point is 15
minutes between sites sometimes just isn’t realistic. To bypass the scheduled
notification delays you can enable, Intersite Change Notification. Once enabled
partners in different sites will be treated equivalently as intrasite
replication, with the exception this only holds for NTDS, NTFRS still works on
the schedule.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;

&lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;span style="mso-bidi-font-family:Calibri;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;"&gt;&lt;font face="Calibri"&gt;Reciprocal
Replication:&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;

&lt;span style="mso-bidi-font-family:Calibri;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;"&gt;&lt;font face="Calibri"&gt;Sometimes
connectivity isn’t always available, for example a Navy/Cruise ship or a dial
up connection. &lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;With this type of topology
both sides need to take advantage of the connect time, so both sides can
replicate at the same time.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;So when the
remote site connects up to the Data Center the replication pair should both
request and receive any delta’s that are available.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;Hence, replication is initiated on the basis
of change rather than on a schedule. &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;

&lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;span style="mso-bidi-font-family:Calibri;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;"&gt;&lt;font face="Calibri"&gt;Immediate
Replication:&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;

&lt;span style="mso-bidi-font-family:Calibri;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;"&gt;&lt;font face="Calibri"&gt;If an administrator
resets a password for a user who has forgotten their password, the change is
immediately replicated back to the PDCe. This isn’t a situation where the PDCe
is notified about the change but instead the change is immediately pushed to
it. The reason this is so important is that if a user attempts to logon and the
password they attempt to use fails, the DC will send the hash from the password
(Password itself is never sent over the wire) back to the PDCe to check to see
if the password is correct, since there is latency in replication. &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;

&lt;b style="mso-bidi-font-weight:normal;"&gt;&lt;span style="mso-bidi-font-family:Calibri;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;"&gt;&lt;font face="Calibri"&gt;Manual
Replication:&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;

&lt;span style="mso-bidi-font-family:Calibri;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;"&gt;&lt;font face="Calibri"&gt;Manual
replication is triggered by the admin. This can occur from either the repadmin
command or from AD Sites and Services. This will cross intersite replication
schedules if requested. So if you have a Lag Site and the network is enabled,
even though your site isn’t scheduled to replicate for possibly days a forced
replication will cause the replication to occur. So you need to be aware of
this, in a lag site I had set up I had a schedule task that actually enabled
and disabled replication to prevent this.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;
&lt;span style="mso-bidi-font-family:Calibri;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;"&gt;&lt;font face="Calibri"&gt;&amp;nbsp;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Calibri;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;"&gt;&lt;font face="Calibri"&gt;Over
the next few weeks I hope to expand and add some diagrams to help make this
easier to follow, as well as some helpful links.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;

&lt;span style="mso-bidi-font-family:Calibri;mso-ascii-font-family:Calibri;mso-hansi-font-family:Calibri;"&gt;&lt;font face="Calibri"&gt;This
can be confusing and I hope I have helped in you grasping this concept.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin:0in 0in 10pt;" class="MsoNormal"&gt;&lt;o:p&gt;&lt;font face="Calibri"&gt;&amp;nbsp;&lt;/font&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;/font&gt;&lt;/font&gt;&lt;img src="http://blogs.dirteam.com/aggbug.aspx?PostID=5668" width="1" height="1"&gt;</content><author><name>pbbergs</name><uri>http://blogs.dirteam.com/members/pbbergs.aspx</uri></author><category term="&amp;quot;Active Directory Replication&amp;quot; &amp;quot;Urgent Replicaton&amp;quot; &amp;quot;Immediate Replication&amp;quot; &amp;quot;Change Site Notification&amp;quot; &amp;quot;Reciprocal Replication&amp;quot;" scheme="http://blogs.dirteam.com/blogs/paulbergson/archive/tags/_2600_quot_3B00_Active+Directory+Replication_2600_quot_3B00_+_2600_quot_3B00_Urgent+Replicaton_2600_quot_3B00_+_2600_quot_3B00_Immediate+Replication_2600_quot_3B00_+_2600_quot_3B00_Change+Site+Notification_2600_quot_3B00_+_2600_quot_3B00_Reciprocal+Replication_2600_quot_3B00_/default.aspx" /></entry><entry><title>Preventing Lingering Object Replication in Active Directory</title><link rel="alternate" type="text/html" href="http://blogs.dirteam.com/blogs/paulbergson/archive/2011/03/08/preventing-lingering-object-replication-in-active-directory.aspx" /><id>http://blogs.dirteam.com/blogs/paulbergson/archive/2011/03/08/preventing-lingering-object-replication-in-active-directory.aspx</id><published>2011-03-08T14:23:00Z</published><updated>2011-03-08T14:23:00Z</updated><content type="html">&lt;P&gt;One thing you want to prevent in Active Directory is an Islanded DC, one in which you have lost connectivity to.&amp;nbsp; If a DC is disconnected beyond its "Tombstone Lifetime" it will begin to accumulate Lingering objects.&amp;nbsp; This isn't something you ever want to happen and if you are put in this situation I would strongly recommend you just flatten the DC, clean up the metadata in your domain and repromote the server.&lt;/P&gt;
&lt;P&gt;Read &lt;A href="http://blogs.dirteam.com/blogs/paulbergson/archive/2009/06/09/active-directory-cleanup-the-most-common-question-i-see.aspx"&gt;my blogpost on AD clean up&lt;/A&gt; for assistance if you do need to remove a failed dc:&lt;/P&gt;
&lt;P&gt;If you have an Islanded DC and for some unknown reason it is reconnected, you surely don't want to start replicating tombstoned objects to healthy DC's.&amp;nbsp; There is a simple fix for this, just enable "Strict Replication Consistency".&amp;nbsp; This registry setting will prevent replication from a corrupt partner.&amp;nbsp; You can simply open up the registry and make the modification on each dc in your domain/forest:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Strict Replication Consistency&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 = Disable (Loose)&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 = Enabled (Strict)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;More information: &lt;A href="http://technet.microsoft.com/en-us/library/cc784245(WS.10).aspx"&gt;http://technet.microsoft.com/en-us/library/cc784245(WS.10).aspx&lt;/A&gt;&lt;BR&gt;&lt;/P&gt;
&lt;P&gt;Better yet, using RepAdmin just&amp;nbsp;update all DC's&amp;nbsp;from a command prompt (You need to elevate if on Vista/2008 or greater) in your forest.&amp;nbsp; I pipe the output and&amp;nbsp;save the text file for documentation.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;repadmin /regkey * +strict &amp;gt; c:\temp\dcListStrict.log&lt;/STRONG&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;This will ensure that all your DC's are protected from any partners that are unhealthy and hopefully save you some real headscratching problems that can occur with&amp;nbsp;Lingering objects.&amp;nbsp; In the example below you can see that only one of the three DC's needed to be updated.&amp;nbsp; You will also notice that rerunning this does not have an adverse effect.&lt;/P&gt;
&lt;P&gt;The output of the above command would look like:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Repadmin: running command /regkey against read-only DC DC01.acme.com&lt;BR&gt;HKLM\System\CurrentControlSet\Services\NTDS\Parameters: "Strict Replication Consistency" REG_DWORD 0x00000001 (1)&lt;BR&gt;New HKLM\System\CurrentControlSet\Services\NTDS\Parameters: "Strict Replication Consistency" REG_DWORD 0x00000001 (1)&lt;/P&gt;
&lt;P&gt;Repadmin: running command /regkey against full DC DC02.acme.com&lt;BR&gt;HKLM\System\CurrentControlSet\Services\NTDS\Parameters: "Strict Replication Consistency" REG_DWORD 0x00000001 (1)&lt;BR&gt;New HKLM\System\CurrentControlSet\Services\NTDS\Parameters: "Strict Replication Consistency" REG_DWORD 0x00000001 (1)&lt;/P&gt;
&lt;P&gt;Repadmin: running command /regkey against full DC DC03.acme.com&lt;BR&gt;HKLM\System\CurrentControlSet\Services\NTDS\Parameters: "Strict Replication Consistency" value does not exist&lt;BR&gt;New HKLM\System\CurrentControlSet\Services\NTDS\Parameters: "Strict Replication Consistency" REG_DWORD 0x00000001 (1)&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;img src="http://blogs.dirteam.com/aggbug.aspx?PostID=5611" width="1" height="1"&gt;</content><author><name>pbbergs</name><uri>http://blogs.dirteam.com/members/pbbergs.aspx</uri></author><category term="&amp;quot;Lingering Objects&amp;quot; &amp;quot;Strict Replication Consistency&amp;quot; &amp;quot;Active Directory&amp;quot;" scheme="http://blogs.dirteam.com/blogs/paulbergson/archive/tags/_2600_quot_3B00_Lingering+Objects_2600_quot_3B00_+_2600_quot_3B00_Strict+Replication+Consistency_2600_quot_3B00_+_2600_quot_3B00_Active+Directory_2600_quot_3B00_/default.aspx" /></entry><entry><title>Windows 7/Vista clients require elevated privileges to install or update a print driver</title><link rel="alternate" type="text/html" href="http://blogs.dirteam.com/blogs/paulbergson/archive/2011/01/31/windows-7-vista-clients-require-elevated-privileges-to-install-or-update-a-print-driver.aspx" /><id>http://blogs.dirteam.com/blogs/paulbergson/archive/2011/01/31/windows-7-vista-clients-require-elevated-privileges-to-install-or-update-a-print-driver.aspx</id><published>2011-01-31T13:48:00Z</published><updated>2011-01-31T13:48:00Z</updated><content type="html">&lt;P&gt;Our Help Desk support staff was really perplexed.&amp;nbsp; They were getting hammered by phone calls whenever a print driver was updated and the Windows 7 clients attempted to upgrade the print driver.&amp;nbsp; Windows XP clients had no problems upgrading, so obviously there was a UAC issue.&lt;/P&gt;&lt;P&gt;After doing some research a new setting was discovered that by default was set to require elevated permissions to install a new or upgraded print driver.&amp;nbsp; To allow users to update or install a new driver there are two new gpo settings that need to be configured for your users.&lt;/P&gt;&lt;P&gt;Both reside at the following location:&lt;/P&gt;&lt;P&gt;Computer Configuration / Policies / Administratice Templates / Printers&lt;/P&gt;&lt;P&gt;When installing drivers for a new Connection: "Do not show warning or elevation prompt"&lt;/P&gt;&lt;P&gt;When updating drivers for an existing connection: "Do not show warning or elevation prompt"&lt;/P&gt;&lt;P&gt;By setting both vales as defined above, users will now be able to connect and update their workstations without a Help Desk support visit.&lt;/P&gt;&lt;img src="http://blogs.dirteam.com/aggbug.aspx?PostID=5543" width="1" height="1"&gt;</content><author><name>pbbergs</name><uri>http://blogs.dirteam.com/members/pbbergs.aspx</uri></author><category term="&amp;quot;Windows 7&amp;quot; Vista &amp;quot;Print Driver&amp;quot; install update UAC GPO" scheme="http://blogs.dirteam.com/blogs/paulbergson/archive/tags/_2600_quot_3B00_Windows+7_2600_quot_3B00_+Vista+_2600_quot_3B00_Print+Driver_2600_quot_3B00_+install+update+UAC+GPO/default.aspx" /></entry></feed>