Monday, August 8, 2011

MCITP syllabus (70-647)


Exam 70-647:
Pro: Windows Server 2008, Enterprise Administrator


Planning network and application services

Plan for name resolution and IP addressing. May include but is not limited to: internal and
external naming strategy, naming resolution support for legacy clients, naming resolution for directory services, IP addressing scheme, TCP/IP version coexistence

Design for network access. May include but is not limited to: network access policies, remote access strategy, perimeter networks, server and domain isolation

Plan for application delivery. May include but is not limited to: application virtualization, presentation virtualization, locally installed software, Web-based applications

Plan for Remote Desktop Services. , Terminal Services licensing, Remote Desktop Services infrastructure

Designing core identity and access management components


Design Active Directory forests and domains. May include but is not limited to: forest structure, forest and domain functional levels, intra-organizational authorization and authentication, schema modifications

Design the Active Directory physical topology. May include but is not limited to: placement of servers, site and replication topology, printer location policies

Design the Active Directory administrative model. May include but is not limited to: delegation, group strategy, compliance auditing, group administration, organizational structure

Design the enterprise-level group policy strategy. May include but is not limited to: group policy hierarchy and scope filtering, control device installation, authentication and authorization

Designing support identity and access management components  

Plan for domain or forest migration, upgrade, and restructuring. May include but is not limited to: cross-forest authentication, backward compatibility, object migration, migration planning,
implementation planning, environment preparation




Design the branch office deployment. May include but is not limited to: authentication strategy, server security

Design and implement public key infrastructure. May include but is not limited to: certificate services, PKI operations and maintenance, certificate life cycle management

Plan for interoperability. May include but is not limited to: inter-organizational authorization and authentication, application authentication interoperability, cross-platform interoperability

Designing for business continuity and data availability

Plan for business continuity. May include but is not limited to: service availability, directory service recovery

Design for software updates and compliance management. May include but is not limited to:
patch management and patch management compliance, Microsoft Update and Windows Update, security baselines, system health models

Design the operating system virtualization strategy.  server
consolidation, application compatibility, virtualization management, placement of servers

Design for data management and data access, data security, data accessibility and redundancy, data collaboration

MCITP syllabus (70-640)


Exam 70-640:

TS: Windows Server 2008 Active Directory, Configuring

1.       Configuring Domain Name System (DNS) for Active Directory
¨    Configure zones.
¨    Configure DNS server settings.
¨    Configure zone transfers and replication.


2.    Configuring the Active Directory infrastructure



¨    Configure a forest or a domain.
¨    Configure trusts.
¨    Configure sites.
¨    Configure Active Directory replication.
¨    Configure the global catalog.
¨    Configure operations masters.

3.    Configuring Active Directory Roles and Services (14 percent)



·       Configure Active Directory Lightweight Directory Service (AD LDS).
·       Configure Active Directory Rights Management Service (AD RMS).
·       Configure the read-only domain controller (RODC).
·       Configure Active Directory Federation Services (AD FSv2).

4.    Creating and maintaining Active Directory objects (18 percent)



·       Automate creation of Active Directory accounts.
·       Maintain Active Directory accounts.
·       Create and apply Group Policy objects (GPOs).
·       Configure GPO templates.

5.       Deploy and manage software by using GPOs.

6.    Configure account policies.

7.    Configure audit policy by using GPOs.

8.    Maintaining the Active Directory environment
·       Configure backup and recovery.
·       Perform offline maintenance.
·       Monitor Active Directory.

9.    Configuring Active Directory Certificate Services 

10.Install Active Directory Certificate Services.

·       Configure CA server settings.

·       Manage certificate templates.

·       Manage enrollments.

·       Manage certificate revocations.

MCITP syllabus (70-643)


Exam 70-643:
TS: Windows Server 2008 Applications Infrastructure, Configuring

Deploying Servers 



           Deploy images by using Windows Deployment Services.
 Configure Microsoft Windows activation.
 Configure Windows Server Hyper-V and virtual machines.
 Configure high availability.
 Configure storage.

Configuring Remote Desktop Services

Configure RemoteApp and Remote Desktop Web Access.
Configure Remote Desktop Gateway (RD Gateway).
Configure Remote Desktop Connection Broker.
Configure and monitor Remote Desktop resources.
Configure Remote Desktop licensing.
Configure Remote Desktop Session Host.

Configuring a Web Services Infrastructure


Configure Web applications.
Manage Web sites.
Configure a File Transfer Protocol (FTP) server.
Configure Simple Mail Transfer Protocol (SMTP).
Manage the Web Server (IIS) role.
Configure SSL security.
Configure Web site authentication and permissions.

Configuring Network Application Services

  
         Manage the Streaming Media Services role.
Configure SharePoint Foundation options.

MCITP syllabus (70-642)



Exam 70-642:
TS: Windows Server 2008 Network Infrastructure, Configuring.
Configuring Addressing and Services  
       Configure IPv4 and IPv6 addressing.
Configure Dynamic Host Configuration Protocol (DHCP).
Configure routing.
  Configure Windows Firewall with Advanced Security.
Configuring Names Resolution

Configure a Domain Name System (DNS) server.
Configure DNS zones.
Configure DNS records.
Configure DNS replication.
Configure name resolution for client computers.

Configuring Network Access

Configure remote access.
Configure Network Access Protection (NAP).
Configure Direct Access.
       Configure Network Policy Server (NPS).

Configuring File and Print Services


Configure a file server.
Configure Distributed File System (DFS).
Configure backup and restore.
    Manage file server resources.
Configure and monitor print services.

Monitoring and Managing a Network Infrastructure

Configure Windows Server Update Services (WSUS) server settings.
Configure performance monitoring.
Configure event logs.
Gather network data.


Monday, July 4, 2011

Steps to clean a computer.



1. Start/Run and type MSCONFIG (doesn’t have to be capitals).

2. Go to the Startup tab and look for anything that doesn’t belong there, especially blank entries with a checkmark beside it. Uncheck those and qttask, msmsgs, itunes stuff. Leave the ones below checked.



1. Next open Windows Explorer

2. Go to Tools Tab then down to Folder Options

3. In the new window go to View tab (2nd over)

4. Click on “Show hidden files”

5. Uncheck Hide Extensions

6. Uncheck Hide Protected Operating System files, click Ok on warning message.

7. Click APPLY and then APPLY TO ALL FOLDERS

8. Click OK to close.

Go back to Windows Explorer

Clean the dead files off the computer

1. Go to “C:\Documents and Settings\USER NAME\Local Settings” where USER NAME is the person who is logged on. Might even be User. In Vista go to USERS folder instead of Doc&Settings.



2. Go into TEMP folder and delete everything in there.

3. Go into Temporary Internet Files and delete everything in there or under Content.IE5 (ignore and leave index.dat file)

4. Do this for everyone in Document and Settings: Administrator, Default User, LocalService, NetworkService and any other user listed. Some may not have all the folders showing, or have anything in it.

5. Go back to the C: drive and then to WINDOWS folder. There is a TEMP folder in there. Empty that one also.

6. Right click on the C: drive, TOOLS tab and click FIX ERRORS. Select first checkbox and a warning will come about doing this upon next reboot, accept it and reboot.

If suspect a virus, go to housecall.trendmicro.com and do an online virus scan. If unable to do any of the above steps reboot, go into SAFE mode (F8) and try from there.

Run as Commands



C:\>runas /profile /env /user:tomax7\admin "mmc %windir%\system32\dsa.msc"

C:\>runas /profile /env /user:tom8\tom "%windir%\notepad.exe



C:\Documents and Settings\tom>runas /?



RUNAS USAGE:



RUNAS [ [/noprofile
/profile] [/env] [/netonly] ] /user: program



RUNAS [ [/noprofile
/profile] [/env] [/netonly] ] /smartcard [/user:] program



/noprofile - specifies that the user's profile should not be loaded.

This causes the application to load more quickly, but can cause some applications to malfunction.



/profile - specifies that the user's profile should be loaded. This is the default.



/env - to use current environment instead of user's.



/netonly - use if the credentials specified are for remote access only.



/savecred - to use credentials previously saved by the user.

This option is not available on Windows XP Home Edition and will be ignored.



/smartcard use if the credentials are to be supplied from a smartcard.



/user should be in form USER@DOMAIN or DOMAIN\USER program command line for EXE.



Examples:

> runas /noprofile /user:mymachine\administrator cmd

> runas /profile /env /user:mydomain\admin "mmc %windir%\system32\dsa.msc"

> runas /env /user:user@domain.microsoft.com "notepad \"my file.txt\""



NOTE: Enter user's password only when prompted.

NOTE: USER@DOMAIN is not compatible with /netonly.

NOTE: /profile is not compatible with /netonly.



C:\Documents and Settings\tom>cd\



C:\>runas /profile /env /user:tomax7\admin "mmc %windir%\system32\dsa.msc"

Enter the password for tomax7\admin:



Attempting to start mmc C:\WINDOWS\system32\dsa.msc as user "tomax7\admin" ..

RUNAS ERROR: Unable to run - mmc C:\WINDOWS\system32\dsa.msc

1326: Logon failure: unknown user name or bad password.



C:\>runas /profile /env /user:tom8\tom "%windir%\notepad.exe

Understanding stub zones

A stub zone is a copy of a zone that contains only those resource records necessary to identify the authoritative Domain Name System (DNS) servers for that zone. A stub zone is used to resolve names between separate DNS namespaces. This type of resolution may be necessary when a corporate merger requires that the DNS servers for two separate DNS namespaces resolve names for clients in both namespaces.

A stub zone consists of:

• The start of authority (SOA) resource record, name server (NS) resource records, and the glue A resource records for the delegated zone.

• The IP address of one or more master servers that can be used to update the stub zone.

The master servers for a stub zone are one or more DNS servers authoritative for the child zone, usually the DNS server hosting the primary zone for the delegated domain name.

Stub zone resolution

When a DNS client performs a recursive query operation on a DNS server hosting a stub zone, the DNS server uses the resource records in the stub zone to resolve the query. The DNS server sends an iterative query to the authoritative DNS servers specified in the NS resource records of the stub zone as if it were using NS resource records in its cache. If the DNS server cannot find the authoritative DNS servers in its stub zone, the DNS server hosting the stub zone attempts standard recursion using its root hints.

The DNS server will store the resource records it receives from the authoritative DNS servers listed in a stub zone in its cache, but it will not store these resource records in the stub zone itself; only the SOA, NS, and glue A resource records returned in response to the query are stored in the stub zone. The resource records stored in the cache are cached according to the Time-to-Live (TTL) value in each resource record. The SOA, NS, and glue A resource records, which are not written to cache, expire according to the expire interval specified in the stub zone's SOA record, which is created during the creation of the stub zone and updated during transfers to the stub zone from the original, primary zone.

If the query was an iterative query, the DNS server returns a referral containing the servers specified in the stub zone.

Communication between DNS servers hosting parent and child zones

A DNS server that has delegated a domain to a child zone on a different DNS server is made aware of new authoritative DNS servers for the child zone only when the resource records for these new DNS servers are added to the parent zone hosted on the DNS server. This is a manual process and requires that the administrators for the different DNS servers communicate often. With stub zones, a DNS server hosting a stub zone for one of its delegated domains can obtain updates of the authoritative DNS servers for the child zone when the stub zone is updated. The update is performed from the DNS server hosting the stub zone and the administrator for the DNS server hosting the child zone does not need to be contacted. This functionality is explained in the following example.

A stub zone is a read-only copy of a zone, which obtains its resource records from other name servers. It contains copies of only three types of resource records:



1. SOA record for the zone.

2. Name server (NS) records for all name servers authoritative for the zone.

3. Host (A) records for all name servers authoritative for the zone.



These resource records are necessary to identify the authoritative DNS server for the zone. A stub zone is used to streamline name resolution, especially in a split namespace scenario.



A DNS server that is hosting a stub zone is configured with the IP address of the authoritative server from which it loads. DNS servers can use stub zones for both iterative and recursive queries. When a DNS server hosting a stub zone receives a recursive query for a computer name in the zone to which the stub zone refers, the DNS server uses the IP address to query the authoritative server, or, if the query is iterative, returns a referral to the DNS servers listed in the stub zone. A stub zone reduces the amount of DNS traffic on the network and makes DNS more efficient especially over slow WAN links.  

Using stub zones

Use stub zones to:

• Keep delegated zone information current. By updating a stub zone for one of its child zones regularly, the DNS server hosting both the parent zone and the stub zone will maintain a current list of authoritative DNS servers for the child zone.

• Improve name resolution. Stub zones enable a DNS server to perform recursion using the stub zone's list of name servers without needing to query the Internet or internal root server for the DNS namespace.

• Simplify DNS administration. By using stub zones throughout your DNS infrastructure, you can distribute a list of the authoritative DNS servers for a zone without using secondary zones. However, stub zones do not serve the same purpose as secondary zones and are not an alternative when considering redundancy and load sharing.

There are two lists of DNS servers involved in the loading and maintenance of a stub zone:

• The list of master servers from which the DNS server loads and updates a stub zone. A master server may be a primary or secondary DNS server for the zone. In both cases, it will have a complete list of the DNS servers for the zone.

• The list of the authoritative DNS servers for a zone. This list is contained in the stub zone using name server (NS) resource records.

When a DNS server loads a stub zone, such as widgets.example.com, it queries the master servers, which can be in different locations, for the necessary resource records of the authoritative servers for the zone widgets.example.com. The list of master servers may contain a single server or multiple servers and can be changed anytime.

Stub zone updates

Stub zone updates involve the following conditions:

• When a DNS server loads a stub zone, it queries the zone's master server for the SOA resource record, NS resource records at the zone's root, and glue A resource records.

• During updates to the stub zone, the master server is queried by the DNS server hosting the stub zone for the same resource record types requested during the loading of the stub zone.

• The Refresh interval of the SOA resource record determines when the DNS server hosting the stub zone will attempt a zone transfer (update).

• If an update fails, the Retry interval of the SOA resource record determines when the update is retried.

• Once the Retry interval has expired without a successful update, the expiration time as specified in the Expires field of the SOA resource record determines when the DNS server stops using the stub zone data.

Use the DNS console in Microsoft Management Console (MMC) to perform the following stub zone update operations:

• Reload. Reload the stub zone from the local storage of the DNS server hosting the stub zone.

• Transfer from master. Have the DNS server hosting the stub zone determine if the serial number in the stub zone's SOA resource record has expired, and then perform a zone transfer from the stub zone's master server.

• Reload from master. Perform a zone transfer from the stub zone's master server regardless of the serial number in the stub zone's SOA resource record.


ref:  Updated: January 21, 2005 http://technet.microsoft.com/en-us/library/cc779197.aspx





Citrix xen App port Numbers

ICA: 1494 Session reliability: 2598 IMA: 2512 (Server to server) 2513 (Server to console) XML: 80 when integrated with IIS can be configu...