Friday, May 29, 2015

Exchange 2013 "0x80070005-00000000-00000000"

Unexpected error "0x80070005-00000000-00000000" can be obtained in an environment of coexistence of Exchange 2010 and Exchange 2013. This error occurs when you send as of another mailbox. For example,
"user 1" mailbox in Exchange Server 2010
"user 2" mailbox in Exchange Server 2013
"user 2" has "full access" to a "user 1" mailbox, but does not have the right to "send as"
"user 2" tries to forward a letter from the "user 1" mailbox, and the "user 2" receives an error "0x80070005-00000000-00000000"

For the granting of the right to "send as" of the need to execute a command in the Exchange Managment Shell:

Add-ADPermission "User 1" -User "User 2" -Extendedrights "Send As"

Sunday, May 10, 2015

Exchange 2010 Managment Console - Queue Viewer. High CPU load.

If the Exchange server console is performed for a long time "Exchange Managment Console - Queue Viewer" it begins to consume large amounts of CPU time, which leads to periodically disable the Outlook. Such situations occur frequently in the management Exchange server administrators group. To avoid such situations, you need to configure limits on a remote RDP sessions. This can be done in person at the relevant servers or Group Policy:

the first method
Administrative Tools - Remote Desktop Services - Remote Desktop Session Host Configuration - RDP-Tcp Properties - Sessions


second method
Computer Configuration - Administrative Templates - Windows Components - Remote Desktop Services - Remote Desktop Session Host - Session Time Limits - Set time limit for disconnected sessions - End a disconnected Session e.g. 10 min

Monday, May 4, 2015

Two ways to add a recipient to exclude spam filter Microsoft Exchange 2010/2013 Edge

In this article I want to write about two ways to add a recipient to the list of exceptions antispam check Microsoft Exchange 2010/2013. The first method is certainly in which the entire outer pouch assigned rating (SCL) of "-1", and usually such mail falls into "Inbox" the recipient's mailbox. The second method allows you to deliver the external mail with a score (SCL) on the basis of which it is possible to move the mail to the "Junk Email" folder.

Method one:
run on Exchange 2010/2013 Edge
$list = (Get-ContentFilterConfig).BypassedRecipients
$list.add("i-evgeny@contoso.com")
Set-ContentFilterConfig -BypassedRecipients $list


Method two:
run on Exchange 2010/2013 FE/backend
Set-Mailbox i-evgeny@contoso.com -AntispamBypassEnabled $true -SCLJunkEnabled $true -SCLJunkThreshold 4


To avoid conflicts must be used for the recipient only one method.

Saturday, March 28, 2015

Grant administrative access to MS SQL Server

Due to some configuration errors SQL server can lose access to the console. In this article I will describe the steps to provide access to the server for the local administrator SQL

Open services.msc
Stop "SQL Server (MSSQLSERVER)" (or other instance name)
Determinete path where sqlservr.exe e.g. "C:\Program Files\Microsoft SQL Server\MSSQL12.MSSQLSERVER\MSSQL\Binn\sqlservr.exe"

Open cmd.exe
Run SQL with minimum configuration e.g. "C:\Program Files\Microsoft SQL Server\MSSQL12.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -f



Open cmd.exe
Run sqlcmd.exe and this command
CREATE LOGIN [PCNAME\admin] FROM WINDOWS
GO
ALTER SERVER ROLE [sysadmin] ADD MEMBER [PCNAME\admin]
GO
 Press CRTL-C in cmd running sqlservr.exe -f, press "Y"
Open services.msc
Start "SQL Server (MSSQLSERVER)" (or other instance name)

Thursday, February 26, 2015

Script for clear cache on DNS Servers in Domain (Domain Controllers)

Sometimes you need to change to the DNS server is very fast to apply. I want to share with you a script that will help to make clear the cache DNS quickly.
1. Clear the cache for all domain controllers of the domain (clear_dns_cache_domain.ps1)

$DomainContext = New-Object System.DirectoryServices.ActiveDirectory.DirectoryContext("Domain", "hq.contoso.com")
$objDomain = [System.DirectoryServices.ActiveDirectory.Domain]::GetDomain($DomainContext)
foreach ($DC in $objDomain.DomainControllers.name)
{
    $Error.Clear()
    write-host $DC " start clear"
    $cache = Get-WmiObject -Namespace root/MicrosoftDNS -ComputerName $DC -query "Select * From MicrosoftDNS_Cache"
    $cache.ClearCache()
    if ($Error) { write-host $DC " fail clear" -fore Yellow }
    else { write-host $DC " cleared" -fore green }
}

2. Clear the cache for all domain controllers in one forest (clear_dns_cache_forest.ps1)

$ForestContext = New-Object System.DirectoryServices.ActiveDirectory.DirectoryContext("Forest", "contoso.com")
$objForest = [System.DirectoryServices.ActiveDirectory.Forest]::GetForest($ForestContext)
foreach ($Domain in $objForest.Domains)
{
    foreach ($DC in $Domain.DomainControllers.name)
    {
        $Error.Clear()
        write-host $DC " start clear"
        $cache = Get-WmiObject -Namespace root/MicrosoftDNS -ComputerName $DC -query "Select * From MicrosoftDNS_Cache"
        $cache.ClearCache()
        if ($Error) { write-host $DC " fail clear" -fore Yellow }
        else { write-host $DC " cleared" -fore green }
    }
}

Tuesday, December 9, 2014

add-QADGroupMember : Cannot resolve directory object for the given identity

When the script (variables formed in progress) powershell encountered an unexpected error:

$Group_DN = "CN=MyGroup1,OU=MyOU1,DC=hq,DC=contoso,DC=com"
add-QADGroupMember -identity $Group_DN -member hq\MyUser1

add-QADGroupMember : Cannot resolve directory object for the given identity:

And in a separate window powershell commands are processed normally. First decided to add quotes received a new error:

add-QADGroupMember : Cannot bind parameter 'Identity'. Cannot convert the "" value of type

Then drew attention to the following line in error:

value of type "Microsoft.PowerShell.Commands.MatchInfo" to type "Quest.ActiveRoles.ArsPowerShellSnapIn.Data.IdentityParameter"

And I realized that you just have to convert the variable type



$Group_DN = "CN=MyGroup1,OU=MyOU1,DC=hq,DC=contoso,DC=com"
[string]$Group_DN2 = $Group_DN
add-QADGroupMember -identity $Group_DN2 -member hq\MyUser1

Monday, December 8, 2014

Self Service Password Reset Web Site

In a complex network with some trusted and untrusted forests, where users can use the accounts of various woods, there are problems with changing the password, the article http://www.kovanev.net/faq/vbs/164-vbs-3 describes a good script to reset your password. In my version redesigned with a request to WINNT LDAP to view subdomains, and adds the ability to work without authentication for users from untrusted forests.

On the Web server, do the following:
1. Create a folder, eg C:\ChangePass
2. In the folder create a file containing index.html (download index.html)

<html>
<head>
<title>Change User Password</title>
<!--BEGIN CALLOUT A-->
<HTA:APPLICATION
BORDER="thin"
BORDERSTYLE="sunken"
CAPTION="yes"
MAXIMIZEBUTTON="yes"
MINIMIZEBUTTON="yes"
SCROLL="no"
SHOWINTASKBAR="no"
SYSMENU="yes"
WINDOWSTATE="normal" />

<!--END CALLOUT A-->
<script language=javascript>
var sampleWidth = 300;
var sampleHeight = 420;
window.resizeTo(sampleWidth,sampleHeight);
var screenPosX = screen.Width/2 - sampleWidth/2;
var screenPosY = screen.Height/2 - sampleHeight/2;
window.moveTo(800, 300);
</script>
</head>

<body>
    <form action="cp.asp" method="post">
        <!--BEGIN CALLOUT C-->
        <p><font size="3">Specify your username: </font></p><input type="text" name="T1" size="20">
        <!--END CALLOUT C-->
        <p><font size="3">Enter your current password: </font></p><input type="password" name="T2" size="20"></p>
        <p><font size="3">Enter a new password: </font></p><input type="password" name="T3" size="20"></p>
        <p><font size="3">Re-enter new password: </font></p><input type="password" name="T4" size="20"></p>
        <!--BEGIN CALLOUT D-->
        <p><input type="Submit" value="Change password" name="B3" >
        <input type="button" value="Cancel" name="B6" onclick=self.close()></p>
        <!--END CALLOUT D-->
    </form>
</body>
</html>

3. Create user for impersonate authentication, add user to NULL group, exclude from Domain Users
4. In the folder create a file containing cp.asp (download cp.asp), add user login, password, domain

<%@ language="VBScript" %>
<%
Dim objLogon
Set objLogon = Server.CreateObject("LoginAdmin.ImpersonateUser")
objLogon.Logon "youruser", "yourpassword", "youruserdomain"

Set WShell = CreateObject("WScript.Shell")
on error resume next
Dim UserName
UserName = Request.Form("T1")
Const ADS_SCOPE_SUBTREE = 2
Set objConnection = CreateObject("ADODB.Connection")
Set objCommand =   CreateObject("ADODB.Command")
objConnection.Provider = "ADsDSOObject"
objConnection.Open "Active Directory Provider"
Set objCommand.ActiveConnection = objConnection
objCommand.Properties("Page Size") = 10000
objCommand.Properties("Searchscope") = ADS_SCOPE_SUBTREE

objCommand.CommandText = _
   "SELECT distinguishedName FROM 'LDAP://hq.contoso.com' WHERE objectCategory='user' " & _ "AND samaccountname = '" & username &"'" &""
Set objRecordSet = objCommand.Execute

objRecordSet.MoveFirst
Do Until objRecordSet.EOF
    strDN = objRecordSet.Fields("distinguishedName").Value
    objRecordSet.MoveNext
Loop

Set User = GetObject("LDAP://" & strDN)

objLogon.Logoff
     Set objLogon = Nothing

Dim NewPassword
Dim NewPassword2
Dim OldPassword

OldPassword = Request.Form("T2")
NewPassword = Request.Form("T3")
NewPassword2 = Request.Form("T4")

If Request.Form("T1") = "" Then
    Response.Write("Username can't be empty!")
end if

If NewPassword<>NewPassword2 Then
    Response.Write("ERROR. New passwords do not match.")
end if

if NewPassword=NewPassword2 then
    Err.Clear
    Call user.CHANGEPASSWORD (OldPassword, NewPassword)

If err.number = 0 Then
    Response.Write("SUCCESS. New password has been saved.")
end if

If err.number = "-2147024810" Then
    Response.Write("ERROR. Wrong password!")
end if

If err.number = "-2147022651" Then
    Response.Write("ERROR. The new password does not meet the policy complexity and frequency of passwords!")
end if
end if
 %>

5. Download LoginAdmin.dll or create your own article: "How to impersonate a user from Active Server Pages"
6. Register the dll, eg regsvr32.exe C:\ChangePass\LoginAdmin.dll
7. In IIS console to create a website "ChangePass", specify the folder "C:\ChangePass", configure Bindings, configure https, anonymous authentication
8. When you open the page, you will see:
UPD: In some cases, the need to provide for Identity "youruser" application pool