<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title> &#187; Ashley Moore</title>
	<atom:link href="http://risualblogs.com/blog/author/ashleym/feed/" rel="self" type="application/rss+xml" />
	<link>http://risualblogs.com/blog</link>
	<description></description>
	<lastBuildDate>Fri, 18 May 2012 16:31:58 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.3</generator>
		<item>
		<title>Direct Access Manage Out not working</title>
		<link>http://consulting.risualblogs.com/blog/2012/05/17/direct-access-manage-out-not-working/</link>
		<comments>http://consulting.risualblogs.com/blog/2012/05/17/direct-access-manage-out-not-working/#comments</comments>
		<pubDate>Thu, 17 May 2012 19:48:54 +0000</pubDate>
		<dc:creator>Ashley Moore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Forefront]]></category>
		<category><![CDATA[UAG]]></category>

		<guid isPermaLink="false">http://2.542</guid>
		<description><![CDATA[Quite a few weeks ago now I came across this issue on a customer site and managed to resolve narrowing it down to group policy and finding the troublesome policy to be the setting for &#34;Access this computer from the network&#34;. On Monday of this week Microsoft released a KB article detailing this problem (http://support.microsoft.com/kb/2663354) [...]


Related posts:<ol><li><a href='http://support.risualblogs.com/blog/2011/12/08/rdp-over-direct-access/' rel='bookmark' title='Permanent Link: RDP over Direct Access'>RDP over Direct Access</a> <small>A customer has requested recently that they want to be...</small></li>
<li><a href='http://support.risualblogs.com/blog/2011/10/12/how-to-configure-the-network-access-account-in-sccm-2012/' rel='bookmark' title='Permanent Link: How to Configure the Network Access Account in SCCM 2012'>How to Configure the Network Access Account in SCCM 2012</a> <small>Just a quick guide on where to configure the Network...</small></li>
<li><a href='http://support.risualblogs.com/blog/2011/10/28/adfs-2-0-401-unauthorized-access/' rel='bookmark' title='Permanent Link: ADFS 2.0 401 Unauthorized Access'>ADFS 2.0 401 Unauthorized Access</a> <small>We had an issue recently when setting up CRM 2011...</small></li>
</ol>

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>Quite a few weeks ago now I came across this issue on a customer site and managed to resolve narrowing it down to group policy and finding the troublesome policy to be the setting for &quot;Access this computer from the network&quot;. On Monday of this week Microsoft released a KB article detailing this problem (<a title="http://support.microsoft.com/kb/2663354" href="http://support.microsoft.com/kb/2663354">http://support.microsoft.com/kb/2663354</a>) but thought it was worth blogging as i did come across it a few weeks ago (promise!)</p>
<p>Basically when you modify this particular group policy setting it changes the local policy on the machine. Manage out capabilities in Direct Access require the internal source user and computer account to authenticate IPsec connections to the DA client. This particular policy setting controls what accounts have access to system services on the DA computer. If the source computer account does not have this access then IPsec authentication will fail. The default setting for this is the only supported one currently for DA, by default this includes &#8211; Administrators, Backup Operators, Everyone, Users</p>
<p>Hope this helps others resolve a peculiar difficult to determine issue!</p>
<p>Ash </p>


<p>Related posts:<ol><li><a href='http://support.risualblogs.com/blog/2011/12/08/rdp-over-direct-access/' rel='bookmark' title='Permanent Link: RDP over Direct Access'>RDP over Direct Access</a> <small>A customer has requested recently that they want to be...</small></li>
<li><a href='http://support.risualblogs.com/blog/2011/10/12/how-to-configure-the-network-access-account-in-sccm-2012/' rel='bookmark' title='Permanent Link: How to Configure the Network Access Account in SCCM 2012'>How to Configure the Network Access Account in SCCM 2012</a> <small>Just a quick guide on where to configure the Network...</small></li>
<li><a href='http://support.risualblogs.com/blog/2011/10/28/adfs-2-0-401-unauthorized-access/' rel='bookmark' title='Permanent Link: ADFS 2.0 401 Unauthorized Access'>ADFS 2.0 401 Unauthorized Access</a> <small>We had an issue recently when setting up CRM 2011...</small></li>
</ol></p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://consulting.risualblogs.com/blog/2012/05/17/direct-access-manage-out-not-working/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8220;An unexpected error has occurred..&#8221; when trying to IRM protect content with RMS Administrative Template</title>
		<link>http://consulting.risualblogs.com/blog/2012/05/04/an-unexpected-error-has-occurred-when-trying-to-irm-protect-content-with-rms-administrative-template/</link>
		<comments>http://consulting.risualblogs.com/blog/2012/05/04/an-unexpected-error-has-occurred-when-trying-to-irm-protect-content-with-rms-administrative-template/#comments</comments>
		<pubDate>Fri, 04 May 2012 14:22:12 +0000</pubDate>
		<dc:creator>Ashley Moore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[AD RMS]]></category>

		<guid isPermaLink="false">http://2.537</guid>
		<description><![CDATA[I recently had this problem on a customer site, documents could be protected using RMS with manual permissions no problems, bootstrapping process completed and all was fine. However after creating Administrative Templates and attempted to apply protection using those templates it failed with the useful “An unexpected error has occurred..” message. Hmmm head scratcher… So [...]


Related posts:<ol><li><a href='http://support.risualblogs.com/blog/2012/02/28/a-server-side-seed-operation-has-failed-error-an-error-occurred-while-performing-the-seed-operation-which-may-indicate-a-problem-with-the-source-disk-error-an-error-occurred-while-attempting-to-a/' rel='bookmark' title='Permanent Link: A server-side seed operation has failed. Error: An error occurred while performing the seed operation, which may indicate a problem with the source disk. Error: An error occurred while attempting to access remote resources. Error: An error occurred while processing a request on server &#8216;SERVER&#8217;. Error: Database &#8216;catalog&#8217; was not active on source server'>A server-side seed operation has failed. Error: An error occurred while performing the seed operation, which may indicate a problem with the source disk. Error: An error occurred while attempting to access remote resources. Error: An error occurred while processing a request on server &#8216;SERVER&#8217;. Error: Database &#8216;catalog&#8217; was not active on source server</a> <small>While running Exchange 2010 SP1, We recently came across the...</small></li>
<li><a href='http://support.risualblogs.com/blog/2011/11/17/how-to-enable-the-new-error-pages-after-updating-to-tmg-sp2/' rel='bookmark' title='Permanent Link: How to Enable the New Error pages after updating to TMG SP2'>How to Enable the New Error pages after updating to TMG SP2</a> <small>With TMG SP2 Microsoft have released a new error page...</small></li>
<li><a href='http://support.risualblogs.com/blog/2012/01/16/disabling-activesync-on-exchange-2010/' rel='bookmark' title='Permanent Link: Disabling ActiveSync on Exchange 2010'>Disabling ActiveSync on Exchange 2010</a> <small>We had a query from a customer recently , asking...</small></li>
</ol>

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>I recently had this problem on a customer site, documents could be protected using RMS with manual permissions no problems, bootstrapping process completed and all was fine. However after creating Administrative Templates and attempted to apply protection using those templates it failed with the useful “An unexpected error has occurred..” message. Hmmm head scratcher…</p>
<p>So troubleshooting I made sure i had applied permissions correctly on the template, not that i should receive an error message like the one i was getting but good place to start. Checked access to the template file share, fine. Checked AD RMS server was exporting the templates correctly, fine but I did notice something else in checking this ..</p>
<p>I opened one of the templates in an XML editor and noticed that the licensing cluster URL contained a :443, then checking in the AD RMS console this was the case in the licensing URL there too. The trouble with this is that the CLC certificates are attempted to be matched with the RAC’s using the RMS URL, if they are different (certification has no :443 and licensing has :443) you hit an error. </p>
<p>To resolve this issue follow these steps (Note: While following these steps you will remove the SCP temporarily, users will not be able to protect or consume new content during this period so be careful!):</p>
<p>1.)&#160; Open the ADRMS&#160; console and Right Click on the Server name, and go to Properties.</p>
<p>2.) Go to the &#8216;SCP&#8217; tab and remove the SCP.</p>
<p>3.) Go to the Cluster URLs tab, and check the box for &#8216;Extranet URLs&#8217; (If you have Extranet URL’s configured then ensure the :443 is not present and move on)</p>
<p>4.) Enter anything into both boxes and click Apply.</p>
<p>5.) Uncheck the &#8216;Extranet URLs&#8217; box, and hit Apply, then OK.</p>
<p>6.) Close the ADRMS Console and re-open it.</p>
<p>7.) Right Click on the server name&gt;Properties&gt;SCP Tab, and register the SCP.</p>
<p>8.)Check your RMS settings now and make sure that no :443 exists in any of the cluster URLs.</p>
<p>9.) Go to Regedit and create this key on each cluster in the server</p>
<p>HKLM/Software/Microsoft/DRMS </p>
<p>Reg_Sz:GICURL   <br />Value: <a href="https://adrms.yourdomain.com/_wmcs/certification/certification.asmx">https://<em>adrms.yourdomain.com/_wmcs/certification/certification.asmx</em></a></p>
<p>11.) Go to an Administrative command prompt and run IISRESET on each server in the cluster</p>
<p>12.) Go to client PC and delete the %localappdata%MicrosoftDRM folder.</p>
<p>13.) In the ADRMS console right click the Administrative Template and select “Archive this Rights Policy Template”</p>
<p>14.) Select Manage Archived Rights Policy Templates and Right click the template and select Copy, give it a different name</p>
<p>15.)Right click the copy and select “Distribute this Rights Policy Template”</p>
<p>Once these steps are completed you should be able to go back into your application and apply protection using the Administrative Template! Yay!</p>
<p>HTH</p>
<p>Ash</p>


<p>Related posts:<ol><li><a href='http://support.risualblogs.com/blog/2012/02/28/a-server-side-seed-operation-has-failed-error-an-error-occurred-while-performing-the-seed-operation-which-may-indicate-a-problem-with-the-source-disk-error-an-error-occurred-while-attempting-to-a/' rel='bookmark' title='Permanent Link: A server-side seed operation has failed. Error: An error occurred while performing the seed operation, which may indicate a problem with the source disk. Error: An error occurred while attempting to access remote resources. Error: An error occurred while processing a request on server &#8216;SERVER&#8217;. Error: Database &#8216;catalog&#8217; was not active on source server'>A server-side seed operation has failed. Error: An error occurred while performing the seed operation, which may indicate a problem with the source disk. Error: An error occurred while attempting to access remote resources. Error: An error occurred while processing a request on server &#8216;SERVER&#8217;. Error: Database &#8216;catalog&#8217; was not active on source server</a> <small>While running Exchange 2010 SP1, We recently came across the...</small></li>
<li><a href='http://support.risualblogs.com/blog/2011/11/17/how-to-enable-the-new-error-pages-after-updating-to-tmg-sp2/' rel='bookmark' title='Permanent Link: How to Enable the New Error pages after updating to TMG SP2'>How to Enable the New Error pages after updating to TMG SP2</a> <small>With TMG SP2 Microsoft have released a new error page...</small></li>
<li><a href='http://support.risualblogs.com/blog/2012/01/16/disabling-activesync-on-exchange-2010/' rel='bookmark' title='Permanent Link: Disabling ActiveSync on Exchange 2010'>Disabling ActiveSync on Exchange 2010</a> <small>We had a query from a customer recently , asking...</small></li>
</ol></p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://consulting.risualblogs.com/blog/2012/05/04/an-unexpected-error-has-occurred-when-trying-to-irm-protect-content-with-rms-administrative-template/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AD RMS with Hardware Load Balancer</title>
		<link>http://consulting.risualblogs.com/blog/2012/05/04/ad-rms-with-hardware-load-balancer/</link>
		<comments>http://consulting.risualblogs.com/blog/2012/05/04/ad-rms-with-hardware-load-balancer/#comments</comments>
		<pubDate>Fri, 04 May 2012 08:38:49 +0000</pubDate>
		<dc:creator>Ashley Moore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[AD RMS]]></category>

		<guid isPermaLink="false">http://2.529</guid>
		<description><![CDATA[Just wanted to create a quick post to share an issue i had recently while on a customer site installing an AD RMS High Availability solution. The solution had two AD RMS servers using a HLB for redundancy, both servers were installed and joined to the same RMS cluster with no problems. However when the [...]


Related posts:<ol><li><a href='http://consulting.risualblogs.com/blog/2011/12/15/ad-rms-changing-certification-pipeline-to-use-ssl-after-initial-install/' rel='bookmark' title='Permanent Link: AD RMS &#8211; Changing Certification Pipeline to use SSL after initial install'>AD RMS &#8211; Changing Certification Pipeline to use SSL after initial install</a> <small>Just a quick post showing how to change the certification...</small></li>
<li><a href='http://consulting.risualblogs.com/blog/2012/01/13/diskpart-during-an-osd-task-sequence/' rel='bookmark' title='Permanent Link: Diskpart during an OSD Task Sequence'>Diskpart during an OSD Task Sequence</a> <small>Whilst at a customer recently I had a requirement to...</small></li>
<li><a href='http://consulting.risualblogs.com/blog/2011/09/26/net-announces-support-for-pure-ip-sip-trunks/' rel='bookmark' title='Permanent Link: NET announces support for Pure-IP SIP Trunks'>NET announces support for Pure-IP SIP Trunks</a> <small>Pure-IP seem to be going from strength to strength. Not...</small></li>
</ol>

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>Just wanted to create a quick post to share an issue i had recently while on a customer site installing an AD RMS High Availability solution.</p>
<p>The solution had two AD RMS servers using a HLB for redundancy, both servers were installed and joined to the same RMS cluster with no problems. However when the HLB was introduced we couldn&#8217;t protect content. Also we couldn’t reach the certification cluster URL (https://ADRMS<em>.yourdomain.com</em>/_wmcs/certification/certification.asmx) IE would just time out eventually.</p>
<p>To cut a long story short after checking all the usual things such as SCP, connectivity, Load Balancer config, DNS etc. it turns out that AD RMS doesn&#8217;t like cookie encryption on the HLB! Once we disabled cookie encryption clients were getting load balanced as expected and able to protect content <img class="wlEmoticon wlEmoticon-smile" style="border-top-style: none;border-bottom-style: none;border-right-style: none;border-left-style: none" alt="Smile" src="http://consulting.risualblogs.com/blog/files/2012/05/wlEmoticon-smile.png" /></p>
<p>(note: This particular HLB was F5 BIG-IP)</p>
<p>Ash</p>


<p>Related posts:<ol><li><a href='http://consulting.risualblogs.com/blog/2011/12/15/ad-rms-changing-certification-pipeline-to-use-ssl-after-initial-install/' rel='bookmark' title='Permanent Link: AD RMS &#8211; Changing Certification Pipeline to use SSL after initial install'>AD RMS &#8211; Changing Certification Pipeline to use SSL after initial install</a> <small>Just a quick post showing how to change the certification...</small></li>
<li><a href='http://consulting.risualblogs.com/blog/2012/01/13/diskpart-during-an-osd-task-sequence/' rel='bookmark' title='Permanent Link: Diskpart during an OSD Task Sequence'>Diskpart during an OSD Task Sequence</a> <small>Whilst at a customer recently I had a requirement to...</small></li>
<li><a href='http://consulting.risualblogs.com/blog/2011/09/26/net-announces-support-for-pure-ip-sip-trunks/' rel='bookmark' title='Permanent Link: NET announces support for Pure-IP SIP Trunks'>NET announces support for Pure-IP SIP Trunks</a> <small>Pure-IP seem to be going from strength to strength. Not...</small></li>
</ol></p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://consulting.risualblogs.com/blog/2012/05/04/ad-rms-with-hardware-load-balancer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FIM 2010 Update 2 &#8211; Error 25070.Error connecting to database FIMSynchronizationService</title>
		<link>http://consulting.risualblogs.com/blog/2012/03/01/fim-2010-update-2-error-25070-error-connecting-to-database-fimsynchronizationservice/</link>
		<comments>http://consulting.risualblogs.com/blog/2012/03/01/fim-2010-update-2-error-25070-error-connecting-to-database-fimsynchronizationservice/#comments</comments>
		<pubDate>Thu, 01 Mar 2012 22:02:30 +0000</pubDate>
		<dc:creator>Ashley Moore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[FIM 2010]]></category>

		<guid isPermaLink="false">http://2.485</guid>
		<description><![CDATA[I was recently on a customer site and had configured the Synchronization Service including creating Management Agents, projections, joins etc. I then realised i had not installed update 2 for FIM, so i proceeded to download and install the update through windows update only to be met with the following error: &#160; Error 25070.Error connecting [...]


Related posts:<ol><li><a href='http://support.risualblogs.com/blog/2012/02/28/a-server-side-seed-operation-has-failed-error-an-error-occurred-while-performing-the-seed-operation-which-may-indicate-a-problem-with-the-source-disk-error-an-error-occurred-while-attempting-to-a/' rel='bookmark' title='Permanent Link: A server-side seed operation has failed. Error: An error occurred while performing the seed operation, which may indicate a problem with the source disk. Error: An error occurred while attempting to access remote resources. Error: An error occurred while processing a request on server &#8216;SERVER&#8217;. Error: Database &#8216;catalog&#8217; was not active on source server'>A server-side seed operation has failed. Error: An error occurred while performing the seed operation, which may indicate a problem with the source disk. Error: An error occurred while attempting to access remote resources. Error: An error occurred while processing a request on server &#8216;SERVER&#8217;. Error: Database &#8216;catalog&#8217; was not active on source server</a> <small>While running Exchange 2010 SP1, We recently came across the...</small></li>
<li><a href='http://support.risualblogs.com/blog/2011/08/04/issue-installing-tmg-update-1-setup-cannot-read-the-registry-value-productid/' rel='bookmark' title='Permanent Link: Issue installing TMG update 1 &ldquo;Setup cannot read the Registry Value ProductID&rdquo;'>Issue installing TMG update 1 &ldquo;Setup cannot read the Registry Value ProductID&rdquo;</a> <small>We had an issue recent where we could install Software...</small></li>
<li><a href='http://consulting.risualblogs.com/blog/2011/11/14/exchange2010-management-console-error/' rel='bookmark' title='Permanent Link: Exchange2010 Management Console error'>Exchange2010 Management Console error</a> <small>“Connecting to remote server failed with the following error message:...</small></li>
</ol>

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>I was recently on a customer site and had configured the Synchronization Service including creating Management Agents, projections, joins etc. I then realised i had not installed update 2 for FIM, so i proceeded to download and install the update through windows update only to be met with the following error:</p>
<p>&#160;</p>
<p>Error 25070.Error connecting to database FIMSynchronizationService. Invalid class string</p>
<p>&#160;</p>
<p>Doh! Silly me, with the databases homed on a remote SQL server the SQL Native Client must be installed on the FIM server. I had forgotten to do this, after doing so the update completed without issue <img style="border-bottom-style: none;border-left-style: none;border-top-style: none;border-right-style: none" class="wlEmoticon wlEmoticon-smile" alt="Smile" src="http://consulting.risualblogs.com/blog/files/2012/03/wlEmoticon-smile.png" /></p>


<p>Related posts:<ol><li><a href='http://support.risualblogs.com/blog/2012/02/28/a-server-side-seed-operation-has-failed-error-an-error-occurred-while-performing-the-seed-operation-which-may-indicate-a-problem-with-the-source-disk-error-an-error-occurred-while-attempting-to-a/' rel='bookmark' title='Permanent Link: A server-side seed operation has failed. Error: An error occurred while performing the seed operation, which may indicate a problem with the source disk. Error: An error occurred while attempting to access remote resources. Error: An error occurred while processing a request on server &#8216;SERVER&#8217;. Error: Database &#8216;catalog&#8217; was not active on source server'>A server-side seed operation has failed. Error: An error occurred while performing the seed operation, which may indicate a problem with the source disk. Error: An error occurred while attempting to access remote resources. Error: An error occurred while processing a request on server &#8216;SERVER&#8217;. Error: Database &#8216;catalog&#8217; was not active on source server</a> <small>While running Exchange 2010 SP1, We recently came across the...</small></li>
<li><a href='http://support.risualblogs.com/blog/2011/08/04/issue-installing-tmg-update-1-setup-cannot-read-the-registry-value-productid/' rel='bookmark' title='Permanent Link: Issue installing TMG update 1 &ldquo;Setup cannot read the Registry Value ProductID&rdquo;'>Issue installing TMG update 1 &ldquo;Setup cannot read the Registry Value ProductID&rdquo;</a> <small>We had an issue recent where we could install Software...</small></li>
<li><a href='http://consulting.risualblogs.com/blog/2011/11/14/exchange2010-management-console-error/' rel='bookmark' title='Permanent Link: Exchange2010 Management Console error'>Exchange2010 Management Console error</a> <small>“Connecting to remote server failed with the following error message:...</small></li>
</ol></p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://consulting.risualblogs.com/blog/2012/03/01/fim-2010-update-2-error-25070-error-connecting-to-database-fimsynchronizationservice/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AD RMS &#8211; Changing Certification Pipeline to use SSL after initial install</title>
		<link>http://consulting.risualblogs.com/blog/2011/12/15/ad-rms-changing-certification-pipeline-to-use-ssl-after-initial-install/</link>
		<comments>http://consulting.risualblogs.com/blog/2011/12/15/ad-rms-changing-certification-pipeline-to-use-ssl-after-initial-install/#comments</comments>
		<pubDate>Thu, 15 Dec 2011 12:00:40 +0000</pubDate>
		<dc:creator>Ashley Moore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[AD RMS]]></category>

		<guid isPermaLink="false">http://2.412</guid>
		<description><![CDATA[Just a quick post showing how to change the certification pipeline to use SSL after initial install not choosing to secure the URL. This may be the case if you need to request a certificate after initial set up or are waiting on a third party certificate, or just change your mind! The steps to [...]


Related posts:<ol><li><a href='http://consulting.risualblogs.com/blog/2011/06/14/problem-deploying-lync-monitoring-server-reports/' rel='bookmark' title='Permanent Link: Problem deploying Lync Monitoring Server Reports'>Problem deploying Lync Monitoring Server Reports</a> <small>Whilst running the SSRS on the Archive/ Monitoring Server I...</small></li>
<li><a href='http://consulting.risualblogs.com/blog/2011/08/11/out-of-band-management-console-issues-sccm/' rel='bookmark' title='Permanent Link: Out of Band Management console issues &#8211; SCCM'>Out of Band Management console issues &#8211; SCCM</a> <small>Whilst recently implementing out of band management for a customer,...</small></li>
</ol>

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>Just a quick post showing how to change the certification pipeline to use SSL after initial install not choosing to secure the URL. This may be the case if you need to request a certificate after initial set up or are waiting on a third party certificate, or just change your mind! The steps to do this are outlined below:</p>
<p>1. Open IIS on the AD RMS server and edit the bindings, add a binding for HTTPS selecting the certificate to use making sure the name matches your cluster URL.</p>
<p>2. Remove the HTTP binding from the list and do an IIRESET.</p>
<p>3. Close and reopen the AD RMS console and ensure in the centre console both URL’s are using HTTPS.</p>
<p>4. If the SCP has already been published in Active Directory you will need to re-publish it so that clients discover the new HTTP’s certification pipeline.</p>
<p>Good Luck!</p>
<p>Ash</p>


<p>Related posts:<ol><li><a href='http://consulting.risualblogs.com/blog/2011/06/14/problem-deploying-lync-monitoring-server-reports/' rel='bookmark' title='Permanent Link: Problem deploying Lync Monitoring Server Reports'>Problem deploying Lync Monitoring Server Reports</a> <small>Whilst running the SSRS on the Archive/ Monitoring Server I...</small></li>
<li><a href='http://consulting.risualblogs.com/blog/2011/08/11/out-of-band-management-console-issues-sccm/' rel='bookmark' title='Permanent Link: Out of Band Management console issues &#8211; SCCM'>Out of Band Management console issues &#8211; SCCM</a> <small>Whilst recently implementing out of band management for a customer,...</small></li>
</ol></p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://consulting.risualblogs.com/blog/2011/12/15/ad-rms-changing-certification-pipeline-to-use-ssl-after-initial-install/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FIM Portal page not displaying</title>
		<link>http://consulting.risualblogs.com/blog/2011/11/01/fim-portal-page-not-displaying/</link>
		<comments>http://consulting.risualblogs.com/blog/2011/11/01/fim-portal-page-not-displaying/#comments</comments>
		<pubDate>Tue, 01 Nov 2011 21:13:53 +0000</pubDate>
		<dc:creator>Ashley Moore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://2.363</guid>
		<description><![CDATA[When deploying the FIM Portal the page is built on WSS 3.0. You may notice that after deploying the Portal you are just displayed by the default WSS 3.0 page when browsing locally or remotely. When you deploy the FIM Service and FIM Portal it actually installs two .wsp’s which style the SharePoint site in [...]


Related posts:<ol><li><a href='http://support.risualblogs.com/blog/2011/10/11/tmg-2010-sp2-released/' rel='bookmark' title='Permanent Link: TMG 2010 SP2 Released'>TMG 2010 SP2 Released</a> <small>Just to let you know TMG 2010 SP2&#160; has been...</small></li>
<li><a href='http://support.risualblogs.com/blog/2011/11/01/how-to-set-up-crm-2011-ifd-and-publishing-via-tmg-or-uag/' rel='bookmark' title='Permanent Link: How to Configure CRM 2011 for IFD and publish via TMG or UAG'>How to Configure CRM 2011 for IFD and publish via TMG or UAG</a> <small>Scenario We have a CRM server that we need to...</small></li>
</ol>

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>When deploying the FIM Portal the page is built on WSS 3.0. You may notice that after deploying the Portal you are just displayed by the default WSS 3.0 page when browsing locally or remotely.</p>
<p>When you deploy the FIM Service and FIM Portal it actually installs two .wsp’s which style the SharePoint site in accordance to the FIM Portal functionality. Sometimes after initial installation these features are not enabled by default. To enable them navigate to Central Administration &gt; Site Actions &gt; Site Settings &gt; Site Features and select Activate on both ILM2 Pages and FIM Password Reset Pages</p>
<p>You should then be able to navigate to the url locally and remotely and see the normal FIM Portal page</p>
<p>Hope this helps some headaches as there arent too many pointers as to why this happens</p>
<p>Thanks,</p>
<p>Ash</p>


<p>Related posts:<ol><li><a href='http://support.risualblogs.com/blog/2011/10/11/tmg-2010-sp2-released/' rel='bookmark' title='Permanent Link: TMG 2010 SP2 Released'>TMG 2010 SP2 Released</a> <small>Just to let you know TMG 2010 SP2&#160; has been...</small></li>
<li><a href='http://support.risualblogs.com/blog/2011/11/01/how-to-set-up-crm-2011-ifd-and-publishing-via-tmg-or-uag/' rel='bookmark' title='Permanent Link: How to Configure CRM 2011 for IFD and publish via TMG or UAG'>How to Configure CRM 2011 for IFD and publish via TMG or UAG</a> <small>Scenario We have a CRM server that we need to...</small></li>
</ol></p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://consulting.risualblogs.com/blog/2011/11/01/fim-portal-page-not-displaying/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HRESULT: 0x800f0818 Unable to add/modify Roles or Features through Server Manager or Powershell after installing updates</title>
		<link>http://support.risualblogs.com/blog/2011/08/11/hresult-0x800f0818-unable-to-addmodify-roles-or-features-through-server-manager-or-powershell-after-installing-updates/</link>
		<comments>http://support.risualblogs.com/blog/2011/08/11/hresult-0x800f0818-unable-to-addmodify-roles-or-features-through-server-manager-or-powershell-after-installing-updates/#comments</comments>
		<pubDate>Thu, 11 Aug 2011 14:13:38 +0000</pubDate>
		<dc:creator>Ashley Moore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Windows Server 2008]]></category>

		<guid isPermaLink="false">http://3.937</guid>
		<description><![CDATA[After installing numerous Windows Updates, usually when bringing a newly installed server up to date on patches, you may recieve the following error in server manager: Error: Unexpected error refreshing Server Manager: Exception from HRESULT:0x800F0818d This issue occurs when corrupt .mum or .cat files are present after the extraction and installation process of windows updates. To [...]


No related posts.

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>After installing numerous Windows Updates, usually when bringing a newly installed server up to date on patches, you may recieve the following error in server manager:</p>
<p>Error: Unexpected error refreshing Server Manager: Exception from HRESULT:0x800F0818d</p>
<p>This issue occurs when corrupt .mum or .cat files are present after the extraction and installation process of windows updates.</p>
<p><a href="http://support.risualblogs.com/blog/files/2011/08/unexpected-error-refreshing-server-manager.png"><img src="http://support.risualblogs.com/blog/files/2011/08/unexpected-error-refreshing-server-manager-300x145.png" alt="" width="300" height="145" class="alignnone size-medium wp-image-941" /></a></p>
<p>To reolve this we need to complete a few steps</p>
<p>1. Download and run the Microsoft Update Readiness Tool from http://support.microsoft.com/kb/947821 once it has run check the log in C:WindowsServicingPackagesCheckSUR.log</p>
<p>2. You should see errors resembling:<br />
 CBS MUM Corrupt 0&#215;00000000 servicingPackagesPackage_for_KB978601~31bf3856ad364e35~amd64~~6.0.1.0.mum  Expected file name Package_for_KB978601_server~31bf3856ad364e35~amd64~~6.0.1.0.mum does not match the actual file name </p>
<p>and further down</p>
<p>Unavailable repair files:<br />
servicingpackagesPackage_for_KB978601~31bf3856ad364e35~amd64~~6.0.1.0.mum </p>
<p>3. There may be more than one problematic update so make a note of all of them, you will then need to download these KB&#8217;s and unpack them using the following commands:</p>
<p>Expand -F:* UpdateKB978601.msu C:Directory</p>
<p>This then shows a cat file which also needs to be unpacked:</p>
<p>Expand -F:* UpdateKB978601.CAB C:DirectoryCAB</p>
<p>4. You will need to grab the two files, one extension .mum and one extension .cat, then rename them making sure they are exactly as was displayed in the CheckSUR.log file. You will then need to copy them into the C:WindowsServicingPackages directory overwriting the existing ones.</p>
<p>These steps should resolve the issues and you should be able to add/remove Roles and Features again <img src='http://risualblogs.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  </p>


<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://support.risualblogs.com/blog/2011/08/11/hresult-0x800f0818-unable-to-addmodify-roles-or-features-through-server-manager-or-powershell-after-installing-updates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Un-delegate AD Permissions</title>
		<link>http://support.risualblogs.com/blog/2011/05/20/un-delegate-ad-permissions/</link>
		<comments>http://support.risualblogs.com/blog/2011/05/20/un-delegate-ad-permissions/#comments</comments>
		<pubDate>Fri, 20 May 2011 14:09:33 +0000</pubDate>
		<dc:creator>Ashley Moore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Active Directory]]></category>

		<guid isPermaLink="false">http://3.813</guid>
		<description><![CDATA[Sometimes after delegating permissions to a user or group it may be required to revoke them (maybe the user has left or group belongs to a temporary team of contractors). To do this you cant go through the delegate control wizard and take back the permissions as you would expect so just thought i would [...]


No related posts.

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>Sometimes after delegating permissions to a user or group it may be required to revoke them (maybe the user has left or group belongs to a temporary team of contractors). To do this you cant go through the delegate control wizard and take back the permissions as you would expect so just thought i would put a quick post up showing how to</p>
<p>First of all open ADUC and select view and make sure Advanced Features is checked<br />
<a href="http://support.risualblogs.com/blog/files/2011/05/Untitled-picture.png"><img class="alignnone size-medium wp-image-814" src="http://support.risualblogs.com/blog/files/2011/05/Untitled-picture-300x161.png" alt="" width="300" height="161" /></a></p>
<p>Next right click the OU that you need to remove the delegated permissions from and select properties and then the security tab</p>
<p><a href="http://support.risualblogs.com/blog/files/2011/05/Untitled-picture2.png"><img class="alignnone size-medium wp-image-815" src="http://support.risualblogs.com/blog/files/2011/05/Untitled-picture2-271x300.png" alt="" width="271" height="300" /></a></p>
<p>Here you should be able to see the user/group that you originally delegated permission to. In order to revoke these delegated permissions simply remove them from the ACL</p>
<p>HTH</p>
<p>Ash</p>


<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://support.risualblogs.com/blog/2011/05/20/un-delegate-ad-permissions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Exchange 2010 &#8211; cant create new distribution group</title>
		<link>http://support.risualblogs.com/blog/2010/05/21/exchange-2010-cant-create-new-distribution-group/</link>
		<comments>http://support.risualblogs.com/blog/2010/05/21/exchange-2010-cant-create-new-distribution-group/#comments</comments>
		<pubDate>Fri, 21 May 2010 14:23:26 +0000</pubDate>
		<dc:creator>Ashley Moore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://3.369</guid>
		<description><![CDATA[When trying to create a new distribution group through EMC you may receive the following error message at the end of the wizard: &#160; Error: Couldn&#8217;t find object &#34;UserAccount&#34;. Please make sure that it was spelled correctly or specify a different object. Reason: The recipient UserAccount isn&#8217;t the expected type. Exchange Management Shell command attempted: [...]


No related posts.

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>When trying to create a new distribution group through EMC you may receive the following error message at the end of the wizard:</p>
<p><a href="http://support.risualblogs.com/blog/files/2010/05/image1.png"><img style="border-right-width: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px" title="image" border="0" alt="image" src="http://support.risualblogs.com/blog/files/2010/05/image_thumb1.png" width="330" height="287" /></a>&#160;</p>
<p>Error:    <br />Couldn&#8217;t find object &quot;<em>UserAccount</em>&quot;. Please make sure that it was spelled correctly or specify a different object. Reason: The recipient <em>UserAccount</em> isn&#8217;t the expected type. </p>
<p>Exchange Management Shell command attempted:    <br />new-DistributionGroup -Name &#8216;test&#8217; -Type &#8216;Distribution&#8217; –OrganizationalUnit ‘<em>OU</em>’ -SamAccountName &#8216;test&#8217; -Alias &#8216;test&#8217; </p>
<p>The reason for this is that when creating a Distribution Group it tries to add the mailbox of the user creating it as the manager of the Distribution Group and usually the Admin account that creates the Distribution Groups will not be Mailbox enabled. </p>
<p>To get around this you can use the New-DistributionGroup cmdlet with the ManagedBy Parameter:</p>
<p>new-DistributionGroup -Name<strong> <em>&#8216;test</em>&#8216;</strong> -Type<strong> &#8216;<em>Distribution&#8217;</em></strong> –OrganizationalUnit <strong><em>‘YourDomain/Distribution Groups’</em></strong> -SamAccountName<strong><em> &#8216;test&#8217;</em></strong> -Alias<em><strong> &#8216;test&#8217;</strong></em> –ManagedBy ‘<strong><em>MailboxEnabledAccount’</em></strong></p>


<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://support.risualblogs.com/blog/2010/05/21/exchange-2010-cant-create-new-distribution-group/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Who can you trust?</title>
		<link>http://support.risualblogs.com/blog/2010/04/16/who-can-you-trust/</link>
		<comments>http://support.risualblogs.com/blog/2010/04/16/who-can-you-trust/#comments</comments>
		<pubDate>Fri, 16 Apr 2010 10:47:23 +0000</pubDate>
		<dc:creator>Ashley Moore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[AD RMS]]></category>

		<guid isPermaLink="false">http://3.357</guid>
		<description><![CDATA[Any RMS protected content can only be consumed or created within the trust boundaries of the domain. It is sometimes desirable to be able to share protected content with other external parties (Partners etc) so what do you do then? Well there are a number of options available, of which the main three used are: [...]


No related posts.

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>Any RMS protected content can only be consumed or created within the trust boundaries of the domain. It is sometimes desirable to be able to share protected content with other external parties (Partners etc) so what do you do then? Well there are a number of options available, of which the main three used are:</p>
<p>TUD – or Trusted User Domain is primarily used when a company with an RMS infrastructure wants to share protected content with another organization with their own RMS infrastructure. In order to do this a traditional Active Directory trust must first be in place, we can then export the SLC public key of the RMS cluster from the domain wanting to consume content and import it on the RMS cluster in the domain wanting to share content. This of course can be replicated both ways so that both sides can open RMS protected content from the other.</p>
<p>TPD – or Trusted Publishing Domain is usually used in one of two scenarios, one where an AD RMS cluster is being decommissioned and replaced. An example might be where forests are being merged and one cluster is taking over the functions of the others. The other scenario might be when a cluster has to issue licenses for content protected by clusters in another forest (can be used for cross forest RMS protected content exchange) To implement this trust you must export the private key of the cluster you are wanting to consolidate and import it into the TPD section of the remaining AD RMS cluster, this is so use licenses can still be acquired for content protected by the decommissioned cluster.</p>
<p>AD FS support for AD RMS – This is an extremely good feature for collaboration with multiple forests where partners do not have their own AD RMS infrastructure or even don&#8217;t have directories based on AD. To implement this solution AD FS must be configured and a federation trust must be in place. You then in AD FS usually create a new claims aware application entry for AD RMS certification URL, you can then define which claims to accept (for AD RMS this is UPN then email) you then do the same for the licensing URL. You must also make sure to add the server role for AD RMS Identity Federation Support and enable federated identity support in the AD RMS console. There are some registry key changes that have to be made on the trusted domain machines (the side without AD RMS) so that the home realm discover works correctly but this can be done via GPO’s*. You will then be able to send and receive RMS protected content from this entity even though they do not have AD RMS implemented!</p>
<ul>
<li>*Registry Key – HKLM/Software/Microsoft/ </li>
<li>Create registry key: MSDRM </li>
<li>Under this create another registry key: Federation </li>
<li>Under this add a string value named: FederationHomeRealm </li>
<li>with a value of: urn:federation:<em>YourDomain</em>.com </li>
</ul>
<p>So as you can see there are many options for expanding your RMS protection outside the boundaries of your domain or forest. Hope you find this useful! <img src='http://risualblogs.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>


<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://support.risualblogs.com/blog/2010/04/16/who-can-you-trust/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

