Saturday, 25 June 2016

SCCM

(1)
To find all windows 7 machines in your environment you can use the following query.

select SMS_R_System.NetbiosName,
SMS_R_System.OperatingSystemNameandVersion from 
SMS_R_System where
SMS_R_System.OperatingSystemNameandVersion like "%Workstation 6.1%"
(2)
To find all windows 10 machines in your environment you can use the following query.

select SMS_R_System.NetbiosName,
SMS_R_System.OperatingSystemNameandVersion from 
SMS_R_System where
SMS_R_System.OperatingSystemNameandVersion like "%Workstation 10%"
(3)
To restart a remote computer Remotely

shutdown /m \\computername /s
(4)
Clients are unable to get updates from SCCM 2012,
getting error: "Job error (0x87d00692) received for assignment"
To resolve this issue check the assigned WSUS server, in my case a GPO was applied in which another WSUS was mentioned. after disabling that GPO on client machines, machines were able to get updates.

you can check the assigned WSUS by checking in the following registry key.

HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate

(5)
To check the status of Update deployment you should check the log file "UpdateDeployment " at location "C:\windows\CCM\Logs" on client.
(6)
To show list of installed updates with power shell command:
Get-HotFix | Sort-Object InstalledOn -Descending
7)
To install SCCM client on workgroup computers
ccmsetup.exe smssitecode=abc smsmp=mp.domain.com
To check the current assigned WSUS server to your client machine. go to the following location on client Machine. Start-->run-->gpedit.msc-->local computer policy-->computer configuration-->Administrative templates-->Windows Compunents-->Widows update. then look into "specify intranet Microsoft update service location" here you will see the server and port like "http://SCCM.domain.com:8530"

Wednesday, 22 June 2016

How to restore a deleted object in active directory 2008 R2 and Activie Directory 2016 and Exchange Server

If you have deleted any AD object unexpectedly and want to restore it. If you have already enabled the ADRecycleBin then you can do it with the following steps.

First let's check if your recycle bin is enabled or not.
you can check with the following command
Get-ADOptionalFeature -Identity 'Recycle Bin Feature'

The above command will show the complete detail of recycle bin.

Let's it was enabled then you can use the following command to first find the deleted object.
you can use the following to display the deleted object first.
Get-ADObject -Filter {displayName -eq "DisplayNameOfUser"} -IncludeDeletedObjects
or
Get-ADObject -Filter {samaccountname -eq "nawaz.nawaz"} -IncludeDeletedObjects

Now it should show the deleted object to you.
let's you have found the deleted object and now want to restore.

you can use the following command to restore that ID.

Get-ADObject -Filter {displayName -eq "DisplayNameOfUser"} -IncludeDeletedObjects | Restore-ADObject


Note: you may need to add the target path as well in AD 2016, so you may use the following command.

Get-ADObject -Filter {UserPrincipalName -eq "nawaz@domain.com"} -IncludeDeletedObjects | Restore-ADObject -TargetPath "OU=Users,OU=HR,OU=Managementname,DC=domain,DC=com"

Note: if this AD Object/ID have any mailbox then that will be automatically recovered with out any issue. just wait for few minutes.
P.S: Will be better if just copy/past the displayname of the user object to be restored. As it is case sensitive. and the result would not display if you typed lower character instead of upper character. 

Sunday, 31 January 2016

UNable to submit CSR and get SSL Certificate from internal CA on windows server 2008 R2

Today i faced an issue, i tried to get certificate against my CSR which i had generated from my Exchange servers 2013 mailbox/cas server.
Now my steps was as below.
first i logged in to mailbox/cas server and from here i generate a CSR and copied that CSR to my CA server. i opened the CA's console and
right click on CA name select All task-->submit new request and select the CSR file.
but i got the below error.

The Request contains no certificate template information. 0x80094801 (-2146875391) Denied by policy Module 0x80094801, the request does not contain a certificate template extension or the certificate template request attribute.

Now i tried few times but no luck. then i tried to submit the request with command prompt.
so i went to the location where my CSR file was placed (C:\SSL).


C:\SSL>Certreq -submit -attrib "certificateTemplate:webserver" certreq.req

and here i was able to submit request and got the required certificate.

 

Thursday, 31 December 2015

How to find WWN in Windows server 2012 and Windows Servers 2008

To find the WWN in windows server 2012 you have to first download "fcinfo_x86" from blow link.

https://www.microsoft.com/en-us/download/details.aspx?id=17530

Please note that on above link you will find three files.
one is for Itanium and one is for x64bit and the third one is for 32bit, which is "Fcinfo_x86" so depending on your system you have to download and install the correct one.
in my environment the "fcinfo_x86" was working the others tow was not working
after downloading and installing go to the following path and run this command

C:\Windows\SysWOW64>fcinfo /details

i got the required details

The following command is also used for finding WWN numbers.

Get-InitiatorPort | Select-Object -Property PortAddress | Format-Table -AutoSize

Tuesday, 15 September 2015

Setting homepage in google chrome through GPO in AD DS 2008

How to set homepage in google chrome through GPO in ADDS 2008

First you have to download ADMX templates from google.com, may be you find at bellow locations.

http://support.google.com/a/bin/answer.py?hl=en&answer=187945
http://dl.google.com/dl/edgedl/chrome/policy/policy_templates.zip

Then place the chrom.admx and en-us files in sysvol at below locations "\\domainname\sysvol\domainname\Policies\PolicyDefinitions".

Now when ever you try to edit any GPO you will see google settings at both computer configuration and users configurations just like as below.

 
 
Now that you have successful added the ADMX temple in your Sysvol, now you can do different settings in chrome.
 
Lets set home page in chrome.
open Group Policy Management Console and create new GPO or edit the old one.
just right click the GPO which you have created and select Edit.
GPMC would be opened go to the following locations and follow these steps.
 
for both users configurations and computer configurations settings are same.
to apply on computers, expend computer configurations-->policies-->administrative templets-->google-->google chrome-->home page
here double click configure the home page url, select Enabled and in homepage URL enter the URL like "Google.com" and click OK.
but it would still not work.
so you have to do some other settings like below.
expend computer configurations-->policies-->administrative templets-->google-->google chrome-->startup pages
here are two settings.
double click on "Action on startup" and select Enabled.
from Action on startup select "open a list of URLS" and click OK.
now double click on "URLs to open on startup" and Enabled it as well. click on Show in "URLs to open on startup"
a new small window will be opened here you have to assign the value for "URLs to open on startup" here enter the complete URL which you want as homepage
 
 
 
Now link it to any OU or Domain.
 
Then go to client machine and type
C:/>gpupdate /force
or
restart your machine.
 
open your google chrome and you should see homepage.
 
If you still have issue then you can get help from the following tools.
 
RSOP.MSC
Gpresult
GPupdate /force
Open chrome and type as URL as below.
chrome://policy

Wednesday, 12 August 2015

How to find serial number of a system in windows

How to find serial number of  a system in windows
Just copy and past the following in command prompt and you will get the serial number of a system

c:\>wmic bios get serialnumber

For more detail you can visit the following site.

https://msdn.microsoft.com/en-us/library/aa394531(VS.85).aspx 

Wednesday, 5 August 2015

Outlook 2013 crash, not starting

Today I faced an issue with my outlook 2013, In my windows 10 I installed office 2013 and it was working fine but after installing few other applications on my system outlook was unable to start.
then I started to find the reason and also I restart my outlook and even my system few times but no luck.
Then I went to event viewer and found the event ID 1000 in application logs.
I also tried in the mean time to check outlook in safe mode (start-->run and type outlook.exe /safe and hit enter)and found its ok, was able to start without any issue.

The complete error in application logs was some thing like bellow.

--Start--

Faulting application name: OUTLOOK.EXE, version: 15.0.4420.1017, time stamp: 0x506734e2
Faulting module name: KERNELBASE.dll, version: 10.0.10240.16384, time stamp: 0x559f3b2a
Exception code: 0xe0434352
Fault offset: 0x000b3e28
Faulting process id: 0x15f4
Faulting application start time: 0x01d0cf9a71ccad5a
Faulting application path: C:\Program Files (x86)\Microsoft Office\Office15\OUTLOOK.EXE
Faulting module path: C:\Windows\SYSTEM32\KERNELBASE.dll
Report Id: cce9f65a-3b8d-11e5-9bcc-acfdce30790a
Faulting package full name:
Faulting package-relative application ID:


----End--
Now I came to know that issue is with Add-in.
So I tried to disable (uncheck) one by one and check the issue
HOW
Start-->Option-->Add-ins-->here you will see all add-ins and below you will see Manage COM Add-ins-->click on Go-->here you will see COM Add-ins
Now you can uncheck any Add-ins
Now after disabling one of them and trying the outlook my issue was resolved.