<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Metcorp Consulting Tech Blog</title>
	<atom:link href="http://blogs.metcorpconsulting.com/tech/?feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://blogs.metcorpconsulting.com/tech</link>
	<description>Technical posts about IT</description>
	<lastBuildDate>Wed, 22 May 2013 19:17:45 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>How Domain Controllers are Located Across Trusts</title>
		<link>http://blogs.metcorpconsulting.com/tech/?p=1647</link>
		<comments>http://blogs.metcorpconsulting.com/tech/?p=1647#comments</comments>
		<pubDate>Wed, 22 May 2013 19:17:45 +0000</pubDate>
		<dc:creator>Sean Metcalf</dc:creator>
				<category><![CDATA[Deployment]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[Technical Reference]]></category>
		<category><![CDATA[Troubleshooting]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[DCLocator]]></category>

		<guid isPermaLink="false">http://blogs.metcorpconsulting.com/tech/?p=1647</guid>
		<description><![CDATA[The ASK PFE Blog has a great article on &#8220;How Domain Controllers are Located Across Trusts&#8220;. Hi AskPFEPlat readers. Tom Moser here. A question I get on a pretty frequent basis from my larger, multi-forest enterprise customers is: “Do I need to add subnets from Forest A to Forest B so that clients find the [...]]]></description>
				<content:encoded><![CDATA[<p>The <a href="http://blogs.technet.com/b/askpfeplat/">ASK PFE Blog</a> has a great article on &#8220;<a href="https://blogs.technet.com/b/askpfeplat/archive/2013/05/06/how-domain-controllers-are-located-across-trusts.aspx">How Domain Controllers are Located Across Trusts</a>&#8220;.</p>
<blockquote><p>Hi AskPFEPlat readers. Tom Moser here. A question I get on a pretty frequent basis from my larger, multi-forest enterprise customers is:</p>
<p>“Do I need to add subnets from Forest A to Forest B so that clients find the correct DC across the trust?”</p>
<p>And here’s how I try to answer that question, usually with a lot of words, a little white boarding, and a lot of pointing. I thought, “this needs pictures…” so here you go.</p>
<p>If you’re in a hurry to get back to /r/sysadmin, the short answer is no. If you want to know why, keep reading. Then maybe cross post this for me there.</p>
<p>*** Point of Clarification ***</p>
<p>This post is about the a scenario where the subnets in the two forests do not overlap (i.e., client’s IP address from forest A is not covered by any subnet in forest B). This would typically occur in resource forest scenarios with separate networks. For example: federating via trust with Microsoft online services or a trust between a corporate forest and a perimeter forest. Everything you’re about to read below assumes that the client IP from Forest A is not covered by any subnet in Forest B.</p>
<p>In cases where the two forests have conflicting subnets (for example, 10.1.1.0/24 means site “Detroit” in Forest A, but means site “Siberia” in Forest B), there are additional considerations. We will cover these in a later post.</p></blockquote>
<p><a href="https://blogs.technet.com/b/askpfeplat/archive/2013/05/06/how-domain-controllers-are-located-across-trusts.aspx?Redirected=true">Read the rest of the article</a></p>
<p>&nbsp;</p>
<p><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://blogs.metcorpconsulting.com/tech/?p=1647"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://blogs.metcorpconsulting.com/tech/?p=1647" data-text="How Domain Controllers are Located Across Trusts"></a><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://blogs.metcorpconsulting.com/tech/?p=1647"></a><a class="a2a_button_google_plus" href="http://www.addtoany.com/add_to/google_plus?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1647&amp;linkname=How%20Domain%20Controllers%20are%20Located%20Across%20Trusts" title="Google+" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/google_plus.png" width="16" height="16" alt="Google+"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1647&amp;linkname=How%20Domain%20Controllers%20are%20Located%20Across%20Trusts" title="Facebook" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1647&amp;linkname=How%20Domain%20Controllers%20are%20Located%20Across%20Trusts" title="Email" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:print()" title="Print" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/print.png" width="16" height="16" alt="Print"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1647&amp;title=How%20Domain%20Controllers%20are%20Located%20Across%20Trusts" id="wpa2a_2"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.metcorpconsulting.com/tech/?feed=rss2&#038;p=1647</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AD Trivia: Where does the domain SID come from?</title>
		<link>http://blogs.metcorpconsulting.com/tech/?p=1645</link>
		<comments>http://blogs.metcorpconsulting.com/tech/?p=1645#comments</comments>
		<pubDate>Wed, 15 May 2013 19:17:10 +0000</pubDate>
		<dc:creator>Sean Metcalf</dc:creator>
				<category><![CDATA[Favorite]]></category>
		<category><![CDATA[Microsoft Products]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[Technical Reference]]></category>
		<category><![CDATA[Troubleshooting]]></category>
		<category><![CDATA[ComputerSID]]></category>
		<category><![CDATA[DC SID]]></category>
		<category><![CDATA[DomainSID]]></category>
		<category><![CDATA[FirstDomainController]]></category>

		<guid isPermaLink="false">http://blogs.metcorpconsulting.com/tech/?p=1645</guid>
		<description><![CDATA[When promoting the first Domain Controller for a new domain, the domain SID is the same as the computer SID of the new DC. The following AD groups are considered &#8220;local&#8221; to the Domain Controllers: Administrators Backup Operators Print Operators Server Operators What&#8217;s interesting is that these groups are the local groups from the first [...]]]></description>
				<content:encoded><![CDATA[<p>When promoting the first Domain Controller for a new domain, the domain SID is the same as the computer SID of the new DC.</p>
<p>The following AD groups are considered &#8220;local&#8221; to the Domain Controllers:</p>
<ul>
<li>Administrators</li>
<li>Backup Operators</li>
<li>Print Operators</li>
<li>Server Operators</li>
</ul>
<p>What&#8217;s interesting is that these groups are the local groups from the first DC promoted for the new domain, so the SID matches.</p>
<p>Mark Russinovich states this scenario well in <a href="https://blogs.technet.com/b/markrussinovich/archive/2009/11/03/3291024.aspx?Redirected=true">his blog</a>:</p>
<blockquote><p>As I said earlier, there’s one exception to rule, and that’s DCs themselves. <strong>Every Domain has a unique <em>Domain SID</em> that’s the machine SID of the system that became the Domain’s first DC</strong>,<em> </em>and all machine SIDs for the Domain’s DCs match the Domain SID. So in some sense, that’s a case where machine SIDs do get referenced by other computers. That means that Domain member computers cannot have the same machine SID as that of the DCs and therefore Domain. However, like member computers, each DC also has a computer account in the Domain, and that’s the identity they have when they authenticate to remote systems.</p></blockquote>
<p>The really interesting scenario is one where Company A owns Company B &amp; Company C and while the IT shop keeps the domains for each domain separated, they build all the DCs from the same image (but don&#8217;t sysprep or change the SID meaning the first DC for each domain has the same machine SID and thus the same domain SID). Company A sells off Company B &amp; Company C. Later on Company B &amp; Company C merge and want to set up AD trusts between them. They can&#8217;t because the domains in both Company B &amp; Company C have the same SID and a trust can&#8217;t reference its own SID!</p>
<p>&nbsp;</p>
<p><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://blogs.metcorpconsulting.com/tech/?p=1645"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://blogs.metcorpconsulting.com/tech/?p=1645" data-text="AD Trivia: Where does the domain SID come from?"></a><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://blogs.metcorpconsulting.com/tech/?p=1645"></a><a class="a2a_button_google_plus" href="http://www.addtoany.com/add_to/google_plus?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1645&amp;linkname=AD%20Trivia%3A%20Where%20does%20the%20domain%20SID%20come%20from%3F" title="Google+" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/google_plus.png" width="16" height="16" alt="Google+"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1645&amp;linkname=AD%20Trivia%3A%20Where%20does%20the%20domain%20SID%20come%20from%3F" title="Facebook" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1645&amp;linkname=AD%20Trivia%3A%20Where%20does%20the%20domain%20SID%20come%20from%3F" title="Email" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:print()" title="Print" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/print.png" width="16" height="16" alt="Print"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1645&amp;title=AD%20Trivia%3A%20Where%20does%20the%20domain%20SID%20come%20from%3F" id="wpa2a_4"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.metcorpconsulting.com/tech/?feed=rss2&#038;p=1645</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PowerShell Code: Enhanced Expand Group Membership Script</title>
		<link>http://blogs.metcorpconsulting.com/tech/?p=1639</link>
		<comments>http://blogs.metcorpconsulting.com/tech/?p=1639#comments</comments>
		<pubDate>Wed, 08 May 2013 19:17:03 +0000</pubDate>
		<dc:creator>Sean Metcalf</dc:creator>
				<category><![CDATA[Powershell Code]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[ExpandGroupMembership]]></category>
		<category><![CDATA[PowerShellScript]]></category>

		<guid isPermaLink="false">http://blogs.metcorpconsulting.com/tech/?p=1639</guid>
		<description><![CDATA[I wrote an enhanced expand Group Membership script based off of the Microsoft AD cmdlet Get-ADGroupMember. I call it Display-ADGroupMember. Here&#8217;s the code: &#160; 1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859Param &#160; &#160; ( &#160; &#160; &#160; &#160; [alias(&#34;Group&#34;,&#34;GN&#34;)] &#160; &#160; &#160; &#160; [string]$GroupName, &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; [alias(&#34;Recursive&#34;,&#34;R&#34;)] &#160; &#160; &#160; &#160; [switch]$Recurse, &#160; &#160; &#160; [...]]]></description>
				<content:encoded><![CDATA[<p>I wrote an enhanced expand Group Membership script based off of the Microsoft AD cmdlet Get-ADGroupMember. I call it <a href="http://blogs.metcorpconsulting.com/tech/wp-content/uploads/2013/04/Display-ADGroupMember.txt">Display-ADGroupMember</a>.</p>
<p>Here&#8217;s the code:<br />
&nbsp;</p>
<div class="codecolorer-container text vibrant" style="overflow:auto;white-space:nowrap;border:1px solid #9F9F9F;width:435px;height:300px;"><table cellspacing="0" cellpadding="0"><tbody><tr><td style="padding:5px;text-align:center;color:#888888;background-color:#EEEEEE;border-right: 1px solid #9F9F9F;font: normal 12px/1.4em Monaco, Lucida Console, monospace;"><div>1<br />2<br />3<br />4<br />5<br />6<br />7<br />8<br />9<br />10<br />11<br />12<br />13<br />14<br />15<br />16<br />17<br />18<br />19<br />20<br />21<br />22<br />23<br />24<br />25<br />26<br />27<br />28<br />29<br />30<br />31<br />32<br />33<br />34<br />35<br />36<br />37<br />38<br />39<br />40<br />41<br />42<br />43<br />44<br />45<br />46<br />47<br />48<br />49<br />50<br />51<br />52<br />53<br />54<br />55<br />56<br />57<br />58<br />59<br /></div></td><td><div class="text codecolorer" style="padding:5px;font:normal 12px/1.4em Monaco, Lucida Console, monospace;white-space:nowrap">Param<br />
&nbsp; &nbsp; (<br />
&nbsp; &nbsp; &nbsp; &nbsp; [alias(&quot;Group&quot;,&quot;GN&quot;)]<br />
&nbsp; &nbsp; &nbsp; &nbsp; [string]$GroupName,<br />
&nbsp; &nbsp; &nbsp; &nbsp; <br />
&nbsp; &nbsp; &nbsp; &nbsp; [alias(&quot;Recursive&quot;,&quot;R&quot;)]<br />
&nbsp; &nbsp; &nbsp; &nbsp; [switch]$Recurse,<br />
&nbsp; &nbsp; &nbsp; &nbsp; <br />
&nbsp; &nbsp; &nbsp; &nbsp; [alias(&quot;ReportFile&quot;,&quot;RF&quot;,&quot;FileName&quot;,&quot;File&quot;)]<br />
&nbsp; &nbsp; &nbsp; &nbsp; [string]$Report,<br />
&nbsp; &nbsp; &nbsp; &nbsp; <br />
&nbsp; &nbsp; &nbsp; &nbsp; [alias(&quot;Display&quot;,&quot;DisplayMembers&quot;,&quot;Members&quot;,&quot;SM&quot;)]<br />
&nbsp; &nbsp; &nbsp; &nbsp; [switch]$ShowMembers = $True<br />
&nbsp; &nbsp; )<br />
&nbsp; &nbsp; <br />
Import-Module ActiveDirectory<br />
<br />
IF ($GroupMemberReport) { Clear-Variable GroupMemberReport }<br />
<br />
$GroupNameDN = (Get-ADGroup -Identity $GroupName).DistinguishedName<br />
Write-Verbose &quot;Enumerating membership for $GroupName ($GroupNameDN) `r &quot;<br />
<br />
IF ($Recurse -eq $True)<br />
&nbsp; &nbsp; { &nbsp;## OPEN IF ($Recurse -eq $True) <br />
&nbsp; &nbsp; &nbsp; &nbsp; $GroupNameMembers = Get-ADGroupMember -Identity $GroupNameDN -Recursive <br />
&nbsp; &nbsp; &nbsp; &nbsp; $GroupNameMembersDirect = Get-ADGroupMember -Identity $GroupNameDN <br />
&nbsp; &nbsp; &nbsp; &nbsp; [int]$GroupNameMembersCount = $GroupNameMembers.Count<br />
&nbsp; &nbsp; &nbsp; &nbsp; [int]$GroupNameMembersDirectCount = $GroupNameMembersDirect.Count<br />
&nbsp; &nbsp; &nbsp; &nbsp; Write-Output &quot;The group $GroupName has $GroupNameMembersDirectCount direct members and $GroupNameMembersCount total members (includes members of nested groups). `r &quot;<br />
&nbsp; &nbsp; } &nbsp;## CLOSE IF ($Recurse -eq $True) &nbsp;<br />
<br />
IF ($Recurse -eq $False)<br />
&nbsp; &nbsp; { &nbsp;## OPEN IF ($Recurse -eq $False)<br />
&nbsp; &nbsp; &nbsp; &nbsp; $GroupNameMembers = Get-ADGroupMember -Identity $GroupNameDN <br />
&nbsp; &nbsp; &nbsp; &nbsp; [int]$GroupNameMembersCount = $GroupNameMembers.Count<br />
&nbsp; &nbsp; &nbsp; &nbsp; Write-Output &quot;The group $GroupName has $GroupNameMembersCount direct members (not including nested group members) `r &quot;<br />
&nbsp; &nbsp; } &nbsp;## CLOSE IF ($Recurse -eq $False)<br />
<br />
$GroupNameMembers = $GroupNameMembers | sort-object | get-unique<br />
&nbsp; &nbsp; <br />
ForEach ($GroupNameMembersItem in $GroupNameMembers)<br />
&nbsp; &nbsp; { &nbsp;## OPEN ForEach ($GroupMembersItem in $GroupNameMembers)<br />
&nbsp; &nbsp; &nbsp; &nbsp; IF ($GroupNameMembersItem.objectClass -eq 'user') { [array]$GroupMembersItemUserList += $GroupNameMembersItem ; Write-Verbose &quot;Adding $GroupMembersItem to members list `r &quot; } &nbsp; &nbsp;<br />
&nbsp; &nbsp; } &nbsp;## CLOSE ForEach ($GroupMembersItem in $GroupNameMembers)<br />
<br />
ForEach ($GroupMembersItemUserListItem in $GroupMembersItemUserList)<br />
&nbsp; &nbsp; { &nbsp;## OPEN ForEach ($GroupMembersItemUserListItem in $GroupMembersItemUserList)<br />
&nbsp; &nbsp; &nbsp; &nbsp; [array]$GroupMemberReport += Get-ADUser $GroupMembersItemUserListItem -property DisplayName,SAMAccountName,LastLogonDate | Select DisplayName,SAMAccountName,LastLogonDate<br />
&nbsp; &nbsp; } &nbsp;## CLOSE ForEach ($GroupMembersItemUserListItem in $GroupMembersItemUserList)<br />
&nbsp; &nbsp; <br />
IF ($ShowMembers -eq $True)<br />
&nbsp; &nbsp; { &nbsp;## OPEN IF ($ShowMembers -eq $True)<br />
&nbsp; &nbsp; &nbsp; &nbsp; $GroupMemberReport<br />
&nbsp; &nbsp; } &nbsp;## CLOSE IF ($ShowMembers -eq $True)<br />
&nbsp; &nbsp; <br />
IF ($Report)<br />
&nbsp; &nbsp; { &nbsp;## OPEN IF ($Report)<br />
&nbsp; &nbsp; &nbsp; &nbsp; $GroupMemberReport | export-csv $Report -NoType<br />
&nbsp; &nbsp; } &nbsp;## CLOSE IF ($Report)</div></td></tr></tbody></table></div>
<p><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://blogs.metcorpconsulting.com/tech/?p=1639"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://blogs.metcorpconsulting.com/tech/?p=1639" data-text="PowerShell Code: Enhanced Expand Group Membership Script"></a><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://blogs.metcorpconsulting.com/tech/?p=1639"></a><a class="a2a_button_google_plus" href="http://www.addtoany.com/add_to/google_plus?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1639&amp;linkname=PowerShell%20Code%3A%20Enhanced%20Expand%20Group%20Membership%20Script" title="Google+" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/google_plus.png" width="16" height="16" alt="Google+"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1639&amp;linkname=PowerShell%20Code%3A%20Enhanced%20Expand%20Group%20Membership%20Script" title="Facebook" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1639&amp;linkname=PowerShell%20Code%3A%20Enhanced%20Expand%20Group%20Membership%20Script" title="Email" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:print()" title="Print" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/print.png" width="16" height="16" alt="Print"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1639&amp;title=PowerShell%20Code%3A%20Enhanced%20Expand%20Group%20Membership%20Script" id="wpa2a_6"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.metcorpconsulting.com/tech/?feed=rss2&#038;p=1639</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PowerShell and Ambiguous Name Resolution (ANR) Search in Active Directory</title>
		<link>http://blogs.metcorpconsulting.com/tech/?p=1626</link>
		<comments>http://blogs.metcorpconsulting.com/tech/?p=1626#comments</comments>
		<pubDate>Wed, 01 May 2013 19:17:41 +0000</pubDate>
		<dc:creator>Sean Metcalf</dc:creator>
				<category><![CDATA[Favorite]]></category>
		<category><![CDATA[Microsoft Products]]></category>
		<category><![CDATA[Powershell Code Snippet]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[ANR]]></category>
		<category><![CDATA[Powershell]]></category>
		<category><![CDATA[PowerShellAD]]></category>

		<guid isPermaLink="false">http://blogs.metcorpconsulting.com/tech/?p=1626</guid>
		<description><![CDATA[I was recently asked how to find a user when you have data that may be the SamAccountName or in another attribute. My first thought was leveraging Ambiguous Name Resolution (ANR) Search in Active Directory. ANR enables you to find a user when you have some information about a user, but don&#8217;t know exactly to [...]]]></description>
				<content:encoded><![CDATA[<p>I was recently asked how to find a user when you have data that may be the SamAccountName or in another attribute. My first thought was leveraging Ambiguous Name Resolution (ANR) Search in Active Directory.</p>
<p>ANR enables you to find a user when you have some information about a user, but don&#8217;t know exactly to which attribute that data corresponds. For example, if you know the user has &#8220;Thor&#8221; somewhere, but don&#8217;t know exactly what the SAMAccountName is (or DN, SID, name, etc).  Submitting an ANR search will query the AD attributes flagged for ANR (attributes must be indexed) and replies with the results (may be more than one user found).</p>
<p>Windows Server 2008 checks the following attributes for ANR queries:</p>
<ul>
<li>displayName</li>
<li>givenName</li>
<li>legacyExchangeDN</li>
<li>msDS-AdditionalSamAccountName</li>
<li>msDS-PhoneticCompanyName</li>
<li>msDS-PhoneticDepartment</li>
<li>msDS-PhoneticDisplayName</li>
<li>msDS-PhoneticFirstName</li>
<li>msDS-PhoneticLastName</li>
<li>physicalDeliveryOfficeName</li>
<li>proxyAddresses</li>
<li>Name</li>
<li>sAMAccountName</li>
<li>sn</li>
</ul>
<p>Since ANR is an LDAP-specific feature with AD, you have to use a LDAP filter to get it.</p>
<p>Using the Microsoft AD cmdlets included in Windows Server 2008 R2, Get-ADObject performs an ANR search:</p>
<p>For Example:<br />
Get-ADObject -LDAPFilter { (&amp;(ObjectClass=User)(ANR=Thor) }</p>
<p>The <a href="http://www.quest.com/powershell/activeroles-server.aspx">Quest AD cmdlets</a> support ANR natively (of course they do!).</p>
<p><span style="text-decoration: underline;"><strong>Reference Articles:</strong></span></p>
<ul>
<li><a href="http://msdn.microsoft.com/en-us/library/cc223243.aspx">MSDN: Ambiguous Name Resolution (ANR)</a></li>
<li><a href="http://www.marc-lognoul.me/itblog-en/post/2013/02/01/Windows-The-Underestimated-Ambiguous-Name-Resolution-%28ANR%29-Search-in-Active-Directory.aspx">Windows: The Underestimated Ambiguous Name Resolution (ANR) Search in Active Directory</a></li>
</ul>
<p><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://blogs.metcorpconsulting.com/tech/?p=1626"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://blogs.metcorpconsulting.com/tech/?p=1626" data-text="PowerShell and Ambiguous Name Resolution (ANR) Search in Active Directory"></a><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://blogs.metcorpconsulting.com/tech/?p=1626"></a><a class="a2a_button_google_plus" href="http://www.addtoany.com/add_to/google_plus?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1626&amp;linkname=PowerShell%20and%20Ambiguous%20Name%20Resolution%20%28ANR%29%20Search%20in%20Active%20Directory" title="Google+" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/google_plus.png" width="16" height="16" alt="Google+"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1626&amp;linkname=PowerShell%20and%20Ambiguous%20Name%20Resolution%20%28ANR%29%20Search%20in%20Active%20Directory" title="Facebook" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1626&amp;linkname=PowerShell%20and%20Ambiguous%20Name%20Resolution%20%28ANR%29%20Search%20in%20Active%20Directory" title="Email" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:print()" title="Print" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/print.png" width="16" height="16" alt="Print"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1626&amp;title=PowerShell%20and%20Ambiguous%20Name%20Resolution%20%28ANR%29%20Search%20in%20Active%20Directory" id="wpa2a_8"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.metcorpconsulting.com/tech/?feed=rss2&#038;p=1626</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hyper-V How to install integration services when the virtual machine is not running</title>
		<link>http://blogs.metcorpconsulting.com/tech/?p=1619</link>
		<comments>http://blogs.metcorpconsulting.com/tech/?p=1619#comments</comments>
		<pubDate>Wed, 24 Apr 2013 20:00:04 +0000</pubDate>
		<dc:creator>Sean Metcalf</dc:creator>
				<category><![CDATA[Microsoft Products]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[Hyper-V]]></category>
		<category><![CDATA[VM Updates]]></category>

		<guid isPermaLink="false">http://blogs.metcorpconsulting.com/tech/?p=1619</guid>
		<description><![CDATA[From Microsoft&#8217;s Virtualization Blog, How to install integration services when the virtual machine is not running: We’ve been talking to a lot of people about deploying integration services (integration components) lately.  As it turns out, they’re pretty easy to patch offline with existing Hyper-V tools. First, why would you update integration services on a not-running [...]]]></description>
				<content:encoded><![CDATA[<p>From Microsoft&#8217;s Virtualization Blog, <a href="https://blogs.technet.com/b/virtualization/archive/2013/04/19/how-to-install-integration-services-when-the-virtual-machine-is-not-running.aspx?utm_source=feedly&amp;Redirected=true ">How to install integration services when the virtual machine is not running</a>:</p>
<blockquote><p>We’ve been talking to a lot of people about deploying integration services (integration components) lately.  As it turns out, they’re pretty easy to patch offline with existing Hyper-V tools.</p>
<p>First, why would you update integration services on a not-running (offline) VM?</p>
<p>Offline VM servicing is valuable for VM templates places that create new VMs frequently since it allows you to keep VM templates up-to-date.  While this post targets exclusively integration service updates, the same update approach applies to many updates as well as any configurations specific to the environment.  Keeping the VM images fully up to date and configured before they are deployed saves significant setup time and support every time a new VM is created.</p>
<p>Here is a detailed write-up about deploying and updating integration services on an offline VM – both VHD/VHDX – using out of box PowerShell tools and a cab (cabinet) file that comes bundled with Server 2008 or later Hyper-V hosts.</p></blockquote>
<p><a href="https://blogs.technet.com/b/virtualization/archive/2013/04/19/how-to-install-integration-services-when-the-virtual-machine-is-not-running.aspx?utm_source=feedly&amp;Redirected=true">Read More</a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://blogs.metcorpconsulting.com/tech/?p=1619"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://blogs.metcorpconsulting.com/tech/?p=1619" data-text="Hyper-V How to install integration services when the virtual machine is not running"></a><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://blogs.metcorpconsulting.com/tech/?p=1619"></a><a class="a2a_button_google_plus" href="http://www.addtoany.com/add_to/google_plus?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1619&amp;linkname=Hyper-V%20How%20to%20install%20integration%20services%20when%20the%20virtual%20machine%20is%20not%20running" title="Google+" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/google_plus.png" width="16" height="16" alt="Google+"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1619&amp;linkname=Hyper-V%20How%20to%20install%20integration%20services%20when%20the%20virtual%20machine%20is%20not%20running" title="Facebook" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1619&amp;linkname=Hyper-V%20How%20to%20install%20integration%20services%20when%20the%20virtual%20machine%20is%20not%20running" title="Email" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:print()" title="Print" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/print.png" width="16" height="16" alt="Print"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1619&amp;title=Hyper-V%20How%20to%20install%20integration%20services%20when%20the%20virtual%20machine%20is%20not%20running" id="wpa2a_10"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.metcorpconsulting.com/tech/?feed=rss2&#038;p=1619</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Using PowerShell to search Group Policy XML Reports</title>
		<link>http://blogs.metcorpconsulting.com/tech/?p=1622</link>
		<comments>http://blogs.metcorpconsulting.com/tech/?p=1622#comments</comments>
		<pubDate>Wed, 17 Apr 2013 20:00:25 +0000</pubDate>
		<dc:creator>Sean Metcalf</dc:creator>
				<category><![CDATA[Microsoft Products]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[GPOs]]></category>
		<category><![CDATA[Powershell]]></category>

		<guid isPermaLink="false">http://blogs.metcorpconsulting.com/tech/?p=1622</guid>
		<description><![CDATA[I recently found this blog article called Using PowerShell to search Group Policy XML Reports which covers a method for extracting settings from a GPO XML report. Fascinating stuff! Read all about it here. &#160;]]></description>
				<content:encoded><![CDATA[<p>I recently found this blog article called <a href="http://outputredirection.blogspot.com/2010/01/using-powershell-to-search-for-group.html">Using PowerShell to search Group Policy XML Reports</a> which covers a method for extracting settings from a GPO XML report. Fascinating stuff!</p>
<p>Read all about it <a href="http://outputredirection.blogspot.com/2010/01/using-powershell-to-search-for-group.html">here</a>.</p>
<p>&nbsp;</p>
<p><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://blogs.metcorpconsulting.com/tech/?p=1622"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://blogs.metcorpconsulting.com/tech/?p=1622" data-text="Using PowerShell to search Group Policy XML Reports"></a><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://blogs.metcorpconsulting.com/tech/?p=1622"></a><a class="a2a_button_google_plus" href="http://www.addtoany.com/add_to/google_plus?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1622&amp;linkname=Using%20PowerShell%20to%20search%20Group%20Policy%20XML%20Reports" title="Google+" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/google_plus.png" width="16" height="16" alt="Google+"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1622&amp;linkname=Using%20PowerShell%20to%20search%20Group%20Policy%20XML%20Reports" title="Facebook" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1622&amp;linkname=Using%20PowerShell%20to%20search%20Group%20Policy%20XML%20Reports" title="Email" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:print()" title="Print" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/print.png" width="16" height="16" alt="Print"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1622&amp;title=Using%20PowerShell%20to%20search%20Group%20Policy%20XML%20Reports" id="wpa2a_12"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.metcorpconsulting.com/tech/?feed=rss2&#038;p=1622</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Installing Windows Server 2012</title>
		<link>http://blogs.metcorpconsulting.com/tech/?p=1491</link>
		<comments>http://blogs.metcorpconsulting.com/tech/?p=1491#comments</comments>
		<pubDate>Wed, 10 Apr 2013 19:17:15 +0000</pubDate>
		<dc:creator>Sean Metcalf</dc:creator>
				<category><![CDATA[Deployment]]></category>
		<category><![CDATA[Microsoft Products]]></category>
		<category><![CDATA[Powershell Code Snippet]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[Server2012]]></category>
		<category><![CDATA[WindowsServer2012]]></category>

		<guid isPermaLink="false">http://blogs.metcorpconsulting.com/tech/?p=1491</guid>
		<description><![CDATA[After installing a Windows Server 2012 server and signing in for the first time, you are prompted to change the default administrator password as part of the logon process. If you find that you are greeted with a command prompt after logging on and wish to have a full GUI, run the following commands to [...]]]></description>
				<content:encoded><![CDATA[<p>After installing a Windows Server 2012 server and signing in for the first time, you are prompted to change the default administrator password as part of the logon process.</p>
<p>If you find that you are greeted with a command prompt after logging on and wish to have a full GUI, run the following commands to switch from &#8220;Server Core&#8221; mode to full GUI.</p>
<p><em>Powershell</em><br />
<em>Install-Module ServerManager</em><br />
<em>Install-WindowsFeature Server-GUI-Shell -Restart</em></p>
<p><span style="text-decoration: underline;">References:</span></p>
<ul>
<li><a href="http://technet.microsoft.com/en-us/library/hh831620.aspx">Install &amp; Deploy Windows Server 2012</a></li>
<li><a href="http://technet.microsoft.com/en-us/library/jj134246.aspx">Installing Windows Server 2012</a></li>
</ul>
<p><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://blogs.metcorpconsulting.com/tech/?p=1491"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://blogs.metcorpconsulting.com/tech/?p=1491" data-text="Installing Windows Server 2012"></a><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://blogs.metcorpconsulting.com/tech/?p=1491"></a><a class="a2a_button_google_plus" href="http://www.addtoany.com/add_to/google_plus?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1491&amp;linkname=Installing%20Windows%20Server%202012" title="Google+" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/google_plus.png" width="16" height="16" alt="Google+"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1491&amp;linkname=Installing%20Windows%20Server%202012" title="Facebook" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1491&amp;linkname=Installing%20Windows%20Server%202012" title="Email" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:print()" title="Print" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/print.png" width="16" height="16" alt="Print"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1491&amp;title=Installing%20Windows%20Server%202012" id="wpa2a_14"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.metcorpconsulting.com/tech/?feed=rss2&#038;p=1491</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>More information on RODCs and why they are special</title>
		<link>http://blogs.metcorpconsulting.com/tech/?p=1611</link>
		<comments>http://blogs.metcorpconsulting.com/tech/?p=1611#comments</comments>
		<pubDate>Wed, 03 Apr 2013 19:17:12 +0000</pubDate>
		<dc:creator>Sean Metcalf</dc:creator>
				<category><![CDATA[Deployment]]></category>
		<category><![CDATA[Microsoft Products]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Domain Controller]]></category>
		<category><![CDATA[RODC]]></category>
		<category><![CDATA[Windows Server 2008]]></category>

		<guid isPermaLink="false">http://blogs.metcorpconsulting.com/tech/?p=1611</guid>
		<description><![CDATA[The ASK PFE Platform blog provides more insight into Read-Only Domain Controllers (RODCs) and why they are so special. Read the blog post: MailBag: RODCs – krbtgt_#####, Orphans, and Load Balancing RODC Connection Objects &#160;]]></description>
				<content:encoded><![CDATA[<p>The ASK PFE Platform blog provides more insight into Read-Only Domain Controllers (RODCs) and why they are so special.</p>
<p>Read the blog post: <a href="https://blogs.technet.com/b/askpfeplat/archive/2013/03/15/mailbag-rodcs-krbtgt-orphans-and-load-balancing-rodc-connection-objects.aspx?Redirected=true ">MailBag: RODCs – krbtgt_#####, Orphans, and Load Balancing RODC Connection Objects</a></p>
<p>&nbsp;</p>
<p><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://blogs.metcorpconsulting.com/tech/?p=1611"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://blogs.metcorpconsulting.com/tech/?p=1611" data-text="More information on RODCs and why they are special"></a><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://blogs.metcorpconsulting.com/tech/?p=1611"></a><a class="a2a_button_google_plus" href="http://www.addtoany.com/add_to/google_plus?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1611&amp;linkname=More%20information%20on%20RODCs%20and%20why%20they%20are%20special" title="Google+" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/google_plus.png" width="16" height="16" alt="Google+"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1611&amp;linkname=More%20information%20on%20RODCs%20and%20why%20they%20are%20special" title="Facebook" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1611&amp;linkname=More%20information%20on%20RODCs%20and%20why%20they%20are%20special" title="Email" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:print()" title="Print" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/print.png" width="16" height="16" alt="Print"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1611&amp;title=More%20information%20on%20RODCs%20and%20why%20they%20are%20special" id="wpa2a_16"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.metcorpconsulting.com/tech/?feed=rss2&#038;p=1611</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Capacity Planning for Active Directory Domain Services</title>
		<link>http://blogs.metcorpconsulting.com/tech/?p=1603</link>
		<comments>http://blogs.metcorpconsulting.com/tech/?p=1603#comments</comments>
		<pubDate>Wed, 27 Mar 2013 19:17:15 +0000</pubDate>
		<dc:creator>Sean Metcalf</dc:creator>
				<category><![CDATA[Career]]></category>
		<category><![CDATA[Deployment]]></category>
		<category><![CDATA[Favorite]]></category>
		<category><![CDATA[Microsoft Products]]></category>
		<category><![CDATA[Technical Reference]]></category>

		<guid isPermaLink="false">http://blogs.metcorpconsulting.com/tech/?p=1603</guid>
		<description><![CDATA[There is a new article on TechNet called &#8220;Capacity Planning for Active Directory Domain Services&#8221; which outlines key items for planning Active Directory Domain Controller capacity (Windows Server 2008 and newer). Here are the highlights: Plan for the peak busy period of the day. It is recommended to look at this in either 30 minute [...]]]></description>
				<content:encoded><![CDATA[<p>There is a new article on TechNet called &#8220;<a href="https://social.technet.microsoft.com/wiki/contents/articles/14355.capacity-planning-for-active-directory-domain-services.aspx">Capacity Planning for Active Directory Domain Services</a>&#8221; which outlines key items for planning Active Directory Domain Controller capacity (Windows Server 2008 and newer).</p>
<p>Here are the highlights:</p>
<ul>
<li>Plan for the peak busy period of the day. It is recommended to look at this in either 30 minute or hour intervals. Anything greater may hide the actual peaks and anything less may be distorted by “transient spikes.”</li>
<li>CPU Sizing:  1 modern physical core per 1,000 users (authentication).</li>
<li>RAM Sizing:  2-4 GB for OS + size of NTDS.dit + size of SYSVOL.</li>
</ul>
<p>Also, don&#8217;t forget to perform core calculations to ensure appropriate capacity for Exchange (8:1 ratio for Exchange cores to GC cores) and other applications.</p>
<p>I typically recommend that at least 1 DC is on physical hardware in each domain &#8211; preferably 1 physical DC per domain in each datacenter.  DCs should be spread across virtual hosts as much as possible to provide redundancy and ensure there&#8217;s DC capacity for virtual clients and application servers.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://blogs.metcorpconsulting.com/tech/?p=1603"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://blogs.metcorpconsulting.com/tech/?p=1603" data-text="Capacity Planning for Active Directory Domain Services"></a><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://blogs.metcorpconsulting.com/tech/?p=1603"></a><a class="a2a_button_google_plus" href="http://www.addtoany.com/add_to/google_plus?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1603&amp;linkname=Capacity%20Planning%20for%20Active%20Directory%20Domain%20Services" title="Google+" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/google_plus.png" width="16" height="16" alt="Google+"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1603&amp;linkname=Capacity%20Planning%20for%20Active%20Directory%20Domain%20Services" title="Facebook" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1603&amp;linkname=Capacity%20Planning%20for%20Active%20Directory%20Domain%20Services" title="Email" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:print()" title="Print" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/print.png" width="16" height="16" alt="Print"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1603&amp;title=Capacity%20Planning%20for%20Active%20Directory%20Domain%20Services" id="wpa2a_18"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.metcorpconsulting.com/tech/?feed=rss2&#038;p=1603</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PowerShell v3 Active Directory Commandlets</title>
		<link>http://blogs.metcorpconsulting.com/tech/?p=1535</link>
		<comments>http://blogs.metcorpconsulting.com/tech/?p=1535#comments</comments>
		<pubDate>Mon, 18 Mar 2013 19:17:02 +0000</pubDate>
		<dc:creator>Sean Metcalf</dc:creator>
				<category><![CDATA[Microsoft Products]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[ADPowershellCommandlets]]></category>
		<category><![CDATA[ADPowershellv3]]></category>
		<category><![CDATA[Powershell]]></category>
		<category><![CDATA[Powershellv3]]></category>

		<guid isPermaLink="false">http://blogs.metcorpconsulting.com/tech/?p=1535</guid>
		<description><![CDATA[Powershell version 2.0 introduced Active Directory commandlets (76 total) a tremendous improvement over the manual ADSI coding necessary with Powershell version 1.0. Powershell version 3.0 has 135 commandlets, adding 59 new commandlets covering AD Central Access Policy, AD Replication, AD Claims, and more. Here&#8217;s the list of all Active Directory commandlets in Powershell v3: Add-ADCentralAccessPolicyMember  [...]]]></description>
				<content:encoded><![CDATA[<p>Powershell version 2.0 introduced Active Directory commandlets (76 total) a tremendous improvement over the manual ADSI coding necessary with Powershell version 1.0.</p>
<p>Powershell version 3.0 has 135 commandlets, adding 59 new commandlets covering AD Central Access Policy, AD Replication, AD Claims, and more.</p>
<p>Here&#8217;s the list of all Active Directory commandlets in Powershell v3:</p>
<ul>
<li><a href="http://technet.microsoft.com/en-us/library/hh852262.aspx"><strong>Add-ADCentralAccessPolicyMember </strong></a></li>
<li>Add-ADComputerServiceAccount</li>
<li>Add-ADDomainControllerPasswordReplicationPolicy</li>
<li>Add-ADFineGrainedPasswordPolicySubject</li>
<li>Add-ADGroupMember</li>
<li>Add-ADPrincipalGroupMembership</li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852327.aspx"><strong>Add-ADResourcePropertyListMember</strong></a></li>
<li>Clear-ADAccountExpiration</li>
<li><strong><a href="http://technet.microsoft.com/en-us/library/hh852204.aspx">Clear-ADClaimTransformLink </a> </strong></li>
<li>Disable-ADAccount</li>
<li>Disable-ADOptionalFeature</li>
<li>Enable-ADAccount</li>
<li>Enable-ADOptionalFeature</li>
<li>Get-ADAccountAuthorizationGroup</li>
<li>Get-ADAccountResultantPasswordReplicationPolicy</li>
<li><strong><a href="http://technet.microsoft.com/en-us/library/hh852317.aspx">Get-ADCentralAccessPolicy  </a>                                   </strong></li>
<li><strong><a href="http://technet.microsoft.com/en-us/library/hh852240.aspx">Get-ADCentralAccessRule</a>                                       </strong></li>
<li><strong><a href="http://technet.microsoft.com/en-us/library/hh852207.aspx">Get-ADClaimTransformPolicy</a>                                    </strong></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852202.aspx"><strong>Get-ADClaimType </strong></a></li>
<li>Get-ADComputer</li>
<li>Get-ADComputerServiceAccount</li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852291.aspx"><strong>Get-ADDCCloningExcludedApplicationList</strong></a></li>
<li>Get-ADDefaultDomainPasswordPolicy</li>
<li>Get-ADDomain</li>
<li>Get-ADDomainController</li>
<li>Get-ADDomainControllerPasswordReplicationPolicy</li>
<li>Get-ADDomainControllerPasswordReplicationPolicyUsage</li>
<li>Get-ADFineGrainedPasswordPolicy</li>
<li>Get-ADFineGrainedPasswordPolicySubject</li>
<li>Get-ADForest</li>
<li>Get-ADGroup</li>
<li>Get-ADGroupMember</li>
<li>Get-ADObject</li>
<li>Get-ADOptionalFeature</li>
<li>Get-ADOrganizationalUnit</li>
<li>Get-ADPrincipalGroupMembership</li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852209.aspx"><strong>Get-ADReplicationAttributeMetadata</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852242.aspx"><strong>Get-ADReplicationConnection</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852265.aspx"><strong>Get-ADReplicationFailure</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852279.aspx"><strong>Get-ADReplicationPartnerMetadata</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852241.aspx"><strong>Get-ADReplicationQueueOperation</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852269.aspx"><strong>Get-ADReplicationSite</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852192.aspx"><strong>Get-ADReplicationSiteLink</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852304.aspx"><strong>Get-ADReplicationSiteLinkBridge</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852246.aspx"><strong>Get-ADReplicationSubnet</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852321.aspx"><strong>Get-ADReplicationUpToDatenessVectorTable</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852316.aspx"><strong>Get-ADResourceProperty</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852250.aspx"><strong>Get-ADResourcePropertyList</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852245.aspx"><strong>Get-ADResourcePropertyValueType</strong></a></li>
<li>Get-ADRootDSE</li>
<li>Get-ADServiceAccount</li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852315.aspx"><strong>Get-ADTrust</strong></a></li>
<li>Get-ADUser</li>
<li>Get-ADUserResultantPasswordPolicy</li>
<li>Install-ADServiceAccount</li>
<li>Move-ADDirectoryServer</li>
<li>Move-ADDirectoryServerOperationMasterRole</li>
<li>Move-ADObject</li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852289.aspx"><strong>New-ADCentralAccessPolicy</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852214.aspx"><strong>New-ADCentralAccessRule</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852301.aspx"><strong>New-ADClaimTransformPolicy</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852216.aspx"><strong>New-ADClaimType</strong></a></li>
<li>New-ADComputer</li>
<li><a href="http://technet.microsoft.com/en-us/library/jj158947.aspx"><strong>New-ADDCCloneConfigFile</strong></a></li>
<li>New-ADFineGrainedPasswordPolicy</li>
<li>New-ADGroup</li>
<li>New-ADObject</li>
<li>New-ADOrganizationalUnit</li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852286.aspx"><strong>New-ADReplicationSite</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852320.aspx"><strong>New-ADReplicationSiteLink</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852295.aspx"><strong>New-ADReplicationSiteLinkBridge</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852206.aspx"><strong>New-ADReplicationSubnet</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852210.aspx"><strong>New-ADResourceProperty</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852263.aspx"><strong>New-ADResourcePropertyList</strong></a></li>
<li>New-ADServiceAccount</li>
<li>New-ADUser</li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852314.aspx"><strong>Remove-ADCentralAccessPolicy</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852251.aspx"><strong>Remove-ADCentralAccessPolicyMember</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852275.aspx"><strong>Remove-ADCentralAccessRule</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852322.aspx"><strong>Remove-ADClaimTransformPolicy</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852324.aspx"><strong>Remove-ADClaimType</strong></a></li>
<li>Remove-ADComputer</li>
<li>Remove-ADComputerServiceAccount</li>
<li>Remove-ADDomainControllerPasswordReplicationPolicy</li>
<li>Remove-ADFineGrainedPasswordPolicy</li>
<li>Remove-ADFineGrainedPasswordPolicySubject</li>
<li>Remove-ADGroup</li>
<li>Remove-ADGroupMember</li>
<li>Remove-ADObject</li>
<li>Remove-ADOrganizationalUnit</li>
<li>Remove-ADPrincipalGroupMembership</li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852297.aspx"><strong>Remove-ADReplicationSite</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852232.aspx"><strong>Remove-ADReplicationSiteLink</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852325.aspx"><strong>Remove-ADReplicationSiteLinkBridge</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852303.aspx"><strong>Remove-ADReplicationSubnet</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852200.aspx"><strong>Remove-ADResourceProperty</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852256.aspx"><strong>Remove-ADResourcePropertyList</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852253.aspx"><strong>Remove-ADResourcePropertyListMember</strong></a></li>
<li>Remove-ADServiceAccount</li>
<li>Remove-ADUser</li>
<li>Rename-ADObject</li>
<li>Reset-ADServiceAccountPassword</li>
<li>Restore-ADObject</li>
<li>Search-ADAccount</li>
<li>Set-ADAccountControl</li>
<li>Set-ADAccountExpiration</li>
<li>Set-ADAccountPassword</li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852285.aspx"><strong>Set-ADCentralAccessPolicy</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852215.aspx"><strong>Set-ADCentralAccessRule</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852235.aspx"><strong>Set-ADClaimTransformLink</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852330.aspx"><strong>Set-ADClaimTransformPolicy</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852219.aspx"><strong>Set-ADClaimType</strong></a></li>
<li>Set-ADComputer</li>
<li>Set-ADDefaultDomainPasswordPolicy</li>
<li>Set-ADDomain</li>
<li>Set-ADDomainMode</li>
<li>Set-ADFineGrainedPasswordPolicy</li>
<li>Set-ADForest</li>
<li>Set-ADForestMode</li>
<li>Set-ADGroup</li>
<li>Set-ADObject</li>
<li>Set-ADOrganizationalUnit</li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852299.aspx"><strong>Set-ADReplicationConnection</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852305.aspx"><strong>Set-ADReplicationSite</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852257.aspx"><strong>Set-ADReplicationSiteLink</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852190.aspx"><strong>Set-ADReplicationSiteLinkBridge</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852195.aspx"><strong>Set-ADReplicationSubnet</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852191.aspx"><strong>Set-ADResourceProperty</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852252.aspx"><strong>Set-ADResourcePropertyList</strong></a></li>
<li>Set-ADServiceAccount</li>
<li>Set-ADUser</li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852296.aspx"><strong>Sync-ADObject</strong></a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh852203.aspx"><strong>Test-ADServiceAccount</strong></a></li>
<li>Uninstall-ADServiceAccount</li>
<li>Unlock-ADAccount</li>
</ul>
<p>The AD commandlets new to Powershell v3 are <strong>bolded</strong>.</p>
<p><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://blogs.metcorpconsulting.com/tech/?p=1535"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://blogs.metcorpconsulting.com/tech/?p=1535" data-text="PowerShell v3 Active Directory Commandlets"></a><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://blogs.metcorpconsulting.com/tech/?p=1535"></a><a class="a2a_button_google_plus" href="http://www.addtoany.com/add_to/google_plus?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1535&amp;linkname=PowerShell%20v3%20Active%20Directory%20Commandlets" title="Google+" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/google_plus.png" width="16" height="16" alt="Google+"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1535&amp;linkname=PowerShell%20v3%20Active%20Directory%20Commandlets" title="Facebook" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1535&amp;linkname=PowerShell%20v3%20Active%20Directory%20Commandlets" title="Email" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:print()" title="Print" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/print.png" width="16" height="16" alt="Print"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1535&amp;title=PowerShell%20v3%20Active%20Directory%20Commandlets" id="wpa2a_20"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.metcorpconsulting.com/tech/?feed=rss2&#038;p=1535</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Powershell command to view the VM Generation ID associated with a virtual 2012 DC</title>
		<link>http://blogs.metcorpconsulting.com/tech/?p=1594</link>
		<comments>http://blogs.metcorpconsulting.com/tech/?p=1594#comments</comments>
		<pubDate>Thu, 14 Mar 2013 03:25:16 +0000</pubDate>
		<dc:creator>Sean Metcalf</dc:creator>
				<category><![CDATA[Powershell Code Snippet]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[Get-ADObject]]></category>
		<category><![CDATA[ms-ds-generation-id]]></category>
		<category><![CDATA[msds-generationid]]></category>
		<category><![CDATA[Powershell Code]]></category>
		<category><![CDATA[VM-Generation-ID]]></category>

		<guid isPermaLink="false">http://blogs.metcorpconsulting.com/tech/?p=1594</guid>
		<description><![CDATA[Powershell command to view the VM Generation ID associated with a virtual Domain Controller running Windows Server 2012 (on a virtual host that supports VM Generation ID): Import-module activedirectory ; (Get-ADObject &#8220;CN=MCLABDC01,OU=Domain Controllers,DC=MCLAB,DC=net&#8221; -server mclabdc01.mclab.net -property msds-generationid).&#8217;msds-generationid&#8217;]]></description>
				<content:encoded><![CDATA[<p>Powershell command to view the VM Generation ID associated with a virtual Domain Controller running Windows Server 2012 (on a virtual host that supports VM Generation ID):</p>
<p><em>Import-module activedirectory ; </em><br />
<em>(Get-ADObject &#8220;CN=MCLABDC01,OU=Domain Controllers,DC=MCLAB,DC=net&#8221; -server mclabdc01.mclab.net -property msds-generationid).&#8217;msds-generationid&#8217;</em></p>
<p><img alt="" src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAA/AAAAEyCAIAAADSgqzPAAAgAElEQVR4nOydeXwkV3Xvz61uacYeGxvMZntmpK57q1szY2ywUT4sITGrF80idXct3dJIM94Bg4hY8pIHZAFECAgQS8JLIAkQIlAcoCHwIO8RREgIAQuxJERgwIAN2GOPLG84IeTN+6O2W7fura7e1N2aM5/vx59xT1Xd7dxTv3vqLrC5uXk//sE/ffvnvp7/0+/5V/1pMf8Jt3eiWk7nqu76n37Jfye66nbt/v3yp9/rH/Pfm3+Sy9WtP7C5ubm5ufkA/sE//fnnkZ7/0+/5V/1pMf8Jt3eiWk7nqu76n37Jfye66nbt/v3yp9/rH/Pfm3+Sy9WtP3DDV08gCIL0BF+5G0EQCV3vmwiC9DCf//zn4YavnnjFZ//1NX/zJQRBEARBEARB+gtP0N/w1ROEWVvD6OL66uLcliXXltSBLSyfXJ8fq3vNZpqHp7+yv4DZlY2Tm8uzXUo9sY3q/Ovsyka99m2R0cX1jbWlUTY3v7YNm35706cd1s32xsnNDS7z0h9PE9K48R5h27sLMCxgJrAy0BLoJRi2skMVYEXY+7r/89Avfnr3iR/fffdX3zebfcz4mYVjwEzIjQG1NeNayB2FvRbsK8H+N73/Z3f8zkHrzD3jJDcBugV0EvQpGD6qscnBkQoMver99/74FWNHCZ0YoKUzmJWlNugV0EugH4ThIzA0AdSCwiQwG3JFoBVgxyA/DYUpYGUYPgj6BDALdBuGbdAdYBVgDjAbGipp6h7XR/a5jenrVggFPW92Gyc3N2oLXvHGlla53xMsMnrlyoyyvubm18R/5SsR2Nz8WqcqVJo6n3+pHu1KG7eY6BbneaaW1OhbkM9WBP0WtNHo4rrbp2ZqnLqKdRm3GwZGOFNLMMiwk87UNjfWlkaTninPpGDzghNwf5f+KE0oenEkxdHF9TTmMbq47j0wKE5qz6DKZ3dJ6RVbN7AEeJNL/rGdBW/EbOT3tmzeTVdmK5lvqqLEXEndxbZipAzMhtwk6DawIrAyGBbki5A/DLlnnrn/uuMf+Pq//PGLYcjatX8mm6+CbgIrQv4IsHJWr8DQBOTesXzfHa87UtXY4UH9asJKUJiEkSrsq5IRJ5u3YO/vfnTzttdf5UD+MLBxQotAS0BNGCrBhcVzRl8PQ2/8i/948D/uOPWNO/9m4dCNxhOfByMvOPz3p05++0enfvn9b/3sb698/LGMbg9Qayczs8wCjiaKXLcpu/6S6kG2PvPNpQhsbn6ta2+fIM+CoPffymNLqyfX58ca0NYNRWdhdkWw7C0T9NLUXUYX11fX1oO3SOtt3K5G6srtjVZp8MbtVj57XNAHVhdodGmX8ZSEX5lJgn5tfTUQNGvrq2tLo0nPlGdSsPlIN/TbNPKjPwBQJBQGFIPbXY2+WltZrSeAeNEfaLgGBb2Yz/Y2d8Pm0fI3qz4X9KnMRn5vO8y76cpsJfNtaeK4u9hmDOyfyLCqtvcaTa9q+QkYKcKBEugvBTqxMzd5wdAN9qd++c+LN8KBybOeNH3GyPQAnQbjEBR+FQoHzyxMweOOwPl/8slH7nhjcRoOHDpTf24mfwT2T8LFDlxqwQGTGGXY/Qd/99C/vuuKEuw7CPlDoB8GeoSwCbK7TB7ngFF8/b/d889vfTnoLzj7+D+c+NJ7L7t4CnLX3fDSV2Z2V7Th8dLHT/3s06/dOeycw6zHjZR35cuElTVW1piZYWYTRUZB3xeZbyJFT82Hr9G50S5pRYWg98OEKcsGiV8GvagGJ5TjYXLVazuM2EXiiNxgqLbg374yE4RV/LTUt0s/EazMjC3xsiOMx9RW3OyNLq6vLi650SP34cuzkbBNNNi5Pj/r/ZOncmRXSvM5U+O+lkRiUXWKGbwG4rcT/40Yi7+Kz2xoYpLbHOJbNijp2vpqpGUjDafKp5R4MaVtpC5m2By+2fCjaq7dY/mMXby5PNtY5lN2GWALy2sry2ubya9zYAvLa0vzNU9nrC4uLas/0Kt6cdzm+SuDGKFw++ji+kZtSZ6Q+CghtJlUP0KFBIk2J+gj+Y8Zg7QXSw0sfddO38Rp7DOhF6ucQPyZAWkEfYtONV1zyM2mQ+YtaU2ZE2h75hMspEUHmJ5W3ptBxxHsJL2FSPMj9LgP/ObxHbsu1/be8FtfOXX/Hd+7feOBO+479eXZMaDlDK2crU9P1/7r1sWXwD5nYKQIj3bKb/vG9x4+9fCJO79/z6mvv/5GePazYOit7/rpxhtnP3Di3lN33PH1U3/xaXjM8+G5zyZXfOz27/zixIMbD3zp/37krjvefPnMOXvLA1f9/pu+vL7+n6d+tnn3qY07P3DzsQue8tnbfv6VErvk0RdMnPu899/y42+98TU3njE6Ducbj774Gnj89U/9s+898pX3XXxg4sJCeSezs8wCwwTD0gw7YzgqH5IQqRV6XBvss/MGpnhvpnVBqhKltCVZ5kUnkBBMTOPnJR/fOCGR1tfNrkgrVlHMVA3XnNhTCHouf0Ej1fPdygvigp7EwuTS1zafJR7BxfgDD/+FN7a0GqkReQOInwhmVzZqC7w25QsVzLH2g4jenFpe+Aq6lg+1Cu0tu1JqDeKLSlpMwqzRsbmwFDJxxjUEH3YKKln2TDewmnZJgCSfQtVJG056u4p4MaUJJRXTbQ7uAq5mwiaQ5pP/7p9Q9pSouowrZUb9ArqCnu/Dfk9e8i6rLczU1ufHFpbXlkYTnikV9AqbF4dM0dthdmVjbV0a/+Z9qyjQ6wv66AAg0rVFzyCrkDlZPpdGZcag6sXSfqTosPKunaqJ69pnci+W+jrZM4Nb0gj61p1qstUlmE2HzFvlLlROoH2Zn1O1ZosOMCVtfG/yf095u5R4j/vW218I9Brzb0888rU/v3TYGThgZ/faJGcDs4HZYNjX3fKLry++HPImsBcMsusvOXLzrv3mzvw0zH1z474vvvCJJTBed8vDP3z41k9dRg9nJv7qCz//9lsO23DhWz7+0x989NUvH9QrUP3oTza/+47xGdg3ddNffe+BW5effkkV9hZBL0K+BK/62IO3vn/f0I2wbyr7hJe9+ssnvvWns7DXhKFxGB4D47Uf+NHtH/6dyR25a8jwNAxPAq1A3oK8Q/IVLT+p8iHS14S0x7Vsn1thYNIspXdBqhKltyWFjAnsMynEI20jae+QC4nUvk4YA9fvcSkarjmxp5pDH/sC6A0gGnt11TMU/pUpj8N5g49IdJ/Pp/xdzleodKQbb6ogFBoN7In1JdhEPUHP27dSH6jyqXiXq0Kt4hBccntMb9X9CJNG1ssTimVD2nCKYkaCHNHp1NFopTShesWMh07joWXpGzq9mEhn/2pB7/fw5Aj9aOgdmlE8EpvnrpROevGtqMuCPo0depmRGYOqF0v7EX9jPKGEcimbuK59Kr6ZJLSm9Jl8QycL+rY41RTNITebDpm3xF0kOoF2ZV5lIekdYHpUrrL196Y3xI14hrS3x4n3uG+9/c27njL/oQce+fP/MQ4XFWH/kezugyRXAqMCeQcK9rUfe2TtnS8Bw9SGDmYvfQYMvekNP9rYOHHq1Mkfff/+L05fYMLIH/zRD77xVvNlsOPQjssW/ueXPv/Zd7/mrOtufXDj9snH/lqGHoKnv21548uvPlwZ1H/nw/ef+pObr9LOu2IHncnQKjATbljeWP/0r104TYzigP6ad9z24Bd+/3oYmr7g0jfD8B/8wy8e+pvjz4Lha71Z/rQMrEyYCcwBNgXMkfqQZCEU+ybWHvtsl4FJbUmapfQuSH17WluS/h7K39mVet+FJH5e0jsUMRRZP5LUUthNxsLQe91iJjdcc2JPHqFPaG+FvIhMIUpJVA0LDR/JCS8rpX0mOfNSVRpLna9QpVjskKCX5lPxLk8cXCZLAWWXU69gTvt9Jq2gb1oTS4vZiqDnc5IwVySeehOZlxVH3mUCQe/GM1Z9ASoPYfquzb9L/UzJEF1m85Fa4hsuvH2mtulOP5AktBVTbrx+VzdCP1Pb3KgtSI2h7ss4ucOmFvSK5miDoI85gXYI+tadaoLVJZhN58xbdBeJTqB9mU96bbfRh9Sl6femn+dw/NyEhQg5EXrcv/3JK2D4Dz/1k//+3G+8GvSDsPeK7AXPIcOHoTAJIxXYZx+vPbT67puAWTsuKMHj3vK++2/73MtfuvOCEhz6i1sf+MfibgcOLHzsl99+41VFGJ7Z9dhX/ul3/+MTNzwXXnLriXu/cLzwW2BcDrt/93MPf/stE9c+7sL3v+ee73zg5qsgf+05IzfvMI5DzgLzQ3f/5CulJ1iZ3JUDT3rz0sZ/f+xFU5nhG84cPvr6f3/wozfbA7uf/6hLpkAvAxvPFg5ljfEsLQGtAJ0B3WxR0LfRPjtqYNIspXdB6ttTm6K0d8fsM6XVxac8hQMDtcut7+ui32lDr5W44Ce54ZoTe3UEPbCF+USnHy2SYsKobMoN4bRL0NjhvFVP08yN8s+XbXqQVHjF7ZLUuRk44TiSW1c3urgeTLlpu6BX5bMRQe8n1OSUG0lH8l5UKQZpCn0sVp204aT5VKQiKaY0oYRvf/FZQFyGIx0yns/2TrnxsyF2Gd4s3fBAYoRe/F/lM2UBFYnNi0Ybk9TB50h5QpJFsdIa5msgKKBiUazEM6SzEKUxqF/Gkn4Ut/CUgl7ZxEr7bEHQt2PKTYtOVWjN9GbTEfOWugu1E2hj5hMspO0+RJ56a+/N0DzWxMn06W8XiPe4L7xtHA78xvUff+hr33rrU/M3Pi5XhQsPnq//GhjevpA3ffaBW9/9Mjh/fEA/svvS19xy30/mj1TPp9edefMdd//skzf++mXA/scHvnvqg3PPhcuesevmL/zTHT/5nSPPGZn+62/85BfveeUVj9vzoqe989YHfnr3HxWrcOmxm957auO7H2YXXX7uE6YeNfoS7UnPedz5v/fK1R/84M9vggMmXPupO2/7wKG9L9P2H534xKl/fcPRgfyNkC/D+SNwkQmjN8FVf/XtX/zXnX+3AGcXgFWAyQW9qonjPa4h+5StQtwiA5NmKb0LUpUovS2pMh+3zzRWt7o4J+0dCiGRJCCjmZybX4t8H1MZQ/qGa07s1Rf06XeCi27pxflKhaB3606yKEGwY8UX8FhERGphktuF1OPf8f09gMPoy+riUuci9An55JY7BB1eLb5P+mEk3kqETzPKRbGSnpDQ1mLTxxamBAkFVSdtOGkxE/pnvJjxNkoo5nIt8mPUVJIMrPXMp+wy0VGucgitUjzKZ0aCiOvzYyqbj1wpm4gS69dCnw0v9mojHsIMLT+2bUh820qpZ5BXpiqf8kWxkl6s6kdNC3plLalWj8memdIJtHNRbFNOVaaJ05pNu81b5S6UTqCNmU9ozU74kHom1/B7U9U3G7pdIN7jvva/3qBdcKV2ycvf/sVf3HPy7s2Nhx7e/H+feevvEVaGnAl7rZd9YfOr7/otOGcss28MjOqT/teX7/rZz+9+5L83/v7jC9968Kc//udi4fWfemj1k5849eO777//57/8P6+2wKiCfuNF7/7WXbffd889d/zL+z/+Nz/5/m9fdRQKNow4b/3Kf/70rhP33//g/Sc2f/DHr4ThcRh5x0fuvv/HJ+765cY/mnsmsuw5ZOQtn7j3gfs37r/37o277rzn4W985leG7bONUvbypX+++45Hau+BwjQYJWIoBb2qieM9Lr19phf0bTcwN6HVtUiW0rsg6e2N2pI088lrDFRWFwRq4w+MC4mG9qhNqRnSN1xzYq8LB0uJ5tLsdof9nvo2Q7UPfV3F0wu0su0m0goztY5MNkC6Ql+3Zl9nvu/QHv/MgcuOwvmXDV52Q/bxh8hQCUaqFxaeC7oJw+PZvWNw3sEzhp933rPmM/tnYPAFsPfo8FOmwRg74zHPgPwcPPbJZ+25DobY4AXV7P7DwI488cKLgB6FHVeAceyip98EF0/BGc+D/ZOPOeMZGcM662kvhN2HQH8+DF0F+1+YOffQrqe96tzhMjzmaeexm7QLfu3R+ZfAvrHMAQv2/ApcfA1cfBwumYHzLssWXgp7D+4YsuHxzzpv98zZz/rDAXoQWLnrFbg1tPj5qHPTybbt+Qyt0WVBT/rz4FhEShDUiQ43e/c1mRDURLao/htceIP0LH3dmn2d+X5EG6nAcBHOPwh6EQ7YZ1wy+fjLpgf2VWHIIkMHz9r7HBg6CEM2GNdn9r9C068hF0xA7iooXA75gxq1zxyePm/3dYND7hz3I6RwFRgm6MehYO+46DDssyB/FIaPwAWXw9DVA9TU9lXhkmOkUMoOXwHsEIyUIT8B7DDkpzP7XgrGDOjjQMuDtEJoFfQqjEySi6fIvjLQQ1CwYP8x2FeFgqnRQ2cOPx8F/dbcLsUL2GMATkb3BT2CIAiCIKcPYFRAN2HvBNAyjFiD+52zLqpkCjbkTJKb2JE7RHIl0CvAZjKF6zU6RYaKQI9AYQzyEyRvD9DJM3IzGX0SqAOsBMYRoCXIOcDK2ZFxyJtgVEEvwdBByE1ozIZ8BfZNgWFq+mFgE5Avg1EENgFGRSscB6MKtAjU1KgN1ALdBsOGERvyZULHwbAgPwn5Chi2RouD+iFy2gh6pL9IJejbckJe5z6+bD3uDMumQ/sJtwu11KGzCREEQRCkW4DuALWB2RqzMoapGSZhJmEmMJMwmzBHYxWNTWqsojFbY5ZmlDXDJHmLFGwYcaBQgXwFjCqwSaAO6CbJFUnuCOjjQIvAymBYwGxgDrAKsCqwCjAHXL3OTO/MV6OkGSVilIlhAjOBmUDLoJdBL4FeAloCWtJoSaOmRm2NOhqtEuoQZqGgR3qTdII+xfqDuvSjoN/6PIuCvh01jyAIgiC9A1BX0FuEWbyaBxoK+gyrZkJBbxLDJHkL8hYUbMg7kK+AUQFWBeoANYleIrkJoheBloCawCzvjCrmAHP8v9vAXEFvElbWjLLGysTbYN4X9J6mL7t/12g5EPSEVgi1CbNQ0CO9STpBn3oxe72H9Jk27b6gb0fNIwiCIEjvANQOBH34I7OAWYTZGnMynqB3NMPWDIsYJjFMMCwfGwwHDIewCmE2oRahZaKXiF4GagK1OAUf6HgXV5GbhJmBmucEva/pqQnUJB4WoRahNqGOL+jNrlcggsRpZg796OL66uLS8snNjdqCu4cOt3+nYselk5sbtZXl+IZi6bfCXFsPdznl11zyJ1zOhsd0ebfLr3T3hwp/FLIUOU4sum8Rv5NRfNczyT500Swpb5fVEoIgCIJsP4BaQK1A0IeCm1qE2RqzM8zJskrGcDTDJoYNRnCNK75daW4T5hBXo1PL1d/ek73ZNZFbCLO8i5lFvDh95OOAgC/lA0Fve39HQY/0JE0Ken/P1M3VxTlhs0/+yvSnEkhJOJWA3+YzOHtsIzx8JNybU35loM4DQT/mjwESz2byMxbfSF5+pEI8S5LbE888QhAEQZBtiSe7aUgg6AcMJyboOcHNLMIszbA1T9nbhLma2/bC/67EZ2YQhifMCq8M8kCDwLxaxzP/f5k3bOh6vSFInKYj9Ioz0oTjDxTiWHJldF/9uA4Obo8dI1LnqO2EK3miFzco6Bs5y11+e70UEQRBEGS74CvsqATnZt3YmmG7at4lDLd7gp5X1aKm96Ppbmy+DBFBz2fAn2zjrselFqGWRi3NF/T+GCMKCnqkJ2mnoA/+NZxhkihV+SulJAh68aRPtaCXXZn4JSHx3HX/ehT0CIIgCNIMYJQ5QV8h3hpZbrK7P12eMCsQ69z8mWg0nVmaOwZwoS4RQR8dAHgb3RBWDv4VmKvm7ax3Oz9px4pM90dBj/QkEUEfP2FYiuJA3bnwpG7/kA73gdwMe/dAXcmVUqS3EzfAHz1WQKWeFVdKBT1/Knu7ptykE/SKYiIIgiDI9gOMEmEmYbZGHU2vepo+kOzuPpJGGQwzWCYrFfSgexNgNH/6TcbFi7JHAvCuZPfVfEljJWKUvFQM78tAhjoD1MlQxxf0pkzQd78CESROGwV9uNyTny8eLDZdXVzyQuyKK6UEi02D20lsfo5qyo36Skmi4aLY2tL82iY/Cz+eVUGR8/kUF8WmEPTSWuq6ZSAIgiBIJ4B8kRhlwmyNVjL6pLvFOzAbDAsMV8qXwSgBK3s6mzkas0ko98P9Jd2NaDRmZQw7Y9gZZmeZlaVWhlqEHwAwP6LPTI2VNVbKGMWooLc15mSps0OvZCOCnl9TaxGGgh7pUfrmpFhBEyMIgiAI0o+4Yp0wizBHo1WSM8nQOBkuk5xDDJvss4jhwHAFckdAfz7Qw4RZGqto7Cihk6BXMrnyzqHxjG6CUYX8NIxcA/mpDLOyhjNgVDPU0YZt0CeAjQGdAN0G6p4wZQO1NMPMFMpa3tQMS8uXtUIJjBLQEuhlMlzWdFuj1SxzBgxLC9bsYoQe6Qd6WtBH4+sYt0YQBEGQvgdYGH0nzCFD4+SCK7XdE9reSjZfGbjYGTCmBnYfg71Xw/Ao6M8DViZsMsOuJfoxGD66c2/53N1jO3QL9h2D/TfCRS+FwjUZag4YlR35qYxehb0O5A4Bezboh2C4CnSSGFPAKkBtLW9l95mZgk2MaqZgDYwUNWMCcuNkaJzsnoBhC4zJTN7ZWbCyhuXP7LcJs7Qg/yjokZ6kpwU9giAIgiDbDAhWoxoWGLamm9mhEmFXAHNg77POyx8998kvzJz39LMueyXoVwM9BHSCGNWB/LUaPQrDdib/vMHCYXjGwTNzNjyhAvlpYJWMXs5SZ4BNZmklo9s7n/Q7QI/sGHgqUFNj9g7DyTAHdBtYCfLjwEqEmsQwtRELjBLo41qutHPYyuTKoBeBlUm+DIYF1PE3vLc1V9NTFPRIj9IFQS/sirPFNJd6ms1nwN+YP93TUl3ZX7gLCZJPCutg6oltVOdfO7/9/+ji+sba0iibm1/bhk2/venTDstvxcudtSf58TShj/YQ2/buAmgg6E3IWxmjMkiPkkIVht/+mZ+f+vHdJ350YuNrf/ZbOx9TfhSbGWA20CPEqAwWrsnQCgyPw75xKLzpgz+743WHrUftPbwjd3ggN5HJlTM5O5OrDrDKjoINQ6/6q407fvPQNDEmdhils5k5SC3QHdAnQB+D3GHIjQMzYaQKhgn6eJaa5xqTg3oRhq8GegTyJTAsoBVCHcIcd7ltE4I+fY/rI/vcxvR1K4SCXty13V8aG13DmrjLZLrVrsDm5tcS95lhc/NrnapQaep8/qV6tCtt3GKiW5znmVr9Jc4dzWcrgn4L2mh0cd3tU8FhZ0TWZYS9VmdqCQYZdlJ+NyfFM+WZFGxecALc8m7xR2lC0Yvje9TWN49wbXq4D2xaz6DKZ3dpaA+AVgwsAd7kkn9sZ8EbMRv5vS2bd9OV2Urmm6ooMVdSd7GdgEKJMEfLTRM2CSMOFCzIl6BQgsIE5H71zP3XXvuBb976npdl9lYfte/aHflpwhwwSpA/DPnioGHD0Djsfedf3/PjN4yZA8NjZ+y9aiA3TgwbCjbssyFvElqC3a/92H23veGqChTGwZjI0BKhZWAWDJdgz/g5v/J6GH7Tn//nQ4/ceep7d37yQwfn4IlP3jn80nOf+fpL3/zTX976h+P7K2eNTA8wK8vsDPU2xGylyHWbsusvqR5k6zPfXIrC/itb/PYJ8iwIev+tHO69mFZbNxSdhdkVwbK3TNBLU3cZXVxfXVuXbvKDgr5ulQrbg259Pntc0AdWF2h0aZfhDxgmyYJ+bT08b2FtfTU8iy3plAYBwebF/VvdZ4r7NW0uz6oSCgOKwe3ecRO1lbqL2nnRH2i4BgW9mM/2NnfD5tHyN6s+F/SpzEZ+bzvMu+nKbCXzbWniuLvYZsCBosaODuy9MUOPafuqsL8I+6+G3I1AD56bc4aHrp389C/+ZfEmOHDs7ItuPHPk+kF2DRiHIf8MGBnbdeAoPG4cHvu+T27+8I1XloFeteuC5w/kjsBIFS6y4CklGJmAoSPwxPnP3P/Ndz6/DCOHwRgHfQJYCQwT9prwBBPypd//t81/ettvAr1y14vXTtz2t88cHrvsnT/+2clTX/vk//72//tkhf065K1dRnkHM7O6rVGLGByNFxkFfV9kvokUPTUfvkbnRrukFRWC3g8TpiwbJH4ZjO+GGQ+Tq17bYcQuEkfkBkPuhvde5v2wip+W+nbpJ4KVGWF/ySAeU1txsze6uL66uORGj9yHL89GwjbRYOf6/Kz3T57KkV0pzSe3XaYQi6pTzMipvfEAqnx7TfGZDU1Miu/CGSnp2vpqpGUjDafKp5R4MaVtpC5m2By+2fCjanFfUfFTVWwI3lDmU3YZYAvLayvLa5vJr3NgC8trS/M1T2esLi4tqz/QJ56OHLF5/sogRijcPrq47m7tKklIfJQQ2kyqH6FCogfJNSzoI/mPGYO0F0sNLH3XTt/EaewzoRernED8mQFpBH2LTjVdc8jNpkPmLWlNmRNoe+YTLKRFB5ieVt6bQccR7CS9hUjzI/S4P/3tmcFdz96x+4Wv/sqp+39y5w82Nn907y+/8tLnAzN3UufR+tSx2iOrb78JCtXB/CSce9R82zdve/DU/T+7/fv3nvrWm26E5/w67HnXO++89w03v+fuu07d+YN/O/Xez2jnPA+eczlcectt33nkrs0T9//j3y3/9Mdv+bWZR+8uD175ujd9+bvf/sWpOx+499TmHe9/aeX8S//3bQ9/rUgvPef84o5n/8V7f7B2y+t/IztShguu2uF8+iN3/1+bHoLc1OBIacAwB3JWhvoHXRkWMZQ+JCFSK/S4Nthn5w1M8d5M64JUJUppS7LMi04gIZiYxs9LPr5xQiKtr+MOL4rWnrSYqRquObGnEPT84Up+I9Xz3coLpNvbC2Fy6WtbtWe84GL8gYf/whtbWo3UiLwBxE8EsysbtQVem/KFCuZY+0FEbze1UAAAACAASURBVE4tL3zF46K4UKvQ3rIrpdYgvqikxSTMGh2bC0uhPhVLfQCW7Jn1zvGtm0+h6qQNJ71dRbyY0oSSiuk2B3cBVzNhE0jzGT+krKHMp+wyrpQZ9QvoCnq+D/s9ecm7rLYwU1ufH1tYXlsaTXimVNArbF4cMkVvh9mVjbV1afw7fmRydNyVLOijAwDpicu+Z5BVyJwsn0ujMmNQ9WJpP1J0WHnXTtXEde0zuRdLfZ3smcEtaQR960412eoSzKZD5q1yFyon0L7Mz6las0UHmJI2vjf5v6e8XUq8x331XdcDPX60ds8vV//ystyMtq8EF14BwyXIT4NRIYZ5/S0Pff1tLwRWhuHDO/Sbnnz4RWcWjmSGyzB360MP/8PNF9pQeMvyf9y++fW/fjI7lDnysX988DuLYyZc+IcfOfG9W37nN87QbajectfG+rsPHYV89UUfuu3Bry4/7clTMGwCOwwjV8Kr/vqhr/zlvj0vhPxU5gkve/VX77n1ndft3H9sp27C8z+4/p+fs/TqwO5ryf5ixigPuoI+b0HeInmL5G2VD5G+JqQ9rmX73AoDk2YpvQtSlSi9LSlkDH/QkLJo0jaS9g65kEjt64QxcP0el6LhmhN7qjn0sS+A3gCisVdXeqejisN5g49IdJ/Pp/xdzleodKQbb6ogFBoN7In1JT1Ui68iMYyX7mApaT4V73JVqFUcgktuj+mtuh9h0sh6eUKxbEgbTlHMSJAjOp06Gq2UJlSvmPHQaTy0LH1DpxcT6exfLej9Hp4coR8NvUMzikdi89yV0kkvvhV1WdCnsUMvMzJjUPViaT/ib4wnlFAuZRPXtU/FN5OE1pQ+k2/oZEHfFqeaojnkZtMh85a4i0Qn0K7MqywkvQNMj8pVtv7e9Ia4Ec+Q9vY48R73zbct7Lzsde9/ePNPXvGMwSdNwsU2GGUwbMKqYDhgWNfd8vDX3/5iMCyij+946uUw9I7X3b7+4OapUyfvuX3zizfSKTgw/0c//Nrb7BfDzqvJU98y9/kvf+69b3j8dZ+79+S/Tz7+KWcwC572ng+d+Pprr3TAeOWnNk799ez44HnPh+EyUAvyDhxfvv07n/j13HXa8ER2+LVvv+3nf//aqZ15Z6dehKs+9M0H/qliVAd3Xwd5E/JFKBwBVtJ0h+gW5ExCFcdrJgqh2Dex9thnuwxMakvSLKV3Qerb09qS9PdQ/s6u1PsuJPHzkt6hiKHI+pGklsJuMhaG3usWM7nhmhN78gh9Qnsr5EVkClFKompYaPhITnhZKe0zyZmXqtJY6nyFKsVihwS9NJ+Kd3ni4DJZCii7nHoFc9rvM2kFfdOaWFrMVgR95KBf9VyReOpNZF5WHHmXCQS9G89Y9QWoPITpuzb/LvUzJUN0mc1HaolvuPD2mZp/mnI8oa2YcuP1u7oR+pna5kZtQWoMdV/GyR02taBXNEcbBH3MCbRD0LfuVBOsLsFsOmfeortIdALty3zSa7uNPqQuTb83/TyH4+cmLETIidDjvvvu/wn0DR+67+RHX3xoIGfDyCRccgz2TWruQU6Gdd3f/Hxt8SVQcLKsBBf80S333/d3v3Hl4y46mDn42a/e+8XjB66BJ//eJ//fN952dQloFc5/4RvXTn36VWW4uXbHzz557f7jZ+QtuOBdH928661XXAvs7bW7/v2Lr7Az+WnIlUCfztKb4OBH/uXuz5eNmcHznz8w8pYPnTz18ReVd9LxnbkjcPDDt95z69S+yZ0XXg+6A4VxeNJVYEwM7K1oe2zYXSZDZouCvo322VEDk2YpvQtS357aFKW9O2afKa0uPuUpHBioXW59Xxf9Tht6rcQFP8kN15zYqyPogS3MJzr9aJEUE0ZlU24Ip12Cxg7nrXqaZm6Uf75s04Okwitul6TOzcAJx5HcurrRxfVgyk3bBb0qn40Iej+hJqfcSDqS96JKMUhT6GOx6qQNJ82nIhVJMaUJJXz7i88C4jIc6ZDxfLZ3yo2fDbHL8GbphgcSI/Ti/yqfKQuoSGxeNNqYpA4+R8oTkiyKldYwXwNBARWLYiWeIZ2FKI1B/TKW9KO4hacU9MomVtpnC4K+HVNuWnSqQmumN5uOmLfUXaidQBszn2Ahbfch8tRbe2+G5rEmTqZPf7tAvMd9410vg73W8U/8/OStf/Y0WgF2lBgmYSZQE5gFefvajz6y9o6XQr6q6SYMv2v5vu/8wdjVZ+Yn4OZ/2dj4/LVGFYw3fPLBjQ+/tAzGNLz48/fc88M3HywPXv0XXz7x04+8vJo1Ji/9g2/dd/L7bxyzIV89vvzTh7/xl5ftm9Hc5xsODM2+cW3jS+/47Z10HOZW7rn1w08zTGDOYK4IYx+69cSXKoWJHbuPEWbDyAQc/OA3Nx7c+PjbBnJVMMpA5YJe1cTxHteQfcpWIW6RgUmzlN4FqUqU3pZUmY/bZxqrW12ck/YOhZBIEpDRTM7Nr0W+j6mMIX3DNSf26gv69DvBRbf04nylQtC7dSdZlCDYseILeCwiIrUwye1C6vHv+P4ewGH0ZXVxqXMR+oR8cssdgg6vFt8n/TASbyXCpxnlolhJT0hoa7HpYwtTgoSCqpM2nLSYCf0zXsx4GyUUc7kW+TFqKkkG1nrmU3aZ6ChXOYRWKR7lMyNBxPX5MZXNR66UTUSJ9Wuhz4YXe7URD2GGlh/bNiS+baXUM8grU5VP+aJYSS9W9aOmBb2yllSrx2TPTOkE2rkotimnKtPEac2m3eatchdKJ9DGzCe0Zid8SD2Ta/i9qeqbDd0uEO9xX/3j12QumNjxlIU3/P0P73/wwQcf+sXPHz712cXf09gEMAuM6ms/++DKu18Nj7sE9l199mUvesq7vvLde04+snH37Z//3MI3T/xy4+tHh373707e8fHPPHL7iftOPnDqQ6+5OTN89bkXv/gp77z1O3edfPiun375fbd84PZv/L55A+TLcP4NH1g/df/GxkP3P3Ly7pPfeteL4LyrIf/2vz31y5888qP/euBfJ+ivP6pgH3jL1//9Zw/+/L77/uPee39x990/+eHGe188mbn0Jjj8vu8+eOr7n3kjPPpibegoMFs9bU/exPEel94+0wv6thuYm9DqWiRL6V2Q9PZGbUma+eQ1BiqrCwK18QfGhURDe9Sm1AzpG645sdflk2IFx31apb7NUO1DX1fx9AKtbLuJtMJMrSOTDZCu0Net2deZ7z+e+MwdT70eLnyu9pTJwQvLsKcIQxNPZJeD4WTz5s58CR5T3JW76pxnvQJoCc66Uhs+OjR6HQzbg+deBfqNmT1P2cGOw/CTd17oDI4cgeHiubufDkYFzr4acpP0mTeQA9Nw5gvgydPnP/a5mmEOXjILe8ey7AoYPgwHXgyPHnvsU3/znJwNFz7zbDoJFzz30ftvgnMOEnZ8z68cg6GDsPcQ7D38qKfPnjX0PHjMFY+6ZCa7t3zmnuqu0VeRkW5X3RbS4uejzk0n267nM7RIlwU96c+DYxEpQVAnOtzs3ddkQlAT2aL6b3DhDdKz9HVr9nXm+5HsRcc1WiEXFIHZcPEU5Iuw50rQS1CYPqtgXlg4dI5hZug0DE/BnkkYNgfpeJZNZ4ybs7nJ7J4xMmLBpdfAyFGytzIwXDxDHyNGFfbdBIWKlr8aWBn0aSg4cKBIRso7mQ3MBuYAKw7QgzBSgosmYX+FjNiQq8AFUzBchXwl8yTrjMtKmQNFoBNgmJCvZAv2GYWyptuwpwpD1YHcZGafCU85orFy1ytwa+hBQe8F7DEAJ6P7gh5BEARBkNOHTOGoRitkbxmoBSMOsBIMHwHdBGNy0LAelS+eYVgZVgW9AjkHdDNDi4RVwDgG1IHcEcibcGAK8lWSq2R0c5BOZJgN+Wli2BobB2qCPgmGDSNlkjcHDAsMGwwHmJmhJWKYUHAgb2msDLoFQw7oNuRtbcQcOFDW8iXQS0BNYI5mWFnDBGrBsA05G3QbCmU4UCTM7HoFIkicVIK+LSfkde7jy9bjzrBsOrSfcLtQSx06mxBBEARBukWGVjTqEGoDNYGWgZpALaA2UAeoTZilGVYmb2ruSlnmXlMGVgZWBqMMzARmAbMJczRmZ5iVpeYALWepmdEtotugO0BtYBYxLJI3Sd4ihk2YQ2hFo46mW5lcOZMranpJoyXCymC4qZhEN8mwCTkLdAvcLXeYCawMrORTRkGP9CbpBH2K9Qd16UdBv/V5FgV9O2oeQRAEQXoHjToatQm1OEHva3r3AsPKGBYn6E1gARJBn6FmlpYz1NSoK+jtiKA3fEHPHEJtTTc1vazlSppeIrTMC3rQTeKq+VDQ85q+DMxEQY/0JukEferF7PUe0mfatPuCvh01jyAIgiC9g8YcwmzCLOJJ+UDQW66gJ4alGRYxLMICVW1xmt69zCbM1pitMStDTReNWoRaQG1Cbfc5JHyODcwm1CLUJHrZU/PUjbibhJluZkig5ql7i8UNJFDQI71LM3PoRxfXVxeXlk9ubtQW3D10uP07FTsundzcqK0sxzcUS78V5tp6uMspv+aSP+FyNjymy7tdfqW7P1T4o5ClyHFi0X2L+J2M4rueSfahi2ZJebuslhAEQRBk+6Ex2xP0EZluBtqdME+FE+8XGyLKnnsUtTT3v/5fCLM8Nc/4J/hQC6hJqCmqeV/TExqoeT7dMJMo6JHepElB7++Zurm6OCds9slfmf5UAikJpxLw23wGZ49thIePhHtzyq8M1Hkg6Mf8MUDi2Ux+xuIbycuPVIhnSXJ74plHCIIgCLKtMaWyPgjDx7AIswi13Hg8oUkPjwT4qTB7xxQFfeR624cfRaCgR3qUpiP0ijPShOMPFOJYcmV0X/24Dg5ujx0jUueo7YQreaIXNyjoGznLXX57vRQRBEEQZFsCoqDnNb1SzUdQPrmOoBc0PYi3xL8MoKBHepR2CvrgX8MZJolSlb9SSoKgF0/6VAt62ZWJXxISz133r0dBjyAIgiBtQJjTElfVopp3aULQK5CF5xOm+qCgR3qRiKCPnzAsRXGg7lx4Urd/SIf7QG6GvXugruRKKdLbiRvgjx4roFLPiiulgp4/lb1dU27SCXpFMREEQRBkeyOT2nFV7U19aerh9TU9kaerAgU90ou0UdCHyz35+eLBYtPVxSUvxK64Ukqw2DS4ncTm56im3KivlCQaLoqtLc2vbfKz8ONZFRQ5n09xUWwKQS+tpa5bBoIgCIJ0FJnalmpoW1gL29TzhbSSPwsk0fV6Q5A4fXNSrKCJEQRBEATpUxoS0CklNTTz/IbVPAp6pDfpaUEfja9j3BpBEARB+p4W1XzX6XoFIkicnhb0CIIgCIJsM7quyFHQI9sPFPQIgiAIgmwdXVfkKOiR7Yco6P1Do8IruCNUgzWp3Jbt0T1kEARBEARBEui6IkdBj2w/QkHv7QpfW1GtPR1dXPfOe2ILy6jjEQRBEARpnK4rchT0yPZDjNAnbCYzU/OPi0JBjyAIgiBIU3RdkaOgR7Yf9QV9sNVMcKQrN+UG95FEEARBEKQBuq7IUdAj24/GIvTCmVPxCfcI0oN03fsjCNKzdN1BnYZ0vdHRZpDtRwOCHmZXBPkOY0uruD080vN03fsjCNKzdN1BnYZ0vdHRZpDtR4MR+ujUeYzQI31B170/giA9S9cd1GlI1xsdbQbZfoi73PAsz1rE1fHRGfMwtrSKp7ci/UPXvT+CID1L1x3UaUjXGx1tBtl+4MFSyPan694fQZCepesO6jSk642ONoNsP1DQI9ufrnt/BEF6lq47qNOQrjc62gyy/UBBj2x/uu79EQTpWbruoE5Dut7oaDPI9gMFPbL96br3RxCkZ+m6gzoN6Xqjo80g24+IoOdOjAqPkSK4mw3S53Td+yMI0rN03UGdhnS90dFmkO1HRNDP1DwdH2xe6W59s1pbUe1liSC9T9e9P4IgPUvXHdRpSNcbHW0G2X5EBP3o4rp7FiyMLa1yW84nbE6PIL1P170/giA9S9cd1GlI1xsdbQbZfohz6L1d56MHSKGgR/qarnt/BEF6lq47KARBkNaRROi9mfQYoUe2C11XDAiC9Cxdd1AIgiCtEwp6YAvL/smvrqZ3T4olDAU90t90XTEgCNKzdN1BIQiCtI4g6D0Rj4Ie2U50XTEgCNKzdN1BIQiCtE5028qxpdXotpXuLjc8gcpHkH6h64oBQZCepesOCkEQpHXwYClk+9N1xYAgSM/SdQeFIAjSOijoke1P1xUDgiA9S9cdFIIgSOugoEe2P11XDAiC9Cxdd1AIgiCtg4Ie2f50XTEgCNKzdN1BIQiCtI4o6EcX1zeiG9p429Kf3NzwN7VUXYkgvUnXFQOCID1L1x0UgiBI64SC3t3QZrW2wu9QCWxufs3fy3J2xVXw0isRpGfpumJAEKRn6bqDQhAEaR0xQi9sOQ9sYdn/X17cx69EkJ6l64oBQZCepesOCkEQpHXqCvq5+TVvT3p3l3oU9Ejf0XXFgCBIz9J1B4UgCNI6dQS9/8vmxsnNjbWVZYzQI31I1xUDgiA9S9cdFIIgSOvUF/QBwBaWuXWxKOiRfqHrigFBkJ6l6w4KQRCkdRoQ9DO1zY21pVH/f1HQI31EL7z425Vu8pXtLWNf11un6XTeGn2+6vpe6EedTrSVR7WxfhAEQbqFuMsNjzu7JvzdV/OqKxGkr8GXfUM102kZ196cpMxVc09oS65aeX5yWbpiFV03WgRBkNMKPFgKOR2wFb+bUoCZ6ud0i4ZK2vpzJPXGyTVTjVTPdaoqmhXKdR6eWqraTeekjc9P144dscNms9T7/QhBEKTPQEGPnA5I3+VyNc8hfUiPa5E2ahrx+hRqPtT0Ha43IUsKaFxopnq+/Dk0YUjgZ4bK002Vz6ae3z6raMYIgbqYQF3DCHqWJetBfdSPEARB+gwU9Mj2R5O/yBsW9FrjtEWCaKm1SOoU61Yan274e0pBv1X1JmQsppIpr31tSF3h4BF9DhWHBJp4l3hxPG6dlM9Gn09FQa+praJdEGYT6j+ZWiQU9O53rUDKJ6n5TneiFI+KFKHrDgpBEKR1UNAj2x/uje6/v6npkVbTtyyDWhP0/nOEoomyKXVyqZ7DPc37PYWaFyYsdbregowlC3q7KUEf19CuorUJ5QS3/79A7VYFfUPPlwl6UdPTVptA0ijU9nRwVNCnGRV3uvukeiB1SxEWoesOCkEQpHUigh7YwrK3zjXcnpJEVsHitjZI/8EL+hBqaunUvNb2GGdLEUdetwmCqaEk+BtNwteMJM/hxY2o+a2ptyBjKkHfmJoXNT2vtn1tTeIZozahUc2tmFauFvQNPj8qRrUo3i3MJrTNgl6jcU1vgnJ4nGRXbekyzRVBY7ZGLZeuOygEQZDWCQW9eyisu18NzK4E2p3/O4L0J+6Ln5M7kQh9cI37F5WsjyiMBPHRJo3i+JdZMgluKYKg3vUSERYoPGYRwyKG8BxBEdqaOtHo+tdgxnkg6BuOy6r0WT0NJzY0GBYYEq0cBmKplVzt/DhBfE5sIj6ntiWTYVSCPqj/MKtCPmn0+YHQDyPiitnz1CK+SNVYGEFPJabVuj9pKEhN4ql5wQItaSeSG6c60fgv8YFZ+j4oe2bXXROCIEh74AX9wnIg4n1xz6t8BOlbvDe3xqwwKu/NE3D/1SHM8SVC3cn0wTNlkdTI73GVbAlKQlCN/hwJR2MVjTmejOOVR6icxI1lApHn6TNqa9TO0PDvhHrPAcMCwwTDl+DUDIRghspmbvgpxurEJobDyd9IXJbw+ZGgnPOdjMb8fNLoE9xRSp4bq1Bu5OaKTirX9F4VxYYxXq3644FYPfuXBSKeRm7kGzdsu1g+o2peYrdu60hmiRjc2Iz7V82/HkJBLzda2bhIquAF7Wsq+pHt9yPePuNLpeXDM9X4IeMNwsVPE9LAvzDq0BITVQyVEQRB+g8xQr+6OEeYe2iUK+gXlk+uz88urZ7c3Djp/SuC9BeckgiFiL+SzwbmAKsQo0qMiv92LxNWTpb14KuxQFVEI4jiFAhXhmqc2CJhKNfPjBfptDXmZDxBbwHl9oLkJznINot08VOxMz4atTVqEd0i7m4khgl5X9D76YaC3hfKfOhdVhs2MSL1Bn6lacxsSK+n3bPFV6sZamWDrAZfWlyVXAi0cijlNWpqnKaHSMzbJjTSNFosb1p9Qe9XY7xQ/iSZUIh7+TRJ3oxrccmU7pjZ8AMDzR8YALVAFwS9lytNGINFB5xh3dZrHb/gbvvyXansP9nRWNXV9MBMoGVgLqodkEKEUQdwUjvDIuOToD75oXKGG5zw/Z3vvJHovmETAwU9giDbh+gc+jFPuG+srSyvBYLeO1LK/TtG65G+w5cRZkzQuzNGKmBUiTEFRhUMB5jlq5ByTMhaEMzrMCzwg6OhsPNXUrr/myDoPYHCTF7NAy0T6qoTJ8uqGU/Ql7lAr0kof30wLIkQSPMMtbOuptctTXcFvQnMhLwJhTLky17qukV0S9M9oayF4lWYHG9ydWhpzNGMqmZMEcPVcJY7CtIigj5hU3+udYzIbBn5lVE1PxBq+qigH4kIeo2aGi37eJreFdlCPDtB04cjHC6f/r/Gq4gbDtGIoNd0S2OWZpha3tRGTK1gEsMNcouCPiKgFTnUDEvLW1rBJHmL+ILe1fQatTKhqQSjU7cIoYrlF2OEc6WMkMj8Je4jjMZMjZVd/NGvRbzPSpOEVQiz3aQb1fSEWSS6KJkwKxsK+sDmI4I+w6wM96khOgotE8YPej0prxkOCei2g0IQBGkd+S43XmB+TBTxMzUM0iP9RzgbxHAllP+jJ+gd4kboXSESmToiBwwzKujD8DxQhaD348QaNd3oaWxOgslPucmwikZtTtAHoXRByot6C1gk3O5H6ANBH0Toy2B4gp6Ttv7knJia9xUSL+BsV9OHEdlwCGT504p8QS8JQvuV6eJNARI1vaitWajpXTUvCnpXzXtC2SS0zOFeGYnUasyWaGVhylCos/2mD/41VJll7huLi28P/CpS5kboTT9CH+RTMfM+0jRhTrznuI/iIvQQDFFYuAUNL+jjs8IIs8T1JIbtCXqZGbgqmZPyXq0Samu0otEqoRUSNyGDf4K8n2pc9nhBH4nQ6+IumfysGyJ0BImg9zEsL0hvYIQeQZDtgFzQz9S8qLz399oC4VR+1zONIA0Rhgb5OcfBckNvAr3jC1Mr1Bzc7IWIpjdMMEz/UdyKPS8cG59Gb2osFPTeUkLJDONgkSW/CDKQ+wLxuRBuScv+PBM3eBnMoQ/EtAnMVfP+tKJgLSZ1NOpE1VhZgJuP5JY9mEMfCHqLMEvzdVLwxUALBwzeVBmNcpreiIZR3Yf486cDee1FZLkpN5HvJ4YFhh18jXF1PIQEe+THZ29bXEtZwUcGr4yioOee4wn6MAlhVauwoNO70QjGlkENeAXnt8Dn5v1HlkDILFxcWesvirWBBstCpGW3iZdQ2RvtGLaL302i5icxg2DAZmvU0WjFNyFOXhtBvQU5CSL9ZmwdNi/obfAHhyAX9Pz0/XAtR+SbEhUEfTDGsAAFPYIg24WIoA+3p/TVPGGWO7fe/R3n2yD9CNBQ0HtiJaKbI9vwxaY62IH61Gg4sd4T9MzyRa3D7SoY14tqNR8G+4MFpvzuhP6MmkDH676ap6KaJ8FkIS7aGuqksJgmoaEg8xVVsKKxAsyBMOIuh5t+Y5GI9DfDshie0Hc/SnCCPqjSskbLhPGzMgJB7+nsbFTTc1MsIkucObnmbh7vBsvL4awPGjw/0joZTtNHVSZXLXpU0DPTG3359Qm0DHrJD9J7BuA+POsnQTilLot8B5l3giJwa3ltwqnkkNi+Oq5BkkijOwpB77g7KXnjVb0cfL4AwwHD9leJ+CMuvjKFOWnBqEO3NT34yONOaLH9eUq8oDcJ5Ye4wSoUh0g0veVOdo8Les5m+D09I+NeIo6BA0MtASt7mr7bDgpBEKR18GApZPvjiTlXzedt8CbOOhpzPHGpm0TnZz54Ykijdka3M2FEmZtp4EXovR1pQkGv+2suPc3kC3pW1vy5H7649MOWvgLWjApx9ZygS1g5mNERCno/oMsJuMjsfz8YzC0E9AUoP61cY2bG8OQUsAqwajpBXyasTKhXKO93o+yPTxxiVIjhCtNyhpoZamV0O6PbGd1xqzRDzYwv6Anz5//4otYXxFbW1fSGpQWIkXuTBHN1qA16UHtl2Rxudxa1oxmOZjgZw84YNjf9WiroHaL7atJvMsIswlyR7athvQQ6J+ipp+YHmZ1ltmbYxI18h4dVCYsfgvA8L+jdjy1uQpVwAxm3vP6keXemjfDxwTNv5mi0Ehf0vpqv+DOOyppeIrRMvAh9xdX0Xp2IHzrKopm5dqVbWs7Scpam2xp1NOZoRoXT9G69+TXsj28zoqB3+C2nvDoxnPBMgFDQR22GOpygLwuynl+mAtRV80VgrrmioEcQZDuAgh7Z/mjekk1XGZeAWZCvgFHJGBVNL8LwQaKXNKMKzPZCd7QEtES8YYBJDHPAWxHrALO9qF6+ohlOhtreY0NVUSHM0QyHMAtoSWNm1rCzzM5SX6gxm7BKiFEhhqPlbS1vZQoWyZlwYYkMmxnDIiMWHLA0dycZb4GsA7RKmDNo2MQwwShljcpZxrGsUYF8EYyyv86vQoyK5gPuCkVmDubL2Xwlk58GVobcGDATRo5BoaIZRW3Y1C60ybA/DT1v+1H2EI05Wd3JUIdQhxQc7aIKKThEd0iuqA0fyujlrDGpGVXIO2DYbmA+S8sZd9lxoFOZSZg5yEzNq0/HlY/BbObg2FHNMAkrEToBzIH8NGHOgF4C6t5VzbBJopcgNwb6EWDlbH7qzJHrssaU23buwgO33f3ochFYmRim18RGBfLHNFYd1MtZb3caLyeegsxXNOYMUocwODYTpwAAIABJREFUa0Avg+4pdXdBgj+48sdmwUpid+cZw4KcA3sqkHOIYWcMM8tKoBchVwRaHcgfz7Cqpof5JFwbEW6GmLfNkZe6qVEryxzCHG/ptpsBvThIp84yrh+kR2HYguEjMHwVsCIUJkm+kvFqIBiG2VmjkvGOOLD4OUha8GWDmRqzMoaVNbgvBt4o18mw6gCbJMYkGJOgm5mhIxndzhjHiG7D8BGimxqtElaBvDt6sTRmDbgNbbgDRa/5wKhA3h02OBpzdlAnQ21vTYhhgz9IBu/HMhgmyZtg2MCqml4czF2t0RLkpzL56s68M5h3Mn6KQK2Mu7ybWYSVgRaBlvzVJo73DcrtU7Sk5Q4SfaLrDgpBEKR1UNAj259sfjJjOBo1iT4BucPATChMQr6azVc0/RDseTbRxzOFY5CvgFEENg70CNBxoBNgFGGkBIXyzrxJ8g4EO+HkJ0nhaMaoDui2RstAx4GVfMUwqRnVTL4CtAy5IxotD+Yrg6y6g04CcxVMlbCjPlMam9KMaiZvZwvmwEiJ7JmAxxzJ7CntGLG1J9lwqZMtHNUKM5oxqTEH2BSwGc2YOrvgZPIlMI7sMKaeYLxwsDAFI4chX8wYRzVjSitMZ/JHM/mjmfxUNj8JzAa9BEZx18jEzn1T2f03AjNh6DmQt+FJL4b9R0n+iLa7mHm0ldlT0vZNaCNlrWBr+ar3tLzHAJ3amZsayE1puSntwFFtdJocOAq5KW1oIrP7BTty5V35awfyM1CogmGBXtT04g69OMgqYByFfBXyNuRNyBchX9pplDTDBmMSjKOQn3aVmTsKInoZckVCi5pRAnoEcgeBVaBwI9DJnUNHQDfBmAQ2nWXHITcOey6H4auAFneOXHPek+bOGDnuNRwtArOzxpRmVAizgJaAjgOb0PIlYBOgHwZjEkZuAja1c3g8q5cIs8CognEUjEkwKpCfhJGjxJjcpVeBls/Ui6CXgdqgO4O5aka3gZqgF0EfB1oEwwRmZ2iVGBUYsUnBGiiYsNeBx0/B3goUbGKUBukRGD4Eew4SferMkZsHjemMPgF6EWgJmK3lp4A5kCsTWs4aJWAlYCUw7Ex+EqgNw0XIFUGfyFBzB6sQVgVWBWYDLYNeBP3ILuP4Ewqv2KVfB7tN2H0l7P5VYIfgwDQZmcwY7hi16D2T2TuMqSyraO7ttAi0DMwmRiXj2gktAS1laWmQlXfmTTBck6sCtYFViDE5aMzsMq7N5q+F/LVaztpx4VWDw5WB/AuJ7sCeKyFXyhgzpDAJIzYYJtBShpbPoBbQKrBpoJNAbWCTYExD4SiMHIXCFOQnM8bkLlodoBbQCWBlyFtgVDJsktAKuIvC9QkwitpIGQoVMKYHckfO3nv5gD4BhWt3FKYfXajuGnEGR2wo2JC3gNkDuj1I7R2GTVgR6GFgE8DcYlY1Y0rLT2fyx7L5a7J6cWDPczPDY113UAiCIK2Dgh5BEARBEARB+piIoJ+peYtfN/wjY1U/evvTn9zcwH1vEARBEARBEKR7fPCDHwxPip2Z9faY57aqlP84v+bteAOzK7zQRxAEQRAEQRBkKwkFPf/r6OI6v3Ol8COwhWVfxPPiHkEQBEEQBEGQLUYi6IXTYeM/uiLePTIWxpZWcX96BEEQBEEQBOkSoqCvq+a9X8aWVr0jqFaWMUKPIAiCIAiCIF0iIuil82eSJ9UAW1jGdbEIgiAIgiAI0iUign6m5k2k4ZH+yP9rfLY9giAIgiAIgiBbA7/LTbATpTuXJlj/Kv5I3AWy0V8QBEEQBEEQBNl65LvcIAiCIAiCIAjSF6CgRxAEQRAEQZA+BgU9giAIgiAIgvQxKOgRBEEQBEEQpI8Rtq0Ml8AGO9twP+L2lAiCIAiCIAjSW8i3rYSxpdWTKzPCobCzK7inDYIgCIIgCIL0FBFBP7q4vlFbIK6gd7et9JU9URwiiyAIgiAIgiBIFxHn0M/UIrvL81F5PlqPIAiCIAiCIEgvIInQe5Pm3Qg9CnoEQRAEQRAE6WGEk2K9Za/B7BqccoMgCIIgCIIgvYwg6D29Hgp6XBSLIAiCIAiCID1MdNvKsaXVpG0rvVA9giAIgiAIgiA9Ah4shSAIgiAIgiB9DAp6BEEQBEEQBOljUNAjCIIgCIIgSB+Dgh5BEARBEARB+hhR0I8urksXvwq/e+dP4UpZBEEQBEEQBOkqoaAfXVzfOLm5WltZjWl0f/ebYEP6uZlZbw+cmdrmRm2h68VAEARBEARBkNMTMULPnyTl/eIeODUr/u4yuriOm9MjCIIgCIIgSLeoL+hnauKRsQF4diyCIAiCIAiCdJc6gh5mV9wZNYrIPap5BEEQBEEQBOkmSYIe2Nz8WrD41WV9fiz8J1TzCIIgCIIgCNJd6k+5kf4+U9tcXZzreu4RBEEQBEEQ5DRH3OWGhw/ARyP3C8v8lbgoFkEQBEEQBEG6BB4shSAIgiAIgiB9DAp6BEEQBEEQBOljUNAjCIIgCIIgSB+Dgh5BEARBEARB+hhR0I8urm/EdrmJ/8ivi8XtbhAEQRAEQRCkW4i73KzWVvjtKaU/Em7bStU2lwiCIAiCIAiCbAGp9qGP/zi6uB6eIIvbViIIgiAIgiBIl2hS0BNmzdRwE3oEQRAEQRAE6TItRei9mfSo6REEQRAEQRCkSzQj6IEtLJ9cnx8L/h45UxZBEARBEARBkC2jaUHviXgU9AiCIAiCIAjSRcRdbniWZy3pj8ST+LhtJYIgCIIgCIJ0GTxYCkEQBEEQBEH6GBT0CIIgCIIgCNLHoKBHEARBEARBkD6mC4J+dHG9i9Pum0ud39gn8ZpUKwrSX9lfwOzKRvdWSCe3UZ1/nV3ZqNe+LTK6uL6xtjTK5ubXtmHTb2/6tMN62wpHVzpJfzxNSOPGe4TT1l2kt8+6rdkjzd3GEiFbQF+3QijoebPbOLnpHgRLoutfky0yeqW4VQ5XX3Pza7GNdCJbYc7Nr3WqQqWp8/mX6tGutHGLiW5xnmdqSY2+BflsRdBvQRsFhyvP1Dh1FesywrZRM7UEgww76UwtPA5C8Ux5JgWbF5wAv5OV8KM0oejFYYreIXSJbiGspZORE+vSewZVPrtLSq/YuoElwJtc8o/tLHgjZiO/t2XzbroyW8l8UxUl5krqLk4r6ha8dUEvdVZe5bepcdtbouboa4W69ZlvLkVgc/NrXXv7BHkWBL3/Vh5bWj25Pj/WgLZuKDoLsyuCZW+ZoJem7jK6uL66th68RVpv43Y1Uldub7RKmz5f7DQR9IHVBRpd2mWEw9qSBP3a+mogaNbWV9eWRpOeKc+kYPORbui3aeRHfwCgSCgMKHK3z83Met1tprYp7V9BZoL3aKDhGhT0Yj7b29wNm0fL36z6XNCnMhv5ve0w76Yrs5XMt6WJ4+7idKPTgl7qrNyAwmptJb55dy+UqDlQ0Hc6RU/Nh6/RudEuaUWFoPfDhCnLBolfBr2oBvcij4fJVa9tft9MLo7IDYZqC/7tKzPBgNtPS3279BPByoyw434Qj6mtuNkbXVxfXVxyo0fuw5dnI2GbaLBzfX7W+yfPcciulOaTC2oKsag6xQxeA/Hbif9GjMVfxWc2NDHJbQ7xLRuUdG19NdKykYZT5VNKvJjSNlIXM2wO32z4UTV/0oKYz9jFm8uzjWU+ZZcBtrC8trK8tpn8Oge2sLy2NF/zdMbq4tKy+gO9qhfHbZ6/MogRCrePLq5v1JbkCYmPEjPvTySoXyFBos0J+kj+Y8Yg7cVSA0vftdM3cRr7TOjFKicQf2ZAGkHfolNN1xxys+mQeUtaU+YE2p75BAtp0QGmp5X3ZtBxBDtJbyHS/Eh7XEJcU7DP9K0pfyPEEkpwVtLTeLpYoi4amOK9mdYFKdsonS3JMi86gYRgYho/L/n4xplNWl83uyKtWEUxUzVcc2JPIei5/AWNVM93Ky+IC3rCxDC59LXNZ4lHcDH+wMN/4Y0trUZqRN4A4ieC2ZWN2gKvTflCBXOs/SCiN6eWF76CruVDrUJ7y66UWoP4opIWkzBrdGwuLIVMnHENwYedgkqWPdONVaRdEiDJp1B10oaT3q4iXkxpQknFdJuDu4CrmbAJpPnkv/snlD0lqi7jSplRv4CuoI8fB+FJnNmVjdrCTG19fmxheW1pNOGZUkGvsPkN0ddEbofZlY21dWn8m/etcTlbx0sI79RI1xY9g6xC5mT5XBqVGYOqF0v7kaLDyrt2qiaua5/JvVjq62TPDG5JI+hbd6rJVpdgNh0yb5W7UDmB9mV+TtWaLTrAlLTxvcn/PeXtUlQ9TupUpfaZsjUTXj1CQgnOKqWg35oSqZt4KwwsoZLTuCBVidLbkkLGBPaZFOKRtpG0d8iFRGpfJ4yB6/e4FA3XnNhTzaGPfQH0BhCNvbrqGYpw+qwkDucNPiLRfT6f8nc5X6HSkW68qYJQaDSwJ9aXYBP1BD1v30p9oMqn4l2uCrWKQ3DJ7TEXVvcjTBpZL08olg1pwymKGQlyRKdTR4opT6heMSVaMxatkb6h04uJdPavFvR+D0+O0I+G3qEZxSOxee5K6aQX34oaFvR1XURDgj6NHXqZkRmDqhdL+xF/YzyhhHe/sonr2qfim0lCa0qfyTd0sqBvi1NN0Rxys+mQeUvcRaITaFfmVRaS3gGmR+UqW39vekPciGdIe3scaY9L9gmxL0ipWjPh1SN+Q25Z0G9NibbMwKS2JK/k1C5IfXtaW5L+Hsrf2ZV634Ukfl7SOxQxFFk/ktRS2E3GwtB73WImN1xzYk8eoU9ob4W8iEwhSklUDQsNH8kJLyvlnTMx81JVGkudr1ClWOyQoJfmU/EuTxxcJksBZZdTr2BO+30mraBvWhNLi9mKoOdzUneuSAcEvbzLBILejWes+gJUHsL0XZt/l/qZkiG6zOYjtcQ3XHj7TG3TnX4gSUhRjQmuQ6iQFFNuvH5XN0LvzteXGkPdl3Fyh00t6BXN0QZBH3MC7RD0rTvVBKtLMJvOmbfoLhKdQPsyn/TabqMPqUvT700/z+H4uQkLEXLSivxN35oNCPo2TLnZihLVtc+OGpi8klO7IPXtqU1R2rtj9pm+jeS9I/GjaH1fF/1OG3qtxAU/yQ3XnNirI+iBLcyni7G5yk8+YVQ25YZw2iVo7HDeqqdp5kb558s2PUgqvOJ2SercDJxwHMmtqxtdXA+m3LRd0Kvy2Yig9xNqcsqNpCN5L6oUgzSFPharTtpw0nwqUpEUU5pQwre/+KdYLsORDhnPZ3un3PjZELsMb5ZueCAxQi/+r/KZsoCKxOZFo41J6uBzpDwhyTozol4NJqwyVCyKlXiGdBaiNAb1y1jSj+IWnlLQK5tYaZ8tCPp2TLlp0akKrZnebDpi3lJ3oXYCbcx8goW03YfIU2/tvRmax5o4mT797QJJsdIUE1TSt2b6V4/KWQlNxv0SeRtuWYmkqW+ZgckrObULUpUovS2pMh+3z5RWJ+0dCiGRJCCjmZybX9uMv+8UxUzVcM2JvfqCXrp7l7xUkS29OF+pEPRu3UkWJQh2rPgCHouISC1McruQevw7frB0L4i+rC4udS5Cn5BPYb+/OuL7pB9G4q1E+DSjXBQr6QkJbS02fWxhSpBQUHXShpMWM6F/xosZb6OEYi7XIj9GTSXJwFrPfMouEx3lKofQKsWjfGYkiLg+P6ay+ciVsokosX4t9NnwYsUUJj7bsW1D4ttWSj2DvDJV+ZQvipX0YlU/alrQK2tJtXpM9syUTqCdi2KbcqoyTZzWbNpt3ip3oXQCbcx8Qmt2wofUM7mG35uqvtnQ7QLqSW7yConbZ/rWlL8R5C5ddFbx7y1cNDSVoO9EidIL+rYbmJvQ6lq0NlK7IOntjdqSNPPJawwS2kjVO+JmU1dARisqlWZI33DNib0unxQrOO7TKvVthmof+jSfL7tOwkp5pKPM1Doy2QDpCn3dmn2deQTpBC1+Pmr716eA0/Z8hmS6LOhJfx4ci0gJgjrR4WbvviYTgprIFtV/gwtvkJ6lr1uzrzOPIB2iBwW9F7DHAJyM7gt6BEEQBEEQBEGaJpWgj0+na4LOfXzZety5d02H9hNuF2qpLTWPIAiCIAiCbGPSCfoU6w/q0o+CfuvzLAr6dtQ8giAIgiAIso1JJ+hTL2av95A+06bdF/TtqHkEQRAEQRBkG9PMHPrRxfXVxaXlk5sbtQV3Dx1u/07FjksnNzdqK8vxDcXSb4W5tr4q3YKKP+FyNjymy7tdfqW7P1T4o5ClyHFi0X2L+J2M4ruexTdsErKkvF1WSwiCIAiCIAhSlyYFvb9n6ubq4pyw2Sd/ZfpTCaQknErAb/MZnD22ER4+Eu7NKb8yUOeBoB/zxwCJZzP5GYtvJC8/UiGeJcntiWceIQiCIAiCIEgCTUfoFWekCccfKMSx5MrovvpxHRzcHjtGpM5R2wlX8kQvblDQN3KWu/z2eikiCIIgCIIgiJR2CvrgX8MZJolSlb9SSoKgF0/6VAt62ZWJXxISz133r0dBjyAIgiAIgvQEEUEfP2FYiuJA3bnIie7uhPWxpdXIDHv3QF3JlVKktxM3wB89VkClnhVXSgU9fyp7u6bcpBP0imIiCIIgCIIgSF3aKOjD5Z78fPFgsenq4pIXYldcKSVYbBrcTmLzc1RTbtRXShINF8XWlubXNvlZ+PGsCoqcz6e4KDaFoJfWUtctA0EQBEEQBOkL+uakWEETIwiCIAiCIAhCelzQR+PrGLdGEARBEARBEJGeFvQIgiAIgiAIgiTTBUEv7IqzxTSXeprNZ8DfmD/d01Jd2V+4CwmSTwrrYOqJbVTnXzu//f/o4vrG2tIom5tf24ZNv73p0w7Lb8XLnbUn+fE0oY/2EDtt3UV6+6zbmj3S3G0sEbIF9HUrhIJe3LXdXxobXcOauMtkutWuwObm1xL3mWFz82udqlBp6nz+pXq0K23cYqJbnOeZWv0lzh3NZyuCfgvaaHRx3e1TwWFnRNZlhL1WZ2oJBhl2Un43J8Uz5ZkUbF5wAtzybvFHaULRi8MUpSvLlbXEnURBGvEMqnx2l4b2AGjFwBLgTS75x3YWvBGzkd/bsnk3XZmtZL6pihJzJXUXpxV1C966oG/RWW19iZqjrxXq1me+uRSF/Ve2+O0T5FkQ9P5bOdx7Ma22big6C7MrgmVvmaCXpu4yuri+urYu3eQHBX3dKhW2B936fPa4oA+sLtDo0i7DHzBMkgX92np43sLa+mp4FlvSKQ0Cgs2L+7e6zxT3a9pcnlUlFAYUudvnZma97jZTS9pEyz+C2r8ynnp9QS/ms73N3bB5tPzNqs8FfSqzkd/bDvNuujJbyXxbmjjuLk43Oi3oW3RWXSlRc6Cg73SKnpoPX6Nzo13SigpB74cJU5YNEr8MxnfDjIfJVa/tMGIXiSNygyF3w3sv8/6A209Lfbv0E8HKjLC/ZBCPqa242RtdXF9dXHKjR+7Dl2cjYZtosHN9ftb7J89xyK6U5pOLEwixqDrFjJzaGw+gyrfXFJ/Z0MSk+C6ckZKura9GWjbScKp8SokXU9pG6mKGzeGbDT+qFvcVFT9VxYbgDWU+ZZcBtrC8trK8tpn8Oge2sLy2NF/zdMbq4tKy+gN94unIEZvnrwxihMLto4vr7taukoTER4mZ9ycS1K+Q6EFyDQv6SP5jxiDtxVIDS9+10zdxGvtM6MUqJxB/ZkAaQd+iU03XHHKz6ZB5S1pT5gTanvkEC2nRAaanlfdm0HEEO0lvIdL8SHtcQlxTsM/0rSl/I8QSasVZbXGJumhgivdmWhekbKN0tiTLvOgEEoKJafy85OMbZzZpfR13eFG09qTFTNVwzYk9haDnD1fyG6me71ZeIN3eXgiTS1/bqj3jBRfjDzz8F97Y0mqkRuQNIH4imF3ZqC3w2pQvVDDH2g8ienNqeeErHhfFhVqF9pZdKbUG8UUlLSZh1ujYXFgK9alY6gOwZM+sd45v3XwKVSdtOOntKuLFlCaUVEy3ObgLuJoJm0Caz/ghZQ1lPmWXcaXMqF9AV9DzfdjvyUveZbWFmdr6/NjC8trSaMIzpYJeYfMboq+J3A6zKxtr69L4d/zI5FgfV3uJ6L/KT1z2PYOsQuZk+VwalRmDqhdL+5Giw8q7dqomrmufyb1Y6utkzwxuSSPoW3eqyVaXYDYdMm+Vu1A5gfZlfk7Vmi06wJS08b3J/z3l7VJUPU7qVKX2mbI1E1494hGTLTirrSyRuom3wsASKjmNC1KVKL0tKWQMf9CQsmjSNpL2DrmQSO3rhDFw/R6XouGaE3uqOfSxL4DeAKKxV1c9Q+FfmfI4nDf4iET3+XzK3+V8hUpHuvGmCkKh0cCeWF/SQ7X4KhLDeOkOlpLmU/EuV4VaxSG45PaYC6v7ESaNrJcnFMuGtOEUxYwEOaLTqSPFlCdUr5gS9x2L1kjf0OnFRDr7Vwt6v4cnR+hHQ+/QjOKR2Dx3pXTSi29FDQv6ui6iIUGfxg69zMiMQdWLpf2IvzGeUML5GMomrmufim8mCa0pfSbf0MmCvi1ONUVzyM2mQ+YtcReJTqBdmVdZSHoHmB6Vq2z9vekNcSOeIe3tceSHUSb6hNgXpFStmfDqEb8ht+CstrJEW2ZgUluSV3JqF6S+Pa0tSX8P5e/sSr3vQhI/L+kdihiKrB9JainsJmNh6L1uMZMbrjmxJ4/QJ7S3Ql5EphClJKqGhYaP5ISXlfLOmZh5qSqNpc5XqFIsdkjQS/OpeJcnDi6TpYCyy6lXMKf9PpNW0DetiaXFbEXQ8zmp+/m1A4Je3mUCQe/GM1Z9ASoPYfquzb9L/UzJEF1m85Fa4hsuvH2m5p+mHE9IUY0JrkOokBRTbrx+VzdC706BlRpD3ZdxcodNLegVzdEGQR9zAu0Q9K071QSrSzCbzpm36C4SnUD7Mp/02m6jD6lL0+9NP8/h+LkJCxFy0or8Td+aDQj6FpzVVpaorn121MDklZzaBalvT22K0t4ds8/0bSTvHYkfRev7uuh32tBrJS74SW645sReHUEPbGE+3bDVVX7yCaOyKTeE0y5BY4fzVj1NMzfKP1+26UFS4RW3S1LnZuCE40huXd3o4now5abtgl6Vz0YEvZ9Qk1NuJB3Je1GlGKQp9LFYddKGk+ZTkYqkmNKEEr79xT/FchmOdMh4Pts75cbPhthleLN0wwOJEXrxf5XPlAVUJDYvGm1MUgefI+UJSdaZEfVqMGGVoWJRrMQzpLMQpTGoX8aSfhS38JSCXtnESvtsQdC3Y8pNi05VaM30ZtMR85a6C7UTaGPmEyyk7T5Ennpr783QPNbEyfTpbxdIipWmmKCSvjXTv3oaclZxDbNlJZKmvmUGJq/k1C5IVaL0tqTKfNw+U1qdtHcohESSgIxmcm5+bTNuQopipmq45sRefUEv3b1LXqrIll6cr1QIerfuOF0b3B61Y8UX8FhERGphktuF1OPf8YPVMEH0ZXVxqXMR+oR8Clto1RHfJ/0wEm8lwqcZ5aJYSU9IaGux6WMLU4KEgqqTNpy0mAn9M17MeBslFHO5FvkxaipJBtZ65lN2megoVzmEVike5TMjQcT1+TGVzUeulE1EifVroc+GFyumMPHZjm0bEt+2UuoZ5JWpyqd8UaykF6v6UdOCXllLqtVjsmemdALtXBTblFOVaeK0ZtNu81a5C6UTaGPmE1qzEz6knsk1/N5U9c2GbhdQT3KTV0jcPtO3pvyNIHfpaZ1VekHfiRKlF/RtNzA3odW1SJbSuyDp7Y3akjTzyWsMEtpI1TviZlNXQEYrKpVmSN9wzYm9Lp8UKzju0yr1bYZqH/q6iqcXSFgpj3SUmVpHJhsgXaGvW7OvM48gnaDFz0dt//oUcNqez5BMlwU96c+DYxEpQVAnOtzs3ddkQlAT2aL6b+tOz0gX6evW7OvMI0iH6EFB7wXsMQAno/uCHkEQBEEQBEGQpkkl6OPT6Zqgcx9fth53pl3Tof2E24VaakvNIwiCIAiCINuYdII+xfqDuvSjoN/6PIuCvh01jyAIgiAIgmxj0gn6/9/e3Rspj6xhAIVcSIEo8MclBFURxHgYimENqvCUAQmoxiUJKEK4hv5arRbwze4i6e6pOsZ+Ggk11BqPWt3v+/Zm9lcfsrBsOn2g/yd+eQAA/o/9Zg39Nr+W+el8e9yLY1VDJ6jfOVJx6fa4F5fzsKDY+6Uwf65lsgRV2OEy69p01Zenz6zqQ3UHoyH12on16xaFlYyGVc+GBZuiIY1envqVAADgpV8G+qZm6qPMD1Gxz/DM97sSJD3pShCW+Wx7j9275iNdbc70mW06bwP9rnkGeNqbqRnYsJB8uqXCcEiJy5/2PAIAgCd+PUM/0iMtan8wEo4TZ/br6g9zcHv5oI3Ii1bbT84M9U/+w0D/J73c05e/uiMAACT9k4G+/Wu3wuRpVA3PTHoS6ONOn+OBPnXm0zcJT/uuN+cL9AAAzEIv0A87DCeNNNQ99Dq6VwvWd6eyt8K+aqibODMpefm6muDvtxUYS88jZyYDfdiV/Z9acvNeoB/5mgAA8NI/GOi77Z7hevF2s2mZn+op9pEzk9rNpu3l68H6nLElN+NnJm7abYotTt8/j3AV/nCoUSIPxxlvin0j0Cd/pcn/zwAAYBEW0yk2ysQAAMB65oG+P79u3hoAAGKzDvQAAMBzAj0AACxYL9AnN4BWmmZSz44AAAAf1gX61eawz+qS8Pui3/WprktTx/e6fnxxsUsVAACmlV5ys82vQaek4/l2/c7iIjPKzgAAwOQSgT5qsLovHucsEd8FegAAmFwc6KM03+/5KtADAMC89DvF9juYRm1Wo2LwAj0AAEwurnJT5ofkeWboAQBghsIqN8dzOBnfbIqthPG9qnITaif1AQCAT9JYCgAAFkygBwCABRPoAQBgwQR6AABYsF5hsY02AAAHYklEQVSgD3a7duUp+8eVtQEAgBlJz9Bv82tb5WaVXeR4AACYp3SgbwvSR62mAACAWUl0ir3fuvZSq83xfLt+Z6fy1jsOAADMwegM/b04rutAXzeZqv7bbD0AAMxHOtC36+ajEN8uxQEAAOZgfIa+2RTbn63vVb8BAACm1Qv0++IxLE/ZLqy/W28DAAAzo7EUAAAsmEAPAAALJtADAMCCCfQAALBgUWOp47neFBuXp9zm13CnLAAAMAdxlZsqx692pzIsdLOrOsUK9AAAMC+9QL/Nr3XJ+d2pbOrQ1+Xns17EBwAA5iBeQ1+Xom/SfHXknMVz9gAAwBwkZujrlfQ/p+3ma5Vdujl7gR4AAGamC/T10prd17rZHXvOuh6xjfoEAABgDqJA/zhnX+su0HfnmaEHAIAZ6petrKvZJMpWCvQAADBDGksBAMCCCfQAALBgAj0AACyYQA8AAAsWB/ptfr33N7/WZen7NSuDg/H2WQAA4GO6QL/Nr/fboywuYTWb1ebw/VNH9lV2aTvI7ovmoOo3AAAwnXiGPgro4T/D4vRVT9n6hCblAwAAH/Yq0Aez8uFs/XrztS8e99vjLs0DAMB0fhnoqxn6eiW9TA8AABP5zZKb1eZ4bjbIhutwAACAD3sV6FObYsMQL9ADAMCE4io3oTCy32+Pezxzr2wlAABMTGMpAABYMIEeAAAWTKAHAIAFE+gBAGDB4kC/za+9za/djthHUJA+cRAAAPi8uMpNWVzKKNAPInvyIAAA8Hkv69AL9AAAMF9vBPphEfrUQQAA4PNeBPpWtLb+yUEAAOBj3g30q92pvF2/d68PAgAAH2OGHgAAFiyuchM6Z1W+r/7ZzcQnDwIAAJ+nsRQAACyYQA8AAAsm0AMAwIIJ9AAAsGBxoFfNBgAAFiSuclMWl7BsZfIgAAAwE2/VoR8rTg8AAExLoAcAgAUT6AEAYMEEegAAWDCBHgAAFiyuchM6Z1/Jg5MPGgAAqGgsBQAACybQAwDAggn0AACwYAI9AAAsWC/Q74t282tX0ybYF3v93n2tN1+rzfHcbpP9OW2n/g4AAPCf1QX61eawzw7V0X3xuBfH6NRtfq3i+2pzPMvxAAAwA+klN212Dw/ui0eZH9YCPQAAzEYi0Fcratp686vN4fvncb/VaX7dW3Kj2xQAAExp0Cm2n+ZDw3U42/wq0wMAwIR6gb6ajB/rBbvKLlF8X+1OZbNTFgAA+Ly4yk27rmZoX8Q1bczQAwDAtMIqN0ExyqAe5bCW5Wp3KvuFLAEAgEloLAUAAAsm0AMAwIIJ9AAAsGACPQAALNjIpljVbAAAYAn6gb6f49d1lH+UxaUU6AEAYH5eBPrKancS6AEAYIaSS27i7C7QAwDAPCU2xQ5XzAv0AAAwT4lAv9qdyn4LWIEeAADmyQw9AAAsWLCGfncq6zX03fR8VeUmdM6mHzQAAFDRWAoAABZMoAcAgAUT6AEAYMEmCPTb/Frmh6m+8O/uvtocz/3KPyPnPN758PfPBACA55KNpR732+NeHKszgs2yj/vTGNo/c7Qqzmpz+P4Z9K4KEvNqc/j+eZGefy1593D8yV2/7wT6f2Gof+umk4wZAIAPiwJ9nXTbUvTvZ+tVdnm/Bs4qu0QPBh8L9Mm7V7b5tfy5tk8yY8P7GIEeAICXRgL95ni+Pc7Zu6FwtTl8/4xO3tcz90FQHk6TjwX6sG5m+7RQ3S58k9AMvnnJ0Nxr/PLkK4LLvl9xv3vnUFyq4W3za5mfzrfHvThWH37Oeq8mgrscz7frd1b/qfpxkmcmx7kvetVCqzce73zN6kbJy9fNc1d4o+RnTrssCgCA940E+uwyjIBPZt/bB4D0XweBfj2YJk8G+nBIoX3R5OPN4funffBoUu/uVPZSfmpIw1cE2eVeHNsPjL7UKrvcm0B/b+JvmR/C4Bte215+/zlt+7/nyJmJcQ6fppJfc7352u4O3bfoPZUNO/42P3L3EmbkM/Pr8xVWAADMwdga+nhWvpkUH8nHTwN9UpRix2bo65nm3ux+f63/7VHmh7E3CcPLk3evzqzGv83rVTfJcFwl+PbyV4E+TM+jgX5snCOBPvE1+7/JeKDPLtUDRjiG5y9hxHoAgJlLz9AnDWNo9Kfk6vMn+mk4CvS9kYSxMvnw8HzwyVQ6uPtgfcsHA31ynCOBPrlYqHmTENzoTwL9+A7mN97PAAAwoReBfrU5fvdT7+i6muwyNpWbXHJTf2A/X3YLzauVKrvDNvz85hP2xaMNpsHYBoMfuTxx92AFTjuSsOjNNr/e/7VAPzbOPwn0zY1+ueQmEejrdfl/+JAGAMCHvQ704dT182naftnKLkqOBfr15mubX4Nc214ehs5EHczepthuyc0w0L8oo1ndfVhUZ5tfqweGdrNpmZ/+vRn6J+MM9raGm2ITX6TZInwKV0ZFl6+fbYqNP9AyGwCARZi4U2w4Tf5fuzsAAPx9Ewf69dSTwaaiAQBYtOkDPQAA8GsCPQAALJhADwAAC/bXX3/9D+XJsWzvRzmZAAAAAElFTkSuQmCC" /></p>
<p><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://blogs.metcorpconsulting.com/tech/?p=1594"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://blogs.metcorpconsulting.com/tech/?p=1594" data-text="Powershell command to view the VM Generation ID associated with a virtual 2012 DC"></a><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://blogs.metcorpconsulting.com/tech/?p=1594"></a><a class="a2a_button_google_plus" href="http://www.addtoany.com/add_to/google_plus?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1594&amp;linkname=Powershell%20command%20to%20view%20the%20VM%20Generation%20ID%20associated%20with%20a%20virtual%202012%20DC" title="Google+" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/google_plus.png" width="16" height="16" alt="Google+"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1594&amp;linkname=Powershell%20command%20to%20view%20the%20VM%20Generation%20ID%20associated%20with%20a%20virtual%202012%20DC" title="Facebook" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1594&amp;linkname=Powershell%20command%20to%20view%20the%20VM%20Generation%20ID%20associated%20with%20a%20virtual%202012%20DC" title="Email" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:print()" title="Print" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/print.png" width="16" height="16" alt="Print"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1594&amp;title=Powershell%20command%20to%20view%20the%20VM%20Generation%20ID%20associated%20with%20a%20virtual%202012%20DC" id="wpa2a_22"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.metcorpconsulting.com/tech/?feed=rss2&#038;p=1594</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Active Directory Domain Administration Report (Administrators, Domain Admins, etc)</title>
		<link>http://blogs.metcorpconsulting.com/tech/?p=1588</link>
		<comments>http://blogs.metcorpconsulting.com/tech/?p=1588#comments</comments>
		<pubDate>Wed, 06 Mar 2013 20:17:20 +0000</pubDate>
		<dc:creator>Sean Metcalf</dc:creator>
				<category><![CDATA[Powershell Code]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[Active Directory Admistration Report]]></category>
		<category><![CDATA[AD Admin Count]]></category>
		<category><![CDATA[AD Admins]]></category>

		<guid isPermaLink="false">http://blogs.metcorpconsulting.com/tech/?p=1588</guid>
		<description><![CDATA[I just posted an Active Directory Domain Administration Report Powershell script which enumerates all members of the default Administrators group in the domain and displays the expanded membership sorted by group. Here&#8217;s what I posted to the TechNet Script Center: Ever wonder who has full admin rights to your domain? The script discovers the default Administrators [...]]]></description>
				<content:encoded><![CDATA[<p>I just posted an <a href="http://gallery.technet.microsoft.com/scriptcenter/AD-Domain-Administration-82378ce6">Active Directory Domain Administration Report Powershell script</a> which enumerates all members of the default Administrators group in the domain and displays the expanded membership sorted by group.</p>
<p>Here&#8217;s what I posted to the <a href="http://technet.microsoft.com/en-us/scriptcenter/bb410849.aspx">TechNet Script Center</a>:</p>
<p>Ever wonder who has full admin rights to your domain?</p>
<p>The script discovers the default Administrators group by looking up the group by its well-known SID (S-1-5-32-544) in the domain and enumerates all user and group members. The expanded membership of the default Administrators group in the domain is what I call &#8220;Domain-Level Admins&#8221; or DLAs. Domain Admins are members of the Domain Admins group in the domain, but there any member of the Administrators group has full admin rights to the Active Directory domain and the associated Domain Controllers.</p>
<p>The script provides the expanded group membership for each of the group members.</p>
<p>Here&#8217;s the output example:</p>
<p>DOMAIN-LEVEL ADMINS:<br />
====================<br />
Discovered 3 Domain-Level Admins (DLAs) with admin rights provided by 6 groups:</p>
<p>Administrators Membership (4 Members):<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
Administrator (CN=Administrator,CN=Users,DC=MCLAB,DC=net)<br />
GROUP: Domain Admins (CN=Domain Admins,CN=Users,DC=MCLAB,DC=net)<br />
GROUP: Enterprise Admins (CN=Enterprise Admins,CN=Users,DC=MCLAB,DC=net)<br />
GROUP: GroupTest01 (CN=GroupTest01,OU=Test,DC=MCLAB,DC=net)</p>
<p>GroupTest03 Membership (0 Members):<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
No members</p>
<p>GroupTest02 Membership (0 Members):<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
No members</p>
<p>GroupTest01 Membership (0 Members):<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
No members</p>
<p>Domain Admins Membership (3 Members):<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
ADMIN (CN=ADMIN,OU=Admins,DC=MCLAB,DC=net)<br />
ADMIN2 (CN=ADMIN2,OU=Admins,DC=MCLAB,DC=net)<br />
Administrator (CN=Administrator,CN=Users,DC=MCLAB,DC=net)</p>
<p>Enterprise Admins Membership (1 Members):<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
ADMIN (CN=ADMIN,OU=Admins,DC=MCLAB,DC=net)</p>
<p>Script started processing at 03/01/2013 22:18:29 and completed at 03/01/2013 22:18:30.</p>
<p>&nbsp;</p>
<p><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://blogs.metcorpconsulting.com/tech/?p=1588"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://blogs.metcorpconsulting.com/tech/?p=1588" data-text="Active Directory Domain Administration Report (Administrators, Domain Admins, etc)"></a><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://blogs.metcorpconsulting.com/tech/?p=1588"></a><a class="a2a_button_google_plus" href="http://www.addtoany.com/add_to/google_plus?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1588&amp;linkname=Active%20Directory%20Domain%20Administration%20Report%20%28Administrators%2C%20Domain%20Admins%2C%20etc%29" title="Google+" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/google_plus.png" width="16" height="16" alt="Google+"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1588&amp;linkname=Active%20Directory%20Domain%20Administration%20Report%20%28Administrators%2C%20Domain%20Admins%2C%20etc%29" title="Facebook" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1588&amp;linkname=Active%20Directory%20Domain%20Administration%20Report%20%28Administrators%2C%20Domain%20Admins%2C%20etc%29" title="Email" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:print()" title="Print" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/print.png" width="16" height="16" alt="Print"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1588&amp;title=Active%20Directory%20Domain%20Administration%20Report%20%28Administrators%2C%20Domain%20Admins%2C%20etc%29" id="wpa2a_24"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.metcorpconsulting.com/tech/?feed=rss2&#038;p=1588</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Active Directory Forest/Domain Configuration Summary &amp; Object Statistics</title>
		<link>http://blogs.metcorpconsulting.com/tech/?p=1582</link>
		<comments>http://blogs.metcorpconsulting.com/tech/?p=1582#comments</comments>
		<pubDate>Wed, 27 Feb 2013 20:17:36 +0000</pubDate>
		<dc:creator>Sean Metcalf</dc:creator>
				<category><![CDATA[Powershell Code]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[Active Directory Configuration Summary]]></category>
		<category><![CDATA[Active Directory Object Statistics]]></category>
		<category><![CDATA[AD Stats]]></category>

		<guid isPermaLink="false">http://blogs.metcorpconsulting.com/tech/?p=1582</guid>
		<description><![CDATA[I just posted a full Powershell script to the TechNet Script Center that gathers Active Directory Forest/Domain Configuration Summary &#38; Object Statistics. This script gathers a variety of information from the Active Directory environment and provides a final report of the configuration. Running this provides a great snapshot of what is in AD and where [...]]]></description>
				<content:encoded><![CDATA[<p>I just posted a full Powershell script to the <a href="http://gallery.technet.microsoft.com/">TechNet Script Center </a>that gathers <a href="http://gallery.technet.microsoft.com/Get-a-summary-of-the-dc0e98cc">Active Directory Forest/Domain Configuration Summary &amp; Object Statistics</a>.</p>
<p>This script gathers a variety of information from the Active Directory environment and provides a final report of the configuration. Running this provides a great snapshot of what is in AD and where it is located.  Data collected includes: Forest &amp; Domain info, AD &amp; Schema versions, AD setup (instantiation) date, AD tombstone lifetime, the last time each partition was backed up, the percentage of RIDs used and percentage of RIDs available, a count of domain GPOs (for current domain), count of all sites and list of DCs by site, DC count total and by OS version, and statistics by object type for users, groups, and computers (workstations and servers).</p>
<p>NOTE: This script leverages the PowerShell v2.0 Active Directory &amp; Group Policy commandlets to work properly.  On Windows Server 2008 R2, install the Active Directory Powershell commandlets by running:<br />
<em>“powershell import-module servermanager ; add-windowsfeature rsat-ad-powershell”  </em></p>
<p>Here are the major components of the script:</p>
<ul>
<li>Get Active Directory Forest &amp; Domain Info</li>
<li>Get AD &amp; Exchange Schema Version Number</li>
<li>Get AD Instantiation Date</li>
<li>Get Domain Password Policy</li>
<li>Get Tombstone Setting</li>
<li>Get AD Last Backup Date</li>
<li>Get Domain RID Info</li>
<li>Get AD Object Count</li>
<li>Get AD LastLogonTimeStamp Replication Setting</li>
<li>Get Domain GPO Stats</li>
<li>Get AD Site Data</li>
<li>Get Domain Controller Information</li>
<li>User Statistics</li>
<li>Get AD Group (Global, Universal, Distribution, Security, etc) Statistics</li>
<li>Get AD Computer (Workstations &amp; Servers) Statistics</li>
</ul>
<p>The final report looks like this:</p>
<blockquote><p>TODAY&#8217;S REPORT<br />
==============<br />
Generated: 02/27/2013 21:36:29<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>ACTIVE DIRECTORY DETAILS:<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Active Directory Forest Name : MCLab.net<br />
Active Directory Domains in the Forest: MCLab.net<br />
Active Directory Current Domain Name : MCLAB</p>
<p>Active Directory Instatiation Date: 03/17/2010 00:58:06</p>
<p>The AD Schema Version is 56 which is Windows Server 2012 Forest Functional Mode<br />
The Exchange Schema Version is 14732 which is Exchange 2010 SP2 Schema</p>
<p>Active Directory&#8217;s Tombstone Lifetime is set to 180 days<br />
The LastLogonTimestamp attribute is configured to replicate every 1 days.<br />
This affects the accuracy of the User &amp; Computer logon stats below (they may be off by ~ 1 days).</p>
<p>Domain Relative IDentifiers (RIDs) determine how many Security IDentifiers (SIDs) can be created.<br />
RIDs Issued: 51600 (0.00 % of total)<br />
RIDs Remaining: 1073690223 (100.00 % of total)</p>
<p>ACTIVE DIRECTORY BACKUP STATUS:<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
DC=MCLAB,DC=net last backed up on 06/16/2011 15:00:31<br />
CN=Configuration,DC=MCLAB,DC=net last backed up on 06/16/2011 15:00:31<br />
CN=Schema,CN=Configuration,DC=MCLAB,DC=net last backed up on 06/16/2011 15:00:31<br />
DC=DomainDnsZones,DC=MCLAB,DC=net last backed up on 06/16/2011 15:00:31<br />
DC=ForestDnsZones,DC=MCLAB,DC=net last backed up on 06/16/20 11 15:00:31</p>
<p>ACTIVE DIRECTORY OBJECT SNAPSHOT:<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Active Directory Schema Partition Stats:<br />
4329 objects in CN=Schema,CN=Configuration,DC=MCLAB,DC=net</p>
<p>Active Directory Configuration Partition Stats:<br />
4329 objects in CN=Configuration,DC=MCLAB,DC=net<br />
9 Deleted objects in CN=Configuration,DC=MCLAB,DC=net<br />
0 Recycled objects in CN=Configuration,DC=MCLAB,DC=net</p>
<p>Active Directory Domain Partition Stats:<br />
2149 objects in DC=MCLAB,DC=net<br />
13 Deleted objects in DC=MCLAB,DC=net<br />
0 Recycled objects in DC=MCLAB,DC=net</p>
<p>There are 12 Active Directory Sites in the AD Forest.<br />
There are 72 GPOs in the current Active Directory Domain.</p>
<p>ACTIVE DIRECTORY FSMOs:<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
AD Forest Naming Master : R2D2.MCLab.net<br />
AD Forest Schema Master : R2D2.MCLab.net<br />
AD Domain PDC Master : R2D2.MCLab.net<br />
AD Domain RID Master : R2D2.MCLab.net<br />
AD Domain Infrastructure Master : R2D2.MCLab.net</p>
<p>DOMAIN CONTROLLER INFORMATION:<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
Out of the 3 DCs in MCLab.net :<br />
0 are RODCs &amp; 3 are writable DCs<br />
0 are running Windows Server 2012<br />
0 are running Windows Server 2008 R2 SP1<br />
2 are running Windows Server 2008 R2 (No Service Pack)<br />
2 are running Windows Server 2008 (Any Service Pack)<br />
0 are running Windows Server 2003 R2 (Any Service Pack)<br />
0 are running Windows Server 2003 (Any Service Pack)<br />
0 are running Windows 2000 Server (Any Service Pack)</p>
<p>DOMAIN USER STATISTICS:<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
There are 1008 user objects discovered in MCLab.net<br />
There are 24 Enabled users and there are 984 Disabled users in MCLab.net<br />
There are 24 users identified as Inactive (with passwords older than 90 days in MCLab.net<br />
There are 11 Enabled Service accounts in MCLab.net (out of a total 11 Service accounts)<br />
There are 8 users in MCLab.net with an Exchange Mailbox.<br />
There are 8 Enabled users in MCLab.net with an Exchange Mailbox.<br />
Out of 24 Enabled users in MCLab.net only 6 have logged on in the last 30 days (there may be up to a 14 day margin of error for this count)<br />
Out of 24 Enabled users in MCLab.net only 6 have logged on in the last 45 days<br />
Out of 24 Enabled users in MCLab.net only 6 have logged on in the last 60 days<br />
Out of 24 Enabled users in MCLab.net only 7 have logged on in the last 90 days<br />
Out of 24 Enabled users in MCLab.net only 7 have logged on in the last 120 days<br />
Out of 24 Enabled users in MCLab.net only 7 have logged on in the last 180 days<br />
Out of All 1008 users in MCLab.net 978 have NEVER logged on (no logon date associated with account)<br />
6 Enabled users logged in within the last week<br />
2 Enabled users logged in yesterday<br />
4 Enabled users logged in today (so far)<br />
0 Enabled users are currently locked out</p>
<p>DOMAIN GROUP STATISTICS:<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
There are 55 Universal groups in AD (37.93 % of all groups)<br />
There are 62 Global groups in AD (42.76 % of all groups)<br />
There are 28 Domain Local groups in AD (19.31 % of all groups)<br />
There are 133 Security groups in AD (91.72 % of all groups)<br />
There are 133 Mail-Enabled Security groups in AD (0.00 % of all groups)<br />
There are 12 Distribution groups in AD (8.28 % of all groups)<br />
There are 0 Distribution groups that are not Universal groups in AD (0.00 % of all groups)</p>
<p>DOMAIN COMPUTER STATISTICS:<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
There are 473 Computers discovered in MCLab.net<br />
There are 471 Enabled Computers and there are 2 Disabled Computers in MCLab.net<br />
There are 461 Computers identified as Inactive (with passwords older than 90 days in MCLab.net</p>
<p>WORKSTATIONS:<br />
After filtering server objects, There are 10 Windows workstations discovered in MCLab.net<br />
There are 8 Enabled Windows workstations discovered in MCLab.net<br />
There are 4 Active Enabled Windows workstations discovered in MCLab.net<br />
There are 0 Active Enabled Windows workstations running Windows XP discovered in MCLab.net<br />
There are 0 Active Enabled Windows workstations running Windows Vista discovered in MCLab.net<br />
There are 3 Active Enabled Windows workstations running Windows 7 discovered in MCLab.net<br />
There are 1 Active Enabled Windows workstations running Windows 8 discovered in MCLab.net<br />
There are 0 enabled workstations that have a blank DNS host name attribute<br />
There are 0 enabled workstations that have a DNS subdomain</p>
<p>SERVERS:<br />
After filtering workstation objects, There are 19 SERVERS discovered in MCLab.net<br />
There are 19 Enabled Windows SERVERS discovered in MCLab.net<br />
There are 0 Active Enabled Windows SERVERS discovered in MCLab.net<br />
There are 18 Active Enabled Windows SERVERS running Windows NT discovered in MCLab.net<br />
There are 0 Active Enabled Windows SERVERS running Windows 2000 discovered in MCLab.net<br />
There are 0 Active Enabled Windows SERVERS running Windows 2003 discovered in MCLab.net<br />
There are 16 Active Enabled Windows SERVERS running Windows 2008 discovered in MCLab.net</p></blockquote>
<p>View the <a href="http://gallery.technet.microsoft.com/Get-a-summary-of-the-dc0e98cc">Active Directory Forest/Domain Configuration Summary &amp; Object Statistics Script</a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://blogs.metcorpconsulting.com/tech/?p=1582"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://blogs.metcorpconsulting.com/tech/?p=1582" data-text="Active Directory Forest/Domain Configuration Summary &#038; Object Statistics"></a><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://blogs.metcorpconsulting.com/tech/?p=1582"></a><a class="a2a_button_google_plus" href="http://www.addtoany.com/add_to/google_plus?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1582&amp;linkname=Active%20Directory%20Forest%2FDomain%20Configuration%20Summary%20%26%20Object%20Statistics" title="Google+" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/google_plus.png" width="16" height="16" alt="Google+"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1582&amp;linkname=Active%20Directory%20Forest%2FDomain%20Configuration%20Summary%20%26%20Object%20Statistics" title="Facebook" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1582&amp;linkname=Active%20Directory%20Forest%2FDomain%20Configuration%20Summary%20%26%20Object%20Statistics" title="Email" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:print()" title="Print" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/print.png" width="16" height="16" alt="Print"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1582&amp;title=Active%20Directory%20Forest%2FDomain%20Configuration%20Summary%20%26%20Object%20Statistics" id="wpa2a_26"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.metcorpconsulting.com/tech/?feed=rss2&#038;p=1582</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PowerShell v3 Web Access</title>
		<link>http://blogs.metcorpconsulting.com/tech/?p=1538</link>
		<comments>http://blogs.metcorpconsulting.com/tech/?p=1538#comments</comments>
		<pubDate>Mon, 25 Feb 2013 20:17:51 +0000</pubDate>
		<dc:creator>Sean Metcalf</dc:creator>
				<category><![CDATA[Deployment]]></category>
		<category><![CDATA[Microsoft Products]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[Powershellv3]]></category>
		<category><![CDATA[PowershellWebAccess]]></category>

		<guid isPermaLink="false">http://blogs.metcorpconsulting.com/tech/?p=1538</guid>
		<description><![CDATA[PowerShell version 3 includes a new feature which provides the capability to get a Powershell command shell via a web browser. Windows Server 2012 includes a Powershell method for configuring the server with Powershell Web Access. Here are the configuration Powershell commands:  Install-WindowsFeature WindowsPowerShellWebAccess –IncludeManagementTools Install-PswaWebApplication –WebApplicationName “pswagateway” –UseTestCertificate Add-PswaAuthroizationRule –UserGroupName &#8220;MCLAB\Domain Admins&#8221; –ComputerGroupName &#8220;MCLAB\Domain [...]]]></description>
				<content:encoded><![CDATA[<p>PowerShell version 3 includes a new feature which provides the capability to get a Powershell command shell via a web browser.</p>
<p>Windows Server 2012 includes a Powershell method for configuring the server with Powershell Web Access.</p>
<p>Here are the configuration Powershell commands:</p>
<ol>
<li> Install-WindowsFeature WindowsPowerShellWebAccess –IncludeManagementTools</li>
<li>Install-PswaWebApplication –WebApplicationName “pswagateway” –UseTestCertificate</li>
<li>Add-PswaAuthroizationRule –UserGroupName &#8220;MCLAB\Domain Admins&#8221; –ComputerGroupName &#8220;MCLAB\Domain Controllers&#8221;–ConfigurationName Microsoft.powershell</li>
<li>After configuration is complete, open a web browser and point it to https://SERVERNAME/pswagateway</li>
<li>Log into the site with credentials that are members of group used in step 3.</li>
</ol>
<p><a href="http://blogs.metcorpconsulting.com/tech/wp-content/uploads/2013/03/PSWA1.png"><img class="alignleft size-full wp-image-1542" alt="PSWA1" src="http://blogs.metcorpconsulting.com/tech/wp-content/uploads/2013/03/PSWA1.png" width="513" height="418" /></a></p>
<p>&nbsp;</p>
<p>Upon successful logon, a Powershell console appears in the browser.</p>
<p><a href="http://blogs.metcorpconsulting.com/tech/wp-content/uploads/2013/03/PSWA2.png"><img class="alignleft size-full wp-image-1543" alt="PSWA2" src="http://blogs.metcorpconsulting.com/tech/wp-content/uploads/2013/03/PSWA2.png" width="865" height="584" /></a></p>
<p>For more information, read this TechNet article:<br />
<a href="https://blogs.technet.com/b/askpfeplat/archive/2012/09/17/want-remote-powershell-management-from-your-browser-see-how-powershell-web-access-in-windows-server-2012-may-help.aspx?Redirected=true">Want Remote PowerShell Management from your browser? See how PowerShell Web Access in Windows Server 2012 may help…</a></p>
<p><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://blogs.metcorpconsulting.com/tech/?p=1538"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://blogs.metcorpconsulting.com/tech/?p=1538" data-text="PowerShell v3 Web Access"></a><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://blogs.metcorpconsulting.com/tech/?p=1538"></a><a class="a2a_button_google_plus" href="http://www.addtoany.com/add_to/google_plus?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1538&amp;linkname=PowerShell%20v3%20Web%20Access" title="Google+" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/google_plus.png" width="16" height="16" alt="Google+"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1538&amp;linkname=PowerShell%20v3%20Web%20Access" title="Facebook" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1538&amp;linkname=PowerShell%20v3%20Web%20Access" title="Email" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:print()" title="Print" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/print.png" width="16" height="16" alt="Print"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1538&amp;title=PowerShell%20v3%20Web%20Access" id="wpa2a_28"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.metcorpconsulting.com/tech/?feed=rss2&#038;p=1538</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Active Directory 2012 DCPromo</title>
		<link>http://blogs.metcorpconsulting.com/tech/?p=1479</link>
		<comments>http://blogs.metcorpconsulting.com/tech/?p=1479#comments</comments>
		<pubDate>Thu, 21 Feb 2013 20:17:47 +0000</pubDate>
		<dc:creator>Sean Metcalf</dc:creator>
				<category><![CDATA[Career]]></category>
		<category><![CDATA[Deployment]]></category>
		<category><![CDATA[Microsoft Products]]></category>
		<category><![CDATA[Powershell Code Snippet]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[Technical Reference]]></category>
		<category><![CDATA[ActiveDirectory]]></category>
		<category><![CDATA[AD2012]]></category>
		<category><![CDATA[Server2012]]></category>
		<category><![CDATA[WindowsServer2012]]></category>

		<guid isPermaLink="false">http://blogs.metcorpconsulting.com/tech/?p=1479</guid>
		<description><![CDATA[Starting with Windows Server 2012, DCPromo is no longer used to promote a member server to be a Domain Controller. Since DCPromo no longer works (Microsoft calls this featured deprecated), there is a new GUI option and associated Powershell commandlets. There are major changes to the promotion process which integrate the process. This simplified process [...]]]></description>
				<content:encoded><![CDATA[<p>Starting with Windows Server 2012, DCPromo is no longer used to promote a member server to be a Domain Controller. Since DCPromo no longer works (Microsoft calls this featured deprecated), there is a new GUI option and associated Powershell commandlets.</p>
<p>There are major changes to the promotion process which integrate the process. This simplified process includes:</p>
<ul>
<li>AD DS role deployment is now part of the new Server Manager architecture and allows remote installation.</li>
<li>The AD DS deployment and configuration engine is now Windows PowerShell, even when using a graphical setup.</li>
<li>Promotion now includes prerequisite checking that validates forest and domain readiness for the new domain controller, lowering the chance of failed promotions.</li>
<li>The Windows Server 2012 forest functional level does not implement new features and domain functional level is required only for a subset of new Kerberos features, relieving administrators of the frequent need for a homogenous domain controller environment.</li>
</ul>
<p>NOTE: The new &#8220;DCPromo&#8221; GUI takes longer than before since it performs many more checks than in the past. Since the GUI provides the PowerShell script code, it&#8217;s a great idea to script the promotion of all new 2012 DCs.</p>
<p><strong>Install the Active Directory Domain Services (ADDS) role:</strong></p>
<ol>
<li>Install the role &#8220;Active Directory Domain Services (ADDS)&#8221; on the target server (local or remote).</li>
<li>Check the Restart checkbox.</li>
<li>Click on Export Configuration Settings to get the Powershell command line equivalent.</li>
</ol>
<p style="text-align: left;">Powershell command:</p>
<p style="text-align: left;"><span style="color: #0000ff;"><em>Add-WindowsFeature AD-Domain-Services</em></span></p>
<p><strong>Promote the server to DC:</strong></p>
<ol>
<li>Run the Active Directory Domain Services Configuration Wizard.</li>
<li>Select Add a Domain Controller to an Existing Domain.</li>
<li>Select the appropriate DC options and enter the DSRM password.</li>
<li>Change any options on the following pages as appropriate.</li>
<li>Click on View Script to view the Powershell script command.</li>
<li>Click Install.</li>
</ol>
<p>Here&#8217;s the Powershell script the GUI creates when creating a new forest accepting all defaults:</p>
<blockquote><p>Import-Module ADDSDeployment<br />
Install-<strong>ADDSForest</strong> `<br />
-CreateDNSDelegation:$False `<br />
-DatabasePath &#8220;c:\Windows\NTDS&#8221; `<br />
-DomainMode &#8220;Win2012&#8243; `<br />
-DomainName &#8220;MCLab.net&#8221; `<br />
-DomainNetbiosName &#8220;MCLAB&#8221; `<br />
-ForestMode &#8220;Win2012&#8243; `<br />
-InstallDNS:$true `<br />
-LogPath &#8220;C:\Windows\NTDS&#8221; `<br />
-NoRebootOnCompletion:$false `<br />
-Sysvolpath &#8220;C:\Windows\SYSVOL&#8221; `<br />
-Force:$true</p></blockquote>
<p>Here&#8217;s the Powershell script the GUI creates when adding a new Domain Controller to an existing domain accepting all defaults:</p>
<blockquote><p>Import-Module ADDSDeployment<br />
$SafeModeAdministratorPasswordText = &#8216;&amp;P@ssw0rd2013&amp;&#8217;<br />
$SafeModeAdministratorPassword = ConvertTo-SecureString -AsPlainText $SafeModeAdministratorPasswordText -Force</p>
<p>Install-<strong>ADDSDomainController</strong> `<br />
-NoGlobalCatalog:$false `<br />
-CreateDNSDelegation:$false `<br />
-Credential (Get-Credential) `<br />
-CriticalReplication:$false `<br />
-DatabasePath “C:\Windows\NTDS” `<br />
-DomainName “mcdevlab.net” `<br />
-InstallDNS:$true `<br />
-LogPath “C:\Windows\NTDS\Logs” `<br />
-SiteName “Default-First-Site-Name” `<br />
-SYSVOLPath “C:\Windows\SYSVOL” `<br />
-Force:$true `<br />
-SafeModeAdministratorPassword $SafeModeAdministratorPassword</p></blockquote>
<p><span style="text-decoration: underline;">Powershell AD commands (with switches):</span></p>
<p><em><strong>Install-ADDSDomainController</strong><br />
</em></p>
<p>-ADPrepCredential<br />
-AllowDomainControllerReinstall<br />
-AllowPasswordReplicationAccountName<br />
-ApplicationPartitionsToReplicate<br />
-CreateDnsDelegation<br />
-Credential<br />
-CriticalReplicationOnly<br />
-DatabasePath<br />
-DelegatedAdministratorAccountName<br />
-DenyPasswordReplicationAccountName<br />
-DnsDelegationCredential<br />
-DomainName **<br />
-Force<br />
-InstallationMediaPath<br />
-InstallDns<br />
-LogPath<br />
-MoveInfrastructureOperationMasterRoleIfNecessary<br />
-NoDnsOnNetwork<br />
-NoGlobalCatalog<br />
-NoRebootOnCompletion<br />
-ReadOnlyReplica<br />
-ReplicationSourceDC<br />
-SafeModeAdministratorPassword<br />
-SiteName<br />
-SkipAutoConfigureDns<br />
-SkipPreChecks<br />
-SystemKey<br />
-SysvolPath<br />
-UseExistingAccount<br />
-Confirm<br />
-WhatIf</p>
<p><em><strong>Install-ADDSForest</strong><br />
</em></p>
<p>-Confirm<br />
-CreateDNSDelegation<br />
-DatabasePath<br />
-DomainMode<br />
-DomainName **<br />
-DomainNetBIOSName **<br />
-DNSDelegationCredential<br />
-ForestMode<br />
-Force<br />
-InstallDNS<br />
-LogPath<br />
-NoDnsOnNetwork<br />
-NoRebootOnCompletion<br />
-SafeModeAdministratorPassword<br />
-SkipAutoConfigureDNS<br />
-SkipPreChecks<br />
-SYSVOLPath<br />
-Whatif</p>
<p><em><strong>Install-ADDSDomain</strong><br />
</em></p>
<p>-ADPrepCredential<br />
-AllowDomainReinstall<br />
-CreateDnsDelegation<br />
-Credential<br />
-DatabasePath<br />
-DnsDelegationCredential<br />
-DomainMode<br />
-DomainType<br />
-Force<br />
-InstallDns<br />
-LogPath<br />
-NewDomainName **<br />
-NewDomainNetbiosName<br />
-NoDnsOnNetwork<br />
-NoGlobalCatalog<br />
-NoRebootOnCompletion<br />
-ParentDomainName **<br />
-ReplicationSourceDC<br />
-SafeModeAdministratorPassword<br />
-SiteName<br />
-SkipAutoConfigureDns<br />
-SkipPreChecks<br />
-SysvolPath<br />
-Confirm<br />
-WhatIf</p>
<p>** Required Powershell switches</p>
<p><span style="text-decoration: underline;">DC Prerequisite Checking:</span><br />
Domain controller configuration also implements a prerequisite checking phase that evaluates the forest and domain prior to continuing with domain controller promotion. This includes FSMO role availability, user privileges, extended schema compatibility and other requirements. This new design alleviates issues where domain controller promotion starts and then halts midway with a fatal configuration error. This lessens the chance of orphaned domain controller metadata in the forest or a server that incorrectly believes it is a domain controller.</p>
<p>The following tools are installed as part of the DC promotion:</p>
<ul>
<li>Active Directory Administrative Center</li>
<li>Active Directory Domains and Trusts</li>
<li>Active Directory Module for Windows PowerShell</li>
<li>Active Directory Sites and Services</li>
<li>Active Directory Users and Computers</li>
<li>ADSI Edit</li>
<li>DNS</li>
<li>Group Policy Management</li>
</ul>
<p>NOTE: Running dcpromo /unattend still installs the binaries as before, but produces a <a href="http://go.microsoft.com/fwlink/?LinkId=220924">warning</a>.</p>
<p><span style="text-decoration: underline;"><br />
<strong>References:</strong></span></p>
<ul>
<li><a href="https://social.technet.microsoft.com/wiki/contents/articles/12370.step-by-step-guide-for-setting-up-windows-server-2012-domain-controller.aspx">Step by Step Guide for Setting Up Windows Server 2012 Domain Controller</a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh472162.aspx">Install Active Directory Domain Services (Level 100)</a></li>
<li><a href="http://technet.microsoft.com/en-us/library/jj574166.aspx">Install Active Directory Domain Services (Level 200)</a></li>
</ul>
<p><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://blogs.metcorpconsulting.com/tech/?p=1479"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://blogs.metcorpconsulting.com/tech/?p=1479" data-text="Active Directory 2012 DCPromo"></a><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://blogs.metcorpconsulting.com/tech/?p=1479"></a><a class="a2a_button_google_plus" href="http://www.addtoany.com/add_to/google_plus?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1479&amp;linkname=Active%20Directory%202012%20DCPromo" title="Google+" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/google_plus.png" width="16" height="16" alt="Google+"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1479&amp;linkname=Active%20Directory%202012%20DCPromo" title="Facebook" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1479&amp;linkname=Active%20Directory%202012%20DCPromo" title="Email" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:print()" title="Print" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/print.png" width="16" height="16" alt="Print"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1479&amp;title=Active%20Directory%202012%20DCPromo" id="wpa2a_30"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.metcorpconsulting.com/tech/?feed=rss2&#038;p=1479</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Domain Controller Cloning in Windows Server 2012</title>
		<link>http://blogs.metcorpconsulting.com/tech/?p=1523</link>
		<comments>http://blogs.metcorpconsulting.com/tech/?p=1523#comments</comments>
		<pubDate>Tue, 19 Feb 2013 20:17:34 +0000</pubDate>
		<dc:creator>Sean Metcalf</dc:creator>
				<category><![CDATA[Deployment]]></category>
		<category><![CDATA[Microsoft Products]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[AD2012]]></category>
		<category><![CDATA[DC Cloning]]></category>
		<category><![CDATA[WindowsServer2012]]></category>

		<guid isPermaLink="false">http://blogs.metcorpconsulting.com/tech/?p=1523</guid>
		<description><![CDATA[One of the best features of the new virtualization safeguarding technology, Windows Server 2012 introduced is the ability to clone virtual Domain Controllers. Cloning Requirements: The hypervisor hosting the virtual DCs must support VM Generation ID. The PDC Emulator for the domain containing the source DC must be online and running Windows Server 2012. The [...]]]></description>
				<content:encoded><![CDATA[<p>One of the best features of the new <a href="http://blogs.metcorpconsulting.com/tech/?p=1471">virtualization safeguarding technology,</a> Windows Server 2012 introduced is the ability to clone virtual Domain Controllers.</p>
<p><strong>Cloning Requirements:</strong></p>
<ul>
<li>The hypervisor hosting the virtual DCs must support <a title="Virtualization Updates to Active Directory 2012" href="http://blogs.metcorpconsulting.com/tech/?p=1471">VM Generation ID</a>.</li>
<li>The PDC Emulator for the domain containing the source DC must be online and running Windows Server 2012.</li>
<li>The source DC has to be running Windows Server 2012.</li>
</ul>
<blockquote><p> The PDCE creates the special Cloneable Domain Controllers group and sets its permission on the root of the domain to allow a domain controller to clone itself.</p></blockquote>
<p>NOTE: The Windows Server 2012 PDCE must be online when cloning due to the following:</p>
<blockquote><p>The cloning domain controller contacts the PDCE directly using the DRSUAPI RPC protocol, in order to create computer objects for the clone DC.</p>
<p>Windows Server 2012 extends the existing Directory Replication Service (DRS) Remote Protocol (UUID E3514235-4B06-11D1-AB04-00C04FC2DCD2) to include a new RPC method IDL_DRSAddCloneDC (Opnum 28). The IDL_DRSAddCloneDC method creates a new domain controller object by copying attributes from an existing domain controller object.</p>
<p>The states of a domain controller are composed of computer, server, NTDS settings, FRS, DFSR, and connection objects maintained for each domain controller. When duplicating an object, this RPC method replaces all references to the original domain controller with corresponding objects of the new domain controller. The caller must have the control access right DS-Clone-Domain-Controller on the domain naming context.</p>
<p>Use of this new method always requires direct access to the PDC emulator domain controller from the caller.</p>
<p>Because this RPC method is new, your network analysis software requires updated parsers to include fields for the new Opnum 28 in the existing UUID E3514235-4B06-11D1-AB04-00C04FC2DCD2. Otherwise, you cannot parse this traffic.<br />
For more information, see 4.1.29 IDL_DRSAddCloneDC (Opnum 28).</p></blockquote>
<p>There is a new group added when installing a Windows Server 2012 DC into the environment called &#8220;Cloneable Domain Controllers&#8221; which controls which DCs can be cloned. Only DCs that will soon be cloned should be in this group and removed after they are cloned. Note that new DCs created through cloning are added to this group by default.</p>
<p><strong>Cloning a DC:</strong></p>
<ol>
<li>Identify the &#8220;source DC&#8221; and copy the DC&#8217;s files VM related files.</li>
<li>Add the source DC&#8217;s computer object to the &#8220;Cloneable Domain Controllers&#8221; global security group or the new cloned DC will be booted into Domain Services Restore Mode.</li>
<li>Run the Powershell command <em>New-ADDCCloneConfig</em> which performs the following checks:* PDC Emulator is Windows Server 2012 or later<br />
* Source domain controller is a member of Cloneable Domain Controllers group<br />
* Source domain controller does not include any excluded applications or services<br />
* Source domain controller does not already contain a DcCloneConfig.xml at the specified pathScript Example:<br />
<em>New-ADDCCloneConfigFile `</em><br />
<em>–CloneComputerName</em>  MCLABDC03`<br />
<em>-IPv4Address 10.10.10.13 `</em><br />
<em>-IPv4DefaultGateway 10.10.10.1 `</em><br />
<em>-IPv4SubnetMask 255.255.0.0  `</em><br />
<em>-IPv4DNSResolver 10.10.10.11,10.10.10.12  `</em><br />
<em>-Static `</em><br />
<em>-SiteName HQSite `</em></p>
<p>NOTE: Omitting the <em>CloneComputerName</em> parameter will force the Powershell script to create the name based on the source DC. For example, if the SourceDC is &#8220;MCLABWXYZDC02&#8243;, then the automatically created name is &#8220;MCLABWXY–CL0001&#8243;. The script takes the first 8 characters from the source DC name and adds &#8220;-CL####&#8221; up to &#8220;-CL9999&#8243;.</p>
<p>After these checks are complete, the script creates the DC Clone Config file in one of the following locations:</p>
<p>* DSA Working Directory<br />
* %windir%\NTDS<br />
* Removable read/write media, in order of drive letter, at the root of the drive</li>
<li>Shut down the source DC VM and export it. The source DC must be shut down gracefully.</li>
<li>Import the new VM and start it up.</li>
<li>When the new DC starts up, it checks for the <em>DCCloneConfig.xml</em> file and if it exists, the cloning process is initiated.</li>
</ol>
<p><span style="text-decoration: underline;">References:</span></p>
<ul>
<li><a href="https://blogs.technet.com/b/askpfeplat/archive/2012/10/01/virtual-domain-controller-cloning-in-windows-server-2012.aspx?Redirected=true">Virtual Domain Controller Cloning in Windows Server 2012</a></li>
<li><a href="https://blogs.technet.com/b/keithmayer/archive/2012/08/06/safely-cloning-an-active-directory-domain-controller-with-windows-server-2012-step-by-step-ws2012-hyperv-itpro-vmware.aspx?Redirected=true">Safely Cloning an Active Directory Domain Controller with Windows Server 2012 &#8211; Step-by-Step</a></li>
<li><a href="http://technet.microsoft.com/en-us/library/jj574223.aspx">Virtualized Domain Controller Deployment and Configuration</a></li>
<li><a href="http://technet.microsoft.com/en-us/library/jj158947.aspx">New-ADDCCloneConfigFile</a></li>
</ul>
<p><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://blogs.metcorpconsulting.com/tech/?p=1523"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://blogs.metcorpconsulting.com/tech/?p=1523" data-text="Domain Controller Cloning in Windows Server 2012"></a><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://blogs.metcorpconsulting.com/tech/?p=1523"></a><a class="a2a_button_google_plus" href="http://www.addtoany.com/add_to/google_plus?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1523&amp;linkname=Domain%20Controller%20Cloning%20in%20Windows%20Server%202012" title="Google+" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/google_plus.png" width="16" height="16" alt="Google+"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1523&amp;linkname=Domain%20Controller%20Cloning%20in%20Windows%20Server%202012" title="Facebook" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1523&amp;linkname=Domain%20Controller%20Cloning%20in%20Windows%20Server%202012" title="Email" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:print()" title="Print" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/print.png" width="16" height="16" alt="Print"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1523&amp;title=Domain%20Controller%20Cloning%20in%20Windows%20Server%202012" id="wpa2a_32"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.metcorpconsulting.com/tech/?feed=rss2&#038;p=1523</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Virtualization Updates to Active Directory 2012</title>
		<link>http://blogs.metcorpconsulting.com/tech/?p=1471</link>
		<comments>http://blogs.metcorpconsulting.com/tech/?p=1471#comments</comments>
		<pubDate>Sun, 17 Feb 2013 20:17:39 +0000</pubDate>
		<dc:creator>Sean Metcalf</dc:creator>
				<category><![CDATA[Career]]></category>
		<category><![CDATA[Microsoft Products]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[AD2012]]></category>
		<category><![CDATA[Virtualize DCs]]></category>
		<category><![CDATA[WindowsServer2012]]></category>

		<guid isPermaLink="false">http://blogs.metcorpconsulting.com/tech/?p=1471</guid>
		<description><![CDATA[As part of the many updates to Active Directory, one of the most interesting is virtualization safeguarding in Windows Server 2012. Active Directory Domain Controllers running Windows Server 2012 can now identify if they are virtualized and have been improperly restored or cloned (copied). Windows Server 2012 introduces a new feature called the VM Generation [...]]]></description>
				<content:encoded><![CDATA[<p>As part of the many updates to Active Directory, one of the most interesting is virtualization safeguarding in Windows Server 2012.</p>
<p>Active Directory Domain Controllers running Windows Server 2012 can now identify if they are virtualized and have been improperly restored or cloned (copied). Windows Server 2012 introduces a new feature called the VM Generation ID which is used to track the virtual machine (VM) on which the OS is running. When a new VM is created in a hypervisor that supports the feature (Hyper-V 2012 &amp; VMWare vSphere 5.1), a VM Generation ID is created by the hypervisor and associated with the VM as the unique VM guest identifier. The VM Generation ID is a 128-bit cryptographically random  integer that changes when the VM&#8217;s configuration file changes. The virtual machine&#8217;s BIOS provides the VM Generation ID to the OS in an 8-byte aligned buffer in guest RAM, ROM, or device memory space which can be queried via ACPI namspace with a compatible ID of &#8220;VM Gen Counter&#8221; (also a DOS Device Name of &#8220;VM_Gen_Counter&#8221;. When the generation ID changes, there is an ACPI Notify operation on the generation ID device ID device using notification code 0&#215;80 (an ACPI GPE can triger this notification).</p>
<p>Each Domain Controller has a unique identifier called the Invocation ID for the Active Directory database instance on that DC. When a DC is backed up and restored, the Invocation ID changes. Each DC tracks changes it makes to its local AD database, NTDS.dit, using an incremental counter called the Update Sequence Number (USN). Active Directory replication leverages a combination of the InvocationID and the USN in order to determine what data a DC requests from other DCs. The USN normally only increases in value; however, there are circumstances where a &#8220;<a href="http://blogs.metcorpconsulting.com/tech/?p=986">USN rollback</a>&#8221; occurs such as when a DC&#8217;s VM snapshot is restored. With a USN roollback, the DC is improperly restored to a point in time &#8220;rolling back&#8221; the USN to a previous value. The DC doesn&#8217;t have AD data that other DCs have and believe that it has (for more information, read my article on the subject: <a href="http://blogs.metcorpconsulting.com/tech/?p=986">USN rollback</a>). The new VM Generation ID protects against this scenario.</p>
<p>At first boot-up, a virtualized Windows Server 2012 Domain Controller queries the hypervisor for the VM Generation ID and stores it in in the Active Directory database file (NTDS.dit). Each time the DC is rebooted, the VM&#8217;s current VM Generation ID is compared with the value in the DC&#8217;s NTDS.dit file (ms-DS-Generation-Id). If the values are different, the DC resets the invocation ID, discards the RID pool, and updates the value in the DC&#8217;s NTDS.dit file.  The DC also non-authoritatively synchronizes the SYSVOL folder to ensure proper operation and replication.</p>
<p>NOTE: The ms-DS-Generation-Id computer attribute does not replicate &#8211; to view a specific DC&#8217;s Generation ID, query for it on that DC.</p>
<p>Here&#8217;s the value when viewed in ADUC on the DC:<br />
<a href="http://blogs.metcorpconsulting.com/tech/wp-content/uploads/2013/02/DC2012-MSDS-GenerationID1.png"><img class="alignleft size-full wp-image-1592" alt="DC2012-MSDS-GenerationID" src="http://blogs.metcorpconsulting.com/tech/wp-content/uploads/2013/02/DC2012-MSDS-GenerationID1.png" width="479" height="536" /></a></p>
<p>Powershell command to view the VM Generation ID associated with a 2012 DC:<br />
<em>Import-module activedirectory ; </em><br />
<em>(Get-ADObject &#8220;CN=MCLABDC01,OU=Domain Controllers,DC=MCLAB,DC=net&#8221; -server mclabdc01.mclab.net -property msds-generationid).&#8217;msds-generationid&#8217;</em></p>
<p><img alt="" src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAA/AAAAEyCAIAAADSgqzPAAAgAElEQVR4nOydeXwkV3Xvz61uacYeGxvMZntmpK57q1szY2ywUT4sITGrF80idXct3dJIM94Bg4hY8pIHZAFECAgQS8JLIAkQIlAcoCHwIO8RREgIAQuxJERgwIAN2GOPLG84IeTN+6O2W7fura7e1N2aM5/vx59xT1Xd7dxTv3vqLrC5uXk//sE/ffvnvp7/0+/5V/1pMf8Jt3eiWk7nqu76n37Jfye66nbt/v3yp9/rH/Pfm3+Sy9WtP7C5ubm5ufkA/sE//fnnkZ7/0+/5V/1pMf8Jt3eiWk7nqu76n37Jfye66nbt/v3yp9/rH/Pfm3+Sy9WtP3DDV08gCIL0BF+5G0EQCV3vmwiC9DCf//zn4YavnnjFZ//1NX/zJQRBEARBEARB+gtP0N/w1ROEWVvD6OL66uLcliXXltSBLSyfXJ8fq3vNZpqHp7+yv4DZlY2Tm8uzXUo9sY3q/Ovsyka99m2R0cX1jbWlUTY3v7YNm35706cd1s32xsnNDS7z0h9PE9K48R5h27sLMCxgJrAy0BLoJRi2skMVYEXY+7r/89Avfnr3iR/fffdX3zebfcz4mYVjwEzIjQG1NeNayB2FvRbsK8H+N73/Z3f8zkHrzD3jJDcBugV0EvQpGD6qscnBkQoMver99/74FWNHCZ0YoKUzmJWlNugV0EugH4ThIzA0AdSCwiQwG3JFoBVgxyA/DYUpYGUYPgj6BDALdBuGbdAdYBVgDjAbGipp6h7XR/a5jenrVggFPW92Gyc3N2oLXvHGlla53xMsMnrlyoyyvubm18R/5SsR2Nz8WqcqVJo6n3+pHu1KG7eY6BbneaaW1OhbkM9WBP0WtNHo4rrbp2ZqnLqKdRm3GwZGOFNLMMiwk87UNjfWlkaTninPpGDzghNwf5f+KE0oenEkxdHF9TTmMbq47j0wKE5qz6DKZ3dJ6RVbN7AEeJNL/rGdBW/EbOT3tmzeTVdmK5lvqqLEXEndxbZipAzMhtwk6DawIrAyGBbki5A/DLlnnrn/uuMf+Pq//PGLYcjatX8mm6+CbgIrQv4IsHJWr8DQBOTesXzfHa87UtXY4UH9asJKUJiEkSrsq5IRJ5u3YO/vfnTzttdf5UD+MLBxQotAS0BNGCrBhcVzRl8PQ2/8i/948D/uOPWNO/9m4dCNxhOfByMvOPz3p05++0enfvn9b/3sb698/LGMbg9Qayczs8wCjiaKXLcpu/6S6kG2PvPNpQhsbn6ta2+fIM+CoPffymNLqyfX58ca0NYNRWdhdkWw7C0T9NLUXUYX11fX1oO3SOtt3K5G6srtjVZp8MbtVj57XNAHVhdodGmX8ZSEX5lJgn5tfTUQNGvrq2tLo0nPlGdSsPlIN/TbNPKjPwBQJBQGFIPbXY2+WltZrSeAeNEfaLgGBb2Yz/Y2d8Pm0fI3qz4X9KnMRn5vO8y76cpsJfNtaeK4u9hmDOyfyLCqtvcaTa9q+QkYKcKBEugvBTqxMzd5wdAN9qd++c+LN8KBybOeNH3GyPQAnQbjEBR+FQoHzyxMweOOwPl/8slH7nhjcRoOHDpTf24mfwT2T8LFDlxqwQGTGGXY/Qd/99C/vuuKEuw7CPlDoB8GeoSwCbK7TB7ngFF8/b/d889vfTnoLzj7+D+c+NJ7L7t4CnLX3fDSV2Z2V7Th8dLHT/3s06/dOeycw6zHjZR35cuElTVW1piZYWYTRUZB3xeZbyJFT82Hr9G50S5pRYWg98OEKcsGiV8GvagGJ5TjYXLVazuM2EXiiNxgqLbg374yE4RV/LTUt0s/EazMjC3xsiOMx9RW3OyNLq6vLi650SP34cuzkbBNNNi5Pj/r/ZOncmRXSvM5U+O+lkRiUXWKGbwG4rcT/40Yi7+Kz2xoYpLbHOJbNijp2vpqpGUjDafKp5R4MaVtpC5m2By+2fCjaq7dY/mMXby5PNtY5lN2GWALy2sry2ubya9zYAvLa0vzNU9nrC4uLas/0Kt6cdzm+SuDGKFw++ji+kZtSZ6Q+CghtJlUP0KFBIk2J+gj+Y8Zg7QXSw0sfddO38Rp7DOhF6ucQPyZAWkEfYtONV1zyM2mQ+YtaU2ZE2h75hMspEUHmJ5W3ptBxxHsJL2FSPMj9LgP/ObxHbsu1/be8FtfOXX/Hd+7feOBO+479eXZMaDlDK2crU9P1/7r1sWXwD5nYKQIj3bKb/vG9x4+9fCJO79/z6mvv/5GePazYOit7/rpxhtnP3Di3lN33PH1U3/xaXjM8+G5zyZXfOz27/zixIMbD3zp/37krjvefPnMOXvLA1f9/pu+vL7+n6d+tnn3qY07P3DzsQue8tnbfv6VErvk0RdMnPu899/y42+98TU3njE6Ducbj774Gnj89U/9s+898pX3XXxg4sJCeSezs8wCwwTD0gw7YzgqH5IQqRV6XBvss/MGpnhvpnVBqhKltCVZ5kUnkBBMTOPnJR/fOCGR1tfNrkgrVlHMVA3XnNhTCHouf0Ej1fPdygvigp7EwuTS1zafJR7BxfgDD/+FN7a0GqkReQOInwhmVzZqC7w25QsVzLH2g4jenFpe+Aq6lg+1Cu0tu1JqDeKLSlpMwqzRsbmwFDJxxjUEH3YKKln2TDewmnZJgCSfQtVJG056u4p4MaUJJRXTbQ7uAq5mwiaQ5pP/7p9Q9pSouowrZUb9ArqCnu/Dfk9e8i6rLczU1ufHFpbXlkYTnikV9AqbF4dM0dthdmVjbV0a/+Z9qyjQ6wv66AAg0rVFzyCrkDlZPpdGZcag6sXSfqTosPKunaqJ69pnci+W+jrZM4Nb0gj61p1qstUlmE2HzFvlLlROoH2Zn1O1ZosOMCVtfG/yf095u5R4j/vW218I9Brzb0888rU/v3TYGThgZ/faJGcDs4HZYNjX3fKLry++HPImsBcMsusvOXLzrv3mzvw0zH1z474vvvCJJTBed8vDP3z41k9dRg9nJv7qCz//9lsO23DhWz7+0x989NUvH9QrUP3oTza/+47xGdg3ddNffe+BW5effkkV9hZBL0K+BK/62IO3vn/f0I2wbyr7hJe9+ssnvvWns7DXhKFxGB4D47Uf+NHtH/6dyR25a8jwNAxPAq1A3oK8Q/IVLT+p8iHS14S0x7Vsn1thYNIspXdBqhKltyWFjAnsMynEI20jae+QC4nUvk4YA9fvcSkarjmxp5pDH/sC6A0gGnt11TMU/pUpj8N5g49IdJ/Pp/xdzleodKQbb6ogFBoN7In1JdhEPUHP27dSH6jyqXiXq0Kt4hBccntMb9X9CJNG1ssTimVD2nCKYkaCHNHp1NFopTShesWMh07joWXpGzq9mEhn/2pB7/fw5Aj9aOgdmlE8EpvnrpROevGtqMuCPo0depmRGYOqF0v7EX9jPKGEcimbuK59Kr6ZJLSm9Jl8QycL+rY41RTNITebDpm3xF0kOoF2ZV5lIekdYHpUrrL196Y3xI14hrS3x4n3uG+9/c27njL/oQce+fP/MQ4XFWH/kezugyRXAqMCeQcK9rUfe2TtnS8Bw9SGDmYvfQYMvekNP9rYOHHq1Mkfff/+L05fYMLIH/zRD77xVvNlsOPQjssW/ueXPv/Zd7/mrOtufXDj9snH/lqGHoKnv21548uvPlwZ1H/nw/ef+pObr9LOu2IHncnQKjATbljeWP/0r104TYzigP6ad9z24Bd+/3oYmr7g0jfD8B/8wy8e+pvjz4Lha71Z/rQMrEyYCcwBNgXMkfqQZCEU+ybWHvtsl4FJbUmapfQuSH17WluS/h7K39mVet+FJH5e0jsUMRRZP5LUUthNxsLQe91iJjdcc2JPHqFPaG+FvIhMIUpJVA0LDR/JCS8rpX0mOfNSVRpLna9QpVjskKCX5lPxLk8cXCZLAWWXU69gTvt9Jq2gb1oTS4vZiqDnc5IwVySeehOZlxVH3mUCQe/GM1Z9ASoPYfquzb9L/UzJEF1m85Fa4hsuvH2mtulOP5AktBVTbrx+VzdCP1Pb3KgtSI2h7ss4ucOmFvSK5miDoI85gXYI+tadaoLVJZhN58xbdBeJTqB9mU96bbfRh9Sl6femn+dw/NyEhQg5EXrcv/3JK2D4Dz/1k//+3G+8GvSDsPeK7AXPIcOHoTAJIxXYZx+vPbT67puAWTsuKMHj3vK++2/73MtfuvOCEhz6i1sf+MfibgcOLHzsl99+41VFGJ7Z9dhX/ul3/+MTNzwXXnLriXu/cLzwW2BcDrt/93MPf/stE9c+7sL3v+ee73zg5qsgf+05IzfvMI5DzgLzQ3f/5CulJ1iZ3JUDT3rz0sZ/f+xFU5nhG84cPvr6f3/wozfbA7uf/6hLpkAvAxvPFg5ljfEsLQGtAJ0B3WxR0LfRPjtqYNIspXdB6ttTm6K0d8fsM6XVxac8hQMDtcut7+ui32lDr5W44Ce54ZoTe3UEPbCF+USnHy2SYsKobMoN4bRL0NjhvFVP08yN8s+XbXqQVHjF7ZLUuRk44TiSW1c3urgeTLlpu6BX5bMRQe8n1OSUG0lH8l5UKQZpCn0sVp204aT5VKQiKaY0oYRvf/FZQFyGIx0yns/2TrnxsyF2Gd4s3fBAYoRe/F/lM2UBFYnNi0Ybk9TB50h5QpJFsdIa5msgKKBiUazEM6SzEKUxqF/Gkn4Ut/CUgl7ZxEr7bEHQt2PKTYtOVWjN9GbTEfOWugu1E2hj5hMspO0+RJ56a+/N0DzWxMn06W8XiPe4L7xtHA78xvUff+hr33rrU/M3Pi5XhQsPnq//GhjevpA3ffaBW9/9Mjh/fEA/svvS19xy30/mj1TPp9edefMdd//skzf++mXA/scHvnvqg3PPhcuesevmL/zTHT/5nSPPGZn+62/85BfveeUVj9vzoqe989YHfnr3HxWrcOmxm957auO7H2YXXX7uE6YeNfoS7UnPedz5v/fK1R/84M9vggMmXPupO2/7wKG9L9P2H534xKl/fcPRgfyNkC/D+SNwkQmjN8FVf/XtX/zXnX+3AGcXgFWAyQW9qonjPa4h+5StQtwiA5NmKb0LUpUovS2pMh+3zzRWt7o4J+0dCiGRJCCjmZybX4t8H1MZQ/qGa07s1Rf06XeCi27pxflKhaB3606yKEGwY8UX8FhERGphktuF1OPf8f09gMPoy+riUuci9An55JY7BB1eLb5P+mEk3kqETzPKRbGSnpDQ1mLTxxamBAkFVSdtOGkxE/pnvJjxNkoo5nIt8mPUVJIMrPXMp+wy0VGucgitUjzKZ0aCiOvzYyqbj1wpm4gS69dCnw0v9mojHsIMLT+2bUh820qpZ5BXpiqf8kWxkl6s6kdNC3plLalWj8memdIJtHNRbFNOVaaJ05pNu81b5S6UTqCNmU9ozU74kHom1/B7U9U3G7pdIN7jvva/3qBdcKV2ycvf/sVf3HPy7s2Nhx7e/H+feevvEVaGnAl7rZd9YfOr7/otOGcss28MjOqT/teX7/rZz+9+5L83/v7jC9968Kc//udi4fWfemj1k5849eO777//57/8P6+2wKiCfuNF7/7WXbffd889d/zL+z/+Nz/5/m9fdRQKNow4b/3Kf/70rhP33//g/Sc2f/DHr4ThcRh5x0fuvv/HJ+765cY/mnsmsuw5ZOQtn7j3gfs37r/37o277rzn4W985leG7bONUvbypX+++45Hau+BwjQYJWIoBb2qieM9Lr19phf0bTcwN6HVtUiW0rsg6e2N2pI088lrDFRWFwRq4w+MC4mG9qhNqRnSN1xzYq8LB0uJ5tLsdof9nvo2Q7UPfV3F0wu0su0m0goztY5MNkC6Ql+3Zl9nvu/QHv/MgcuOwvmXDV52Q/bxh8hQCUaqFxaeC7oJw+PZvWNw3sEzhp933rPmM/tnYPAFsPfo8FOmwRg74zHPgPwcPPbJZ+25DobY4AXV7P7DwI488cKLgB6FHVeAceyip98EF0/BGc+D/ZOPOeMZGcM662kvhN2HQH8+DF0F+1+YOffQrqe96tzhMjzmaeexm7QLfu3R+ZfAvrHMAQv2/ApcfA1cfBwumYHzLssWXgp7D+4YsuHxzzpv98zZz/rDAXoQWLnrFbg1tPj5qHPTybbt+Qyt0WVBT/rz4FhEShDUiQ43e/c1mRDURLao/htceIP0LH3dmn2d+X5EG6nAcBHOPwh6EQ7YZ1wy+fjLpgf2VWHIIkMHz9r7HBg6CEM2GNdn9r9C068hF0xA7iooXA75gxq1zxyePm/3dYND7hz3I6RwFRgm6MehYO+46DDssyB/FIaPwAWXw9DVA9TU9lXhkmOkUMoOXwHsEIyUIT8B7DDkpzP7XgrGDOjjQMuDtEJoFfQqjEySi6fIvjLQQ1CwYP8x2FeFgqnRQ2cOPx8F/dbcLsUL2GMATkb3BT2CIAiCIKcPYFRAN2HvBNAyjFiD+52zLqpkCjbkTJKb2JE7RHIl0CvAZjKF6zU6RYaKQI9AYQzyEyRvD9DJM3IzGX0SqAOsBMYRoCXIOcDK2ZFxyJtgVEEvwdBByE1ozIZ8BfZNgWFq+mFgE5Avg1EENgFGRSscB6MKtAjU1KgN1ALdBsOGERvyZULHwbAgPwn5Chi2RouD+iFy2gh6pL9IJejbckJe5z6+bD3uDMumQ/sJtwu11KGzCREEQRCkW4DuALWB2RqzMoapGSZhJmEmMJMwmzBHYxWNTWqsojFbY5ZmlDXDJHmLFGwYcaBQgXwFjCqwSaAO6CbJFUnuCOjjQIvAymBYwGxgDrAKsCqwCjAHXL3OTO/MV6OkGSVilIlhAjOBmUDLoJdBL4FeAloCWtJoSaOmRm2NOhqtEuoQZqGgR3qTdII+xfqDuvSjoN/6PIuCvh01jyAIgiC9A1BX0FuEWbyaBxoK+gyrZkJBbxLDJHkL8hYUbMg7kK+AUQFWBeoANYleIrkJoheBloCawCzvjCrmAHP8v9vAXEFvElbWjLLGysTbYN4X9J6mL7t/12g5EPSEVgi1CbNQ0CO9STpBn3oxe72H9Jk27b6gb0fNIwiCIEjvANQOBH34I7OAWYTZGnMynqB3NMPWDIsYJjFMMCwfGwwHDIewCmE2oRahZaKXiF4GagK1OAUf6HgXV5GbhJmBmucEva/pqQnUJB4WoRahNqGOL+jNrlcggsRpZg796OL66uLS8snNjdqCu4cOt3+nYselk5sbtZXl+IZi6bfCXFsPdznl11zyJ1zOhsd0ebfLr3T3hwp/FLIUOU4sum8Rv5NRfNczyT500Swpb5fVEoIgCIJsP4BaQK1A0IeCm1qE2RqzM8zJskrGcDTDJoYNRnCNK75daW4T5hBXo1PL1d/ek73ZNZFbCLO8i5lFvDh95OOAgC/lA0Fve39HQY/0JE0Ken/P1M3VxTlhs0/+yvSnEkhJOJWA3+YzOHtsIzx8JNybU35loM4DQT/mjwESz2byMxbfSF5+pEI8S5LbE888QhAEQZBtiSe7aUgg6AcMJyboOcHNLMIszbA1T9nbhLma2/bC/67EZ2YQhifMCq8M8kCDwLxaxzP/f5k3bOh6vSFInKYj9Ioz0oTjDxTiWHJldF/9uA4Obo8dI1LnqO2EK3miFzco6Bs5y11+e70UEQRBEGS74CvsqATnZt3YmmG7at4lDLd7gp5X1aKm96Ppbmy+DBFBz2fAn2zjrselFqGWRi3NF/T+GCMKCnqkJ2mnoA/+NZxhkihV+SulJAh68aRPtaCXXZn4JSHx3HX/ehT0CIIgCNIMYJQ5QV8h3hpZbrK7P12eMCsQ69z8mWg0nVmaOwZwoS4RQR8dAHgb3RBWDv4VmKvm7ax3Oz9px4pM90dBj/QkEUEfP2FYiuJA3bnwpG7/kA73gdwMe/dAXcmVUqS3EzfAHz1WQKWeFVdKBT1/Knu7ptykE/SKYiIIgiDI9gOMEmEmYbZGHU2vepo+kOzuPpJGGQwzWCYrFfSgexNgNH/6TcbFi7JHAvCuZPfVfEljJWKUvFQM78tAhjoD1MlQxxf0pkzQd78CESROGwV9uNyTny8eLDZdXVzyQuyKK6UEi02D20lsfo5qyo36Skmi4aLY2tL82iY/Cz+eVUGR8/kUF8WmEPTSWuq6ZSAIgiBIJ4B8kRhlwmyNVjL6pLvFOzAbDAsMV8qXwSgBK3s6mzkas0ko98P9Jd2NaDRmZQw7Y9gZZmeZlaVWhlqEHwAwP6LPTI2VNVbKGMWooLc15mSps0OvZCOCnl9TaxGGgh7pUfrmpFhBEyMIgiAI0o+4Yp0wizBHo1WSM8nQOBkuk5xDDJvss4jhwHAFckdAfz7Qw4RZGqto7Cihk6BXMrnyzqHxjG6CUYX8NIxcA/mpDLOyhjNgVDPU0YZt0CeAjQGdAN0G6p4wZQO1NMPMFMpa3tQMS8uXtUIJjBLQEuhlMlzWdFuj1SxzBgxLC9bsYoQe6Qd6WtBH4+sYt0YQBEGQvgdYGH0nzCFD4+SCK7XdE9reSjZfGbjYGTCmBnYfg71Xw/Ao6M8DViZsMsOuJfoxGD66c2/53N1jO3QL9h2D/TfCRS+FwjUZag4YlR35qYxehb0O5A4Bezboh2C4CnSSGFPAKkBtLW9l95mZgk2MaqZgDYwUNWMCcuNkaJzsnoBhC4zJTN7ZWbCyhuXP7LcJs7Qg/yjokZ6kpwU9giAIgiDbDAhWoxoWGLamm9mhEmFXAHNg77POyx8998kvzJz39LMueyXoVwM9BHSCGNWB/LUaPQrDdib/vMHCYXjGwTNzNjyhAvlpYJWMXs5SZ4BNZmklo9s7n/Q7QI/sGHgqUFNj9g7DyTAHdBtYCfLjwEqEmsQwtRELjBLo41qutHPYyuTKoBeBlUm+DIYF1PE3vLc1V9NTFPRIj9IFQS/sirPFNJd6ms1nwN+YP93TUl3ZX7gLCZJPCutg6oltVOdfO7/9/+ji+sba0iibm1/bhk2/venTDstvxcudtSf58TShj/YQ2/buAmgg6E3IWxmjMkiPkkIVht/+mZ+f+vHdJ350YuNrf/ZbOx9TfhSbGWA20CPEqAwWrsnQCgyPw75xKLzpgz+743WHrUftPbwjd3ggN5HJlTM5O5OrDrDKjoINQ6/6q407fvPQNDEmdhils5k5SC3QHdAnQB+D3GHIjQMzYaQKhgn6eJaa5xqTg3oRhq8GegTyJTAsoBVCHcIcd7ltE4I+fY/rI/vcxvR1K4SCXty13V8aG13DmrjLZLrVrsDm5tcS95lhc/NrnapQaep8/qV6tCtt3GKiW5znmVr9Jc4dzWcrgn4L2mh0cd3tU8FhZ0TWZYS9VmdqCQYZdlJ+NyfFM+WZFGxecALc8m7xR2lC0Yvje9TWN49wbXq4D2xaz6DKZ3dpaA+AVgwsAd7kkn9sZ8EbMRv5vS2bd9OV2Urmm6ooMVdSd7GdgEKJMEfLTRM2CSMOFCzIl6BQgsIE5H71zP3XXvuBb976npdl9lYfte/aHflpwhwwSpA/DPnioGHD0Djsfedf3/PjN4yZA8NjZ+y9aiA3TgwbCjbssyFvElqC3a/92H23veGqChTGwZjI0BKhZWAWDJdgz/g5v/J6GH7Tn//nQ4/ceep7d37yQwfn4IlP3jn80nOf+fpL3/zTX976h+P7K2eNTA8wK8vsDPU2xGylyHWbsusvqR5k6zPfXIrC/itb/PYJ8iwIev+tHO69mFZbNxSdhdkVwbK3TNBLU3cZXVxfXVuXbvKDgr5ulQrbg259Pntc0AdWF2h0aZfhDxgmyYJ+bT08b2FtfTU8iy3plAYBwebF/VvdZ4r7NW0uz6oSCgOKwe3ecRO1lbqL2nnRH2i4BgW9mM/2NnfD5tHyN6s+F/SpzEZ+bzvMu+nKbCXzbWniuLvYZsCBosaODuy9MUOPafuqsL8I+6+G3I1AD56bc4aHrp389C/+ZfEmOHDs7ItuPHPk+kF2DRiHIf8MGBnbdeAoPG4cHvu+T27+8I1XloFeteuC5w/kjsBIFS6y4CklGJmAoSPwxPnP3P/Ndz6/DCOHwRgHfQJYCQwT9prwBBPypd//t81/ettvAr1y14vXTtz2t88cHrvsnT/+2clTX/vk//72//tkhf065K1dRnkHM7O6rVGLGByNFxkFfV9kvokUPTUfvkbnRrukFRWC3g8TpiwbJH4ZjO+GGQ+Tq17bYcQuEkfkBkPuhvde5v2wip+W+nbpJ4KVGWF/ySAeU1txsze6uL66uORGj9yHL89GwjbRYOf6/Kz3T57KkV0pzSe3XaYQi6pTzMipvfEAqnx7TfGZDU1Miu/CGSnp2vpqpGUjDafKp5R4MaVtpC5m2By+2fCjanFfUfFTVWwI3lDmU3YZYAvLayvLa5vJr3NgC8trS/M1T2esLi4tqz/QJ56OHLF5/sogRijcPrq47m7tKklIfJQQ2kyqH6FCogfJNSzoI/mPGYO0F0sNLH3XTt/EaewzoRernED8mQFpBH2LTjVdc8jNpkPmLWlNmRNoe+YTLKRFB5ieVt6bQccR7CS9hUjzI/S4P/3tmcFdz96x+4Wv/sqp+39y5w82Nn907y+/8tLnAzN3UufR+tSx2iOrb78JCtXB/CSce9R82zdve/DU/T+7/fv3nvrWm26E5/w67HnXO++89w03v+fuu07d+YN/O/Xez2jnPA+eczlcectt33nkrs0T9//j3y3/9Mdv+bWZR+8uD175ujd9+bvf/sWpOx+499TmHe9/aeX8S//3bQ9/rUgvPef84o5n/8V7f7B2y+t/IztShguu2uF8+iN3/1+bHoLc1OBIacAwB3JWhvoHXRkWMZQ+JCFSK/S4Nthn5w1M8d5M64JUJUppS7LMi04gIZiYxs9LPr5xQiKtr+MOL4rWnrSYqRquObGnEPT84Up+I9Xz3coLpNvbC2Fy6WtbtWe84GL8gYf/whtbWo3UiLwBxE8EsysbtQVem/KFCuZY+0FEbze1UAAAACAASURBVE4tL3zF46K4UKvQ3rIrpdYgvqikxSTMGh2bC0uhPhVLfQCW7Jn1zvGtm0+h6qQNJ71dRbyY0oSSiuk2B3cBVzNhE0jzGT+krKHMp+wyrpQZ9QvoCnq+D/s9ecm7rLYwU1ufH1tYXlsaTXimVNArbF4cMkVvh9mVjbV1afw7fmRydNyVLOijAwDpicu+Z5BVyJwsn0ujMmNQ9WJpP1J0WHnXTtXEde0zuRdLfZ3smcEtaQR960412eoSzKZD5q1yFyon0L7Mz6las0UHmJI2vjf5v6e8XUq8x331XdcDPX60ds8vV//ystyMtq8EF14BwyXIT4NRIYZ5/S0Pff1tLwRWhuHDO/Sbnnz4RWcWjmSGyzB360MP/8PNF9pQeMvyf9y++fW/fjI7lDnysX988DuLYyZc+IcfOfG9W37nN87QbajectfG+rsPHYV89UUfuu3Bry4/7clTMGwCOwwjV8Kr/vqhr/zlvj0vhPxU5gkve/VX77n1ndft3H9sp27C8z+4/p+fs/TqwO5ryf5ixigPuoI+b0HeInmL5G2VD5G+JqQ9rmX73AoDk2YpvQtSlSi9LSlkDH/QkLJo0jaS9g65kEjt64QxcP0el6LhmhN7qjn0sS+A3gCisVdXeqejisN5g49IdJ/Pp/xdzleodKQbb6ogFBoN7In1JT1Ui68iMYyX7mApaT4V73JVqFUcgktuj+mtuh9h0sh6eUKxbEgbTlHMSJAjOp06Gq2UJlSvmPHQaTy0LH1DpxcT6exfLej9Hp4coR8NvUMzikdi89yV0kkvvhV1WdCnsUMvMzJjUPViaT/ib4wnlFAuZRPXtU/FN5OE1pQ+k2/oZEHfFqeaojnkZtMh85a4i0Qn0K7MqywkvQNMj8pVtv7e9Ia4Ec+Q9vY48R73zbct7Lzsde9/ePNPXvGMwSdNwsU2GGUwbMKqYDhgWNfd8vDX3/5iMCyij+946uUw9I7X3b7+4OapUyfvuX3zizfSKTgw/0c//Nrb7BfDzqvJU98y9/kvf+69b3j8dZ+79+S/Tz7+KWcwC572ng+d+Pprr3TAeOWnNk799ez44HnPh+EyUAvyDhxfvv07n/j13HXa8ER2+LVvv+3nf//aqZ15Z6dehKs+9M0H/qliVAd3Xwd5E/JFKBwBVtJ0h+gW5ExCFcdrJgqh2Dex9thnuwxMakvSLKV3Qerb09qS9PdQ/s6u1PsuJPHzkt6hiKHI+pGklsJuMhaG3usWM7nhmhN78gh9Qnsr5EVkClFKompYaPhITnhZKe0zyZmXqtJY6nyFKsVihwS9NJ+Kd3ni4DJZCii7nHoFc9rvM2kFfdOaWFrMVgR95KBf9VyReOpNZF5WHHmXCQS9G89Y9QWoPITpuzb/LvUzJUN0mc1HaolvuPD2mZp/mnI8oa2YcuP1u7oR+pna5kZtQWoMdV/GyR02taBXNEcbBH3MCbRD0LfuVBOsLsFsOmfeortIdALty3zSa7uNPqQuTb83/TyH4+cmLETIidDjvvvu/wn0DR+67+RHX3xoIGfDyCRccgz2TWruQU6Gdd3f/Hxt8SVQcLKsBBf80S333/d3v3Hl4y46mDn42a/e+8XjB66BJ//eJ//fN952dQloFc5/4RvXTn36VWW4uXbHzz557f7jZ+QtuOBdH928661XXAvs7bW7/v2Lr7Az+WnIlUCfztKb4OBH/uXuz5eNmcHznz8w8pYPnTz18ReVd9LxnbkjcPDDt95z69S+yZ0XXg+6A4VxeNJVYEwM7K1oe2zYXSZDZouCvo322VEDk2YpvQtS357aFKW9O2afKa0uPuUpHBioXW59Xxf9Tht6rcQFP8kN15zYqyPogS3MJzr9aJEUE0ZlU24Ip12Cxg7nrXqaZm6Uf75s04Okwitul6TOzcAJx5HcurrRxfVgyk3bBb0qn40Iej+hJqfcSDqS96JKMUhT6GOx6qQNJ82nIhVJMaUJJXz7i88C4jIc6ZDxfLZ3yo2fDbHL8GbphgcSI/Ti/yqfKQuoSGxeNNqYpA4+R8oTkiyKldYwXwNBARWLYiWeIZ2FKI1B/TKW9KO4hacU9MomVtpnC4K+HVNuWnSqQmumN5uOmLfUXaidQBszn2Ahbfch8tRbe2+G5rEmTqZPf7tAvMd9410vg73W8U/8/OStf/Y0WgF2lBgmYSZQE5gFefvajz6y9o6XQr6q6SYMv2v5vu/8wdjVZ+Yn4OZ/2dj4/LVGFYw3fPLBjQ+/tAzGNLz48/fc88M3HywPXv0XXz7x04+8vJo1Ji/9g2/dd/L7bxyzIV89vvzTh7/xl5ftm9Hc5xsODM2+cW3jS+/47Z10HOZW7rn1w08zTGDOYK4IYx+69cSXKoWJHbuPEWbDyAQc/OA3Nx7c+PjbBnJVMMpA5YJe1cTxHteQfcpWIW6RgUmzlN4FqUqU3pZUmY/bZxqrW12ck/YOhZBIEpDRTM7Nr0W+j6mMIX3DNSf26gv69DvBRbf04nylQtC7dSdZlCDYseILeCwiIrUwye1C6vHv+P4ewGH0ZXVxqXMR+oR8cssdgg6vFt8n/TASbyXCpxnlolhJT0hoa7HpYwtTgoSCqpM2nLSYCf0zXsx4GyUUc7kW+TFqKkkG1nrmU3aZ6ChXOYRWKR7lMyNBxPX5MZXNR66UTUSJ9Wuhz4YXe7URD2GGlh/bNiS+baXUM8grU5VP+aJYSS9W9aOmBb2yllSrx2TPTOkE2rkotimnKtPEac2m3eatchdKJ9DGzCe0Zid8SD2Ta/i9qeqbDd0uEO9xX/3j12QumNjxlIU3/P0P73/wwQcf+sXPHz712cXf09gEMAuM6ms/++DKu18Nj7sE9l199mUvesq7vvLde04+snH37Z//3MI3T/xy4+tHh373707e8fHPPHL7iftOPnDqQ6+5OTN89bkXv/gp77z1O3edfPiun375fbd84PZv/L55A+TLcP4NH1g/df/GxkP3P3Ly7pPfeteL4LyrIf/2vz31y5888qP/euBfJ+ivP6pgH3jL1//9Zw/+/L77/uPee39x990/+eHGe188mbn0Jjj8vu8+eOr7n3kjPPpibegoMFs9bU/exPEel94+0wv6thuYm9DqWiRL6V2Q9PZGbUma+eQ1BiqrCwK18QfGhURDe9Sm1AzpG645sdflk2IFx31apb7NUO1DX1fx9AKtbLuJtMJMrSOTDZCu0Net2deZ7z+e+MwdT70eLnyu9pTJwQvLsKcIQxNPZJeD4WTz5s58CR5T3JW76pxnvQJoCc66Uhs+OjR6HQzbg+deBfqNmT1P2cGOw/CTd17oDI4cgeHiubufDkYFzr4acpP0mTeQA9Nw5gvgydPnP/a5mmEOXjILe8ey7AoYPgwHXgyPHnvsU3/znJwNFz7zbDoJFzz30ftvgnMOEnZ8z68cg6GDsPcQ7D38qKfPnjX0PHjMFY+6ZCa7t3zmnuqu0VeRkW5X3RbS4uejzk0n267nM7RIlwU96c+DYxEpQVAnOtzs3ddkQlAT2aL6b3DhDdKz9HVr9nXm+5HsRcc1WiEXFIHZcPEU5Iuw50rQS1CYPqtgXlg4dI5hZug0DE/BnkkYNgfpeJZNZ4ybs7nJ7J4xMmLBpdfAyFGytzIwXDxDHyNGFfbdBIWKlr8aWBn0aSg4cKBIRso7mQ3MBuYAKw7QgzBSgosmYX+FjNiQq8AFUzBchXwl8yTrjMtKmQNFoBNgmJCvZAv2GYWyptuwpwpD1YHcZGafCU85orFy1ytwa+hBQe8F7DEAJ6P7gh5BEARBkNOHTOGoRitkbxmoBSMOsBIMHwHdBGNy0LAelS+eYVgZVgW9AjkHdDNDi4RVwDgG1IHcEcibcGAK8lWSq2R0c5BOZJgN+Wli2BobB2qCPgmGDSNlkjcHDAsMGwwHmJmhJWKYUHAgb2msDLoFQw7oNuRtbcQcOFDW8iXQS0BNYI5mWFnDBGrBsA05G3QbCmU4UCTM7HoFIkicVIK+LSfkde7jy9bjzrBsOrSfcLtQSx06mxBBEARBukWGVjTqEGoDNYGWgZpALaA2UAeoTZilGVYmb2ruSlnmXlMGVgZWBqMMzARmAbMJczRmZ5iVpeYALWepmdEtotugO0BtYBYxLJI3Sd4ihk2YQ2hFo46mW5lcOZMranpJoyXCymC4qZhEN8mwCTkLdAvcLXeYCawMrORTRkGP9CbpBH2K9Qd16UdBv/V5FgV9O2oeQRAEQXoHjToatQm1OEHva3r3AsPKGBYn6E1gARJBn6FmlpYz1NSoK+jtiKA3fEHPHEJtTTc1vazlSppeIrTMC3rQTeKq+VDQ85q+DMxEQY/0JukEferF7PUe0mfatPuCvh01jyAIgiC9g8YcwmzCLOJJ+UDQW66gJ4alGRYxLMICVW1xmt69zCbM1pitMStDTReNWoRaQG1Cbfc5JHyODcwm1CLUJHrZU/PUjbibhJluZkig5ql7i8UNJFDQI71LM3PoRxfXVxeXlk9ubtQW3D10uP07FTsundzcqK0sxzcUS78V5tp6uMspv+aSP+FyNjymy7tdfqW7P1T4o5ClyHFi0X2L+J2M4rueSfahi2ZJebuslhAEQRBk+6Ex2xP0EZluBtqdME+FE+8XGyLKnnsUtTT3v/5fCLM8Nc/4J/hQC6hJqCmqeV/TExqoeT7dMJMo6JHepElB7++Zurm6OCds9slfmf5UAikJpxLw23wGZ49thIePhHtzyq8M1Hkg6Mf8MUDi2Ux+xuIbycuPVIhnSXJ74plHCIIgCLKtMaWyPgjDx7AIswi13Hg8oUkPjwT4qTB7xxQFfeR624cfRaCgR3qUpiP0ijPShOMPFOJYcmV0X/24Dg5ujx0jUueo7YQreaIXNyjoGznLXX57vRQRBEEQZFsCoqDnNb1SzUdQPrmOoBc0PYi3xL8MoKBHepR2CvrgX8MZJolSlb9SSoKgF0/6VAt62ZWJXxISz133r0dBjyAIgiBtQJjTElfVopp3aULQK5CF5xOm+qCgR3qRiKCPnzAsRXGg7lx4Urd/SIf7QG6GvXugruRKKdLbiRvgjx4roFLPiiulgp4/lb1dU27SCXpFMREEQRBkeyOT2nFV7U19aerh9TU9kaerAgU90ou0UdCHyz35+eLBYtPVxSUvxK64Ukqw2DS4ncTm56im3KivlCQaLoqtLc2vbfKz8ONZFRQ5n09xUWwKQS+tpa5bBoIgCIJ0FJnalmpoW1gL29TzhbSSPwsk0fV6Q5A4fXNSrKCJEQRBEATpUxoS0CklNTTz/IbVPAp6pDfpaUEfja9j3BpBEARB+p4W1XzX6XoFIkicnhb0CIIgCIJsM7quyFHQI9sPFPQIgiAIgmwdXVfkKOiR7Yco6P1Do8IruCNUgzWp3Jbt0T1kEARBEARBEui6IkdBj2w/QkHv7QpfW1GtPR1dXPfOe2ILy6jjEQRBEARpnK4rchT0yPZDjNAnbCYzU/OPi0JBjyAIgiBIU3RdkaOgR7Yf9QV9sNVMcKQrN+UG95FEEARBEKQBuq7IUdAj24/GIvTCmVPxCfcI0oN03fsjCNKzdN1BnYZ0vdHRZpDtRwOCHmZXBPkOY0uruD080vN03fsjCNKzdN1BnYZ0vdHRZpDtR4MR+ujUeYzQI31B170/giA9S9cd1GlI1xsdbQbZfoi73PAsz1rE1fHRGfMwtrSKp7ci/UPXvT+CID1L1x3UaUjXGx1tBtl+4MFSyPan694fQZCepesO6jSk642ONoNsP1DQI9ufrnt/BEF6lq47qNOQrjc62gyy/UBBj2x/uu79EQTpWbruoE5Dut7oaDPI9gMFPbL96br3RxCkZ+m6gzoN6Xqjo80g24+IoOdOjAqPkSK4mw3S53Td+yMI0rN03UGdhnS90dFmkO1HRNDP1DwdH2xe6W59s1pbUe1liSC9T9e9P4IgPUvXHdRpSNcbHW0G2X5EBP3o4rp7FiyMLa1yW84nbE6PIL1P170/giA9S9cd1GlI1xsdbQbZfohz6L1d56MHSKGgR/qarnt/BEF6lq47KARBkNaRROi9mfQYoUe2C11XDAiC9Cxdd1AIgiCtEwp6YAvL/smvrqZ3T4olDAU90t90XTEgCNKzdN1BIQiCtI4g6D0Rj4Ie2U50XTEgCNKzdN1BIQiCtE5028qxpdXotpXuLjc8gcpHkH6h64oBQZCepesOCkEQpHXwYClk+9N1xYAgSM/SdQeFIAjSOijoke1P1xUDgiA9S9cdFIIgSOugoEe2P11XDAiC9Cxdd1AIgiCtg4Ie2f50XTEgCNKzdN1BIQiCtI4o6EcX1zeiG9p429Kf3NzwN7VUXYkgvUnXFQOCID1L1x0UgiBI64SC3t3QZrW2wu9QCWxufs3fy3J2xVXw0isRpGfpumJAEKRn6bqDQhAEaR0xQi9sOQ9sYdn/X17cx69EkJ6l64oBQZCepesOCkEQpHXqCvq5+TVvT3p3l3oU9Ejf0XXFgCBIz9J1B4UgCNI6dQS9/8vmxsnNjbWVZYzQI31I1xUDgiA9S9cdFIIgSOvUF/QBwBaWuXWxKOiRfqHrigFBkJ6l6w4KQRCkdRoQ9DO1zY21pVH/f1HQI31EL7z425Vu8pXtLWNf11un6XTeGn2+6vpe6EedTrSVR7WxfhAEQbqFuMsNjzu7JvzdV/OqKxGkr8GXfUM102kZ196cpMxVc09oS65aeX5yWbpiFV03WgRBkNMKPFgKOR2wFb+bUoCZ6ud0i4ZK2vpzJPXGyTVTjVTPdaoqmhXKdR6eWqraTeekjc9P144dscNms9T7/QhBEKTPQEGPnA5I3+VyNc8hfUiPa5E2ahrx+hRqPtT0Ha43IUsKaFxopnq+/Dk0YUjgZ4bK002Vz6ae3z6raMYIgbqYQF3DCHqWJetBfdSPEARB+gwU9Mj2R5O/yBsW9FrjtEWCaKm1SOoU61Yan274e0pBv1X1JmQsppIpr31tSF3h4BF9DhWHBJp4l3hxPG6dlM9Gn09FQa+praJdEGYT6j+ZWiQU9O53rUDKJ6n5TneiFI+KFKHrDgpBEKR1UNAj2x/uje6/v6npkVbTtyyDWhP0/nOEoomyKXVyqZ7DPc37PYWaFyYsdbregowlC3q7KUEf19CuorUJ5QS3/79A7VYFfUPPlwl6UdPTVptA0ijU9nRwVNCnGRV3uvukeiB1SxEWoesOCkEQpHUigh7YwrK3zjXcnpJEVsHitjZI/8EL+hBqaunUvNb2GGdLEUdetwmCqaEk+BtNwteMJM/hxY2o+a2ptyBjKkHfmJoXNT2vtn1tTeIZozahUc2tmFauFvQNPj8qRrUo3i3MJrTNgl6jcU1vgnJ4nGRXbekyzRVBY7ZGLZeuOygEQZDWCQW9eyisu18NzK4E2p3/O4L0J+6Ln5M7kQh9cI37F5WsjyiMBPHRJo3i+JdZMgluKYKg3vUSERYoPGYRwyKG8BxBEdqaOtHo+tdgxnkg6BuOy6r0WT0NJzY0GBYYEq0cBmKplVzt/DhBfE5sIj6ntiWTYVSCPqj/MKtCPmn0+YHQDyPiitnz1CK+SNVYGEFPJabVuj9pKEhN4ql5wQItaSeSG6c60fgv8YFZ+j4oe2bXXROCIEh74AX9wnIg4n1xz6t8BOlbvDe3xqwwKu/NE3D/1SHM8SVC3cn0wTNlkdTI73GVbAlKQlCN/hwJR2MVjTmejOOVR6icxI1lApHn6TNqa9TO0PDvhHrPAcMCwwTDl+DUDIRghspmbvgpxurEJobDyd9IXJbw+ZGgnPOdjMb8fNLoE9xRSp4bq1Bu5OaKTirX9F4VxYYxXq3644FYPfuXBSKeRm7kGzdsu1g+o2peYrdu60hmiRjc2Iz7V82/HkJBLzda2bhIquAF7Wsq+pHt9yPePuNLpeXDM9X4IeMNwsVPE9LAvzDq0BITVQyVEQRB+g8xQr+6OEeYe2iUK+gXlk+uz88urZ7c3Djp/SuC9BeckgiFiL+SzwbmAKsQo0qMiv92LxNWTpb14KuxQFVEI4jiFAhXhmqc2CJhKNfPjBfptDXmZDxBbwHl9oLkJznINot08VOxMz4atTVqEd0i7m4khgl5X9D76YaC3hfKfOhdVhs2MSL1Bn6lacxsSK+n3bPFV6sZamWDrAZfWlyVXAi0cijlNWpqnKaHSMzbJjTSNFosb1p9Qe9XY7xQ/iSZUIh7+TRJ3oxrccmU7pjZ8AMDzR8YALVAFwS9lytNGINFB5xh3dZrHb/gbvvyXansP9nRWNXV9MBMoGVgLqodkEKEUQdwUjvDIuOToD75oXKGG5zw/Z3vvJHovmETAwU9giDbh+gc+jFPuG+srSyvBYLeO1LK/TtG65G+w5cRZkzQuzNGKmBUiTEFRhUMB5jlq5ByTMhaEMzrMCzwg6OhsPNXUrr/myDoPYHCTF7NAy0T6qoTJ8uqGU/Ql7lAr0kof30wLIkQSPMMtbOuptctTXcFvQnMhLwJhTLky17qukV0S9M9oayF4lWYHG9ydWhpzNGMqmZMEcPVcJY7CtIigj5hU3+udYzIbBn5lVE1PxBq+qigH4kIeo2aGi37eJreFdlCPDtB04cjHC6f/r/Gq4gbDtGIoNd0S2OWZpha3tRGTK1gEsMNcouCPiKgFTnUDEvLW1rBJHmL+ILe1fQatTKhqQSjU7cIoYrlF2OEc6WMkMj8Je4jjMZMjZVd/NGvRbzPSpOEVQiz3aQb1fSEWSS6KJkwKxsK+sDmI4I+w6wM96khOgotE8YPej0prxkOCei2g0IQBGkd+S43XmB+TBTxMzUM0iP9RzgbxHAllP+jJ+gd4kboXSESmToiBwwzKujD8DxQhaD348QaNd3oaWxOgslPucmwikZtTtAHoXRByot6C1gk3O5H6ANBH0Toy2B4gp6Ttv7knJia9xUSL+BsV9OHEdlwCGT504p8QS8JQvuV6eJNARI1vaitWajpXTUvCnpXzXtC2SS0zOFeGYnUasyWaGVhylCos/2mD/41VJll7huLi28P/CpS5kboTT9CH+RTMfM+0jRhTrznuI/iIvQQDFFYuAUNL+jjs8IIs8T1JIbtCXqZGbgqmZPyXq0Samu0otEqoRUSNyGDf4K8n2pc9nhBH4nQ6+IumfysGyJ0BImg9zEsL0hvYIQeQZDtgFzQz9S8qLz399oC4VR+1zONIA0Rhgb5OcfBckNvAr3jC1Mr1Bzc7IWIpjdMMEz/UdyKPS8cG59Gb2osFPTeUkLJDONgkSW/CDKQ+wLxuRBuScv+PBM3eBnMoQ/EtAnMVfP+tKJgLSZ1NOpE1VhZgJuP5JY9mEMfCHqLMEvzdVLwxUALBwzeVBmNcpreiIZR3Yf486cDee1FZLkpN5HvJ4YFhh18jXF1PIQEe+THZ29bXEtZwUcGr4yioOee4wn6MAlhVauwoNO70QjGlkENeAXnt8Dn5v1HlkDILFxcWesvirWBBstCpGW3iZdQ2RvtGLaL302i5icxg2DAZmvU0WjFNyFOXhtBvQU5CSL9ZmwdNi/obfAHhyAX9Pz0/XAtR+SbEhUEfTDGsAAFPYIg24WIoA+3p/TVPGGWO7fe/R3n2yD9CNBQ0HtiJaKbI9vwxaY62IH61Gg4sd4T9MzyRa3D7SoY14tqNR8G+4MFpvzuhP6MmkDH676ap6KaJ8FkIS7aGuqksJgmoaEg8xVVsKKxAsyBMOIuh5t+Y5GI9DfDshie0Hc/SnCCPqjSskbLhPGzMgJB7+nsbFTTc1MsIkucObnmbh7vBsvL4awPGjw/0joZTtNHVSZXLXpU0DPTG3359Qm0DHrJD9J7BuA+POsnQTilLot8B5l3giJwa3ltwqnkkNi+Oq5BkkijOwpB77g7KXnjVb0cfL4AwwHD9leJ+CMuvjKFOWnBqEO3NT34yONOaLH9eUq8oDcJ5Ye4wSoUh0g0veVOdo8Les5m+D09I+NeIo6BA0MtASt7mr7bDgpBEKR18GApZPvjiTlXzedt8CbOOhpzPHGpm0TnZz54Ykijdka3M2FEmZtp4EXovR1pQkGv+2suPc3kC3pW1vy5H7649MOWvgLWjApx9ZygS1g5mNERCno/oMsJuMjsfz8YzC0E9AUoP61cY2bG8OQUsAqwajpBXyasTKhXKO93o+yPTxxiVIjhCtNyhpoZamV0O6PbGd1xqzRDzYwv6Anz5//4otYXxFbW1fSGpQWIkXuTBHN1qA16UHtl2Rxudxa1oxmOZjgZw84YNjf9WiroHaL7atJvMsIswlyR7athvQQ6J+ipp+YHmZ1ltmbYxI18h4dVCYsfgvA8L+jdjy1uQpVwAxm3vP6keXemjfDxwTNv5mi0Ehf0vpqv+DOOyppeIrRMvAh9xdX0Xp2IHzrKopm5dqVbWs7Scpam2xp1NOZoRoXT9G69+TXsj28zoqB3+C2nvDoxnPBMgFDQR22GOpygLwuynl+mAtRV80VgrrmioEcQZDuAgh7Z/mjekk1XGZeAWZCvgFHJGBVNL8LwQaKXNKMKzPZCd7QEtES8YYBJDHPAWxHrALO9qF6+ohlOhtreY0NVUSHM0QyHMAtoSWNm1rCzzM5SX6gxm7BKiFEhhqPlbS1vZQoWyZlwYYkMmxnDIiMWHLA0dycZb4GsA7RKmDNo2MQwwShljcpZxrGsUYF8EYyyv86vQoyK5gPuCkVmDubL2Xwlk58GVobcGDATRo5BoaIZRW3Y1C60ybA/DT1v+1H2EI05Wd3JUIdQhxQc7aIKKThEd0iuqA0fyujlrDGpGVXIO2DYbmA+S8sZd9lxoFOZSZg5yEzNq0/HlY/BbObg2FHNMAkrEToBzIH8NGHOgF4C6t5VzbBJopcgNwb6EWDlbH7qzJHrssaU23buwgO33f3ochFYmRim18RGBfLHNFYd1MtZb3caLyeegsxXNOYMUocwODYTpwAAIABJREFUa0Avg+4pdXdBgj+48sdmwUpid+cZw4KcA3sqkHOIYWcMM8tKoBchVwRaHcgfz7Cqpof5JFwbEW6GmLfNkZe6qVEryxzCHG/ptpsBvThIp84yrh+kR2HYguEjMHwVsCIUJkm+kvFqIBiG2VmjkvGOOLD4OUha8GWDmRqzMoaVNbgvBt4o18mw6gCbJMYkGJOgm5mhIxndzhjHiG7D8BGimxqtElaBvDt6sTRmDbgNbbgDRa/5wKhA3h02OBpzdlAnQ21vTYhhgz9IBu/HMhgmyZtg2MCqml4czF2t0RLkpzL56s68M5h3Mn6KQK2Mu7ybWYSVgRaBlvzVJo73DcrtU7Sk5Q4SfaLrDgpBEKR1UNAj259sfjJjOBo1iT4BucPATChMQr6azVc0/RDseTbRxzOFY5CvgFEENg70CNBxoBNgFGGkBIXyzrxJ8g4EO+HkJ0nhaMaoDui2RstAx4GVfMUwqRnVTL4CtAy5IxotD+Yrg6y6g04CcxVMlbCjPlMam9KMaiZvZwvmwEiJ7JmAxxzJ7CntGLG1J9lwqZMtHNUKM5oxqTEH2BSwGc2YOrvgZPIlMI7sMKaeYLxwsDAFI4chX8wYRzVjSitMZ/JHM/mjmfxUNj8JzAa9BEZx18jEzn1T2f03AjNh6DmQt+FJL4b9R0n+iLa7mHm0ldlT0vZNaCNlrWBr+ar3tLzHAJ3amZsayE1puSntwFFtdJocOAq5KW1oIrP7BTty5V35awfyM1CogmGBXtT04g69OMgqYByFfBXyNuRNyBchX9pplDTDBmMSjKOQn3aVmTsKInoZckVCi5pRAnoEcgeBVaBwI9DJnUNHQDfBmAQ2nWXHITcOey6H4auAFneOXHPek+bOGDnuNRwtArOzxpRmVAizgJaAjgOb0PIlYBOgHwZjEkZuAja1c3g8q5cIs8CognEUjEkwKpCfhJGjxJjcpVeBls/Ui6CXgdqgO4O5aka3gZqgF0EfB1oEwwRmZ2iVGBUYsUnBGiiYsNeBx0/B3goUbGKUBukRGD4Eew4SferMkZsHjemMPgF6EWgJmK3lp4A5kCsTWs4aJWAlYCUw7Ex+EqgNw0XIFUGfyFBzB6sQVgVWBWYDLYNeBP3ILuP4Ewqv2KVfB7tN2H0l7P5VYIfgwDQZmcwY7hi16D2T2TuMqSyraO7ttAi0DMwmRiXj2gktAS1laWmQlXfmTTBck6sCtYFViDE5aMzsMq7N5q+F/LVaztpx4VWDw5WB/AuJ7sCeKyFXyhgzpDAJIzYYJtBShpbPoBbQKrBpoJNAbWCTYExD4SiMHIXCFOQnM8bkLlodoBbQCWBlyFtgVDJsktAKuIvC9QkwitpIGQoVMKYHckfO3nv5gD4BhWt3FKYfXajuGnEGR2wo2JC3gNkDuj1I7R2GTVgR6GFgE8DcYlY1Y0rLT2fyx7L5a7J6cWDPczPDY113UAiCIK2Dgh5BEARBEARB+piIoJ+peYtfN/wjY1U/evvTn9zcwH1vEARBEARBEKR7fPCDHwxPip2Z9faY57aqlP84v+bteAOzK7zQRxAEQRAEQRBkKwkFPf/r6OI6v3Ol8COwhWVfxPPiHkEQBEEQBEGQLUYi6IXTYeM/uiLePTIWxpZWcX96BEEQBEEQBOkSoqCvq+a9X8aWVr0jqFaWMUKPIAiCIAiCIF0iIuil82eSJ9UAW1jGdbEIgiAIgiAI0iUign6m5k2k4ZH+yP9rfLY9giAIgiAIgiBbA7/LTbATpTuXJlj/Kv5I3AWy0V8QBEEQBEEQBNl65LvcIAiCIAiCIAjSF6CgRxAEQRAEQZA+BgU9giAIgiAIgvQxKOgRBEEQBEEQpI8Rtq0Ml8AGO9twP+L2lAiCIAiCIAjSW8i3rYSxpdWTKzPCobCzK7inDYIgCIIgCIL0FBFBP7q4vlFbIK6gd7et9JU9URwiiyAIgiAIgiBIFxHn0M/UIrvL81F5PlqPIAiCIAiCIEgvIInQe5Pm3Qg9CnoEQRAEQRAE6WGEk2K9Za/B7BqccoMgCIIgCIIgvYwg6D29Hgp6XBSLIAiCIAiCID1MdNvKsaXVpG0rvVA9giAIgiAIgiA9Ah4shSAIgiAIgiB9DAp6BEEQBEEQBOljUNAjCIIgCIIgSB+Dgh5BEARBEARB+hhR0I8urksXvwq/e+dP4UpZBEEQBEEQBOkqoaAfXVzfOLm5WltZjWl0f/ebYEP6uZlZbw+cmdrmRm2h68VAEARBEARBkNMTMULPnyTl/eIeODUr/u4yuriOm9MjCIIgCIIgSLeoL+hnauKRsQF4diyCIAiCIAiCdJc6gh5mV9wZNYrIPap5BEEQBEEQBOkmSYIe2Nz8WrD41WV9fiz8J1TzCIIgCIIgCNJd6k+5kf4+U9tcXZzreu4RBEEQBEEQ5DRH3OWGhw/ARyP3C8v8lbgoFkEQBEEQBEG6BB4shSAIgiAIgiB9DAp6BEEQBEEQBOljUNAjCIIgCIIgSB+Dgh5BEARBEARB+hhR0I8urm/EdrmJ/8ivi8XtbhAEQRAEQRCkW4i73KzWVvjtKaU/Em7bStU2lwiCIAiCIAiCbAGp9qGP/zi6uB6eIIvbViIIgiAIgiBIl2hS0BNmzdRwE3oEQRAEQRAE6TItRei9mfSo6REEQRAEQRCkSzQj6IEtLJ9cnx8L/h45UxZBEARBEARBkC2jaUHviXgU9AiCIAiCIAjSRcRdbniWZy3pj8ST+LhtJYIgCIIgCIJ0GTxYCkEQBEEQBEH6GBT0CIIgCIIgCNLHoKBHEARBEARBkD6mC4J+dHG9i9Pum0ud39gn8ZpUKwrSX9lfwOzKRvdWSCe3UZ1/nV3ZqNe+LTK6uL6xtjTK5ubXtmHTb2/6tMN62wpHVzpJfzxNSOPGe4TT1l2kt8+6rdkjzd3GEiFbQF+3QijoebPbOLnpHgRLoutfky0yeqW4VQ5XX3Pza7GNdCJbYc7Nr3WqQqWp8/mX6tGutHGLiW5xnmdqSY2+BflsRdBvQRsFhyvP1Dh1FesywrZRM7UEgww76UwtPA5C8Ux5JgWbF5wAv5OV8KM0oejFYYreIXSJbiGspZORE+vSewZVPrtLSq/YuoElwJtc8o/tLHgjZiO/t2XzbroyW8l8UxUl5krqLk4r6ha8dUEvdVZe5bepcdtbouboa4W69ZlvLkVgc/NrXXv7BHkWBL3/Vh5bWj25Pj/WgLZuKDoLsyuCZW+ZoJem7jK6uL66th68RVpv43Y1Uldub7RKmz5f7DQR9IHVBRpd2mWEw9qSBP3a+mogaNbWV9eWRpOeKc+kYPORbui3aeRHfwCgSCgMKHK3z83Met1tprYp7V9BZoL3aKDhGhT0Yj7b29wNm0fL36z6XNCnMhv5ve0w76Yrs5XMt6WJ4+7idKPTgl7qrNyAwmptJb55dy+UqDlQ0Hc6RU/Nh6/RudEuaUWFoPfDhCnLBolfBr2oBvcij4fJVa9tft9MLo7IDYZqC/7tKzPBgNtPS3279BPByoyw434Qj6mtuNkbXVxfXVxyo0fuw5dnI2GbaLBzfX7W+yfPcciulOaTC2oKsag6xQxeA/Hbif9GjMVfxWc2NDHJbQ7xLRuUdG19NdKykYZT5VNKvJjSNlIXM2wO32z4UTV/0oKYz9jFm8uzjWU+ZZcBtrC8trK8tpn8Oge2sLy2NF/zdMbq4tKy+gO9qhfHbZ6/MogRCrePLq5v1JbkCYmPEjPvTySoXyFBos0J+kj+Y8Yg7cVSA0vftdM3cRr7TOjFKicQf2ZAGkHfolNN1xxys+mQeUtaU+YE2p75BAtp0QGmp5X3ZtBxBDtJbyHS/Eh7XEJcU7DP9K0pfyPEEkpwVtLTeLpYoi4amOK9mdYFKdsonS3JMi86gYRgYho/L/n4xplNWl83uyKtWEUxUzVcc2JPIei5/AWNVM93Ky+IC3rCxDC59LXNZ4lHcDH+wMN/4Y0trUZqRN4A4ieC2ZWN2gKvTflCBXOs/SCiN6eWF76CruVDrUJ7y66UWoP4opIWkzBrdGwuLIVMnHENwYedgkqWPdONVaRdEiDJp1B10oaT3q4iXkxpQknFdJuDu4CrmbAJpPnkv/snlD0lqi7jSplRv4CuoI8fB+FJnNmVjdrCTG19fmxheW1pNOGZUkGvsPkN0ddEbofZlY21dWn8m/etcTlbx0sI79RI1xY9g6xC5mT5XBqVGYOqF0v7kaLDyrt2qiaua5/JvVjq62TPDG5JI+hbd6rJVpdgNh0yb5W7UDmB9mV+TtWaLTrAlLTxvcn/PeXtUlQ9TupUpfaZsjUTXj1CQgnOKqWg35oSqZt4KwwsoZLTuCBVidLbkkLGBPaZFOKRtpG0d8iFRGpfJ4yB6/e4FA3XnNhTzaGPfQH0BhCNvbrqGYpw+qwkDucNPiLRfT6f8nc5X6HSkW68qYJQaDSwJ9aXYBP1BD1v30p9oMqn4l2uCrWKQ3DJ7TEXVvcjTBpZL08olg1pwymKGQlyRKdTR4opT6heMSVaMxatkb6h04uJdPavFvR+D0+O0I+G3qEZxSOxee5K6aQX34oaFvR1XURDgj6NHXqZkRmDqhdL+xF/YzyhhHe/sonr2qfim0lCa0qfyTd0sqBvi1NN0Rxys+mQeUvcRaITaFfmVRaS3gGmR+UqW39vekPciGdIe3scaY9L9gmxL0ipWjPh1SN+Q25Z0G9NibbMwKS2JK/k1C5IfXtaW5L+Hsrf2ZV634Ukfl7SOxQxFFk/ktRS2E3GwtB73WImN1xzYk8eoU9ob4W8iEwhSklUDQsNH8kJLyvlnTMx81JVGkudr1ClWOyQoJfmU/EuTxxcJksBZZdTr2BO+30mraBvWhNLi9mKoOdzUneuSAcEvbzLBILejWes+gJUHsL0XZt/l/qZkiG6zOYjtcQ3XHj7TG3TnX4gSUhRjQmuQ6iQFFNuvH5XN0LvzteXGkPdl3Fyh00t6BXN0QZBH3MC7RD0rTvVBKtLMJvOmbfoLhKdQPsyn/TabqMPqUvT700/z+H4uQkLEXLSivxN35oNCPo2TLnZihLVtc+OGpi8klO7IPXtqU1R2rtj9pm+jeS9I/GjaH1fF/1OG3qtxAU/yQ3XnNirI+iBLcyni7G5yk8+YVQ25YZw2iVo7HDeqqdp5kb558s2PUgqvOJ2SercDJxwHMmtqxtdXA+m3LRd0Kvy2Yig9xNqcsqNpCN5L6oUgzSFPharTtpw0nwqUpEUU5pQwre/+KdYLsORDhnPZ3un3PjZELsMb5ZueCAxQi/+r/KZsoCKxOZFo41J6uBzpDwhyTozol4NJqwyVCyKlXiGdBaiNAb1y1jSj+IWnlLQK5tYaZ8tCPp2TLlp0akKrZnebDpi3lJ3oXYCbcx8goW03YfIU2/tvRmax5o4mT797QJJsdIUE1TSt2b6V4/KWQlNxv0SeRtuWYmkqW+ZgckrObULUpUovS2pMh+3z5RWJ+0dCiGRJCCjmZybX9uMv+8UxUzVcM2JvfqCXrp7l7xUkS29OF+pEPRu3UkWJQh2rPgCHouISC1McruQevw7frB0L4i+rC4udS5Cn5BPYb+/OuL7pB9G4q1E+DSjXBQr6QkJbS02fWxhSpBQUHXShpMWM6F/xosZb6OEYi7XIj9GTSXJwFrPfMouEx3lKofQKsWjfGYkiLg+P6ay+ciVsokosX4t9NnwYsUUJj7bsW1D4ttWSj2DvDJV+ZQvipX0YlU/alrQK2tJtXpM9syUTqCdi2KbcqoyTZzWbNpt3ip3oXQCbcx8Qmt2wofUM7mG35uqvtnQ7QLqSW7yConbZ/rWlL8R5C5ddFbx7y1cNDSVoO9EidIL+rYbmJvQ6lq0NlK7IOntjdqSNPPJawwS2kjVO+JmU1dARisqlWZI33DNib0unxQrOO7TKvVthmof+jSfL7tOwkp5pKPM1Doy2QDpCn3dmn2deQTpBC1+Pmr716eA0/Z8hmS6LOhJfx4ci0gJgjrR4WbvviYTgprIFtV/gwtvkJ6lr1uzrzOPIB2iBwW9F7DHAJyM7gt6BEEQBEEQBEGaJpWgj0+na4LOfXzZety5d02H9hNuF2qpLTWPIAiCIAiCbGPSCfoU6w/q0o+CfuvzLAr6dtQ8giAIgiAIso1JJ+hTL2av95A+06bdF/TtqHkEQRAEQRBkG9PMHPrRxfXVxaXlk5sbtQV3Dx1u/07FjksnNzdqK8vxDcXSb4W5tr4q3YKKP+FyNjymy7tdfqW7P1T4o5ClyHFi0X2L+J2M4ruexTdsErKkvF1WSwiCIAiCIAhSlyYFvb9n6ubq4pyw2Sd/ZfpTCaQknErAb/MZnD22ER4+Eu7NKb8yUOeBoB/zxwCJZzP5GYtvJC8/UiGeJcntiWceIQiCIAiCIEgCTUfoFWekCccfKMSx5MrovvpxHRzcHjtGpM5R2wlX8kQvblDQN3KWu/z2eikiCIIgCIIgiJR2CvrgX8MZJolSlb9SSoKgF0/6VAt62ZWJXxISz133r0dBjyAIgiAIgvQEEUEfP2FYiuJA3bnIie7uhPWxpdXIDHv3QF3JlVKktxM3wB89VkClnhVXSgU9fyp7u6bcpBP0imIiCIIgCIIgSF3aKOjD5Z78fPFgsenq4pIXYldcKSVYbBrcTmLzc1RTbtRXShINF8XWlubXNvlZ+PGsCoqcz6e4KDaFoJfWUtctA0EQBEEQBOkL+uakWEETIwiCIAiCIAhCelzQR+PrGLdGEARBEARBEJGeFvQIgiAIgiAIgiTTBUEv7IqzxTSXeprNZ8DfmD/d01Jd2V+4CwmSTwrrYOqJbVTnXzu//f/o4vrG2tIom5tf24ZNv73p0w7Lb8XLnbUn+fE0oY/2EDtt3UV6+6zbmj3S3G0sEbIF9HUrhIJe3LXdXxobXcOauMtkutWuwObm1xL3mWFz82udqlBp6nz+pXq0K23cYqJbnOeZWv0lzh3NZyuCfgvaaHRx3e1TwWFnRNZlhL1WZ2oJBhl2Un43J8Uz5ZkUbF5wAtzybvFHaULRi8MUpSvLlbXEnURBGvEMqnx2l4b2AGjFwBLgTS75x3YWvBGzkd/bsnk3XZmtZL6pihJzJXUXpxV1C966oG/RWW19iZqjrxXq1me+uRSF/Ve2+O0T5FkQ9P5bOdx7Ma22big6C7MrgmVvmaCXpu4yuri+urYu3eQHBX3dKhW2B936fPa4oA+sLtDo0i7DHzBMkgX92np43sLa+mp4FlvSKQ0Cgs2L+7e6zxT3a9pcnlUlFAYUudvnZma97jZTS9pEyz+C2r8ynnp9QS/ms73N3bB5tPzNqs8FfSqzkd/bDvNuujJbyXxbmjjuLk43Oi3oW3RWXSlRc6Cg73SKnpoPX6Nzo13SigpB74cJU5YNEr8MxnfDjIfJVa/tMGIXiSNygyF3w3sv8/6A209Lfbv0E8HKjLC/ZBCPqa242RtdXF9dXHKjR+7Dl2cjYZtosHN9ftb7J89xyK6U5pOLEwixqDrFjJzaGw+gyrfXFJ/Z0MSk+C6ckZKura9GWjbScKp8SokXU9pG6mKGzeGbDT+qFvcVFT9VxYbgDWU+ZZcBtrC8trK8tpn8Oge2sLy2NF/zdMbq4tKy+gN94unIEZvnrwxihMLto4vr7taukoTER4mZ9ycS1K+Q6EFyDQv6SP5jxiDtxVIDS9+10zdxGvtM6MUqJxB/ZkAaQd+iU03XHHKz6ZB5S1pT5gTanvkEC2nRAaanlfdm0HEEO0lvIdL8SHtcQlxTsM/0rSl/I8QSasVZbXGJumhgivdmWhekbKN0tiTLvOgEEoKJafy85OMbZzZpfR13eFG09qTFTNVwzYk9haDnD1fyG6me71ZeIN3eXgiTS1/bqj3jBRfjDzz8F97Y0mqkRuQNIH4imF3ZqC3w2pQvVDDH2g8ienNqeeErHhfFhVqF9pZdKbUG8UUlLSZh1ujYXFgK9alY6gOwZM+sd45v3XwKVSdtOOntKuLFlCaUVEy3ObgLuJoJm0Caz/ghZQ1lPmWXcaXMqF9AV9DzfdjvyUveZbWFmdr6/NjC8trSaMIzpYJeYfMboq+J3A6zKxtr69L4d/zI5FgfV3uJ6L/KT1z2PYOsQuZk+VwalRmDqhdL+5Giw8q7dqomrmufyb1Y6utkzwxuSSPoW3eqyVaXYDYdMm+Vu1A5gfZlfk7Vmi06wJS08b3J/z3l7VJUPU7qVKX2mbI1E1494hGTLTirrSyRuom3wsASKjmNC1KVKL0tKWQMf9CQsmjSNpL2DrmQSO3rhDFw/R6XouGaE3uqOfSxL4DeAKKxV1c9Q+FfmfI4nDf4iET3+XzK3+V8hUpHuvGmCkKh0cCeWF/SQ7X4KhLDeOkOlpLmU/EuV4VaxSG45PaYC6v7ESaNrJcnFMuGtOEUxYwEOaLTqSPFlCdUr5gS9x2L1kjf0OnFRDr7Vwt6v4cnR+hHQ+/QjOKR2Dx3pXTSi29FDQv6ui6iIUGfxg69zMiMQdWLpf2IvzGeUML5GMomrmufim8mCa0pfSbf0MmCvi1ONUVzyM2mQ+YtcReJTqBdmVdZSHoHmB6Vq2z9vekNcSOeIe3tceSHUSb6hNgXpFStmfDqEb8ht+CstrJEW2ZgUluSV3JqF6S+Pa0tSX8P5e/sSr3vQhI/L+kdihiKrB9JainsJmNh6L1uMZMbrjmxJ4/QJ7S3Ql5EphClJKqGhYaP5ISXlfLOmZh5qSqNpc5XqFIsdkjQS/OpeJcnDi6TpYCyy6lXMKf9PpNW0DetiaXFbEXQ8zmp+/m1A4Je3mUCQe/GM1Z9ASoPYfquzb9L/UzJEF1m85Fa4hsuvH2m5p+mHE9IUY0JrkOokBRTbrx+VzdC706BlRpD3ZdxcodNLegVzdEGQR9zAu0Q9K071QSrSzCbzpm36C4SnUD7Mp/02m6jD6lL0+9NP8/h+LkJCxFy0or8Td+aDQj6FpzVVpaorn121MDklZzaBalvT22K0t4ds8/0bSTvHYkfRev7uuh32tBrJS74SW645sReHUEPbGE+3bDVVX7yCaOyKTeE0y5BY4fzVj1NMzfKP1+26UFS4RW3S1LnZuCE40huXd3o4now5abtgl6Vz0YEvZ9Qk1NuJB3Je1GlGKQp9LFYddKGk+ZTkYqkmNKEEr79xT/FchmOdMh4Pts75cbPhthleLN0wwOJEXrxf5XPlAVUJDYvGm1MUgefI+UJSdaZEfVqMGGVoWJRrMQzpLMQpTGoX8aSfhS38JSCXtnESvtsQdC3Y8pNi05VaM30ZtMR85a6C7UTaGPmEyyk7T5Ennpr783QPNbEyfTpbxdIipWmmKCSvjXTv3oaclZxDbNlJZKmvmUGJq/k1C5IVaL0tqTKfNw+U1qdtHcohESSgIxmcm5+bTNuQopipmq45sRefUEv3b1LXqrIll6cr1QIerfuOF0b3B61Y8UX8FhERGphktuF1OPf8YPVMEH0ZXVxqXMR+oR8Clto1RHfJ/0wEm8lwqcZ5aJYSU9IaGux6WMLU4KEgqqTNpy0mAn9M17MeBslFHO5FvkxaipJBtZ65lN2megoVzmEVike5TMjQcT1+TGVzUeulE1EifVroc+GFyumMPHZjm0bEt+2UuoZ5JWpyqd8UaykF6v6UdOCXllLqtVjsmemdALtXBTblFOVaeK0ZtNu81a5C6UTaGPmE1qzEz6knsk1/N5U9c2GbhdQT3KTV0jcPtO3pvyNIHfpaZ1VekHfiRKlF/RtNzA3odW1SJbSuyDp7Y3akjTzyWsMEtpI1TviZlNXQEYrKpVmSN9wzYm9Lp8UKzju0yr1bYZqH/q6iqcXSFgpj3SUmVpHJhsgXaGvW7OvM48gnaDFz0dt//oUcNqez5BMlwU96c+DYxEpQVAnOtzs3ddkQlAT2aL6b+tOz0gX6evW7OvMI0iH6EFB7wXsMQAno/uCHkEQBEEQBEGQpkkl6OPT6Zqgcx9fth53pl3Tof2E24VaakvNIwiCIAiCINuYdII+xfqDuvSjoN/6PIuCvh01jyAIgiAIgmxj0gn6/9/e3Rspj6xhAIVcSIEo8MclBFURxHgYimENqvCUAQmoxiUJKEK4hv5arRbwze4i6e6pOsZ+Ggk11BqPWt3v+/Zm9lcfsrBsOn2g/yd+eQAA/o/9Zg39Nr+W+el8e9yLY1VDJ6jfOVJx6fa4F5fzsKDY+6Uwf65lsgRV2OEy69p01Zenz6zqQ3UHoyH12on16xaFlYyGVc+GBZuiIY1envqVAADgpV8G+qZm6qPMD1Gxz/DM97sSJD3pShCW+Wx7j9275iNdbc70mW06bwP9rnkGeNqbqRnYsJB8uqXCcEiJy5/2PAIAgCd+PUM/0iMtan8wEo4TZ/br6g9zcHv5oI3Ii1bbT84M9U/+w0D/J73c05e/uiMAACT9k4G+/Wu3wuRpVA3PTHoS6ONOn+OBPnXm0zcJT/uuN+cL9AAAzEIv0A87DCeNNNQ99Dq6VwvWd6eyt8K+aqibODMpefm6muDvtxUYS88jZyYDfdiV/Z9acvNeoB/5mgAA8NI/GOi77Z7hevF2s2mZn+op9pEzk9rNpu3l68H6nLElN+NnJm7abYotTt8/j3AV/nCoUSIPxxlvin0j0Cd/pcn/zwAAYBEW0yk2ysQAAMB65oG+P79u3hoAAGKzDvQAAMBzAj0AACxYL9AnN4BWmmZSz44AAAAf1gX61eawz+qS8Pui3/WprktTx/e6fnxxsUsVAACmlV5ys82vQaek4/l2/c7iIjPKzgAAwOQSgT5qsLovHucsEd8FegAAmFwc6KM03+/5KtADAMC89DvF9juYRm1Wo2LwAj0AAEwurnJT5ofkeWboAQBghsIqN8dzOBnfbIqthPG9qnITaif1AQCAT9JYCgAAFkygBwCABRPoAQBgwQR6AABYsF5hsY02AAAHYklEQVSgD3a7duUp+8eVtQEAgBlJz9Bv82tb5WaVXeR4AACYp3SgbwvSR62mAACAWUl0ir3fuvZSq83xfLt+Z6fy1jsOAADMwegM/b04rutAXzeZqv7bbD0AAMxHOtC36+ajEN8uxQEAAOZgfIa+2RTbn63vVb8BAACm1Qv0++IxLE/ZLqy/W28DAAAzo7EUAAAsmEAPAAALJtADAMCCCfQAALBgUWOp47neFBuXp9zm13CnLAAAMAdxlZsqx692pzIsdLOrOsUK9AAAMC+9QL/Nr3XJ+d2pbOrQ1+Xns17EBwAA5iBeQ1+Xom/SfHXknMVz9gAAwBwkZujrlfQ/p+3ma5Vdujl7gR4AAGamC/T10prd17rZHXvOuh6xjfoEAABgDqJA/zhnX+su0HfnmaEHAIAZ6petrKvZJMpWCvQAADBDGksBAMCCCfQAALBgAj0AACyYQA8AAAsWB/ptfr33N7/WZen7NSuDg/H2WQAA4GO6QL/Nr/fboywuYTWb1ebw/VNH9lV2aTvI7ovmoOo3AAAwnXiGPgro4T/D4vRVT9n6hCblAwAAH/Yq0Aez8uFs/XrztS8e99vjLs0DAMB0fhnoqxn6eiW9TA8AABP5zZKb1eZ4bjbIhutwAACAD3sV6FObYsMQL9ADAMCE4io3oTCy32+Pezxzr2wlAABMTGMpAABYMIEeAAAWTKAHAIAFE+gBAGDB4kC/za+9za/djthHUJA+cRAAAPi8uMpNWVzKKNAPInvyIAAA8Hkv69AL9AAAMF9vBPphEfrUQQAA4PNeBPpWtLb+yUEAAOBj3g30q92pvF2/d68PAgAAH2OGHgAAFiyuchM6Z1W+r/7ZzcQnDwIAAJ+nsRQAACyYQA8AAAsm0AMAwIIJ9AAAsGBxoFfNBgAAFiSuclMWl7BsZfIgAAAwE2/VoR8rTg8AAExLoAcAgAUT6AEAYMEEegAAWDCBHgAAFiyuchM6Z1/Jg5MPGgAAqGgsBQAACybQAwDAggn0AACwYAI9AAAsWC/Q74t282tX0ybYF3v93n2tN1+rzfHcbpP9OW2n/g4AAPCf1QX61eawzw7V0X3xuBfH6NRtfq3i+2pzPMvxAAAwA+klN212Dw/ui0eZH9YCPQAAzEYi0Fcratp686vN4fvncb/VaX7dW3Kj2xQAAExp0Cm2n+ZDw3U42/wq0wMAwIR6gb6ajB/rBbvKLlF8X+1OZbNTFgAA+Ly4yk27rmZoX8Q1bczQAwDAtMIqN0ExyqAe5bCW5Wp3KvuFLAEAgEloLAUAAAsm0AMAwIIJ9AAAsGACPQAALNjIpljVbAAAYAn6gb6f49d1lH+UxaUU6AEAYH5eBPrKancS6AEAYIaSS27i7C7QAwDAPCU2xQ5XzAv0AAAwT4lAv9qdyn4LWIEeAADmyQw9AAAsWLCGfncq6zX03fR8VeUmdM6mHzQAAFDRWAoAABZMoAcAgAUT6AEAYMEmCPTb/Frmh6m+8O/uvtocz/3KPyPnPN758PfPBACA55KNpR732+NeHKszgs2yj/vTGNo/c7Qqzmpz+P4Z9K4KEvNqc/j+eZGefy1593D8yV2/7wT6f2Gof+umk4wZAIAPiwJ9nXTbUvTvZ+tVdnm/Bs4qu0QPBh8L9Mm7V7b5tfy5tk8yY8P7GIEeAICXRgL95ni+Pc7Zu6FwtTl8/4xO3tcz90FQHk6TjwX6sG5m+7RQ3S58k9AMvnnJ0Nxr/PLkK4LLvl9xv3vnUFyq4W3za5mfzrfHvThWH37Oeq8mgrscz7frd1b/qfpxkmcmx7kvetVCqzce73zN6kbJy9fNc1d4o+RnTrssCgCA940E+uwyjIBPZt/bB4D0XweBfj2YJk8G+nBIoX3R5OPN4funffBoUu/uVPZSfmpIw1cE2eVeHNsPjL7UKrvcm0B/b+JvmR/C4Bte215+/zlt+7/nyJmJcQ6fppJfc7352u4O3bfoPZUNO/42P3L3EmbkM/Pr8xVWAADMwdga+nhWvpkUH8nHTwN9UpRix2bo65nm3ux+f63/7VHmh7E3CcPLk3evzqzGv83rVTfJcFwl+PbyV4E+TM+jgX5snCOBPvE1+7/JeKDPLtUDRjiG5y9hxHoAgJlLz9AnDWNo9Kfk6vMn+mk4CvS9kYSxMvnw8HzwyVQ6uPtgfcsHA31ynCOBPrlYqHmTENzoTwL9+A7mN97PAAAwoReBfrU5fvdT7+i6muwyNpWbXHJTf2A/X3YLzauVKrvDNvz85hP2xaMNpsHYBoMfuTxx92AFTjuSsOjNNr/e/7VAPzbOPwn0zY1+ueQmEejrdfl/+JAGAMCHvQ704dT182naftnKLkqOBfr15mubX4Nc214ehs5EHczepthuyc0w0L8oo1ndfVhUZ5tfqweGdrNpmZ/+vRn6J+MM9raGm2ITX6TZInwKV0ZFl6+fbYqNP9AyGwCARZi4U2w4Tf5fuzsAAPx9Ewf69dSTwaaiAQBYtOkDPQAA8GsCPQAALJhADwAAC/bXX3/9D+XJsWzvRzmZAAAAAElFTkSuQmCC" /></p>
<p>You may notice in the graphic above that when querying DC02 for DC01&#8242;s msds-generationid attribute value, it is blank. Since this value does not replicate, you have to query for the value on the DC that stores the value.</p>
<p>This feature also provides the capability to clone (copy) Domain Controllers.</p>
<p>Scenarios where the VM Generation ID is changed:</p>
<ul>
<li>Virtual machine starts executing a snapshot.</li>
<li>Virtual machine is recovered from a backup.</li>
<li>Virtual machine is failed over in a disaster recovery environment.</li>
<li>Virtual machine is imported, copied, or cloned.</li>
<li>Virtual machine&#8217;s configuration changes (depending on change).</li>
<li>Virtual machine is moved from a hypervisor host not supporting VM Generation ID to one that does.</li>
</ul>
<p>Only Domain Controllers running Windows Server 2012 on a Hyper-V 2012 or VMWare vSphere 5.1 VM support this feature.</p>
<p>VMWare VM-Generation-ID support:</p>
<ul>
<li>VMware vSphere 5.0 Update 2 (vCenter Server and ESXi must both be at 5.0 Update 2)</li>
<li>VMware vSphere 5.1 (ESXi must be at least 5.0 Update 2)</li>
</ul>
<p><span style="text-decoration: underline;">Some key caveats:</span></p>
<blockquote><p>With this new capability come several requirements and limitations:</p>
<p><strong>* A restored domain controller must be able to contact a writable DC.</strong></p>
<p>If restored, a domain controller must have connectivity to a writable domain controller; a read-only domain controller cannot send the delta of updates. The topology is likely correct for this already, as a writable domain controller always needed a writable partner. However, if all writable domain controllers are restoring simultaneously, none of them can find a valid source. The same goes if the writable domain controllers are offline for maintenance or otherwise unreachable through the network.</p>
<p><strong>* All domain controllers in a domain must not be restored simultaneously.</strong></p>
<p>If all snapshots restore at once, Active Directory replication works normally but SYSVOL replication halts. The restore architecture of FRS and DFSR require setting their replica instance to non-authoritative sync mode. If all domain controllers restore at once, and each domain controller marks itself non-authoritative for SYSVOL, they all will then try to synchronize group policies and scripts from an authoritative partner; at that point, though, all partners are also non-authoritative.</p>
<p><strong>* Any changes originating from a restored domain controller that have not yet replicated outbound since the snapshot was taken are lost forever.</strong></p></blockquote>
<p>Here&#8217;s an excerpt from <a href="http://technet.microsoft.com/en-us/library/hh831734.aspx">Microsoft Article: Introduction to Active Directory Domain Services (AD DS) Virtualization (Level 100)</a>:</p>
<blockquote><p><a title="Collapse">Safe virtualization of domain controllers:</a></p>
<p>Virtual environments present unique challenges to distributed workloads that depend upon a logical clock-based replication scheme. AD DS replication, for example, uses a monotonically increasing value (known as a USN or Update Sequence Number) assigned to transactions on each domain controller. Each domain controller’s database instance is also given an identity, known as an InvocationID. The InvocationID of a domain controller and its USN together serve as a unique identifier associated with every write-transaction performed on each domain controller and must be unique within the forest.</p>
<div>
<p>AD DS replication uses InvocationID and USNs on each domain controller to determine what changes need to be replicated to other domain controllers. If a domain controller is rolled back in time outside of the domain controller’s awareness and a USN is reused for an entirely different transaction, replication will not converge because other domain controllers will believe they have already received the updates associated with the re-used USN under the context of that InvocationID.</p>
<p>For example, the following illustration shows the sequence of events that occurs in Windows Server 2008 R2 and earlier operating systems when USN rollback is detected on VDC2, the destination domain controller that is running on a virtual machine. In this illustration, the detection of USN rollback occurs on VDC2 when a replication partner detects that VDC2 has sent an up-to-dateness USN value that was seen previously by the replication partner, which indicates that VDC2’s database has rolled back in time improperly.</p>
<p><img id="6c232604-e0b3-4424-becb-cc0cd3a2cb40" title="How replication can become inconsistent" alt="How replication can become inconsistent" src="https://technet.microsoft.com/dynimg/IC611912.gif" /></p>
<p>A virtual machine (VM) makes it easy for hypervisor administrators to roll back a domain controller’s USNs (its logical clock) by, for example, applying a snapshot outside of the domain controller’s awareness. For more information about USN and USN rollback, including another illustration to demonstrate undetected instances of USN rollback, see <a href="http://technet.microsoft.com/library/virtual_active_directory_domain_controller_virtualization_hyperv%28WS.10%29.aspx#usn_and_usn_rollback">USN and USN Rollback</a>.</p>
<p>Beginning with Windows Server 2012, AD DS virtual domain controllers hosted on hypervisor platforms that expose an identifier called VM-Generation ID can detect and employ necessary safety measures to protect the AD DS environment if the virtual machine is rolled back in time by the application of a VM snapshot. The VM-GenerationID design uses a hypervisor-vendor independent mechanism to expose this identifier in the address space of the guest virtual machine, so the safe virtualization experience is consistently available of any hypervisor that supports VM-GenerationID. This identifier can be sampled by services and applications running inside the virtual machine to detect if a virtual machine has been rolled back in time.</p>
<div>
<div>
<div><a title="Collapse">How do these virtualization safeguards work?</a></p>
<div>
<hr />
</div>
</div>
</div>
<div>
<p>During domain controller installation, AD DS initially stores the VM GenerationID identifier as part of the msDS-GenerationID attribute on the domain controller’s computer object in its database (often referred to as the directory information tree, or DIT). The VM GenerationID is independently tracked by a Windows driver inside the virtual machine.</p>
<p>When an administrator restores the virtual machine from a previous snapshot, the current value of the VM GenerationID from the virtual machine driver is compared against a value in the DIT.</p>
<p>If the two values are different, the invocationID is reset and the RID pool discarded thereby preventing USN re-use. If the values are the same, the transaction is committed as normal.</p>
<p>AD DS also compares the current value of the VM GenerationID from the virtual machine against the value in the DIT each time the domain controller is rebooted and, if different, it resets the invocationID, discards the RID pool and updates the DIT with the new value. It also non-authoritatively synchronizes the SYSVOL folder in order to complete safe restoration. This enables the safeguards to extend to the application of snapshots on VMs that were shutdown. These safeguards introduced in Windows Server 2012 enable AD DS administrators to benefit from the unique advantages of deploying and managing domain controllers in a virtualized environment.</p>
<p>The following illustration shows how virtualization safeguards are applied when the same USN rollback is detected on a virtualized domain controller that runs Windows Server 2012 on a hypervisor that supports VM-GenerationID.</p>
<p><img id="793f3694-d3f9-427a-98ea-571033d474f4" title="Example of how virtualization safeguards work" alt="Example of how virtualization safeguards work" src="https://technet.microsoft.com/dynimg/IC619304.gif" /></p>
<p>In this case, when the hypervisor detects a change to VM-GenerationID value, virtualization safeguards are triggered, including the reset of the InvocationID for the virtualized DC (from A to B in the preceding example) and updating the VM-GenerationID value saved on the VM to match the new value (G2) stored by the hypervisor. The safeguards ensure that replication converges for both domain controllers.</p>
<p>With Windows Server 2012, AD DS employs safeguards on virtual domain controllers hosted on VM-GenerationID aware hypervisors and ensures that the accidental application of snapshots or other such hypervisor-enabled mechanisms that could ‘rollback’ a virtual machine’s state does not disrupt the AD DS environment (by preventing replication problems such as a USN bubble or lingering objects). However, restoring a domain controller by applying a virtual machine snapshot is not recommended as an alternative mechanism to backing up a domain controller. It is recommended that you continue to use Windows Server Backup or other VSS-writer based backup solutions.</p>
</div>
</div>
</div>
</blockquote>
<p><span style="text-decoration: underline;">References:</span></p>
<ul>
<li><a href="http://technet.microsoft.com/en-us/library/hh831734.aspx">Microsoft Article: Introduction to Active Directory Domain Services (AD DS) Virtualization (Level 100)</a></li>
<li><a href="https://www.microsoft.com/en-us/download/details.aspx?id=30707">Microsoft Virtual Machine Generation ID Whitepaper document</a></li>
<li><a href="http://blogs.virtualizationadmin.com/lowe/2012/07/31/virtualize-your-windows-server-2012-domain-controllers/">Virtualize your Windows Server 2012 domain controllers</a></li>
<li><a href="http://support.microsoft.com/kb/888794">Things to consider when you host Active Directory domain controllers in virtual hosting environments</a></li>
<li><a href="http://technet.microsoft.com/en-us/library/jj574223.aspx">Virtualized Domain Controller Deployment and Configuration</a></li>
<li><a href="http://blogs.vmware.com/apps/2013/01/windows-server-2012-vm-generation-id-support-in-vsphere.html">Windows Server 2012 VM-Generation ID Support in vSphere</a></li>
<li><a href="http://technet.microsoft.com/en-us/subscriptions/hh446580%28v=vs.85%29.aspx">ms-DS-Generation-Id Attribute</a></li>
</ul>
<p><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://blogs.metcorpconsulting.com/tech/?p=1471"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://blogs.metcorpconsulting.com/tech/?p=1471" data-text="Virtualization Updates to Active Directory 2012"></a><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://blogs.metcorpconsulting.com/tech/?p=1471"></a><a class="a2a_button_google_plus" href="http://www.addtoany.com/add_to/google_plus?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1471&amp;linkname=Virtualization%20Updates%20to%20Active%20Directory%202012" title="Google+" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/google_plus.png" width="16" height="16" alt="Google+"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1471&amp;linkname=Virtualization%20Updates%20to%20Active%20Directory%202012" title="Facebook" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1471&amp;linkname=Virtualization%20Updates%20to%20Active%20Directory%202012" title="Email" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:print()" title="Print" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/print.png" width="16" height="16" alt="Print"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1471&amp;title=Virtualization%20Updates%20to%20Active%20Directory%202012" id="wpa2a_34"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.metcorpconsulting.com/tech/?feed=rss2&#038;p=1471</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Active Directory Changes in Windows Server 2012</title>
		<link>http://blogs.metcorpconsulting.com/tech/?p=1468</link>
		<comments>http://blogs.metcorpconsulting.com/tech/?p=1468#comments</comments>
		<pubDate>Tue, 12 Feb 2013 20:17:13 +0000</pubDate>
		<dc:creator>Sean Metcalf</dc:creator>
				<category><![CDATA[Career]]></category>
		<category><![CDATA[Microsoft Products]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[Technical Reference]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[WindowsServer2012]]></category>

		<guid isPermaLink="false">http://blogs.metcorpconsulting.com/tech/?p=1468</guid>
		<description><![CDATA[Active Directory, aka Directory Services, has been updated quite a bit in Windows Server 2012. Here are some of the major updates: Virtualization: Rapid deployment with cloning &#38; safeguarding Dynamic Access Control DirectAccess Offline Domain Join Active Directory Federation Services (AD FS) Active Directory Administrative Center Improvements PowerShell version 3 commandlets including Active Directory Replication [...]]]></description>
				<content:encoded><![CDATA[<p>Active Directory, aka Directory Services, has been updated quite a bit in Windows Server 2012.</p>
<p>Here are some of the major updates:</p>
<ul>
<li><a title="Virtualization Updates to Active Directory 2012" href="http://blogs.metcorpconsulting.com/tech/?p=1471">Virtualization</a>: Rapid deployment with cloning &amp; safeguarding</li>
<li><a href="https://blogs.technet.com/b/wincat/archive/2012/11/07/planning-for-windows-server-2012-dynamic-access-control-deployments-dac.aspx?Redirected=true">Dynamic Access Control</a></li>
<li><a href="http://technet.microsoft.com/en-us/library/jj574150.aspx">DirectAccess Offline Domain Join</a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh831502.aspx">Active Directory Federation Services (AD FS)</a></li>
<li>Active Directory Administrative Center Improvements</li>
<li>PowerShell version 3 commandlets including Active Directory Replication and Topology (<a href="http://technet.microsoft.com/en-us/library/hh831757.aspx">Introduction </a>&amp; <a href="http://technet.microsoft.com/en-us/library/jj574083.aspx">Advanced </a>Topics)</li>
<li>Windows PowerShell History Viewer</li>
<li>Active Directory Recycle Bin User Interface</li>
<li>Fine-Grained Password Policy User Interface</li>
<li><a href="https://blogs.technet.com/b/askpfeplat/archive/2013/02/04/active-directory-based-activation-vs-key-management-services.aspx?Redirected=true">Active Directory Based Activation</a></li>
<li><a href="https://blogs.technet.com/b/askpfeplat/archive/2012/12/17/windows-server-2012-group-managed-service-accounts.aspx?Redirected=true">Group Managed Service Accounts</a></li>
<li><a href="http://technet.microsoft.com/en-us/library/hh831747.aspx">Flexible Authentication Secure Tunneling (FAST)</a> (<a href="http://tools.ietf.org/html/rfc6113">RFC 6113</a>) adds additional security to Kerberos (also known as Kerberos Armoring) and requires Windows Server 2012 with Windows 8.</li>
<li>RID Improvements: Protection &amp; Expansion</li>
<li>Kerberos Constrained Delegation now possible across forests</li>
<li>Enhanced LDAP logging and new controls</li>
<li>Deferred Index Creation &#8211; DCs can be configured to build indexes at reboot or via LDAP control versus the default: immediate index creation.</li>
<li>Ability to track DNT usage on Windows Server 2012 DCs using perfmon.</li>
</ul>
<p><a href="http://technet.microsoft.com/en-us/library/hh831477.aspx">Microsoft article: &#8220;What&#8217;s New in Active Directory Domain Services (AD DS)&#8221;</a></p>
<p><a href="http://download.microsoft.com/download/5/B/2/5B254183-FA53-4317-B577-7561058CEF42/WS%202012%20Evaluation%20Guide.pdf">Microsoft WhitePaper: Windows Server 2012 Evaluation Guide (pdf download)</a></p>
<p>&nbsp;</p>
<p><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://blogs.metcorpconsulting.com/tech/?p=1468"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://blogs.metcorpconsulting.com/tech/?p=1468" data-text="Active Directory Changes in Windows Server 2012"></a><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://blogs.metcorpconsulting.com/tech/?p=1468"></a><a class="a2a_button_google_plus" href="http://www.addtoany.com/add_to/google_plus?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1468&amp;linkname=Active%20Directory%20Changes%20in%20Windows%20Server%202012" title="Google+" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/google_plus.png" width="16" height="16" alt="Google+"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1468&amp;linkname=Active%20Directory%20Changes%20in%20Windows%20Server%202012" title="Facebook" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1468&amp;linkname=Active%20Directory%20Changes%20in%20Windows%20Server%202012" title="Email" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:print()" title="Print" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/print.png" width="16" height="16" alt="Print"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1468&amp;title=Active%20Directory%20Changes%20in%20Windows%20Server%202012" id="wpa2a_36"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.metcorpconsulting.com/tech/?feed=rss2&#038;p=1468</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Server 2012 Videos</title>
		<link>http://blogs.metcorpconsulting.com/tech/?p=1463</link>
		<comments>http://blogs.metcorpconsulting.com/tech/?p=1463#comments</comments>
		<pubDate>Wed, 06 Feb 2013 21:00:51 +0000</pubDate>
		<dc:creator>Sean Metcalf</dc:creator>
				<category><![CDATA[Microsoft Products]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[Videos]]></category>
		<category><![CDATA[Windows2012]]></category>
		<category><![CDATA[WindowsServer2012]]></category>

		<guid isPermaLink="false">http://blogs.metcorpconsulting.com/tech/?p=1463</guid>
		<description><![CDATA[TechEd 2012 in Orlando, Florida had lots of sessions covering Windows Server 2012. Here&#8217;s a list: Modernizing Your Datacenter Windows Server 2012 Overview What’s New in Windows Server 2012 Hyper-V, Part 1 Windows Server 2012 VDI/RDS Infrastructure and Management What’s New in Windows Server 2012 Hyper-V, Part 2 Windows Server 2012 Networking Performance and Management [...]]]></description>
				<content:encoded><![CDATA[<p>TechEd 2012 in Orlando, Florida had lots of sessions covering Windows Server 2012.</p>
<p>Here&#8217;s a list:</p>
<ul>
<li><a title="Modernizing Your Datacenter" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/FDN04">Modernizing Your Datacenter</a></li>
<li><strong><a title="Windows Server 2012 Overview" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/WSV205">Windows Server 2012 Overview</a></strong></li>
<li><a title="What's New in Windows Server 2012 Hyper-V, Part 1" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/VIR308">What’s New in Windows Server 2012 Hyper-V, Part 1</a></li>
<li><a title="RDS Infrastructure and Management" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/VIR314">Windows Server 2012 VDI/RDS Infrastructure and Management</a></li>
<li><a title="What's New in Windows Server 2012 Hyper-V, Part 2" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/VIR309">What’s New in Windows Server 2012 Hyper-V, Part 2</a></li>
<li><a title="Windows Server 2012 Networking Performance and Management" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/WSV304">Windows Server 2012 Networking Performance and Management</a></li>
<li><a title="Windows Server 2012 Dynamic Access Control Overview" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/SIA207">Windows Server 2012 Dynamic Access Control Overview</a></li>
<li><a title="Compete to Win, Part 1- Comparing Core Virtualization Platforms" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/VIR311">Compete to Win, Part 1- Comparing Core Virtualization Platforms</a></li>
<li><a title="Inside Windows Server 2012 Multi-Server Management Capabilities" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/WSV306">Inside Windows Server 2012 Multi-Server Management Capabilities</a></li>
<li><a title="Cluster Shared Volumes Reborn in Windows Server 2012- Deep Dive" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/WSV430">Cluster Shared Volumes Reborn in Windows Server 2012- Deep Dive</a></li>
<li><a title="The Path to Continuous Availability with Windows Server 2012" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/WSV328">The Path to Continuous Availability with Windows Server 2012</a></li>
<li><a title="Private Cloud" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/WSV210">Dell Windows Server 2012 Greenfield Data Design – Hosted Server / Private Cloud</a></li>
<li><a title="Windows Server 2012 Hyper-V Storage" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/VIR301">Windows Server 2012 Hyper-V Storage</a></li>
<li><strong><a title="13 at 3-15 pm)" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/SIA312">What’s New in Active Directory in Windows Server 2012</a></strong></li>
<li><a title="RemoteFX and RDP Rocking RDS in Windows Server 2012" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/VIR313">RemoteFX and RDP Rocking RDS in Windows Server 2012</a></li>
<li><a title="Hyper-V over SMB2- Remote File Storage Support in Windows Server 2012 Hyper-V" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/VIR306">Hyper-V over SMB2- Remote File Storage Support in Windows Server 2012 Hyper-V</a></li>
<li><a title="Standards Support and Interoperability in Windows Server 2012- Storage, Networking, and Manageme" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/WSV308">Standards Support and Interoperability in Windows Server 2012- Storage, Networking, and Management</a></li>
<li><a title="Deploying Windows Server 2012- From Bare Metal, Server Core, Minimal Server Interface, and More" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/WSV309">Deploying Windows Server 2012- From Bare Metal, Server Core, Minimal Server Interface, and More</a></li>
<li><a title="Windows Server 2012 NIC Teaming and Multichannel Solutions" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/WSV314">Windows Server 2012 NIC Teaming and Multichannel Solutions</a></li>
<li><a title="Windows Server 2012 Dynamic Access Control Deep Dive for Active Directory and Central Authorizat" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/SIA341">Windows Server 2012 Dynamic Access Control Deep Dive for Active Directory and Central Authorization</a></li>
<li><a title="Hyper-V High-Availability and Mobility- Designing the Infrastructure for Your Private Cloud" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/VIR401">Hyper-V High-Availability and Mobility- Designing the Infrastructure for Your Private Cloud</a></li>
<li><a title="Windows Server 2012 + Advanced Storage Solutions = Datacenter Elevation" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/WSV212">Windows Server 2012 + Advanced Storage Solutions = Datacenter Elevation</a></li>
<li><a title="Building a Highly Available Failover Cluster Solution with Windows Server 2012 from the Ground U" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/WSV324">Building a Highly Available Failover Cluster Solution with Windows Server 2012 from the Ground Up</a></li>
<li><a title="Windows Server 2012 File and Storage Services Management" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/WSV334">Windows Server 2012 File and Storage Services Management</a></li>
<li><a title="An Overview of Hyper-V Networking in Windows Server 2012" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/VIR303">An Overview of Hyper-V Networking in Windows Server 2012</a></li>
<li><a title="Windows Server 2012 Dynamic Access Control Best Practices and Case Study Deployments in Microsof" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/SIA316">Windows Server 2012 Dynamic Access Control Best Practices and Case Study Deployments in Microsoft</a></li>
<li><strong><a title="Active Directory Virtualization Safeguards and Domain Controller Cloning with Windows Server 201" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/SIA317">Active Directory Virtualization Safeguards and Domain Controller Cloning with Windows Server 2012</a></strong></li>
<li><a title="Get Hands-on with the New Hyper-V Extensible Switch in Windows Server 2012" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/VIR307">Get Hands-on with the New Hyper-V Extensible Switch in Windows Server 2012</a></li>
<li><a title="Windows Server 2012 Storage Solutions- Vast Storage Capabilities for Everyone" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/WSV327">Windows Server 2012 Storage Solutions- Vast Storage Capabilities for Everyone</a></li>
<li><a title="Update Management in Windows Server 2012- Revealing Cluster-Aware Updating and the New Generatio" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/WSV322">Update Management in Windows Server 2012- Revealing Cluster-Aware Updating and the New Generation of WSUS</a></li>
<li><a title="Windows Server 2012 IP Address Management" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/WSV307">Windows Server 2012 IP Address Management</a></li>
<li><a title="Windows Server 2012 DirectAccess- How to Quickly and Easily Deploy Your Next Generation Remote…" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/WSV302">Windows Server 2012 DirectAccess- How to Quickly and Easily Deploy Your Next Generation Remote Access Experience</a></li>
<li><a title="Windows Server 2012 High-Performance, Highly-Available Storage Using SMB" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/WSV303">Windows Server 2012 High-Performance, Highly-Available Storage Using SMB</a></li>
<li><a title="Windows Server 2012 File System Enhancements- Redefining File Storage" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/WSV315">Windows Server 2012 File System Enhancements- Redefining File Storage</a></li>
<li><a title="Hyper-V Network Virtualization for Scalable Multi-Tenancy in Windows" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/VIR305">Hyper-V Network Virtualization for Scalable Multi-Tenancy in Windows</a></li>
<li><strong><a title="Windows Server 2012- A Techie’s Insight into the Hot New Features" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/WSV326">Windows Server 2012- A Techie’s Insight into the Hot New Features</a></strong></li>
<li><a title="Networking for Hybrid Cloud- BranchCache and Cross Premise Connectivity" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/WSV333">Networking for Hybrid Cloud- BranchCache and Cross Premise Connectivity</a></li>
<li><a title="Windows Server 2012- Cluster-in-a-Box, RDMA, and More" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/WSV310">Windows Server 2012- Cluster-in-a-Box, RDMA, and More</a></li>
<li><a title="Using the Windows Server 2012 Server Manager for Remote and Multi-Server Management" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/WSV335">Using the Windows Server 2012 Server Manager for Remote and Multi-Server Management</a></li>
<li><a title="Building Flexible Hyper-V Environments Windows Server 2012 Hyper-V Live Migration and Live Stora" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/VIR304">Building Flexible Hyper-V Environments Windows Server 2012 Hyper-V Live Migration and Live Stora</a></li>
<li><a title="Preparing for The Big One - Protection and Recovery Using New Capabilities of Windows…" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/MGT327">Preparing for The Big One – Protection and Recovery Using New Capabilities of Windows Server 2012 &amp; System Center 2012 SP1</a></li>
<li><strong><a title="The Evolution of Active Directory Recovery" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/SIA319">The Evolution of Active Directory Recovery</a></strong></li>
<li><a title="What’s New with Windows Server 2012 and Microsoft System Center 2012 SP1" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/VIR201">What’s New with Windows Server 2012 and Microsoft System Center 2012 SP1</a></li>
<li><a title="Guest Clustering and VM Monitoring in Windows Server 2012" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/WSV411">Guest Clustering and VM Monitoring in Windows Server 2012</a></li>
<li><a title="Deploying Private Clouds (Lessons Learned from the Windows Server 2012 TAP)" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/WSV323">Deploying Private Clouds (Lessons Learned from the Windows Server 2012 TAP)</a></li>
<li><a title="DNSSEC Deployment with Windows Server 2012" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/WSV325">DNSSEC Deployment with Windows Server 2012</a></li>
<li><a title="Building Hosted Public and Private Clouds Using Windows Server 2012" href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/WSV301">Building Hosted Public and Private Clouds Using Windows Server 2012</a></li>
</ul>
<p>From:  <a href="http://kurtsh.com/2012/08/17/video-windows-server-2012-recordings-teched-2012/">Kurtsh.com</a></p>
<p><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://blogs.metcorpconsulting.com/tech/?p=1463"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://blogs.metcorpconsulting.com/tech/?p=1463" data-text="Windows Server 2012 Videos"></a><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://blogs.metcorpconsulting.com/tech/?p=1463"></a><a class="a2a_button_google_plus" href="http://www.addtoany.com/add_to/google_plus?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1463&amp;linkname=Windows%20Server%202012%20Videos" title="Google+" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/google_plus.png" width="16" height="16" alt="Google+"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1463&amp;linkname=Windows%20Server%202012%20Videos" title="Facebook" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1463&amp;linkname=Windows%20Server%202012%20Videos" title="Email" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:print()" title="Print" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/print.png" width="16" height="16" alt="Print"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1463&amp;title=Windows%20Server%202012%20Videos" id="wpa2a_38"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.metcorpconsulting.com/tech/?feed=rss2&#038;p=1463</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fine Grained Password Policies</title>
		<link>http://blogs.metcorpconsulting.com/tech/?p=1448</link>
		<comments>http://blogs.metcorpconsulting.com/tech/?p=1448#comments</comments>
		<pubDate>Wed, 30 Jan 2013 20:17:21 +0000</pubDate>
		<dc:creator>Sean Metcalf</dc:creator>
				<category><![CDATA[Deployment]]></category>
		<category><![CDATA[Microsoft Products]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[FGPP]]></category>
		<category><![CDATA[Fine Grained Password Policies]]></category>
		<category><![CDATA[Password Policy]]></category>

		<guid isPermaLink="false">http://blogs.metcorpconsulting.com/tech/?p=1448</guid>
		<description><![CDATA[The AskPFE blog provides very useful information on a new feature in Active Directory starting with Windows Server 2008. This feature, Fine Grained Password Policies (FGPP), enables an organization to have multiple password policies. Hi All! DougG here to share some insight on password policies – enjoy. We were all excited when Windows 2008 Domain [...]]]></description>
				<content:encoded><![CDATA[<p>The AskPFE blog provides very useful information on a new feature in Active Directory starting with Windows Server 2008. This feature, Fine Grained Password Policies (FGPP), enables an organization to have multiple password policies.</p>
<blockquote><p>Hi All! DougG here to share some insight on password policies – enjoy.</p>
<p>We were all excited when Windows 2008 Domain Functional level introduced FGPP (Fine Grained Password Policies). After several years in the field I have not seen abuse of this feature. In-fact, I am pleased to share that those using the FGPP are taking the conservative approach. By that, I mean I am not finding 20 or 30 FGPPs in domains. Rather, only 1 to 3 FGPP have been typically sufficient for most customers using FGPP. This means you are still using the Default Domain Policy to manage passwords for users that do not have a FGPP applied to them.</p>
<p>It is the Domain Password Policy that is the more complex of the two and the reason for this post.</p>
<p><strong>WARNING!</strong></p>
<p><strong>First and for most, if you try to demo this or follow along on a domain make sure you are in a lab environment. What I am about to show you will impact the users and if you are in a production environment this will cause an RPE or CLM (Resume’ Producing Event or Career Limiting Move) – take your pick.</strong></p>
<p>If you know these three facts you will be able to understand why things work the way they do.</p>
<p>1. Only policies applied at the DOMAIN level will apply a password policy to domain users. This can be the Default Domain Policy DDP or a policy that you have added that has a higher precedence (lower number than the DDP). Or it can be a combination of policies at the domain level.</p>
<p>2. Any policies applied to OUs, INCLUDING the domain controller OU, which has password policies will not be applied.</p>
<p>3. The password policy is written at the domain head by the PDCe (remember the stance that we don’t support sub OUs for domain controllers?)</p>
<p>Where do we get tripped up? RSOP for one. RSOP results will show you the policy including any OU that has a password policy setting. But only policies at the Domain level apply to the domain users. So when you look at an RSOP result you scratch your head, because what the user is experiencing is not what is on the RSOP report.</p>
<p>For example: If you wanted users in a specific OU to have shorter password length requirement and applied a password policy on their OU you will see your new settings in an RSOP report for those users.</p></blockquote>
<p>Continue reading the <a href="https://blogs.technet.com/b/askpfeplat/archive/2013/01/14/fun-and-games-active-directory-password-policies.aspx?Redirected=true">article</a>.</p>
<p><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://blogs.metcorpconsulting.com/tech/?p=1448"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://blogs.metcorpconsulting.com/tech/?p=1448" data-text="Fine Grained Password Policies"></a><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://blogs.metcorpconsulting.com/tech/?p=1448"></a><a class="a2a_button_google_plus" href="http://www.addtoany.com/add_to/google_plus?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1448&amp;linkname=Fine%20Grained%20Password%20Policies" title="Google+" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/google_plus.png" width="16" height="16" alt="Google+"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1448&amp;linkname=Fine%20Grained%20Password%20Policies" title="Facebook" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1448&amp;linkname=Fine%20Grained%20Password%20Policies" title="Email" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:print()" title="Print" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/print.png" width="16" height="16" alt="Print"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1448&amp;title=Fine%20Grained%20Password%20Policies" id="wpa2a_40"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.metcorpconsulting.com/tech/?feed=rss2&#038;p=1448</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Powershell Code: Get Domain Trust Information</title>
		<link>http://blogs.metcorpconsulting.com/tech/?p=1443</link>
		<comments>http://blogs.metcorpconsulting.com/tech/?p=1443#comments</comments>
		<pubDate>Fri, 18 Jan 2013 20:17:12 +0000</pubDate>
		<dc:creator>Sean Metcalf</dc:creator>
				<category><![CDATA[Microsoft Products]]></category>
		<category><![CDATA[Powershell Code]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[Active Directory Trust]]></category>
		<category><![CDATA[Get-ADTrusts]]></category>

		<guid isPermaLink="false">http://blogs.metcorpconsulting.com/tech/?p=1443</guid>
		<description><![CDATA[A customer recently asked me to write a script that would provide information on every trust the domain had, specifically which ones had SID filtering enabled. The script provides a count of discovered trusts and if there is 1 or more discovered, it displays the trust information. Here&#8217;s the code: 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263Import-module ActiveDirectory $DomainDNS = (Get-ADDomain).DNSRoot [...]]]></description>
				<content:encoded><![CDATA[<p>A customer recently asked me to write a script that would provide information on every trust the domain had, specifically which ones had SID filtering enabled.</p>
<p>The script provides a count of discovered trusts and if there is 1 or more discovered, it displays the trust information.</p>
<p>Here&#8217;s the code:</p>
<div class="codecolorer-container text vibrant" style="overflow:auto;white-space:nowrap;border:1px solid #9F9F9F;width:435px;height:300px;"><table cellspacing="0" cellpadding="0"><tbody><tr><td style="padding:5px;text-align:center;color:#888888;background-color:#EEEEEE;border-right: 1px solid #9F9F9F;font: normal 12px/1.4em Monaco, Lucida Console, monospace;"><div>1<br />2<br />3<br />4<br />5<br />6<br />7<br />8<br />9<br />10<br />11<br />12<br />13<br />14<br />15<br />16<br />17<br />18<br />19<br />20<br />21<br />22<br />23<br />24<br />25<br />26<br />27<br />28<br />29<br />30<br />31<br />32<br />33<br />34<br />35<br />36<br />37<br />38<br />39<br />40<br />41<br />42<br />43<br />44<br />45<br />46<br />47<br />48<br />49<br />50<br />51<br />52<br />53<br />54<br />55<br />56<br />57<br />58<br />59<br />60<br />61<br />62<br />63<br /></div></td><td><div class="text codecolorer" style="padding:5px;font:normal 12px/1.4em Monaco, Lucida Console, monospace;white-space:nowrap">Import-module ActiveDirectory<br />
$DomainDNS = (Get-ADDomain).DNSRoot<br />
<br />
Write-output &quot;Get list of AD Domain Trusts in $DomainDNS `r&quot;<br />
$ADDomainTrusts = Get-ADObject -Filter {ObjectClass -eq &quot;trustedDomain&quot;} -Properties *<br />
[int]$ADDomainTrustsCount = $ADDomainTrusts.Count<br />
<br />
Write-Output &quot;Discovered $ADDomainTrustsCount trusts in $DomainDNS&quot;<br />
<br />
IF ($ADDomainTrustsCount -ge 1)<br />
{ ## OPEN IF ($ADDomainTrustsCount -ge 1)<br />
ForEach ($Trust in $ADDomainTrusts)<br />
{ ## OPEN ForEach ($Trust in $ADDomainTrusts)<br />
$TrustName = $Trust.Name<br />
$TrustDescription = $Trust.Description<br />
$TrustCreated = $Trust.Created<br />
$TrustModified = $Trust.Modified<br />
$TrustDirectionNumber = $Trust.DirectionNumber<br />
$TrustTypeNumber = $Trust.TypeNumber<br />
$TrustAttributesNumber = $Trust.AttributesNumber<br />
<br />
SWITCH ($TrustTypeNumber)<br />
{ ## OPEN SWITCH ($TrustTypeNumber)<br />
1 { $TrustType = &quot;Downlevel (Windows NT domain external&quot;}<br />
2 { $TrustType = &quot;Uplevel (Active Directory domain - parent-child, root domain, shortcut, external, or forest&quot;}<br />
3 { $TrustType = &quot;MIT (non-Windows) Kerberos version 5 realm&quot;}<br />
4 { $TrustType = &quot;DCE (Theoretical trust type - DCE refers to Open Group's Distributed Computing Environment specification.&quot;}<br />
} ## CLOSE SWITCH ($TrustTypeNumber)<br />
<br />
IF (!$TrustType) { $TrustType = $TrustTypeNumber }<br />
<br />
SWITCH ($TrustAttributesNumber)<br />
{ ## OPEN SWITCH ($TrustTypeNumber)<br />
1 { $TrustAttributes = &quot;Non-Transitive&quot;}<br />
2 { $TrustAttributes = &quot;Uplevel clients only (Windows 2000 or newer&quot;}<br />
4 { $TrustAttributes = &quot;Quarantined Domain (External)&quot;}<br />
8 { $TrustAttributes = &quot;Forest Trust&quot;}<br />
10 { $TrustAttributes = &quot;Cross-Organizational Trust (Selective Authentication)&quot;}<br />
20 { $TrustAttributes = &quot;Intra-Forest Trust (trust within the forest)&quot;}<br />
} ## CLOSE SWITCH ($TrustTypeNumber)<br />
<br />
IF (!$TrustAttributes) { $TrustAttributes = $TrustAttributesNumber }<br />
<br />
SWITCH ($TrustDirectionNumber)<br />
{ ## OPEN SWITCH ($TrustTypeNumber)<br />
1 { $TrustDirection = &quot;Inbound (TrustING domain)&quot;}<br />
2 { $TrustDirection = &quot;Outbound (TrustED domain)&quot;}<br />
3 { $TrustDirection = &quot;Bidirectional (two-way trust)&quot;}<br />
} ## CLOSE SWITCH ($TrustTypeNumber)<br />
<br />
IF (!$TrustDirection) { $TrustDirection = $TrustDirectionNumber }<br />
<br />
Write-output &quot;Trust Name: $TrustName `r &quot;<br />
Write-output &quot;Trust Description: $TrustDescription `r &quot;<br />
Write-output &quot;Trust Created: $TrustCreated `r &quot;<br />
Write-output &quot;Trust Modified: $TrustModified `r &quot;<br />
Write-output &quot;Trust Direction: $TrustDirection `r &quot;<br />
Write-output &quot;Trust Type: $TrustType `r &quot;<br />
Write-output &quot;Trust Attributes: $TrustAttributes `r &quot;<br />
Write-output &quot; `r &quot;<br />
<br />
} ## CLOSE ForEach ($Trust in $ADDomainTrusts)<br />
} ## CLOSE IF ($ADDomainTrustsCount -ge 1)</div></td></tr></tbody></table></div>
<p><span style="text-decoration: underline;"><strong>References:</strong></span></p>
<p><a href="http://technet.microsoft.com/en-us/library/cc757352%28v=ws.10%29.aspx"></p>
<ul>
<li>Understanding Trust Types</li>
<li>Trust Technologies</li>
<li>What are Domain and Forest Trusts?</li>
</ul>
<p></a></p>
<p><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://blogs.metcorpconsulting.com/tech/?p=1443"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://blogs.metcorpconsulting.com/tech/?p=1443" data-text="Powershell Code: Get Domain Trust Information"></a><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://blogs.metcorpconsulting.com/tech/?p=1443"></a><a class="a2a_button_google_plus" href="http://www.addtoany.com/add_to/google_plus?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1443&amp;linkname=Powershell%20Code%3A%20Get%20Domain%20Trust%20Information" title="Google+" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/google_plus.png" width="16" height="16" alt="Google+"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1443&amp;linkname=Powershell%20Code%3A%20Get%20Domain%20Trust%20Information" title="Facebook" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1443&amp;linkname=Powershell%20Code%3A%20Get%20Domain%20Trust%20Information" title="Email" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:print()" title="Print" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/print.png" width="16" height="16" alt="Print"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1443&amp;title=Powershell%20Code%3A%20Get%20Domain%20Trust%20Information" id="wpa2a_42"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.metcorpconsulting.com/tech/?feed=rss2&#038;p=1443</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AskPFE&#8217;s Most Popular Posts of 2012</title>
		<link>http://blogs.metcorpconsulting.com/tech/?p=1434</link>
		<comments>http://blogs.metcorpconsulting.com/tech/?p=1434#comments</comments>
		<pubDate>Sat, 12 Jan 2013 21:00:02 +0000</pubDate>
		<dc:creator>Sean Metcalf</dc:creator>
				<category><![CDATA[Tech]]></category>
		<category><![CDATA[Technical Reference]]></category>

		<guid isPermaLink="false">http://blogs.metcorpconsulting.com/tech/?p=1434</guid>
		<description><![CDATA[AskPFE posted their most popular posts of 2012. There&#8217;s a lot of useful information in these posts: 10.) Want Remote PowerShell Management from your browser? See how PowerShell Web Access in Windows Server 2012 may help… 9.) Slow Boot Slow Logon (SBSL), A Tool Called XPerf and Links You Need To Read 8.) MCM: Core [...]]]></description>
				<content:encoded><![CDATA[<p><a href="http://blogs.technet.com/b/askpfeplat/?Redirected=true">AskPFE</a> posted their most popular posts of 2012.</p>
<p>There&#8217;s a lot of useful information in these posts:</p>
<p>10.) <a title="Want Remote PowerShell Management from your browser? See how PowerShell Web Access in Windows Server 2012 may help…" href="http://blogs.technet.com/b/askpfeplat/archive/2012/09/17/want-remote-powershell-management-from-your-browser-see-how-powershell-web-access-in-windows-server-2012-may-help.aspx">Want Remote PowerShell Management from your browser? See how PowerShell Web Access in Windows Server 2012 may help…</a></p>
<p>9.)<a href="http://blogs.technet.com/b/askpfeplat/archive/2012/06/09/slow-boot-slow-logon-sbsl-a-tool-called-xperf-and-links-you-need-to-read.aspx"> Slow Boot Slow Logon (SBSL), A Tool Called XPerf and Links You Need To Read</a></p>
<p>8.) <a href="http://blogs.technet.com/b/askpfeplat/archive/2012/07/23/mcm-core-active-directory-internals.aspx">MCM: Core Active Directory Internals</a></p>
<p>7.) <a href="http://blogs.technet.com/b/askpfeplat/archive/2011/12/12/how-to-implement-the-central-store-for-group-policy-admin-templates-completely-hint-remove-those-adm-files.aspx">How to Implement the Central Store for Group Policy Admin Templates, Completely (Hint: Remove Those .ADM files!)</a></p>
<p>6.) <a href="http://blogs.technet.com/b/askpfeplat/archive/2012/11/19/hyper-v-2008-r2-sp1-best-practices-in-easy-checklist-form.aspx">HYPER-V 2008 R2 SP1 Best Practices (In Easy Checklist Form)</a></p>
<p>5.) <a href="http://blogs.technet.com/b/askpfeplat/archive/2012/01/16/how-to-become-a-premier-field-engineer-pfe.aspx">How to become a Premier Field Engineer (PFE)</a></p>
<p>4.) <a href="http://blogs.technet.com/b/askpfeplat/archive/2012/10/01/virtual-domain-controller-cloning-in-windows-server-2012.aspx">Virtual Domain Controller Cloning in Windows Server 2012</a></p>
<p>3.) <a href="http://blogs.technet.com/b/askpfeplat/archive/2012/10/10/windows-server-2012-storage-spaces-is-it-for-you-could-be.aspx">Windows Server 2012 Storage Spaces: Is it for you? Could be…</a></p>
<p>2.) <a href="http://blogs.technet.com/b/askpfeplat/archive/2012/09/03/introducing-the-first-windows-server-2012-domain-controller.aspx">Introducing the first Windows Server 2012 Domain Controller (Part 1 of 2)</a></p>
<p>1.) <a href="http://blogs.technet.com/b/askpfeplat/archive/2012/11/19/did-your-active-directory-domain-time-just-jump-to-the-year-2000.aspx">Did Your Active Directory Domain Time Just Jump To The Year 2000?</a> / <a href="http://blogs.technet.com/b/askpfeplat/archive/2012/11/23/fixing-when-your-domain-traveled-back-in-time-the-great-system-time-rollback-to-the-year-2000.aspx">Fixing When Your Domain Traveled Back In Time, the Great System Time Rollback to the Year 2000</a></p>
<p>Here&#8217;s the <a href="https://blogs.technet.com/b/askpfeplat/archive/2013/01/09/the-most-popular-posts-of-2012.aspx?Redirected=true">full blog post</a>.</p>
<p><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://blogs.metcorpconsulting.com/tech/?p=1434"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://blogs.metcorpconsulting.com/tech/?p=1434" data-text="AskPFE&#8217;s Most Popular Posts of 2012"></a><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://blogs.metcorpconsulting.com/tech/?p=1434"></a><a class="a2a_button_google_plus" href="http://www.addtoany.com/add_to/google_plus?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1434&amp;linkname=AskPFE%E2%80%99s%20Most%20Popular%20Posts%20of%202012" title="Google+" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/google_plus.png" width="16" height="16" alt="Google+"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1434&amp;linkname=AskPFE%E2%80%99s%20Most%20Popular%20Posts%20of%202012" title="Facebook" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1434&amp;linkname=AskPFE%E2%80%99s%20Most%20Popular%20Posts%20of%202012" title="Email" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:print()" title="Print" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/print.png" width="16" height="16" alt="Print"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1434&amp;title=AskPFE%E2%80%99s%20Most%20Popular%20Posts%20of%202012" id="wpa2a_44"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.metcorpconsulting.com/tech/?feed=rss2&#038;p=1434</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CMD to PowerShell Guide for AD</title>
		<link>http://blogs.metcorpconsulting.com/tech/?p=1419</link>
		<comments>http://blogs.metcorpconsulting.com/tech/?p=1419#comments</comments>
		<pubDate>Thu, 03 Jan 2013 21:00:45 +0000</pubDate>
		<dc:creator>Sean Metcalf</dc:creator>
				<category><![CDATA[Microsoft Products]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[Technical Reference]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Powershell Reference]]></category>

		<guid isPermaLink="false">http://blogs.metcorpconsulting.com/tech/?p=1419</guid>
		<description><![CDATA[The Goatee PFE has put together an excellent guide cross-referencing Active Directory commands with the AD Powershell commandlets. While studying the new 2012 cmdlets in preparation for conference talks last summer I created a quick cheat sheet for PowerShell equivalence to REPADMIN and DNSCMD. The other day I sat down and expanded this to include [...]]]></description>
				<content:encoded><![CDATA[<p>The Goatee PFE has put together an excellent guide cross-referencing Active Directory commands with the AD Powershell commandlets.</p>
<blockquote><p>While studying the new 2012 cmdlets in preparation for conference talks last summer I created a quick cheat sheet for PowerShell equivalence to REPADMIN and DNSCMD. The other day I sat down and expanded this to include a raft of familiar utilities:</p>
<table border="0" cellspacing="0" cellpadding="2">
<tbody>
<tr>
<td valign="top" width="133">REPADMIN<br />
DCPROMO<br />
CSVDE<br />
NETDOM<br />
NLTEST<br />
GPUPDATE<br />
GPRESULT</td>
<td valign="top" width="133">DSGET<br />
DSQUERY<br />
DSADD<br />
DSMOD<br />
DSRM<br />
DSMOVE<br />
DSACLS</td>
<td valign="top" width="133">DNSCMD<br />
NSLOOKUP<br />
PING<br />
IPCONFIG<br />
NETSTAT</td>
</tr>
</tbody>
</table>
<p>This guide will get you off and running to convert any old batch files you still have lying around or hiding in scheduled tasks.</p></blockquote>
<p><a href="https://blogs.technet.com/b/ashleymcglone/archive/2013/01/02/free-download-cmd-to-powershell-guide-for-ad.aspx?Redirected=true">Download the PDF from Goatee PFE</a></p>
<p><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://blogs.metcorpconsulting.com/tech/?p=1419"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://blogs.metcorpconsulting.com/tech/?p=1419" data-text="CMD to PowerShell Guide for AD"></a><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://blogs.metcorpconsulting.com/tech/?p=1419"></a><a class="a2a_button_google_plus" href="http://www.addtoany.com/add_to/google_plus?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1419&amp;linkname=CMD%20to%20PowerShell%20Guide%20for%20AD" title="Google+" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/google_plus.png" width="16" height="16" alt="Google+"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1419&amp;linkname=CMD%20to%20PowerShell%20Guide%20for%20AD" title="Facebook" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1419&amp;linkname=CMD%20to%20PowerShell%20Guide%20for%20AD" title="Email" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:print()" title="Print" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/print.png" width="16" height="16" alt="Print"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1419&amp;title=CMD%20to%20PowerShell%20Guide%20for%20AD" id="wpa2a_46"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.metcorpconsulting.com/tech/?feed=rss2&#038;p=1419</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Behind the Scenes with DCPromo Install From Media (IFM)</title>
		<link>http://blogs.metcorpconsulting.com/tech/?p=1415</link>
		<comments>http://blogs.metcorpconsulting.com/tech/?p=1415#comments</comments>
		<pubDate>Wed, 12 Dec 2012 21:00:18 +0000</pubDate>
		<dc:creator>Sean Metcalf</dc:creator>
				<category><![CDATA[Microsoft Products]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[Technical Reference]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[DCPromo]]></category>
		<category><![CDATA[IFM]]></category>

		<guid isPermaLink="false">http://blogs.metcorpconsulting.com/tech/?p=1415</guid>
		<description><![CDATA[Here&#8217;s a great blog post on Behind the Scenes with DCPromo Install From Media (IFM): Install from media (IFM) contains two important things. NTDS.DIT (Active Directory Database) – at the time the IFM is generated (Regardless of Windows Server 2003, Windows Server 2008 or later –the NTDS.dit is pretty much unchanged until DCPROMO makes a [...]]]></description>
				<content:encoded><![CDATA[<p>Here&#8217;s a great blog post on Behind the Scenes with DCPromo Install From Media (IFM):</p>
<blockquote><p>Install from media (IFM) contains two important things.</p>
<ul>
<li>NTDS.DIT (Active Directory Database) – at the time the IFM is generated (Regardless of Windows Server 2003, Windows Server 2008 or later –the NTDS.dit is pretty much unchanged until DCPROMO makes a lot of changes at the becoming domain controller that takes use of the database – it will change the DSA reference and update related “instance specific” information in the hidden table )</li>
<li>SYSVOL (SYSVOL GPT Storage)</li>
<li>Registry (Contains the SYSKEY used to decrypt the PEK (also known as Password Encryption Key) that efficiently ensure that the protection for sensitive information stored in the Active Directory database (Such as Password Hashes) are unique to each instance of the database (read each domain controller) –Note: This doesn’t apply to RODCs .</li>
</ul>
</blockquote>
<ul>
<li><a title="IFM Part 1" href="http://blogs.chrisse.se/2011/07/08/how-install-from-media-ifm-really-works-part-1">Part 1</a></li>
<li><a title="IFM Part 2" href="http://blogs.chrisse.se/2011/07/29/how-install-from-media-ifm-really-works-part-2/ ">Part 2</a></li>
</ul>
<p><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://blogs.metcorpconsulting.com/tech/?p=1415"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://blogs.metcorpconsulting.com/tech/?p=1415" data-text="Behind the Scenes with DCPromo Install From Media (IFM)"></a><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://blogs.metcorpconsulting.com/tech/?p=1415"></a><a class="a2a_button_google_plus" href="http://www.addtoany.com/add_to/google_plus?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1415&amp;linkname=Behind%20the%20Scenes%20with%20DCPromo%20Install%20From%20Media%20%28IFM%29" title="Google+" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/google_plus.png" width="16" height="16" alt="Google+"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1415&amp;linkname=Behind%20the%20Scenes%20with%20DCPromo%20Install%20From%20Media%20%28IFM%29" title="Facebook" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1415&amp;linkname=Behind%20the%20Scenes%20with%20DCPromo%20Install%20From%20Media%20%28IFM%29" title="Email" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:print()" title="Print" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/print.png" width="16" height="16" alt="Print"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1415&amp;title=Behind%20the%20Scenes%20with%20DCPromo%20Install%20From%20Media%20%28IFM%29" id="wpa2a_48"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.metcorpconsulting.com/tech/?feed=rss2&#038;p=1415</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ASKPFE: MCM: Active Directory Indexing For the Masses</title>
		<link>http://blogs.metcorpconsulting.com/tech/?p=1417</link>
		<comments>http://blogs.metcorpconsulting.com/tech/?p=1417#comments</comments>
		<pubDate>Fri, 30 Nov 2012 21:00:49 +0000</pubDate>
		<dc:creator>Sean Metcalf</dc:creator>
				<category><![CDATA[MCM]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[Technical Reference]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[AD Indexing]]></category>

		<guid isPermaLink="false">http://blogs.metcorpconsulting.com/tech/?p=1417</guid>
		<description><![CDATA[Here&#8217;s a great article from the AskPFE Blog regarding Active Directory Indexing. The article includes lots of screenshots so you can follow along in your lab. ASKPFE: MCM: Active Directory Indexing For the Masses &#160;]]></description>
				<content:encoded><![CDATA[<p>Here&#8217;s a great article from the <a href="https://blogs.technet.com/b/askpfeplat/">AskPFE Blog</a> regarding Active Directory Indexing. The article includes lots of screenshots so you can follow along in your lab.</p>
<p><a href="https://blogs.technet.com/b/askpfeplat/archive/2012/11/12/mcm-active-directory-indexing-for-the-masses.aspx?Redirected=true">ASKPFE: MCM: Active Directory Indexing For the Masses</a></p>
<p>&nbsp;</p>
<p><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://blogs.metcorpconsulting.com/tech/?p=1417"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://blogs.metcorpconsulting.com/tech/?p=1417" data-text="ASKPFE: MCM: Active Directory Indexing For the Masses"></a><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://blogs.metcorpconsulting.com/tech/?p=1417"></a><a class="a2a_button_google_plus" href="http://www.addtoany.com/add_to/google_plus?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1417&amp;linkname=ASKPFE%3A%20MCM%3A%20Active%20Directory%20Indexing%20For%20the%20Masses" title="Google+" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/google_plus.png" width="16" height="16" alt="Google+"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1417&amp;linkname=ASKPFE%3A%20MCM%3A%20Active%20Directory%20Indexing%20For%20the%20Masses" title="Facebook" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1417&amp;linkname=ASKPFE%3A%20MCM%3A%20Active%20Directory%20Indexing%20For%20the%20Masses" title="Email" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:print()" title="Print" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/print.png" width="16" height="16" alt="Print"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1417&amp;title=ASKPFE%3A%20MCM%3A%20Active%20Directory%20Indexing%20For%20the%20Masses" id="wpa2a_50"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.metcorpconsulting.com/tech/?feed=rss2&#038;p=1417</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>When your system clock time-traveled</title>
		<link>http://blogs.metcorpconsulting.com/tech/?p=1455</link>
		<comments>http://blogs.metcorpconsulting.com/tech/?p=1455#comments</comments>
		<pubDate>Fri, 23 Nov 2012 22:00:09 +0000</pubDate>
		<dc:creator>Sean Metcalf</dc:creator>
				<category><![CDATA[Deployment]]></category>
		<category><![CDATA[Microsoft Products]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[Technical Reference]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[System Clock Skew]]></category>
		<category><![CDATA[Windows Time]]></category>

		<guid isPermaLink="false">http://blogs.metcorpconsulting.com/tech/?p=1455</guid>
		<description><![CDATA[Recently, there was a mistake with the NTP time system from the Navy tricking many computer systems into thinking it was the year 2000 again. More detailed information on the AskPFE blog: Hey y’all, Mark back again with some more detail around what to when the system time rollback to November 19th 2000, caused Active Directory [...]]]></description>
				<content:encoded><![CDATA[<p>Recently, there was a mistake with the NTP time system from the Navy tricking many computer systems into thinking it was the year 2000 again.</p>
<p>More detailed information on the <a href="http://blogs.technet.com/b/askpfeplat/?Redirected=true">AskPFE blog</a>:</p>
<blockquote><p>Hey y’all, Mark back again with some more detail around what to when the system time rollback to November 19<sup>th </sup>2000, caused Active Directory replication and other time-sensitive operations to fail in your environment. This post contains guidance by a small army of Microsoft PFEs, support professionals and developers. If you have any questions about the recommendations in this post, feel free to give CTS a call and they can guide you through the recovery. Recovering from a time rollback is a complex situation so read each step carefully and don’t skip ahead or you’ll make the problem worse. Also this post is going to be a long one and will probably break the record for additional links so you’ll want to get comfortable.</p>
<p>Here is what this post is going to cover.</p>
<p><a href="https://blogs.technet.com/b/askpfeplat/archive/2012/11/23/fixing-when-your-domain-traveled-back-in-time-the-great-system-time-rollback-to-the-year-2000.aspx?Redirected=true#_How_Did_This">How Did This Happen?</a></p>
<p><a href="https://blogs.technet.com/b/askpfeplat/archive/2012/11/23/fixing-when-your-domain-traveled-back-in-time-the-great-system-time-rollback-to-the-year-2000.aspx?Redirected=true#_What_Are_The">What Are The Symptoms?</a></p>
<p><a href="https://blogs.technet.com/b/askpfeplat/archive/2012/11/23/fixing-when-your-domain-traveled-back-in-time-the-great-system-time-rollback-to-the-year-2000.aspx?Redirected=true#_Mitigation">Mitigation</a></p>
<p>1.) <a href="https://blogs.technet.com/b/askpfeplat/archive/2012/11/23/fixing-when-your-domain-traveled-back-in-time-the-great-system-time-rollback-to-the-year-2000.aspx?Redirected=true#_Correct_Time">Correct Time</a></p>
<p>2.) <a href="https://blogs.technet.com/b/askpfeplat/archive/2012/11/23/fixing-when-your-domain-traveled-back-in-time-the-great-system-time-rollback-to-the-year-2000.aspx?Redirected=true#_2%29_Check_for">Check For Replication Errors</a></p>
<p>3.) <a href="https://blogs.technet.com/b/askpfeplat/archive/2012/11/23/fixing-when-your-domain-traveled-back-in-time-the-great-system-time-rollback-to-the-year-2000.aspx?Redirected=true#_3%29_Additional_Mitigation">Additional Mitigation</a></p>
<p><a href="https://blogs.technet.com/b/askpfeplat/archive/2012/11/23/fixing-when-your-domain-traveled-back-in-time-the-great-system-time-rollback-to-the-year-2000.aspx?Redirected=true#_Ongoing_Tasks">Ongoing Tasks</a></p>
<h3>How Did This Happen?</h3>
<p>On November 19th, 2012, time servers at USNO.NAVY.MIL incorrectly provided time samples listing CY 2000 as the current year between the hours of 21:07 UTC and 21:59 UTC (16:07-16:59 EST). Get more info <a href="http://tycho.usno.navy.mil/ntp.html">here</a>.</p>
<p>Forests most impacted by this time rollback shared two traits:</p>
<p>1. The forest root PDC or master time servers in the forest lacked time jump protection discussed in in <a href="http://support.microsoft.com/kb/884776">KB 884776</a> (probably because they were running the W2K3 OS)</p>
<p>2. The forest contained Windows Server 2003 DCs (more on this below)</p>
<p>Windows added support for time jump protection starting with the Server 2003 (and XP member workstations) in the form of two registry values: MaxPosPhaseCorrection and MaxNegPhaseCorrection (we’ll refer to both these keys going forward as max*phasecorrection). By default, the max*phasecorrection settings are not populated on Windows Server 2003 DCs. As a result, such DCs adjust the system time after receiving forward or back-dated time samples. Windows Sever 2008 and later DCs set the max*phasecorrection settings to 48 hours and ignore time samples that vary by more than 48 hours from locally configured time.</p>
<p>Time jump protection is not defined on Windows member workstations or servers until enabled by an administrator for the following reasons. Microsoft Commercial Support has observed massive time jumps (from days to multiple decades in the past and future) in customer forests for the last 10 years. Multiple root causes exist but up until now have never been caused by a highly accurate time servers giving out inaccurate time. While the max*phasecorrection settings offer a degree of protection when the time service is running, it offers no protection when inaccurate time is adopted during a reboot or while the time service is not running. Furthermore, the use of max*phasecorrection can prevent client and server computers from adjusting back to accurate time. While smaller max*phasecorrection values make Windows time clients less susceptible to adopting bad time, they also make it hard for such clients to self-correct if good time varies by more than max*phasecorrection seconds in the past or future. For example, setting max*phasecorrection to say 1 hour would prevent time client from self-correcting from a time zone or AM | PM misconfiguration. Given the ratio of domain controllers to member servers and workstations, Microsoft elected not to configure time jump protection on such computers. More information on time jump protection can be found in <a href="http://support.microsoft.com/kb/884776">KB 884776</a>.</p></blockquote>
<p>&nbsp;</p>
<p>Read the rest of the AskPFE Article <a href="https://blogs.technet.com/b/askpfeplat/archive/2012/11/23/fixing-when-your-domain-traveled-back-in-time-the-great-system-time-rollback-to-the-year-2000.aspx?Redirected=true">here</a>.</p>
<p>&nbsp;</p>
<p><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://blogs.metcorpconsulting.com/tech/?p=1455"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://blogs.metcorpconsulting.com/tech/?p=1455" data-text="When your system clock time-traveled"></a><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://blogs.metcorpconsulting.com/tech/?p=1455"></a><a class="a2a_button_google_plus" href="http://www.addtoany.com/add_to/google_plus?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1455&amp;linkname=When%20your%20system%20clock%20time-traveled" title="Google+" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/google_plus.png" width="16" height="16" alt="Google+"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1455&amp;linkname=When%20your%20system%20clock%20time-traveled" title="Facebook" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1455&amp;linkname=When%20your%20system%20clock%20time-traveled" title="Email" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:print()" title="Print" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/print.png" width="16" height="16" alt="Print"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1455&amp;title=When%20your%20system%20clock%20time-traveled" id="wpa2a_52"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.metcorpconsulting.com/tech/?feed=rss2&#038;p=1455</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Domain Controller Virtual Cloning</title>
		<link>http://blogs.metcorpconsulting.com/tech/?p=1439</link>
		<comments>http://blogs.metcorpconsulting.com/tech/?p=1439#comments</comments>
		<pubDate>Sat, 10 Nov 2012 21:00:22 +0000</pubDate>
		<dc:creator>Sean Metcalf</dc:creator>
				<category><![CDATA[Deployment]]></category>
		<category><![CDATA[Microsoft Products]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[Technical Reference]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Domain Controller]]></category>
		<category><![CDATA[Virtual DC]]></category>

		<guid isPermaLink="false">http://blogs.metcorpconsulting.com/tech/?p=1439</guid>
		<description><![CDATA[One of the best new features of Windows Server 2012 is virtual cloning. The ASKPFE blog has an excellent article covering this new feature: Tom Moser here with a post on one of the new ADDS features in Windows Server 2012; Virtual Domain Controller Cloning. Until now, cloning, snapshotting, copying, or pretty much doing anything [...]]]></description>
				<content:encoded><![CDATA[<p>One of the best new features of Windows Server 2012 is virtual cloning.</p>
<p>The <a href="http://blogs.technet.com/b/askpfeplat/?Redirected=true">ASKPFE blog</a> has an excellent article covering this new feature:</p>
<blockquote><p>Tom Moser here with a post on one of the new ADDS features in Windows Server 2012; Virtual Domain Controller Cloning.</p>
<p>Until now, cloning, snapshotting, copying, or pretty much doing anything but rebuilding from scratch to a virtual domain controller wasn&#8217;t just unsupported; it had the potential to be really bad for your directory. Cloning or restoring snapshots of DCs could result in <a href="http://support.microsoft.com/kb/875495">USN rollbacks</a> or lingering objects, just to name a couple of problems.</p>
<p>Starting in Windows Server 2012, we now support DC cloning as well as snapshot restoration of domain controllers. With the RTM bits available, I found myself rebuilding my lab and took the opportunity to document the process to demonstrate just how easy it is to clone virtual domain controllers with Windows Server 2012.</p>
<p>Requirements</p>
<p>There are a few base infrastructure requirements to take advantage of DC cloning.</p>
<ul>
<li>The hypervisor must support VM-GenerationID. Hyper-V running on Windows Server 2012 supports this feature. Other virtualization vendors will have the ability to implement this as well, so check with your vendor to see if it&#8217;s supported.</li>
<li>The source virtual DC must be running Windows Server 2012.</li>
<li>The PDC emulator role holder must be online and available to the cloned DC <em>and </em>must be running Windows Server 2012.</li>
</ul>
<p>There are a few other steps and requirements and I&#8217;ll take you through those now.</p></blockquote>
<p>Read the rest of the article <a href="https://blogs.technet.com/b/askpfeplat/archive/2012/10/01/virtual-domain-controller-cloning-in-windows-server-2012.aspx?Redirected=true">here</a>.</p>
<p><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://blogs.metcorpconsulting.com/tech/?p=1439"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://blogs.metcorpconsulting.com/tech/?p=1439" data-text="Domain Controller Virtual Cloning"></a><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://blogs.metcorpconsulting.com/tech/?p=1439"></a><a class="a2a_button_google_plus" href="http://www.addtoany.com/add_to/google_plus?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1439&amp;linkname=Domain%20Controller%20Virtual%20Cloning" title="Google+" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/google_plus.png" width="16" height="16" alt="Google+"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1439&amp;linkname=Domain%20Controller%20Virtual%20Cloning" title="Facebook" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1439&amp;linkname=Domain%20Controller%20Virtual%20Cloning" title="Email" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:print()" title="Print" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/print.png" width="16" height="16" alt="Print"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1439&amp;title=Domain%20Controller%20Virtual%20Cloning" id="wpa2a_54"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.metcorpconsulting.com/tech/?feed=rss2&#038;p=1439</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Post-Graduate AD Studies</title>
		<link>http://blogs.metcorpconsulting.com/tech/?p=1432</link>
		<comments>http://blogs.metcorpconsulting.com/tech/?p=1432#comments</comments>
		<pubDate>Tue, 30 Oct 2012 20:00:25 +0000</pubDate>
		<dc:creator>Sean Metcalf</dc:creator>
				<category><![CDATA[MCM]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[Technical Reference]]></category>
		<category><![CDATA[Active Directoy References]]></category>

		<guid isPermaLink="false">http://blogs.metcorpconsulting.com/tech/?p=1432</guid>
		<description><![CDATA[The AskDS Blog has a great list of Active Directory information links. Anyway, what with the hiring we’re doing now, a month ago I promised you some further reading around how you can amp up your Active Directory skills. Rather than burying it in another mail sack, I figured I’d lay it all out here [...]]]></description>
				<content:encoded><![CDATA[<p>The AskDS Blog has a great list of Active Directory information links.</p>
<blockquote><p>Anyway, what with the hiring we’re doing now, <a href="http://blogs.technet.com/b/askds/archive/2010/06/25/friday-mail-sack-1970-s-conversion-van-edition.aspx">a month ago</a> I promised you some further reading around how you can amp up your Active Directory skills. Rather than burying it in another mail sack, I figured I’d lay it all out here in one spot. If you feel like you need to fill in the cracks on your directory service knowledge, here’s what we force feed our new hires</p>
<p><strong>Core Technology Reading</strong></p>
<p>If you read nothing else, read these core pieces. While they are Win2003/XP specific, that’s still at least 75% of the business install base and highly relevant. For the most part things don’t change <em>that</em> much architecturally between versions either (ignoring GP and User Profiles). They give you the fundamentals to build on later.</p>
<blockquote><p><a href="http://technet.microsoft.com/en-us/library/cc780036%28WS.10%29.aspx">Active Directory Collection</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc782376%28WS.10%29.aspx">Active Directory Replication Model</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc755326%28WS.10%29.aspx">Active Directory Replication Topology</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc780455%28WS.10%29.aspx">Authentication</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc782880%28WS.10%29.aspx">Authorization</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc779926%28WS.10%29.aspx">DNS Technical Reference</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc758751%28WS.10%29.aspx">Group Policy</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc781463%28WS.10%29.aspx">Interactive Logon</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc739058%28WS.10%29.aspx">Kerberos Authentication Technical Reference</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc779826%28WS.10%29.aspx">Public Key Infrastructure (PKI)</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc778264%28WS.10%29.aspx">TCP/IP Technical Reference</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc781516%28WS.10%29.aspx">User Profiles</a></p></blockquote>
<p><strong>Post Graduate Technology Reading</strong></p>
<p>Then we get to the more advanced subjects, the specific features added in later models, and the things that will take you into rarefied air. Much of this is Windows Server 2008 and later too, so if you haven’t started rolling out our later OS this will get you ready. If you can get through these, you’re ready to run AD in the environments with 100,000+ computers. And as I always tell people, if you know <em>how</em> something works, you can troubleshoot <em>any</em> kind of problem<em> </em>– even if the issue has never seen seen before.</p>
<blockquote><p><a href="http://technet.microsoft.com/en-us/library/dd728034%28WS.10%29.aspx">Active Directory Domain Services in the Perimeter Network</a><br />
<a href="http://technet.microsoft.com/en-us/library/dd772723%28WS.10%29.aspx">Active Directory and Active Directory Domain Services Port Requirements</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc759402%28WS.10%29.aspx">Active Directory Schema</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc974332%28WS.10%29.aspx">ADMT Guide: Migrating and Restructuring Active Directory Domains</a><br />
<a href="http://technet.microsoft.com/en-us/library/dd723678%28WS.10%29.aspx">AppLocker</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc754678%28WS.10%29.aspx">AD DS Design Guide</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc736984%28WS.10%29.aspx">CA Certificates</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc785237%28WS.10%29.aspx">Certificates</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc776207%28WS.10%29.aspx">Certificate Services</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc758751%28WS.10%29.aspx">Core Group Policy Technical Reference</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc786524%28WS.10%29.aspx">Designing a Group Policy Infrastructure</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc772778%28WS.10%29.aspx">DFSR</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc773238%28WS.10%29.aspx">DFS Replication: Frequently Asked Questions (FAQ)</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc757042%28WS.10%29.aspx">Distributed File System (DFS)</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc781627%28WS.10%29.aspx">DNS Support for Active Directory</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc738955%28WS.10%29.aspx">Domain and Forest Trusts Technical Reference</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc759297%28WS.10%29.aspx">File Replication Service FRS</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc775731%28WS.10%29.aspx">Global Catalog Technical Reference</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc776182%28WS.10%29.aspx">Group Policy Components</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc778172%28WS.10%29.aspx">Group Policy Management Console</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc780591%28WS.10%29.aspx">Group Policy Object Editor</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc780455%28WS.10%29.aspx">Logon and Authentication Technologies</a><br />
<a href="http://technet.microsoft.com/en-us/library/ff641731%28WS.10%29.aspx">Managed Service Accounts</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc766489%28WS.10%29.aspx">Managing Roaming User Data Deployment Guide</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc780758%28WS.10%29.aspx">Operations Masters Technical Reference</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc771744%28WS.10%29.aspx">Read-Only Domain Controller Planning and Deployment Guide</a><br />
<a href="http://technet.microsoft.com/en-us/library/virtual_active_directory_domain_controller_virtualization_hyperv%28WS.10%29.aspx">Running Domain Controllers in Hyper-V</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc771395%28WS.10%29.aspx">Security Auditing</a><br />
<a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=5534bee1-3cad-4bf0-b92b-a8e545573a3e&amp;displaylang=en">Security Compliance Manager</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc782090%28WS.10%29.aspx">Security Identifiers Technical Reference</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc775598%28WS.10%29.aspx">Security Descriptors and Access Control Lists Technical Reference</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc738722%28WS.10%29.aspx">Security Principals Technical Reference</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc787823%28WS.10%29.aspx">Staging Group Policy Deployments</a><br />
<a href="http://technet.microsoft.com/en-us/library/dd640019%28WS.10%29.aspx">SYSVOL Replication Migration Guide: FRS to DFS Replication</a><br />
<a href="http://technet.microsoft.com/en-us/library/dd835546%28WS.10%29.aspx">User Account Control Technical Reference</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc753516%28WS.10%29.aspx">What&#8217;s New in Active Directory Domain Services in Win2008</a><br />
<a href="http://technet.microsoft.com/en-us/library/dd378796%28WS.10%29.aspx">What&#8217;s New in Active Directory Domain Services in Win2008 R2</a><br />
<a href="http://technet.microsoft.com/en-us/library/ff404297%28WS.10%29.aspx">Windows Smart Card Technical Reference</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc773061%28WS.10%29.aspx">Windows Time Service Technical Reference</a><br />
<a href="http://technet.microsoft.com/en-us/library/cc736411%28WS.10%29.aspx">WINS Technical Reference</a></p></blockquote>
</blockquote>
<p>Get the information <a href="https://blogs.technet.com/b/askds/archive/2010/07/27/post-graduate-ad-studies.aspx?Redirected=true">here</a>.</p>
<p>&nbsp;</p>
<p><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://blogs.metcorpconsulting.com/tech/?p=1432"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://blogs.metcorpconsulting.com/tech/?p=1432" data-text="Post-Graduate AD Studies"></a><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://blogs.metcorpconsulting.com/tech/?p=1432"></a><a class="a2a_button_google_plus" href="http://www.addtoany.com/add_to/google_plus?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1432&amp;linkname=Post-Graduate%20AD%20Studies" title="Google+" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/google_plus.png" width="16" height="16" alt="Google+"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1432&amp;linkname=Post-Graduate%20AD%20Studies" title="Facebook" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1432&amp;linkname=Post-Graduate%20AD%20Studies" title="Email" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:print()" title="Print" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/print.png" width="16" height="16" alt="Print"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1432&amp;title=Post-Graduate%20AD%20Studies" id="wpa2a_56"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.metcorpconsulting.com/tech/?feed=rss2&#038;p=1432</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Introducing the first Windows Server 2012 Domain Controller</title>
		<link>http://blogs.metcorpconsulting.com/tech/?p=1430</link>
		<comments>http://blogs.metcorpconsulting.com/tech/?p=1430#comments</comments>
		<pubDate>Thu, 18 Oct 2012 20:00:34 +0000</pubDate>
		<dc:creator>Sean Metcalf</dc:creator>
				<category><![CDATA[Deployment]]></category>
		<category><![CDATA[Microsoft Products]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[2012 DC]]></category>
		<category><![CDATA[Domain Controller]]></category>
		<category><![CDATA[Windows Server 2012 Domain Controller]]></category>

		<guid isPermaLink="false">http://blogs.metcorpconsulting.com/tech/?p=1430</guid>
		<description><![CDATA[The AskPFE blog has another great Windows Server 2012 article describing how to best rollout new 2012 DCs. Greg Jaworski here again to discuss introducing the first Windows Server 2012 Domain Controller. We will discuss things such as extending the schema, enhancements to the Domain Controller promotion process (it is no longer called dcpromo), and [...]]]></description>
				<content:encoded><![CDATA[<p>The AskPFE blog has another great Windows Server 2012 article describing how to best rollout new 2012 DCs.</p>
<blockquote><p>Greg Jaworski here again to discuss introducing the first Windows Server 2012 Domain Controller. We will discuss things such as extending the schema, enhancements to the Domain Controller promotion process (it is no longer called dcpromo), and things you should be doing to ensure a smooth upgrade and minimal issues. This will be a two part blog post. In the first part we will cover the GUI way of introducing the first Windows Server 2012 Domain Controller. In the second post we will cover the PowerShell way of doing this and also how you can take a look at your environment before introducing that first Windows Server 2012 Domain Controller.</p>
<p>Premier Field Engineering has significant experience in the area of AD upgrades. Many times we are onsite during various parts of the upgrade process. We also have discussions about upgrades during Active Directory Risk Assessments (ADRAP) and have an entire offering called the Active Directory Upgrade Assessment (ADUA) to assist with the upgrade process. We understand the concerns of upgrades. Many managers and IT people do not like the words irreversible, forest recovery, and no back-out plan. People also tend to not like mission critical applications breaking.</p></blockquote>
<p>Read the rest of the article <a href="https://blogs.technet.com/b/askpfeplat/archive/2012/09/03/introducing-the-first-windows-server-2012-domain-controller.aspx?Redirected=true">here</a>.</p>
<p><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://blogs.metcorpconsulting.com/tech/?p=1430"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://blogs.metcorpconsulting.com/tech/?p=1430" data-text="Introducing the first Windows Server 2012 Domain Controller"></a><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://blogs.metcorpconsulting.com/tech/?p=1430"></a><a class="a2a_button_google_plus" href="http://www.addtoany.com/add_to/google_plus?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1430&amp;linkname=Introducing%20the%20first%20Windows%20Server%202012%20Domain%20Controller" title="Google+" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/google_plus.png" width="16" height="16" alt="Google+"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1430&amp;linkname=Introducing%20the%20first%20Windows%20Server%202012%20Domain%20Controller" title="Facebook" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1430&amp;linkname=Introducing%20the%20first%20Windows%20Server%202012%20Domain%20Controller" title="Email" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:print()" title="Print" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/print.png" width="16" height="16" alt="Print"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1430&amp;title=Introducing%20the%20first%20Windows%20Server%202012%20Domain%20Controller" id="wpa2a_58"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.metcorpconsulting.com/tech/?feed=rss2&#038;p=1430</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Server 2012 Domain Controller Recommendations</title>
		<link>http://blogs.metcorpconsulting.com/tech/?p=1428</link>
		<comments>http://blogs.metcorpconsulting.com/tech/?p=1428#comments</comments>
		<pubDate>Wed, 10 Oct 2012 20:00:04 +0000</pubDate>
		<dc:creator>Sean Metcalf</dc:creator>
				<category><![CDATA[Microsoft Products]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[DC Placement]]></category>
		<category><![CDATA[Domain Controller]]></category>
		<category><![CDATA[Windows Server 2012]]></category>

		<guid isPermaLink="false">http://blogs.metcorpconsulting.com/tech/?p=1428</guid>
		<description><![CDATA[The AskPFE Blog has some useful suggestions for Windows Server 2012 Domain Controller placement. Following up on Greg Jaworski’s great post from last week where he talked about how to promote a domain controller in Windows Server 2012, today we will cover some thoughts around where to place your first Windows Server 2012 DCs and [...]]]></description>
				<content:encoded><![CDATA[<p>The AskPFE Blog has some useful suggestions for Windows Server 2012 Domain Controller placement.</p>
<blockquote><p>Following up on <a href="http://blogs.technet.com/b/askpfeplat/archive/2012/09/03/introducing-the-first-windows-server-2012-domain-controller.aspx">Greg Jaworski’s great post</a> from last week where he talked about how to promote a domain controller in Windows Server 2012, today we will cover some thoughts around where to place your first Windows Server 2012 DCs and how many to plan on rolling out at once.  This blog post is meant to be used as high level guidance as every environment is different, so your mileage most likely will vary.  If you are interested in a more detailed recommendation specific to your environment, I encourage you to speak with your Microsoft account team contact(s) to get you hooked up with the right resources at Microsoft to assist.</p>
<ol>
<li>Where you place your first 2012 DCs and how many you need greatly depends on two things:</li>
<li>What new 2012 features you plan on using right out of the gate.If you have multiple domains and/or multiple forests with trusts in place.</li>
</ol>
<p>Let’s break these down a bit more with some specific examples.  For those of you who have not looked into the new Windows Server 2012 features Dynamic Access Control (DAC), Kerberos FAST (AKA armoring), and DC cloning, some of this content may be a bit confusing.  We plan on covering these topics in greater detail in future blog posts.  In the interim, I encourage you to review the following links on TechNet for a quick review before and/or after reading the next section.</p></blockquote>
<p>Read the rest of the article <a href="https://blogs.technet.com/b/askpfeplat/archive/2012/09/10/how-many-windows-server-2012-domain-controllers-do-i-need-initially-and-where-should-i-put-them.aspx?Redirected=true">here</a>.</p>
<p><a class="a2a_button_google_plusone addtoany_special_service" data-annotation="none" data-href="http://blogs.metcorpconsulting.com/tech/?p=1428"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://blogs.metcorpconsulting.com/tech/?p=1428" data-text="Windows Server 2012 Domain Controller Recommendations"></a><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://blogs.metcorpconsulting.com/tech/?p=1428"></a><a class="a2a_button_google_plus" href="http://www.addtoany.com/add_to/google_plus?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1428&amp;linkname=Windows%20Server%202012%20Domain%20Controller%20Recommendations" title="Google+" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/google_plus.png" width="16" height="16" alt="Google+"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1428&amp;linkname=Windows%20Server%202012%20Domain%20Controller%20Recommendations" title="Facebook" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_email" href="http://www.addtoany.com/add_to/email?linkurl=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1428&amp;linkname=Windows%20Server%202012%20Domain%20Controller%20Recommendations" title="Email" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/email.png" width="16" height="16" alt="Email"/></a><a href="javascript:print()" title="Print" rel="nofollow" target="_blank"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/icons/print.png" width="16" height="16" alt="Print"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.metcorpconsulting.com%2Ftech%2F%3Fp%3D1428&amp;title=Windows%20Server%202012%20Domain%20Controller%20Recommendations" id="wpa2a_60"><img src="http://blogs.metcorpconsulting.com/tech/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.metcorpconsulting.com/tech/?feed=rss2&#038;p=1428</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
