<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:evnet="http://www.mscommunities.com/rssmodule/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"><channel><title>Entries tagged with ad - TechNet Edge</title><atom:link rel="self" type="application/rss+xml" href="http://edge.technet.com/tags/ad/feed/ipod/default.aspx" /><itunes:summary>ad</itunes:summary><itunes:author>extreme, Joey, neil, AdamBomb</itunes:author><image><url>http://mschnlnine.vo.llnwd.net/d1/Dev/App_Themes/Edge/images/feedimage.png</url><title>Entries tagged with ad - TechNet Edge</title><link>http://edge.technet.com/Tags/AD/</link></image><itunes:image href="http://mschnlnine.vo.llnwd.net/d1/Dev/App_Themes/Edge/images/feedimage.png" /><itunes:category text="Technology" /><description>ad</description><link>http://edge.technet.com/Tags/AD/</link><language>en-us</language><pubDate>Mon, 14 Jul 2008 21:18:25 GMT</pubDate><lastBuildDate>Mon, 14 Jul 2008 21:18:25 GMT</lastBuildDate><generator>EvNet (EvNet, Version=1.0.3186.2534, Culture=neutral, PublicKeyToken=null)</generator><item><title>Server 2008 and Active Directory snapshot software at QBranch</title><description>&lt;img src="http://mschnlnine.vo.llnwd.net/d1/edge/8/8/4/1/QbranchSweden_small_edge.jpg" border="0" /&gt;&lt;p&gt;Joachim Nasslander, Solution specialist at &lt;a href="http://www.qbranch.se/" target="_blank"&gt;QBranch&lt;/a&gt; in Sweden, starts off by telling us about their own company's ~50 server and ~5,000 customer server environment which has been running Windows Server 2008 since 2006.&lt;/p&gt;
&lt;p&gt;At 02:27 Fredrik Lindstrom, Developer at QBranch, tells us about active directory snapshot software he wrote to compare the snapshot versions and restore deleted objects and their values in AD.  He tells us about some of the limitations and plans for the program moving forward.&lt;/p&gt;
&lt;p&gt;At 4:06 Fredrik gives us a demo of the software.&lt;/p&gt;
&lt;p&gt;You can download Fredrik's program here:&lt;br /&gt;
&lt;a href="http://lindstrom.nullsession.com/?page_id=11"&gt;http://lindstrom.nullsession.com/?page_id=11&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.microsoft.com/windowsserver2008/" target="_blank"&gt;Learn more about Server 2008&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://blogs.technet.com/extreme/archive/2007/10/18/analysis-of-windows-server-2008-ad-snapshot-viewer.aspx" target="_blank"&gt;Learn more about AD snapshots&lt;/a&gt;&lt;/p&gt;&lt;img src="http://edge.technet.com/1488/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://edge.technet.com/Media/Server-2008-and-Active-Directory-snapshot-software-at-QBranch/</comments><itunes:summary>Joachim Nasslander, Solution specialist at QBranch in Sweden, starts off by telling us about their own company's ~50 server and ~5,000 customer server environment which has been running Windows Server 2008 since 2006.
At 02:27 Fredrik Lindstrom, Developer at QBranch, tells us about active directory snapshot software he wrote to compare the snapshot versions and restore deleted objects and their values in AD.  He tells us about some of the limitations and plans for the program moving forward.
At 4:06 Fredrik gives us a demo of the software.
You can download Fredrik's program here:
http://lindstrom.nullsession.com/?page_id=11
Learn more about Server 2008
Learn more about AD snapshots</itunes:summary><link>http://edge.technet.com/Media/Server-2008-and-Active-Directory-snapshot-software-at-QBranch/</link><pubDate>Mon, 04 Aug 2008 07:01:00 GMT</pubDate><guid isPermaLink="false">http://mschnlnine.vo.llnwd.net/d1/edge/8/8/4/1/QbranchSweden_edge.mp4</guid><evnet:views>14700</evnet:views><evnet:viewtrackingurl>http://edge.technet.com/1488/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Joachim Nasslander, Solution specialist at QBranch in Sweden, starts off by telling us about their own company's ~50 server and ~5,000 customer server environment which has been running Windows Server 2008 since 2006.
At 02:27 Fredrik Lindstrom, Developer at QBranch, tells us about active directory&amp;#8230;</evnet:previewtext><media:thumbnail url="http://edge.technet.com/Link/cefe159b-8dab-49c0-9550-bacfdc0650b6/" height="240" width="320" /><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/edge/8/8/4/1/QbranchSweden_small_edge.jpg" height="64" width="85" /><media:group><media:content url="http://mschnlnine.vo.llnwd.net/d1/edge/8/8/4/1/QbranchSweden_edge.mp4" expression="full" duration="377" fileSize="20463931" type="video/mp4" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/edge/8/8/4/1/QbranchSweden_edge.mp3" expression="full" duration="377" fileSize="3014321" type="audio/mp3" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/edge/8/8/4/1/QbranchSweden_edge.mp4" expression="full" duration="377" fileSize="20463931" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/edge/8/8/4/1/QbranchSweden_edge.wma" expression="full" duration="377" fileSize="3054121" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/edge/8/8/4/1/QbranchSweden_edge.wmv" expression="full" duration="377" fileSize="19349627" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/edge/8/8/4/1/QbranchSweden_2MB_edge.wmv" expression="full" duration="377" fileSize="116000201" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/edge/8/8/4/1/QbranchSweden_Zune_edge.wmv" expression="full" duration="377" fileSize="29847767" type="video/x-ms-wmv" medium="video" /><media:content url="mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/8/8/4/1/QbranchSweden_s_edge.wmv" expression="full" duration="377" fileSize="202" type="video/x-ms-asf" medium="video" /></media:group><enclosure url="http://mschnlnine.vo.llnwd.net/d1/edge/8/8/4/1/QbranchSweden_edge.mp4" length="20463931" type="video/mp4" /><dc:creator>extreme</dc:creator><itunes:author>extreme</itunes:author><slash:comments>0</slash:comments><wfw:commentRss>http://edge.technet.com/Media/Server-2008-and-Active-Directory-snapshot-software-at-QBranch/RSS/</wfw:commentRss><trackback:ping>http://edge.technet.com/1488/Trackback.aspx</trackback:ping><category>AD</category><category>Customer Story</category><category>Windows Server 2008</category></item><item><title>Server 2008 - AD Backup and Restore PM interview</title><description>&lt;img src="http://mschnlnine.vo.llnwd.net/d1/edge/1/9/7/WS08BackupRestorePM_small_edge.jpg" border="0" /&gt;&lt;p&gt;I met up with Stephanie Cheung, the program manager for active directory backup and recovery and we discuss:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;What &lt;a href="http://technet2.microsoft.com/windowsserver2008/en/library/caa05f49-210f-4f4c-b33f-c8ad50a687101033.mspx?mfr=true"&gt;restartable AD&lt;/a&gt; is and when it is appropriate to use it
    &lt;ul&gt;
        &lt;li&gt;Good for usage when you want to recover deleted objects without rebooting &lt;/li&gt;
        &lt;li&gt;Bad for when you need to do a "bare metal" restore or have database corruption&lt;/li&gt;
    &lt;/ul&gt;
    &lt;/li&gt;
    &lt;li&gt;Thoughts around when to do a "Dcpromo /forceremoval" versus restoring from backup.  This includes discussion of restoring using &lt;a href="http://technet2.microsoft.com/WindowsServer2008/en/library/146d1360-09ac-4cdd-8d44-c9756d3550c91033.mspx"&gt;install from media&lt;/a&gt; (IFM) and IFM for an RODC. &lt;/li&gt;
    &lt;li&gt;What the &lt;a href="http://blogs.technet.com/extreme/archive/2007/10/18/analysis-of-windows-server-2008-ad-snapshot-viewer.aspx"&gt;database mounting tool&lt;/a&gt; (DMT - old name "snapshot" tool) does and some ideas on what we're going to do to make recovery of deleted objects easier using DMT. &lt;/li&gt;
    &lt;li&gt;A best practice around preventing deletion of objects in AD (including the new "&lt;a href="http://support.microsoft.com/kb/840001"&gt;Protect object from accidental deletion&lt;/a&gt;" checkbox for objects). &lt;/li&gt;
    &lt;li&gt;Future thoughts for AD backup and restore, such as reducing &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=AFE436FA-8E8A-443A-9027-C522DEE35D85&amp;displaylang=en"&gt;forest recovery&lt;/a&gt; time &lt;/li&gt;
    &lt;li&gt;General disaster recovery tips &lt;/li&gt;
&lt;/ul&gt;&lt;img src="http://edge.technet.com/791/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://edge.technet.com/Media/Server-2008-AD-Backup-and-Restore-PM-interview/</comments><itunes:summary>I met up with Stephanie Cheung, the program manager for active directory backup and recovery and we discuss:

    What restartable AD is and when it is appropriate to use it
    
        Good for usage when you want to recover deleted objects without rebooting 
        Bad for when you need to do a "bare metal" restore or have database corruption
    
    
    Thoughts around when to do a "Dcpromo /forceremoval" versus restoring from backup.  This includes discussion of restoring using install from media (IFM) and IFM for an RODC. 
    What the database mounting tool (DMT - old name "snapshot" tool) does and some ideas on what we're going to do to make recovery of deleted objects easier using DMT. 
    A best practice around preventing deletion of objects in AD (including the new "Protect object from accidental deletion" checkbox for objects). 
    Future thoughts for AD backup and restore, such as reducing forest recovery time 
    General disaster recovery tips 
</itunes:summary><link>http://edge.technet.com/Media/Server-2008-AD-Backup-and-Restore-PM-interview/</link><pubDate>Fri, 11 Apr 2008 06:59:00 GMT</pubDate><guid isPermaLink="false">http://mschnlnine.vo.llnwd.net/d1/edge/1/9/7/WS08BackupRestorePM_edge.mp4</guid><evnet:views>9208</evnet:views><evnet:viewtrackingurl>http://edge.technet.com/791/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>&lt;p&gt;I met up with Stephanie Cheung, the program manager for active directory backup and recovery and we discuss:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;What &lt;a href="http://technet2.microsoft.com/windowsserver2008/en/library/caa05f49-210f-4f4c-b33f-c8ad50a687101033.mspx?mfr=true"&gt;restartable AD &lt;/a&gt;is and when it is appropriate to use it
    &lt;ul&gt;
        &lt;li&gt;Good for usage when you want to recover deleted objects without rebooting &lt;/li&gt;
        &lt;li&gt;Bad for when you need to do a "bare metal" restore or have database corruption&lt;/li&gt;
    &lt;/ul&gt;
    &lt;/li&gt;
&lt;/ul&gt;</evnet:previewtext><media:thumbnail url="http://edge.technet.com/Link/dd56bed7-12d5-494b-975d-35039c160852/" height="240" width="320" /><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/edge/1/9/7/WS08BackupRestorePM_small_edge.jpg" height="64" width="85" /><media:group><media:content url="http://mschnlnine.vo.llnwd.net/d1/edge/1/9/7/WS08BackupRestorePM_edge.mp4" expression="full" duration="1042" fileSize="59222227" type="video/mp4" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/edge/1/9/7/WS08BackupRestorePM_edge.mp3" expression="full" duration="1042" fileSize="8343220" type="audio/mp3" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/edge/1/9/7/WS08BackupRestorePM_edge.mp4" expression="full" duration="1042" fileSize="59222227" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/edge/1/9/7/WS08BackupRestorePM_edge.wma" expression="full" duration="1042" fileSize="8443501" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/edge/1/9/7/WS08BackupRestorePM_edge.wmv" expression="full" duration="1042" fileSize="66318899" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/edge/1/9/7/WS08BackupRestorePM_2MB_edge.wmv" expression="full" duration="1042" fileSize="326444215" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/edge/1/9/7/WS08BackupRestorePM_Zune_edge.wmv" expression="full" duration="1042" fileSize="82683967" type="video/x-ms-wmv" medium="video" /><media:content url="mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/1/9/7/WS08BackupRestorePM_s_edge.wmv" expression="full" duration="1042" fileSize="210" type="video/x-ms-asf" medium="video" /></media:group><enclosure url="http://mschnlnine.vo.llnwd.net/d1/edge/1/9/7/WS08BackupRestorePM_edge.mp4" length="59222227" type="video/mp4" /><dc:creator>extreme</dc:creator><itunes:author>extreme</itunes:author><slash:comments>0</slash:comments><wfw:commentRss>http://edge.technet.com/Media/Server-2008-AD-Backup-and-Restore-PM-interview/RSS/</wfw:commentRss><trackback:ping>http://edge.technet.com/791/Trackback.aspx</trackback:ping><category>Active Directory</category><category>AD</category><category>Windows Server 2008</category></item><item><title>Windows Server 2008 - AD RODC PM interview</title><description>&lt;img src="http://mschnlnine.vo.llnwd.net/d1/edge/8/8/6/ADRoDCPM_small_edge.jpg" border="0" /&gt;I met up with Gregoire Guetat, a program manager (PM) who has worked on Dcpromo, ADPrep, Replication Engine, and RODC.  In this video, he tells us why the team decided to create the RODC, recommendations for best practices with RODC (RODC + Server Core and Bitlocker), his take on virtualization of DCs, why "USN Bubbles" are bad and why you can't have one on a RODC, tip on where the RODCs should point for DNS, explanation of details for two-staged DC promotions &amp;amp; Install from Media (IFM).  Also, the DS team is planning on coming out with a white paper for guidance on having RODCs in the DMZ.  He also tells us a couple other things which are coming up on the DS team and explains what interoperability there is currently with RODC and Exchange. &lt;br /&gt;
&lt;br /&gt;
If you decide to tune into "Over the Edge" at ~20:45, you'll hear about where he's from in France, what are the best places to visit there, and also hear about his &lt;a href="http://whirlyball.net/html/"&gt;Whirlyball&lt;/a&gt; experience.&lt;img src="http://edge.technet.com/688/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://edge.technet.com/Media/AD-PM-interview-Take-2/</comments><itunes:summary>I met up with Gregoire Guetat, a program manager (PM) who has worked on Dcpromo, ADPrep, Replication Engine, and RODC.  In this video, he tells us why the team decided to create the RODC, recommendations for best practices with RODC (RODC + Server Core and Bitlocker), his take on virtualization of DCs, why "USN Bubbles" are bad and why you can't have one on a RODC, tip on where the RODCs should point for DNS, explanation of details for two-staged DC promotions &amp;amp; Install from Media (IFM).  Also, the DS team is planning on coming out with a white paper for guidance on having RODCs in the DMZ.  He also tells us a couple other things which are coming up on the DS team and explains what interoperability there is currently with RODC and Exchange. 

If you decide to tune into "Over the Edge" at ~20:45, you'll hear about where he's from in France, what are the best places to visit there, and also hear about his Whirlyball experience.</itunes:summary><link>http://edge.technet.com/Media/AD-PM-interview-Take-2/</link><pubDate>Wed, 19 Mar 2008 06:59:00 GMT</pubDate><guid isPermaLink="false">http://mschnlnine.vo.llnwd.net/d1/edge/8/8/6/ADRoDCPM_edge.mp4</guid><evnet:views>6584</evnet:views><evnet:viewtrackingurl>http://edge.technet.com/688/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>I met up with Gregoire Guetat, a program manager (PM) who has worked on Dcpromo, ADPrep, Replication Engine, and RODC.  In this video, he tells us why the team decided to create the RODC, recommendations for best practices with RODC (RODC + Server Core and Bitlocker), his take on virtualization of DCs, why "USN Bubbles" are bad and why you can't have one on a RODC, tip on where the RODCs should point for DNS, explanation of details for two-staged DC promotions &amp;amp; Install from Media (IFM).&lt;br /&gt;
&lt;br /&gt;
If you decide to tune into "Over the Edge" at ~20:45, you'll hear about where he's from in France, what are the best places to visit there, and also hear about his &lt;a href="http://whirlyball.net/html/"&gt;Whirlyball &lt;/a&gt;experience.</evnet:previewtext><media:thumbnail url="http://edge.technet.com/Link/aa070723-fc29-4b29-8958-492b1263a0da/" height="240" width="320" /><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/edge/8/8/6/ADRoDCPM_small_edge.jpg" height="64" width="85" /><media:group><media:content url="http://mschnlnine.vo.llnwd.net/d1/edge/8/8/6/ADRoDCPM_edge.mp4" expression="full" duration="1559" fileSize="83420064" type="video/mp4" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/edge/8/8/6/ADRoDCPM_edge.mp3" expression="full" duration="1559" fileSize="12474537" type="audio/mp3" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/edge/8/8/6/ADRoDCPM_edge.mp4" expression="full" duration="1559" fileSize="83420064" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/edge/8/8/6/ADRoDCPM_edge.wma" expression="full" duration="1559" fileSize="12615903" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/edge/8/8/6/ADRoDCPM_edge.wmv" expression="full" duration="1559" fileSize="68849623" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/edge/8/8/6/ADRoDCPM_2MB_edge.wmv" expression="full" duration="1559" fileSize="193844774" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/edge/8/8/6/ADRoDCPM_Zune_edge.wmv" expression="full" duration="1559" fileSize="123998915" type="video/x-ms-wmv" medium="video" /><media:content url="mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/8/8/6/ADRoDCPM_s_edge.wmv" expression="full" duration="1559" fileSize="189" type="video/x-ms-asf" medium="video" /></media:group><enclosure url="http://mschnlnine.vo.llnwd.net/d1/edge/8/8/6/ADRoDCPM_edge.mp4" length="83420064" type="video/mp4" /><dc:creator>extreme</dc:creator><itunes:author>extreme</itunes:author><slash:comments>4</slash:comments><wfw:commentRss>http://edge.technet.com/Media/AD-PM-interview-Take-2/RSS/</wfw:commentRss><trackback:ping>http://edge.technet.com/688/Trackback.aspx</trackback:ping><category>AD</category><category>Over the Edge</category><category>RODC</category><category>Windows Server 2008</category></item><item><title>Windows Server 2008 Active Directory Auditing and FGPP PM Interview</title><description>&lt;img src="http://mschnlnine.vo.llnwd.net/d1/edge/2/9/5/WS08ADAuditFppPM_small_edge.jpg" border="0" /&gt;Hear about Windows Server 2008 AD auditing and FGPP directly from the source!  In this interview with Siddharth Bhai the program manager (PM) for this AD functionality, he gives us a bunch of great information.  &lt;br /&gt;
&lt;br /&gt;
For instance he: &lt;br /&gt;
- Explains the recommended practices on how to create password settings objects (PSOs) and delegate the permissions for these.  &lt;br /&gt;
&lt;br /&gt;
- Gives numerous reasons as to why the team made the decision for PSOs being assigned via groups and not OUs&lt;br /&gt;
&lt;br /&gt;
- Tells us why the team didn't produce a more rich GUI tool to create PSOs (instead of the manual creation using ADSIedit)&lt;br /&gt;
&lt;br /&gt;
- Describes why they made the decisions to include the new auditing features in WS08&lt;br /&gt;
&lt;br /&gt;
- Simplifies the areas how to apply auditing (Global auditing, Schema, specific ACE per object)&lt;br /&gt;
&lt;br /&gt;
- Shares thoughts on what might be coming up next with auditing and FGPP&lt;br /&gt;
&lt;br /&gt;
Some resources referenced in this interview:&lt;br /&gt;
&lt;a href="http://technet2.microsoft.com/windowsserver2008/en/library/a9c25483-89e2-4202-881c-ea8e02b4b2a51033.mspx"&gt;Windows Server 2008 Auditing AD DS Changes Step-by-Step Guide&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://technet2.microsoft.com/windowsserver2008/en/library/2199dcf7-68fd-4315-87cc-ade35f8978ea1033.mspx"&gt;Step-by-Step Guide for Fine-Grained Password and Account Lockout Policy Configuration&lt;/a&gt;&lt;br /&gt;&lt;img src="http://edge.technet.com/592/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://edge.technet.com/Media/592/</comments><itunes:summary>Hear about Windows Server 2008 AD auditing and FGPP directly from the source!  In this interview with Siddharth Bhai the program manager (PM) for this AD functionality, he gives us a bunch of great information.  

For instance he: 
- Explains the recommended practices on how to create password settings objects (PSOs) and delegate the permissions for these.  

- Gives numerous reasons as to why the team made the decision for PSOs being assigned via groups and not OUs

- Tells us why the team didn't produce a more rich GUI tool to create PSOs (instead of the manual creation using ADSIedit)

- Describes why they made the decisions to include the new auditing features in WS08

- Simplifies the areas how to apply auditing (Global auditing, Schema, specific ACE per object)

- Shares thoughts on what might be coming up next with auditing and FGPP

Some resources referenced in this interview:
Windows Server 2008 Auditing AD DS Changes Step-by-Step Guide
Step-by-Step Guide for Fine-Grained Password and Account Lockout Policy Configuration</itunes:summary><link>http://edge.technet.com/Media/592/</link><pubDate>Fri, 29 Feb 2008 07:59:00 GMT</pubDate><guid isPermaLink="false">http://mschnlnine.vo.llnwd.net/d1/edge/2/9/5/WS08ADAuditFppPM_edge.mp4</guid><evnet:views>6029</evnet:views><evnet:viewtrackingurl>http://edge.technet.com/592/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Hear about Windows Server 2008 AD auditing and FGPP directly from the source!  In this interview with Siddharth Bhai the program manager (PM) for this AD functionality, he gives us a bunch of great information.  &lt;br /&gt;
&lt;br /&gt;
For instance he: &lt;br /&gt;
- Explains the recommended practices on how to create password settings objects (PSOs) and delegate the permissions for these.  &lt;br /&gt;
&lt;br /&gt;
- Gives numerous reasons as to why the team made the decision for PSOs being assigned via groups and not OUs- Tells us why the team didn't produce a more rich GUI tool to create PSOs (instead of the manual creation using ADSIedit)</evnet:previewtext><media:thumbnail url="http://edge.technet.com/Link/369affeb-41d5-48e3-9afd-c283a40c2c50/" height="240" width="320" /><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/edge/2/9/5/WS08ADAuditFppPM_small_edge.jpg" height="64" width="85" /><media:group><media:content url="http://mschnlnine.vo.llnwd.net/d1/edge/2/9/5/WS08ADAuditFppPM_edge.mp4" expression="full" duration="1253" fileSize="75610908" type="video/mp4" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/edge/2/9/5/WS08ADAuditFppPM_edge.mp3" expression="full" duration="1253" fileSize="10031566" type="audio/mp3" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/edge/2/9/5/WS08ADAuditFppPM_edge.mp4" expression="full" duration="1253" fileSize="75610908" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/edge/2/9/5/WS08ADAuditFppPM_edge.wma" expression="full" duration="1253" fileSize="10146777" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/edge/2/9/5/WS08ADAuditFppPM_edge.wmv" expression="full" duration="1253" fileSize="79474669" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/edge/2/9/5/WS08ADAuditFppPM_2MB_edge.wmv" expression="full" duration="1253" fileSize="392437483" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/edge/2/9/5/WS08ADAuditFppPM_Zune_edge.wmv" expression="full" duration="1253" fileSize="99373241" type="video/x-ms-wmv" medium="video" /><media:content url="mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/2/9/5/WS08ADAuditFppPM_s_edge.wmv" expression="full" duration="1253" fileSize="205" type="video/x-ms-asf" medium="video" /></media:group><enclosure url="http://mschnlnine.vo.llnwd.net/d1/edge/2/9/5/WS08ADAuditFppPM_edge.mp4" length="75610908" type="video/mp4" /><dc:creator>extreme</dc:creator><itunes:author>extreme</itunes:author><slash:comments>1</slash:comments><wfw:commentRss>http://edge.technet.com/Media/592/RSS/</wfw:commentRss><trackback:ping>http://edge.technet.com/592/Trackback.aspx</trackback:ping><category>AD</category><category>PM</category><category>Windows Server 2008</category></item><item><title>Server 2008 Active Directory IPD guide</title><description>&lt;img src="http://mschnlnine.vo.llnwd.net/d1/edge/4/6/5/IPD-AD-Guide_small_edge.jpg" border="0" /&gt;&lt;p&gt;In this interview, I met up with Charles Denny on the solutions accelerator team who is in charge of the infrastructure and planning guide for AD (this is the next generation of the (&lt;a href="http://www.microsoft.com/technet/solutionaccelerators/wssra/default.mspx"&gt;WSSRA&lt;/a&gt;) guides.  We talk about the purpose of this guide and dig into information in the guide which might be useful to you such as his viewpoint on one of the most difficult business decisions which need to be made in an AD environment.  &lt;/p&gt;
&lt;p&gt;There is tons of documentation out there on how to technically do things with AD, but until now with the IPD, there is not very much with how to successfully design your infrastructure and the decisions which need to be made along the way.  For instance, divestitures in deciding what forest design to choose is one important factor to consider.  This guide will help you in migrating to Windows Server 2008 from a needed angle.  &lt;/p&gt;
&lt;p&gt;To take a look at the beta to the TS and AD guides, go to the Connect site by clicking &lt;a href="https://connect.microsoft.com/InvitationUse.aspx?ProgramID=1587&amp;InvitationID=IPDM-QX6H-7TTV&amp;SiteID=14"&gt;here&lt;/a&gt; if new or &lt;a href="https://connect.microsoft.com/content/content.aspx?ContentID=6556&amp;SiteID=14"&gt;here&lt;/a&gt; if already enrolled.&lt;/p&gt;
&lt;p&gt;Also, the guides for the below can be found &lt;a href="http://www.microsoft.com/downloads/details.aspx?familyid=AD3921FB-8224-4681-9064-075FDF042B0C&amp;displaylang=en" target="_blank"&gt;here&lt;/a&gt;:&lt;/p&gt;
&lt;li&gt;Infrastructure Planning and Design Series Introduction &lt;/li&gt;
&lt;li&gt;Selecting the Right Virtualization Technology &lt;/li&gt;
&lt;li&gt;SoftGrid Application Virtualization &lt;/li&gt;
&lt;li&gt;Windows Server Virtualization (for Windows Server 2008 virtualization and Virtual Server 2005 R2 SP1) &lt;/li&gt;&lt;img src="http://edge.technet.com/564/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://edge.technet.com/Media/564/</comments><itunes:summary>In this interview, I met up with Charles Denny on the solutions accelerator team who is in charge of the infrastructure and planning guide for AD (this is the next generation of the (WSSRA) guides.  We talk about the purpose of this guide and dig into information in the guide which might be useful to you such as his viewpoint on one of the most difficult business decisions which need to be made in an AD environment.  
There is tons of documentation out there on how to technically do things with AD, but until now with the IPD, there is not very much with how to successfully design your infrastructure and the decisions which need to be made along the way.  For instance, divestitures in deciding what forest design to choose is one important factor to consider.  This guide will help you in migrating to Windows Server 2008 from a needed angle.  
To take a look at the beta to the TS and AD guides, go to the Connect site by clicking here if new or here if already enrolled.
Also, the guides for the below can be found here:
Infrastructure Planning and Design Series Introduction 
Selecting the Right Virtualization Technology 
SoftGrid Application Virtualization 
Windows Server Virtualization (for Windows Server 2008 virtualization and Virtual Server 2005 R2 SP1) </itunes:summary><link>http://edge.technet.com/Media/564/</link><pubDate>Fri, 22 Feb 2008 07:59:00 GMT</pubDate><guid isPermaLink="false">http://mschnlnine.vo.llnwd.net/d1/edge/4/6/5/IPD-AD-Guide_edge.mp4</guid><evnet:views>5969</evnet:views><evnet:viewtrackingurl>http://edge.technet.com/564/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>In this interview, I met up with Charles Denny on the solutions accelerator team who is in charge of the infrastructure and planning guide for AD (this is the next generation of the (WSSRA) guides.  We talk about the purpose of this guide and dig into information in the guide which might be useful to you such as his viewpoint on one of the most difficult business decisions which need to be made in an AD environment.</evnet:previewtext><media:thumbnail url="http://edge.technet.com/Link/1a46efe9-860f-421b-80aa-18a6fcfa1d76/" height="240" width="320" /><media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/edge/4/6/5/IPD-AD-Guide_small_edge.jpg" height="64" width="85" /><media:group><media:content url="http://mschnlnine.vo.llnwd.net/d1/edge/4/6/5/IPD-AD-Guide_edge.mp4" expression="full" duration="599" fileSize="36627926" type="video/mp4" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/edge/4/6/5/IPD-AD-Guide_edge.mp3" expression="full" duration="599" fileSize="4798926" type="audio/mp3" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/edge/4/6/5/IPD-AD-Guide_edge.mp4" expression="full" duration="599" fileSize="36627926" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/edge/4/6/5/IPD-AD-Guide_edge.wma" expression="full" duration="599" fileSize="4862685" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/edge/4/6/5/IPD-AD-Guide_edge.wmv" expression="full" duration="599" fileSize="38240273" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/edge/4/6/5/IPD-AD-Guide_2MB_edge.wmv" expression="full" duration="599" fileSize="187777539" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/edge/4/6/5/IPD-AD-Guide_Zune_edge.wmv" expression="full" duration="599" fileSize="47561261" type="video/x-ms-wmv" medium="video" /><media:content url="mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/4/6/5/IPD-AD-Guide_s_edge.wmv" expression="full" duration="599" fileSize="197" type="video/x-ms-asf" medium="video" /></media:group><enclosure url="http://mschnlnine.vo.llnwd.net/d1/edge/4/6/5/IPD-AD-Guide_edge.mp4" length="36627926" type="video/mp4" /><dc:creator>extreme</dc:creator><itunes:author>extreme</itunes:author><slash:comments>1</slash:comments><wfw:commentRss>http://edge.technet.com/Media/564/RSS/</wfw:commentRss><trackback:ping>http://edge.technet.com/564/Trackback.aspx</trackback:ping><category>AD</category><category>IPD</category><category>Windows Server 2008</category></item><item><title>Linux / Samba / Unix and Microsoft Integration chat with Ralf Wigand</title><description>&lt;img src="http://edge.technet.com/Link/3deeae37-f8e7-46e8-8f69-8f010b849e87/" border="0" /&gt;While I was at IT Forum, I attended Ralf Wigand's &lt;a href="http://www.mseventseurope.com/OnlinePub/Public/sessions.aspx?EventId=mJ1zMVxtUYw%3d"&gt;IDA406 session &lt;/a&gt;entitled: "Broaden your Active Directory Horizon – Linux Authentication" and thought it would be great to interview him.  Ralf is on the IT staff from the University of Karlsruhe and has worked with Linux since the days of &lt;a href="http://en.wikipedia.org/wiki/Minux"&gt;Minix&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
In this interview we talked about where he currently commonly sees environment integration with Linux / Unix and &lt;a href="http://technet.microsoft.com/en-us/interopmigration/bb380242.aspx"&gt;Services for Unix (SFU), &lt;/a&gt;the benefits of each operating system platform, and where he would like to see the Microsoft / Linux integration story moving forward.  He gives tips on common mistakes and best practices with integration of Linux/Samba and Microsoft servers and resources on where to go to make this happen. &lt;br /&gt;
&lt;br /&gt;
What are your thoughts on Microsoft and Linux / Unix integration?&lt;img src="http://edge.technet.com/308/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://edge.technet.com/Media/Linux--Samba--Unix-and-Microsoft-Integration-chat-with-Ralf-Wigand/</comments><itunes:summary>While I was at IT Forum, I attended Ralf Wigand's IDA406 session entitled: "Broaden your Active Directory Horizon – Linux Authentication" and thought it would be great to interview him.  Ralf is on the IT staff from the University of Karlsruhe and has worked with Linux since the days of Minix.

In this interview we talked about where he currently commonly sees environment integration with Linux / Unix and Services for Unix (SFU), the benefits of each operating system platform, and where he would like to see the Microsoft / Linux integration story moving forward.  He gives tips on common mistakes and best practices with integration of Linux/Samba and Microsoft servers and resources on where to go to make this happen. 

What are your thoughts on Microsoft and Linux / Unix integration?</itunes:summary><link>http://edge.technet.com/Media/Linux--Samba--Unix-and-Microsoft-Integration-chat-with-Ralf-Wigand/</link><pubDate>Thu, 29 Nov 2007 18:00:00 GMT</pubDate><guid isPermaLink="false">http://edge.technet.com/Media/Linux--Samba--Unix-and-Microsoft-Integration-chat-with-Ralf-Wigand/</guid><evnet:views>4666</evnet:views><evnet:viewtrackingurl>http://edge.technet.com/308/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>While I was at IT Forum, I attended Ralf Wigand's IDA406 session entitled: "Broaden your Active Directory Horizon – Linux Authentication" and thought it would be great to interview him.  Ralf is on the IT staff from the University of Karlsruhe and has worked with Linux since the days of Minix.</evnet:previewtext><media:thumbnail url="http://edge.technet.com/Link/d0fde3a7-069b-492c-aebd-2764708e1eae/" height="240" width="320" /><media:thumbnail url="http://edge.technet.com/Link/3deeae37-f8e7-46e8-8f69-8f010b849e87/" height="64" width="85" /><media:group><media:content url="http://mschnlnine.vo.llnwd.net/d1/edge/8/0/3/RalfWigand_edge.mp4" expression="full" fileSize="71640103" type="video/mp4" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/edge/8/0/3/RalfWigand_edge.mp3" expression="full" fileSize="9429078" type="audio/mp3" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/edge/8/0/3/RalfWigand_edge.mp4" expression="full" fileSize="71640103" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/edge/8/0/3/RalfWigand_edge.wma" expression="full" fileSize="9540039" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/edge/8/0/3/RalfWigand_edge.wmv" expression="full" fileSize="74821169" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/edge/8/0/3/RalfWigand_2MB_edge.wmv" expression="full" fileSize="368781013" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/edge/8/0/3/RalfWigand_Zune_edge.wmv" expression="full" fileSize="93372861" type="video/x-ms-wmv" medium="video" /><media:content url="mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/8/0/3/RalfWigand_s_edge.wmv" expression="full" fileSize="192" type="video/x-ms-asf" medium="video" /></media:group><enclosure url="http://mschnlnine.vo.llnwd.net/d1/edge/8/0/3/RalfWigand_edge.mp4" length="71640103" type="video/mp4" /><dc:creator>extreme</dc:creator><itunes:author>extreme</itunes:author><slash:comments>1</slash:comments><wfw:commentRss>http://edge.technet.com/Media/Linux--Samba--Unix-and-Microsoft-Integration-chat-with-Ralf-Wigand/RSS/</wfw:commentRss><trackback:ping>http://edge.technet.com/308/Trackback.aspx</trackback:ping><category>AD</category><category>Linux</category><category>Samba</category><category>Services for Unix</category><category>Windows Server 2008</category></item><item><title>Windows Server 2008 - Active Directory Auditing Enhancements</title><description>&lt;img src="http://dtzar.members.winisp.net/Post-Images/image_4-85.png" border="0" /&gt;&lt;p&gt;
				&lt;img alt="" src="http://dtzar.members.winisp.net/Post-Images/image_4-300.png" /&gt;I hope this post will act as a good reference point to be able to quickly understand the good and bad about new AD auditing enhancements and then enable you to dive deeper at will using the links in this article.&lt;/p&gt;
&lt;p&gt;There’s nothing more exciting than auditing right? Well, check this out and hopefully it will spark some interest. &lt;/p&gt;
&lt;p&gt;In Windows Server 2003 R2 and prior, the auditing of active directory certainly has not been a strong point. You would enable or disable global AD auditing for success or failures, set a SACL on the objects you wanted to monitor, and then typically one or both of the following would happen: &lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;Your security event log fills up with &lt;i&gt;way&lt;/i&gt; more security events than you’d ever hoped for, possibly wrapping or ballooning the size of the security log. &lt;/li&gt;
    &lt;li&gt;Auditing doesn’t actually provide enough information for you to make any use of the events which are recorded in the security event log. i.e. it only says who was successful at modifying the object, but nothing on the details of the value(s) which were changed. &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;In Server 2008, we are on a good path to fix this pain. Some of the key improvements to AD auditing are as follows: &lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;You can limit the number of attributes which are audited for object types. For instance, you only want to know if the Employee’s Pay Level attribute is modified for all user accounts and nothing else. &lt;/li&gt;
    &lt;li&gt;Auditing is now broken into four categories: Access (same as 2000/2003), Changes, Replication, and Detailed Replication. The most interesting come from the new changes category:
    &lt;ul&gt;
        &lt;li&gt;AD DS logs the previous and current values of the attribute. If the attribute has more than one value, only the values that change as a result of the modify operation are logged. &lt;/li&gt;
        &lt;li&gt;If a new object is created, values of the attributes that are populated at the time of creation are logged. &lt;/li&gt;
        &lt;li&gt;If an object is moved, the previous and new location (distinguished name) is logged for moves within the domain. When an object is moved to a different domain, a create event is generated on the domain controller in the target domain. &lt;/li&gt;
        &lt;li&gt;If an object is undeleted, the location where the object is moved to is logged. &lt;/li&gt;
    &lt;/ul&gt;
    &lt;/li&gt;
&lt;/ul&gt;
&lt;p align="center"&gt;&lt;/p&gt;
&lt;p&gt;What are the downfalls? &lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;You have to modify the schema in order to limit the number of attributes which are audited per object type. This isn’t really difficult, but it would be nice if there were some friendlier type way to do it. &lt;/li&gt;
    &lt;li&gt;You cannot view or modify the audit policy subcategories with the Local Group Policy Editor (GPedit.msc). You can only do this with the command-line tool Auditpol.exe. &lt;/li&gt;
    &lt;li&gt;As far as I can tell, you can’t limit auditing to different specific attributes for a subset of the same type of object. For instance, you would like to audit attributes X, Y, Z for all admin user accounts, but only attribute X for all regular user accounts. Of course you have some control over this with your SACLs… &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;b&gt;Get Started:&lt;/b&gt;&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;A screencast on How to enable granular AD auditing in WS08 (coming in the future from me) &lt;/li&gt;
    &lt;li&gt;&lt;a href="http://technet2.microsoft.com/windowsserver2008/en/library/a9c25483-89e2-4202-881c-ea8e02b4b2a51033.mspx?mfr=true"&gt;&lt;span&gt;Windows Server 2008 Auditing AD DS Changes Step-by-Step Guide&lt;/span&gt;&lt;/a&gt; &lt;/li&gt;
    &lt;li&gt;&lt;a href="http://technet2.microsoft.com/windowsserver2008/en/library/ad35ab51-2e85-41e9-91f7-ccedf2fc98241033.mspx?mfr=true"&gt;&lt;span&gt;TechNet - AD DS: Auditing&lt;/span&gt;&lt;/a&gt; &lt;/li&gt;
    &lt;li&gt;&lt;a href="http://www.windowsnetworking.com/articles_tutorials/Introducing-Windows-Server-2008.html"&gt;&lt;span&gt;Windows Networking Site AD enhancements overview&lt;/span&gt;&lt;/a&gt; &lt;/li&gt;
    &lt;li&gt;MS Directory Services Team &lt;a href="http://blogs.technet.com/askds/archive/2007/10/19/introducing-auditing-changes-in-windows-2008.aspx"&gt;&lt;span&gt;Blog Post on WS08 Auditing Enhancements&lt;/span&gt;&lt;/a&gt; &lt;/li&gt;
&lt;/ul&gt;&lt;img src="http://edge.technet.com/314/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://edge.technet.com/Media/Windows-Server-2008-Active-Directory-Auditing-Enhancements/</comments><itunes:summary>
				I hope this post will act as a good reference point to be able to quickly understand the good and bad about new AD auditing enhancements and then enable you to dive deeper at will using the links in this article.
There’s nothing more exciting than auditing right? Well, check this out and hopefully it will spark some interest. 
In Windows Server 2003 R2 and prior, the auditing of active directory certainly has not been a strong point. You would enable or disable global AD auditing for success or failures, set a SACL on the objects you wanted to monitor, and then typically one or both of the following would happen: 

    Your security event log fills up with way more security events than you’d ever hoped for, possibly wrapping or ballooning the size of the security log. 
    Auditing doesn’t actually provide enough information for you to make any use of the events which are recorded in the security event log. i.e. it only says who was successful at modifying the object, but nothing on the details of the value(s) which were changed. 

In Server 2008, we are on a good path to fix this pain. Some of the key improvements to AD auditing are as follows: 

    You can limit the number of attributes which are audited for object types. For instance, you only want to know if the Employee’s Pay Level attribute is modified for all user accounts and nothing else. 
    Auditing is now broken into four categories: Access (same as 2000/2003), Changes, Replication, and Detailed Replication. The most interesting come from the new changes category:
    
        AD DS logs the previous and current values of the attribute. If the attribute has more than one value, only the values that change as a result of the modify operation are logged. 
        If a new object is created, values of the attributes that are populated at the time of creation are logged. 
        If an object is moved, the previous and new location (distinguished name) is logged for moves within the domain. When an object is moved to a different domain, a create event is generated on the domain controller in the target domain. 
        If an object is undeleted, the location where the object is moved to is logged. 
    
    


What are the downfalls? 

    You have to modify the schema in order to limit the number of attributes which are audited per object type. This isn’t really difficult, but it would be nice if there were some friendlier type way to do it. 
    You cannot view or modify the audit policy subcategories with the Local Group Policy Editor (GPedit.msc). You can only do this with the command-line tool Auditpol.exe. 
    As far as I can tell, you can’t limit auditing to different specific attributes for a subset of the same type of object. For instance, you would like to audit attributes X, Y, Z for all admin user accounts, but only attribute X for all regular user accounts. Of course you have some control over this with your SACLs… 

Get Started:

    A screencast on How to enable granular AD auditing in WS08 (coming in the future from me) 
    Windows Server 2008 Auditing AD DS Changes Step-by-Step Guide 
    TechNet - AD DS: Auditing 
    Windows Networking Site AD enhancements overview 
    MS Directory Services Team Blog Post on WS08 Auditing Enhancements 
</itunes:summary><link>http://edge.technet.com/Media/Windows-Server-2008-Active-Directory-Auditing-Enhancements/</link><pubDate>Thu, 29 Nov 2007 01:00:00 GMT</pubDate><guid isPermaLink="false">http://edge.technet.com/Media/Windows-Server-2008-Active-Directory-Auditing-Enhancements/</guid><evnet:views>4327</evnet:views><evnet:viewtrackingurl>http://edge.technet.com/314/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>&lt;img alt="" src="http://dtzar.members.winisp.net/Post-Images/image_4-300.png" /&gt;I hope this post will act as a good reference point to be able to quickly understand the good and bad about new AD auditing enhancements and then enable you to dive deeper at will using the links in this article.</evnet:previewtext><media:thumbnail url="http://dtzar.members.winisp.net/Post-Images/image_4-85.png" height="64" width="85" /><dc:creator>extreme</dc:creator><itunes:author>extreme</itunes:author><slash:comments>8</slash:comments><wfw:commentRss>http://edge.technet.com/Media/Windows-Server-2008-Active-Directory-Auditing-Enhancements/RSS/</wfw:commentRss><trackback:ping>http://edge.technet.com/314/Trackback.aspx</trackback:ping><category>Active Directory</category><category>AD</category><category>Auditing</category><category>Windows Server 2008</category></item><item><title>Microsoft IT Active Directory Interview with Brian Puhl</title><description>&lt;img src="http://edge.technet.com/Link/ac5b8abd-631f-4781-a6f8-45ca8e7efe17/" border="0" /&gt;&lt;div&gt;We sat down with Brian Puhl who has been working for Microsoft IT (MSIT) on the deployment, maintenance, planning of their active directory infrastructure since around Windows Server 2000. Learn about how Microsoft does AD from the source and also the projects they're working on.  A seamless experience for your corporate users inside the corporate network and out on the internet, without using a VPN?  Smartcard login/authentication for all MS employees? Average of 1 Schema change every 4 months?&lt;/div&gt;&lt;img src="http://edge.technet.com/272/WebViewBug.aspx?EVT=0" height="1" width="1" alt="" /&gt;</description><comments>http://edge.technet.com/Media/Microsoft-IT-Active-Directory-Interview-with-Brian-Puhl/</comments><itunes:summary>We sat down with Brian Puhl who has been working for Microsoft IT (MSIT) on the deployment, maintenance, planning of their active directory infrastructure since around Windows Server 2000. Learn about how Microsoft does AD from the source and also the projects they're working on.  A seamless experience for your corporate users inside the corporate network and out on the internet, without using a VPN?  Smartcard login/authentication for all MS employees? Average of 1 Schema change every 4 months?</itunes:summary><link>http://edge.technet.com/Media/Microsoft-IT-Active-Directory-Interview-with-Brian-Puhl/</link><pubDate>Wed, 28 Nov 2007 00:00:00 GMT</pubDate><guid isPermaLink="false">http://edge.technet.com/Media/Microsoft-IT-Active-Directory-Interview-with-Brian-Puhl/</guid><evnet:views>5352</evnet:views><evnet:viewtrackingurl>http://edge.technet.com/272/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>We sat down with Brian Puhl who has been working for Microsoft IT (MSIT) on the deployment, maintenance, planning of their active directory infrastructure since around Windows Server 2000. Learn about how Microsoft does AD from the source and also the projects they're working on.  A seamless&amp;#8230;</evnet:previewtext><media:thumbnail url="http://edge.technet.com/Link/c4ce4745-8c79-4744-9148-fa4ffaf90a63/" height="240" width="320" /><media:thumbnail url="http://edge.technet.com/Link/ac5b8abd-631f-4781-a6f8-45ca8e7efe17/" height="64" width="85" /><media:group><media:content url="http://mschnlnine.vo.llnwd.net/d1/edge/2/7/2/BrianPuhl-11-21-07_edge.mp4" expression="full" fileSize="117549494" type="video/mp4" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/edge/2/7/2/BrianPuhl-11-21-07_edge.mp3" expression="full" fileSize="15506831" type="audio/mp3" medium="audio" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/edge/2/7/2/BrianPuhl-11-21-07_edge.mp4" expression="full" fileSize="117549494" type="video/mp4" medium="video" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/edge/2/7/2/BrianPuhl-11-21-07_edge.wma" expression="full" fileSize="15686143" type="audio/x-ms-wma" medium="audio" /><media:content isDefault="true" url="http://mschnlnine.vo.llnwd.net/d1/edge/2/7/2/BrianPuhl-11-21-07_edge.wmv" expression="full" fileSize="123042032" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/edge/2/7/2/BrianPuhl-11-21-07_2MB_edge.wmv" expression="full" fileSize="606697583" type="video/x-ms-wmv" medium="video" /><media:content url="http://mschnlnine.vo.llnwd.net/d1/edge/2/7/2/BrianPuhl-11-21-07_Zune_edge.wmv" expression="full" fileSize="155377340" type="video/x-ms-wmv" medium="video" /><media:content url="mms://mschnlnine.wmod.llnwd.net/a1809/d1/edge/2/7/2/BrianPuhl-11-21-07_s_edge.wmv" expression="full" fileSize="209" type="video/x-ms-asf" medium="video" /></media:group><enclosure url="http://mschnlnine.vo.llnwd.net/d1/edge/2/7/2/BrianPuhl-11-21-07_edge.mp4" length="117549494" type="video/mp4" /><dc:creator>extreme</dc:creator><itunes:author>extreme</itunes:author><slash:comments>2</slash:comments><wfw:commentRss>http://edge.technet.com/Media/Microsoft-IT-Active-Directory-Interview-with-Brian-Puhl/RSS/</wfw:commentRss><trackback:ping>http://edge.technet.com/272/Trackback.aspx</trackback:ping><category>Active Directory</category><category>AD</category><category>Brian Puhl</category><category>MSIT</category><category>Windows Server 2008</category></item></channel></rss>