Thursday, 2 September 2010

Enable Vista's Built-in Administrator Account




If you’re not comfortable in using command line inactivating Administrator account in WindowsVista, there is another easy way to enable the Administrator account by using graphical user interface (GUI) within Vista desktop. It’s not necessary a must to use Administrator user account to login to Vista, but it’s useful if you want the convenient of using computer without distraction of User Account Control,or simply want to have a super user account as a ‘backdoor’ backup that able to reset your password if forgotten.




How to Enable Windows Vista and Windows 7 Administrator Account
Method 1
Under the command prompt shell window, run the following command:
net user administrator /active:yes
Note that you may need to disable UAC or open elevated command prompt.
Method 2
Enable the built-in Administrator account by using the Local Users and Groups MMC console to change the properties of the Administrator account:
  1. Open the MMC console and select Local Users and Groups.
  2. Right-click the Administrator account and select Properties. The Administrator Properties window appears.
  3. On the General tab, clear the Account is Disabled box.
  4. Close the MMC console.
  5. Administrator access is now enabled.
Method 3







How to Enable Administrator Account and Show on Welcome Screen from GUI Local Security Policy





  1. Click on Vista Start button, then go to Control Panel.
  1. Inside Control Panel, click on System and Maintenance link, follow byAdministrator Tools at the bottom.
  2. An Administrator Tools window appears. From there, click on Local Security Policy applet.
  3. Alternatively, type secpol.msc in Start Search box and press Enter.
  4. Click Continue on User Account Control’s Windows needs your permission to continue running Microsoft Management Console (MMC)dialog box.
  5. On the left pane of Local Security Policy MMC, expand Security Settings(should be opened by default), then expand Local Policies.
  6. Click on Security Options branch.
  7. Double click on Accounts: Administrator account status setting, then select Enabled radio button on Local Security Setting tab of Properties window.
  8. Click on OK button.
  9. Log off, switch user of restart your computer to logon with activated Administrator account.

How to Set Password to Protect Files or Folders in Windows 7 Vista or XP

Everyone has a secret. And your secret could be stored in your computer. If you are not the only one who use your computer, your secret files and folders will need to be stored with password protected. This article will show you a trick on how you can set password for your files or folders in Windows very easily.
How to Set Password for Files or Folders in Windows 7 Vista XP- Step 1:
Move all your secret files into one single folder.
How to Set Password to Protect Files or Folders in Windows 7 Vista or XP
How to Set Password for Files or Folders in Windows 7 Vista XP- Step 2:
Install WinRar if you don’t have it.
Right click your secret folder and click Add to archive.
How to Set Password to Protect Files or Folders in Windows 7 Vista or XP
How to Set Password for Files or Folders in Windows 7 Vista XP- Step 3:
Go to Advanced tab and then click Set Password.

How to Set Password to Protect Files or Folders in Windows 7 Vista or XP
How to Set Password for Files or Folders in Windows 7 Vista XP- Step 4:
Type in your desired password.
Check the checkbox for Encrypt file names if you want to encrypt the file names for all your files.
How to Set Password to Protect Files or Folders in Windows 7 Vista or XP
How to Set Password for Files or Folders in Windows 7 Vista XP- Step 5:
Click OK and OK again. Wait for the zipping process to be completed.
How to Set Password for Files or Folders in Windows 7 Vista XP- Step 6:
When it’s done, you should see a .rar file beside your secret folder. Try to unrar the file with the password you’ve set previously. If it works, you can now delete your original secret folder.
How to Set Password to Protect Files or Folders in Windows 7 Vista or XP

Wednesday, 1 September 2010

Save queries in Windows Server 2003's Active Directory Users and Computers tool


Windows Server 2003 administrators can’t live without the Active Directory Users and Computers tool. Here’s a quick look at the saved queries portion of the tool, which allows you to save and reuse lookups for different Active Directory (AD) objects. The ability to reuse queries can save time and speed up the process of locating objects within your AD environment.
The Active Directory Users and Computers tool is included in the AD implementation used by Windows Server 2003. The following steps will help in saving AD queries:
  1. Open Active Directory Users And Computers.
  2. Right-click the Saved Queries folder in the left pane of the window.
  3. Select New and choose Query.
  4. Enter a name and description for your saved query. (The description is optional, but it can help you remember what the query is looking for if you ever need to revisit the query definition.)
  5. Click the Define Query button, which will open the Common Queries window. (You’ll find that Microsoft has created a few predefined queries to assist you in finding certain objects. For this example, we will create our own query to find any users whose last names are similar to Miller.)
  6. In the Find box, select Users, Contacts, And Groups.
  7. Select the Advanced tab.
  8. Click the Field button, select User, and then select Last Name.
  9. For an operator in the center list box, select Is Like.
  10. Enter Miller or Mille* in the final text box on the row and click Add.
  11. Click OK in the Define Query window to return to the New Query window. (In the New Query window, you can also choose to include sub containers. Selecting this will search in any child organizational units or container objects for things that meet the conditions of the query you created.)
  12. Click OK to close the New Query window and return to Active Directory Users And Computers.
Your query will appear saved beneath Saved Queries in the left pane of the console. To execute the query, right-click it and choose Refresh. If you select the query without refreshing, the results from the last time you ran the query will appear.
This method does not circumvent or remove the need for Active Directory Users and Computers, but it may make it a little more useful. Remember that you can create truly custom queries for all of the AD object properties in your environment.

How to Create Active Directory ( In Windows Server 2003)

Creating the Active Directory

After you have installed Windows Server 2003 on a stand-alone server, run the Active Directory Wizard to create the new Active Directory forest or domain, and then convert the Windows Server 2003 computer into the first domain controller in the forest. To convert a Windows Server 2003 computer into the first domain controller in the forest, follow these steps:
  1. Insert the Windows Server 2003 CD-ROM into your computer's CD-ROM or DVD-ROM drive.
  2. Click Start, click Run, and then type dcpromo.
  3. Click OK to start the Active Directory Installation Wizard, and then click Next.
  4. Click Domain controller for a new domain, and then click Next.
  5. Click Domain in a new forest, and then click Next.
  6. Specify the full DNS name for the new domain. Note that because this procedure is for a laboratory environment and you are not integrating this environment into your existing DNS infrastructure, you can use something generic, such as mycompany.local, for this setting. Click Next.
  7. Accept the default domain NetBIOS name (this is "mycompany" if you used the suggestion in step 6). Click Next.
  8. Set the database and log file location to the default setting of the c:\winnt\ntds folder, and then click Next.
  9. Set the Sysvol folder location to the default setting of the c:\winnt\sysvol folder, and then click Next.
  10. Click Install and configure the DNS server on this computer, and then click Next.
  11. Click Permissions compatible only with Windows 2000 or Windows Server 2003 servers or operating systems, and then click Next.
  12. Because this is a laboratory environment, leave the password for the Directory Services Restore Mode Administrator blank. Note that in a full production environment, this password is set by using a secure password format. Click Next.
  13. Review and confirm the options that you selected, and then click Next.
  14. The installation of Active Directory proceeds. Note that this operation may take several minutes.
  15. When you are prompted, restart the computer. After the computer restarts, confirm that the Domain Name System (DNS) service location records for the new domain controller have been created. To confirm that the DNS service location records have been created, follow these steps:

    1. Click Start, point to Administrative Tools, and then click DNS to start the DNS Administrator Console.
    2. Expand the server name, expand Forward Lookup Zones, and then expand the domain.
    3. Verify that the _msdcs, _sites, _tcp, and _udp folders are present. These folders and the service location records they contain are critical to Active Directory and Windows Server 2003 operations.

Adding Users and Computers to the Active Directory Domain

After the new Active Directory domain is established, create a user account in that domain to use as an administrative account. When that user is added to the appropriate security groups, use that account to add computers to the domain.
  1. To create a new user, follow these steps:

    1. Click Start, point to Administrative Tools, and then click Active Directory Users and Computers to start the Active Directory Users and Computers console.
    2. Click the domain name that you created, and then expand the contents.
    3. Right-click Users, point to New, and then click User.
    4. Type the first name, last name, and user logon name of the new user, and then click Next.
    5. Type a new password, confirm the password, and then click to select one of the following check boxes:



      • Users must change password at next logon (recommended for most users)
      • User cannot change password
      • Password never expires
      • Account is disabled
      Click Next.
    6. Review the information that you provided, and if everything is correct, clickFinish.
  2. After you create the new user, give this user account membership in a group that permits that user to perform administrative tasks. Because this is a laboratory environment that you are in control of, you can give this user account full administrative access by making it a member of the Schema, Enterprise, and Domain administrators groups. To add the account to the Schema, Enterprise, and Domain administrators groups, follow these steps:

    1. On the Active Directory Users and Computers console, right-click the new account that you created, and then click Properties.
    2. Click the Member Of tab, and then click Add.
    3. In the Select Groups dialog box, specify a group, and then click OK to add the groups that you want to the list.
    4. Repeat the selection process for each group in which the user needs account membership.
    5. Click OK to finish.
  3. The final step in this process is to add a member server to the domain. This process also applies to workstations. To add a computer to the domain, follow these steps:

    1. Log on to the computer that you want to add to the domain.
    2. Right-click My Computer, and then click Properties.
    3. Click the Computer Name tab, and then click Change.
    4. In the Computer Name Changes dialog box, click Domain under Member Of, and then type the domain name. Click OK.
    5. When you are prompted, type the user name and password of the account that you previously created, and then click OK.

      A message that welcomes you to the domain is generated.
    6. Click OK to return to the Computer Name tab, and then click OK to finish.
    7. Restart the computer if you are prompted to do so.

How to Join a Domain in Windows 7

Joining your machine to a domain will let you enjoy the domain's benefits, such as scalability, central management, Group Policies, security and more.

Prerequisites

Before joining your Windows 7 machine to a domain, make sure you properly understand the following prerequisites:
Use Windows 7 Professional, Ultimate or Enterprise - Only Windows 7 these editions can join a domain. No, Windows 7 Home can't. Don't try it.
Have a  network Interface Card (NIC) - Duh, but unless you have one (or a wireless connection) how do you expect to connect to the server?


After installing Windows 7, it's important to install the correct hardware drivers to get your video, sound, network, and other components working properly.
Be physically be connected to the LAN - Windows 7 (and previous OSs) has an LAN auto sensing feature. Whenever you disconnect from the network, a balloon appears in the tray area notifying you of the disconnection status. Note that Windows 7 can be joined in an offline mode to a Windows Server 2008 R2 domain, but that's a topic for a different article.
Have a valid IP address - Valid for the network you're connected to. You can either configure one manually, receive one from a local DHCP Server, or leave it as is and receive an APIPA address (whatever starts with 169.254.X.Y). If it's an APIPA address you're asking for potential problems, as APIPA and AD do not go together hand-in-hand.
Have all-time connectivity to the Domain Controller - Or at least one of them. The IP address you've configured (or leased) should be good enough to enable you to connect to one of the Domain Controllers on your Domain. You may test your connectivity with PING, but make note that a successful PING does not guarantee that you've got proper connection to the DCs.
Have a properly configured DNS server - Without a properly configured DNS server your workstation will not be able to connect to the domain. Even if it did (for example you had a working DNS server but you somehow messed it up or shut it down) it will take a lot of time to actually log-on, and many AD related administration tasks will not work. The DNS server must hold a zone with the exact name of the AD domain you're trying to join. It also must hold 4 SRV folders (you can tell by the "_" in their name). If it doesn't, you either misspelled the domain name or DNS zone, or the zone is not configured to accept dynamic registrations, or it's not a Windows 2000/2003/2008 DNS server, or the Domain Controller does not have a working connection with the DNS server (firewall problems, improper IP configuration, IPSec etc.)
Have all-time connectivity to the DNS server - Test your connection to the DNS server by PINGing it and performing an NSLOOKUP query.
Possess local Administrative power - A simple user won't do. You must be the local Administrator.
Know the correct domain name, Administrator's name and password - Misspelled your domain name? You won't get to the Username and Password prompt!
Got your domain name right? You'll be asked for a valid username and password. To be safe, enter one that has Domain Admins rights, although you could get away with less, depending on your AD configuration (by default, any domain user has the right to join up to 10 machines to the domain. But this setting may have been altered by the domain admin).
You can perform the preceding tasks by using the Computer Name tab in the System Properties dialog box from the Control Panel or by right-clicking My Computer, and then Properties or by pressing the Windows logo key and Break. You may also use the NETDOM command. I will cover both methods.

Method #1 - The Traditional Way

1. Open System by clicking the Start button, right-click "Computer", and then click "Properties".
2. Under "Computer name, domain, and workgroup settings", click "Change settings".
Actually, you can also click on "Advanced system settings" and click on the "Computer Name" tab.
A third method to get to the same place is to use the Control Panel. Type "Domain" in the search box, then click on "Join a domain" link.
Either way, you're there. If you're prompted for an administrator password or confirmation, type the password or provide confirmation.
3. Click the Computer Name tab, and then click "Change".
4. Under Member of, click Domain.
5. Type the name of the domain that you want to join, and then click OK.
You will be asked to type your user name and password for the domain.
Once you are successfully joined to the domain, you will be prompted to restart your computer. You must restart your computer before the changes take effect.
Alternatively, you can click "Network ID" to use the Join a Domain or Workgroup wizard to automate the process of connecting to a domain and creating a domain user account on your computer. This is a longer way and I'm not sure why people would want to use it, but I'll document it anyway.
Go through the steps of the wizard. Make sure you select "This computer is part of a business network".
Then select "My company uses a network with a domain".
Provide the domain name and proper credentials.
And again.
You will still need to restart when the wizard is done.

Method #2 - Using NETDOM

By using NETDOM you can accomplish the task of joining a domain from the command prompt, and do it all in one line.
NETDOM is now included in the core OS, unlike Windows 2000/XP/2003 where you had to install the Support Tools to get it.
Open a Command Prompt window with Administrative credentials and type the following line:

Notes: Replace DOMAIN.COM and DOMAIN with your correct domain name, and of course, enter the proper user credentials. Also note there's an additional "d" in "user" and "password", that is NOT a typo.


netdom join %computername% /domain:DOMAIN.COM /userd:DOMAIN\administrator /passwordd:P@ssw0rd

Reboot the computer to complete the process.

Delete IE7 History From the Command Line

When cloning a computer running Windows XP, 2003, Vista or 2008, one of the tasks that you should perform before running SYSPREP is to delete the Internet Explorer 6 history, stored passwords, offline files and cookies. Same goes when preparing a computer for transfer to another user, or simply requiring that previous user data be deleted.
Network Performance Monitor: Map Your Network in Minutes!
Relax while Network Performance Monitor automatically maps your network, even VMs!

NPM automatically discovers your LAN or WAN and produces comprehensive, easy-to-view network diagrams that can be exported into gorgeous reports!
You Have Got To Try This! Get the Download Here...

Through the usual IE GUI

One method of performing this task is by using the IE7 GUI.
Open Internet Explorer, and from the Tools menu, open Internet Options.
Go to the General tab, and in the Browser History section, click on the Delete button.
In the Delete Browser History window, click one of the following buttons, based upon your requirements:
Temporary Internet Files > Delete files – To delete copies of web pages, images, and media that  are saved for faster viewing.
Cookies > Delete cookies – To delete cookies, which are files stored on your computer by websites to save preferences such as login information.
History > Delete history – To delete the history of the websites you have visited.
Form data > Delete forms – To delete all the saved information that you have typed into forms.
Passwords > Delete passwords – To delete all the passwords that are automatically filled in when you log on to a website you've previously visited.
Delete all – To delete all of the above in one operation.

By using a command

However, sometimes it is much easier to simply run a command line command or batch file to perform the same tasks. I use such a batch file and place it in one of my "special scripts" folder, where I store all my cool stuff. All I have to do is simply double-click on it, and bingo, history, passwords, cookies and offline files are deleted.
Here are the independent commands you can use. Go to Start > Run. Type CMD and pressEnter. In the Command Prompt window, type (or copy and paste) the following commands, and press Enter:
Delete Temporary Internet Files

RunDll32.exe InetCpl.cpl,ClearMyTracksByProcess 8

Delete Cookies

RunDll32.exe InetCpl.cpl,ClearMyTracksByProcess 2

Delete History

RunDll32.exe InetCpl.cpl,ClearMyTracksByProcess 1

Delete Form Data

RunDll32.exe InetCpl.cpl,ClearMyTracksByProcess 16

Delete Stored Passwords

RunDll32.exe InetCpl.cpl,ClearMyTracksByProcess 32

Delete All

RunDll32.exe InetCpl.cpl,ClearMyTracksByProcess 255

Delete All with the "Also delete files and settings stored by add-ons" options selected

RunDll32.exe InetCpl.cpl,ClearMyTracksByProcess 4351

Now it seems that the interesting bit is that you can combine the numbers to get 2 or more functions at the same time. For example, type:

RunDll32.exe InetCpl.cpl,ClearMyTracksByProcess 9

This will delete the files (+8) and history (+1) in one step. You can incorporate this into a logoff script, and assign it to users by using Group Policy (GPO).

Creating a shortcut

You can create a shortcut and place it on your desktop or Quick Launch toolbar.
Right-click on an empty spot on your desktop, select New > Shortcut.
In the Create Shortcut window, paste one of the above commands.
Give it an appropriate name, and press Finish.
You can also change the shortcut icon by right-clicking on it and selecting Properties. Next press the Change Icon button.
You can use the following file to find some interesting icons for the shortcut:

%SystemRoot%'System32'shell32.dll

Creating a batch file

You can also create a batch file that you can simply run by double-clicking on it. Save the following text as a .BAT file:

@ECHO OFF
ECHO Deleting current user's Temporary Files, Cookies, History, Form Data and Stored Passwords
RunDll32.exe InetCpl.cpl,ClearMyTracksByProcess 1
RunDll32.exe InetCpl.cpl,ClearMyTracksByProcess 2
RunDll32.exe InetCpl.cpl,ClearMyTracksByProcess 8
RunDll32.exe InetCpl.cpl,ClearMyTracksByProcess 16
RunDll32.exe InetCpl.cpl,ClearMyTracksByProcess 32
RunDll32.exe InetCpl.cpl,ClearMyTracksByProcess 255
ECHO Done!
PAUSE
CLS

Second example uses e different approach, but it's also worth noting:

@ECHO OFF
ECHO Cleaning Current User's Temp Folders
FOR /D %%G IN ("C:'Documents and Settings'*.*") DO DEL/S/Q/F "%%G'Cookies'*.*"
FOR /D %%G IN ("C:'Documents and Settings'*.*") DO DEL/S/Q/F "%%G'Local Settings'Temp'*.*"
FOR /D %%G IN ("C:'Documents and Settings'*.*") DO DEL/S/Q/F "%%G'Local Settings'History'*.*"
FOR /D %%G IN ("C:'Documents and Settings'*.*") DO DEL/S/Q/F "%%G'Local Settings'Temporary Internet Files'*.*"
ECHO Done!
PAUSE
CLS



Changing the default SQL Server backup folder

ProblemWhen you install SQL Server the path for the installation is generally something such as the following: C:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL.  In this directory there are also folders for your DATA files and also your BACKUP files.  Within SQL Server Management Studio you have the ability to change the default location for your Data and Log files for all new databases, but you can not change the default directory for your backups.  Is it possible to change the default directory for backups, so it does not need to be specified each time I run a backup?

SolutionThe directories for the default data files, log files and backups are stored in the system registry.  As mentioned already you have the ability to change the default data and log directories using SQL Server Management Studio, by right clicking on the server name and selecting properties and navigating to the Database Settings page as shown below.



But if you search through all of the pages under Database Settings you will not find anything that shows the default backup directory.  To find this we need to look in the registry.
If we open the registry using REGEDIT or some other tool and if you navigate to this key:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft SQL Server\MSSQL.2\MSSQLServer or similar for your instance of SQL Server we can see the following information   The highlighted line below shows the default directory for the backups for this one instance.
 
If you want to change the value you can edit the registry value and save the new location.  So for this example let's change it to 'D:\SQLBackups'.
If I do a backup using SQL Management Studio and click on "Add" for a new destination file the following screen shows the default folder has now changed to 'D:\SQLBackups'.
Another way to change the registry is to using the extended stored procedures XP_REGREAD and XP_REGWRITE.
To read the value from the registry you can issue the following command:
DECLARE @BackupDirectory VARCHAR(100) EXEC master..xp_regread @rootkey='HKEY_LOCAL_MACHINE',
  
@key='SOFTWARE\Microsoft\Microsoft SQL Server\MSSQL.2\MSSQLServer',
  
@value_name='BackupDirectory',
  
@BackupDirectory=@BackupDirectory OUTPUT SELECT @BackupDirectory
This will provide the following output, since we changed the value above directly in the registry.
If we want to change this back to the default folder we can use the following command
EXEC master..xp_regwrite
     
@rootkey='HKEY_LOCAL_MACHINE',
     
@key='SOFTWARE\Microsoft\Microsoft SQL Server\MSSQL.2\MSSQLServer',
     
@value_name='BackupDirectory',
     
@type='REG_SZ',
     
@value='C:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Backup'
If we run this command again we can see that this has changed:
DECLARE @BackupDirectory VARCHAR(100) EXEC master..xp_regread @rootkey='HKEY_LOCAL_MACHINE',
  
@key='SOFTWARE\Microsoft\Microsoft SQL Server\MSSQL.2\MSSQLServer',
  
@value_name='BackupDirectory',
  
@BackupDirectory=@BackupDirectory OUTPUT SELECT @BackupDirectory
To determine where SQL Server is installed you can right click on the server name, select Properties.  The root directory as highlighted below will show you the corresponding install name for the instance such as "MSSQL2" highlighted below, so you know which registry entry needs to be changed.
That's all there is to it, so save yourself some time and change the default location.