<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.chrisse.se/utility/FeedStylesheets/atom.xsl" media="screen"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en"><title type="html">Christoffer Andersson</title><subtitle type="html">Executive Consultant at TrueSec</subtitle><id>http://blogs.chrisse.se/blogs/chrisse/atom.aspx</id><link rel="alternate" type="text/html" href="http://blogs.chrisse.se/blogs/chrisse/default.aspx" /><link rel="self" type="application/atom+xml" href="http://blogs.chrisse.se/blogs/chrisse/atom.aspx" /><generator uri="http://communityserver.org" version="2.1.61129.2">Community Server</generator><updated>2008-02-06T04:39:00Z</updated><entry><title>Stanimir Stoyanov awarded Microsoft MVP in C#</title><link rel="alternate" type="text/html" href="http://blogs.chrisse.se/blogs/chrisse/archive/2009/04/03/stanimir-stoyanov-awarded-microsoft-mvp-in-c.aspx" /><id>http://blogs.chrisse.se/blogs/chrisse/archive/2009/04/03/stanimir-stoyanov-awarded-microsoft-mvp-in-c.aspx</id><published>2009-04-03T05:27:33Z</published><updated>2009-04-03T05:27:33Z</updated><content type="html">&lt;p&gt;Stanimir Stoyanov has been awarded the Microsoft MVP (Most Valuable Professional) title in Visual C#, Stanimir Stoyanov is a programmer, Software beta tester, and Windows enthusiast and also a very good friend of mine, he has been helping out in the development of the Fine Grain Password Policy Tool and other upcoming tools. Congratulations Stanimir you have made a great contribution to the community.  Read more about him at his blog &lt;a href="http://www.stoyanoff.info/"&gt;here&lt;/a&gt;&lt;/p&gt;&lt;img src="http://blogs.chrisse.se/aggbug.aspx?PostID=59" width="1" height="1"&gt;</content><author><name>Christoffer Andersson</name><uri>http://blogs.chrisse.se/members/Christoffer+Andersson.aspx</uri></author><category term="Microsoft MVP" scheme="http://blogs.chrisse.se/blogs/chrisse/archive/tags/Microsoft+MVP/default.aspx" /></entry><entry><title>It’s been Windows 7 Summit, Visit to Redmond and Microsoft TechDays</title><link rel="alternate" type="text/html" href="http://blogs.chrisse.se/blogs/chrisse/archive/2009/03/30/it-s-been-windows-7-summit-visit-to-redmond-and-microsoft-techdays.aspx" /><id>http://blogs.chrisse.se/blogs/chrisse/archive/2009/03/30/it-s-been-windows-7-summit-visit-to-redmond-and-microsoft-techdays.aspx</id><published>2009-03-29T22:37:00Z</published><updated>2009-03-29T22:37:00Z</updated><content type="html">&lt;P&gt;It's been a very busy month, I've been traveling a lot and been speaking at a few different seminars and conferences. First of was the Windows 7 Summit held here in Sweden by ourselves TrueSec, &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Windows 7 Summit&lt;BR&gt;&lt;/STRONG&gt;&lt;STRONG&gt;&lt;IMG src="http://www.chrisse.se/cs-content/5.jpg"&gt;&lt;BR&gt;&lt;/STRONG&gt;I did two sessions together with Mikael Nyström, first session was an introduction to the Windows 7 Client, covering some UI changes and the approach Microsoft has taken with Multi-Touch and the other was about new technologies and features in Windows Server 2008 R2, it was a great time and I had lots of fun on the stage, I'm sorry that I misspelled my own sisters name during the Recycle-Bin demo &lt;SPAN style="FONT-FAMILY:Wingdings;"&gt;J&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Microsoft decided to record the sessions, so if anyone is interested to see the sessions (In Swedish), here you go! &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;An introduction to the Windows 7 Client. &lt;BR&gt;&lt;/STRONG&gt;&lt;SPAN style="FONT-FAMILY:Tahoma;FONT-SIZE:10pt;"&gt;&lt;A href="http://mediadl.microsoft.com/mediadl/www/s/sverige/technettv/2009/Win7Summit/Windows7Summit-090226-pass1.wmv" target=_blank&gt;http://mediadl.microsoft.com/mediadl/www/s/sverige/technettv/2009/Win7Summit/Windows7Summit-090226-pass1.wmv &lt;/A&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;New Technologies and Features in Windows Server 2008 R2&lt;BR&gt;&lt;/STRONG&gt;&lt;A href="http://mediadl.microsoft.com/mediadl/www/s/sverige/technettv/2009/Win7Summit/Windows7Summit-090226-pass2.wmv" target=_blank&gt;http://mediadl.microsoft.com/mediadl/www/s/sverige/technettv/2009/Win7Summit/Windows7Summit-090226-pass2.wmv&lt;/A&gt;&lt;SPAN style="COLOR:black;"&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Redmond&lt;BR&gt;&lt;/STRONG&gt;Directly after the Windows 7 summit it was time to fly over to Seattle/Redmond for the Microsoft MVP Summit. A big thanks to the entire Directory Service Team at Microsoft for the amazing week we had in Redmond at the Microsoft Campus working with them, and all other DS MVPs that attended the Microsoft MVP Summit, also thanks to my friend Eddy for inviting me to his new house, you got a nice place &lt;SPAN style="FONT-FAMILY:Wingdings;"&gt;J&lt;/SPAN&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft TechDays in Västerås&lt;BR&gt;&lt;IMG src="http://www.chrisse.se/cs-content/3.jpg"&gt;&lt;BR&gt;&lt;/STRONG&gt;At Microsoft TechDays in Västerås (Sweden) I attended as a speaker and presented on how to Incorporate RODCs (Read Only Domain Controllers) to your existing&amp;nbsp;Active Directory, this was a 400 level sessions where I decided to give a deep-dive on how RODCs really works (and doesn't work) in detail and how it effects an already existing Active Directory and related components. Unfortunately time didn't allow me to show the FAS (Filter Attribute Set) Demo, I'm sorry for that, but I'm planning a detail article on FAS works, the basic idea is that you can flag attributes with sensitive/confidential information to never replicate to RODCs, in case of an RODC compromise, this information isn't reveled. &lt;/P&gt;
&lt;P&gt;You can download the slide deck from the session here: &lt;A href="http://www.chrisse.se/cs-content/tech_days09_sweden_ds_final.zip"&gt;tech_days09_sweden_ds_final.zip&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;I've got many questions about RODCs and DNS after my sessions, I've blogged about that topic a while ago, you can find the article here: &lt;A href="http://blogs.chrisse.se/blogs/chrisse/archive/2009/01/25/how-read-only-domain-controllers-and-dns-works.aspx"&gt;How Read-Only Domain Controllers and DNS works.&lt;/A&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Thanks to Microsoft for putting together the TechDays Conference, this was the first time the concept of "TechDays" where used in Sweden, the idea is to have a sort of local TechED event, and I must said everything did work very well, hopefully there will be a TechDays next year as well. &lt;/P&gt;&lt;img src="http://blogs.chrisse.se/aggbug.aspx?PostID=57" width="1" height="1"&gt;</content><author><name>Christoffer Andersson</name><uri>http://blogs.chrisse.se/members/Christoffer+Andersson.aspx</uri></author><category term="Active Directory" scheme="http://blogs.chrisse.se/blogs/chrisse/archive/tags/Active+Directory/default.aspx" /></entry><entry><title>The real Enterprise Read-Only Domain Controllers group [498]</title><link rel="alternate" type="text/html" href="http://blogs.chrisse.se/blogs/chrisse/archive/2009/02/03/the-real-enterprise-read-only-domain-controllers-group-498.aspx" /><id>http://blogs.chrisse.se/blogs/chrisse/archive/2009/02/03/the-real-enterprise-read-only-domain-controllers-group-498.aspx</id><published>2009-02-03T02:39:47Z</published><updated>2009-02-03T02:39:47Z</updated><content type="html">&lt;p&gt;It's been yet another sleepless night working, actually I have a lot of stuff going on right now, I guess I don't will feel too well when this week is over, anyway some interesting facts about the Enterprise Read-Only Domain Controllers group (Yes the _real_ one this time, with RID 498 that's not an FSP), have you ever look thru the members of that group? Why would you ever do that, isn't it obvious that it's going to contain the RODC accounts in the enterprise? Nope, in fact it won't, it will always be empty &lt;span style="font-family:Wingdings;"&gt;J&lt;/span&gt;
	&lt;/p&gt;&lt;p&gt;So how does this really work? Adprep /rodcprep stamps each NC head with an ACE (in order to allow RODCs replicate changes from the NC), NDNCs are stamped with an ACE for the Read-Only Enterprise Domain Controllers group (Note that the group doesn't exist at this stage, but always has a well-known RID of 498, so that's how adprep dose it)
&lt;/p&gt;&lt;p&gt;&lt;span style="font-size:10pt;"&gt;&lt;span style="font-family:Tahoma;"&gt;But won't replication of NDNCs fail as Enterprise Read-Only Domain Controllers is granted extended-right Replicate Changes but the group is empty?  Nope RODCs will always include the RID 498 in its token &lt;/span&gt;&lt;span style="font-family:Wingdings;"&gt;J&lt;/span&gt;&lt;span style="font-family:Tahoma;"&gt;
			&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Tahoma;font-size:10pt;"&gt;So what do we really need the group for? It's there for display purposes, so you don't have to see something like (Unknown Account) if you look at the ACL.&lt;/span&gt;&lt;/p&gt;&lt;img src="http://blogs.chrisse.se/aggbug.aspx?PostID=56" width="1" height="1"&gt;</content><author><name>Christoffer Andersson</name><uri>http://blogs.chrisse.se/members/Christoffer+Andersson.aspx</uri></author></entry><entry><title>NT AUTHORITY\ENTERPRISE READ-ONLY DOMAIN CONTROLLERS BETA</title><link rel="alternate" type="text/html" href="http://blogs.chrisse.se/blogs/chrisse/archive/2009/02/01/nt-authority-enterprise-read-only-domain-controllers-beta.aspx" /><id>http://blogs.chrisse.se/blogs/chrisse/archive/2009/02/01/nt-authority-enterprise-read-only-domain-controllers-beta.aspx</id><published>2009-02-01T02:02:00Z</published><updated>2009-02-01T02:02:00Z</updated><content type="html">&lt;p&gt;I was working late tonight to finish my session "Incorporate RODCs (Read Only Domain Controllers) to your existing Active Directory"  that I'm going to present at Microsoft TechDays 17-18 mars in Västerås. If you're interested in a deep dive session (level 400+) about Read-Only Domain Controllers, then my session is for you, read more at: &lt;a href="http://www.microsoft.com/sverige/techdays09/sv/about.aspx"&gt;http://www.microsoft.com/sverige/techdays09/sv/about.aspx&lt;/a&gt;
	&lt;/p&gt;&lt;p&gt;However, I was about to reproduce a bug that we have found with "adprep /rodcprep" to include it in the session, and how to correct and avoid it to happen, when I was reviewing the security of my NCs I noticed a strange group: &lt;span style="color:black;font-family:Tahoma;font-size:10pt;"&gt;NT AUTHORITY\ENTERPRISE READ-ONLY DOMAIN CONTROLLERS BETA. It's a part of the NT AUTHORITY and my guess is that this group was introduced in my forest in the early days of Longhorn Server when there was still a requirement to have the PDC running Longhorn Server in order to incorporate RODCs to your forest. Now days (Post Beta 3) Enterprise Read-Only Domain Controllers and Read-Only Domain Controllers (Domain specific) is created in your domain using a trigger that happens on the promotion of the first RODC or the first Pre-Stage of an RODC.&lt;/span&gt;
	&lt;/p&gt;&lt;p /&gt;&lt;img src="http://blogs.chrisse.se/aggbug.aspx?PostID=55" width="1" height="1"&gt;</content><author><name>Christoffer Andersson</name><uri>http://blogs.chrisse.se/members/Christoffer+Andersson.aspx</uri></author></entry><entry><title>How Read Only Domain Controllers and DNS works</title><link rel="alternate" type="text/html" href="http://blogs.chrisse.se/blogs/chrisse/archive/2009/01/25/how-read-only-domain-controllers-and-dns-works.aspx" /><id>http://blogs.chrisse.se/blogs/chrisse/archive/2009/01/25/how-read-only-domain-controllers-and-dns-works.aspx</id><published>2009-01-25T14:34:29Z</published><updated>2009-01-25T14:34:29Z</updated><content type="html">&lt;p&gt;I was recently asked by a friend of mine how Read-Only Domain Controllers (RODCs) works with DNS, since they can host DNS for Active Directory, so I think it was a good idea with a blog post on how it really works. First of all Windows Server 2008 bring new capabilities to both Active Directory and DNS and many of them are related. 
&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Read-Only Domain Controllers (RODCs) and the Primary Read-Only Zone
&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;When you promote a Read-Only Domain Controller (RODC) and also select it to be a DNS server, it will perform inbound replication of the DNS Zones (Either stored in the applications or domain NCs) as any Writeable Domain Controller. But if you're familiar with RODC basics you know they never perform outbound replication and the database is mostly read-only (including the DNS records), Windows Server 2008 DNS Introduce a new zone type called the Primary Read-Only Zone. The Administrator of RODC can view contents of DNS but will unable to change it from a RODC.
&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Read-Only Domain Controllers (RODCs) are not pointing the SOA to them self unlike Writable Domain Controllers
&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Writable Domain Controllers are always pointing the SOA to them self, because they all host writable copies of Active Directory-Integrated Zones, How ever RODCs doesn't host writable copies of those and therefore points the SOA to an Writable Domain Controller using the following SOA selection model.
&lt;/p&gt;&lt;ol&gt;&lt;li&gt;Trying to select a writable domain controller that is running Windows Server 2008 and is published as a NS for the zone
&lt;/li&gt;&lt;li&gt;&lt;div&gt;If there are no Windows Server 2008 writable domain controllers that publish a NS for the zone a randomly domain controller will be picked from the NS list.
&lt;/div&gt;&lt;p&gt;&lt;strong&gt;Note: &lt;/strong&gt;The current SOA target DC is maintained separately for each zone and re-selected every 20 minutes (not configurable). The selection algorithm contains a random component to try to spread load between writable domain controllers.
&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;[2] Needs a clarification to another difference, RODCs doesn't register NS records, so it makes [2] safe from picking any RODC.   
&lt;/p&gt;&lt;p&gt;&lt;strong&gt;DNS Updates for clients having a Read-Only Domain Controller (RODC) as preferred DNS server
&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;When a client attempts a dynamic update, it sends SOA query to its preferred DNS server. Typically, clients are configured to use the DNS server in their branch site as their preferred DNS server. The RODC should read its SOA record and at best effort return a writable Windows Server 2008 domain controller to the client (Using the SOA selection model above), the RODC waits a certain amount of time, as explained below, and then it attempts to replicate the updated DNS record object in Active Directory from the DNS server that it referred the client to through an RSO operation back to the RODC, an RSO operation is an operational attribute named replicateSingleObject that has existed in Active Directory since Windows 2000 and allows replication of a single object by using a LDAP modify operation of the replicateSingleObject attribute, However the replicateSingleObject has been updated in Windows Server 2008 to support replication of secrets to RODCs, More information about the attribute and it's syntax can be found here: http://msdn.microsoft.com/en-us/library/cc223306(PROT.13).aspx
&lt;/p&gt;&lt;p&gt;&lt;strong&gt;How Read-Only Domain Controllers perform RSO operations of DNS record updates
&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;For the DNS server on the RODC to perform an RSO operation of the DNS record update, a DNS server that runs Windows Server 2008 must host writeable copies of the zone that contains the record. That Windows Server 2008 DNS server must register a name server (NS) resource record for the zone, with other words [1] must be used in the SOA selection model above.&lt;br /&gt;&lt;strong&gt;&lt;br /&gt;Note:&lt;/strong&gt; The Windows Server 2003 Branch Office Guide recommended restricting name server (NS) record registration to a subset of the available DNS servers. If you followed those guidelines and you do not register at least one writable Windows Server 2008 DNS server as a name server for the zone, the DNS server on the RODC attempts to perform the RSO operation with a DNS server that runs Windows Server 2003 using [2] in the SOA selection model. That operation fails and generates a 4015 Error in the DNS event log of the RODC, and replication of the DNS record update will be delayed until the next scheduled replication cycle and RSO operation cannot be made by the RODC DNS against a Windows Server 2003 Domain Controller. 
&lt;/p&gt;&lt;p&gt;More specifically how the RSO operation really works, the SOA query triggers the DNS server on the RODC to put an entry in remotePollList, which is an internal queue on each DNS server. The entry includes the following:
&lt;/p&gt;&lt;ul&gt;&lt;li&gt;The object to be replicated
&lt;/li&gt;&lt;li&gt;The source domain controller to replicate from 
&lt;/li&gt;&lt;li&gt;A time stamp
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;The time stamp is set to a time in the future that is equal to the current time plus a replication delay. The replication delay is controlled by a registry setting named &lt;strong&gt;DsRemoteReplicationDelay&lt;/strong&gt;. By default, the value of this setting is 30 seconds.
&lt;/p&gt;&lt;p&gt;The internal queue (remotePollList) is processed at regular intervals. The queue-processing interval is controlled by a registry setting named &lt;strong&gt;DSPollingInterval.&lt;/strong&gt; By default, the value of the interval is three minutes.
&lt;/p&gt;&lt;p&gt;When the DNS server processes the queue, it attempts to replicate only objects whose time stamp is less than current time. Therefore, the delay between the time that the RODC refers the client to an authoritative DNS server and then attempts to replicate in is determined by the following:
&lt;/p&gt;&lt;ul&gt;&lt;li&gt;The next time that the DNS server processes the queue
&lt;/li&gt;&lt;li&gt;Whether the remote replication delay that is set on the entry in the queue has elapsed
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;If you use the default values for the registry settings, the amount of time before the RODC attempts to replicate the DNS update is a minimum of 30 seconds and a maximum of 210 seconds.
&lt;/p&gt;&lt;p&gt;You can modify the values of these registry settings to reduce the amount of time before the RODC attempts to replicate the DNS update. The minimum value for the &lt;strong&gt;DsRemoteReplicationDelay&lt;/strong&gt; setting is 5 seconds. The minimum value for the &lt;strong&gt;DSPollingInterval &lt;/strong&gt;setting is 30 seconds. If you use the minimum values, the amount of time before the RODC attempts to replicate the DNS update is a minimum of 5 seconds and a maximum of 35 seconds. 
&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; Max number of RSO requests per 5 minutes cycle is 300 to prevent Denial of Service attacks
&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; DsPollingInterval controls all Active Directory polling, not just RODC RSO handling. If you change this value, be aware that this change will affect more than just RODC RSO operations. For example, this setting will affect how often the DNS server polls Active Directory for new or updated resource records or DNS zones.
&lt;/p&gt;&lt;p&gt;The following table lists some additional registry entries that are related to the RSO operations that are performed for DNS updates on an RODC. These registry entries are stored in the following registry key: &lt;strong&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNS\Parameters&lt;/strong&gt;
	&lt;/p&gt;&lt;div&gt;&lt;table style="border-collapse:collapse;"&gt;&lt;tr&gt;&lt;td style="padding-left:7px;padding-right:7px;border-top:solid #4bacc6 1.0pt;border-left:none;border-bottom:solid #4bacc6 1.0pt;border-right:none;"&gt;&lt;p&gt;&lt;span style="color:black;"&gt;&lt;strong&gt;Registry entry&lt;/strong&gt;&lt;/span&gt; &lt;/p&gt;&lt;/td&gt;&lt;td style="padding-left:7px;padding-right:7px;border-top:solid #4bacc6 1.0pt;border-left:none;border-bottom:solid #4bacc6 1.0pt;border-right:none;"&gt;&lt;p&gt;&lt;span style="color:black;"&gt;&lt;strong&gt;Minimum value&lt;/strong&gt;&lt;/span&gt; &lt;/p&gt;&lt;/td&gt;&lt;td style="padding-left:7px;padding-right:7px;border-top:solid #4bacc6 1.0pt;border-left:none;border-bottom:solid #4bacc6 1.0pt;border-right:none;"&gt;&lt;p&gt;&lt;span style="color:black;"&gt;&lt;strong&gt;Maximum value&lt;/strong&gt;&lt;/span&gt; &lt;/p&gt;&lt;/td&gt;&lt;td style="padding-left:7px;padding-right:7px;border-top:solid #4bacc6 1.0pt;border-left:none;border-bottom:solid #4bacc6 1.0pt;border-right:none;"&gt;&lt;p&gt;&lt;span style="color:black;"&gt;&lt;strong&gt;Default value&lt;/strong&gt;&lt;/span&gt; &lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="background:#d2eaf1;"&gt;&lt;td style="padding-left:7px;padding-right:7px;border-left:none;border-right:none;"&gt;&lt;p&gt;&lt;span style="color:black;"&gt;EnableRSOForRODC&lt;/span&gt; &lt;/p&gt;&lt;/td&gt;&lt;td style="padding-left:7px;padding-right:7px;border-left:none;border-right:none;"&gt;&lt;p&gt;&lt;span style="color:black;"&gt;Either True or False&lt;/span&gt; &lt;/p&gt;&lt;/td&gt;&lt;td style="padding-left:7px;padding-right:7px;border-left:none;border-right:none;"&gt;&lt;p&gt;&lt;span style="color:black;"&gt; &lt;/span&gt; &lt;/p&gt;&lt;/td&gt;&lt;td style="padding-left:7px;padding-right:7px;border-left:none;border-right:none;"&gt;&lt;p&gt;&lt;span style="color:black;"&gt;True&lt;/span&gt; &lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding-left:7px;padding-right:7px;"&gt;&lt;p&gt;&lt;span style="color:black;"&gt;MaximumRodcRsoQueueLength&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="padding-left:7px;padding-right:7px;"&gt;&lt;p&gt;&lt;span style="color:black;"&gt;1&lt;/span&gt; &lt;/p&gt;&lt;/td&gt;&lt;td style="padding-left:7px;padding-right:7px;"&gt;&lt;p&gt;&lt;span style="color:black;"&gt;1000000&lt;/span&gt; &lt;/p&gt;&lt;/td&gt;&lt;td style="padding-left:7px;padding-right:7px;"&gt;&lt;p&gt;&lt;span style="color:black;"&gt;300&lt;/span&gt; &lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="background:#d2eaf1;"&gt;&lt;td style="padding-left:7px;padding-right:7px;border-left:none;border-right:none;"&gt;&lt;p&gt;&lt;span style="color:black;"&gt;MaximumRodcRsoAttemptsPerCycle&lt;/span&gt; &lt;/p&gt;&lt;/td&gt;&lt;td style="padding-left:7px;padding-right:7px;border-left:none;border-right:none;"&gt;&lt;p&gt;&lt;span style="color:black;"&gt;1&lt;/span&gt; &lt;/p&gt;&lt;/td&gt;&lt;td style="padding-left:7px;padding-right:7px;border-left:none;border-right:none;"&gt;&lt;p&gt;&lt;span style="color:black;"&gt;1000000&lt;/span&gt; &lt;/p&gt;&lt;/td&gt;&lt;td style="padding-left:7px;padding-right:7px;border-left:none;border-right:none;"&gt;&lt;p&gt;&lt;span style="color:black;"&gt;100&lt;/span&gt; &lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="padding-left:7px;padding-right:7px;border-bottom:solid #4bacc6 1.0pt;"&gt;&lt;p&gt;&lt;span style="color:black;"&gt;DsRemoteReplicationDelay&lt;/span&gt; &lt;/p&gt;&lt;/td&gt;&lt;td style="padding-left:7px;padding-right:7px;border-bottom:solid #4bacc6 1.0pt;"&gt;&lt;p&gt;&lt;span style="color:black;"&gt;5&lt;/span&gt; &lt;/p&gt;&lt;/td&gt;&lt;td style="padding-left:7px;padding-right:7px;border-bottom:solid #4bacc6 1.0pt;"&gt;&lt;p&gt;&lt;span style="color:black;"&gt;3600&lt;/span&gt; &lt;/p&gt;&lt;/td&gt;&lt;td style="padding-left:7px;padding-right:7px;border-bottom:solid #4bacc6 1.0pt;"&gt;&lt;p&gt;&lt;span style="color:black;"&gt;30&lt;/span&gt; &lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;&lt;p&gt;
 &lt;/p&gt;&lt;p&gt;To modify any of the registry entries that are related to the RSO operations for DNS updates on an RODC, use the Dnscmd.exe command-line tool to set the appropriate parameter.&lt;br /&gt;&lt;strong&gt;Example:&lt;/strong&gt; "dnscmd &amp;lt;server&amp;gt;.&amp;lt;domain&amp;gt;.&amp;lt;com&amp;gt; /Config /DsRemoteReplicationDelay 10"
&lt;/p&gt;&lt;p&gt;I think that's all I can think of for now.&lt;/p&gt;&lt;img src="http://blogs.chrisse.se/aggbug.aspx?PostID=54" width="1" height="1"&gt;</content><author><name>Christoffer Andersson</name><uri>http://blogs.chrisse.se/members/Christoffer+Andersson.aspx</uri></author></entry><entry><title>When using tokeGroups attribuet to retrieve group membership fails</title><link rel="alternate" type="text/html" href="http://blogs.chrisse.se/blogs/chrisse/archive/2009/01/15/when-using-tokegroups-attribuet-to-retrieve-group-membership-fails.aspx" /><id>http://blogs.chrisse.se/blogs/chrisse/archive/2009/01/15/when-using-tokegroups-attribuet-to-retrieve-group-membership-fails.aspx</id><published>2009-01-14T16:17:23Z</published><updated>2009-01-14T16:17:23Z</updated><content type="html">&lt;p&gt;When using tokeGroups attribute to retrieve group membership fails, well more optionally would of course be to use the attribute tokenGroupsNoGCAcceptable as it will return a value on "best effort" even if there isn't a GC around, but that's not the issue here, and the issue actually applies to tokenGroupsNoGCAcceptable as well.
&lt;/p&gt;&lt;p&gt;If we assume that all DCs in the forest are also made GCs, what will cause the code below to break?  It contains an interesting bug actually, and a scenario that the developers of this app failed to take care of, Note this application is actually a Microsoft app. I will be interesting to see if anyone else can identify the issue &lt;span style="font-family:Wingdings;"&gt;J&lt;/span&gt; btw; it caused the entire app to crash. 
&lt;/p&gt;&lt;p&gt;
 &lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;&lt;span style="color:blue;"&gt;internal&lt;/span&gt;
			&lt;span style="color:blue;"&gt;class&lt;/span&gt;
			&lt;span style="color:#2b91af;"&gt;Program
&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;    {
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;internal&lt;/span&gt;
			&lt;span style="color:blue;"&gt;static&lt;/span&gt;
			&lt;span style="color:blue;"&gt;void&lt;/span&gt; Main(&lt;span style="color:blue;"&gt;string&lt;/span&gt;[] args)
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;        {
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:#2b91af;"&gt;Console&lt;/span&gt;.WriteLine(&lt;span style="color:#a31515;"&gt;"BREUtils:checkDomainUseRoles."&lt;/span&gt;);
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;
 &lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:#2b91af;"&gt;ArrayList&lt;/span&gt; tokenGroups = &lt;span style="color:blue;"&gt;new&lt;/span&gt;
			&lt;span style="color:#2b91af;"&gt;ArrayList&lt;/span&gt;();
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;            tokenGroups = checkDomainUserRoles(&lt;span style="color:#a31515;"&gt;"internal\\ADCH"&lt;/span&gt;);
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;        }
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;
 &lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;public&lt;/span&gt;
			&lt;span style="color:blue;"&gt;static&lt;/span&gt;
			&lt;span style="color:#2b91af;"&gt;ArrayList&lt;/span&gt; checkDomainUserRoles(&lt;span style="color:blue;"&gt;string&lt;/span&gt; user)
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;        {
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:#2b91af;"&gt;ArrayList&lt;/span&gt; list = &lt;span style="color:blue;"&gt;new&lt;/span&gt;
			&lt;span style="color:#2b91af;"&gt;ArrayList&lt;/span&gt;();
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:#2b91af;"&gt;DirectoryEntry&lt;/span&gt; entry = &lt;span style="color:blue;"&gt;null&lt;/span&gt;;
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:#2b91af;"&gt;DirectoryEntry&lt;/span&gt; searchRoot = &lt;span style="color:blue;"&gt;null&lt;/span&gt;;
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:#2b91af;"&gt;DirectorySearcher&lt;/span&gt; searcher = &lt;span style="color:blue;"&gt;null&lt;/span&gt;;
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:#2b91af;"&gt;SearchResultCollection&lt;/span&gt; results = &lt;span style="color:blue;"&gt;null&lt;/span&gt;;
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;try
&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;            {
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:green;"&gt;//ZeroTouchServiceUtil.LogDebugEvent(string.Format("Entering BREUtilities::checkDomainUserRoles called with parameters user: {0} ", user));
&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;string&lt;/span&gt; str = user.Split(&lt;span style="color:blue;"&gt;new&lt;/span&gt;
			&lt;span style="color:blue;"&gt;char&lt;/span&gt;[] { &lt;span style="color:#a31515;"&gt;'\\'&lt;/span&gt; })[1];
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;string&lt;/span&gt; str2 = user.Split(&lt;span style="color:blue;"&gt;new&lt;/span&gt;
			&lt;span style="color:blue;"&gt;char&lt;/span&gt;[] { &lt;span style="color:#a31515;"&gt;'\\'&lt;/span&gt; })[0];
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                entry = &lt;span style="color:blue;"&gt;new&lt;/span&gt;
			&lt;span style="color:#2b91af;"&gt;DirectoryEntry&lt;/span&gt;(&lt;span style="color:#a31515;"&gt;"LDAP://rootDSE"&lt;/span&gt;);
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;string&lt;/span&gt; str3 = (&lt;span style="color:blue;"&gt;string&lt;/span&gt;)entry.Properties[&lt;span style="color:#a31515;"&gt;"DefaultNamingContext"&lt;/span&gt;][0];
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                searchRoot = &lt;span style="color:blue;"&gt;new&lt;/span&gt;
			&lt;span style="color:#2b91af;"&gt;DirectoryEntry&lt;/span&gt;(&lt;span style="color:#a31515;"&gt;"GC://"&lt;/span&gt; + str3);
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                searcher = &lt;span style="color:blue;"&gt;new&lt;/span&gt;
			&lt;span style="color:#2b91af;"&gt;DirectorySearcher&lt;/span&gt;(searchRoot);
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;string&lt;/span&gt; str4 = &lt;span style="color:#a31515;"&gt;"(&amp;amp;(objectClass=user)(samaccountname="&lt;/span&gt; + str + &lt;span style="color:#a31515;"&gt;"))"&lt;/span&gt;;
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                searcher.Filter = str4;
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                searcher.SearchRoot = &lt;span style="color:blue;"&gt;new&lt;/span&gt;
			&lt;span style="color:#2b91af;"&gt;DirectoryEntry&lt;/span&gt;(&lt;span style="color:#a31515;"&gt;"LDAP://"&lt;/span&gt; + str2);
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                searcher.PropertiesToLoad.Add(&lt;span style="color:#a31515;"&gt;"CN"&lt;/span&gt;);
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                results = searcher.FindAll();
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;if&lt;/span&gt; (results.Count != 1)
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                {
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:green;"&gt;//ZeroTouchServiceUtil.LogDebugEvent(string.Format("BREUtilities::checkDomainUserRoles: User Account {0} found {1} times.", user, results.Count));
&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;return&lt;/span&gt; list;
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                }
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:#2b91af;"&gt;DirectoryEntry&lt;/span&gt; entry3 = &lt;span style="color:blue;"&gt;null&lt;/span&gt;;
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;try
&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                {
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                    entry3 = &lt;span style="color:blue;"&gt;new&lt;/span&gt;
			&lt;span style="color:#2b91af;"&gt;DirectoryEntry&lt;/span&gt;(results[0].Path.Replace(&lt;span style="color:#a31515;"&gt;"GC://"&lt;/span&gt;, &lt;span style="color:#a31515;"&gt;"LDAP://"&lt;/span&gt;));
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                    entry3.RefreshCache(&lt;span style="color:blue;"&gt;new&lt;/span&gt;
			&lt;span style="color:blue;"&gt;string&lt;/span&gt;[] { &lt;span style="color:#a31515;"&gt;"CN"&lt;/span&gt;, &lt;span style="color:#a31515;"&gt;"tokenGroups"&lt;/span&gt; });
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:#2b91af;"&gt;PropertyValueCollection&lt;/span&gt; c = entry3.Properties[&lt;span style="color:#a31515;"&gt;"tokenGroups"&lt;/span&gt;];
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:#2b91af;"&gt;ArrayList&lt;/span&gt; list2 = &lt;span style="color:blue;"&gt;new&lt;/span&gt;
			&lt;span style="color:#2b91af;"&gt;ArrayList&lt;/span&gt;(c.Count);
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                    list2.AddRange(c);
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;for&lt;/span&gt; (&lt;span style="color:blue;"&gt;int&lt;/span&gt; i = 0; i &amp;lt; list2.Count; i++)
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                    {
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;byte&lt;/span&gt;[] sid = (&lt;span style="color:blue;"&gt;byte&lt;/span&gt;[])list2[i];
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;string&lt;/span&gt; str5 = ConvertSidToStringSid(sid);
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:#2b91af;"&gt;DirectoryEntry&lt;/span&gt; entry4 = &lt;span style="color:blue;"&gt;new&lt;/span&gt;
			&lt;span style="color:#2b91af;"&gt;DirectoryEntry&lt;/span&gt;(&lt;span style="color:blue;"&gt;string&lt;/span&gt;.Format(&lt;span style="color:#a31515;"&gt;"LDAP://&amp;lt;SID={0}&amp;gt;"&lt;/span&gt;, str5));
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;try
&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                        {
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;string&lt;/span&gt; str7 = entry4.Properties[&lt;span style="color:#a31515;"&gt;"samAccountName"&lt;/span&gt;].Value.ToString();
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                            list.Add(str7);
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                        }
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;catch&lt;/span&gt; (&lt;span style="color:#2b91af;"&gt;Exception&lt;/span&gt; exception)
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                        {
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:#2b91af;"&gt;Console&lt;/span&gt;.WriteLine(&lt;span style="color:#a31515;"&gt;"Error: "&lt;/span&gt; + exception.Message);
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                        }
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;finally
&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                        {
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                            DisposeDirectoryObject(entry4);
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                        }
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                    }
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;return&lt;/span&gt; list;
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                }
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;catch&lt;/span&gt; (&lt;span style="color:#2b91af;"&gt;Exception&lt;/span&gt; exception2)
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                {
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:#2b91af;"&gt;Console&lt;/span&gt;.WriteLine(&lt;span style="color:#a31515;"&gt;"Error in BREUtilities::checkDomainUserRoles: "&lt;/span&gt; + exception2.Message);
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;return&lt;/span&gt; list;
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                }
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;finally
&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                {
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                    DisposeDirectoryObject(entry3);
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                }
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;            }
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;catch&lt;/span&gt; (&lt;span style="color:#2b91af;"&gt;Exception&lt;/span&gt; exception3)
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;            {
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:#2b91af;"&gt;Console&lt;/span&gt;.WriteLine(&lt;span style="color:#a31515;"&gt;"Error in BREUtilities::checkDomainUserRoles. "&lt;/span&gt; + exception3.Message);
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;            }
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;finally
&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;            {
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                DisposeDirectoryObject(searcher);
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                DisposeDirectoryObject(searchRoot);
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                DisposeDirectoryObject(entry);
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                DisposeDirectoryObject(results);
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;            }
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;return&lt;/span&gt; list;
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;        }
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;
 &lt;/p&gt;&lt;p&gt;
 &lt;/p&gt;&lt;p&gt;
 &lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;public&lt;/span&gt;
			&lt;span style="color:blue;"&gt;static&lt;/span&gt;
			&lt;span style="color:blue;"&gt;void&lt;/span&gt; DisposeDirectoryObject(&lt;span style="color:blue;"&gt;object&lt;/span&gt; obj)
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;        {
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;try
&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;            {
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;if&lt;/span&gt; (obj != &lt;span style="color:blue;"&gt;null&lt;/span&gt;)
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                {
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;if&lt;/span&gt; (obj &lt;span style="color:blue;"&gt;is&lt;/span&gt;
			&lt;span style="color:#2b91af;"&gt;DirectorySearcher&lt;/span&gt;)
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                    {
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                        ((&lt;span style="color:#2b91af;"&gt;DirectorySearcher&lt;/span&gt;)obj).Dispose();
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                    }
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;else&lt;/span&gt;
			&lt;span style="color:blue;"&gt;if&lt;/span&gt; (obj &lt;span style="color:blue;"&gt;is&lt;/span&gt;
			&lt;span style="color:#2b91af;"&gt;DirectoryEntry&lt;/span&gt;)
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                    {
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                        ((&lt;span style="color:#2b91af;"&gt;DirectoryEntry&lt;/span&gt;)obj).Dispose();
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                    }
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;else&lt;/span&gt;
			&lt;span style="color:blue;"&gt;if&lt;/span&gt; (obj &lt;span style="color:blue;"&gt;is&lt;/span&gt;
			&lt;span style="color:#2b91af;"&gt;SearchResultCollection&lt;/span&gt;)
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                    {
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                        ((&lt;span style="color:#2b91af;"&gt;SearchResultCollection&lt;/span&gt;)obj).Dispose();
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                    }
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                }
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;            }
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;catch&lt;/span&gt; (&lt;span style="color:#2b91af;"&gt;Exception&lt;/span&gt; exception)
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;            {
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:green;"&gt;//ZeroTouchServiceUtil.LogErrorEvent(string.Format("Exception in BREUtilities:DisposeDirectoryObjects. Error: {0}", exception.ToString()));
&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;            }
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;        }
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;
 &lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;private&lt;/span&gt;
			&lt;span style="color:blue;"&gt;static&lt;/span&gt;
			&lt;span style="color:blue;"&gt;string&lt;/span&gt; ConvertSidToStringSid(&lt;span style="color:blue;"&gt;byte&lt;/span&gt;[] sid)
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;        {
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:#2b91af;"&gt;IntPtr&lt;/span&gt; destination = &lt;span style="color:blue;"&gt;new&lt;/span&gt;
			&lt;span style="color:#2b91af;"&gt;IntPtr&lt;/span&gt;();
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:#2b91af;"&gt;IntPtr&lt;/span&gt; pSidString = &lt;span style="color:blue;"&gt;new&lt;/span&gt;
			&lt;span style="color:#2b91af;"&gt;IntPtr&lt;/span&gt;();
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;            destination = &lt;span style="color:#2b91af;"&gt;Marshal&lt;/span&gt;.AllocHGlobal(sid.Length);
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:#2b91af;"&gt;Marshal&lt;/span&gt;.Copy(sid, 0, destination, sid.Length);
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;            ConvertSidToStringSid(destination, &lt;span style="color:blue;"&gt;ref&lt;/span&gt; pSidString);
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;string&lt;/span&gt; str = &lt;span style="color:#2b91af;"&gt;Marshal&lt;/span&gt;.PtrToStringAuto(pSidString);
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:#2b91af;"&gt;Marshal&lt;/span&gt;.FreeHGlobal(destination);
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:#2b91af;"&gt;Marshal&lt;/span&gt;.FreeHGlobal(pSidString);
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;return&lt;/span&gt; str;
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;        }
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;
 &lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;private&lt;/span&gt;
			&lt;span style="color:blue;"&gt;static&lt;/span&gt;
			&lt;span style="color:blue;"&gt;string&lt;/span&gt; ConvertToOctetString(&lt;span style="color:blue;"&gt;byte&lt;/span&gt;[] val)
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;        {
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:#2b91af;"&gt;StringBuilder&lt;/span&gt; builder = &lt;span style="color:blue;"&gt;new&lt;/span&gt;
			&lt;span style="color:#2b91af;"&gt;StringBuilder&lt;/span&gt;((val.GetUpperBound(0) + 1) * 2);
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;for&lt;/span&gt; (&lt;span style="color:blue;"&gt;int&lt;/span&gt; i = 0; i &amp;lt; val.GetUpperBound(0); i++)
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;            {
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;                builder.Append(val[i].ToString(&lt;span style="color:#a31515;"&gt;"x2"&lt;/span&gt;));
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;            }
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;return&lt;/span&gt; builder.ToString();
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;        }
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;
 &lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;        [&lt;span style="color:#2b91af;"&gt;DllImport&lt;/span&gt;(&lt;span style="color:#a31515;"&gt;"advapi32.dll"&lt;/span&gt;, CharSet = &lt;span style="color:#2b91af;"&gt;CharSet&lt;/span&gt;.Auto, SetLastError = &lt;span style="color:blue;"&gt;true&lt;/span&gt;)]
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;private&lt;/span&gt;
			&lt;span style="color:blue;"&gt;static&lt;/span&gt;
			&lt;span style="color:blue;"&gt;extern&lt;/span&gt;
			&lt;span style="color:blue;"&gt;int&lt;/span&gt; ConvertSidToStringSid(&lt;span style="color:#2b91af;"&gt;IntPtr&lt;/span&gt; pSID, &lt;span style="color:blue;"&gt;ref&lt;/span&gt;
			&lt;span style="color:#2b91af;"&gt;IntPtr&lt;/span&gt; pSidString);
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;        [&lt;span style="color:#2b91af;"&gt;DllImport&lt;/span&gt;(&lt;span style="color:#a31515;"&gt;"advapi32.dll"&lt;/span&gt;, CharSet = &lt;span style="color:#2b91af;"&gt;CharSet&lt;/span&gt;.Auto)]
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;private&lt;/span&gt;
			&lt;span style="color:blue;"&gt;static&lt;/span&gt;
			&lt;span style="color:blue;"&gt;extern&lt;/span&gt;
			&lt;span style="color:blue;"&gt;bool&lt;/span&gt; ConvertSidToStringSid(&lt;span style="color:#2b91af;"&gt;IntPtr&lt;/span&gt; pSID, [&lt;span style="color:#2b91af;"&gt;In&lt;/span&gt;, &lt;span style="color:#2b91af;"&gt;Out&lt;/span&gt;, &lt;span style="color:#2b91af;"&gt;MarshalAs&lt;/span&gt;(&lt;span style="color:#2b91af;"&gt;UnmanagedType&lt;/span&gt;.LPTStr)] &lt;span style="color:blue;"&gt;ref&lt;/span&gt;
			&lt;span style="color:blue;"&gt;string&lt;/span&gt; pStringSid);
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;
 &lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;        [&lt;span style="color:#2b91af;"&gt;DllImport&lt;/span&gt;(&lt;span style="color:#a31515;"&gt;"advapi32.dll"&lt;/span&gt;, CharSet = &lt;span style="color:#2b91af;"&gt;CharSet&lt;/span&gt;.Auto)]
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;
			&lt;span style="color:blue;"&gt;private&lt;/span&gt;
			&lt;span style="color:blue;"&gt;static&lt;/span&gt;
			&lt;span style="color:blue;"&gt;extern&lt;/span&gt;
			&lt;span style="color:blue;"&gt;bool&lt;/span&gt; ConvertStringSidToSid(&lt;span style="color:blue;"&gt;string&lt;/span&gt; pStringSid, &lt;span style="color:blue;"&gt;ref&lt;/span&gt;
			&lt;span style="color:#2b91af;"&gt;IntPtr&lt;/span&gt; pSID);
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;
 &lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New;font-size:10pt;"&gt;    }&lt;/span&gt;&lt;/p&gt;&lt;img src="http://blogs.chrisse.se/aggbug.aspx?PostID=53" width="1" height="1"&gt;</content><author><name>Christoffer Andersson</name><uri>http://blogs.chrisse.se/members/Christoffer+Andersson.aspx</uri></author></entry><entry><title>Fine Grain Password Policy Tool 1.0 (2300.0) RTM</title><link rel="alternate" type="text/html" href="http://blogs.chrisse.se/blogs/chrisse/archive/2009/01/11/fine-grain-password-policy-tool-1-0-2300-0-rtm.aspx" /><id>http://blogs.chrisse.se/blogs/chrisse/archive/2009/01/11/fine-grain-password-policy-tool-1-0-2300-0-rtm.aspx</id><published>2009-01-11T14:32:00Z</published><updated>2009-01-11T14:32:00Z</updated><content type="html">&lt;P style="MARGIN:0cm 0cm 0pt;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="COLOR:black;mso-ansi-language:EN-US;"&gt;&lt;FONT size=3 face=Calibri&gt;Build:&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="COLOR:black;mso-ansi-language:EN-US;"&gt;&lt;FONT size=3 face=Calibri&gt; FGPP RTM_2300-20081223.0&lt;BR&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Branch&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;: FGPP-RTM-branch.&lt;BR&gt;&lt;B&gt;Usage&lt;/B&gt;: Production Usage. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:12pt;mso-ansi-language:EN-US;"&gt;&lt;BR&gt;General Information&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;This build is the final RTM build of the Fine Grain Password Policy Tool. (&lt;/SPAN&gt;&lt;SPAN style="COLOR:black;mso-ansi-language:EN-US;"&gt;&lt;FONT size=3 face=Calibri&gt;FGPP RTM_2300-20081223.0)&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt; For full release notes see the document “Release notes for Fine Grain Password Policy Tool” included in the package, as well to be released on the website later today, other documentation available with this release are.&lt;BR&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:-18pt;MARGIN:0cm 0cm 0pt 36pt;mso-list:l0 level1 lfo1;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY:Symbol;COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;mso-bidi-font-family:Symbol;mso-fareast-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Quick Start Guide for Fine Grain Password Policy Tool&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:-18pt;MARGIN:0cm 0cm 0pt 36pt;mso-list:l0 level1 lfo1;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY:Symbol;COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;mso-bidi-font-family:Symbol;mso-fareast-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Windows PowerShell Usage for Fine Grain Password Policy Tool&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:-18pt;MARGIN:0cm 0cm 0pt 36pt;mso-list:l0 level1 lfo1;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY:Symbol;COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;mso-bidi-font-family:Symbol;mso-fareast-font-family:Symbol;"&gt;&lt;SPAN style="mso-list:Ignore;"&gt;·&lt;SPAN style="FONT:7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Password Policy Samples for Fine Grain Password Policy Tool&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:12pt;mso-ansi-language:EN-US;"&gt;&lt;BR&gt;Acknowledgements&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;BR&gt;&lt;B&gt;&lt;BR&gt;Stanimir Stoyanov,&lt;/B&gt; thanks&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';FONT-SIZE:10pt;mso-ansi-language:EN;"&gt; for providing the incredible support and your ideas while this piece of software was being written. Especially for the work that was done with the Native Methods. Please have a look at this blog for other projects he has been released &lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;A href="http://www.stoyanoff.info/"&gt;&lt;FONT color=#0000ff&gt;http://www.stoyanoff.info&lt;/FONT&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;BR&gt;Björn Österman, t&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';FONT-SIZE:10pt;mso-ansi-language:EN;"&gt;hanks for your help and support with the initial design of the Password Policy class.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';FONT-SIZE:10pt;mso-ansi-language:EN;"&gt;&lt;BR&gt;TrueSec Team&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';FONT-SIZE:10pt;mso-ansi-language:EN;"&gt;, thanks for providing support while this piece of software was being written.&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;BR&gt;&lt;BR&gt;Overview of Fine Grain Password Policies in Windows Server 2008:&lt;BR&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;"&gt;&lt;A target=_blank href="https://mail.truesec.com/exchweb/bin/redir.asp?URL=http://technet2.microsoft.com/windowsserver2008/en/library/056a73ef-5c9e-44d7-acc1-4f0bade6cd751033.mspx"&gt;&lt;SPAN style="mso-ansi-language:EN-US;"&gt;&lt;FONT color=#0000ff&gt;http://technet2.microsoft.com/windowsserver2008/en/library/056a73ef-5c9e-44d7-acc1-4f0bade6cd751033.mspx&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;BR&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:12pt;mso-ansi-language:EN-US;"&gt;Download&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;BR&gt;&lt;BR&gt;Download Fine Grain Password Policy Tool (x86) 1.0.&lt;BR&gt;&lt;A href="http://blogs.chrisse.se/files/folders/fgpp/entry51.aspx"&gt;http://blogs.chrisse.se/files/folders/fgpp/entry51.aspx&lt;/A&gt;&lt;BR&gt;&lt;BR&gt;Download Fine Grain Password Policy Tool (x64) 1.0.&lt;BR&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;A href="http://blogs.chrisse.se/files/folders/fgpp/entry50.aspx"&gt;&lt;FONT color=#0000ff&gt;http://blogs.chrisse.se/files/folders/fgpp/entry50.aspx&lt;/FONT&gt;&lt;/A&gt;&lt;B&gt;&lt;SPAN style="COLOR:black;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Quick Start Guide&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:#1f497d;FONT-SIZE:10pt;mso-ansi-language:EN-US;mso-themecolor:dark2;"&gt;.&lt;BR&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;"&gt;&lt;A target=_blank href="https://mail.truesec.com/exchweb/bin/redir.asp?URL=http://blogs.chrisse.se/blogs/chrisse/pages/fine-grain-password-policy-tool.aspx"&gt;&lt;FONT color=#0000ff&gt;http://blogs.chrisse.se/blogs/chrisse/pages/fine-grain-password-policy-tool.aspx&lt;/FONT&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:6pt 0cm 0pt;" class=punktlistats&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;System Requirements&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:6pt 0cm 0pt;" class=brdtextts&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Fine Grain Password Policy Tool 1.0 are “Supported” on the following platforms&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:-18pt;MARGIN:6pt 0cm 0pt 36pt;" class=brdtextts&gt;&lt;SPAN style="FONT-FAMILY:Symbol;COLOR:black;FONT-SIZE:10pt;"&gt;·&lt;/SPAN&gt;&lt;SPAN style="COLOR:black;FONT-SIZE:7pt;mso-ansi-language:EN-US;"&gt;&lt;FONT face="Times New Roman"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Windows Server 2008&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:-18pt;MARGIN:6pt 0cm 0pt 36pt;" class=brdtextts&gt;&lt;SPAN style="FONT-FAMILY:Symbol;COLOR:black;FONT-SIZE:10pt;"&gt;·&lt;/SPAN&gt;&lt;SPAN style="COLOR:black;FONT-SIZE:7pt;mso-ansi-language:EN-US;"&gt;&lt;FONT face="Times New Roman"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Windows Server 2008 R2 Beta 1 (Build 7000) or later&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:-18pt;MARGIN:6pt 0cm 0pt 36pt;" class=brdtextts&gt;&lt;SPAN style="FONT-FAMILY:Symbol;COLOR:black;FONT-SIZE:10pt;"&gt;·&lt;/SPAN&gt;&lt;SPAN style="COLOR:black;FONT-SIZE:7pt;mso-ansi-language:EN-US;"&gt;&lt;FONT face="Times New Roman"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Windows Vista, Windows Vista with Service Pack 1 or later&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:-18pt;MARGIN:6pt 0cm 0pt 36pt;" class=brdtextts&gt;&lt;SPAN style="FONT-FAMILY:Symbol;COLOR:black;FONT-SIZE:10pt;"&gt;·&lt;/SPAN&gt;&lt;SPAN style="COLOR:black;FONT-SIZE:7pt;mso-ansi-language:EN-US;"&gt;&lt;FONT face="Times New Roman"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Windows 7 Beta (Build 700&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:#1f497d;FONT-SIZE:10pt;mso-ansi-language:EN-US;mso-themecolor:dark2;"&gt;0&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;) or later &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:-18pt;MARGIN:6pt 0cm 0pt 36pt;" class=brdtextts&gt;&lt;SPAN style="FONT-FAMILY:Symbol;COLOR:black;FONT-SIZE:10pt;"&gt;·&lt;/SPAN&gt;&lt;SPAN style="COLOR:black;FONT-SIZE:7pt;mso-ansi-language:EN-US;"&gt;&lt;FONT face="Times New Roman"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Windows Server 2003 with Service Pack 1 or later and Windows Server 2003 R2&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:-18pt;MARGIN:6pt 0cm 0pt 36pt;" class=brdtextts&gt;&lt;SPAN style="FONT-FAMILY:Symbol;COLOR:black;FONT-SIZE:10pt;"&gt;·&lt;/SPAN&gt;&lt;SPAN style="COLOR:black;FONT-SIZE:7pt;mso-ansi-language:EN-US;"&gt;&lt;FONT face="Times New Roman"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Windows XP Service Pack 2 or later&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:6pt 0cm 0pt;" class=punktlistats&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:6pt 0cm;" class=rubrik4ts&gt;&lt;STRONG&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Prerequisites&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:6pt 0cm 0pt;" class=brdtextts&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Before installing this build, you must have:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:6pt 0cm 0pt 17.85pt;" class=brdtextts&gt;&lt;U&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Windows Server 2008, Windows Server 2008 R2 and Windows Vista, Windows 7&lt;/SPAN&gt;&lt;/U&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:6pt 0cm 0pt 17.85pt;" class=punktlistats&gt;&lt;SPAN style="FONT-FAMILY:Symbol;COLOR:black;FONT-SIZE:10pt;"&gt;·&lt;/SPAN&gt;&lt;SPAN style="COLOR:black;FONT-SIZE:7pt;mso-ansi-language:EN-US;"&gt;&lt;FONT face="Times New Roman"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Windows Server 2008 Active Directory Domain.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:6pt 0cm 0pt 17.85pt;" class=punktlistats&gt;&lt;SPAN style="FONT-FAMILY:Symbol;COLOR:black;FONT-SIZE:10pt;"&gt;·&lt;/SPAN&gt;&lt;SPAN style="COLOR:black;FONT-SIZE:7pt;mso-ansi-language:EN-US;"&gt;&lt;FONT face="Times New Roman"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Windows PowerShell installed (for command-line and scripting support)&lt;BR&gt;&lt;U&gt;Windows Server 2003 and Windows XP&lt;/U&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:6pt 0cm 0pt 17.85pt;" class=punktlistats&gt;&lt;SPAN style="FONT-FAMILY:Symbol;COLOR:black;FONT-SIZE:10pt;"&gt;·&lt;/SPAN&gt;&lt;SPAN style="COLOR:black;FONT-SIZE:7pt;mso-ansi-language:EN-US;"&gt;&lt;FONT face="Times New Roman"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Microsoft .NET Framework 2.0.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:6pt 0cm 0pt 17.85pt;" class=punktlistats&gt;&lt;SPAN style="FONT-FAMILY:Symbol;COLOR:black;FONT-SIZE:10pt;"&gt;·&lt;/SPAN&gt;&lt;SPAN style="COLOR:black;FONT-SIZE:7pt;mso-ansi-language:EN-US;"&gt;&lt;FONT face="Times New Roman"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Microsoft Management Console 3.0 &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:6pt 0cm 0pt 17.85pt;" class=punktlistats&gt;&lt;SPAN style="FONT-FAMILY:Symbol;COLOR:black;FONT-SIZE:10pt;"&gt;·&lt;/SPAN&gt;&lt;SPAN style="COLOR:black;FONT-SIZE:7pt;mso-ansi-language:EN-US;"&gt;&lt;FONT face="Times New Roman"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Windows Server 2008 Active Directory Domain.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:6pt 0cm 0pt 17.85pt;" class=punktlistats&gt;&lt;SPAN style="FONT-FAMILY:Symbol;COLOR:black;FONT-SIZE:10pt;"&gt;·&lt;/SPAN&gt;&lt;SPAN style="COLOR:black;FONT-SIZE:7pt;mso-ansi-language:EN-US;"&gt;&lt;FONT face="Times New Roman"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Windows PowerShell installed (for command-line and scripting support)&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:6pt 0cm 0pt;" class=punktlistats&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;mso-ansi-language:EN-US;"&gt;&lt;BR&gt;&lt;FONT size=3&gt;Usage information&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;mso-ansi-language:EN-US;"&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:6pt 0cm 0pt;" class=punktlistats&gt;&lt;STRONG&gt;&lt;SPAN style="FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="MARGIN:6pt 0cm 0pt;" class=punktlistats&gt;&lt;STRONG&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Fine Grain Password Policy Tool Core PowerShell Samples.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="mso-ansi-language:EN-US;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;FGPP RC0 Milestone (Build 2270-2292) supports the following PowerShell Commands.&lt;BR&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;I&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN;"&gt;Create new Password Policies&lt;/SPAN&gt;&lt;/I&gt;&lt;/STRONG&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;New-PasswordPolicy &amp;lt;Name&amp;gt; [-domain &amp;lt;FQDNDomainName&amp;gt;] &amp;gt;] [–server &amp;lt;DCFQDN&amp;gt;] -MaximumPasswordAge &amp;lt;timespan&amp;gt; -MinimumPasswordAge &amp;lt;timespan&amp;gt; -MinimumPasswordLength &amp;lt;PassswordMinLenght&amp;gt; -PasswordComplexityEnabled &amp;lt;$True/$False&amp;gt; -PasswordReversibleEncryptionEnabled &amp;lt;$True/$False&amp;gt; -PasswordSettingsPrecendence &amp;lt;PrecendenceOrder&amp;gt; -PasswordHistoryLength &amp;lt;NumberOfPasswords&amp;gt; -LockoutDuration &amp;lt;timespan&amp;gt; -LockoutObservationWindow &amp;lt;timespan&amp;gt; -LockoutThreshold &amp;lt;int&amp;gt; -AppliesTo *SupportedNameFormats&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;B&gt;&lt;I&gt;&lt;U&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN;"&gt;&lt;BR&gt;&lt;EM&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';"&gt;Modify existing&amp;nbsp;Password Policies&lt;/SPAN&gt;&lt;/EM&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/I&gt;&lt;/B&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Modify-PasswordPolicy &amp;lt;name&amp;gt; [-domain &amp;lt;FQDNDomainName&amp;gt;] &amp;gt;] [–server &amp;lt;DCFQDN&amp;gt;] [-MaximumPasswordAge &amp;lt;timespan&amp;gt;] [-MinimumPasswordAge &amp;lt;timespan&amp;gt;] [-MinimumPasswordLength &amp;lt;PassswordMinLenght&amp;gt;] [-PasswordComplexityEnabled &amp;lt;$True/$False&amp;gt;] [-PasswordReversibleEncryptionEnabled &amp;lt;$True/$False&amp;gt;] [-PasswordSettingsPrecendence &amp;lt;PrecendenceOrder&amp;gt;] [-PasswordHistoryLength &amp;lt;NumberOfPasswords&amp;gt;] [-LockoutDuration &amp;lt;timespan&amp;gt;] [-LockoutObservationWindow &amp;lt;timespan&amp;gt;] [-LockoutThreshold &amp;lt;int&amp;gt;] -AppliesToAdd *SupportedNameFormats -AppliesToRemove *SupportedNameFormats&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 12pt;" class=MsoNormal&gt;&lt;B&gt;&lt;I&gt;&lt;U&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN;"&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/I&gt;&lt;/B&gt;&lt;STRONG&gt;&lt;I&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN;"&gt;Delete Password Policies&lt;/SPAN&gt;&lt;/I&gt;&lt;/STRONG&gt;&lt;B&gt;&lt;I&gt;&lt;U&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN;"&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/I&gt;&lt;/B&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Delete-PasswordPolicy &amp;lt;name&amp;gt; [-domain &amp;lt;FQDNDomainName&amp;gt;] [–server &amp;lt;DCFQDN&amp;gt;] [-all]&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;EM&gt;&lt;B&gt;&lt;U&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN;"&gt;Reame Password Policies&lt;/SPAN&gt;&lt;/U&gt;&lt;/B&gt;&lt;/EM&gt;&lt;B&gt;&lt;I&gt;&lt;U&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN;"&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/I&gt;&lt;/B&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Rename-PasswordPolicy &amp;lt;name&amp;gt; [-domain &amp;lt;FQDNDomainName&amp;gt;] -NewName &amp;lt;name&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;B&gt;&lt;I&gt;&lt;U&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN;"&gt;&lt;BR&gt;&lt;EM&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';"&gt;Add users and global groups to an existing Password Policy&lt;/SPAN&gt;&lt;/EM&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/I&gt;&lt;/B&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Add-PasswordPolicy -Name &amp;lt;name&amp;gt; [-domain &amp;lt;FQDNDomainName&amp;gt;] [–server &amp;lt;DCFQDN&amp;gt;] -AppliesTo *SupportedNameFormats&lt;BR&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;EM&gt;&lt;B&gt;&lt;U&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN;"&gt;Remove users and global groups to an existing Password Policy&lt;/SPAN&gt;&lt;/U&gt;&lt;/B&gt;&lt;/EM&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 12pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Remove-PasswordPolicy -Name &amp;lt;name&amp;gt; [-domain &amp;lt;FQDNDomainName&amp;gt;] [–server &amp;lt;DCFQDN&amp;gt;] -AppliesTo *SupportedNameFormats [-all]&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;EM&gt;&lt;B&gt;&lt;U&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN;"&gt;Get the Effective PasswordPolicy for one or more users objects&lt;/SPAN&gt;&lt;/U&gt;&lt;/B&gt;&lt;/EM&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Get-PasswordPolicyEffective &amp;lt;name&amp;gt; [-domain &amp;lt;FQDNDomainName&amp;gt;] [–server &amp;lt;DCFQDN&amp;gt;]&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;B&gt;&lt;I&gt;&lt;U&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Export Password Policies&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/I&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Export-PasswordPolicy &amp;lt;name&amp;gt; &amp;lt;path&amp;gt; [-domain &amp;lt;FQDNDomainName&amp;gt;] [–server &amp;lt;DCFQDN&amp;gt;]&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;B&gt;&lt;I&gt;&lt;U&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Import Password Policies&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/I&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Import-PasswordPolicy &amp;lt;name&amp;gt; &amp;lt;path&amp;gt; [-domain &amp;lt;FQDNDomainName&amp;gt;] [–server &amp;lt;DCFQDN&amp;gt;]&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;STRONG&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;--------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="mso-ansi-language:EN-US;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;STRONG&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;*SupportedNameFormats: &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;[Domain\UserN, "First LastName", {4fa050f0-f561-11cf-bdd9-00aa003a77b6}, example.microsoft.com/software/user name, &lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;"&gt;&lt;A target=_blank href="mailto:usern@example.microsoft.com"&gt;&lt;SPAN style="mso-ansi-language:EN-US;"&gt;&lt;FONT color=#0000ff&gt;usern@example.microsoft.com&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;, S-1-5-21-397955417-626881126-188441444-501]&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:6pt 0cm 0pt;" class=punktlistats&gt;&lt;SPAN style="mso-ansi-language:EN-US;"&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Fine Grain Password Policy Tool Additional PowerShell Samples.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;STRONG&gt;&lt;SPAN style="mso-ansi-language:EN-US;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="MARGIN:6pt 0cm 0pt;" class=punktlistats&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;.&lt;/SPAN&gt;&lt;SPAN style="mso-ansi-language:EN-US;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;STRONG&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;--------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="mso-ansi-language:EN-US;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;B&gt;&lt;I&gt;&lt;U&gt;&lt;SPAN style="mso-ansi-language:EN-US;"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;How to use the Get-PasswordPolicy and New-PasswordPolicy to copy an existing PasswordPolicy&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/I&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Note:&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt; Any parameter can be used with New-PasswordPolicy override settings from the existing policy.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;SPAN style="mso-ansi-language:EN-US;"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Get-PasswordPolicy &amp;lt;name&amp;gt; [-domain &amp;lt;FQDNDomainName&amp;gt;] &lt;B&gt;|&lt;/B&gt; New-PasswordPolicy &amp;lt;Name&amp;gt; [-domain &amp;lt;FQDNDomainName&amp;gt;] [-MaximumPasswordAge &amp;lt;timespan&amp;gt;] [-MinimumPasswordAge &amp;lt;timespan&amp;gt;] [-MinimumPasswordLength &amp;lt;PassswordMinLenght&amp;gt;] [-PasswordComplexityEnabled &amp;lt;$True/$False&amp;gt;] [-PasswordReversibleEncryptionEnabled &amp;lt;$True/$False&amp;gt;] [-PasswordSettingsPrecendence &amp;lt;PrecendenceOrder&amp;gt;] [-PasswordHistoryLength &amp;lt;NumberOfPasswords&amp;gt;] [-LockoutDuration &amp;lt;timespan&amp;gt;] [-LockoutObservationWindow &amp;lt;timespan&amp;gt;] [-LockoutThreshold &amp;lt;int&amp;gt; -AppliesTo * SupportedNameFormats]&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;STRONG&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;--------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="mso-ansi-language:EN-US;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;B&gt;&lt;I&gt;&lt;U&gt;&lt;SPAN style="mso-ansi-language:EN-US;"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;How to check policy compliance for linked users for a one or more Password Policies&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/I&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;SPAN style="mso-ansi-language:EN-US;"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;foreach ($Policy in Get-PasswordPolicy [&amp;lt;Name&amp;gt;]) { foreach ($Applied in $Policy.AppliesTo) { Get-PasswordPo&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;SPAN style="mso-ansi-language:EN-US;"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;licyEffective $Applied } }&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.chrisse.se/aggbug.aspx?PostID=52" width="1" height="1"&gt;</content><author><name>Christoffer Andersson</name><uri>http://blogs.chrisse.se/members/Christoffer+Andersson.aspx</uri></author><category term="Fine Grain Password Policy Tool" scheme="http://blogs.chrisse.se/blogs/chrisse/archive/tags/Fine+Grain+Password+Policy+Tool/default.aspx" /><category term="Active Directory" scheme="http://blogs.chrisse.se/blogs/chrisse/archive/tags/Active+Directory/default.aspx" /></entry><entry><title>Windows 7 and Windows Server 2008 R2</title><link rel="alternate" type="text/html" href="http://blogs.chrisse.se/blogs/chrisse/archive/2008/10/28/windows-7-and-windows-server-2008-r2.aspx" /><id>http://blogs.chrisse.se/blogs/chrisse/archive/2008/10/28/windows-7-and-windows-server-2008-r2.aspx</id><published>2008-10-28T08:27:00Z</published><updated>2008-10-28T08:27:00Z</updated><content type="html">&lt;P style="MARGIN:0cm 0cm 10pt;" class=MsoNormal&gt;&lt;SPAN style="mso-ansi-language:EN-US;"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&lt;SPAN style="mso-ansi-language:EN-US;"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;IMG style="WIDTH:250px;HEIGHT:231px;" src="http://www.aeroxp.org/wp-content/uploads/2008/10/windows7.jpg" width=250 height=231&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 10pt;" class=MsoNormal&gt;&lt;SPAN style="mso-ansi-language:EN-US;"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;In an earlier blog post I did promise you to talk a little bit about what's next, I did then already reveled that I did start playing with what's going to be next (Post-Windows Vista and Windows Server 2008). So I did start to play with "what's next" in November last year, and in fact - Yes Windows Server 2008 wasn't even RTM at that time. Now one year later, me and my team at TrueSec has been working very close around this release with Microsoft and is a part of the Windows 7 and Windows Server 2008 R2 Technology Adoption Program (TAP). So what does this mean? Well it's been a lot of sleepless nights of testing and verification that has been going on, around 35% of my Domain Controllers are already running on Pre-Beta/Alpha code for the Windows Server 2008 R2 release. There is a lot of interesting and cool features in this release, which I can't talk about in detail yet. I know there will be a lot of sessions on the topics that are new in this release in PDC2008 that did start yesterday, I except today’s keynote to have its focus on Windows 7 and Windows Server 2008 R2, also next week I’m attending TechEd Europe 2008 in Barcelona and I will be working as ATE (Ask the Experts) there. If you attend please come by the Active Directory (Identity and Access) both and say hello. I know there is going to be event’s that will talk about new features in the next release "Windows Server 2008 R2" that's related to Active Directory. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 10pt;" class=MsoNormal&gt;&lt;SPAN style="mso-ansi-language:EN-US;"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;So what can I mention about this release so far? It’s actually surprising fast and stable and most features planned for this release is already in, and works as you can except them to work at this stage, I'm looking forward to see how the world will adopt this release.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.chrisse.se/aggbug.aspx?PostID=49" width="1" height="1"&gt;</content><author><name>Christoffer Andersson</name><uri>http://blogs.chrisse.se/members/Christoffer+Andersson.aspx</uri></author></entry><entry><title>Fine Grain Password Policy Tool RC0 is ready!</title><link rel="alternate" type="text/html" href="http://blogs.chrisse.se/blogs/chrisse/archive/2008/10/07/fine-grain-password-policy-tool-rc0-is-ready.aspx" /><id>http://blogs.chrisse.se/blogs/chrisse/archive/2008/10/07/fine-grain-password-policy-tool-rc0-is-ready.aspx</id><published>2008-10-06T14:25:00Z</published><updated>2008-10-06T14:25:00Z</updated><content type="html">&lt;P style="MARGIN:0cm 0cm 0pt;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:12pt;mso-ansi-language:EN-US;"&gt;General Information&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;This build is very close to RTM quality and is “feature complete” we&amp;nbsp;have&amp;nbsp;resolved many bugs and issues in this&amp;nbsp;release,&amp;nbsp;please report any issues or bugs. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;BR&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt; The PasswordPolicy Cmd'let now has built-in help for all available commannds. I.e: get-help New-PasswordPolicy -full&lt;BR&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;As usual&amp;nbsp;many thanks to Stanimir Stoyanov for helping me solving some issues in this release. (&lt;A href="http://www.stoyanoff.info/"&gt;http://www.stoyanoff.info&lt;/A&gt;)&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';FONT-SIZE:10pt;mso-fareast-font-family:Calibri;mso-fareast-theme-font:minor-latin;mso-ansi-language:EN-US;mso-fareast-language:SV;mso-bidi-language:AR-SA;"&gt;&lt;SPAN style="COLOR:black;"&gt;&lt;BR&gt;&lt;BR&gt;Overview of Fine Grain Password Policies in Windows Server 2008:&lt;BR&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-fareast-font-family:Calibri;mso-fareast-theme-font:minor-latin;mso-ansi-language:SV;mso-fareast-language:SV;mso-bidi-language:AR-SA;"&gt;&lt;A target=_blank href="http://technet2.microsoft.com/windowsserver2008/en/library/056a73ef-5c9e-44d7-acc1-4f0bade6cd751033.mspx"&gt;&lt;SPAN style="mso-ansi-language:EN-US;"&gt;&lt;FONT color=#0000ff&gt;http://technet2.microsoft.com/windowsserver2008/en/library/056a73ef-5c9e-44d7-acc1-4f0bade6cd751033.mspx&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-fareast-font-family:Calibri;mso-fareast-theme-font:minor-latin;mso-ansi-language:SV;mso-fareast-language:SV;mso-bidi-language:AR-SA;"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-fareast-font-family:Calibri;mso-fareast-theme-font:minor-latin;mso-ansi-language:SV;mso-fareast-language:SV;mso-bidi-language:AR-SA;"&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:12pt;mso-ansi-language:EN-US;"&gt;Download&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;BR&gt;Download Fine Grain Password Policy Tool (x86) RC0.&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;BR&gt;&lt;A href="http://blogs.chrisse.se/files/folders/fgpp/entry45.aspx"&gt;http://blogs.chrisse.se/files/folders/fgpp/entry45.aspx&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 12pt;mso-margin-top-alt:auto;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Download Fine Grain Password Policy Tool (x64) RC0.&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;A href="http://blogs.chrisse.se/files/folders/fgpp/entry44.aspx"&gt;http://blogs.chrisse.se/files/folders/fgpp/entry44.aspx&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Fine Grain Password Policy Tool Quick Start Guide &lt;BR&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;"&gt;&lt;A target=_blank href="http://blogs.chrisse.se/blogs/chrisse/pages/fine-grain-password-policy-tool.aspx"&gt;&lt;FONT color=#0000ff&gt;http://blogs.chrisse.se/blogs/chrisse/pages/fine-grain-password-policy-tool.aspx&lt;/FONT&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:6pt 0cm 0pt;" class=punktlistats&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;System Requirements&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:6pt 0cm 0pt;" class=brdtextts&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Fine Grain Password Policy Tool (FGPP) RC0 are “Supported” on the following platforms&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:-18pt;MARGIN:6pt 0cm 0pt 36pt;" class=brdtextts&gt;&lt;SPAN style="FONT-FAMILY:Symbol;COLOR:black;FONT-SIZE:10pt;"&gt;·&lt;/SPAN&gt;&lt;SPAN style="COLOR:black;FONT-SIZE:7pt;mso-ansi-language:EN-US;"&gt;&lt;FONT face="Times New Roman"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Windows Server 2008&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:-18pt;MARGIN:6pt 0cm 0pt 36pt;" class=brdtextts&gt;&lt;SPAN style="FONT-FAMILY:Symbol;COLOR:black;FONT-SIZE:10pt;"&gt;·&lt;/SPAN&gt;&lt;SPAN style="COLOR:black;FONT-SIZE:7pt;mso-ansi-language:EN-US;"&gt;&lt;FONT face="Times New Roman"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Windows Vista and Windows Vista Service Pack 1 or later &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:-18pt;MARGIN:6pt 0cm 0pt 36pt;" class=brdtextts&gt;&lt;SPAN style="FONT-FAMILY:Symbol;COLOR:black;FONT-SIZE:10pt;"&gt;·&lt;/SPAN&gt;&lt;SPAN style="COLOR:black;FONT-SIZE:7pt;mso-ansi-language:EN-US;"&gt;&lt;FONT face="Times New Roman"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Windows Server 2003 Service Pack 1 or later&amp;nbsp;and Windows Server 2003 R2&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT:-18pt;MARGIN:6pt 0cm 0pt 36pt;" class=brdtextts&gt;&lt;SPAN style="FONT-FAMILY:Symbol;COLOR:black;FONT-SIZE:10pt;"&gt;·&lt;/SPAN&gt;&lt;SPAN style="COLOR:black;FONT-SIZE:7pt;mso-ansi-language:EN-US;"&gt;&lt;FONT face="Times New Roman"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Windows XP Service Pack 2 or later&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;" class=MsoNormal&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN:6pt 0cm;" class=rubrik4ts&gt;&lt;STRONG&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Prerequisites&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:6pt 0cm 0pt;" class=brdtextts&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Before installing this build, you must have:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:6pt 0cm 0pt 17.85pt;" class=brdtextts&gt;&lt;U&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Windows Server 2008 and Windows Vista&lt;/SPAN&gt;&lt;/U&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:6pt 0cm 0pt 17.85pt;" class=punktlistats&gt;&lt;SPAN style="FONT-FAMILY:Symbol;COLOR:black;FONT-SIZE:10pt;"&gt;·&lt;/SPAN&gt;&lt;SPAN style="COLOR:black;FONT-SIZE:7pt;mso-ansi-language:EN-US;"&gt;&lt;FONT face="Times New Roman"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Windows Server 2008 Active Directory Domain.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:6pt 0cm 0pt 17.85pt;" class=punktlistats&gt;&lt;SPAN style="FONT-FAMILY:Symbol;COLOR:black;FONT-SIZE:10pt;"&gt;·&lt;/SPAN&gt;&lt;SPAN style="COLOR:black;FONT-SIZE:7pt;mso-ansi-language:EN-US;"&gt;&lt;FONT face="Times New Roman"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Windows PowerShell installed (for command-line and scripting support)&lt;BR&gt;&lt;U&gt;Windows Server 2003 and Windows XP&lt;/U&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:6pt 0cm 0pt 17.85pt;" class=punktlistats&gt;&lt;SPAN style="FONT-FAMILY:Symbol;COLOR:black;FONT-SIZE:10pt;"&gt;·&lt;/SPAN&gt;&lt;SPAN style="COLOR:black;FONT-SIZE:7pt;mso-ansi-language:EN-US;"&gt;&lt;FONT face="Times New Roman"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Microsoft .NET Framework 2.0.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:6pt 0cm 0pt 17.85pt;" class=punktlistats&gt;&lt;SPAN style="FONT-FAMILY:Symbol;COLOR:black;FONT-SIZE:10pt;"&gt;·&lt;/SPAN&gt;&lt;SPAN style="COLOR:black;FONT-SIZE:7pt;mso-ansi-language:EN-US;"&gt;&lt;FONT face="Times New Roman"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Microsoft Management Console 3.0 &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:6pt 0cm 0pt 17.85pt;" class=punktlistats&gt;&lt;SPAN style="FONT-FAMILY:Symbol;COLOR:black;FONT-SIZE:10pt;"&gt;·&lt;/SPAN&gt;&lt;SPAN style="COLOR:black;FONT-SIZE:7pt;mso-ansi-language:EN-US;"&gt;&lt;FONT face="Times New Roman"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Windows Server 2008 Active Directory Domain.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:6pt 0cm 0pt 17.85pt;" class=punktlistats&gt;&lt;SPAN style="FONT-FAMILY:Symbol;COLOR:black;FONT-SIZE:10pt;"&gt;·&lt;/SPAN&gt;&lt;SPAN style="COLOR:black;FONT-SIZE:7pt;mso-ansi-language:EN-US;"&gt;&lt;FONT face="Times New Roman"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Windows PowerShell installed (for command-line and scripting support)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:6pt 0cm 0pt 17.85pt;" class=punktlistats&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;STRONG&gt;&lt;BR&gt;Fine Grain Password Policy Tool MCC - Password Policy Properties:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:6pt 0cm 0pt 17.85pt;" class=punktlistats&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;IMG style="WIDTH:350px;HEIGHT:537px;" src="http://www.chrisse.se/FGPP/FGPP-RC0_2281.1_UI_01.jpg" width=350 height=537&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:6pt 0cm 0pt;" class=punktlistats&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;mso-ansi-language:EN-US;"&gt;&lt;BR&gt;&lt;FONT size=3&gt;Usage information&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;mso-ansi-language:EN-US;"&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:6pt 0cm 0pt;" class=punktlistats&gt;&lt;STRONG&gt;&lt;SPAN style="FONT-SIZE:10pt;"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman"&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="MARGIN:6pt 0cm 0pt;" class=punktlistats&gt;&lt;STRONG&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Fine Grain Password Policy Tool Core PowerShell Samples.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;FGPP RC0 Milestone (Build 2270-2292) supports the following PowerShell Commands.&lt;BR&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;I&gt;&lt;U&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN;"&gt;Create new Password Policies&lt;/SPAN&gt;&lt;/U&gt;&lt;/I&gt;&lt;/STRONG&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;New-PasswordPolicy &amp;lt;Name&amp;gt; [-domain &amp;lt;FQDNDomainName&amp;gt;] &amp;gt;] [–server &amp;lt;DCFQDN&amp;gt;] -MaximumPasswordAge &amp;lt;timespan&amp;gt; -MinimumPasswordAge &amp;lt;timespan&amp;gt; -MinimumPasswordLength &amp;lt;PassswordMinLenght&amp;gt; -PasswordComplexityEnabled &amp;lt;$True/$False&amp;gt; -PasswordReversibleEncryptionEnabled &amp;lt;$True/$False&amp;gt; -PasswordSettingsPrecendence &amp;lt;PrecendenceOrder&amp;gt; -PasswordHistoryLength &amp;lt;NumberOfPasswords&amp;gt; -LockoutDuration &amp;lt;timespan&amp;gt; -LockoutObservationWindow &amp;lt;timespan&amp;gt; -LockoutThreshold &amp;lt;int&amp;gt; -AppliesTo *SupportedNameFormats&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;B&gt;&lt;I&gt;&lt;U&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN;"&gt;&lt;BR&gt;&lt;EM&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';"&gt;Modify existing&amp;nbsp;Password Policies&lt;/SPAN&gt;&lt;/EM&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/I&gt;&lt;/B&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Modify-PasswordPolicy &amp;lt;name&amp;gt; [-domain &amp;lt;FQDNDomainName&amp;gt;] &amp;gt;] [–server &amp;lt;DCFQDN&amp;gt;] [-MaximumPasswordAge &amp;lt;timespan&amp;gt;] [-MinimumPasswordAge &amp;lt;timespan&amp;gt;] [-MinimumPasswordLength &amp;lt;PassswordMinLenght&amp;gt;] [-PasswordComplexityEnabled &amp;lt;$True/$False&amp;gt;] [-PasswordReversibleEncryptionEnabled &amp;lt;$True/$False&amp;gt;] [-PasswordSettingsPrecendence &amp;lt;PrecendenceOrder&amp;gt;] [-PasswordHistoryLength &amp;lt;NumberOfPasswords&amp;gt;] [-LockoutDuration &amp;lt;timespan&amp;gt;] [-LockoutObservationWindow &amp;lt;timespan&amp;gt;] [-LockoutThreshold &amp;lt;int&amp;gt;] -AppliesToAdd *SupportedNameFormats -AppliesToRemove *SupportedNameFormats&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 12pt;" class=MsoNormal&gt;&lt;B&gt;&lt;I&gt;&lt;U&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN;"&gt;&lt;BR&gt;&lt;STRONG&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';"&gt;Delete Password Policies&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/I&gt;&lt;/B&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Delete-PasswordPolicy &amp;lt;name&amp;gt; [-domain &amp;lt;FQDNDomainName&amp;gt;] [–server &amp;lt;DCFQDN&amp;gt;] [-all]&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;EM&gt;&lt;B&gt;&lt;U&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN;"&gt;Reame Password Policies&lt;/SPAN&gt;&lt;/U&gt;&lt;/B&gt;&lt;/EM&gt;&lt;B&gt;&lt;I&gt;&lt;U&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN;"&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/I&gt;&lt;/B&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Rename-PasswordPolicy &amp;lt;name&amp;gt; [-domain &amp;lt;FQDNDomainName&amp;gt;] -NewName &amp;lt;name&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;B&gt;&lt;I&gt;&lt;U&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN;"&gt;&lt;BR&gt;&lt;EM&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';"&gt;Add users and global groups to an existing Password Policy&lt;/SPAN&gt;&lt;/EM&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/I&gt;&lt;/B&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Add-PasswordPolicy -Name &amp;lt;name&amp;gt; [-domain &amp;lt;FQDNDomainName&amp;gt;] [–server &amp;lt;DCFQDN&amp;gt;] -AppliesTo *SupportedNameFormats&lt;BR&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;EM&gt;&lt;B&gt;&lt;U&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN;"&gt;Remove users and global groups to an existing Password Policy&lt;/SPAN&gt;&lt;/U&gt;&lt;/B&gt;&lt;/EM&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 12pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Remove-PasswordPolicy -Name &amp;lt;name&amp;gt; [-domain &amp;lt;FQDNDomainName&amp;gt;] [–server &amp;lt;DCFQDN&amp;gt;] -AppliesTo *SupportedNameFormats [-all]&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;EM&gt;&lt;B&gt;&lt;U&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN;"&gt;Get the Effective PasswordPolicy for one or more users objects&lt;/SPAN&gt;&lt;/U&gt;&lt;/B&gt;&lt;/EM&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Get-PasswordPolicyEffective &amp;lt;name&amp;gt; [-domain &amp;lt;FQDNDomainName&amp;gt;] [–server &amp;lt;DCFQDN&amp;gt;]&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;B&gt;&lt;I&gt;&lt;U&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Export Password Policies&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/I&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Export-PasswordPolicy &amp;lt;name&amp;gt; &amp;lt;path&amp;gt; [-domain &amp;lt;FQDNDomainName&amp;gt;] [–server &amp;lt;DCFQDN&amp;gt;]&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;B&gt;&lt;I&gt;&lt;U&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Import Password Policies&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/I&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Import-PasswordPolicy &amp;lt;name&amp;gt; &amp;lt;path&amp;gt; [-domain &amp;lt;FQDNDomainName&amp;gt;] [–server &amp;lt;DCFQDN&amp;gt;]&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;STRONG&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;--------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="mso-ansi-language:EN-US;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;STRONG&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;*SupportedNameFormats: &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;[Domain\UserN, "First LastName", {4fa050f0-f561-11cf-bdd9-00aa003a77b6}, example.microsoft.com/software/user name, &lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;"&gt;&lt;A target=_blank href="mailto:usern@example.microsoft.com"&gt;&lt;SPAN style="mso-ansi-language:EN-US;"&gt;&lt;FONT color=#0000ff&gt;usern@example.microsoft.com&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;, S-1-5-21-397955417-626881126-188441444-501]&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:6pt 0cm 0pt;" class=punktlistats&gt;&lt;SPAN style="mso-ansi-language:EN-US;"&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Fine Grain Password Policy Tool Additional PowerShell Samples.&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="MARGIN:6pt 0cm 0pt;" class=punktlistats&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;B&gt;&lt;I&gt;&lt;U&gt;&lt;SPAN style="mso-ansi-language:EN-US;"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;How to use the Get-PasswordPolicy and New-PasswordPolicy to copy an existing PasswordPolicy&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/I&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;Note:&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt; Any parameter can be used with New-PasswordPolicy override settings from the existing policy.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;SPAN style="mso-ansi-language:EN-US;"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Get-PasswordPolicy &amp;lt;name&amp;gt; [-domain &amp;lt;FQDNDomainName&amp;gt;] &lt;B&gt;|&lt;/B&gt; New-PasswordPolicy &amp;lt;Name&amp;gt; [-domain &amp;lt;FQDNDomainName&amp;gt;] [-MaximumPasswordAge &amp;lt;timespan&amp;gt;] [-MinimumPasswordAge &amp;lt;timespan&amp;gt;] [-MinimumPasswordLength &amp;lt;PassswordMinLenght&amp;gt;] [-PasswordComplexityEnabled &amp;lt;$True/$False&amp;gt;] [-PasswordReversibleEncryptionEnabled &amp;lt;$True/$False&amp;gt;] [-PasswordSettingsPrecendence &amp;lt;PrecendenceOrder&amp;gt;] [-PasswordHistoryLength &amp;lt;NumberOfPasswords&amp;gt;] [-LockoutDuration &amp;lt;timespan&amp;gt;] [-LockoutObservationWindow &amp;lt;timespan&amp;gt;] [-LockoutThreshold &amp;lt;int&amp;gt; -AppliesTo * SupportedNameFormats]&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;STRONG&gt;&lt;SPAN style="FONT-FAMILY:'Arial','sans-serif';COLOR:black;FONT-SIZE:10pt;mso-ansi-language:EN-US;"&gt;--------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="mso-ansi-language:EN-US;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;B&gt;&lt;I&gt;&lt;U&gt;&lt;SPAN style="mso-ansi-language:EN-US;"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;How to check policy compliance for linked users for a one or more Password Policies&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/I&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;SPAN style="mso-ansi-language:EN-US;"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;foreach ($Policy in Get-PasswordPolicy [&amp;lt;Name&amp;gt;]) { foreach ($Applied in $Policy.AppliesTo) { Get-PasswordPo&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;" class=MsoNormal&gt;&lt;SPAN style="mso-ansi-language:EN-US;"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;licyEffective $Applied } }&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;img src="http://blogs.chrisse.se/aggbug.aspx?PostID=46" width="1" height="1"&gt;</content><author><name>Christoffer Andersson</name><uri>http://blogs.chrisse.se/members/Christoffer+Andersson.aspx</uri></author><category term="Fine Grain Password Policy Tool" scheme="http://blogs.chrisse.se/blogs/chrisse/archive/tags/Fine+Grain+Password+Policy+Tool/default.aspx" /></entry><entry><title>Windows Server 2003 Domain Controllers may perform Automatic Site Coverage for RODCs</title><link rel="alternate" type="text/html" href="http://blogs.chrisse.se/blogs/chrisse/archive/2008/09/23/windows-server-2003-domain-controllers-may-perform-automatic-site-coverage-for-rodcs.aspx" /><id>http://blogs.chrisse.se/blogs/chrisse/archive/2008/09/23/windows-server-2003-domain-controllers-may-perform-automatic-site-coverage-for-rodcs.aspx</id><published>2008-09-22T23:01:00Z</published><updated>2008-09-22T23:01:00Z</updated><content type="html">&lt;P style="MARGIN-LEFT:36pt;"&gt;&lt;SPAN style="FONT-FAMILY:Arial;FONT-SIZE:10pt;"&gt;&lt;STRONG&gt;Note: &lt;/STRONG&gt;Domain controllers running Windows Server 2003 do not consider RODCs when they evaluate site coverage requirements and may register its Domain Name System (DNS) service (SRV) resource records for a site that contains an RODC. As a result, they perform automatic site coverage for any site regardless of the presence of an RODC for the same domain. Consequently, client computers that attempt to discover a domain controller in the RODC site can also find the domain controller that is running Windows Server 2003 and may not authenticate to the RODC. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT:36pt;"&gt;&lt;SPAN style="FONT-FAMILY:Arial;FONT-SIZE:10pt;"&gt;There are a few possible solutions for this problem: &lt;/SPAN&gt;&lt;/P&gt;
&lt;OL style="MARGIN-LEFT:72pt;"&gt;
&lt;LI&gt;&lt;SPAN style="FONT-FAMILY:Arial;FONT-SIZE:10pt;"&gt;Apply the Windows Server 2008 read-only domain controller compatibility pack for Windows Server 2003 clients and for Windows XP clients (http://support.microsoft.com/kb/944043/en-us)&lt;BR&gt;(This hotfix has to be applied to all Windows Server 2003 DCs that may perform automatic site Coverage)&lt;BR&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="FONT-FAMILY:Arial;FONT-SIZE:10pt;"&gt;Ensure that only domain controllers running Windows Server 2008 are present in the site closest to the RODC site. &lt;BR&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="FONT-FAMILY:Arial;FONT-SIZE:10pt;"&gt;Configure the weight or the priority of the DNS SRV records so that clients are more likely to authenticate with the RODC than with a remote Windows Server 2003 domain controller. &lt;BR&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="FONT-FAMILY:Arial;FONT-SIZE:10pt;"&gt;Disable automatic site coverage on domain controllers running Windows Server 2003 present in the site closest to the RODC site. &lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY:Arial;FONT-SIZE:10pt;"&gt;How to disable automatic site coverage: &lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN style="FONT-FAMILY:Arial;FONT-SIZE:10pt;"&gt;Click Start, click Run, type &lt;STRONG&gt;regedit&lt;/STRONG&gt;, and then click OK. &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="FONT-FAMILY:Arial;FONT-SIZE:10pt;"&gt;Navigate to the following registry subkey &lt;STRONG&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters&lt;/STRONG&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="FONT-FAMILY:Arial;FONT-SIZE:10pt;"&gt;Click Edit, point to New, and then click &lt;STRONG&gt;DWORD&lt;/STRONG&gt; Value. &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="FONT-FAMILY:Arial;FONT-SIZE:10pt;"&gt;Type&lt;STRONG&gt; AutoSiteCoverage&lt;/STRONG&gt; as the name of the new entry, and then press &lt;STRONG&gt;ENTER&lt;/STRONG&gt;. &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="FONT-FAMILY:Arial;FONT-SIZE:10pt;"&gt;Double-click the new &lt;STRONG&gt;AutoSiteCoverage&lt;/STRONG&gt; registry entry &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="FONT-FAMILY:Arial;FONT-SIZE:10pt;"&gt;Under Value data, type &lt;STRONG&gt;0&lt;/STRONG&gt; to disable automatic site coverage. 1 = to enable it. &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="FONT-FAMILY:Arial;FONT-SIZE:10pt;"&gt;Click Start, Click Run, type &lt;STRONG&gt;cmd&lt;/STRONG&gt; and then click OK. &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="FONT-FAMILY:Arial;FONT-SIZE:10pt;"&gt;In the Command Prompt, type the following command:&lt;BR&gt;&lt;STRONG&gt;nltest /dsregdns &lt;/STRONG&gt;or restart the &lt;STRONG&gt;netlogon&lt;/STRONG&gt; service &lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;img src="http://blogs.chrisse.se/aggbug.aspx?PostID=42" width="1" height="1"&gt;</content><author><name>Christoffer Andersson</name><uri>http://blogs.chrisse.se/members/Christoffer+Andersson.aspx</uri></author><category term="Active Directory" scheme="http://blogs.chrisse.se/blogs/chrisse/archive/tags/Active+Directory/default.aspx" /></entry><entry><title>In appreciation to your valuable contribution to Windows Server 2008  </title><link rel="alternate" type="text/html" href="http://blogs.chrisse.se/blogs/chrisse/archive/2008/09/22/in-appreciation-to-your-valuable-contribution-to-windows-server-2008.aspx" /><id>http://blogs.chrisse.se/blogs/chrisse/archive/2008/09/22/in-appreciation-to-your-valuable-contribution-to-windows-server-2008.aspx</id><published>2008-09-21T23:44:00Z</published><updated>2008-09-21T23:44:00Z</updated><content type="html">&lt;P&gt;&lt;IMG style="WIDTH:323px;HEIGHT:431px;" src="http://www.chrisse.se/cs-content/2.jpg" width=323 height=431&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've received a package from Microsoft to the office yesterday with some stuff as thanks for the work we did put into the Windows Server 2008 release, thank you Microsoft this is the best DVD I've got so far of Windows Server 2008 &lt;SPAN style="FONT-FAMILY:Wingdings;"&gt;J&lt;/SPAN&gt; But I have moved on to something different to play with these days &lt;SPAN style="FONT-FAMILY:Wingdings;"&gt;J&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.chrisse.se/aggbug.aspx?PostID=41" width="1" height="1"&gt;</content><author><name>Christoffer Andersson</name><uri>http://blogs.chrisse.se/members/Christoffer+Andersson.aspx</uri></author><category term="Windows Server 2008" scheme="http://blogs.chrisse.se/blogs/chrisse/archive/tags/Windows+Server+2008/default.aspx" /></entry><entry><title>How do I verify that my forest and domain has been successfully prepared for Windows Server 2003 </title><link rel="alternate" type="text/html" href="http://blogs.chrisse.se/blogs/chrisse/archive/2008/09/15/how-do-i-verify-that-my-forest-and-domain-has-been-successfully-prepared-for-windows-server-2003.aspx" /><id>http://blogs.chrisse.se/blogs/chrisse/archive/2008/09/15/how-do-i-verify-that-my-forest-and-domain-has-been-successfully-prepared-for-windows-server-2003.aspx</id><published>2008-09-14T18:24:56Z</published><updated>2008-09-14T18:24:56Z</updated><content type="html">&lt;p&gt;&lt;br /&gt;This is a frequently asked question the Active Directory newsgroups, so I thought it was worth a blog post.
&lt;/p&gt;&lt;p&gt;To determine if adprep successfully have prepared the forsest and the domain (/forestPrep and /domainPrep) look for the objects below:&lt;br /&gt;&lt;br /&gt;CN=Windows2003Update,CN=ForestUpdates,CN=Configuration,DC=X (Should exist if the forest has been successfully prepared)
&lt;/p&gt;&lt;p&gt;CN=Windows2003Update,CN=DomainUpdates,CN=System,DC=X (Should exist in each domain that has been successfully prepared)
&lt;/p&gt;&lt;p&gt;If you know/have the DC that adprep was executed on left, You can check those log files, they give a more detailed explanation of the adprep process.  C:\Windows\debug\adprep.
&lt;/p&gt;&lt;p&gt;In fact running adprep again can be used as a verification process, as the tool itself will notify you that the process has only been run once and doesn't need to be rerun. 
&lt;/p&gt;&lt;p&gt;By the way, it's about time to move away from Windows 2000 DCs these days &lt;span style="font-family:Wingdings;"&gt;J&lt;/span&gt;&lt;/p&gt;&lt;img src="http://blogs.chrisse.se/aggbug.aspx?PostID=40" width="1" height="1"&gt;</content><author><name>Christoffer Andersson</name><uri>http://blogs.chrisse.se/members/Christoffer+Andersson.aspx</uri></author><category term="Active Directory" scheme="http://blogs.chrisse.se/blogs/chrisse/archive/tags/Active+Directory/default.aspx" /></entry><entry><title>Back in Sweden after a month in US</title><link rel="alternate" type="text/html" href="http://blogs.chrisse.se/blogs/chrisse/archive/2008/09/11/back-in-sweden-after-a-month-in-us.aspx" /><id>http://blogs.chrisse.se/blogs/chrisse/archive/2008/09/11/back-in-sweden-after-a-month-in-us.aspx</id><published>2008-09-10T16:09:00Z</published><updated>2008-09-10T16:09:00Z</updated><content type="html">&lt;P&gt;I'm back on track in Sweden after being in the US for about a month; actually I have been working a month here already, so we continue the "Windows Vista Enterprise Project" that I'm currently completely busy with (see previous post). There still remains very much work to do, and trying to catch up with all different kind of dependences this project has to other teams inside the company i.e. DNS Team, Active Directory Team, PKI Team, Storage Team, Network Team, etc takes a lot of time. &lt;/P&gt;
&lt;P&gt;&lt;IMG style="WIDTH:512px;HEIGHT:384px;" src="http://www.chrisse.se/cs-content/1.jpg" width=512 height=384&gt;&lt;/P&gt;
&lt;P&gt;Yesterday we did ship a first release of our Windows Vista image supporting 5 different hardware models, both x86 and x64 (that actually makes it 10) and a customized installation of Microsoft Office 2007. To certify a specific hardware model, takes about 8 hours (both x86 and x64) and then we use an 'own' developed method for certify our hardware. This is basically it (a bit simplified) &lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Download all drivers for the specific model from the hardware vendor's web site. &lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;Create a folder structure for the specific hardware model in the central storage repository that looks something like: &lt;/DIV&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV&gt;HP nc6010p x64 &lt;/DIV&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV&gt;6010p &lt;/DIV&gt;
&lt;UL&gt;
&lt;LI&gt;Network &lt;/LI&gt;
&lt;LI&gt;Chipset &lt;/LI&gt;
&lt;LI&gt;Storage &lt;/LI&gt;
&lt;LI&gt;And so on… &lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;Swsetup &lt;/DIV&gt;
&lt;UL&gt;
&lt;LI&gt;App0Driver1 &lt;/LI&gt;
&lt;LI&gt;And so on. &lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;Extract the content by lunching a custom tool (wrapping around winrar.exe) &lt;/DIV&gt;
&lt;UL&gt;
&lt;LI&gt;Identify driver type. (Core Driver) or (App0): The difference between those is that Core Driver is a REAL driver and App0 is a "BAD" driver that needs to execute some kind of setup package, i.e. .exe or .msi package. &lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;
&lt;LI&gt;Check in the "REAL" drivers into the System Center Configuration Manager (Our main deployment tool) into the "All Drivers" driver package. &lt;/LI&gt;
&lt;LI&gt;Create Application Packages for all App0 Drivers. &lt;/LI&gt;
&lt;LI&gt;Create a task sequencer for the specific hardware, It will be something like "Install Vista Core-VBL-Hardware-HP6910p X86" The HW model is automatically detected by using a simple WMI query. &lt;/LI&gt;
&lt;LI&gt;Adding the App0 packages, and configures the task sequencer to use "Auto Apply Drivers" that means that Windows Vista during the deployment will do a PNP detection and by its own chose the best drivers from the "All-Drivers" driver package. We have to watch out for compatibility issues here between x86/x64 and storage drivers, It can cause Windows to never boot. &lt;/LI&gt;
&lt;LI&gt;Once the computer has finished it's deployment, We use a custom made report in System Center Configuration Manager that tells us the best matching drivers that was picked up by Windows during the install, the best matching drivers in the "All-Drivers" driver package, as well all drivers that for some reason failed to install (if any) or if a device is completely missing a driver. &lt;/LI&gt;
&lt;LI&gt;Based on this information, the drivers for the specific model is locked and the model us getting its own Driver Package, based on the report generated above, the deployment starts all over again but now with its own driver package instead of "Auto Apply Drivers", &lt;/LI&gt;
&lt;LI&gt;The process is repeated until all devices have a working driver.&lt;/LI&gt;&lt;/UL&gt;&lt;img src="http://blogs.chrisse.se/aggbug.aspx?PostID=39" width="1" height="1"&gt;</content><author><name>Christoffer Andersson</name><uri>http://blogs.chrisse.se/members/Christoffer+Andersson.aspx</uri></author><category term="Windows Vista" scheme="http://blogs.chrisse.se/blogs/chrisse/archive/tags/Windows+Vista/default.aspx" /></entry><entry><title>How to manage an Windows Vista Enterprise Project</title><link rel="alternate" type="text/html" href="http://blogs.chrisse.se/blogs/chrisse/archive/2008/07/21/how-to-manage-an-windows-vista-enterprise-project.aspx" /><id>http://blogs.chrisse.se/blogs/chrisse/archive/2008/07/21/how-to-manage-an-windows-vista-enterprise-project.aspx</id><published>2008-07-21T08:54:00Z</published><updated>2008-07-21T08:54:00Z</updated><content type="html">&lt;P&gt;It's been a very long time since I did the last blog post here. So what did happen, did I just disappeared a few weeks before Windows Server 2008 RTM. Oh no, But Windows Server 2008 RTM has been a lot of work to me and the entire company, as you may been aware of I have been responsible for putting Windows Server 2008 Pre-release code out in production at a bunch of customers, It's definitely been a lot of challenges and a lots of fun to driving this program, as well it did put a lot of value both to the customers that participated and to Microsoft – for all the great feedback we did give them, and all the bugs we did found and got resolved before the product did hit RTM. I will quote a line for the RTM announcement I received from Microsoft. "When you look at Windows Server 2008, you should think there is a little price of you in that product – thanks for helping us making this product" and I would say thanks for letting me having the opportunity to be a part of the Longhorn project. It is a few days now since I've installed the first Windows Longhorn DC back in early 2005. I would like to thank many people at Microsoft and at last, but not least Mikael Nyström (TrueSec Employee) and Anders Jansson (former TrueSec Employee) for running this program with me. &lt;/P&gt;
&lt;P&gt;So what are I'm up to know? Did I move straight on to the next Windows version? Well in fact I did, I went on to early builds on what's next after Windows Vista/Windows Server 2008 even before Windows Server 2008 did hit RTM, but that's another story. &lt;/P&gt;
&lt;P&gt;Let's stay with Windows Vista for a while, okay wait a sec, aren't I'm supposed to be a server guy, or more specific AD guy? O Yes I'm, don't get me wrong there. But I got very bored of all noises about Windows Vista like "There is no way you can migrate an enterprise company over to that crapy platform". Eh, if you know me you know that I'm totally are in love with large enterprise environment, the complexity, scalability issues, communication, and working across different countries, working with multiple teams. So I did decided to join and drive one of the most interesting and challenging projects I've come across so far, I happen to be in Team Platform Core: &lt;/P&gt;
&lt;P&gt;Deploying and migrating over 60&amp;nbsp;000 clients from a mixture of Windows XP and Windows 2000 Professional with a time line of only 3 years, reaching out to 95% of all internal business units with Windows Vista SP1 and Office 2007 SP1 using System Center Configuration Manager 2007. This customer dose currently has around 10000 + applications. Oh yes they have to remain working once we switched every PC into Windows Vista form now and the coming two years. It gets even more complicated, they happen to have an industrial line that runs 24/5 around the globe. &lt;/P&gt;
&lt;P&gt;I think we have so far done a lot of right decision in this project, and it's the best team I ever been working with, both internal and external people in this project is very skilled and professional in what they do, we definitely have the right people here. The most challenge part so far has been time, but there is no way to delay the final results of this project, you may ask why? The answer is pretty simple: End of support for Windows 2000 Professional by year 210 (most of the workstations are running at this platform today) not receiving security updates nor there is going to be any support beyond that date isn't an option for an enterprise customer like this. So we have about 2 years left, we haven't deployed a single Windows Vista PC in production yet. So if our calculations are made right. (Yes our team did get the statistics of the network performance at over 640 sites, did put together I formula for when to use a SCCM DP, SCCM Branch Office DP, SCCM Secondary Site Server, when to create an AD site, did calculate with the size of the Windows Vista Image to go over the wire (approximately 3GB) plus Office 2007 (approximately 1GB), and what we refer to as app0 (HW based apps) and app1 (core apps) as well USMT data during migration (approximately 20GB) going upstream and downstream.) Our rollout team has to migrate around 100 PCs each day in two years to be able to successfully accomplish the goal. I will report more from this project and what it is like to be in the middle of it, next post will probably be about application compatibility, what strategy we did choose, why Microsoft ACT wasn't enough, what custom tools our team did put together to in order for making it all possible for Team Application.&lt;/P&gt;&lt;img src="http://blogs.chrisse.se/aggbug.aspx?PostID=37" width="1" height="1"&gt;</content><author><name>Christoffer Andersson</name><uri>http://blogs.chrisse.se/members/Christoffer+Andersson.aspx</uri></author><category term="Windows Vista" scheme="http://blogs.chrisse.se/blogs/chrisse/archive/tags/Windows+Vista/default.aspx" /></entry><entry><title>Fine Grain Password Policy Tool Beta 2 is ready!</title><link rel="alternate" type="text/html" href="http://blogs.chrisse.se/blogs/chrisse/archive/2008/02/06/fine-grain-password-policy-tool-beta-2-is-ready.aspx" /><id>http://blogs.chrisse.se/blogs/chrisse/archive/2008/02/06/fine-grain-password-policy-tool-beta-2-is-ready.aspx</id><published>2008-02-05T19:39:00Z</published><updated>2008-02-05T19:39:00Z</updated><content type="html">&lt;P class=MsoNormal&gt;&lt;STRONG&gt;&lt;B&gt;&lt;FONT face=Arial color=black size=4&gt;&lt;SPAN style="FONT-SIZE:13.5pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Fine Grain Password Policy Tool Beta&amp;nbsp;2 is ready!&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;"&gt;&lt;B&gt;&lt;FONT face=Calibri color=black size=2&gt;&lt;SPAN style="FONT-WEIGHT:bold;FONT-SIZE:11pt;COLOR:black;"&gt;Build:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;FONT color=black&gt;&lt;SPAN style="COLOR:black;"&gt; FGPP Beta 2_2256-20080120.1&lt;BR&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;B&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-WEIGHT:bold;FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Branch&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;: FGPP-Beta2-branch.&lt;BR&gt;&lt;B&gt;&lt;SPAN style="FONT-WEIGHT:bold;"&gt;Usage&lt;/SPAN&gt;&lt;/B&gt;: In a&amp;nbsp;Windows Server 2008 Test&amp;nbsp;environment.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;"&gt;&lt;B&gt;&lt;FONT face=Arial color=black size=3&gt;&lt;SPAN style="FONT-WEIGHT:bold;FONT-SIZE:12pt;COLOR:black;FONT-FAMILY:Arial;"&gt;&lt;BR&gt;General Information&lt;BR&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;FONT face=Arial size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Arial;"&gt;&lt;FONT color=black&gt;&lt;SPAN style="COLOR:black;"&gt;&lt;BR&gt;Overview of Fine Grain Password Policies in Windows Server 2008:&lt;BR&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT face=Arial color=#0000ff size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;&lt;A class="" href="http://technet2.microsoft.com/windowsserver2008/en/library/056a73ef-5c9e-44d7-acc1-4f0bade6cd751033.mspx"&gt;&lt;SPAN&gt;http://technet2.microsoft.com/windowsserver2008/en/library/056a73ef-5c9e-44d7-acc1-4f0bade6cd751033.mspx&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT face=Arial size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;&lt;BR&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;B&gt;&lt;FONT face=Arial color=black size=3&gt;&lt;SPAN style="FONT-WEIGHT:bold;FONT-SIZE:12pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Download&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;&lt;BR&gt;&lt;BR&gt;Download Fine Grain Password Policy Tool (x86) Beta 2.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;&lt;BR&gt;&lt;A title=blocked::http://blogs.chrisse.se/files/folders/32/download.aspx href="http://blogs.chrisse.se/files/folders/32/download.aspx"&gt;&lt;FONT color=#0000ff&gt;http://blogs.chrisse.se/files/folders/32/download.aspx&lt;/FONT&gt;&lt;/A&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;&lt;BR&gt;Download Fine Grain Password Policy Tool (x64) Beta 2.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT face=Arial size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Arial;"&gt;&lt;A title=blocked::http://blogs.chrisse.se/files/folders/33/download.aspx href="http://blogs.chrisse.se/files/folders/33/download.aspx"&gt;http://blogs.chrisse.se/files/folders/33/download.aspx&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Quick Start Guide&lt;BR&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT face=Arial color=#0000ff size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;&lt;A class="" href="http://blogs.chrisse.se/blogs/chrisse/pages/fine-grain-password-policy-tool.aspx"&gt;&lt;SPAN&gt;http://blogs.chrisse.se/blogs/chrisse/pages/fine-grain-password-policy-tool.aspx&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT face=Arial size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=punktlistats style="MARGIN-BOTTOM:0pt;MARGIN-LEFT:0cm;MARGIN-RIGHT:0cm;mso-margin-top-alt:6.0pt;"&gt;&lt;B&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-WEIGHT:bold;FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;System Requirements&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=brdtextts style="MARGIN-BOTTOM:0pt;MARGIN-LEFT:0cm;MARGIN-RIGHT:0cm;mso-margin-top-alt:6.0pt;"&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Fine Grain Password Policy Tool (FGPP) Beta 2 are “Supported” on the following platforms&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=brdtextts style="MARGIN-BOTTOM:0pt;MARGIN-LEFT:36pt;TEXT-INDENT:-18pt;MARGIN-RIGHT:0cm;mso-margin-top-alt:6.0pt;"&gt;&lt;FONT face=Symbol color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Symbol;"&gt;·&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT color=black size=1&gt;&lt;SPAN style="FONT-SIZE:7pt;COLOR:black;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Windows Server 2008&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=brdtextts style="MARGIN-BOTTOM:0pt;MARGIN-LEFT:36pt;TEXT-INDENT:-18pt;MARGIN-RIGHT:0cm;mso-margin-top-alt:6.0pt;"&gt;&lt;FONT face=Symbol color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Symbol;"&gt;·&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT color=black size=1&gt;&lt;SPAN style="FONT-SIZE:7pt;COLOR:black;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Windows Vista and Windows Vista Service Pack 1&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=brdtextts style="MARGIN-BOTTOM:0pt;MARGIN-LEFT:36pt;TEXT-INDENT:-18pt;MARGIN-RIGHT:0cm;mso-margin-top-alt:6.0pt;"&gt;&lt;FONT face=Symbol color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Symbol;"&gt;·&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT color=black size=1&gt;&lt;SPAN style="FONT-SIZE:7pt;COLOR:black;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Windows Server 2003 Service Pack 1 and Windows Server 2003 R2&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=brdtextts style="MARGIN-BOTTOM:0pt;MARGIN-LEFT:36pt;TEXT-INDENT:-18pt;MARGIN-RIGHT:0cm;mso-margin-top-alt:6.0pt;"&gt;&lt;FONT face=Symbol color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Symbol;"&gt;·&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT color=black size=1&gt;&lt;SPAN style="FONT-SIZE:7pt;COLOR:black;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Windows XP Service Pack 2&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=punktlistats style="MARGIN-BOTTOM:0pt;MARGIN-LEFT:0cm;MARGIN-RIGHT:0cm;mso-margin-top-alt:6.0pt;"&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=rubrik4ts style="MARGIN-BOTTOM:6pt;MARGIN-LEFT:0cm;MARGIN-RIGHT:0cm;mso-margin-top-alt:6.0pt;"&gt;&lt;STRONG&gt;&lt;B&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Prerequisites&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/STRONG&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=brdtextts style="MARGIN-BOTTOM:0pt;MARGIN-LEFT:0cm;MARGIN-RIGHT:0cm;mso-margin-top-alt:6.0pt;"&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Before installing this build, you must have:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=brdtextts style="MARGIN-BOTTOM:0pt;MARGIN-LEFT:17.85pt;MARGIN-RIGHT:0cm;mso-margin-top-alt:6.0pt;"&gt;&lt;U&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Windows Server 2008 and Windows Vista&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/U&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=punktlistats style="MARGIN-BOTTOM:0pt;MARGIN-LEFT:17.85pt;MARGIN-RIGHT:0cm;mso-margin-top-alt:6.0pt;"&gt;&lt;FONT face=Symbol color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Symbol;"&gt;·&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT color=black size=1&gt;&lt;SPAN style="FONT-SIZE:7pt;COLOR:black;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Windows Server 2008 Active Directory Domain.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=punktlistats style="MARGIN-BOTTOM:0pt;MARGIN-LEFT:17.85pt;MARGIN-RIGHT:0cm;mso-margin-top-alt:6.0pt;"&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT face=Symbol color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Symbol;"&gt;·&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT color=black size=1&gt;&lt;SPAN style="FONT-SIZE:7pt;COLOR:black;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Windows PowerShell installed (for command-line and scripting support)&lt;BR&gt;&lt;U&gt;&lt;BR&gt;Windows Server 2003 and Windows XP&lt;/U&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=punktlistats style="MARGIN-BOTTOM:0pt;MARGIN-LEFT:17.85pt;MARGIN-RIGHT:0cm;mso-margin-top-alt:6.0pt;"&gt;&lt;FONT face=Symbol color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Symbol;"&gt;·&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT color=black size=1&gt;&lt;SPAN style="FONT-SIZE:7pt;COLOR:black;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Microsoft .NET Framework 2.0.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=punktlistats style="MARGIN-BOTTOM:0pt;MARGIN-LEFT:17.85pt;MARGIN-RIGHT:0cm;mso-margin-top-alt:6.0pt;"&gt;&lt;FONT face=Symbol color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Symbol;"&gt;·&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT color=black size=1&gt;&lt;SPAN style="FONT-SIZE:7pt;COLOR:black;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Microsoft Management Console 3.0 &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=punktlistats style="MARGIN-BOTTOM:0pt;MARGIN-LEFT:17.85pt;MARGIN-RIGHT:0cm;mso-margin-top-alt:6.0pt;"&gt;&lt;FONT face=Symbol color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Symbol;"&gt;·&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT color=black size=1&gt;&lt;SPAN style="FONT-SIZE:7pt;COLOR:black;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Windows Server 2008 Active Directory Domain, &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=punktlistats style="MARGIN-BOTTOM:0pt;MARGIN-LEFT:17.85pt;MARGIN-RIGHT:0cm;mso-margin-top-alt:6.0pt;"&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT face=Symbol color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Symbol;"&gt;·&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT color=black size=1&gt;&lt;SPAN style="FONT-SIZE:7pt;COLOR:black;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT face=Arial color=black&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Windows PowerShell installed (for command-line and scripting support)&lt;BR&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=punktlistats style="MARGIN-BOTTOM:0pt;MARGIN-LEFT:0cm;MARGIN-RIGHT:0cm;mso-margin-top-alt:6.0pt;"&gt;&lt;FONT face=Arial color=black size=3&gt;&lt;SPAN style="FONT-WEIGHT:bold;FONT-SIZE:12pt;COLOR:black;FONT-FAMILY:Arial;"&gt;&lt;FONT size=2&gt;Microsoft Managemnt Console for Fine Grain Password Polices: (Click for full size)&lt;/FONT&gt;&lt;BR&gt;&lt;A class="" title="Fine Grain Password Policy Tool Beta 2" href="http://www.chrisse.se/FGPP/FGPP-Beta2_2256.1_UIPS_01.jpg" target=_blank&gt;&lt;IMG style="WIDTH:728px;HEIGHT:415px;" height=421 src="http://www.chrisse.se/FGPP/FGPP-Beta2_2256.1_UIPS_01.jpg" width=754&gt;&lt;/A&gt;&lt;BR&gt;&lt;BR&gt;&lt;BR&gt;Usage information&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT face=Arial color=black&gt;&lt;SPAN style="COLOR:black;FONT-FAMILY:Arial;"&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=punktlistats style="MARGIN-BOTTOM:0pt;MARGIN-LEFT:0cm;MARGIN-RIGHT:0cm;mso-margin-top-alt:6.0pt;"&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Note: Use Fine Grain Password Policy at your own risk.&lt;BR&gt;&lt;BR&gt;Note: The Fine Grain Password Policy Tool will currently only work from a domain joined computer.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=punktlistats style="MARGIN-BOTTOM:0pt;MARGIN-LEFT:0cm;MARGIN-RIGHT:0cm;mso-margin-top-alt:6.0pt;"&gt;&lt;STRONG&gt;&lt;B&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Fine Grain Password Policy Tool Core PowerShell Samples.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/STRONG&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;FGPP Beta 2 Milestone (Build 2230-2258) supports the following PowerShell Commands.&lt;BR&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;STRONG&gt;&lt;B&gt;&lt;I&gt;&lt;U&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-STYLE:italic;FONT-FAMILY:Arial;"&gt;&lt;BR&gt;Create new Password Policies&lt;BR&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/U&gt;&lt;/I&gt;&lt;/B&gt;&lt;/STRONG&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;New-PasswordPolicy &amp;lt;Name&amp;gt; [-domain &amp;lt;FQDNDomainName&amp;gt;] -MaximumPasswordAge &amp;lt;DD.HH:MM&amp;gt; -MinimumPasswordAge &amp;lt;DD.HH:MM&amp;gt; -MinimumPasswordLength &amp;lt;PassswordMinLenght&amp;gt; -PasswordComplexityEnabled &amp;lt;$True/$False&amp;gt; -PasswordReversibleEncryptionEnabled &amp;lt;$True/$False&amp;gt; -PasswordSettingsPrecendence &amp;lt;PrecendenceOrder&amp;gt; -PasswordHistoryLength &amp;lt;NumberOfPasswords&amp;gt; -LockoutDuration &amp;lt;DD.HH:MM&amp;gt; -LockoutObservationWindow &amp;lt;DD.HH:MM&amp;gt; -LockoutThreshold &amp;lt;int&amp;gt; -AppliesTo *SupportedNameFormats&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;B&gt;&lt;I&gt;&lt;U&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-WEIGHT:bold;FONT-SIZE:10pt;COLOR:black;FONT-STYLE:italic;FONT-FAMILY:Arial;"&gt;&lt;BR&gt;&lt;EM&gt;&lt;I&gt;&lt;FONT face=Arial&gt;&lt;SPAN style="FONT-FAMILY:Arial;"&gt;Modify existing&amp;nbsp;Password Policies&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/I&gt;&lt;/EM&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/U&gt;&lt;/I&gt;&lt;/B&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Modify-PasswordPolicy &amp;lt;name&amp;gt; [-domain &amp;lt;FQDNDomainName&amp;gt;] [-MaximumPasswordAge &amp;lt;DD.HH:MM&amp;gt;] [-MinimumPasswordAge &amp;lt;DD.HH:MM&amp;gt;] [-MinimumPasswordLength &amp;lt;PassswordMinLenght&amp;gt;] [-PasswordComplexityEnabled &amp;lt;$True/$False&amp;gt;] [-PasswordReversibleEncryptionEnabled &amp;lt;$True/$False&amp;gt;] [-PasswordSettingsPrecendence &amp;lt;PrecendenceOrder&amp;gt;] [-PasswordHistoryLength &amp;lt;NumberOfPasswords&amp;gt;] [-LockoutDuration &amp;lt;DD.HH:MM&amp;gt;] [-LockoutObservationWindow &amp;lt;DD.HH:MM&amp;gt;] [-LockoutThreshold &amp;lt;int&amp;gt;] -AppliesToAdd *SupportedNameFormats -AppliesToRemove *SupportedNameFormats&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN-BOTTOM:12pt;"&gt;&lt;B&gt;&lt;I&gt;&lt;U&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-WEIGHT:bold;FONT-SIZE:10pt;COLOR:black;FONT-STYLE:italic;FONT-FAMILY:Arial;"&gt;&lt;STRONG&gt;&lt;B&gt;&lt;FONT face=Arial&gt;&lt;SPAN style="FONT-FAMILY:Arial;"&gt;&lt;BR&gt;Delete Password Policies&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/STRONG&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/U&gt;&lt;/I&gt;&lt;/B&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Delete-PasswordPolicy &amp;lt;name&amp;gt; [-domain &amp;lt;FQDNDomainName&amp;gt;] [-all]&lt;BR&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;EM&gt;&lt;B&gt;&lt;I&gt;&lt;U&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-WEIGHT:bold;FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Reame Password Policies&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/U&gt;&lt;/I&gt;&lt;/B&gt;&lt;/EM&gt;&lt;B&gt;&lt;I&gt;&lt;U&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-WEIGHT:bold;FONT-SIZE:10pt;COLOR:black;FONT-STYLE:italic;FONT-FAMILY:Arial;"&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/U&gt;&lt;/I&gt;&lt;/B&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Rename-PasswordPolicy &amp;lt;name&amp;gt; [-domain &amp;lt;FQDNDomainName&amp;gt;] -NewName &amp;lt;name&amp;gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;B&gt;&lt;I&gt;&lt;U&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-WEIGHT:bold;FONT-SIZE:10pt;COLOR:black;FONT-STYLE:italic;FONT-FAMILY:Arial;"&gt;&lt;BR&gt;&lt;EM&gt;&lt;I&gt;&lt;FONT face=Arial&gt;&lt;SPAN style="FONT-FAMILY:Arial;"&gt;Add users and global groups to an existing Password Policy&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/I&gt;&lt;/EM&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/U&gt;&lt;/I&gt;&lt;/B&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Add-PasswordPolicy -Name &amp;lt;name&amp;gt; [-domain &amp;lt;FQDNDomainName&amp;gt;] -AppliesTo *SupportedNameFormats&lt;BR&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;EM&gt;&lt;B&gt;&lt;I&gt;&lt;U&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-WEIGHT:bold;FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Remove users and global groups to an existing Password Policy&lt;BR&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/U&gt;&lt;/I&gt;&lt;/B&gt;&lt;/EM&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Remove-PasswordPolicy -Name &amp;lt;name&amp;gt; [-domain &amp;lt;FQDNDomainName&amp;gt;] -AppliesTo *SupportedNameFormats [-all]&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;EM&gt;&lt;B&gt;&lt;I&gt;&lt;U&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-WEIGHT:bold;FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Get the Effective PasswordPolicy for one or more users objects&lt;BR&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/U&gt;&lt;/I&gt;&lt;/B&gt;&lt;/EM&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Get-PasswordPolicyEffective &amp;lt;name&amp;gt; [-domain &amp;lt;FQDNDomainName&amp;gt;]&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;STRONG&gt;&lt;B&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;------------------------------------------------------------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;STRONG&gt;&lt;B&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;*SupportedNameFormats: &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/STRONG&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;[Domain\UserN, "First LastName", {4fa050f0-f561-11cf-bdd9-00aa003a77b6}, example.microsoft.com/software/user name, &lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT face=Arial color=#0000ff size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;&lt;A title=blocked::mailto:usern@example.microsoft.com href="mailto:usern@example.microsoft.com" target=_blank&gt;&lt;SPAN&gt;usern@example.microsoft.com&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;, S-1-5-21-397955417-626881126-188441444-501]&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=punktlistats style="MARGIN-BOTTOM:0pt;MARGIN-LEFT:0cm;MARGIN-RIGHT:0cm;mso-margin-top-alt:6.0pt;"&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;SPAN style="FONT-SIZE:12pt;"&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;STRONG&gt;&lt;B&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Fine Grain Password Policy Tool Additional PowerShell Samples.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/B&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class=punktlistats style="MARGIN-BOTTOM:0pt;MARGIN-LEFT:0cm;MARGIN-RIGHT:0cm;mso-margin-top-alt:6.0pt;"&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;FGPP Beta 2 Milestone (Build 2230-2258) supports the following PowerShell Commands.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;STRONG&gt;&lt;B&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;------------------------------------------------------------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;B&gt;&lt;I&gt;&lt;U&gt;&lt;FONT face=Calibri size=2&gt;&lt;SPAN style="FONT-WEIGHT:bold;FONT-SIZE:11pt;FONT-STYLE:italic;"&gt;How to use the Get-PasswordPolicy and New-PasswordPolicy to copy an existing PasswordPolicy&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/U&gt;&lt;/I&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;B&gt;&lt;FONT face=Calibri size=2&gt;&lt;SPAN style="FONT-WEIGHT:bold;FONT-SIZE:10pt;"&gt;Note:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;FONT size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;"&gt; Any parameter can be used with New-PasswordPolicy override settings from the existing policy.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face=Calibri size=2&gt;&lt;SPAN style="FONT-SIZE:11pt;"&gt;Get-PasswordPolicy &amp;lt;name&amp;gt; [-domain &amp;lt;FQDNDomainName&amp;gt;] &lt;B&gt;&lt;SPAN style="FONT-WEIGHT:bold;"&gt;|&lt;/SPAN&gt;&lt;/B&gt; New-PasswordPolicy &amp;lt;Name&amp;gt; [-domain &amp;lt;FQDNDomainName&amp;gt;] [-MaximumPasswordAge &amp;lt;&lt;FONT face=Arial size=2&gt;DD.HH:MM&lt;/FONT&gt;&amp;gt;] [-MinimumPasswordAge &amp;lt;&lt;FONT face=Arial size=2&gt;DD.HH:MM&lt;/FONT&gt;&amp;gt;] [-MinimumPasswordLength &amp;lt;PassswordMinLenght&amp;gt;] [-PasswordComplexityEnabled &amp;lt;$True/$False&amp;gt;] [-PasswordReversibleEncryptionEnabled &amp;lt;$True/$False&amp;gt;] [-PasswordSettingsPrecendence &amp;lt;PrecendenceOrder&amp;gt;] [-PasswordHistoryLength &amp;lt;NumberOfPasswords&amp;gt;] [-LockoutDuration &amp;lt;&lt;FONT face=Arial size=2&gt;DD.HH:MM&lt;/FONT&gt;&amp;gt;] [-LockoutObservationWindow &amp;lt;&lt;FONT face=Arial size=2&gt;DD.HH:MM&lt;/FONT&gt;&amp;gt;] [-LockoutThreshold &amp;lt;int&amp;gt; -AppliesTo * SupportedNameFormats]&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;STRONG&gt;&lt;B&gt;&lt;FONT face=Arial color=black size=2&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Arial;"&gt;------------------------------------------------------------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;B&gt;&lt;I&gt;&lt;U&gt;&lt;FONT face=Calibri size=2&gt;&lt;SPAN style="FONT-WEIGHT:bold;FONT-SIZE:11pt;FONT-STYLE:italic;"&gt;How to check policy compliance for linked users for a one or more Password Policies&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/U&gt;&lt;/I&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face=Calibri size=2&gt;&lt;SPAN style="FONT-SIZE:11pt;"&gt;foreach ($Policy in Get-PasswordPolicy [&amp;lt;Name&amp;gt;]) { foreach ($Applied in $Policy.AppliesTo) { Get-PasswordPo&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT face=Calibri size=2&gt;&lt;SPAN style="FONT-SIZE:11pt;"&gt;licyEffective $Applied } }&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.chrisse.se/aggbug.aspx?PostID=34" width="1" height="1"&gt;</content><author><name>Christoffer Andersson</name><uri>http://blogs.chrisse.se/members/Christoffer+Andersson.aspx</uri></author><category term="Windows Server 2008" scheme="http://blogs.chrisse.se/blogs/chrisse/archive/tags/Windows+Server+2008/default.aspx" /><category term="FGPP" scheme="http://blogs.chrisse.se/blogs/chrisse/archive/tags/FGPP/default.aspx" /><category term="Fine Grain Password Policy Tool" scheme="http://blogs.chrisse.se/blogs/chrisse/archive/tags/Fine+Grain+Password+Policy+Tool/default.aspx" /></entry></feed>