Search This Blog

Loading...

Tuesday, November 11, 2014

Lync vNext - Official Info

From the link below:


In the first half of 2015, the next version of Lync will become Skype for Business with a new client experience, new server release and updates to the service in Office 365.  We believe that Skype for Business will again transform the way people communicate by giving organizations reach to hundreds of millions of Skype users outside the walls of their business.


The whole story here: http://blogs.office.com/2014/11/11/introducing-skype-business/

Friday, October 24, 2014

TreeUndelete


A long time ago I wrote a script that restored a whole tree of objects, basically it restored an OU and all objects that belonged to that OU. The first time I showed it was in a session at Microsoft TechDays in Örebro 2010. After that, it served me well over the years, even though it didn’t have error handling and other good stuff. But since I was the only one using it and knew how the script worked – it was ok J

This year I presented at a conference in Åre and showed the script once again. Since people liked it, I wanted to post it somewhere but didn’t feel comfortable since it lacked a lot of features. Getting the time to fix it was hard but my colleague and friend Simon Wåhlin (who has forgotten more about Powershell than I know today) did re-write it and has now published it.

If you want to see a cool script, check it out here: http://blog.simonw.se/restore-ou-tree-from-ad-recycle-bin-with-powershell/
 

Monday, October 20, 2014

AD ACL Scanner

  • A tool completly written in PowerShell.
  • A tool with GUI used to create reports of access control lists in Active Directory .

  • https://adaclscan.codeplex.com/



    Features

    It has the following features:
    • View HTML reports of ACLs and save it to disk.
    • Export ACLs on Active Directory objects in a CSV format.
    • Connect and browse you default domain, schema , configuration or a naming context defined by distinguishedname.
    • Browse naming context by clicking you way around, either by OU’s or all types of objects.
    • Report only explicitly assigned ACLs.
    • Report on OUs , OUs and Container Objects or all object types.
    • Filter ACLs for a specific access type.. Where does “Deny” permission exists?
    • Filter ACLs for a specific identity. Where does "Domain\Client Admins" have explicit access? Or use wildcards like "jdoe".
    • Filter ACLs for permission on specific object. Where are permissions set on computer objects?
    • Skip default permissions (defaultSecurityDescriptor) in report. Makes it easier to find custom permissions.
    • Report owner of object.
    • Compare previous results with the current configuration and see the differences by color scheme (Green=matching permissions, Yellow= new permissions, Red= missing permissions).
    • Report when permissions were modified
    • Can use AD replication metadata when comparing.
    • Can convert a previously created CSV file to a HTML report.
    • Effective rights, select a security principal and match it agains the permissions in AD.
    • Color coded permissions based on criticality when using effective rights scan.
    • List you domains and select one from the list.
    • Get the size of the security descriptor (bytes).
    • Rerporting on disabled inheritance .
    • Get all inherited permissions in report.

    System requirements

    • Powershell 2.0 or above
    • PowerShell using a single-threaded apartment
    Last edited Oct 12 at 9:16 PM by robing, version 13

    Thursday, October 02, 2014

    Attributes synchronized to Azure AD

    http://msdn.microsoft.com/en-us/library/azure/dn764938.aspx

    From above link:

    --snip--
    With Azure AD Sync, you can remove individual attributes from being synchronized.
    Some services might not behave as expected when certain attributes are removed. The affected attributes are listed with their Active Directory LDAP name in the Install the AADSync Service.
    There are also some attributes that might be listed with a different name in other interfaces. For example, the attribute l from Active Directory is tracked as city in Azure AD.
    --snip--

    Follow the link on top to see the full article, it is very useful.

    Wednesday, October 01, 2014

    MVP Award

    Awarded MVP for the 17th year!


    Dear Jimmy Andersson,

    Congratulations! We are pleased to present you with the 2014 Microsoft® MVP Award!


     

    Friday, September 26, 2014

    Comparison of Microsoft's sync tools to the cloud.

    Below are a comparison (copy/pasted from the source) of the different Sync tools from Microsoft. It was updated on September 5, 2014. To be absolutely updated go to http://msdn.microsoft.com/en-us/library/azure/dn798669.aspx since things will change over time.

    On-Premises to Cloud Synchronization

     
    Feature Azure Active Directory Synchronization Tool (DirSync) Azure Active Directory Synchronization Services (AAD Sync) Forefront Identity Manager 2010 R2 (FIM)
    Connect to single on-premises AD forestXXX
    Connect to multiple on-premises AD forests
    XX
    Connect to single on-premises LDAP directory (no AD at all)
    CSX
    Connect to multiple on-premises LDAP directories
    CSX
    Connect to on-premises AD and on-premises LDAP directories
    CSX
    Connect to custom systems (i.e. SQL, Oracle, MySQL, etc.).
    CSX
    Synchronize customer defined attributes (directory extensions)CSCS

    Cloud to On-Premises Synchronization

    Feature Azure Active Directory Synchronization Tool (DirSync) Azure Active Directory Synchronization Services (AAD Sync) Forefront Identity Manager 2010 R2 (FIM)
    Write-back of devicesXCS
    Attribute write back (for Exchange hybrid deployment )XXX
    Write-back of users, groups objectsCSCS
    Write-back of passwords (from SSPR and password change)CSCS
    Write-back of customer defined attributes (directory extensions)CSCS

    Authentication Feature Support

    Feature Azure Active Directory Synchronization Tool (DirSync) Azure Active Directory Synchronization Services (AAD Sync) Forefront Identity Manager 2010 R2 (FIM)
    Password Hash Sync for single on-premises AD forestXCS
    Password Hash Sync for multiple on-premises AD forests
    CS
    Federation (SSO)XXX

    Set-up and Installation

    Feature Azure Active Directory Synchronization Tool (DirSync) Azure Active Directory Synchronization Services (AAD Sync) Forefront Identity Manager 2010 R2 (FIM)
    Supports installation on a Domain ControllerXX
    Supports installation using SQL ExpressXX
    Step-up from DirSync to AADSync


    Localization Windows Server languages)XCS
    Support for Windows Server 2008 and Windows Server 2008 R2XXX
    Support for Windows Server 2012 and Windows Server 2012 R2XX

    Filtering and Configuration

    Feature Azure Active Directory Synchronization Tool (DirSync) Azure Active Directory Synchronization Services (AAD Sync) Forefront Identity Manager 2010 R2 (FIM)
    Filter on Domains and Organizational UnitsXXX
    Filter on attribute values on objectsXXX
    Allow minimal set of attributes to be synchronized "MinSync"
    X
    Allow different service templates to be applied for attribute flows
    X
    Allow removing attributes from flowing from AD to AAD
    X
    Allow advanced customization for attribute flows
    XX