Dec 02

Windows Server 2016 Technical Preview 4 install and first boot

Here are two quick videos showing the install and first boot of Server 2016 Technical Release 4

Server 2016 Technical Review 4

Server 2016 Technical Review 4


number1This first video we install and boot to Core. Core is the default of the two options; Core or GUI. So, if you select all the defaults, you will have Core.



number2In this second video we install and boot to the GUI install.


Nov 24

4 videos to understand Windows Server Desired State Configuration (DSC) and FREE eBook

Desired State Configuration is a big part of most 2012 R2 certification tests; get an understanding from these 5 videos.

I have tried to arrange these in order; if you watch them in order, you should have a good basic understanding of DSC. It’s a very useful capability. The first two are approximately 1 hour each. DSC can do PUSH or PULL. Push would normally be ad hoc, test, or small needs. Most normal production use would be PULL.

Free eBook from The DSC Book

number1VIDEO 1

Time = 1:09
Description; Targeted somewhat to developers; or with a dev mindset. Give a good overview of the design, deployment and possible uses. Lots of groundwork explanation. .MOF (Managed Object Format) file creation and use. This is a classroom recording, so there is some live Q & A.

number2VIDEO 2 – DSC is the ENDGAME for PowerShell

Time = 1:04

Published on May 19, 2014

Description; Windows PowerShell 4.0 introduces Desired State Configuration (DSC), and it’s time to put it to use. With DSC, you declaratively tell computers what you want them to look like, and how you want them to be configured, and let DSC make it happen and KEEP that configuration enforced. In this session, you not only see how DSC works, but you will be introduced to custom resource development, letting you start teaching; DSC how to configure internal applications, databases, and other infrastructure elements.

number3VIDEO 3 – More hands on and examples

Time = 1:17

Published on Nov 9, 2014

Description; Are you paying attention to DevOps? Adoption of DevOps practices can greatly improve your company’s deployment efficiency. PowerShell Desired State Configuration (DSC) helps teams take the management of their Windows-based infrastructure into the DevOps space by capturing their infrastructure as code. The declarative PowerShell model enables autonomous, idempotent, and transparent configuration and deployment of Windows infrastructure and components. Capturing infrastructure as code is not only a means to manage what they have, at scale and speed, it is also a way to decouple the complexity of their existing environment in order to facilitate a migration to the cloud. Come see how DSC works and how you can use it to make configuration of internal applications, databases, and other infrastructure elements more efficient.


VIDEO 4 – Use Powershell DSC to install SQL Server

Time = :14

Published on Dec 18, 2014

Description; I briefly show how powershell DSC can be used to configure and deploy a brand new SQL Server installation.

Oct 11

Flashcard App sets for 70-410 PowerShell and ITIL

Flashcard Sets for ITIL and PowerShell for 70-410, 411, 412, 417

I have created two flashcard sets at, one for ITIL Foundations terms (remember, no acronym memorization is needed for Foundations test).

ITIL – 52 flashcards on the key terms and definitions.

70-410, 411, 412 and 417 PowerShell commands.

You can review these online, or you can download an APP to study them on your phone. The app is

Flashcard Machine ITIL and PowerShell sets

Flashcard Machine flashcards for ITIL and 70-410

called Flashcard Machine, and it’s FREE. To find my two flashcard sets search for these terms on;

ITIL – ITIL 2011 JL Key Service Management Terms (53 cards)

70-410 PowerShell – 70-410 JL PowerShell Commands (68 cards)

As you can see, I have “JL” in each title so you can make sure you’re getting my sets.

Sep 02

70-412 and 70-417 Study Guide List

Over the past few months I have posted a series of Study Guides targeted at 70-412, which would alsoServer2012TOC be useful for 70-417.  I want to put a hyperlinked Table of Contents here to show what order would be best to review them. These are study guides from the FREE Pluralsight training.



Here are the hyperlinks;

1) Configure Active Directory

2) Configure High Availability

3) Configure Network Services

4) Configure Continuity and Disaster Recovery

5) Configure File and Storage Solutions

6) Configure Identity and Access Solutions

Other useful links on this effort would be;

MCSA and Build a LAB

Server 2012 R2 – New Features of R2

Sep 02

Windows Server 2012 R2 (70-412) Identity and Access Solutions – Study Guide

Prepare yourself for the Microsoft MCSA 70-412 exam. This course explores how to implement an advanced DHCP solution, implement an advanced DNS solution, and deploy and manage IP Address Management.

These notes are my personal notes from the FREE training on Pluralsight. You can get your FREE signup through technet/MSDN or Dreamspark. The title of this course is exactly the title of this post. These notes are from this specific course only. I use these as a refresher Study Guide. POWERSHELL topics and2012GregShields cmdlets are in purple. I have a few notes with the “DEMO” each time the training included a DEMO just so you can see how many demos there were which were really helpful. Thanks to Greg Shields @ConcentratdGreg, the trainer, contact info at the end.


  1. Install and Configure AD Certificate Services. Essentially setting up internal certificate trusts to mirror, and and can negate the need for, external certificates like Microsoft, Verisign, etc.
    1. Install an Enterprise Certificate Authority
      1. The “issuing CA” creates the actual cert file. Issuing CA gets trust from Policy CA, who gets it from a Root CA
      2. Root is typically standalone, offline. Policy CA standalone or enterprise, typically online. Issuing CA typically enterprise online.
      3. Issuing CA is the one doing all the day to day work.
      4. Install CA ROLE, and the Online Responder ROLE2012CertificateServicesRoles
        1. optional web enrollment pieces, or can use the console to manage
      5. Post install configuration; configure active directory certificate services, requires member of local admins for some services, and Enterprise Admin for some.
      6. Decide what TYPE of CA you’re installing. 2012CertificateServicesRolePermissions
      7. Choose a NAME for the CA,  usually combination of server name, domain name. Choose validity period (default = 5 years)
      8. Certificate Templates – basic templates are provided, then when you fill them out with specific information it creates the actual certificate. Some are “available for issue” then there are dozens of additional ones that are not available for issue by default.
      9. refresh GP then root cert should be available through AD. certs are automatically trusted by any computer in the domain
      10. from a client, you can “request a new certificate”, and it automatically enrolls
    2. Configure CRL (certificate revocation list) Distribution Points
      1. when you need to manage expiration due to termination, employee leaving, new job responsibilities, etc.
      2. The CRL location shows up in the “details” tab on the actual cert
      3. set up CRL revocation list locations BEFORE passing out certs
      4.  you can’t delete crl revocations. Think about it, that makes sense.  But when the list gets really long there are ways to make the queries faster.
    3. Install and Configure Online Responder
      • Configure the Online Responder (which also needs a cert) OCSP response signing
      • Revocation Configuration for the Online Responder
      • Online responder downloads a copy of the CRL to make responses
      • enter the URL for the Online Responder in cert templates, and again have this set up prior to issuing any certs or you have to redo them all.
    4. Implement Administrative Separation
      1. Principle of Least Privilege
      2. Read this Technet on Role Based Administration
      3. In the security tab of the CA, set up the right permissions
      4. one additional command; PS certutil -setreg ca\RoleSeparationEnabled 1
    5. Configure CA Backup and Recovery
      1. right click, all tasks, back up and restore recommend private key and logs (checkboxes)
      2. certutil can also do backups (old way)
      3. now of course PS Backup-CARoleService
  2. Manage Certificates
    1. Enrolling for Certificates
      1. instead of “find cert” start with “request”
      2. From IIS, you can create request and complete request from wizard on the right side of IIS.
      3. Example using a PS code signing certificate
    2. Manage Certificate Templates
      Cert tabs
      Certificate Template Tabs
      1. right click / manage, see “code signing certificate”
      2. copy “duplicate” the template, then modify the new duplicate for  use
      3. publish certificate in AD checkbox
      4. compatibility settings
      5. choose encrypt/signature or both
      6. auto renewal can force a different private key
      7. WHAT this cert is going to be  used for is baked in the cert configuration. For this example signing PS, this would be “code signing”
      8. “subject name” is usually the FQDN of the webserver. In this case, we specify the user name for our PS signing cert.
      9. you can configure manager approvals or signatures prior to approval
      10. security tab; read, enroll, auto-enroll.
    3. Implement and Manage Certificate Deployment, Validation and Revocation
      1. now that the template is created, we talk about deployment, validation and revocation
      2. now you have to right click on Certificate Templates, choose new certificate to issue and find the newly created template to issue.
      3. revoke certificate from a right click on the cert. This is PERMANENT and not reversible. Note there is a “HOLD” that can be a temporary hold.
      4. force a CRL update by “publish CRL”
      5. new crl once a week, new delta crl once a day.
    4. Configure and Manage Key Archival and Recovery
      1. there is no default capability to archive keys
      2. archive when enabled happens in AD
      3. KRA Key recovery agent cert can recover keys
      4. copy and modify certificate template
      5. then you “enroll” for the KRA certificate
      6. two commands to recover
        1. PS certutil -GetKey
        2. certutil -RecoverKey
    5. Manage Certificate Renewal
      1. manual non-GPO renewal
      2. in Certificate console, right click on template, “re-enroll all certificate users”
    6. Manage Certificate Enrollment and Renewal to Computers and Users using Group Policy
      1. to auto populate our PS code signing certificate, assigned to our IT group
      2. GPMC, new GPO
      3. user side, public key policies
        1. need certificate enrollment (AD)
        2. auto-enrollment (enable)
        3. auto-renewal   /log expiry events, other options
        4. auto renewal is 80% of cert lifespan, or the expiry of the renewal period
      4.  testing on machine, log in, gp runs, check for PS Signing cert
    7. Configure and Enroll a Hyper-V Replica Certificate
      1. If you choose replication in Hyper-V and select “encrypt”, then it will error as there is no dedicated custom cert
      2. copy and rename a “Computer” template
      3. then make it available for use
      4. now when you go back to Hyper-V Manager it shows up.
  3. Install and Configure AD Rights Management Services
    1. Install a Licensing or Certificate AD RMS Server
      1. RMS servers are referred to as “cluster”, just meaning multiple servers. You can also do a single server cluster. You need to be Enterprise Admin to complete this setup.
      2. If you go to a document on File Server, you go to “protect document” then  “restrict access” to connect to RMS and “get templates”. Will error if you have no RMS set up.
      3. Install Active Directory Rights Management Server ROLE.
      4. Post install configuration is required (yellow alert top right of Server Manager)
      5. RMS is tied to email field in AD properties general/email field. Even if you don’t have email in reality it just pulls from that field.
      6. Store RMS Cluster Key (keep this), password, website.
      7. For location, suggest CName instead of FQDN so you can adapt in the future if the hardware changes.
    2. Manage AD RMS Service Connection Point
    3. Manage RMS Templates
      1. Rights Policy Templates determine what/how you are going to offer to your users.
      2. example; content that Finance group needs to protect
      3. Name policy “Finance Protected Content”, add description.
      4. Tied to the email associated with the finance security group, and you can choose what they can do. Lots of rights / actions, and you can create custom ones as well. view/edit/save/print/save/save as/etc.
      5. you can disallow client side caching; they would have to be online to access the data
      6. define revocation policy; when you revoke the license, you revoke the ability to access that policy, you also provide a url where the policy resides.
    4. Configure Exclusion Policies
      1. you can determine  “Lockbox version exclusion” which is pretty bizarre, read about it on the link.
    5. Backup and Restore AD RMS
      1. what do you have to include in backups?
      2. Configuration DB, directory services DB, logging DB. Either in SQL or the Windows server internal SQL. The internal SQL requires a full server backup. So, from a backup perspective it’s better to use SQL.
      3. server certificate needs to be backed up
      4. cluster key password
      5. export trusted publishing domain
  4. Implement AD Federation Services – focus seems to be on Workplace Join
    1. Configure Workplace Join
      1. understanding Federation
        1. Traditionally, access is controlled by a user ID and login. Or, from AD permissions.
        2. Federation is used when access needs to be provided to users OUTSIDE of your domain. (Partner, merger, acquisition, etc.)
        3. Federation servers handle the federation process between organizations. It’s kind of a bridgehead or gateway for the access request/granting. It does this by generating “claims“.
        4. Relying Party (us) and Claims Provider (them)
        5. This happens from a pair of Trusts from each direction; Claims Provider Trust and Relying Party Trust.
      2. Think also for BYOD situations for non-domain joined devices. Device itself is added to AD.
      3. Typically connect through Web Application Proxy (not on the 412 test)
      4. Settings / network / “workplace” is where you see it.. on your desktop, not the server.
      5. Create a Group Managed Service Account.
      6. Create a certificate for AD FS
        1. domain computers needs to have enroll privileges
        2. Enroll from your AD FS server
        3. This will require entering additional information to enroll the cert; hostname, DNS name, etc.
        4. For non-domain devices, it’s a lot easier if you use a public cert, for access and CRL access which is open to non-domain users on the internet.
    2. Install AD FS
      1. Now create ADFS, create the first server in a federation server farm.
        1. associate to cert
        2. name it, add display name
        3. add service account (use an existing account)
        4. SQL or internal database.
        5. finalize the wizard. now you should be the Relying Party Trust.
    3. Implement Claims based Authentication including Relying Party Trusts
      1. in AD FS console, look under Relying Party Trusts to see the claims options.
    4. Configure Authentication Policies
      1. from PowerShell
        1. Initialize-ADDeviceRegistration
      2. Back in console, enable device authentication in the global policy
      3. This is just using “windows authentication” instead of Forms based, or other options.
    5. Configure Multi Factor Authentication
      1. This is a Authentication Policy in the console
      2. registered/unregistered, intranet/extranet
      3. now test Workplace Join from desktop. You just click “join” and it’s joined. Button changes from “join” to “leave”.


Sep 01

FREE ebook 70-409

VEEAM is offering a FREE ebook on the Microsoft 70-409 certification; Server Virtualization with Windows Server Hyper-V and System Center. This book is by @orinthomas ( who is a great IT author and trainer, I’ve used a lot of his material. You could study this book, online resources, and use the Second Shot to pick up this cert. Here is the link to the download page on VEEAM;

Jul 15

List of FREE courses on Pluralsight

Course subscriptions

Jul 11

Windows Server 2012 R2 (70-412) Continuity and Disaster Recovery – Study Guide

Prepare yourself for the Microsoft MCSA 70-412 exam. This course explores how to implement an advanced DHCP solution, implement an advanced DNS solution, and deploy and manage IP Address Management.

Videos at the bottom (WinRE)

These notes are my personal notes from the FREE training on Pluralsight. You can get your FREE signup through technet/MSDN or Dreamspark. The title of this course is exactly the title of this post. These notes are from this specific course only. I use these as a refresher Study Guide. POWERSHELL topics and2012GregShieldscmdlets are in purple. I have a few notes with the “DEMO” each time the training included a DEMO just so you can see how many demos there were which were really helpful. Thanks to Greg Shields @ConcentratdGreg, the trainer, contact info at the end.

All, or nearly all, sections include DEMOS so I’m not notating that separately.2012TrainingRecommendedOrder

These training courses should be preferably taken in this order (screenshot).

  1. Configure and Manage Backup Solutions
    1. Configure Windows Server Backups FEATURE
      1. Compared to NT backups, this focuses on VOLUMES.
      2. Pretty fully featured technology today.
      3. If you want to do Bare Metal backups, you need to check that along with System State, System Reserved, and probably the C or OS drive.
      4. Advanced settings
        1. excluded files
        2. VSS settings
          1. copy vs. full (are you using some other backup application, if so you use COPY)
      5. Destination
        1. local volume
        2. remote shared folder
        3. Optimize backup performance = types of backups (full, incremental, etc.)
      6. POWERSHELL WB = Windows Backup
      7. Get-WBJob
      8. Stop-WBJob
      9. Get-WBVSSBackupOption
    2. Configure Azure Backups
      1. designed to just get a back up into the Cloud
      2. Create “Backup Vault” tied to subscription and choose location
      3. Download Vault credentials, and download and install Azure Backup Agent
      4. Is now called MICROSOFT Azure Backup NOT Windows Azure Backup
      5. set up encryption; Microsoft cannot recover data
      6. Azure looks almost the same as a Windows backup. File and folder; just data, not system restore.
    3. Configure role-specific backups
      1. Backup Operators is the default, maybe too many permissions for many cases; can shut down system.
      2. Create your own role for backup files and directories and restore files and directories
    4. Manage VSS settings using VSS Admin
      1. extended from original design (previous versions for users) to now include backups (quiescence)
      2. VSS writer (specific by vendor for the application, Exchange, Oracle, AD, SQL, etc.
      3. the VSS requester is the partner to the writer
      4. PS vssadmin list writers
      5. vssadmin list providers
      6. vssadmin add shadowstorage /for=c: /on=f: /maxsize=20% set location for VSS
      7. vssadmin create shadow /for=c:     create vss shadow copy, very quick nearly instantly
      8. vssadmin can remove, revert, etc.
  2. Recover Servers (restore)
    1. individual file or folder recovery
      1. backup from – choose location, then choose files and folders (other choices volumes, applications, system state, or virtual machines)
      2. can put back in same, or different location
    2. Bare metal server recovery
      1. boot into WINRE (WINdows Recovery Environment) and also here; Tom’s Guide; when to use RE
        1. one option is to use shutdown command shutdown /r /o /t 02012NewShutdownSwitches (Check out Windows 8 new shutdown switches here)
        2. the /o is a new switch
        3. This is a gui based windows recovery console. Allows you to find the system image, install drives, connect to network locations to find image. Do you want to repartition drives.
        4. Don’t even need DVD media.
        5. Here is a link to a video of the WINRE console.
        6. The F8 replacement is WINRE
        7. msconfig – set what startup you get for NEXT boot to boot into safe mode, AD repair, etc. In case boots are so fast you can’t see F8
        8. you can also boot to windows DVD
        9. From WINRE you can boot to command prompt view, and you can manipulate unmounted drive (OS is not mounted). You can tell because command prompt is on the X drive which is the WINRE OS
          1. startrep (start repair scan)
          2. bootrec (boot record repair) Fixmbr, Fixboot, ScanOS, RebuildBcd
          3. Advanced boot options (looks like the F8 options)
            1. safe mode, with networking, with command prompt, boot logging, debugging, low-resolution video, last known good, disable restart, disable early launch anti-malware etc., etc.
        10. Configure the boot configuration data store
        11. multi boot menu to offer recovery options (not multi os boot)
          1. bcdedit
          2. bcdedit /export c:\save (export and save config)
  3. Configure site level fault tolerance
    1. Configure Hyper-V Replica, including Replica Broker and VMs
      1. Replica is NOT failover clustering
      2. provides a way to keep another copy of VM files (usually at remote site)
      3. Replica CAN work with failover clusters
      4. Replica is NOT OS specific; you can set it up with just shell VM, no OS to prove it
      5. Kerberos – not encrypted traffic, requires trusted AD
      6. certs – encrypted, no trusted domain needed
      7. set up on each VM individually
      8. configure frequency
      9. can also set up scheduled recovery points
      10. VSS for application consistent recovery points
      11. you can do the initial replication via external media, network, choose other machine, etc.
      12. set failover TCP/IP
      13. on the TARGET location server there is “test failover” under network adapter in Hyper-V Manager
      14. PLANNED failovers all start from the SOURCE location
      15. UNPLANNED start from Destination location (thought is that the source location is down, or offline)
      16. Adding Replica to Failover Cluster, need to
        1. Need to add the Hyper-V Replica Broker ROLE
    2. Configure Multi Site Clustering, including network settings, Quorum, and Failover Settings
    3. Configure Hyper-V Replica Extended Replication
      1. create a second replication site
      2. this is initiated from the TARGET location of the original source.
      3. most other stuff is the same
    4. Configure Global Update Manager
      2. When a state change occurs such as a cluster resource is taken offline, the nodes in a failover cluster must be notified of the change and acknowledge it before the cluster commits the change to the database. The Global Update Manager is responsible for managing these cluster database updates. In Windows Server 2012 R2, you can configure how the cluster manages global updates. By default, the Global Update Manager uses the following modes for failover cluster workloads in Windows Server 2012 R2:
    5. Recover a Multi Site Failover Cluster
      1. make sure you can support the IP and network configuration in the failover site
      2. same Cluster Manager is used to manage stretch (multi site) clusters
      3. configure preferred owners to deselect the DR site
      4. QUORUM
        1. node and file share is preferred
        2. even number of hosts per location preferred
        3. Force start without a quorum;
Jul 11

Installing Hyper-V Role in VMware Workstation; error Hyper-V cannot be installed: A hypervisor is already running

This quick post and video shows how to get past the Hyper-V cannot be installed: “A hypervisor is 2012HyperVErroralready running” error when trying to install the Hyper-V Role on a server running as a VM on VMware Workstation. This is common in a virtual lap scenario for certification study.

To resolve this issue, change the guest OS type to Hyper-V.Caution: Hyper-V functionality inside VMware Fusion is experimental and is unsupported.To change the guest OS type to Hyper-V:

  1. Shut down the virtual machine.
  2. Click Virtual machine > Settings.
  3. Select General and change the guest OS type to Hyper-V (unsupported).
  4. Select Processors & Memory in the Settings.
  5. In the Advanced options of Processors & Memory, select Enable hypervisor applications in the virtual machine
  6. Reboot the virtual machine to enable Hyper-V.

The video is here

Jun 27

Windows Server 2012 R2 (70-412) Configure Network Services – Study Guide

Prepare yourself for the Microsoft MCSA 70-412 exam. This course explores how to implement an advanced DHCP solution, implement an advanced DNS solution, and deploy and manage IP Address Management.


These notes are my personal notes from the FREE training on Pluralsight. You can get your FREE signup through technet/MSDN or Dreamspark. The title of this course is exactly the title of this post. These notes are from this specific course only. I use these as a refresher Study Guide. POWERSHELL topics and2012GregShieldscmdlets are in purple. I have a few notes with the “DEMO” each time the training included a DEMO just so you can see how many demos there were which were really helpful. Thanks to Greg Shields @ConcentratdGreg, the trainer, contact info at the end.

All, or nearly all, sections include DEMOS so I’m not notating that separately.


  1. Implement an Advanced DHCP Solution
    1. Create and configure superscopes and multicast scopes
      1. superscopes – combine multiple DHCP scopes to have broader range of addresses
      2. initial subnet didn’t have enough addresses
      3. when you run out of addresses;
        1. define by geographical location; floor, building, city, etc.
        2. assign multiple network IPs to router (downside is network admin involvement)
        3. DHCP RELAY – we’ve been there…allows DHCP traffic to cross router
        4. DEMO
          1. In DHCP, create superscope, then add multiple scopes to it
          2. Multicast scope –
            1. create Multicast scope, pick start/end IP, set TTL
            2. unlikely would be allowed on most modern networks
            3. most common use is WDS or other desktop deployments
    2. Configure DHCP filters and policies
      1. nodes in DHCP mmc
        1. filters; allow or deny by MAC
        2. then have to “enable” by checkbox
        3. can set exemptions
        4. Policies; what options will the managed machines get
          1. vendor class
          2. MAC
          3. FQDN
        5. Then set what treatment those hosts that fit the policy actually get
    3. Implement DHCPv6
      1. Not a lot of real world use yet
      2. NOT very simple
      3. built into IPv6 can auto assign anyhow. Don’t believe it read this article…IPv6 address autoconfiguration
      4. This would be used for anything beyond what the protocol can do.
      5. CANNOT assign a default gateway
      6. CAN assign most other options
      7. NOT really needed for auto assignment, more used for address control
      8. DEMO
        1. click on IPv6, right click “new scope”
        2. etc. pretty much like IPv4
        3. beware of test questions about WHY you would use it.
    4. HA for DHCP – failover and split scopes
      1. split scopes (the old way)
        1. 80% / 20% is the most common (I’m sure I’ve seen test questions that said that was wrong though).  Well the 80/20 split scope is Microsoft best practice see here.
        2. Can be messy recovering from a server outage; the DHCP databases don’t know anything about what the other one is doing.
      2. DHCP Failover
        1. one DB
        2. can use 100% of scope
      3. DEMO
        1. split scopes (split scope configuration wizard)
        2. DHCP Failover
          1. per scope
          2. “Configure Failover”
          3. set load balance or hot standby and some other settings
          4. you can enable message authentication via shared secret
          5. Configure DNS registration, can discard as well
    5. DHCP Name Protection2012DHCPNameProtection
      1. mainly for non-windows computers (screenshot)
      2. prevents non-windows from registering a name that is already in use.
    6. DNS Registration
        1. Configure DNS registration, can discard as well
  2. Implement an Advanced DNS Solution
    1. Configure Security for DNS, including DNSSEC, DNS Socket Pool, and Cache Locking
      1. DNSSEC does not necessarily require certs.
      2. To enable you “sign” the zone.
      3. Key Master is the authoritative DNS server that generates and manages the key for the zone.
      4. when you create the new key, then you have all kinds of options
      5. Needs to be AD integrated zone
      6. KSK – Key Signing Key and ZSK – Zone Signing Key
      7. Trust Anchor (for authenticating non-authoritative server
      8. Then GP is used to tell clients to ask for the DNS key
      9. “name resolution policy”, checkbox for enable DNSSEC
      10. create rules to determine who it applies to
      11. DNS Socket Pool (in response to Kaminsky attack DNS vulnerability)
        1. randomizes the SOURCE PORT to not be using TCP/53 and UDP/53
        2. enabled by default, but you tweak settings like number of ports
        3. DnsCmd /config /socketpoolsize 100000
        4. DnsCme /info /socketpoolsize
      12. Cache Locking
        1. Locks cache after update in cache.
        2. cannot be overwritting by a percentage of TTL
        3. default is 100% of TTL
        4. DnsCmd /config /cachelockingpercent 50
    2. Configure DNS Logging
      1. two places it can be configured depending on what you want
      2. event logging (1)  goes into event logs
      3. debug logging (2) goes into file
    3. Configure Delegated Administration
      1. under “security” tab
      2. for you to delegate activities, you MUST have AD integrated zone (test question?)
    4. Configure recursion
      1. disabled by default
      2. servicing servers outside your network
      3. should be ON on external server to prevent DNS attacks
    5. Configure Netmask ordering
      1. common use – WSUS
      2. essentially allows DNS server give a client an address that corresponds to the subnet that they are in. For traveling users.
      3. First response goes to server with same subnet
    6. Configure Global Names Zone
      1. for needs that used to be handled by WINS
      2. short name resolution
      3. create a zone called “GlobalNames”
      4. will contain short names
      5. you have to explicitly enable on all DNS servers
      6. dnscmd servername /config /enableglobalnamessupport 1
    7. Analyze Zone level statistics
      1. Get-DNSServerStatistics -zonename company.local
      2. DNSLint
        1. graphical display of internal/external on .htm file
        2. dnslint 
  3. Deploy and Manage IP Address Management – IPAM
    1. Provision IPAM via manual or GP
    2. IMPORTANT NOTE: to change  the IPAM provisioning method (like from manual to automatic) you must UNINSTALL and REINSTALL!
      1. install FEATURE
      2. configure from Server Manager
      3. choose database (internal or SQL)
      4. GPO Name prefix (manual configuration of IPAM is tedious and not recommended)
      5. run PS command Invoke-IpamGpoProvisioning -Domain ….creates the Group Policies and links them.
      6. Run IPAM server discovery
      7. Choose the ones you want and set them to managed.
        1. managed servers need to show up in “security filtering’ box on the GPO
        2. machine has to receive and apply the GP before it shows as “unblocked” and “managed”
        3. IPAM is more of a “push” instead of pulling in existing IP use
        4. IP Address block
          1. 1 or more IP ranges
        5. Add address range (block of IPs or open range that IPAM can use)
        6. can add reservations and VIPs
        7. along with normal DNS, gateway and other information
    3. Configure server discovery
    4. create and manage IP blocks and ranges
    5. migrate to IPAM
      1. tasks / import IP addresses (imports from .csv). certain mandatory columns for IPAM imports – IPAddress,IPAddressState,AssignmentType,ManagedByService,ServiceInstance,AssetTag
    6. monitor utilization of IP address space
      1. lirrlw pie chart by each range, can be adjusted for the entire server
    7. delegate IPAM administration
      1. there is an “ACCESS CONTROL” link on the very bottom left to set up roles and access.
      2. several default roles but you can create your own customized roles and set the policy settings
    8. Manage IPAM collections
      1. request new addresses (fine and allocate) “find next”
      2. RECLAIM ip addresses that are no longer used, delete resource records and DHCP reservations if exist.
      3. EVENT CATALOG – log viewer of IPAM events
      4. ADDRESS RANGE GROUPS – group by custom fields you defined during IP creation
    9. configure IPAM database storage
      1. PS Move-IPAMDatabase (moved internal IPAM DB to SQL if you want)
      2. lots of IPAM powershell commands (automation possibilities)