SBS, SMB, SME, Hyper-V Failover Clusters, Technology, System Builder Tips, views from the I.T. Trenches, and more.
Thursday, 9 October 2008
Yet another sour Trend call ...
We did an upgrade for a client in the early spring and suggested switching from Symantec to Trend. They willingly went ahead trusting our judgement.
Well, after just getting off the phone with them because there were more malware problems at their site, we have dropped a few pegs on the trust ladder ... again due to Trend. The conversation with the partner was not a happy one ... as they are completely unimpressed with the Trend A/V product relative to their solid Symantec experience for the last 10 years.
So, we are about to initiate a new Symantec Multi-tier Protection Small Business Edition with the Essential Maintenance 24x7 support and upgrades for 1 year for all of their seats at our expense.
We will then download the Symantec product, uninstall Trend on all of their workstations and servers and install the Symantec product on all of their workstations and servers and configure it to run at our own expense.
Needless to say, I am pretty choked with Trend right now ... as is one of our best and longstanding clients.
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
SBS - Adding Software Assurance to OEM or Retail SBS R2 Premium
- Purchase OEM SBS 2003 R2 Premium with new hardware: T75-02110
- Note that OEM for SBS 2003 must be purchased with new hardware and remains tied to that hardware (motherboard) for its life with no Software Assurance attached.
- OR
- Purchase Retail Fully Packaged Product sBS 2003 R2 Premium: T75-01255
- THEN
- Purchase Software Assurance on SBS 2003 R2 Premium: T75-00935
- Open Value Agreement with 3 year spread payment purchased in year 1.
Realistically, OEM would be the best route to go since adding Software Assurance unbinds that OEM license from the hardware and enables us to move that OS to new hardware if and when the time comes to upgrade it. The license becomes ours.
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
Wednesday, 8 October 2008
The one and ONLY reason to never have TS port 3389 open!
A TSGrinder like tool put the kybosh on a huge project we were working on years back due to the risk factor and the number of sniffs and subsequent attempts against the TS box.
If Terminal Services is needed, then the Remote Web Workplace is the cat's meow. A direct link in RWW to the "Application Server" means users will pick up quickly where they need to click.
SSL security, with the ability to provide another tier of security in AuthAnvil tokens means that Terminal Services will be that much more secure.
And, with the advent of SBS 2008 and TSApps, the RWW integration scenarios just keep growing!
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
Tuesday, 7 October 2008
SBS 2008 - Windows SBS Console Tasks behaviour
From there, it is time to get to know the new Windows SBS Console.
When we click on the Users Tab at the top of the console, we are greeted with a list of users and a set of tasks along the right hand side of the console:

Windows SBS Console - Users Tab
The tasks very from SBS Wizards to links to information about the tasks.
When we click on one of the users in the user list, the Tasks section changes to display user specific tasks as well as the default tasks:
User Specific Tasks on top of the default User Tasks
Note that the title for the user specific tasks indicates the user that would be impacted by any changes made.
The item specific tasks will always appear on top of the original default tasks. There is a kind of sliding motion effect just after clicking on an item to reveal the specific tasks.
This behaviour will happen in any of the specific management sections of the SBS Console after clicking on something in one of the lists.
Click and explore! :D
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.


SBS 2008 - Kewl Wizard - Add a new user role based on user properties
Some of the things we worked out on SBS 2003:
- SBS domain with multiple e-mail domains had a User Template named and designated for each domain. Run the Add User Wizard and choose the DomainA.com User Template and that would be the user's UserName@DomainA.com e-mail address. This tied into custom LDAP queries via Exchange Recipient Policies, Group Policy, and Security Group membership.
- Custom share permissions assigned via User Template and tied into Access-Based Enumeration.
- Custom OUs for particular workstation and user setups via the Add Computer wizard.
Things have changed a bit for SBS 2008:
Add a new user role based on the User's properties
The new Add a new user role based on the User's properties wizard that takes all of the customizations that we can do with a test user account and create the new User Role (SBS 2003: User Template).
How kewl is that?!? :)
Once we have our User Role created, we can go on to add any new users based on it, or run the Change user role for user accounts wizard to change existing user's profiles.
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.


Monday, 6 October 2008
Dell RAID - PERC 6/i and 6/E - Still No Audible Alarm!
Our experience: SBS on Dell with PERC5i drive failure and DIY where a new client had their entire business on the line with one failed RAID 1 array member and no indication other than a blinking yellow light inside a server cabinet to indicate a problem.
Eriq has now brought up that the PERC 6 series also have no audible alarm on it: On 18 months.
One generation of RAID controllers in the PERC 5 series with no audible alarm is forgivable as an engineering oversight.
But, to engineer a whole new generation of RAID controllers without any way to indicate there is a problem?
Deal with Dell server product? Then, click here to help support Eriq's call to bring audible alarms back to Dell RAID controllers on Dell's site IdeaStorm: Bring Back the Audible Alarm on RAID controllers.
Depending on how the management software does or does not interface with the RAID controller to hopefully fire off an e-mail if an array member fails, we would be very wary of any Dell server products at a client site as a result of this. In the case of the PERC 5 series, no e-mail capabilities whatsoever.
So, if that is the case on the PERC 6, good backups are an absolute must. Not that they should not be in the first place!?!
Tested your client backups for recoverability lately?
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.


Microsoft SPLA - Huge changes happening
There is a lot to digest here folks. Take the time to read through and get in touch with your SPLA contact to get any further questions answered.Announcing the Launch of a New Version of SPLA
Beginning October 1st, a new version of the Services Provider License Agreement (SPLA) will launch. There are several changes under the new version and we are highlighting the main points here. Please refer to the SPLA section within the Microsoft Partner Portal for more details.SPLA version 2008 Agreement Launch Details
1. SPLA Agreement Moving Under the MBSA
2. Downloads available to all SPLA partners
3. Three-year commitment offering to launch in early 20091. SPLA Moving Under the MBSA
- Beginning with SPLA 2008, the Service Provider License Agreement (SPLA) will be linked to a Microsoft Business and Services Agreement (MBSA/MBA). The MBSA/MBA is a perpetual agreement between the customer and Microsoft that contains high-level terms and conditions that are applicable to all agreements signed under it.- SPLA partners who have an existing MBSA/MBA via another Volume Licensing agreement (EA, ESA, Select Plus, Select, or ISV) should work with their Account Manager and/or reseller to link the MBSA/MBA to their SPLA agreement. You will simply need to provide your MBSA/MBA number the next time you sign a SPLA agreement.
- SPLA partners without an existing MBSA/MBA will be required to sign one the next time you sign a SPLA agreement. The MBSA will automatically be included in your next SPLA packet.
Benefits:
- MBSA/MBA offers evergreen terms and conditions- Once an MBSA is in place SPLA partners will only need to sign a shorter and simplified SPLA agreement every 3 years
- Partners can use existing MBSA/MBAs - simple process to link to SPLA
- It will be easier to acquire the required support from Microsoft as the MBSA includes the ability to purchase Premier and Professional support
- The MBSA/MBA can be used for additional purchasing opportunities with Microsoft
2. Downloads available to all SPLA partners
- Beginning October 23rd, all SPLA partners will have the ability to download products via the Microsoft Volume Licensing Services (MVLS) site as an alternative to purchasing media from the pricelist. SPLA partners will receive a welcome communication (via email) which will provide instructions on how to set up an account and access MVLS. This communication will be sent to your "notices" contact and 'electronic notices' contact identified on your SPLA agreement.Benefits:
- No-cost option for media
- No longer have to wait for media to be delivered - download option also makes products available closer to the time of launch
- MVLS currently supports 24 languagesSPLA Partner Guidance for Using MVLS
- SPLA partners are free to explore the site but should be aware that MVLS has not yet been modified for SPLA partner usage - the main functionality being delivered today is the ability to access downloaded media.- Things to be aware of:
* SPLA agreement will not be displayed on the MLS (Microsoft Licensing Statement) however, the agreement detail will be available on MVLS (please note that it has not been customized specifically for SPLA partners).
* Volume License Keys will not be available in MVLS. SPLA partners will continue to contact the Call Center for their Volume License keys.
- A guide for partners (including screenshots) will be posted on the MSPP SPLA page - 'Training Resources' tab on or after Oct 1st.
3. 3-year commitment offering to launch in early 2009
- The 3-year commitment offering will feature the addition of SKUs that will allow service providers to commit up-front to licenses for certain products and receive a 12% discount - with no minimum purchase quantity required.- Partners can combine 3-year commitment and monthly SKUs purchases within the same SPLA agreement.
- 3-year commitment offering is billed with up-front annual payments; there are no true-ups or true-downs.
- This 3-year commitment offer will be available in early 2009; more information will be presented prior to the availability of this offer.
Benefits:
- Great option for SPLA partners with stable infrastructures, long-term commitments with customers and/or the ability to pay up front each year.SPLA Changes to Align with Microsoft Online Services
Additionally, on July 8 2008, Microsoft announced there will be changes to SPLA, as highlighted at Microsoft Worldwide Partner Conference, to bring pricing and use rights in line with Microsoft Online Services. This will enable valued SPLA partners to deliver similar offerings, while differentiating their services to meet the diverse needs of customers. In anticipation to the upcoming launch of the Microsoft Online Services in the United States here is an overview of the changes being made to the SPLA program.What's Changing:
- A business productivity suite subscriber access license (SAL) will be added to the SPLA to provide an equivalent to the Microsoft Online Services Suite offering. The new SAL will include:* Exchange Standard
* Microsoft Office SharePoint Server (MOSS) Standard
* Office Communications Server (OCS) Standard
* Live Meeting Standard
- A discounted SAL for Software Assurance (SA) will be added to allow purchasing of discounted SPLA SALs if end customer owns Software Assurance on server Client Access Licenses (CALs ) in Volume Licensing (VL).
- Messaging Application Programming Interface (MAPI) network protocol will be included in the Exchange Standard SKU. Now Exchange Standard includes MAPI functionality, whereas before Standard Plus or Enterprise Plus were required for full MAPI functionality even if the end customer had Outlook. As a result the following restriction text will be removed from the SPUR:
"Restriction on use. Only users for whom you obtain an Exchange Server 2007 Hosted Exchange Standard plus SAL or Exchange Server 2007 Hosted Exchange Enterprise Plus SAL may use the Messaging Application Programming Interface (MAPI) network protocol to access and use the server software."
- Microsoft Office SharePoint Server (MOSS) Standard, Office Communication Server Standard, and Office Communication Server Enterprise SAL will be discounted.
Contact
If you have a direct agreement with Microsoft, please contact your Microsoft Account Manager for details. If you have an indirect agreement, please contact your SPLA reseller for additional details or questions.
And, for those of us who had Ingram Micro Canada as our primary SPLA contact, we are even further out of touch as our SPLA contact there bailed a while back and everything has been up in the air with them since then. :(
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
150GB Raptor AHFD Series with clear view panel ...
Until a regular ADFD series died and the only RMA drive we could get back from WD was the AHDFD series.

150GB WD AHFD Series with see-through top
It is pretty neat to see the internals of the drive working after first plugging the drive into a live system via USB.
While waiting for a command from the system, the heads sit right in the centre of the platters given them a 50/50 placement for the quickest access to the outside edge or inside edge of the platters.
Once the drive was initialized, we ran a full format to NTFS and the heads do indeed slowly work their way across the platters from the outside to the inside.
If ever you wanted to know exactly how a drive works internally while processing the various storage commands from a system, this is definitely the way.
Note the warning that accompanies the drive to very careful around the Plexiglas ... to the point that the warranty is void if the cover is damaged in any way.
Neat idea, but not the most practical. :)
This series will probably be a one-off with the advent of the small form factor VelociRaptors that outperform their older siblings by a huge margin ... and do not have the cover real estate to allow for a view port of some sort.
And, there is probably nothing too attractive running under the hood of the new Solid-State Drives either. ;)
Definitely a 10 on the geek kewl factor scale though. We are glad to have had one here to check it out.
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
Saturday, 4 October 2008
SBS - Event ID 537 NTLM Logon Errors Solved - Sorta
Robert Crane has the fix: Login errors after Trend upgrade.
As per the comments also in our above post:
- In ADUC: Create a new User: Trend and set password: 0hReally?
- Add the user to Internet Users for SBS 2003 Premium to allow access through ISA.
- Set the username and password to Trend's Web Reputation proxy settings.
The errors should stop. The big thing is to make sure that both the user name and password do not combine to more than 14 characters. We cannot even do this: domain\Trend since the domain characters will also count.
We have all seen all manners of code slip by with some pretty funky bugs. This has to be one of the better ones to have slipped by the "quality control" people over at Trend.
For us, this situation, the lack of support, and the fact that one of our clients who was virus free until we installed Trend A/V on their systems pretty much puts the final nail in the coffin.
We will go back to Symantec for the time period between now and when our clients have SBS 2008 installed. From there we will run with ForeFront and Live OneCare on SBS 2008.We are also in the process of proposing ExchangeDefender to all of our clients too. It is a very minimal cost per month, provides great protection for all incoming and outgoing e-mail, and provides a little extra monthly revenue for us.
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
Friday, 3 October 2008
A tired Papa...

Jean-Luc and a tired Papa
All is well in the Elder household with Monique pretty much at 100% and Jean-Luc eating, sleeping, and seemingly growing like crazy!
Thank you all for the well wishes, cards, flowers, and gifts.
Off to Tim's for more Rocket Juice! ;)
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
Thursday, 2 October 2008
SBSC Canada gets a new blog...
He took over for Kim Harrison who was the person to get SBSC going here in Canada. She did an absolutely phenomenal job building SBSC ... so the bar is quite high.
So far, Satish as done a very good job picking up the reins from Kim by demonstrating a keen interest in further developing the SBSC program in Canada and reaching out to us in the SBSC.
Now, in addition to all that he has done since taking over, he has started a blog here: SBSC Canada.
For SBSC Canucks, this is one for your RSS Reader and for anyone who wants to keep an eye on SBSC in Canada, your readers could do with a subscription too!
Way to go Satish! We look forward to hearing from you.
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
SBS and EBS OEM Part Numbers
- EBS Prem CAL OEM
- 7AA-00078: Win Esntl Bus Prem CALSte 2008 English 1pk DSP OEI 20 Clt Device CAL
- 7AA-00056: Win Esntl Bus Prem CALSte 2008 English 1pk DSP OEI 20 Clt User CAL
- 7AA-00067: Win Esntl Bus Prem CALSte 2008 English 1pk DSP OEI 5 Clt Device CAL
- 7AA-00045: Win Esntl Bus Prem CALSte 2008 English 1pk DSP OEI 5 Clt User CAL
- EBS Prem OEM
- 6ZA-00032: Win Essntl Bus Svr Prem 2008 English 1pk DSP OEI CD/DVD 1-4CPU 5 Clt
- EBS Std CAL OEM
- 6YA-00078: Win Essntl Bus CAL Ste 2008 English 1pk DSP OEI 20 Clt Device CAL
- 6YA-00056: Win Essntl Bus CAL Ste 2008 English 1pk DSP OEI 20 Clt User CAL
- EBS Std OEM
- 6XA-00068: Win Essntl Bus Svr Std 2008 English 1pk DSP OEI CD/DVD 1-4CPU 5 Clt
- Windows Small Business Server 2008 Standard and CALs
- T72-02453: Windows Small Bus Svr Std 2008 English 1pk DSP OEI DVD 1-4CPU 5 Clt
- 6UA-00601: Windows Small Bus CAL Ste 2008 English 1pk DSP OEI 1 Clt Device CAL
- 6UA-00582: Windows Small Bus CAL Ste 2008 English 1pk DSP OEI 1 Clt User CAL
- 6UA-00563: Windows Small Bus CAL Ste 2008 English 1pk DSP OEI 5 Clt Device CAL
- 6UA-00544: Windows Small Bus CAL Ste 2008 English 1pk DSP OEI 5 Clt User CAL
- Windows Small Business Server 2008 Premium and CALs
- T75-02475: Win Small Bus Svr Prem 2008 English 1pk DSP OEI DVD 1-4CPU 5 Clt
- 6VA-00601: Win SBS Prem CAL Ste 2008 English 1pk DSP OEI 1 Clt Device CAL
- 6VA-00582: Win SBS Prem CAL Ste 2008 English 1pk DSP OEI 1 Clt User CAL
- 6VA-00563: Win SBS Prem CAL Ste 2008 English 1pk DSP OEI 5 Clt Device CAL
- 6VA-00544: Win SBS Prem CAL Ste 2008 English 1pk DSP OEI 5 Clt User CAL
For now, we are still working with the Open Value Agreement setup for our new and existing clients. Open Value Licensing still presents the best value for our clients over OEM especially for the ones that refresh their server setups every two years.
OEM does not make sense when we take the two year old SBS server that was licensed OEM and now need to license a Windows Server 2008 Standard OS which cannot be "relicensed" with an OEM license. It ends up costing our clients a lot more in the long run.
Both OEM and Open Value Licensing offer downgrade rights, but only the Open Value Licensing gives us the ability to transfer that license to another server.
The other benefit to Open Value is the ability to spread the costs over 3 payments. OEM is all upfront.
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
SBS - Event ID 537 NTLM Logon Errors - 0x80090308 and Trend
The e-mail support was horrendous. Unfortunately, things did not work out at all.
From there, an escalation was made and we were put in touch with B. who was somewhat helpful via telephone ... though her script only went so far before we were asked to send the entire server log set to Trend.
We have not heard back since ... though it has only been since late last week.
Here is our initial post on the problem from July: SBS - Trend Worry Free Business Security Event ID 537.
We have been hearing from others about this problem on their SBS box or their client's SBS boxes too.
The error:
Security 537 2/10/2008 4:44 AM 16,044 *And, something that came to us via one person who contacted us as a result of the first post on this issue that causes us to pause:Logon Failure: Reason: An error occurred during logon
User Name:
Domain:
Logon Type: 3
Logon Process: Èù
Authentication Package: NTLM
Workstation Name:
Status code: 0x80090308
Substatus code: 0x0
Caller User Name: -
Caller Domain: -
Caller Logon ID: -
Caller Process ID: -
Transited Services: -
Dear XXXXXX,
This is an update.
According to RD, the event ID 537 is caused by TMUFE, which is our Web Reputation service engine.
The behaviour of TMUFE will be as follows:So it is normal for the security warning to show up on event logs of the SBS server.
- Connect to Proxy Server without authentication.
- Proxy server return access denied (Event ID 537) and request authentication.
- Connect to Proxy Server with configured user name/password.
Thank you and have a great day!
Best regards,
Txxxx Cxxxx
Systems Engineer
Australia Technical Support Center
TrendLabs HQ, Trend Micro Incorporated
And, just tonight as this post was being written, the following showed up in our Experts-Exchange Inbox: SBS performance report displays thousands of event id 537 errors. Apparently the above note was sent to the person posing the question who has 5 SBS servers showing the problem.
The above mentioned services were indeed a part of our troubleshooting with B. Especially when it came to having ISA on the box. But, if there were authentication issues, updates too should fail which they were not.This situation is going from bad to worse in a hurry. :(
Trend, better pull up your socks and get this fixed in a hurry, because right now we are on the edge of walking away ... as our clients that have the product installed are not impressed either ... especially this one: Trend Micro Worry Free Security is not so worry free?
ForeFront and Windows Live OneCare for Server on SBS 2008 are looking more and more attractive everyday ... with ExchangeDefender sitting in front!
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.
Wednesday, 1 October 2008
Hyper-V Server 2008 RTM available for download today!
We have an Intel SR1530HSH 1U Xeon X3350 that will be configured with 8GB of ECC RAM and a pair of Seagate Enterprise SATA drives mirrored via an Intel SRCSASRB RAID controller waiting for this!
We will be running our SBS 2003/2008 labs on this system setup for migration scenarios and other SBS 2008 testing.
Note that the download is a little chunky at a little over 1GB:

It is good to see that Microsoft has adopted the use of ISOs for their downloads over the last couple of years or so. We experimented with some of the setup VHDs that can be had too, but with limited success.Hyper-V Server 2008 ISO Download
The ISOs give us first hand product experience from install right through to post configuration product management which the VHDs do not do.
The Hyper-V Server 2008 product is essentially the same setup that we have been putting together on Server 2008 x64 Server Core install with the Hyper-V role installed and updated.
More to come, as we build the system and bring the new Hyper-V Server 2008 online!
Thanks to Susan: Hyper-V RTMs who in turn points to other posts on the subject.
Links:
- Hyper-V Server 2008 Product Site.
- TechNet Edge: First Look: Hyper-V Server.
- Microsoft Hyper-V Server 2008 Configuration Guide (DOCX)
- Microsoft Hyper-V Server 2008 Getting Started Guide (DOCX)
The Getting Started Guide link also includes the Hyper-V Configuration Tool Guide.
A screenshot of the tool (remember configuring these for conventional memory tuning old DOS hands?):
Hyper-V Configuration Tool
Note that most of the commands available in the tool can be found verbatim on this blog post:
Server Core - From Scratch to Hyper-V Production.
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.


Vista and Outlook 2007 Search Broken? Search results may be incomplete...
Well, this Outlook/Vista problem has been nagging for a while, though not to the point where it was interfering with things ... until yesterday.
Synnex (Search Results)
Search results may be incomplete because items are still being indexed. Click here for more details.
It seems that the search feature was working fine at one point, then it became broken. A direct correlation cannot be pulled as far as the why things broke, but if memory serves correctly, Vista Service Pack 1 was the Anti-Trust modification for the search feature (Ars Technica) may be the culprit.
No matter what, and even on whichever Vista SP1 machine, the same results happened when searching for something in Outlook 2007.
Some Internet searching around did not turn up too much in the way of fixes for the problem. There are a number of somewhat relevant posts on the Vistax64 Forums with no real resolution to the problem.
The solution turned out to be to download the new Windows Search 4.0, install, reboot, and let the indexer run.
After the reboot, and a short time with the system online, the search results were as follows:
Synnex (Search Results)
Your search returned a large number of results. Narrow your search, or click here to view all results.
The time it took to index everything was relatively short.
And, now our searches work.
An update search in the WSUS v3 SP1 console for "Windows Search" or "KB940157" turned up nothing. Not sure why that is as we would like to deploy the update to our Vista installations. For now, we will run the update on all of our own Vista installs and link to it in a broadcast e-mail to our Vista based client users.
Finally, search works! :)
Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.