Thursday, 4 November 2010

One of Life’s Curve Balls

Last week very early (3AM) Tuesday morning Monique woke me up. What began then was eventually the loss of our fourth pregnancy by miscarriage.

As a result, I have not been posting as of late.

This week is the first week back up on my feet so-to-speak, but I am nowhere near ready to put too much energy back into our business or this blog.

Posting will continue to be low for the next little while as we take time to heal and discover just how much our lives have changed both good and bad since last week.

Thanks for reading.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Friday, 29 October 2010

BlackBerry Training – BlackBerry Express Installation Walk Through

The documentation for the BESX install is just okay.

Courtesy of fellow MVP Jason Miller the following training video provides _all_ of the required preparation steps and actual install steps that are required to install BESX on SBS 2008 or on a standalone server.

The above step-by-step helped us a lot in figuring out where things went sideways for us on our standalone BESX install.

We are still not all the way through reworking the BESX install as our client is in production. We will be working on the setup tomorrow.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Monday, 25 October 2010

SBS 2008 Setup Guide 1.7.0 Released

We added the batch file for cleaning up the networking errors in the SBS 2008 BPA along with some clarifications on how to set up the local admin group restricted domain user we deploy to all workstations on the SBS domain.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

SBS 2008 Set Up Last Step – Networking Batch File

The following four networking settings get flagged consistently in the SBS 2008 Best Practices Analyzer on our SBS 2008 installs lately:

image

  • Add-On Congestion Control Provider
  • Receive Window Auto-Tuning Level
  • Receive-Side Scaling State
  • Task Offload

To fix the above, copy and paste the following commands into Notepad, clean up any blog inserted format characters, and save as a batch file. Run the batch file near the end of the SBS 2008 OS configuration found in our SBS 2008 Setup Guide.

netsh int tcp set global congestion=none

netsh int tcp set global autotuning=disabled

netsh int tcp set global rss=disabled

netsh int ip set global taskoffload=disabled

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Favorite Sync Now In Windows Live Essentials 2011

It has been a bit of a struggle to figure out what happened to the Live Toolbar ability to sync Internet Explorer’s Favorites.

After searching around we came upon Windows Live Mesh, now called Sync, that allows is to synchronize our Favorites folder across many different systems.

With the introduction of the Tega v2 we now have_a lot_ of devices to keep shared profile data synchronized across. The Live Toolbar helped to keep things sorted out when it came to IE Favorites.

image

Now that we have that worked out . . . for now . . . we have some addition profile tweaks to complete such as adding SharePoint libraries to Windows 7’s Favorites list (previous blog post) on the Tega v2.

Posted via Tega v2 entirely by touch. This will take some getting used to. A small Bluetooth keyboard is now on the To Do list for this week.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Saturday, 23 October 2010

How To Connect The Tega v2 To SBS 2008/v7

One of the requirements for a machine to connect to an SBS 2008 or SBS v7 network is a physical network connection.

A wireless connection does not come up fast enough for the various tasks that the SBS Setup Wizard needs to accomplish when preparing a device.

In the case of the Tega v2, the wireless NIC does not come up until _after_ logging into the OS. So, our first attempt to join our SBS v7 domain failed. The SBS Setup Wizard requires a connection to SBS during the setup procedures.

Since we have two USB ports on the Tega v2 we dropped in on one of our local suppliers and picked up an USB to RJ45 network adapter that has no real indication of manufacturer other than SR1600 on the driver install.

Once the driver was installed we cleaned up the bits and pieces of the previous SBS Connect attempt and re-ran the wizard from the http://connect site.

We set the tablet up for the users that may need to use it and it ran through and configured everything without a hiccup.

A few things that should be a part of any Tega v2 setup on an SBS 2008/v7 domain:

  • USB to RJ45 NIC adapter for a physical connection to the network.
  • USB flash drive with the required install applications.

The second is due to the fact that while the built-in wireless is okay for day to day needs it is rather slow for throughput. So, we put our needed apps on a USB flash drive and ran them from there.

This device is _neat_!

Other than a bit of a learning curve to use it without a keyboard, it will be set up to do exactly the same things that we do with our workstations and laptops.

So, essentially out of the box with the same amount of configuration that goes into any other Windows 7 device we have a fully functional system that allows us to do pretty much anything we would need to do while on the road in an amazingly small form factor.

Too kewl! :D

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Friday, 22 October 2010

ShadowProtect – Garbage In = Garbage Out

The situation we are in is not the fault of ShadowProtect specifically, but one that we have encountered before where the system’s disks were starting to fail and the backup was image based. Thus, any image backup software can be found to have bad data within the image.

image

We are in the process of finalizing an SBS 2008 server setup for a new client on-site. Their “server” system was experiencing spontaneous reboots with Check Disk running on each start up. This morning the system refused to come back up.

We had set up a ShadowProtect backup on that machine to help protect the data that was on it.

However, as the above screenshot of a BeyondCompare data copy out of the mounted ShadowProtect image shows us, if the data going in is bad the data coming out will be bad.

We experienced a situation like this at an unprecedented level a few years ago where a client’s very large RAID 5 array decided to start dropping sectors on the drives. We ended up recovering that SBS domain using the Swing method and the data through a combination of backup recoveries across the two servers at that site.

In this case we have no other fallback methods other than some of the users may have a copy of the corrupted files on the own systems since the central “server” has been behaving quite flaky for a while now.

So, we will be mounting the ShadowProtect backups that have been running on the flaky system for a couple of weeks now to see if we can find any of the now corrupted files that still may be in good shape.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Thursday, 21 October 2010

Some Thoughts On Implementing ExchangeDefender

When it comes to implementing ExchangeDefender e-mail sanitation and continuity services there are a few steps that need to be taken to prepare the client for the forthcoming changes.

Keep a Report or Two

Keep a report or two in a folder in the e-mail client to show to the client’s users. It then becomes a one click process to show users how to gain access to their ExchangeDefender management portal.

We demonstrate how to whitelist an address or domain and how to set automatic encryption for e-mail recipients or the recipient’s domains.

We tend to run through a training process with key people in the organization a few days or a week before the actual implementation. Then when it comes time to demonstrate ExchangeDefender features to users a day or so before implementing ExchangeDefender services the key people will be a lot further along the learning curve and thus be a front line for many straight forward questions.

E-mail Volume

It is a good idea to go over with users how the volume of e-mail they are receiving will decrease quite substantially once the ExchangeDefender service is implemented.

It is also _very_ important to make sure that they know that once the services are online some of the folks that they normally correspond with may drop off the map so to speak. This may happen because the sender’s e-mail server IP may be on an RBL somewhere on the Internet. This explanation will tie into a discussion on whitelisting e-mail addresses and'/or domains.

Encrypt an E-mail

Encrypt an e-mail to a Hotmail or other e-mail account accessible while at the client’s site to demonstrate how to receive an ExchangeDefender encrypted e-mail. It is a good idea to do this ahead of time so that all we need to do is fire up our cell modem and retrieve the encrypted content.

We make sure to point out how HTML based signatures with images and code in a source e-mail will get distorted when the receiver goes to open the encrypted e-mail. A simple signature for encrypted e-mail is a recommendation that we make.

Camtasia Capture

Produce a few client specific Camtasia captures of the ExchangeDefender services being used by a test e-mail user on the client’s domain so that the names are familiar to users that will make reference to the videos at a later time.

Conclusion

In the end, we find that users have a great service experience when we take the time to make sure that users are prepared for the coming changes, have a good idea of how to use the system from get-go, and know that they have someone to turn to with any questions.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

TegaTech Tega v2 Has Arrived

We have had a very busy moment so there was not really any time to have a look at the tablet other than to pull it out of the box and plug it in to allow it to charge.

The unit looks and feels really good.

Windows 7 Professional is installed on this particular unit, so once the battery was charged we fired it up, ran through the OOBE, connected it to our shop wireless, and joined our SBS v7 domain.

The whole process was relatively painless with the touch keyboard being fairly straightforward in use.

After domain joining without a keyboard use the Ease of Access button near the bottom left hand corner of the screen to enable an on screen keyboard that will allow for the needed CTRL+ALT+DLTE key strokes to unlock the tablet.

A client project beckons, so there will be some additional thoughts on our experiences with the unit soon.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Wednesday, 20 October 2010

TS RemoteApps – Disable Printer Redirection For Branch Offices

In most cases branch offices will have a site to site hardware based VPN. In some cases where the branch office is large enough there may be a local DC or RODC installed there.

In either case we are probably joining the remote PCs to the SBS 2008 domain so that we can manage them, their updates, their mapped drive letters, and more.

So, when the remote users are connecting to their needed application via TS RemoteApps they will not need to have printer redirection enabled. If they do, then they may end up with multiple copies of the local printer being served by the TS session thus causing confusion.

So, to eliminate any possibility of confusion for the user we edit the TS RemoteApp’s RDP file that we created to disable printer redirection.

  1. Create the RDP file in TS RemoteApps manager.
  2. Edit the RDP file by doing the following:
    1. Right click on the file and left click on Open With.
      • image
    2. Uncheck Always use the selected …
    3. Click the Browse button.
    4. Navigate to %windir%.
    5. Vista/Win7: Type Notepad in the Search Windows field
      • image
    6. Double click on Notepad.exe found in C:\Windows
      • image
    7. Make sure Notepad is highlighted and click OK.
      • image
      • Again, make sure that Always use the selected program … is not checked.
    8. Change the following setting from “1” to “0”:
      • OLD Setting: redirectprinters:i:1
      • NEW Setting: redirectprinters:i:0
      • image
    9. Save the file by clicking File –> Save.
    10. Close Notepad.
    11. Distribute the RDP file.

Once the above process has been done once, the Open with menu will show Notepad as an option:

image

We now have a RemoteApps session that will no longer show the Printer Name (Redirected) as their default printer along with (Redirected) copies all of the other standard Group Policy deployed printers that would be on their SBS 2008 domain.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

How To Highlight, Right Click, And Print More Than 15 Files

There seems to be a certain limitation in Windows that for some can be quite the burden.

For some folks there is a need to highlight a bunch of files and have them print to a printer right away. One would assume that the process would be simple:

  1. Highlight the files.
  2. Right click on the group and click on Print.

Here are our right click options when 15 files are highlighted:

image

Note the option to print is there.

When we go ahead and highlight 16 documents we see the following menu offered:

image

We have lost the ability to print those documents.

The answer came from this KB article:

Resolution

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer
Name : MultipleInvokePromptMinimum
Type : DWORD
Range: 1 - 16 (decimal)
Default : 15 (decimal)

For some, an actual decimal number like 128 may work where the number 16 may not actually allow for more than 15 files to be highlighted and printed.

image

Once we logged off and back on again we were able to highlight more than 15 documents:

image 

Caution Note: In testing this out on the above Word documents we encountered a huge system stall while Word fired itself up and subsequently started to print the documents. YMMV.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Monday, 18 October 2010

v1.6.0 of Our SBS 2008 Setup Guide Released

Since we have been doing a number of SBS 2008 setups lately, we have updated and tweaked our SBS 2008 Setup Guide for some of the changes in product service packs and updates, restructured the order of some of the steps to be more in line with the actual workflows, and added some comments on things such as how to install a GoDaddy certificate.

Note that we use the Answer File method to install all of our SBS 2008 and up operating systems.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Installing BlackBerry Enterprise Server Express and Java

We are in the process of finishing up a rather large SBS 2008 Premium deployment. Part of the setup requires us to install BlackBerry Enterprise Server Express on the second server for this client.

Once we ran through the prerequisite BESX setup steps on SBS 2008 we ran the actual BESX install on the second server. BESX had the ability to install the needed Java software during the setup routine but the actual Java components setup kept failing on our Windows Server 2008 SP2 x64 system.

So, we downloaded the newest Java versions and installed them. We ran through the BESX install process again thinking (read assuming) that BESX would see the _newer_ versions as legitimate and move on. It did not and the install failed yet again.

The BESX install window indicates that it requires Java RE and SEDK version 6 update 18 in the install routine window just prior to running the component installs. There was no Java installed on this server prior to running BESX setup.

image 

So, we uninstalled all of the 32-bit and 64-bit versions of Java 6 Update 22, downloaded the earlier versions, installed them, and were finally able to install BESX on the standalone server.

There is a reference to the Holy Hand Grenade of Antioch’s usage instructions in here somewhere! :)

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Friday, 15 October 2010

Exchange Server 2007 SP3 Setup Time on SBS 2008 SP2 Fresh OS

We are running Exchange Server 2007 SP3 on our two new SBS 2008 SP2 integrated setups.

The first server to receive the service pack is an Intel Server System SR1630HGPRX with an Intel Xeon X3450 CPU and 16 GB of ECC Kingston RAM. Three 300 GB 15K RPM Seagate SAS drives are configured in a RAID 5 array via an Intel RS2BL040 RAID controller with a battery backup attached.

Note that this is a vanilla SBS install in that we have not yet run the Getting Started Tasks but do have SBS Backup configured and taking backups. So, no mailboxes on this one yet.

image

The MSIEXEC process has one of the cores on this server pinned with the process indicating 12% CPU utilization.

In the end, the entire process did not take that long at all:

image

  • Intel SR1630HGPRX with Intel Xeon X3450, 16 GB RAM, 600GB 15K SAS RAID 5:
    • Elapsed Time: 00:25:36

The second server is an Intel Server System SR1625URR dual Xeon E5620, 24 GB RAM, 146 GB 15K 2.5” SAS RAID 10 array consisting of 6 drives (438 GB usable storage) plus two hot spares attached to an Intel RS2BL080 RAID controller with battery backup.

Again, the MSIEXEC process had one core pinned:

image

And again the process did not take that long:

image

  • Intel SR1625URR with dual Intel Xeon E5620, 24 GB RAM, 438GB 15K SAS RAID 10:
    • Elapsed Time: 00:25:05

    Now that we have an idea of what a vanilla SBS/Exchange install time will be we will go on to service pack some of our smaller SBS 2008 installs. So far, the feedback we have been seeing on running the service pack 3 update on SBS 2008 has been pretty positive.

    Philip Elder
    MPECS Inc.
    Microsoft Small Business Specialists
    Co-Author: SBS 2008 Blueprint Book

    *Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

    Windows Live Writer

    Thursday, 14 October 2010

    SBS 2008 Setup Guide V1.7.0

    This will be our preliminary set up checklist for getting an SBS 2008 install configured once the base OS install has completed. This post will compliment what is in our SBS 2008 Blueprint book. It will also provide the foundation for a chapter in our upcoming SBS 2008 Advanced Blueprint book.

    There will be some minor tweaks and modifications to this list as we go along with our installs. If things change a lot, then we will run a new post and call it V2. :)

    For the most part, items in the list will be fleshed out in the SBS 2008 Blueprint book. Items that we have encountered beyond the book, will be addressed in existing or subsequent blog posts.

    The following assumes that the server manufacturer’s prep disk was used to update the BIOS, motherboard firmware, RAID controller firmware, backplane firmware, and any other device’s onboard firmware prior to installing the SBS 2008 OS. The firmware update step is an absolutely critical one for the stability of the server.

    Here is our list so far:

    1. Install the manufacturer’s drivers.
        1. RAID including RAID monitoring/status software.
        2. Chipset.
        3. Video.
        4. NIC (Do not team). Unplug or disable any extra NICs for now.
        5. Management suites from the hardware manufacturers will be installed later on in this process.
        6. We do not install System Center Essentials that is provided by Intel on our Intel based SBS 2008 servers.
      1. Desktop
          1. Set the desktop resolution for the monitor attached.
            • Keep in mind that some remote management modules such as Dell’s DRAC may not work if the monitor’s resolution is set too high.
          2. Enable desktop icons.
        1. GUI Customization
            1. Windows Explorer.
            2. Start Menu.
            3. Notification Area.
            4. Add a Desktop Toolbar to the Task Bar .
            5. Internet Explorer.
              1. Add http://download.microsoft.com to Trusted Sites.
            6. Task Manager Process Column Customization.
          1. Partitioning
              • RAID 1+0 is our default (4 disks) + hot spare. Name after the amount of storage is the drive label.
                • 640GB (4x 320GB SATA)
                • C: 100GB SS-SBS (Rename to SBS name)
                • S: 25GB SwapFile (8GB RAM * 1.5 with wiggle room)
                • L: 515GB NetworkData
            • Move the optical drive letter to Z:.
            • Move the Swap File (Reboot and use the above script to speed it up).
            • Copy and paste this services shutdown batch file onto the desktop (previous blog post).
              • Right click and Run as Administrator.
              • Batch file will improve reboot times by 50%-75%!
            • Install and configure Print Services Role: SBS 2008 Terminal Services and HP Printer Drivers (previous blog post).
            • Windows Native Tools Management Console modifications
                1. Add the Group Policy Management Console
                2. Add the Print Management snap-In (after adding the Print Server Role).
                3. Add the Share and Storage Management snap-in.
                4. Add the File Server Resource Manager snap-in.
                5. Add the TS Gateway Manager.
                6. Add the Windows Server Backup snap-in.
              1. Run MMC and add the local Computer Certificate store snap-in and save to the desktop for later use.
                  • Can be found in the SBS Native Tools console.
                • Configure an authoritative time source for the SBS OS.
                  1. Blog Post: SBS 2008 Physical And Hyper-V – Set Up the Domain Time Structure.
                  2. TechNet: Synchronize the Source Server time with an external time source for Windows SBS 2008 migration.
                  3. Once the commands have run, an error message or two may show in the Event Logs soon to be replaced by a successful connection to the authoritative time source.
                  4. Note Oliver Sommer’s comments in the above article.
                • Enable ShadowCopies on the NetworkData partition and set a schedule. We use before hours, coffee, lunch, coffee, and after hours for the schedule.
                • DHCP IPv4 Properties (DNS updates & credentials)
                  • Domain: SBSDomain.local
                    • Extension is required.
                • DHCP additional exclusions for printers (x.1-10) and servers (x.250-254).
                • DNS Settings for Scavenging at 7 days and AD integrated zones.
                • Create a 5GB Soft Quota (File Server Resource Manager).
                • Add Network Service to IIS WAMREG admin service to eliminate DCOM 10016 errors in the event logs (links to MS KB920783 article).
                  • Note that the BPA will pick up any previous log entries and claim that the problem still exists. The error is safe to ignore once the edit has been completed.
                • Enable firewall logging and pop-ups: SBS 2008 Windows Firewall with Advanced Security troubleshooting (previous blog post).
                • Create the default Company Shared Folder with required NTFS and share permissions on the L: NetworkData partition.
                    • Share Name: Company.
                    • Quota: 5GB Soft.
                    • Enable Access-based Enumeration.
                    • NTFS Permissions:
                      • Domain Admins = FULL.
                      • Domain Users = Modify.
                    • Share Permissions:
                      • Domain Admins = FULL.
                      • Domain Users = FULL.
                  • Create the ClientApps (previous blog post on GP and the ClientApps folder) on the L: NetworkData partition.
                      • Share Name: ClientApps.
                      • Quota: None.
                      • Enable Access-based Enumeration. Subfolders can have custom permissions at a later date to exclude users or groups and thus hide those subfolders at a later date.
                      • NTFS and Share Permissions:
                        • Domain Admins = FULL.
                        • Domain Users = FULL.
                        • Domain Controllers = FULL.
                        • Domain Computers = FULL
                    • Make changes to the WSUS Setup:
                      • WSUS Classifications: Enable all except Drivers.
                        • Driver delivery for Windows Vista and 7 has 
                      • WSUS Sync Schedule: Increase synchronization frequency schedule depending on what products are installed on the server.
                    • Getting Started Tasks – Out of Order
                      1. Configure and take a backup now.
                      2. Times: 12:30, 17:30, 23:00.
                        • Make sure that the backup times and the Volume Shadow Copy snapshots do not happen at the same time.
                      3. Backup Now by right clicking on the configured backup and running it.
                      4. Backup in between each batch of updates.
                    • Exchange Server 2007 Rollup Install (previous blog post). Microsoft Download site search for Exchange 2007 rollup (Microsoft Download Site Search). Check to make sure there are no newer rollups.
                    • Server Updates via WSUS/MU.
                    • Create a new User Role in the SBS Console.
                      • Name: Standard User – Restricted.
                      • Remove all Group Memberships.
                      • Add the Domain Users security group only.
                      • Remove OWA permission.
                      • No RWW or VPN.
                      • Verify permissions in the User Role after it is created.
                      • This role is used for the local admin account deployed via Group Policy later in this guide.
                    • Group Policy Configurations (previous blog post):
                        1. Default Computer Policy:
                          1. Local Policies: User Rights Assignment.
                          2. Local Policies: Security Options.
                            • Enable UAC by default in Group Policy (previous blog post).
                            • NOTE: The UAC structure can be split up between Computers, SBSComputers, and SBSServers GPOs so that domain admin accounts only get prompted on servers.
                          3. Remote Connectivity: Remove the Disconnect option from the Start Menu and add the Windows Security option.
                        2. Windows SBSUsers Policy:
                          1. Configure Screensaver Management. Our default is 45 minutes with logon.scr as the default SS. Password is always required.
                            • 2010-10-18: For Windows 7 we now use scrnsave.scr as the basis for all screensavers which is a blank screen.
                          2. Mapped Network Drive (M: = \\SS-SBS\Company) via Group Policy Preferences
                          3. Set the Companyweb as the default site in IE.
                          4. Add the RWW and OWA URLs to IE’s Favorites.
                        3. Windows SBSComputers Policy:
                          1. Deploy a restricted domain user to _all_ system’s Local Admin Group.
                            1. Create a new user using the Standard User – Restricted Role.
                            2. Deploy to workstation’s Local Admin Group via Group Policy Preferences.
                            3. Remove the user’s mailbox (previous blog post).
                        4. Default Printer Deployment Policy:
                          1. Deploy printers to XP Professional x86 (previous blog post).
                          2. Deploy printers to Windows Vista using the Printer Management snap-in.
                        5. Windows SBSComputers XP Pro Policy:
                          1. Deploy Windows Defender to Windows XP Professional (Optional).
                      1. Install the server hardware manufacturer’s management software suite.
                      2. Set the SBS Domain Password Polices (60-75 days, 10-12 characters minimum with complexity).
                        • Note that all user’s passwords will reset to request a new password!
                      3. Enable Folder Redirection.
                        • Changing the security settings in the default GPO for redirection will show FR as not enabled in the SBS Console.
                        • We remove the Exclusive Access setting on any folders redirected to remove complications when it comes time to migrate the client to a new server.
                      4. Remove the Public share in the SBS Console.
                      5. If using the self-issued certificate, copy the package to the Network Admin\SBS folder in the Company shared drive. (We create a Network Admin folder in the Company Shared Folder at all client sites).
                        • If using a GoDaddy certificate, make sure to install the GoDaddy Intermediate certificates (download page) into the Intermediate Certification Authorities store individually to avoid any issues later.
                          1.  gd_intermediate.crt
                          2. gd_cross_intermediate.crt
                          3. Disable All Uses for GoDaddy Class 2 root certificate in Trusted Root Certification Authorities.
                          4. Restart the IISAdmin service.
                          5. Install the GoDaddy certificate using the wizard.
                      6. Move the relevant data folders to the L: partition. We move all but the Exchange databases.
                          1. WSS (SharePoint) Data.
                          2. Users’ Shared Folders.
                            1. Re-enable Access-based Enumeration
                          3. Users’ Redirected Folders Data.
                            1. Re-enable Access-based Enumeration
                          4. WSUS Update Repository Data.
                        1. SBS Console Getting Started Tasks.
                            1. Connect to the Internet.
                            2. Customer Feedback options.
                            3. Set up your Internet address.
                            4. Configure a Smart Host for Internet e-mail.
                            5. Add a trusted certificate.
                            6. Configure server backup: Earlier in this checklist.
                            7. Add new users (use the multiple wizard under users if there are a lot of users to add).
                            8. Connect computers: http://connect.
                            9. Share Printers via Group Policy for Windows Vista and PushPrinterConnections.exe for Windows XP Pro SP3 (both links are previous blog posts).
                            10. Set up Office Live Small Business.
                          1. Configure the Reports e-mail addresses.
                          2. Copy Logon Failure XML code (CodePlex site) into a new Event ID Filter and set an e-mail to fire when a failed logon occurs.
                          3. Configure Workstations on the domain.
                          4. Create and configure the Group Policy Central Store.
                          5. Enable an MFP or Copier to Scan To E-mail Destined To A Companyweb SharePoint Library (previous blog post).
                          6. Enable and configure Windows Search Services on SBS 2008 or a Windows Server 2008 RTM/R2 file server and Libraries on Windows 7 (Official SBS Blog post).
                            1. Install the Search Service.
                            2. Add the share to Windows 7 Libraries.
                            3. Click start and start typing and watch those network files results flow!
                          7. Fix the SharePoint 2436 Search errors (Official SBS Blog post).
                          8. Fix the networking settings for Add-On Congestion Control Provider, Receive Window Auto-Tuning Level, Receive-Side Scaling State, Task Offload (previous blog post)
                          9. Download, install, and run the SBS 2008 Best Practices Analyzer.
                            1. The BPA will pick up a lot of the little things that need to be configured such as advanced OS networking features that should be disabled, the SharePoint 2436 error above, and others.
                          10. Change the initial domain administrator’s password if using an Answer File (remember to reset the DHCP credentials, and any Event Log event fired Task too). Note that if the admin account has not been logged off since changing the Password Policies, a log off and log on again will require a password change anyway.
                          11. Configure Custom Views and e-mail Task triggers for Event IDs (SBS Native Tools Management):
                          12. OPTIONS:
                          13. Customize the SBS Console Reports.
                          14. Run a backup. Crash the server. Restore the Backup. Deliver.

                          One thing to keep in mind when it comes to checklists is that they are never meant to be a replacement for the materials they summarize!

                          It is very important to understand why the various steps need to be accomplished, how those steps can change over time due to changes in the operating system, the hardware configurations underneath the OS, and the technician’s own growth in experience and understanding.

                          The “why” leads to an ability to understand how things are going wrong when they do. Note that we are saying, “when” and not “if” things go wrong.

                          Troubleshooting

                          UPDATES:

                          • 2009-05-11: V1.0.1 – Added a step and a few sub steps for Group Policy settings.
                          • 2009-05-14: V1.0.2 – Added the IE SBSUsers settings.
                          • 2009-05-19: V1.1.0 – Added some tweaks and changes to the existing steps.
                          • 2009-05-23: V1.1.1 – Added the option to map the Companyweb site to a network drive.
                          • 2009-05-29: V1.2.0 – Significant changes and adjustments made with some additional steps too.
                          • 2009-09-05: V1.2.1 – Added the option for allowing copiers and MFPs to relay e-mail through to users and a SharePoint library, the Troubleshooting section, and some formatting changes.
                          • 2010-01-14: Numerous updates including the Exchange 2007 SP2 mention.
                          • 2010-01-17: v1.4.1 – Added the need to set up time synchronization as well as cleaned up some HTML code.
                          • 2010-01-27: v1.4.2 – Added the blog post link for configuring the time service step.
                          • 2010-05-01: v1.5.0 – Numerous changes and updates to the process.
                          • 2010-10-18: v1.6.0 – Restructured some of the step’s order to better represent the work flow such as backing up SBS _before_ applying the Exchange service place. Numerous other changes.
                          • 2010-10-25: v1.7.0 – Added some steps and some clarifications for the steps.

                          Philip Elder
                          MPECS Inc.
                          Microsoft Small Business Specialists
                          Co-Author: SBS 2008 Blueprint Book

                          *All Mac on SBS posts will not be written on a Mac until we replace our now missing iMac! (previous blog post)

                          Windows Live Writer