Configure Fine-Grained Password Policies in Active Directory

Configure Fine-Grained Password Policies in Active Directory

Active Directory, Identity, Windows Server
Applies to: Windows Server 2025 / 2022 / 2019 / 2016 / 2012 R2 / 2012 Fine-Grained Password Policies (FGPPs) let you apply different password and account lockout settings to different sets of users in the same Active Directory domain. This is useful when one domain-wide policy is not enough, for example when privileged or service accounts need different controls from standard user accounts. FGPPs were introduced with Windows Server 2008. For currently supported Windows Server versions, Microsoft documents them for Windows Server 2025, 2022, 2019, and 2016, with a domain functional level of Windows Server 2012 or higher. In This Article 1. What Is a Fine-Grained Password Policy? 2. Requirements and Scope 3. Understand Precedence 4. Configure an FGPP with ADAC 5. Configure an FGPP with PowerShell 6. Verify…
Read More
How to Perform a Windows Server Bare-Metal Backup and Recovery

How to Perform a Windows Server Bare-Metal Backup and Recovery

Windows Server
Applies to: Windows Server 2025 / 2022 / 2019 / 2016 / 2012 R2 / 2012 / 2008 R2 / 2008 Windows Server Backup can create full server, volume, system state, and bare-metal recovery backups. If the server cannot boot or a system disk fails, you can start Windows Recovery Environment (WinRE) and restore the server from a previously created backup. The original version of this article was written for Windows Server 2008. The same core backup and bare-metal recovery model is still available in current Windows Server releases. In This Article 1. Full Server vs. Bare-Metal Recovery 2. Install Windows Server Backup 3. Create a Bare-Metal or Full Server Backup 4. Create a Backup with WBAdmin 5. Perform a Bare-Metal Recovery 6. Key Takeaways 1. Full Server vs. Bare-Metal…
Read More

How to Reset Default Domain Policy and Default Domain Controllers Policy

Active Directory, Identity, Windows Server
Applies to: Windows Server 2025 / 2022 / 2019 / 2016 / 2012 R2 / 2012 / 2008 R2 / 2008 / 2003 R2 / 2003 Dcgpofix.exe recreates the two default Group Policy Objects that are created with an Active Directory domain: Default Domain Policy and Default Domain Controllers Policy. This tool is intended for disaster recovery. It should not be used as a normal troubleshooting shortcut because it resets the default GPOs to Microsoft-defined defaults and can overwrite settings that were intentionally configured in those policies. In This Article 1. What Dcgpofix Restores 2. Before Running Dcgpofix 3. Reset Default Domain Policy 4. Reset Default Domain Controllers Policy 5. Reset Both Default GPOs 6. Validate the Result 7. Important Limitations 8. Key Takeaways 1. What Dcgpofix Restores Microsoft documents…
Read More
How to Configure Local Continuous Replication (LCR) in Exchange Server 2007

How to Configure Local Continuous Replication (LCR) in Exchange Server 2007

Archive / Legacy Topics, Exchange, High Availability
Applies to: Exchange Server 2007 Historical: Local Continuous Replication (LCR) was an Exchange Server 2007 high-availability feature. It was removed in Exchange Server 2010 and replaced by the Database Availability Group (DAG) and mailbox database copy model. LCR creates a second copy of an Exchange 2007 storage group on the same Mailbox server. Transaction logs are copied and replayed into the replica database, providing a local recovery copy if the active database or storage fails. In This Article 1. What LCR Does 2. Configure Local Continuous Replication 3. Important Storage Considerations 4. What Replaced LCR 5. Key Takeaways 1. What LCR Does LCR is a single-server replication technology. It is enabled per storage group and uses Exchange log shipping to maintain a passive local copy of the databases in that…
Read More
Windows Server 2003 Cluster with StarWind iSCSI on VMware Workstation

Windows Server 2003 Cluster with StarWind iSCSI on VMware Workstation

Archive / Legacy Topics, Failover Clustering, VMware, Windows Server, Workstation
Applies to: Windows Server 2003 | VMware Workstation 7.x / 6.x | legacy StarWind iSCSI Target Historical: This article documents an older shared-storage clustering setup using Windows Server 2003 virtual machines, VMware Workstation, Microsoft iSCSI Initiator, and the legacy StarWind iSCSI Target interface. The exact StarWind screens and Windows Server clustering workflow shown here are no longer current, but the underlying storage model is still useful: both cluster nodes connect to the same shared iSCSI LUNs, which are then presented to Windows Failover Clustering. In This Article 1. Original Design 2. Configure StarWind Storage 3. Configure the Networks 4. Connect the First Cluster Node 5. Connect the Second Cluster Node 6. Current Windows Server Guidance 7. Key Takeaways 1. Original Design The original setup used three components: iSCSI target: StarWind…
Read More