Tuesday, August 9, 2016

Creating an anti-spoofing rule in Office365

Here's how to create a mail flow rule in Office365 to send spammers who spoof your domain to the online quarantine.  These instructions are applicable ass of 8/9/16.  Typically, these spoofed messages will go to your users' junk e-mail boxes, but this can still lead to confusion, so we don't want these messages to go to junk e-mail at all.

In the Exchange Admin Center, go to Mail Flow:



















Add a new mail flow rule:
























Hit More Options near the bottom of the page:

























Give the rule a name of "Spoof Check."  Tell the rule to apply this rule if sender is outside of the organization and the sender's domain is [your public domain] and do the following: deliver the message to the hosted quarantine.


Tuesday, July 26, 2016

log on as a service is greyed out on domain connected computers

I found Log on as a Service to be greyed out in local security policy for my domain member server (running Win 2008 R2).  It looked like this:


























It is greyed out because the setting is defined in group policy management by a domain controller and not in local security policy.  I was able to edit the setting here on a domain controller here:

In my case, I had to log on to one of my Windows 2008 R2 domain controllers and open Group Policy Management and go to Default Domain Policy where I could go to edit the log on as a service for the entire domain.

The setting is located here:
















And editing the value looks like this (right click on default domain policy and choose edit):


 






Saturday, July 2, 2016

Downloading Acrobat 9 updates now that Acrobat is no longer actively supported

Acrobat 9 (Standard or Pro) will no longer download updates automatically from version 9.0.0 at least that was my experience on 6/30/16.  Acrobat 9 is no longer supported by Adobe.  Luckily, I found this page:
http://khkonsulting.com/2014/08/where-are-my-adobe-acrobat-9-updates%E2%80%BD%E2%80%BD%E2%80%BD/#comment-306225

The page explains that while the autodownload function no longer works, you can manually download the updates from here:
PC - ftp://ftp.adobe.com/pub/adobe/acrobat/win
Mac - ftp://ftp.adobe.com/pub/adobe/acrobat/mac

I found that when I got to about version 9.3.5, the autoupdate feature *did* work, but the autoupdate feature definitely did not work on version 9.0.0.

Friday, June 17, 2016

Configuring Outlook with a Google account (Google settings change needed after July 2014)

You need to an adjustment to your Google settings to get Google email working in Outlook.  I got this message when trying to set up a Google account in June 2016:

Your IMAP server wants to alert you to the following: Please log in via your web browser:
http://support.google.com/mail/accounts/bing/answer.py?answer=78754 (Failure)


The link above doesn't help as far as I can tell.

I got the answer from Microsoft's site:
https://support.microsoft.com/en-us/kb/2984937

On 7/15/14, Google disabled basic authentication, so you need to enable basic authentication to get Outlook (or Apple Mail or others) to successfully authenticate with Google accounts.

You can enable basic authentication here (assumes you are logged into your Google account):
https://www.google.com/settings/security/lesssecureapps


Thursday, May 19, 2016

Using DISM to repair WIndows when sfc /scannow can't repair Windows 10

I have found that sfc /scannow doesn't repair system files on Windows 10 in many cases.  Sfc /scannow will find problems but not repair them.

I have found a fix that won't work for the average user - only sysadmins with access to a Windows 10 ISO.

Here's what I did:


  • Downloaded the Windows 10 Pro 64 bit version 1511 ISO from "Microsoft Volume Licensing Service Center" - this 4 GB file will take a while to download
  • Mounted the ISO file as d:
  • Ran this command from an elevated command prompt:
    DISM /Online /Cleanup-Image /RestoreHealth /source:WIM:d:\Sources\Install.wim:1 /LimitAccess
  • Re-ran "sfc /scannow" after the DISM command above finishes

Thursday, April 14, 2016

Using Windows 10 search to pull up Outlook emails in the Windows search interface

This post will discuss getting emails to appear in the Windows 10 search interface *if* you are using Start10 or some similar start menu program.

I was working with a user who had Windows 8 and Office 2010 installed.  The user had Start8 installed as the Windows 8 interface stinks.  The user often ran searches via clicking Start and then typing search terms and hitting "See More Results" just like you can/could do in Windows 7.  When clicking "See More Results" - the results included emails from Outlook.  This was the critical behavior we wanted to keep (getting emails in the search results).

You'd get to the needed searches like this:









I upgraded the user's laptop to match our current software setup - Windows 10 and Office 2013.  For this executive user, I also installed Start10 (not part of my standard install).  

The bright side was that the user could still click on "see more results" and get files or emails, but the problem was that the user would double click on the emails and get nothing (no error or ability to see the message).  I'm 95% sure I could have fixed the problem right then and there via deleting the file C:\Program Files\Common Files\System\MSMAPI\1033\MSMAPI32.DLL - but I wasn't sure about that fix until later.  You can delete that MSMAPI32.DLL file with Outlook closed and the file Outlook will recreate the file on next open (credit for that info here).

My assumption was that the indexing was broken.  The search was pulling up indexed results that didn't point to the underlying issue.  I rebuilt the index.  No dice.  Same problem.  I could see the searches, but the user could not double click on the emails and get Outlook to open them.  

I then upgraded to Office (and Outlook 2016) assuming that it was some way in that Windows 10 was having trouble talking to Outlook 2013.  With installation of Outlook 2016, emails would not appear in the "see more results" entries.  I later learned that Microsoft says they have disabled the feature that made Outlook results appear in Windows searches.  Supposedly, MS disabled this feature for both Outlook 2013 and Outlook 2016, but my experience says that Outlook 2013 still works.  

If I could go back in time, I'd reinstall Outlook 2013, but in this case - I uninstalled Outlook 2016 and installed Outlook 2010.  I had to delete the OST and let the OST rebuild.  While I was at it, I rebuilt the index for best info for the user.

Things are great, right?  Not true.  I run a search, and I get emails among the search results, but I get an error of "Either there is no default mail client or the current mail client cannot fulfill the messaging request. Please run Microsoft Outlook and set it as the default mail client."  I tried the MS FixIt and deleting the registry entries for both 32 bit and 64 bit as described in the excellent troubleshooting steps here:

However, no dice.  I also tried to set Outlook as the default program via Set Program Defaults in Windows 10.  No dice.  The eventual fix was to delete C:\Program Files\Common Files\System\MSMAPI\1033\MSMAPI32.DLL with Outlook closed.  Upon Outlook reopen, the file recreated itself (different size and date) and the ability to click on emails found in search was successful.

Thursday, February 25, 2016

Lost password recovery on Windows 7 (free)

I was handed a laptop with Windows 7 Pro and a single user on the laptop with an unknown password.  I had a 1 GB flash drive.  Ideally, I would have had a 8 GB or larger USB drive that I could put a Windows 7 installer on, but I didn't (would have saved me from needing Linux).

These steps require medium level tech savvy.  If you've never worked in a DOS prompt before or don't know what that means, you won't have much luck with these steps.

Here's what I did step by step:

On another laptop, I did these things:
Downloaded Linux Live USB Creator from here: http://www.linuxliveusb.com\
Downloaded System Rescue CD from here: http://www.system-rescue-cd.org/Download
Made a bootable System Rescue CD on the 1 GB USB flash drive

On the laptop with the unknown password, I ran these steps:
Booted to the Linux distro we put on the USB drive
Started the default Linux version when presented
ran "startx" to start the GUI
opened up a terminal/CLI prompt
ran mount -t ntfs-3g /dev/sda1 /mnt/windows
** note that /sda1 might not be the location of your C drive where Windows is located, might be sda2 or sda3
ran cd /mnt
ran cd windows
** note that windows is case sensitive so it might need to be "cd Windows"
ran cd system32
** note that system32 is case sensitive so it might need to be "cd System32"
ran mv utilman.exe utilman.bak
ran cp cmd.exe utilman.exe
reboot the computer back into Windows
At the login screen, hit Windows key + U
at the DOS prompt, run "net user USERNAME PASSWORD" where USERNAME is the name of the user and PASSWORD is the new password

** of note if you run just "net user" from a DOS prompt, you'll be presented with the existing usernames on the computer