!SAC (!Special Administration Console) EMS, 235
32-bit Windows
64-bit Windows
ASP.NET, 274
CD burning, 275
driver installer routines, 275
Group Policy software development, 274
hardware/software compatibility, 272-273
Itanium computers (Intel), 274
.NET Framework, 274
NetMeeting, 275
power management, 275
printer support, 275
product activation, 275
Remote Assistance, 275
Windows Installer, 275
Windows Media Player, 275
MBR, 269
32-bit Windows Server 2003 editions versus 64-bit versions, 5
64-bit operating system options (GPO Editor), 91
64-bit Windows, 268
32-bit Window
ASP.NET, 274
CD burning, 275
driver installer routines, 275
Group Policy software development, 274
hardware/software compatibility, 272-273
Itanium computers (Intel), 274
.NET Framework, 274
NetMeeting, 275
power management, 275
printer support, 275
product activation, 275
Remote Assistance, 275
Windows Installer, 275
Windows Media Player, 275
EPIC architectures (Intel), 268
Hammer (AMD), 269
Itanium 2 processors (Intel), 268-269
Itanium computers (Intel), 271
boot architectures, 272
disk partitioning, 269-270
Itanium processors (Intel), 268-269
Pentium processors, 268
superfloppies, 273
64-bit Windows Server 2003 editions
Itanium processors (Intel), EPIC architectures, 268
versus 32-bit versions, 5
128-bit (RC4) encryption, Terminal Servers, 202
802.1X, Windows Server support, 185
ABO (Administration Base Objects), IIS console administration, 114
access permissions, establishing in Terminal Servers, 202
accessing
Remote Assistance, 42
resource properties in clusters, 216-217
account policies (security), 54
activating. See deploying
activation keys (Windows product activation), 25
Active Directory, 71
AD/AM, 84
administrative tools
dragging/dropping, 75
renaming domain controllers, 79
renaming domains, 79
RSoP MMC snap-ins, 77
security policies, 78
starting, 75-77
ADMT 2.0, 74
application partitions, 80
cross-forest trusts, 82-83
domain functional levels
Last Logon Timestamp attribute, 84
raising, 73
renaming domain controllers, 79
renaming domains, 79
Windows 2000 mixed, 72
Windows 2000 native, 72
Windows Server 2003, 72
domains, remote office logons, 84-85
functional levels, 72-74
GPMC, 75
Identity Integration Feature Pack, 75
Replication, 82
Replication from Media feature, 85
RSoP MMC snap-in, 95
schema deactivation, 80-81
Active Directory integrated zones (DNS), 135-136
active-active clusters, 210
active-passive clusters, 210-212
AD/AM (Active Directory/Application Mode), 84
adding
assemblies to configured assemblies list, 157
members to NLB clusters, 221
nodes to clusters, 214
resources to clusters, 215
Additional Commands option (Setup Manager Wizard), 22
administration
IIS consoles, ABO, 114
servers, IIS consoles, 115
Web sites, IIS consoles, 115
Web-based administration, IIS console, 121
administration agent services (ADS), 29
administrative scripts, VBScripts
testing, 259
writing, 258-262
Administrative Templates option (GPO Editor), 92-93
Administrative TemplatesNetwork section (Computer Configuration policies)
DNS Client section, 103
Network Connections section, 103
QoS Packet Scheduler section, 104
SNMP section, 104
Administrative TemplatesShared Folders section (User Configuration policy sections), 105
Administrative TemplatesSystem section
Computer Configuration policies
Error Reporting feature, 103
Net Logon section, 102
Remote Assistance section, 102
Remote Procedure Call section, 103
Scripts section, 102
System Restore feature, 102
User Profiles section, 101
Windows Time Service section, 103
User Configuration policies
Ctrl+Alt+Del section, 105
Power Management section, 106
Scripts section, 105
User Profiles section, 105
Administrative TemplatesWindows Components section
Computer Configuration policies, 101
User Configuration policies
Application Compatibility section, 104
Help and Support Center section, 104
Terminal Services section, 104
Windows Media Player section, 105
Windows Messenger section, 104
Windows Update section, 105
administrative tools (Active Directory)
domain controllers, renaming, 79
domains, renaming, 79
dragging/dropping, 75
inheritance parents, showing, 75
multiple objects, selecting, 75
permissions, showing, 75
configuring, 77
security policies, 78
starting, 77
Saved Queries feature, 76
ADMT 2.0 (Active Directory Migration Tool), 74
Adprep command-line tool, 238
ADS (Automated Deployment Services)
administration agent, 29
configuring, 29-31
controller services, 29-31
controllers, 29
Deployment Agent Builder service, 30
images, 31
job templates, 30
network boot services, 29
PXE services, 30
system requirements, 28-29
versus RIS, 28
ADSI, scripting in Terminal Services, 198
Advanced mode (Windows Backup), ASR backup sets, 264
Advanced Settings dialog box, 177
affinity setting property (NLB cluster port ranges), 222
All Programs Menu section (Start menu), 46
Allow Time Zone Redirection settings (Terminal Service Group Policies), 197
Alternate Configuration tab (DHCP), 134-135
analyzing security databases, 57
anycast addresses (IPv6), 168
APIPA (Automatic Private IP Addressing) feature (DHCP), 134-135
Application Compatibility section
Computer Configuration policy sections, 101
User Configuration policy sections, 104
application partitions, Active Directory, 80
application pools (IIS console), 110-112
configuring, 116-118
Health tab, 116
Identity tab, 118
multiple applications, assigning to, 113
Performance tab, 117-118
rapid fail protection, 113
Web gardens, 113
Application Server mode (Terminal Services), 189, 202
application servers, defining, 109
applications
application pools (IIS console), assigning to, 113
assigning, Install This Application at Logon option (Group Policy), 90-91
COM+ applications, converting to Web services, 163
custom configurations, 160
dependencies, viewing, 160
executing with .NET Framework, 153-154
managing
via .NET Framework Configuration console, 156, 160
Web services, 161
native code applications, .NET Framework, 155
properties, modifying, 160
remote services, managing, 160
repairing, 160
applying security templates, 228
Approval Log (SUS), 255
approving SUS updates, 250-251, 254
AppSec. See Software Restriction Group Policy (Terminal Servers)
boot architectures, Itanium computers (Intel), 271-272
IIS consoles
application pools, 110-113
application pools, configuring, 116-118
application pools, Performance tab, 117-118
http.sys drivers, 110-112, 124
worker processes, 110-112, 116
worker processes, security enhancements, 123-124
WWW Service Administrator and Monitoring component, 112
ASP.NET, 163
64-bit Windows, 274
IIS consoles, 124
ASR (Automated System Recovery), 17, 263-265
assemblies
adding, 157
assemblies lists, 156-157
backward compatibility, 158
binding policies, 158
codebases, 158
configured assemblies
adding to, 157
managing, 156-158
documenting, 157
preinstalled assemblies (Windows Server 2003), 157
versioning, documenting, 158
assemblies lists, 156-157
assembly cache (.NET Framework Configuration console), managing, 156-157
assigning
applications, Install This Application at Logon option (Group Policy), 90-91
logging levels to UDDI, 161
multiple applications to application pools (IIS console), 113
permissions to Remote Desktop for Administration (Terminal Services), 191
asymmetric key encryption, 148
attended installations (Windows Server 2003)
CD-based installations, 16-19
network-based installations, 19-20
audio CDs, burning, 40
automated backups, DHCP, 134
automatic network configuration feature, 183
Automatic Partner Configuration (WINS), 132
Automatic Reconnection settings (Terminal Service Group Policies), 196
Automatic Updates (SUS), 251-254
automating GPO, GPMC, 99
AWE (Address Windows Extensions), Enterprise Edition Server, 7
Backup or Restore Wizard (Windows Backup), ASR backup sets, 264
BackupExec (Veritas), 263
backups
automated backups, DHCP, 134
BackupExec (Veritas), 263
BrightStor (Computer Associates), 263
manual backups, DHCP, 134
shadow files (file sharing), 143
system state backups, 262
ASR (Automated System Recovery), 263-265
system state backups, 262
backward compatibility (assemblies), 158
bandwidth
low bandwidth settings, configuring, 200-201
OOB management
EMS, 234-236
headless server hardware specifications, 232-233
RDP 5.2 settings, 201
basic disks, 270
binding policies (assemblies), 158
blocking WINS replication, 133
bone broadcasts (NetMon), 65
boot architectures, Itanium computers (Intel), 271-272
Bootcfg command-line tool, 238
BrightStor (Computer Associates), 263
burning
audio CDs, 40
caching records in WINS, 132
CAL (client access licenses), 11
CD Writing Wizard, 39
CD-based installation (Windows Server 2003), 16
disaster recovery, 17
license agreements, 17
network card configuration, 18
partitions, formatting, 17
passwords, 18
personalizing, 18
server component configuration, 19
certificate mapping (IPSec), 172
Check Server Wizard, troubleshooting RIS installation, 27
Choice command-line tool, 238
CIDR (Classless Interdomain Routing), 168
class C property (NLB cluster port ranges), 223
Classic ASP, IIS consoles, 124
Client/Server Data Redirection section (Terminal Service Group Policies), 197
clients
Automatic Update (SUS) clients, configuration behavior, 253-254
RDC clients (Terminal Services), 187
configuring control key functions, 193
connecting to Terminal Server console sessions, 192
enabling, 191
Experiences tab, 200-201
Full Screen mode, 193
Full Screen mode, Connection bars, 193
RDP 5.2, 188, 191-193, 200-201
remote clients, RQS, 182
Remote Desktop MMC snap-in (Terminal Services)
connecting to Terminal Server console sessions, 192
RDP 5.2, 191
Remote Desktop Web Connection clients (Terminal Services), 194
Terminal Services Configuration MMC snap-in (Terminal Services), 195-196
Terminal Services Manager MMC snap-in (Terminal Services), 195
Clip command-line tool, 238
CLR (common language runtime) .NET Framework
code access security policy management, 156-159
cross-platform compatibility, 153-154
Cluster Administrator (Cluster Service)
clusters, managing, 215
New Cluster Wizard, 213-214
New Resource dialog box, adding resources to clusters, 215
nodes, specifying resource ownership in cluster creation, 215
Properties dialog box, 216
resource groups, 217
resources, 216
Cluster Parameters dialog box (NLB Manager), 219
Cluster Service, 209. See also NLB
active-active clusters, 210
active-passive clusters, 210-212
Cluster Administrator
accessing resource group properties, 217
accessing resource properties, 216
managing clusters, 215
New Cluster Wizard, 213-214
New Resource dialog box, 215
Properties dialog box, 216
specifying resource ownership in cluster creation, 215
specifying resources in clusters, 216
transferring resources in clusters, 216
clusters
creating, 213-214
naming, 214
Datacenter Edition Server, 8
DFS roots, 224
DHCP service, 224
Distributed Transaction Coordinator, 224
domain user accounts, 214
failovers, 212
file shares, 224
IIS, 223
majority node set clusters, 211
message queuing, 224
preconfigured clusters, 211
printer spools, 224
single node clusters, 211
single quorum device clusters, 211
Volume Shadow Copy Service, 224
WINS, 224
clustering (Windows), Enterprise Edition Server, 7
clusters
active-active clusters, 210
active-passive clusters, 210-212
creating, 213-214
DFS roots, 224
DHCP service, 224
Distributed Transaction Coordinator, 224
domain user accounts, 214
file shares, 224
IIS, 223-224
majority node set clusters, 211
managing, 215
message queuing, 224
naming, 214
NLB clusters
adding members to, 221
configuring, 219
configuring port rules, 221
creating, 219-220
editing port ranges, 222-223
editing port settings, 222
error checking, 221
IP addresses, 220
remote control feature, 219
request handling, 218
selecting network interface, 220
specifying affinity modes, 220
specifying port rules, 220
nodes, specifying resource ownership, 215
preconfigured clusters, 211
printer spools, 224
accessing properties, 217
adding to clusters, 215
failback policy, 217
failover policy, 217
resources
adding, 215
application services, 213
computer names, 212
dependencies, 213
IP addresses, 212
logical drives, 213
node failures, 213
properties, 216
quorums, 213
specifying, 216
transferring, 216
transferring ownership, 213
single node clusters, 211
single quorum device clusters, 211
TCP/IP, 213
WINS, 224
code access security policies (.NET Framework Configuration console), managing, 156-159
code groups, 158-159
codebases, 158
codes, permission sets, 158-159
COM+ applications, converting to Web services, 163
command-line tools
Adprep, 238
Bootcfg, 238
Choice, 238
Clip, 238
Defrag, 238
Diskpart, 238
Dsadd, 238
Dsget, 238
Dsmod, 238
Dsmove, 238
Dsrm, 238
Eventcreate, 238
Eventquery, 238
Freedisk, 239
Fsutil, 239
Getmac, 239
Gpresult, 239
HFNetChk, 257-258. See also MBSA
Iisback, 239
Iiscnfg, 239
Iisftp, 239
Iisftpdr, 239
Iisvdir, 239
Iisweb, 239
Inuse, 239
Logman, 239
MBSA, security updates, 256-258
NLB, 239
Openfiles, 239
Pagefileconfig, 239
Perfmon, 239
Prncnfg, 239
Prndrvr, 239
Prnjobs, 239
Prnmngr, 239
Prnport, 239
Prnqctl, 239
Relog, 239
remote servers, 236
Rss, 239
Sc, 239
Schtasks, 239
secedit.exe, 228
security enhancements, 124
Setx, 239
Shutdown, 239
Systeminfo, 240
Takeown, 240
Taskkill, 240
Tasklist, 240
Typeperf, 240
Waitfor, 240
Whoami, 240
backward compatibility, 238
installing, 237
interactive mode, 237
security, 237
communications channels (remoting services), 160
comparing Windows Server 2003 editions, 5
compatibility
hardware/software compatibility (32-bit/64-bit Windows), 272-273
IIS (Internet Information Services) console, 114
compatibility addresses (IPv6), 168
compatibility checks, Windows Server upgrades, 32
compatibility level option (Terminal Service Application Server mode), 202
compatws.inf security template, 53, 226
compressed folders
Compressed Folders feature (Windows Server 2003), 37-38
NTFS folders, 36-37
Zip files, 37-38
Compressed Folders feature (Windows Server 2003), 37-38
compressed IPv6 addresses, 167
Computer Configuration policy sections (Group Policy)
Administrative TemplatesNetwork section
DNS Client section, 103
Network Connections section, 103
QoS Packet Scheduler section, 104
SNMP section, 104
Administrative TemplatesSystem section
Error Reporting feature, 103
Net Logon section, 102
Remote Assistance section, 102
Remote Procedure Call section, 103
Scripts section, 102
System Restore feature, 102
User Profiles section, 101
Windows Time Service section, 103
Administrative TemplatesWindows Components section, 101
Windows SettingsSecurity Settings section, 100
Computer management console, 144
computer names (cluster resources), 212
Configure Your Server Wizard, NAS configuration, 148
configured assemblies (.NET Framework Configuration console)
assemblies, adding to, 157
managing, 156-158
configuring
application pools (IIS console), 116-118
Automatic Updates (SUS), 251-254
ICF, 175-177
IPv6 stacks, 170
low bandwidth settings, 200-201
networks, automatic network configuration feature, 183
port rules for NLB clusters, 221
RPC session security, 202
servers, IIS consoles, 115
software restriction policies, Group Policy, 230
SUS, 248
SUS synchronization schedules, 248
Terminal Server Session Directory, 205
Terminal Service Group Policies, 195
Client/Server Data Redirection section, 197
Enable TS per NIC settings, 198
Encryption and Security section, 197
Licensing section, 198
NIC for Session Directory to Use for Redirection settings, 198
Permission Compatibility Full Security or Relaxed Security settings, 198
Session Directory section, 198
Terminal Services section, 196-197
Web Services extensions, IIS console, 119-120
Web sites, IIS consoles, 115
Connection bars (RDC Client Full Screen mode), 193
consoles, RDP 5.2 connections, 194
control keys, configuring functions via RDC clients, 193
Control Panel section (Start menu), 46
controller services (ADS), 29-31
converting COM+ applications to Web services, 163
copying records, Active Directory integrated zones (DNS), 135
cross-forest authentication, IAS, 166
cross-forest trusts (Active Directory), 82-83
Ctrl+Alt+Del section (User Configuration policy sections), 105
custom security templates, 55
Custom Settings option (network card configuration), 18
custom topologies (DFS replicas), 145
customizing
applications, 160
desktop performance, 44-45
Start menu (Windows Server 2003), 46
support information URL via GPO Editor, 90
-d switches (MBSA), 257
DACL (discretionary access control lists), modifying, 196
data encryption, EFS, 61
data storage
NAS, 146-148
SAN, 146-147
databases, shadow copies (file sharing), 141
Datacenter Edition Server, 4, 8-9
DC security.inf security template, 53, 226
DDNS (Dynamic Domain Name Service), security, 63
deactivating schemas, Active Directory, 80-81
Debug Logging tab (DNS), 138
Default Utilities section (Start menu), 46
Defrag command-line tool, 238
Delegation tab (GPMC), 98
demand-dial connections, RRAS, 180
deploy.cab files, 21
deploying
32-bit applications, 230
software
DFS, 144-145
IntelliMirror, 230
Windows Server 2003
ADS, 28-31
hardware hashes, 24
product activation notifications, 25
RIS, 26-27
Windows product activation, 24-25
Deployment Agent Builder service (ADS), 30
designation rules (Fax Services), 141
desktop
performance, customizing, 44-45
Remote Assistance, 41
accessing, 42
controlling, 44
desktop control requests, 44
invitations, 42
screensavers, 36
themes, 35-36
wallpaper, 36
desktop control requests (Remote Assistance), 44
device drivers, installing, 17
devices groups, 140
DFS (Distributed File Systems)
domain-based DFS, 144
multiple roots, 145
replicas, 144-146
root clusters, 224
server-based DFS, 144
software deployment, 144-145
DFW, 162
DHCP (Dynamic Host Configuration Protocol), 134
Alternate Configuration tab, 135
APIPA, 135
security, 64
DHCP services
cluster resources, 213
clusters, 224
DHCPv6, 170
Diffie-Hellman key exchange (IPSec encryption), 172
direct metabase editing (IIS console), 125
disaster recovery
ASR, 17
CD-based installation (Windows Server 2003), 17
shadow copies (file sharing), 143
disconnected sessions (Terminal Servers), 204-207
Disk management console, SAN management, 147
disk partitioning
ESP, 270
Itanium computers (Intel), 269-271
Microsoft Data partitions, 270
MSR partitions, 270-271
OEM partitions, 270
Diskpart command-line tool, 238
displaying
fax devices, 140
GPO, GPMC, 98-99
records in WINS, 132
Distributed Transaction Coordinator, 224
DLC (Direct Link Control) protocol, 185
DNS (Domain Name Systems)
Active Directory integrated zones, 135-136
Debug Logging tab, 138
Event Viewer MMC snap-in, 138
forwarders, 138
Launch Nslookup option, 138
permission management, 138
recursion, 138
stub zones, 137
DNS Client section (Computer Configuration policy sections), 103
Do Not Allow Local Administrators to Customize Permissions settings (Terminal Service Group Policies), 196-197
Do Not Allow Smart Card Device Redirection settings (Terminal Service Group Policies), 197
documenting
assemblies, 157
assembly versions, 158
domain controllers
remote office logons (Active Directory), 84-85
replication, 82
Replication from Media feature (Active Directory), 85
domain events, auditing (security strategies), 67
domain functional levels (Active Directory)
Last Logon Timestamp attribute, 84
raising, 73
renaming domain controllers, 79
renaming domains, 79
Windows 2000 mixed, 72
Windows 2000 native, 72
Windows Server 2003, 72
domain user accounts, clusters, 214
domain-based DFS (Distributed File Systems), 144
DomainDNSZones (Active Directory integrated zones), 136
domains
AD/AM, 84
domain controllers, replication, 82
organizing, 75
remote office logons (Active Directory), 84-85
renaming, Active Directory administrative tools, 79
downloading
GPMC, 98
themes, 36
dragging/dropping
Active Directory administrative tools, 75
files to CD burners, 39
drivers
device drivers, installing, 17
installer routines, 64-bit Windows, 275
null drivers, 232
printer drivers (RDP 5.2), remapping 199
Zip drivers, 273
Dsadd command-line tool, 238
Dsget command-line tool, 238
DSML (Directory Services Markup Language), 162
Dsmod command-line tool, 238
Dsmove command-line tool, 238
Dsrm command-line tool, 238
duration (Remote Assistance invitations), 42
dynamic addresses (IPSec), 171-172
Dynamic DNS tab (DDNS), 134
editing
GPO, GPMC, 99
IIS console metabases, 125-126
port ranges for NLB clusters, 222-223
port settings for NLB clusters, 222
EFI (Extensible Firmware Interface), 271-272
EFS (Encrypting File System)
encrypted files, remote server storage, 149
implementing, 148
multiple-user access, 61
NTFS folders, 37
faxes, sending to inboxes, 139-141
invitations (Remote Assistance), 42
mailboxes, 126-128
sending via SMTP services, 127
EMS (Emergency Management Services)
components of, 234-236
!SAC, 235
SAC, 235-236
SPRC hardware, 20
Windows Server 2003 installation, 20
Windows Server 2003 remote installation, 20
Enable Result Caching option (WINS), 132
Enable TS per NIC settings (Terminal Service Group Policies), 198
encryption
asymmetric key, 148
EFS
implementing, 148
multiple-user access, 61
remote server storage, 149
IPSec, 172-173
passwords, Setup Manager Wizard, 22
remote server storage, 149
symmetric key, 148
Terminal Servers, 202
Web-based administration console, 121-123
WebDAV, 149
Encryption and Security section (Terminal Service Group Policies), 197
Enhanced Color and Resolution option (RDP 5.2), 200
Enhanced Performance in Low Bandwidth Environments option (RDP 5.2), 200-201
Enterprise Edition Server, 4, 7
Enterprise Services, 162
EPIC (Explicitly Parallel Instruction Computing) architectures (Intel), 268
Error Reporting feature (Computer Configuration policy sections), 103
ESP (EFI System Partitions), 270
event log policies (security), 54
Event Viewer MMC snap-in (DNS), 138
Eventcreate command-line tool, 238
Eventquery command-line tool, 238
Experiences tab (RDC client), configuring low bandwidth settings, 200-201
expressed IPv6 addresses, 167
Extended policy tab (GPO Editor), 92
-f switches (MBSA), 258
Factory mode (sysprep.exe utility), 23
failback policy (cluster resource groups), 217
failover policy (cluster resource groups), 217
farms (Terminal Servers), 203
disconnected sessions, 204
NLB, 210
Fax Administration console, 139
Fax Client console (Fax Services), 141
fax devices
configuring, 139-140
displaying, 140
Fax Monitor console (Fax Services), 141
Fax Services
designation rules, 141
devices groups, 140
Fax Client console, 141
fax devices, configuring, 139
Fax Monitor console, 141
fax printers, installing, 139
Fax Services management console, 140
installing, 140
limitations of, 140
routing faxes, configuration options, 139-140
Fax Services management console, 140
faxes
designation rules, 141
email inboxes, sending to, 139-141
fax devices
configuring, 139-140
displaying, 140
fax printers, installing, 139
routing, configuration options, 139-140
feature packs, 14
Enterprise Edition Server, 7
service packs as, 68
-fh switches (MBSA), 257
file extensions, security enhancements, 124
File Share Wizard (Computer management console), 144
file sharing
clusters, 224
DFS, 144-145
NAS, 146-148
Publish tab (Computer management console), 144
remote file sharing, WebDAV, 149-150
SAN, 146-147
shadow copies, 141-143
WebDAV, 149-150
file system policies (security), 54
files
auditing (security strategies), 67
deploy.cab, 21
ref.chm (unattended installations), 21
WUAU.adm files, Automatic Updates (SUS), 252
Zip files, 37-38
filtering Group Policy
Administrative Templates option (GPO Editor), 92-93
WMI filters, 88
financing Select License programs, 13
-fip switches (MBSA), 257
firewalls
ICF, 175-177
IPv6, moving to, 171
FireWire (IEEE-1394), Windows Server support, 183
firmware, 271-272
five nines reliability, 8
folders
auditing (security strategies), 67
compression, Compressed Folders feature (Windows Server 2003), 37-38
NTFS folders
compression, 36-37
EFS, 37
forest functional levels (Active Directory), 73
raising, 74
Windows 2000, 72
Windows Server 2003, 72
Windows Server 2003 Interim, 72
ForestDNSZones (Active Directory integrated zones), 136
forests, Group Policy cross-forest support, 89
formatting partitions, CD-based installation (Windows Server 2003), 17
forwarders (DNS), 138
Freedisk command-line tool, 239
fresh installs versus upgrades, 34
Fsutil command-line tool, 239
full mesh topologies (DFS replicas), 145
Full Screen mode (RDC clients), 193
functional levels (Active Directory)
domain functional levels
Last Logon Timestamp attribute, 84
raising, 73
renaming domain controllers, 79
renaming domains, 79
Windows 2000 mixed, 72
Windows 2000 native, 72
Windows Server 2003, 72
forest functional levels, 73
raising, 74
Windows 2000, 72
Windows Server 2003, 72
Windows Server 2003 Interim, 72
GC servers
remote office logons (Active Directory), 84-85
replication, 82
General tab (Terminal Server Properties dialog box), Connect to Console check box, 192
Getmac command-line tool, 239
global unicast addresses (IPv6), 169
GPMC (Group Policy Management Console), 89
Active Directory, 75
automation scripts, 99
Delegation tab, 98
downloading, 98
GPO
displaying, 98-99
editing, 99
Group Policy Inheritance tab, 98
Group Policy Modeling section, 99
Group Policy Results section, 99
RSoP MMC snap-ins, 99
tree-pane view, 98
GPO (Group Policy Objects), 59
Automatic Updates (SUS), configuring, 252-253
automating, GPMC, 99
cross-forest support, 89
displaying, GPMC, 98-99
editing, GPMC, 99
Administrative Templates option, 92-93
Extended policy tab, 92
Requirements section, 92
Software Installation section, 90
Standard policy tab, 92
WMI filters, 88
GPO Editor
Administrative Templates option, 92-93
Extended policy tab, 92
Requirements section, 92
Software Installation section, 90-91
Standard policy tab, 92
Gpresult command-line tool, 239
GPT (GUID Partition Tables)
32-bit Windows disk management utilities, 273
basic disks, 270
gpupdate command-line utility, refreshing Group Policy, 100
Group Policy, 87
64-bit Windows, 274
Automatic Updates (SUS), configuring, 254
Computer Configuration policy sections
Administrative TemplatesNetwork section, 103-104
Administrative TemplatesSystem section, 101-103
Administrative TemplatesWindows Components section, 101
Windows SettingsSecurity Settings section, 100
cross-forest support, 89
filtering, Administrative Templates option (GPO Editor), 92-93
GPMC (Active Directory), 75, 89
automation scripts, 99
downloading, 98
editing GPO, 99
tree-pane view, 98
GPO
configuring Automatic Updates (SUS), 252-253
cross-forest support, 89
WMI filters, 88
GPO Editor
Administrative Templates option, 92-93
Extended policy tab, 92
Requirements section, 92
Software Installation section, 90
Standard policy tab, 92
Include OLE Class and Product Information option, 91
Install This Application at Logon option, 90-91
managing
GPMC, 98-99
GPO Editor, 92-93
RSoP MMC snap-in, 93-97
Network Configuration Operators groups, 182
refreshing, 100
Remote Assistance control, 44
restricted group policies, 54
RIS management, 27
security, 59
Security Settings extension, Security Configuration Manager toolset, 52
setup security.inf security templates, 226
Software Restriction Group Policy, 203
software restriction policies, 230
Terminal Servers Session Directory Group Policy, 206-207
configuring, 195
configuring, Client/Server Data Redirection section, 197
configuring, Enable TS per NIC settings, 198
configuring, Encryption and Security section, 197
configuring, Licensing section, 198
configuring, NIC for Session Directory to Use for Redirection settings, 198
configuring, Permission Compatibility Full Security or Relaxed Security settings, 198
configuring, Session Directory section, 198
configuring, Terminal Service section, 196-197
RPC Security Policy/Secure Server (Require Security) Group Policy, 202
Set Client Connection Encryption Level Group Policy, 202
troubleshooting, RSoP MMC snap-in, 93-97
User Configuration policy sections
Administrative TemplatesShared Folders section, 105
Administrative TemplatesSystem section, 105-106
Administrative TemplatesWindows Components section, 104-105
wireless networks, 185
WMI filters, 88
Group Policy Inheritance tab (GPMC), 98
Group Policy Management Console, IntelliMirror, 230
Group Policy MMC snap-in, 91
Group Policy Modeling section (GPMC), 99
Group Policy Results section (GPMC), 99
Guest Access permissions (Terminal Servers), 202
GUID (Globally Unique Identifiers)
ESP, 270
Microsoft Data partitions, 270
MSR partitions, 270-271
OEM partitions, 270
-h switches (MBSA), 257
Hammer (AMD), 269
hardware
32-bit Windows, 273
64-bit Windows, 273
device drivers, installing, 17
headless servers, 225, 231-233
SPRC hardware, EMS, 20
hardware hashes, 24
hardware
OOB management, 232-233
PXE-compliant network adapters, 233
remote-control hardware, 233
serial ports, 232
specifications, 232
UPS, 234
software, EMS, 234-236
Health tab (IIS console), 116
heartbeat signals, 212
Help and Support Center section (User Configuration policy sections), 104
/hf switches (MBSA), 257
HFNetChk command-line tool, 257-258. See also MBSA
hisecdc.inf security template, 53, 227
hisecws.inf security template, 54, 227
hot fixes
availability of, 244
Security hot fixes. See security updates
service packs, 244-245
hot fixes (security maintenance), 68
hot-add memory, Enterprise Edition Server, 7
http.sys drivers, 110-112, 124
hub and spoke topologies (DFS replicas), 145
-I ipaddress switches (MBSA), 257
Ia641dr.efi boot loader, 271
IAS (Internet Authentication Services), 83, 166
ICA protocol (Citrix Metaframe) versus RDP 5.2, 201-202
ICF. See Windows Firewalls
ICMP (Internet Control Message Protocol) tab (Advanced Settings dialog box), 177
ICS (Internet Connection Sharing), 174
Identity Integration Feature Pack (Active Directory), 75
Identity tab (IIS console), 118
IEEE-1394 (FireWire), Windows Server support, 183
IIS (Internet Information Services) console, 66, 107
administration, ABO, 114
architecture of, 110
application pools, 110-113, 116-118
http.sys drivers, 110-112, 124
worker processes, 110-112, 116, 123-124
WWW Service Administrator and Monitoring component, 112
ASP.NET, 124
backward compatibility, 114
Classic ASP, 124
clusters, 223
Health tab, 116
Identity tab, 118
in-process applications, 112
list of improvements, 108
log files, auditing (security strategies), 67
metabases
editing, 125
saving changes, 126
passport authentication, 115
Performance tab, 117-118
POP3 services, 126-128
rapid fail protection, 113, 116
Recycling tab, 116
security enhancements, 123-124
server administration, 115
server configuration, 115
SMTP services
relaying, 126
sending email, 127
upgrading, 124
Web Services extensions, configuring, 119-120
Web site administration/configuration, 115
Web-based administration console, security, 121-123
Iisback command-line tool, 239
Iiscnfg command-line tool, 239
Iisftp command-line tool, 239
Iisftpdr command-line tool, 239
Iisvdir command-line tool, 239
Iisweb command-line tool, 239
IL (Intermediate Language), .NET Framework, 153-159
image distribution services (ADS), 29
images, ADS, 31
imaging software installation (Windows Server 2003), 23
importing security templates to security databases, 56
in-process applications, 112
Include OLE Class and Product Information option (Group Policy), 91
Infiniband, 269
Install This Application at Logon option (Group Policy), 90-91
installing
device drivers, 17
fax printers, 139
Fax Services, 140
IPv6 stacks, 170
Remote Desktop Web Connection clients, 194
RIS, 27
security templates, 226
Setup Manager Wizard, 21
SUS, 246
Terminal Server Session Directory, 205
Terminal Services, 189
Windows Server 2003, 15
attended installations, 16-20
CD-based installation, 16-19
default installation directory, 17
EMS, 20
imaging software installation, 23
network-based installation, 19-20
remote installation, EMS, 20
unattended installations, 21-22
WMIC, 237
installs, upgrades versus fresh installs, 34
instant message invitations (Remote Assistance), 42
IntelliMirror, 230
interactive mode (WMIC), 237
Internet. See also networking
Inuse command-line tool, 239
inventorying updates, MBSA, 256-258
invitation files (Remote Assistance), 42
IP addresses
APIPA, 134-135
cluster resources, 212
clusters, creating, 214
conflicts, 134
IPv6, 165
anycast addresses, 168
compatibility addresses, 168
compressed addresses, 167
expressed addresses, 167
loopback addresses, 168
mapped addresses, 168
multicast addresses, 167-168
unicast addresses, 167-169
unspecified addresses, 168
MBSA, 257
NLB clusters, 220
IP Security Monitor console, 173-174
IP Security Policies console, certificate mapping, 172
IPSec (Internet Protocol Security), 166
certificate mapping, 172
dynamic addresses, 171-172
encryption, 172-173
IP Security Monitor console, 173-174
IPSec/L2TP tunnels, VPN servers, 171
Netsh.exe command-line tool, 174
IPSec/L2TP tunnels, VPN servers, 171
IPv6, 165
CIDR, 168
development Web site, 166, 169
IP addresses
anycast addresses, 168
compatibility addresses, 168
compressed addresses, 167
expressed addresses, 167
loopback addresses, 168
mapped addresses, 168
multicast addresses, 167-168
unicast addresses, 167-169
unspecified addresses, 168
IPv6 stacks, 169-170
IPX/SPX protocol, 185
IrDA protocol, 185
isolation mode (worker processes), 112
Itanium 2 processors (Intel), 268-269
Itanium computers (Intel)
32-bit Windows, 274
boot architectures, 271-272
disk partitioning, 269-271
firmware, 271
Ia641dr.efi boot loader, 271
Itanium processors (Intel)
EPIC architectures, 268
memory support, 269
Jaz drives, 273
JIT (just in time) compilation, 154
job templates (ADS), 30
Join Session Directory setting (Terminal Server Session Directory Group Policy), 206
JVM (Java Virtual Machines), 154
Keep-Alive Connections settings (Terminal Service Group Policies), 196
Kerberos protocols, security, 63
lame delegations (NS records), 137
LAR (Large Account Resellers), Select License programs, 13
Last Logon Timestamp attribute (Active Directory), 84
latency, domain controller replication, 82
Launch Nslookup option (DNS), 138
license agreements
Open License agreements, 26
Select License agreements, 26
Windows product activation, 24-25
Windows Server 2003, CD-based installation, 17
license keys
Setup Manager Wizard, 21
Windows product activation, 25
Open License keys, 26
Select License keys, 26
License Server Security Group settings (Terminal Service Group Policies), 198
licenses
CAL, 11
Open License programs, 11-12
Select License programs, 12-13
server licenses, 11
Software Assurance programs, 13
Licensing section (Terminal Service Group Policies), 198
Limit Maximum Color Depth settings (Terminal Service Group Policies), 196
link-local unicast addresses (IPv6), 168
load balancing, farms (Terminal Servers), 203-204
local administrator passwords, Setup Manager Wizard, 22
local policies (security), 54
local resources
remapping, RDP 5.2, 199
security, 199
Local Security Policy MMC snap-in (Security Configuration Manager toolset), 52
Logging mode (RSoP MMC snap-in), 95-96
logical drives, cluster resources, 213
logins, NLB clusters, 223
Logman command-line tool, 239
loopback addresses (IPv6), 168
low bandwidth settings, configuring, 200-201
mailboxes, 126-128
maintaining security (security strategies)
hot fixes, 68
security updates, 69
service packs, 68
maintenance
administrative scripts, VBScript, 258-262
backups
ASR, 263-265
BackupExec (Veritas), 263
BrightStor (Computer Associates), 263
Windows Backup, 262
hot fixes, 244-245
security updates, 244
MBSA, 256-258
service packs, 244-245
SUS, 245
Approval Log, 255
approving updates, 250-251
automatic update approval, 254
Automatic Updates, 251-254
configuring, 248
configuring synchronization schedules, 248
installing, 246
Monitor Server page, 255
running updates, 251
saving updates, 246
starting synchronizations, 248
update availability, 246
System Restore, 263
Windows Update, 245-246
majority node set clusters, 211
Manage Your Server application, configuring RRAS as NAT/firewall servers, 178-179
Manage Your Server Wizard, 19
managing
application remote services, 160
applications
via .NET Framework Configuration console, 156, 160
Web services, 161
assembly cache (.NET Framework Configuration console), 156-157
clusters, 215
code access security policies (.NET Framework Configuration console), 156-159
configured assemblies (.NET Framework Configuration console), 156-158
Group Policy
GPMC, 98-99
GPO Editor, 92-93
RSoP MMC snap-in, 93-97
partitions, Ntdsutil utility, 80
permissions in DNS, 138
remoting services (.NET Framework Configuration console), 156, 160
RIS, 27
SANS, Disk management console, 147
manual backups, DHCP, 134
mapped addresses (IPv6), 168
mapping
local resources (RDP 5.2), 199
printer drivers (RDP 5.2), 199
mass upgrades, 34
MBR (master boot records), 269, 273
MBSA (Microsoft Baseline Security Analyzer), 60-61, 256-258
memory
64-bit Windows, 269
hot-add memory, Enterprise Edition Server, 7
NUMA, Enterprise Edition Server, 7
message queuing, clusters, 224
metabases (IIS console)
editing, 125
saving changes, 126
Microsoft Data partitions, 270
Microsoft security philosophy, 50-51
Microsoft Security Web site, 110
MIIS (Microsoft Identity Integration Server)
Enterprise Edition server, 7
Standard Edition server, 6
MMC (Microsoft Management Console) tutorial Web site, 228
modifying
application properties, 160
DACL, 196
Monitor Server page (SUS), 255
MSMQ (Microsoft Message Queue Service), 163
MSR (Microsoft Reserved) partitions, 270-271
mstsc.exe (RDC clients), 187
multicast addresses (IPv6), 167-168
multipath failover, SAN, 147
multiple applications, assigning to application pools (IIS console), 113
multiple DFS roots, 145
multiple objects, selecting via Active Directory administrative tools, 75
multiple replicas (DFS), 146
-n switches (MBSA), 257
naming clusters, 214
NAS (network attached storage), 146-148
NAT/firewall servers, configuring as RRAS, 178-179
64-bit Windows, 274
applications, executing, 153-154
ASP.NET, 163
IL, 153-159
JIT compilation, 154
native code applications, 152, 155
programming languages, 153
runtime security, 163
.NET Framework Configuration console, 155
application management, 156, 160
assembly cache management, 156-157
code access security policy management, 156-159
configured assembly management, 156-158
remoting services management, 156, 160
Net Logon section (Computer Configuration policy sections), 102
NetBEUI protocol, 185
NetBIOS (network basic input/output systems), WINS, 132
NetMeeting, 64-bit Windows, 275
NetMon (Network Monitor), 64-66
netsh command (DHCP), 134
netsh interface ipv6 command, configuring IPv6 stacks, 170
Netsh.exe command-line tool, 174
Netstat tool, 183
network boot services (ADS), 29
network bridging, 183
network cards, CD-based installation (Windows Server 2003), 18
Network Configuration Operators groups, 182
Network Connections section (Computer Configuration policy sections), 103
Network Location Awareness feature, 181
network services
DHCP, 134-135
DNS
Active Directory integrated zones, 135-136
Debug Logging tab, 138
Event Viewer MMC snap-in, 138
forwarders, 138
Launch Nslookup option, 138
permission management, 138
recursion, 138
stub zones, 137
WINS, 132-133
network-based installation (Windows Server 2003), 19-20
networking
IPv6, 165-167
CIDR, 168
development Web site, 166, 169
IP addresses, 167-169
IPv6 stacks, 169-170
PPPoE, 166
Networking tab (Windows Task Manager), 181
networks
changes in settings, Network Location Awareness feature, 181
configuring, automatic network configuration feature, 183
IEEE-1394 (FireWire) support, 183
Netstat tool, 183
permanent virtual circuit encapsulation (xDSL), 184
wireless networks, 184-185
New Cluster Wizard (Cluster Administrator), 213-214
New Resource dialog box (Cluster Administrator), adding resources to clusters, 215
NIC for Session Directory to Use for Redirection settings (Terminal Service Group Policies), 198
NLB (Network Load Balancing), 163, 209-210. See also Cluster Service
clusters
adding members to, 221
alternative login credentials, 223
configuring, 219
configuring port rules, 221
creating, 219-220
editing port ranges, 222-223
editing port settings, 222
error checking, 221
IP addresses, 220
remote control feature, 219
request handling, 218
selecting network interface, 220
specifying affinity modes, 220
specifying port rules, 220
IIS clusters, 223
NLB (Network Load Balancing) command-line tool, 239
NLB Manager
alternative login credentials feature, 223
Cluster Parameters dialog box, configuring clusters, 219
clusters, configuring, 219-220
nodes
cluster resources, 213
clusters, adding to, 214
resource ownership, specifying in cluster creation, 215
resources, transferring, 216
none property (NLB cluster port ranges), 222
Notepad, VBScript writing/testing, 258-259
notssid.inf security template, 227
NS (name server) records, 137
Ntdsutil utility, managing partitions, 80
NTFS (NT File System)
file permissions, 54
folders
compression, 36-37
EFS, 37
null drivers, 232
NUMA (non-uniform memory access), Enterprise Edition Server, 7
OEM partitions, 270
OOB (out of bandwidth) management
EMS, 234-236
headless server hardware specifications, 232-233
Open Business programs (Open License program), 11-12
Open License agreements (Windows product activation), 26
Open License keys (Windows product activation), 26
Open License programs, 11-12
Open Volume programs (Open License program), 11-12
Openfiles command-line tool, 239
operating system upgrades, 33
OSPF (Open Shortest Path First) protocol, 185
-p switches (MBSA), 258
Pagefileconfig command-line tool, 239
partitions
application partitions, Active Directory, 80
ESP, 270
formatting, CD-based installation (Windows Server 2003), 17
images, ADS, 31
Itanium computers (Intel), 269-271
managing, Ntdsutil utility, 80
Microsoft Data partitions, 270
MSR partitions, 270-271
OEM partitions, 270
schema deactivation, Active Directory, 80-81
passport authentication, IIS console, 115
passwords
CD-based installation (Windows Server 2003), 18
encryption, Setup Manager Wizard, 22
local administrator passwords, Setup Manager Wizard, 22
security databases, 59
Terminal Servers, 202
PCI peripheral bus architectures. See Infiniband
Pentium processors, 268
per-client licenses (CAL), 11
per-seat licenses (CAL), 11
Perfmon command-line tool, 239
performance, setup security.inf security templates, 226
Performance tab (IIS console), 117-118
permanent virtual circuit encapsulation (xDSL), 184
Permission Compatibility Full Security or Relaxed Security settings (Terminal Service Group Policies), 198
permission sets, 158-159
permissions
access permissions, Terminal Servers, 202
managing in DNS, 138
Remote Desktop for Administration (Terminal Services) permissions, assigning, 191
showing, Active Directory administrative tools, 75
showing inheritance parents, Active Directory administrative tools, 75
personalizing CD-based installation (Windows Server 2003), 18
PFE (Programmer's File Editor), writing VBScript, 258
Pinned Programs section (Start menu), 45
Planning mode (RSoP MMC snap-in), 95-97
point commitments (Select License programs), 13
policies
security policies, RSoP (Active Directory administrative tools), 78
software restriction policies
components of, 228-229
Group Policy, 230
POP3 services
IIS consoles, 126-128
SMTP services, 128
port numbers, Web-based administration console security, 123
port range property (NLB cluster port ranges), 223
power management, 64-bit Windows, 275
Power Management section (User Configuration policy sections), 106
PPPoE (Point-to-Point over Ethernet), 166
RRAS, 179
Windows Server support, 182
Precedence tab (RSoP MMC snap-in), 93
preconfigured clusters, 211
preinstalled assemblies (Windows Server 2003), 157
Prevent License Upgrade settings (Terminal Service Group Policies), 198
printer drivers, remapping, 199
printer spools, clusters, 224
printers
64-bit Windows, 275
fax printers, installing, 139
private keys. See asymmetric key encryption
Prncnfg command-line tool, 239
Prndrvr command-line tool, 239
Prnjobs command-line tool, 239
Prnmngr command-line tool, 239
Prnport command-line tool, 239
Prnqctl command-line tool, 239
product activation
64-bit Windows, 275
notifications (Windows Server 2003), 25
software
product ID, 13
troubleshooting, 14
volume license keys, 14
product activation notifications (Windows Server 2003), 25
product development, RC cycles, 50
product ID, 13
versus volume license keys, 14
viewing, 24
product support, Datacenter Edition Server, 8
Properties dialog box
Cluster Administrator, 216
Terminal Server, 192
protocol property (NLB cluster port ranges), 223
protocols
DHCP
Alternate Configuration tab, 134-135
APIPA, 134-135
automated backups, 134
Dynamic DNS tab, 134
manual backups, 134
netsh command, 134
security, 64
DLC, 185
ICA (Citrix Metaframe) versus RDP 5.2, 201-202
IPSec, 166
IPv6, 165
CIDR, 168
development Web site, 166, 169
IP addresses, 167-168
IPv6 stacks, 169-170
IPX/SPX, 185
IrDA, 185
Kerberos security, 63
NetBEUI, 185
OSPF, 185
Console connections, 194
Enhanced Color and Resolution option, 200
Enhanced Performance in Low Bandwidth Environments option, 200-201
remapping local resources, 199
remapping printer drivers, 199
Shared Clipboard option, 200
smart card redirection support, 203
Sound Card Redirection option, 200
Time Zone Redirection option, 201
versus ICA protocol (Citrix Metaframe), 201-202
SMTP services
IIS consoles, 126-127
POP3 services, 128
SOAP, 161-163
public keys. See asymmetric key encryption
Publish tab (Computer management console), file sharing, 144
purchasing
Open License programs, 12
Select License programs, 12-13
Software Assurance programs, 13
PXE services, ADS, 30
PXE-compliant network adapters, headless servers, 233
QFE (quick-fix engineering). See hot fixes
QoS Packet Scheduler section (Computer Configuration policy sections), 104
queries, Saved Queries feature (Active Directory administrative tools), 76
cluster resources, 213
single quorum device clusters, 211
-r switches (MBSA), 257
raising
domain functional levels (Active Directory), 73
forest functional levels (Active Directory), 74
rapid fail protection (IIS console), 113, 116
RC (release candidate) cycles, 50
RC4 (128-bit) encryption, Terminal Servers, 202
RDC (Remote Desktop Connections) clients, 187
control keys, configuring functions, 193
enabling, 191
Experiences tab, configuring low bandwidth settings, 200-201
Full Screen mode, 193
Enhanced Color and Resolution option, 200
Enhanced Performance in Low Bandwidth Environments option, 200-201
Shared Clipboard option, 200
Sound Card Redirection option, 200
Time Zone Redirection option, 201
Terminal Server console sessions, connecting to, 192
RDP (Remote Desktop Protocol) 5.2, 188, 191-193, 199
Console connections, 194
Enhanced Color and Resolution option, 200
Enhanced Performance in Low Bandwidth Environments option, 200-201
local resources, remapping, 199
printer drivers, remapping, 199
Shared Clipboard option, 200
smart card redirection support, 203
Sound Card Redirection option, 200
Time Zone Redirection option, 201
versus ICA protocol (Citrix Metaframe), 201-202
Recently Used Programs section (Start menu), 45
records
copying, Active Directory integrated zones (DNS), 135
NS (name server) records, 137
storing, Active Directory integrated zones (DNS), 135
WINS, caching in, 132
recursion (DNS), 138
Recycling tab (IIS console), 116
ref.chm files (unattended installations), 21
refreshing Group Policy, 100
registry policies (security), 54
Relay Restrictions dialog box (SMTP services), 126
relaying SMTP services, IIS consoles, 126
reliability, Datacenter Edition Server, 8-9
Relog command-line tool, 239
remote administration (Terminal Services), headless servers, 231
hardware
OOB management, 232-233
PXE-compliant network adapters, 233
remote-control hardware, 233
serial ports, 232
specifications, 232
UPS, 234
software, EMS, 234-236
Remote Administration mode (Terminal Services), 189. See also Remote Desktop for Administration
Remote Assistance, 41
64-bit Windows, 275
accessing, 42
controlling, 44
desktop control requests, 44
invitations, 42
Remote Assistance section (Computer Configuration policy sections), 102
remote clients, RQS, 182
remote control feature (NLB clusters), 219
remote control feature packs, 230
Remote Desktop, 41
Remote Desktop for Administration (Terminal Services), 189. See also Remote Administration mode (Terminal Services)
enabling, 190
permissions
assigning, 191
virtual desktop connections, 194
security, 191
Remote Desktop Users group (Terminal Servers), establishing access permissions, 202
Remote Desktop Web Connection clients, 194
Remote Desktops MMC snap-in (Terminal Services)
RDP 5.2, 191
Terminal Server console sessions, connecting to, 192
remote file sharing, WebDAV, 149-150
Remote Install tab (Windows Server 2003), 27
remote installing Windows Server 2003, EMS, 20
remote monitoring, IP Security Monitor console (IPSec), 174
remote office logons (Active Directory), 84-85
Remote Procedure Call (Computer Configuration policy sections), 103
remote servers
command-line tools, 236
encrypted file storage, 149
Remote tab (System Properties dialog box), enabling Remote Desktop for Administration (Terminal Services), 190
remote-control hardware (headless servers), 233
remoting services (.NET Framework Configuration console), managing, 156, 160
Remove and Prevent Access to the Shut Down command, 105
Remove Disconnect Option from Shut Down Dialog settings (Terminal Service Group Policies), 197
Remove Windows Security Item from Start Menu settings (Terminal Service Group Policies), 197
renaming
domain controllers, 79
domains, 79
repairing applications, 160
replicas (DFS), 144-145
replication
domain controllers, 82
GC servers, 82
replication exclusion lists, 145
Replication from Media feature (Active Directory), 85
Requirements section (GPO Editor), 92
resource groups (clusters), 213-217
resources (clusters)
application services, 213
clusters, adding to, 215
clusters, specifying in, 216
clusters, transferring in, 216
computer names, 212
dependencies, 213
IP addresses, 212
logical drives, 213
node failures, 213
ownership transferals, 213
properties, 216
quorums, 213
resource groups, 213-217
Restrict Terminal Services Users to a Single Remote Session settings (Terminal Service Group Policies), 196
restricted group policies (security), 54
Resultant Set of Policy Wizard, 93
ring topologies (DFS replicas), 145
RIS (Remote Installation Services), 26
configuring, 27
installing, 27
managing, 27
versus ADS, 28
RIS Setup Properties Wizard, 27
rootsec.inf security template, 227
routers, moving to IPv6, 171
routing faxes, configuration options, 139-140
RPC Security Policy/Secure Server (Require Security) Group Policy (Terminal Services), 202
RPC session security, configuring, 202
RQS (RAS Quarantine Service), 182
RRAS (Routing and Remote Access Service), 177
demand-dial connections, 180
EAP-TLS configurations, 178
name resolution requests, handling, 178
NAT/firewall servers, configuring as, 178-179
PPPoE, 179
VPN servers, 179-180
RSoP (Resultant Set of Policy) MMC snap-ins, 93
configuring, 77
GPMC, 99
IntelliMirror, 230
policies, displaying data, 95-97
Precedence tab, 93
Resultant Set of Policy Wizard, 93
security policies, 78
starting, 77
user configuration policies, 95-97
user rights policies, 94
Rss command-line tool, 239
/S parameters (command-line tools), 236, 240
-s switches (MBSA), 258
!SAC (!Special Administration Console) EMS, 235
SAC (Special Administration Console), EMS, 235-236
SAK (Server Appliance Kits), 232
SAN (storage area networks), 146-147
Saprep.exe utility (SAK), null drivers, 232
Saved Queries feature (Active Directory administrative tools), 76
saving
IIS console metabase changes, 126
SUS updates, 246
Sc command-line tool, 239
SCA (Security Configuration and Analysis) MMC snap-in (Security Configuration Manager toolset), 52-53, 56
scheduling shadow copies (file sharing), 142
schemas, deactivating, 80-81
Schtasks command-line tool, 239
screensavers (desktop), 36
Scripts section
Computer Configuration policy sections, 102
User Configuration policy sections, 105
Secedit.exe command-line tool (Security Configuration Manager toolset), 52, 59, 228
securedc.inf security template, 54, 227
securews.inf security template, 54, 227
security, 49
account policies, 54
auditing, 67
code access security policy management (.NET Framework Configuration console), 156-159
cross-forest trusts (Active Directory), 82-83
data encryption, EFS, 61
DDNS, 63
default configurations, 51
DHCP, 64
EFS
implementing, 148
remote server storage, 149
encryption
asymmetric key, 148
remote server storage, 149
symmetric key, 148
WebDAV, 149
event log policies, 54
file system policies, 54
firewalls, ICF, 175-177
Group Policy, 59
IIS, 66-67
IPSec, 166
certificate mapping, 172
dynamic addresses, 171-172
encryption, 172-173
IP Security Monitor console, 173-174
IPSec/L2TP tunnels, 171
Kerberos protocol, 63
local policies, 54
local resources, 199
maintenance (security strategies)
hot fixes, 68
security updates, 69
service packs, 68
MBSA, 60-61
Microsoft security philosophy, 50-51
Microsoft Security Web site, 110
NeMon, 64
.NET Framework, 163
NetMon, 65-66
NLB clusters
alternative login credentials, 223
remote control feature, 219
NTFS file permissions, 54
passwords
CD-based installation (Windows Server 2003), 18
encryption in Setup Manager Wizard, 22
local administrator passwords in Setup Manager Wizard, 22
security databases, 59
account policies, 54
event log policies, 54
file system policies, 54
local policies, 54
registry policies, 54
restricted group policies, 54
system service policies, 54
RC cycles, 50
registry policies, 54
Remote Desktop for Administration (Terminal Services), 191
Remote Desktop Users group (Terminal Servers), establishing access permissions, 202
restricted group policies, 54
RPC session security, configuring, 202
RSoP MMC snap-in (Active Directory administrative tools) policies, 78
Security Configuration Manager toolset, 51
Local Security Policy MMC snap-in, 52
Secedit.exe command-line tool, 52, 59
Security Settings extension (Group Policy), 52
Security Templates MMC snap-in, 52-53, 55
security holes, 62
security policies, 54
security templates, 52
account policies, 54
creating custom templates, 55
definitions, 55
different OS, 59
event log policies, 54
file system policies, 54
local policies, 54
registry policies, 54
restricted group policies, 54
snap-ins, 53-56
system service policies, 54
strategy development
auditing security, 67
security maintenance, 68-69
system service policies, 54
Terminal Servers
encryption, 202
passwords, 202
smart card redirection support, 203
Terminal Services, Application Server mode, 202
Web-based administration console, 121-123
WebDAV, 149
Windows product activation, 24-25
WMIC, 237
Security Configuration and Analysis MMC snap-in, applying security templates, 228
Security Configuration Manager toolset, 51
Local Security Policy MMC snap-in, 52
Secedit.exe command-line tool, 52, 59
Security Settings extension (Group Policy), 52
Security Templates MMC snap-in, 52
compatws template, 53
configuring, 55
DC security template, 53
hisecdc template, 53
hisecws template, 54
securedc template, 54
securews template, 54
security databases
analyzing, 57
manual configuration, 58
password policies, 59
SCA MMC snap-ins, 56
security templates, importing to, 56
security hot fixes. See security updates
Security Logging tab (Advanced Settings dialog box), 177
Security Settings extension (Group Policy), Security Configuration Manager toolset, 52
Security tab (Terminal Services Configuration MMC snap-in), 196
security templates, 52
applying, 228
compatws.inf, 226
custom templates, 55
DC security.inf, 226
definitions, 55
different OS, 59
hisecdc.inf, 227
hisecws.inf, 227
installing, 226
notssid.inf, 227
rootsec.inf, 227
securedc.inf, 227
securews.inf, 227
security databases
analyzing, 57
importing to, 56
security policies, 54
setup security.inf, 226
snap-ins, 53-54
configuring, 55
security databases, 56
Security Templates MMC snap-in (Security Configuration Manager toolset), 52
compatws template, 53
configuring, 55
DC security template, 53
hisecdc template, 53
hisecws template, 54
securedc template, 54
securews template, 54
security updates, 69
MBSA, 256-258
service packs, 244-245
Select License agreements (Windows product activation), 26
Select License keys (Windows product activation), 26
Select License programs, 12-13
Select Remote Users button (System Properties dialog box), 191
sending
email via SMTP services, 127
faxes to email inboxes, 139-141
files to CD burners, 40
serial ports, Windows requirements, 232
server appliances. See headless servers
server licenses, 11
server-based DFS (Distributed File Systems), 144
servers
64-bit servers, Itanium processors (Intel), 268
administration, IIS console, 115
application servers, defining, 109
configuring
CD-based installation (Windows Server 2003), 19
IIS console, 115
DNS servers, recursion, 138
farms, NLB, 210
feature packs, 14
GC servers, 82-85
hardware, 232-234
software, EMS, 234-236
heartbeat signals, 212
NAT/firewall servers, configuring RRAS as, 178-179
remote servers
command-line tools, 236
encrypted file storage, 149
server licenses, 11
SQL servers, cluster resources, 213
Standard Edition, 4
MIIS, 6
uses of, 5-6
Terminal Servers, 227
VPN, RRAS, 179-180
Web Edition, 4
costs of, 9
UDDI, 10
uses of, 10
Services tab (Advanced Settings dialog box), 177
Session Directory Cluster Name setting (Terminal Server Session Directory Group Policy), 206
Session Directory section (Terminal Service Group Policies), 198
Session Directory Server setting (Terminal Server Session Directory Group Policy), 206
session states, IIS console upgrades, 124
Set Client Connection Encryption Level Group Policy (Terminal Services), 202
Setup Manager Wizard, 21-22
Setup Properties Wizard (RIS), 27
setup security.inf security template, 226
Setup Wizard, 33
Setx command-line tool, 239
shadow copies (file sharing)
creating, 142
databases, 141
disaster recovery, 143
managing, vssadmin command-line utility, 142
scheduling, 142
Shadow Copies tab, 142
viewing, 143
Shared Clipboard option (RDP 5.2), 200
Show Clients button (Remote Install tab), 27
Shutdown button. See Remove and Prevent Access to the Shut Down command
Shutdown command-line tool, 239
SID (Security Identifiers), Terminal Servers, 227
single node clusters, 211
single property (NLB cluster port ranges), 222
single quorum device clusters, building, 211
single-host addresses. See unicast addresses
site-local unicast addresses (IPv6), 169
smart card redirection support (Terminal Servers), 203
SMS (Systems Management Server), 245
update inventories, 258
versus IntelliMirror, 230
SMTP (Simple Mail Transfer Protocol) services
IIS consoles, 126
relaying, 126
sending email, 127
POP3 services, 128
snap-ins
Event Viewer (DNS), 138
Group Policy MMC snap-ins, 91
Local Security Policy (Security Configuration Manager toolset), 52
Remote Desktops MMC snap-ins (Terminal Services)
connecting to Terminal Server console sessions, 192
RDP 5.2, 191
RSoP MMC snap-ins (Active Directory administrative tools)
configuring, 77
GPMC, 99
IntelliMirror, 230
Logging mode, 95-96
Precedence tab, 93
Resultant Set of Policy Wizard, 93
security policies, 78
starting, 77
user configuration policies, 95-97
user rights policies, 94
SCA (Security Configuration Manager toolset), 52-53, 56
Security Configuration and Analysis MMC snap-in, 228
Security Templates (Security Configuration Manager toolset), 52
compatws template, 53
configuring, 55
DC security template, 53
hisecdc template, 53
hisecws template, 54
securedc template, 54
securews template, 54
Terminal Services Configuration MMC snap-in (Terminal Services), 195-196
Terminal Services Manager MMC snap-in (Terminal Services), 195
SNMP section (Computer Configuration policy sections), 104
SOAP (Simple Object Access Protocol), 161-163
software
32-bit Windows, 272-273
64-bit Windows, 272-273
deploying
DFS, 144-145
IntelliMirror, 230
development
.NET Framework, 151-159
traditional programming procedures, 152-153
Group Policy development, 274
product activation
product ID, 13
troubleshooting, 14
volume license keys, 14
restriction policies, 100
components of, 228-229
Group Policy, 230
upgrades, 13
Software Assurance programs, costs of, 13
Software Installation section (GPO Editor)
64-bit operating system options, 91
support information URL modification, 90
Software Restriction Group Policy (Terminal Servers), 203
Software Restriction policies (Computer Configuration policy sections), 100, 228-230
Sound Card Redirection option (RDP 5.2), 200
SPRC hardware, EMS, 20
SQL servers, cluster resources, 213
Standard Edition Server, 4
MIIS, 6
uses of, 5-6
Standard Folders section (Start menu), 46
Standard policy tab (GPO Editor), 92
Start menu (Windows Server 2003)
All Programs Menu section, 46
Control Panel section, 46
customizing, 46
Default Utilities section, 46
Pinned Programs section, 45
Recently Used Programs section, 45
shortcuts, 47
Standard Folders section, 46
starting
RSoP MMC snap-in (Active Directory administrative tools), 77
SUS synchronizations, 248
storing
data
NAS, 146-148
SAN, 146-147
records, Active Directory integrated zones, 135
stub zones (DNS), 137
subnet masks, 167-168
superfloppies, 273
SUS (Software Update Service), 245-246
Approval Log, 255
Automatic Updates, 251
client configuration behavior, 253-254
configuring, Group Policy settings, 254
configuring, 248
installing, 246
Monitor Server page, 255
synchronizations, 248
updates
approving, 250-251
automatic approval of, 254
availability of, 246
running, 251
saving, 246
symmetric key encryption, 148
synchronizations (SUS), 248
sysprep.exe utility, 23
System Properties dialog box
Remote tab, enabling Remote Desktop for Administration (Terminal Services), 190
Select Remote Users button, 191
System Restore feature (Computer Configuration policy sections), 102, 263
system service policies (security), 54
system state backups, 262
Systeminfo command-line tool, 240
Takeown command-line tool, 240
Taskkill command-line tool, 240
Tasklist command-line tool, 240
TCP connections, Netstat tool, 183
TCP/IP, clusters, 213
templates
compatws (Security Templates MMC snap-in), 53
DC security (Security Templates MMC snap-in), 53
hisecdc (Security Templates MMC snap-in), 53
hisecws (Security Templates MMC snap-in), 54
job templates (ADS), 30
securedc (Security Templates MMC snap-in), 54
securews (Security Templates MMC snap-in), 54
security templates, 52
account policies, 54
analyzing security databases, 57
applying, 228
compatws.inf, 226
creating custom templates, 55
DC security.inf, 226
definitions, 55
different OS, 59
event log policies, 54
file system policies, 54
hisecdc.inf, 227
hisecws.inf, 227
importing to security databases, 56
installing, 226
local policies, 54
notssid.inf, 227
registry policies, 54
restricted group policies, 54
rootsec.inf, 227
securedc.inf, 227
securews.inf, 227
setup security.inf, 226
snap-ins, 53-56
system service policies, 54
Terminal Server (Terminal Services), 190
access permissions, establishing, 202
Connection bars (RDC clients), 193
encryption, 202
farms, 203-204
passwords, 202
Properties dialog box, 192
Remote Desktop Users group, establishing access permissions, 202
SID, notssid.inf security templates, 227
smart card redirection support, 203
Terminal Server IP Address Redirection setting (Terminal Server Session Directory Group Policy), 206-207
Terminal Server Session Directory, 188, 198, 203-204
configuring, 205
disconnected sessions, 205-207
Enterprise Edition Server, 7
Group Policy, 206-207
installing, 205
Terminal Services
ADSI scripting, 198
Application Server mode, 189, 202
defining, 188
Group Policy
configuring, 195-198
RPC Security Policy/Secure Server (Require Security) Group Policy, 202
installing, 189
RDC clients, 187
configuring control key functions, 193
connecting to Terminal Server console sessions, 192
enabling, 191
Experiences tab, 200-201
Full Screen mode, 193
Full Screen mode, Connection bars, 193
RDP 5.2, 188, 191-193, 200-201
remote administration, headless servers, 231-236
Remote Administration mode, 189
Remote Desktop for Administration, 189
assigning permissions, 191
enabling, 190
security, 191
virtual desktop connections, 194
Remote Desktop Web Connection clients, 194
Remote Desktops MMC snap-in, 191-192
Set Client Encryption Level Group Policy, 202
Software Restriction Group Policy, 203
Terminal Server, 190
encryption, 202
farms, 203-204
Terminal Server Session Directory, 188, 198, 203-204
configuring, 205
disconnected sessions, 205-207
Group Policy, Join Session Directory setting, 206
Group Policy, Session Directory Cluster Name setting, 206
Group Policy, Session Directory Server setting, 206
Group Policy, Terminal Server IP Address Redirection setting, 206-207
installing, 205
Terminal Services, Remote Desktop Users group, 202
Terminal Services Configuration MMC snap-in, 195-196
Terminal Services Manager MMC snap-in, 195
WMI scripting, 198
Terminal Services client component. See RDC
Terminal Services Configuration MMC snap-in (Terminal Services), 195-196
Terminal Services Manager MMC snap-in (Terminal Services), 195
Computer Configuration policy sections, 101
Terminal Service Group Policies
Automatic Reconnection setting, 196
Do Not Allow Local Administrators to Customize Permissions setting, 196-197
Keep-Alive Connections setting, 196
Limit Maximum Color Depth setting, 196
Remove Disconnect Option from Shut Down Dialog setting, 197
Remove Windows Security Item from Start Menu setting, 197
Restrict Terminal Services Users to a Single Remote Session setting, 196
User Configuration policy sections, 104
testing VBScript, 259
themes (desktop), 35-36
Time Zone Redirection option (RDP 5.2), 201
timeouts, IIS console security enhancements, 124
tokens, disconnected sessions, 207
toolsets (Security Configuration Manager), 51
Local Security Policy MMC snap-in, 52
Secedit.exe command-line tool, 52, 59
Security Settings extension (Group Policy), 52
Security Templates MMC snap-in, 52-55
transferring cluster resource ownership, 213
tree-pane view (GPMC), 98
troubleshooting
Group Policy, RSoP MMC snap-in, 93-97
product activation, 14
RIS installations, 27
turning on/off APIPA, 135
Typeperf command-line tool, 240
Typical Settings option (network card configuration), 18
-u switches (MBSA), 258
UDDI (Universal Data Definition Interface), Web Edition Server, 10
UDDI (Universal Description, Discover and Integration), 161
unattended installations (Windows Server 2003)
ref.chm files, 21
Setup Manager Wizard, 21-22
unicast addresses (IPv6), 167
global unicast addresses, 169
link-local unicast addresses, 168
site-local unicast addresses, 169
unspecified addresses (IPv6), 168
updates. See also hot fixes
Datacenter Edition Server, 9
inventories, MBSA, 256-258
security updates (security strategies), 69, 244, 256-258
SUS updates
approving, 250-251
availability of, 246
running, 251
saving, 246
upgrade paths (Windows Server 2003), 33-34
upgrade setups. See winnt32.exe
upgrading
IIS consoles, 124
mass upgrades, 34
operating system upgrades, Setup Wizard, 33
Software Assurance programs, costs of, 13
versus fresh installs, 34
to Windows Server 2003, 31, 123
compatibility checks, 32
mass upgrades, 34
supported upgrade paths, 33-34
Windows compatibility reports, 33
UPnP (Universal Plug and Play), 174-175
UPS (uninterruptible power supplies), headless servers, 234
User Access permission (Terminal Servers), establishing, 202
user configuration policies, RSoP MMC snap-in, 95-97
User Configuration policy sections (Group Policy)
Administrative TemplatesShared Folders section, 105
Administrative TemplatesSystem section, 105-106
Administrative TemplatesWindows Components section, 104-105
User Profiles section
Computer Configuration policy sections, 101
User Configuration policy sections, 105
user requests, NLB clusters, 218
user rights policies, RSoP MMC snap-in, 94
-v switches (MBSA), 257-258
VBScript
testing, 259
writing, 258-262
VDS (Virtual Disk Services), 147
Verify Server button (Remote Install tab), 27
View Previous Versions option (Windows Explorer), shadow copies (file sharing), 143
viewing
application dependencies, 160
product ID, 24
shadow copies (file sharing), 143
virtual desktops, connecting to via Remote Desktop for Administration (Terminal Services), 194
Visual Studio, 273
volume license keys (product activation), 24
ADS, 29
versus product ID, 14
Volume Shadow Copy Service, clusters, 224
VPN servers
IPSec/L2TP tunnels, 171
RRAS, 179-180
vssadmin command-line utility, shadow copy management (file sharing), 142
Waitfor command-line tool, 240
wallpaper (desktop), 36
Web Edition Server, 4
costs of, 9
UDDI, 10
uses of, 10
Web gardens, 113
Web server, command-line tool security enhancements, 124
Web services
application management, 161
COM+ applications, converting to, 163
extensions
configuring, 119-120
creating, 120
modifying properties, 119
.NET Framework, 151-152
CLR, 153-159
executing applications, 153-154
IL, 153
native code applications, 155
.NET Framework Configuration console, 155-160
programming languages, 153
SOAP, 161
WSDL, 161
Web sites
administration, IIS console, 115
configuring, IIS console, 115
Microsoft Security, 110
MMC tutorial, 228
Open License programs, 12
remote control feature packs, 230
secedit.exe command-line tool tutorial, 228
Windows Backup tutorial, 262
Web-based administration console, security, 121-123
WebDAV (Web Distributed Authoring and Versioning), 149-150
Whoami command-line tool, 240
Windows 2000 versus Windows Server 2003, 4
Windows 2000 forest functional levels (Active Directory), 72
Windows 2000 mixed domain functional levels (Active Directory), 72
Windows 2000 native domain functional levels (Active Directory), 72
Windows Backup, 262
Advanced mode, 264
ASR (Automated System Recovery), 263-265
Backup or Restore Wizard, 264
system state backups, 262
tutorial Web site, 262
Windows clustering, Enterprise Edition Server, 7
Windows compatibility reports, 33
Windows Components option (Setup Manager Wizard), 22
Windows Components Wizard, installing Remote Desktop Web Connection clients, 194
Windows Explorer, View Previous Versions option, 143
Windows Firewalls, 103
Windows Installer, 64-bit Windows, 275
Windows Media Player, 64-bit Windows, 275
Windows Media Player section (User Configuration policy sections), 105
Windows Messenger section
Computer Configuration policy sections, 101
User Configuration policy sections, 104
Windows product activation
activation keys, 25
license keys, 24-25
Open License keys, 26
Select License keys, 26
Windows Server 2003
32-bit versus 64-bit versions, 5
installing, 19-20
activating
hardware hashes, 24
product activation notifications, 25
RIS, 27
Windows product activation, 24-25
CAL, 11
Compressed Folders feature, 37-38
default installation directory, 17
deploying
ADS, 28-31
RIS, 26-27
domain functional levels (Active Directory), 72
editions, comparing, 5
EMS, SPRC hardware, 20
forest functional levels (Active Directory), 72
installing, 15
attended installations, 16-20
CD-based installation, 16-18
EMS, 20
imaging software installation, 23
unattended installations, 21-22
Interim forest functional levels (Active Directory), 72
product activation
product ID, 13
volume license keys, 14
accessing, 42
controlling, 44
desktop control requests, 44
invitations, 42
Remote Desktop, 41
Remote Install tab, 27
remote installation, EMS, 20
Start menu
All Programs Menu Programs section, 46
Control Panel section, 46
customizing, 46
Default Utilities section, 46
Pinned Programs section, 45
Recently Used Programs section, 45
shortcuts, 47
Standard Folders section, 46
compatibility checks, 32
mass upgrades, 34
supported upgrade paths, 33-34
Windows compatibility reports, 33
versus Windows 2000, 4
versus Windows XP, 3
Windows SettingsSecurity Settings section (Computer Configuration policies), 100
Windows Setup Wizard
Windows compatibility reports, 33
Windows Server 2003, upgrading to, 31-32
Windows Task Manager, Networking tab, 181
Windows Time Service section (Computer Configuration policy sections), 103
Windows Update, 245-246
Windows Update section
Computer Configuration policy sections, 101
User Configuration policy sections, 105
Windows XP versus Windows Server 2003, 3
winnt.exe, 16
winnt32.exe, 16
network-based installation, 19-20
Windows Server upgrades, 31-32
WINS (Windows Internet Name Services)
Automatic Partner Configuration, 132
clusters, 224
Enable Result Caching option, 132
records, caching, 132
replication, blocking, 133
Wireless Network (IEEE 802.11) policies (Computer Configuration policy sections), 100
wireless networks, 184-185
wireless zero configurations (wireless networks), 185
Backup or Restore Wizard (Windows Backup), creating ASR backup sets, 264
CD Writing Wizard, 39
Check Server Wizard, troubleshooting RIS installations, 27
Configure Your Server Wizard, NAS configuration, 148
File Share (Computer management console), 144
Manager Your Server, 19
New Cluster Wizard (Cluster Administrator), 213-214
Resultant Set of Policy Wizard, 93
RIS Setup Properties Wizard, 27
Setup Manager Wizard, 21-22
Setup Wizard
operating system upgrades, 33
upgrading to Windows Server 2003, 31-32
Windows Components Wizard, Remote Desktop Web Connection client installation, 194
Windows Setup Wizard, compatibility reports, 33
WMI, scripting Terminal Services in, 198
WMI (Windows Management Instrumentation) filters, 88
WMIC (Windows Management Instrumentation Command-line) tool, 236, 240
backward compatibility, 238
installing, 237
interactive mode, 237
security, 237
worker processes (IIS console), 110
Health tab, 116
isolation mode, 112
Recycling tab, 116
security enhancements, 123-124
WOW (Windows on Windows), 272
writing VBScript, 258
IIS log file rotation scripts, 259-262
remote information queries, 259
WSDL (Web Services Description Language), 161
WSRM (Windows System Resource Manager), 240-241
WUAU.adm files, Automatic Updates (SUS), 252
WWW Service Administrator and Monitoring component (IIS console), 112
-x switches (MBSA), 258
xDSL, permanent virtual circuit encapsulation, 184
Zip drivers, 273
Zip files, 37-38
18.117.246.159