Posts

Showing posts from April, 2014

Get-BitsTransfer -AllUsers Remotly?

i attempting see if can retrieve bits jobs running on remote machine.  have tried code , works great if using local machine nothing returned remote machine. suggestions how retrieve information? $jobwork = {     #get-all bits downloads     $jobout = get-bitstransfer -allusers | ? { $_.jobstate -ne 'transferred'}     $jobout } $jobresults = start-job -scriptblock $jobwork -name $job_name -argumentlist $compname in script specifying go computer.. you passing compname used, think code confused , not doing anything you might need invoke-command -computername { job } Windows Server  >  Windows PowerShell

Apply IE 11 lockdown to a RemoteApp Collection App using Group Policy

i know title confusing here situation: i have customer needs access office 365 browser session pushed through remoteapp. however, cannot work life of me. i've tried setting registry per session using gpp, i've tried using ie gpp... it's tedious , difficult lock down ie 11 , still make functional.  one item bothers me cannot remove menu bar after setting proper gpo , users can access windows update!!! though server has disabled through gpo... highly concerning... need getting configured... any thoughts? computer solutions group lead engineer www.csgsupport.net Windows Server  >  Windows Server General Forum

SBS 2003 and TS CAL 2003

hi    have small business server 2003  oem 5 cal  , bought ms ts cal 2003 single open 5 user cal, how can use ts user cal at  sbs 2003 .i have installed licensing @ sbs 2003 , activated.but remote user can use 2 user.how can 5 concurrence terminal user. can install ts 5  user cal  @ sbs 2003. is there solution?     you can't run true terminal services on sbs 2003 server: http://support.microsoft.com/kb/828056 you can 3 administrators in, 2 in rdp , third if append /console end of server name or ip address pointing @ in rdp client (eg. 192.168.1.1 /console).   Windows Server  >  Remote Desktop Services (Terminal Services)

Question of DHCP Network Access Protection with IP reservation for non-compliant machine behaviour

Image
  dear sir,     in customer existing network, using microsoft windows 2008r2 dhcp server ip assignment client. each machines / devices have mac address has configured in dhcp server same ip address reservation.     customer apply dhcp nap network, found if dhcp nap tab of "enable scope" selected. printers not obtained ip printers doesn't have nap clients software. q1. mean printers / network devices must use static ip manual configure method if customer need implement dhcp nap? q2. may want confirm dhcp nap feature if machine has nap clients installed: can obtain ip based on policy server (restricted / full access etc). if machine hasn't nap client installed (e.g.printer): not allow obtain ip dhcp server. q3. possible configure dhcp 2 scope, 1 nap enabled, 1 no nap enabled mac address reservation? regards, joe hi joe, thanks posting here. for devices don’t support nap , can set nap exemption allow access network obtaining address f

Word API method to convert from Chinese Simplified to Chinese Traditional and vice versa

Image
hello there, if have chinese language pack, on review tab, there 2 buttons allow convert between chinese traditional , chinese simplified notations. (image courtesy of www.eduhk.hk ) does know api functions word uses these conversions? thank you. well world live in , these hands we're given... hi exotic, generally, office object model doesn't provide properties or methods translation. per query, may refer thread below discusses similar question see if can helpful: https://social.msdn.microsoft.com/forums/sqlserver/en-us/f312e16f-6a3d-4dd0-9146-b6ffd10f9cb0/api-for-converting-chinese-traditional-to-chinese-simplified?forum=worddev then forum focus on general questions word client. since your query more related developing issues involving word, if have further concerns on this, we'd encourage post following dedicated msdn forum word better response: https://social.msdn.microsoft.com/forums/office/en-us/home?forum=worddev the reason why recommend

SQL Cluster Disk Configuration

i starting new clustering , deploying new 2012 windows failover cluster sql 2012 sp1 installation. i provision disks iscsi , want know if once target in configured , disks visible both hosts (not configured) do i bring online,  initialise , create volume on disks on 1 server or on both (it same disk why twice) please confused sysadmin.. you need on 1 node of cluster.  however, not bad idea @ least test bringing disk online each node - not required, because validation test perform action. . : | : . : | : . tim Windows Server  >  High Availability (Clustering)

lock users in server2003

we have policy users lock when they continuously type 5 time wrong password . we want find out how many users lock in active  directory @ time .  is there software find out issue. we want find out @ time lock users.please  you can use saved queries feature to query active directory locked-out accounts. please open active directory users , computers console, right-click on saved queries , select new --> query. type name , description, specify query root , click define query button. select custom search open find custom search box. select advanced tab , enter following ldap string in enter ldap query textbox:   (&(objectcategory=person)(objectclass=user)(lockouttime>=1)) shaon shan| technet subscriber support in forum| if have feedback on our support, please contact tngfb@microsoft.com Windows Server  > 

Server 2012: Cache up to the RAM limit and then very slow.

this problem there since ever know windows nt 4.0 sp2: a simple local file copy can make os use ram caching, point cache swapped out disk , there fore performance drops badly. saw in nt 4.0, server 200, windows xp, server 2003, server 2008/vista, server 2008-r2/win7 , see same stuff in server 2012. you need: source faster destination. like: raid can read 200 mb/s, , target raid (same machin) can take 100 mb/s write sinde hdd's cannot go faster. additional setup info: write caching drive has been turned of in device manager. applies raid controller, no write caching. can turn on write caching if want @ point, result same. you start copying, wither explorer or xcopy, not matter. can see task manager filling available ram. when has reached it's limit disk trashing starts, can hear how system disk (a third raid package, not involved in copy job) starts work heavy, , system starts crawl. i know 2 workarounds that: 1 xcopy /j, other http://supercopier.sfxteam.org/ ver

RDS client licensing problem

i have 2 server 2008r2 servers used ts client servers , have 50 2008 rds cal's.  both servers had been working 1 has stopped.  i error message "the remote session disconnected because there no remote desktop license servers available provide license.  please contact server administrator." however, when log on the server check license information , configuration reported being ok.  i can use remote desktop session host configuration mmc view config can see remote desktop licensing mode set "per user" , remote desktop license servers set "specified" i can click on "licensing diagnosis" part of snap in , tells me "licensing diagnosis did not identify , licensing problems remote desktop session host server"  where tells me there 50 licenses available (as there should be) , licensing mode set "per user"  the licensing diagnosis information" window shows 0 warnings , says "licensing diagnosis did not iden

Defined printers become invalid (randomly) in TS sessions

hi folks, put problem printing/faxing forum, didn't answers, post here. basic os problem, not printing problem. problem: users printing in ts session, no matter type of client, printing errors meaning selected printer invalid or cannot found. happens printers non-default printers user, , non-ms apps. strange thing problems occur of printers, not persistently same printers. printer, except default, can give error, seemingly randomly. when printer has started give off error, it's not usable anymore, unless user chooses printer default. if user chooses printer that's giving error, works printer, some, not all, of other printers start give error instead. (please, have @ setup first, don't waste time doesn't apply). i've got following setup: windows 2008 enterprise server x64 terminal services run. users connect terminal server plethora of different rdp-clients range of os'es (different versions of windows + linux). there no local printers, or other

Cannot see all the computer on the network

here have, i have network @ 1 location, on domain. server running windows 2003 standard , set dc, dhcp server, dns server. at location  have network, same first, running windows 2008 standard. the networks connected hardware vpn router connection on internet. the vpn routers not set send out ips. both vpn routers same. the networks have different ip ranges,  10.0.0.1, , 10.0.10.1.  have same sub net. i can ping other networks computers, , use remote desktop connection connect server. i have set trusts servers. i can print 1 network other. the problem is, can not see other computers on different domain. when 1 server dc both servers domains, every thing worked, when lost internet, things got messed up, installed dc on other domain. when go to  "my network place" shows domain. i need transfer files 1 domain other. thank john   hi john, i'm not sure why using 66.255.200.3 , 66.255.200.5 dns. isp's dns, correct? if ad infrastructure, can&

Vdi collection Error

Image
hello, as inform have installed windows server 2012 std edition. and installed remote desktop service on same computer vdi. after have created windows 7 pro virtual machine of hyper v. then going create collection 1 poled second personal in both getting error  error name is-->  the integration component in virtual desktop template not correct version.. please me how resolve issue. regards, waseem hi, please make sure vm template syspreped. making sure have syspreped virtual machine after installing software required users) , click next. note if not have image can created using following command: %windir%\system32\sysprep\sysprep.exe /generalize /oobe /shutdown /mode:vm in addition, please make sure hyper-v integration service installed in windows 7 template virtual machine. windows 8 / windows server 2012: pooled virtual desktop infrastructure http://blogs.technet.com/b/askperf/archive/2012/10/31/windows-8-windows-server-2012-poo

Remote desktop keeps losing connection.

hello everyone,   company been having issue fore last couple days. remote desktop connections periodically drop connections try reconnect. this happens when trying remote a out terminal servers , when trying remote to an outside terminal server. not sure going on. worked great up until 2 days ago. this is on servers 2003 up to 2012. have ideas?   hi unity, thanks post. are there related events in event viewer? if yes, please post further research. best regards, jay please remember mark replies answers if , un-mark them if provide no help. if have feedback technet subscriber support, contact tnmff@microsoft.com. Windows Server  >  Remote Desktop Services (Terminal Services)

Chain of trust on mobile phones

i’m trying suggestion. we’ve internal pki infrastructure setup , 1 standalone root ca (server 2012 r2) , 3 intermediate cas comprising of 2 enterprise cas (server 2012 r2)  and 1 standalone (server 2012 r2). we’ve project management function tool jira, stash, wiki etc. have certificate issued our internal cas works fine when accessed internal network workstations, servers etc.  but whenever our end users access these websites using mobile phones internal wi-fi , certificate not trusted, certificate pops every , then. want solve issue. what recommended approach solve issue? thanks help! manage them airwatch/mobileiron , include root certificate in profile downloaded managed devices. way of customers use this sane way manage devices brian Windows Server  >  Security

Error Connecting to WSUS Server

have 2008 r2 server serves our wsus server. when open wsus, comes following message: error: connection error an error occured trying conect wsus server. error can happen number of reasons. check connectivity server. i copied error clipboard , have posted below. i've tried rebooting didn't fix it. other ideas? ---------------------------------------------------------- the wsus administration console unable connect wsus server via remote api.  verify update services service, iis , sql running on server. if problem persists, try restarting iis, sql, , update services service. the wsus administration console has encountered unexpected error. may transient error; try restarting administration console. if error persists,  try removing persisted preferences console deleting wsus file under %appdata%\microsoft\mmc\. system.io.ioexception -- handshake failed due unexpected packet format. source system stack trace:    at system.ne

Log on user to temp profile every time

why every user logging temporary profile on ts server 2008 r2? doesn't matter if user local or domain. on terminal profiles tab path set e.g. "//serverts/users". permissions folder ok. so, happened? on test config, w2k3 + xp ok. so, why w2k8 doesn't work? :| hi,     as far know, there 2 version of user profile between windows server 2003 , windows server 2008, , both incompatibility between version 1 user profiles (windows 2000, windows xp, windows server 2003) , version 2 user profiles (windows vista, windows server 2008), new roaming user profile (the folder v2 suffix distinguish former user profiles) have set users logon windows vista , windows server 2008.     for general roaming profile, here step-to-step practice:   1. prepare roaming user profile   - log on windows server 2008 domain user account produce user profile. log off computer.   - log on windows server 2008 domain administrator account.   - click start--->right-cl

Permissions on a service via GPO

Image
i use gpo set permissions (start , stop) on service global group.  there way set these permissions on service without having specify startup type?  can accomplish locally editing permissions of service, rather use gpo efficiently set on many servers. hi, thanks posting. how configured service permission local? can configure through command line, “sc.exe” or “secedit.exe” command? the method found set permissions individual services using security tmplates or sc command. if can set services permission through sc command, may create script , use startup policy deploy setting. for more information please refer following ms articles: security templates http://technet.microsoft.com/en-us/library/cc772881(v=ws.10).aspx sc: management services http://technet.microsoft.com/en-us/library/cc772676(v=ws.10).aspx services permissions http://technet.microsoft.com/en-us/library/cc782435(v=ws.10).aspx lawrence technet community support

RemoteApp unable to start ClickOnce application

hello,     i know if succeed run clickonce application remote app?     i've try many scenario like     1. use appref.ms file create application     2. use path clickonce setup.exe on server     3. of 2 through command prompt cmd /c "path setup.exe"     1. doesnt' work     2/3 seem start, popup ie windows close.     does know how clickonce application work?     i know can deploy normal exe, application deploy everywhere click once, , losing automatic version update not option. thank ml unfortunately clickonce app not supported remoteapp today. bringing our attention, improvement idea remoteapp. for now, options either deploy normal exe mentioned or set initial app user and/or server , ask user connect through regular ts. thanks! Windows Server  >  Remote Desktop Services (Termin

iSCSI target randomly gets dropped while doing backup (Hyper-v)

Image
hello here our situation. we bought cloud-storage product, company provided hyper-v (linux) vm. the hyper-v mount physical hard drive, , use iscsi initiator connect vm ip. i created shared folder drive(mapped iscsi initiator  ) the problem when run backup server, speed getting slower , slower, , when each file seems writting disk, drive down network(i can't access network @ time.)and backup job fail, after while drive again. (i can access local server, not network when problem happens) i googled , found people have issue: http://www.experts-exchange.com/microsoft/applications/virtual_server/q_23920391.html https://www-secure.symantec.com/connect/forums/iscsi-target-randomly-gets-dropped-while-doing-incremental-backup now sure it's problem 3 things : hyper-v,  iscsi initiator, or linux vm provided us. anyone has idea? can't see error event logs, when drive down network. jason hi, what’s os of hyper-v host server? what’s os version of hyper

(echo 00001) -vs- 00001 -- are they equal?

Image
examine following powershell sequence.  how can numeric quantity retain leading zeros? <# c: #> $n1 = echo 00001 <# c: #> $n2 = 00001 <# c: #> $n1 -eq $n2 true <# c: #> $n1 00001 <# c: #> $n2 1 <# c: #> $n1.gettype() ispublic isserial name basetype -------- -------- ---- -------- true true int32 system.valuetype <# c: #> $n2.gettype() ispublic isserial name basetype -------- -------- ---- -------- true true int32 system.valuetype examine following powershell sequence.  how can numeric quantity retain leading zeros? <# c: #> $n1 = echo 00001 <# c: #> $n2 = 00001 <# c: #> $n1 -eq $n2 true <# c: #> $n1 00001 <# c: #> $n2 1 <# c: #> $n1.gettype()

Set-ADDomainMode - ResourceUnavailable

Image
context: i'm making effort learn how perform various operations powershell. this test network. two domain controllers: dc2 - windows 2008 r2 dc5 - windows 2012 ++++++++++++++ problem: when attempt increase domain functional level using believe correct ps cmdlet, obtain following error (note: cmdlets run on windows 2012 server): ps c:\> get-addomain | set-addomainmode -domainmode windows2008domain confirm [snip] y set-addomainmode : referral returned server @ line:1 char:16 + get-addomain | set-addomainmode -domainmode windows2008domain +                ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~     + categoryinfo          : resourceunavailable: (dc=mynet,dc=lan:addomain) [set-addomainmode], adreferralexception     + fullyqualifiederrorid : activedirectoryserver:8235,microsoft.activedirectory.management.commands.setaddomainmode ++++++++++++++++++++++++++++++++++ yet get-addomain cmdlet return name of domain (tried various methods here): ps

can windows 2016 server be joined to azure ad tenant?

can windows 2016 server joined azure ad tenant? hi, thanks post. regarding azure ad issue, suggest refer experts following forum professional support: https://social.msdn.microsoft.com/forums/en-us/home?forum=windowsazuread&filter=alltypes&sort=lastpostdesc the reason why recommend posting appropriately qualified pool of respondents, , other partners read forums regularly can either share knowledge or learn interaction us.  thank understanding. best regards, alvin wang please remember mark replies answers if , unmark them if provide no help. if have feedback technet subscriber support, contact tnmff@microsoft.com . Windows Server  >  Windows Server Technical Preview

Migrar Windows Server 2003 a Windows Server 2012 Standard

estimados, existe la posibilidad de migrar mi servidor windows 2003 server x32 un servidor windows server 2012 standard x64, para así dejar este ultimo como un controlador secundario en mi empresa. si alguien sabe algo sobre esta informacion por favor confirmar. saludos, ignacio,   ¿como estas? necesitariamos un poco mas de informacion como: ¿el windows server 2003 es controlador de dominio? ¿deseas realizar una migracion "in place" del servidor es decir actualizar el mismo servidor? ¿si el windows server 2003 es controlador de dominio, deseas agregar un dc adicional windows server 2012 y eliminar el 2003? si el windows server 2003 es dc, ¿tiene todos los roles fsmo? el windows server 2003, ¿tiene algun otro rol de servidor? aguardamos tus comentarios para poder ayudarte saludos! this posting provided "as is" no warranties , confers no rights! test suggestion in test environment before implementing!

SQL Server Instance Performance

this has been answered elsewhere, i've been unable find it. if assume following server configuration. sql server 2005 enterprise x64 2 x quad core cpus 72gb ram c: (os, mirrored pair) d: (data file drive 3xhdd raid 1+0) e: (log file drive mirrored pair) f: single stand alone disk backups tempdb split 8 files on e: drive best practice/optimal performance configuration server host several databases. databases will, theoretically, not busy @ same time, when become busy, take extreme hit on short period of time. had 1 client go live, , ram didnt seem issue, cpu's took bit of beating.  improved improving indexes. i thinking best way go keep on 1 instance, , go there.  multiple instances has little overhead, half resource (in addition, alter amount of memory being used, need restart entire instance). thoughts please? regards andy hello, as belongs sql server please ask again in sql server forum: http://social.technet.microsoft.com/forums/en

"Add the Administrators security group to roaming user profiles" still not allowing access

Image
i'm doing testing of roaming profiles , have them working. administrator, cannot access each user's individual profile folder. have enabled gp setting "add administrators security group roaming user profiles" , done gpupdate on client pc i'm using first logon device user profile creation. gpresult shows gpo being applied, still doesn't grant me access. i aware policy doesn't apply retroactively , folders created after gpo applied grant me access. i'm testing creating folder multiple times after i've created gpo. argument doesn't apply. after digging, found old thread stated policy must configured on client pc user logging onto time in order work. tried doing , granted access after profile directory created. but doesn't seem right answer. yes, solves problem. if have 500 computers in organisation, wouldn't mean you'd have enable setting on each , every 1 of them? no way admin want that. can shed light on this? ok, have so

Device Management Hyper-V Core Server

i can access core server , can work disk management, event view can see serive when try access device manager gives me error "unable access computer hvs1. make sure computer on network, has remote administration enabled, , running plug , play , remote registry services. the error : access denied." hi,   this expected behavior.   device manager:   you must first enable allow remote access pnp interface policy setting. this, on computer running windows vista or full installation of windows server 2008, open local group policy editor mmc snap-in, connect computer running server core installation, navigate computer configuration\administrative templates\device installation, , enable allow remote access pnp interface . restart computer running server core installation. note when device manager used remotely, it read-only .   for more information, can refer to:   server core installation option getting started guide http://www.microsoft.com/downloads/details.aspx?fam

Get-QADuser Faster ?

i improve performance of 1 of script. i'm using quest cmdlets get-qaduser, , slowness comes command measure-command { get-qaduser -searchattributes @{employeeid=102541} -enabled -dontusedefaultincludedproperties}  measure-command { get-qaduser -ldapfilter '(employeeid=102541)' -enabled -dontusedefaultincludedproperties}  the 2 commands above takes around 400/500 millisecond each. i've tried use -searchroot reduce scope, little, rather not use it, because want check entire ad. i not necessarily want use get-qaduser. any ideas ?   sorry, missed -enabled switch, although i assume means cmdlet won't return object unless account enabled. still, directorysearcher filter ldap standard used many tools, joe richards' adfind, dsquery *, etc. find enabled users employeeid equal 102541 filter be: $searcher.filter = "(&(employeeid=$id)(!useraccountcontrol:1.2.840.113556.1.4.803:=2))"   the "&" "and" operator (bo

Problem in installing evaluation version

i have downloaded windows server r2 evaluation software form windows site. trying install same in hp proliant g9 server. before completion ,the server shows message windows not find valid license file. kindly inform steps taken install & evaluate server os. the evaluation software not require license file.  require connection internet activate, separate.  may copy using corrupted.  did install directly downloaded iso file or did create usb or dvvd install from?  if created usb or dvd install from, should try again recreate it.  if still fails, copy of iso have got corrupted during download.  can try getting copy.  best try obtaining second copy different physical location ensure not corrupted copy stored on cache server in path regular isp. . : | : . : | : . tim Windows Server  >  Windo

Adding a secure site to IE through GP 2008

hi, trying add url everyone’s ie 8 secure sites. editing gp user configuration > windows settings > internet explorer maintenance >security> security zones , content ratings> properties. checking ‘import current security zones , privacy settings , warning .....   ” you have chosen import settings compatible windows server 2003, ie enhanced security configuration. these security settings ignored on machines enhanced security configuration isn’t enabled.     to import settings enhanced security configuration, click continue. import settings users enhanced security configuration isn’t enable, click cancel remove enhanced security configuration , import standard settings previous dialog....” what think means enhanced security configuration turned on somewhere in gp, need turn off come setting. know might find setting cannot find it. many thanks hi,  the message referring local ie esc configuration on computer being used edit policy. since local computer&

UNABLE TO TYPE @ ON LOGIN SCREEN OF WINDOWS SERVER 2003

please can me wierd problem.......this problem,i  unable type @  in login screen in windows server 2003 after setting up  server password included @ symbol. i tried log in server after installing appilcation unable type  @ login screen. i have tried several keyboards ps\2 , usb unable login server. the server not on domain , has on other administrator account login can change @password acount please server application , data configure in important prefer to login server rather reinstalling server if can me appreciate it. why happens when need important data ?????????????????   hi,   i meant try booting bios see if type symbol @ there (in bios console, e.g. password settings).   also, please try recovery console (by inserting setup media cd/dvd rom , press r during installation process), see if can type symbol @ in recovery console.   then, try booting safe mode (press f8 after start computer) , see if can type password , log safe mode. if can log safe mode, can try clea

Unable to add GUI shell to Core install with Server 2012 R2 VL media

hi we using vl media named "sw_dvd5_windows_svr_std_and_datactr_2012_r2_64bit_english_core_mlf_x19-05182" , after installing 2012 r2 standard core version can't add gui shell features using local media source.  using alternate 2012 r2 media technet subscription , same commands work fine.  it seems particular vl media missing packages winsxs store (it released in past week , appears have patch rollup applied against - winsxs packages v16408). further details: have tried using both dism , add-windowsfeature commands, pointing source wim or winsxs no avail (these commands work fine when using technet media).  i.e-     install-windowsfeature server-gui-mgmt-infra,server-gui-shell -source wim:d:\sources\install.wim:2      dism /online /enable-feature /featurename:server-gui-mgmt /featurename:server-gui-shell /featurename:servercore-fullserver /source c:\mount\windows\winsxs /limitaccess always fails cbs.log showing unable locate source.  digging deeper cbs.l

Restricted Groups setting not working.

Image
i've been struggling group policy today, , use advice... i've been given list of needs happen. 1:  local account administrator must disabled. 2:  create new local account of nw_admin 3:  administrators group needs updated, contain 'domain\sg admins' group , new local administrator. local admin account disabled - check. create new local account of nw_admin - check. i did under computer config -> preferences -> control panel settings -> local users , groups next, set restricted groups domain group want add. so in computer config -> policies -> windows settings -> security settings -> restricted groups. i created new group.  selected domain, , used advanced search feature physically select 'sg admins' group. i left 'members' section blank. and in 'this group member of' typed 'builtin\administrators'. (i've tried variety of caps, lower case , mixed case). one quick '

Server 2003 hung on update 49/92 while shutting down " please dont power off ...."

i have server lost drive due failure in raid 5. shutting server down reseed , windows started auto update on shut down thing. c:\ drive low on disk space begin with. has since been stuck on 49/92 10 hours. best course of action?? poweredge 1800 running server 2003 r2 great plains on (ie accounting server). greatly appreciated.   reastart server in safe mode , try deleteing c:\windows\winsxs\pending.xml file http://www.virmansec.com/blogs/skhairuddin Windows Server  >  Windows Server General Forum

SYSVOL & Atribute User Replication when DC is Off on Site Link Bridge

we have ad hierchary: site link1: site0 - site1    site link2: site1 - site2    (these 2 site links have cost 100 , replication interval 15) site link bridge: site link1 + site link2 site 0 have 4 dcs. site 1 , site 2 have dc. fsmo roles on site 0. kcc , bridge enabled when dc on site1 off, sysvol changes on site 0 replicated site2, atribute user changes not replicated site2 how long kcc takes generate object beetween site0 , site2?? can't see it... there doesn't ever have have bridge between 0 - 2.  dc in site 0 can replicate site 1 , dc in site 1 can replicate 2. if there network connectivity between 0 , 2 (which doesn't sound there is) suggest create link between them, otherwise can run diagnostics if @ concerned errors might in domain. http://blogs.dirteam.com/blogs/paulbergson/archive/2009/01/26/troubleshooting-active-directory-issues.aspx -- paul bergson mvp - directory services mcitp: enterprise administrator mcts, mct, mcse, mcsa, securit