<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Random Ramblings</title>
	<atom:link href="http://whobrokeit.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://whobrokeit.wordpress.com</link>
	<description>IT technical blog</description>
	<lastBuildDate>Wed, 06 Jan 2010 11:57:56 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='whobrokeit.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/7339c28cf11d5452527620aa26b65c77?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Random Ramblings</title>
		<link>http://whobrokeit.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://whobrokeit.wordpress.com/osd.xml" title="Random Ramblings" />
	<atom:link rel='hub' href='http://whobrokeit.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Forefront Integration with nap Step by Step</title>
		<link>http://whobrokeit.wordpress.com/2009/12/24/forefront-integration-with-nap-step-by-step-2/</link>
		<comments>http://whobrokeit.wordpress.com/2009/12/24/forefront-integration-with-nap-step-by-step-2/#comments</comments>
		<pubDate>Thu, 24 Dec 2009 12:28:24 +0000</pubDate>
		<dc:creator>Greg</dc:creator>
				<category><![CDATA[Forefront Client Security]]></category>
		<category><![CDATA[NAP]]></category>
		<category><![CDATA[FcsNap]]></category>
		<category><![CDATA[Forefront Nap Intgergration]]></category>

		<guid isPermaLink="false">http://whobrokeit.wordpress.com/2009/12/24/forefront-integration-with-nap-step-by-step-2/</guid>
		<description><![CDATA[  Step 1 Install the SHA   Install the SHA first, FcsNapSha86.msi or FcsNapSha64.msi depending on which version of windows you have. Reasoning is so that you don&#8217;t end up with a policy that none of the clients can comply to. The easiest way to do this is to use a Group Policy. So the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=whobrokeit.wordpress.com&amp;blog=11062119&amp;post=59&amp;subd=whobrokeit&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>
 </p>
<h2>Step 1 Install the SHA<br />
</h2>
<p>
 </p>
<p>Install the SHA first, FcsNapSha86.msi or FcsNapSha64.msi depending on which version of windows you have. Reasoning is so that you don&#8217;t end up with a policy that none of the clients can comply to.
</p>
<p>The easiest way to do this is to use a Group Policy.
</p>
<p>So the first thing you need to do is created a distribution share with permission for Administrators, Authenticated Users and Domain Users.
</p>
<p>Open GPMC and navigate the OU that contains the computers that require the SHA and create and link a GPO, specify a name e.g. Forefront SHA deployment policy.
</p>
<p>Right click the new GPO and click edit. Navigate to: Computer Configuration- Policies – Software settings – Software Installation. Right click and create a new Package. In the dialog box type in the UNC path of the installer and choose assigned. e.g. \\myserver\software\fcsnapsha86.msi
</p>
<p>However in my scenario I am using WDS to deploy client machines so I have added the SHA to the Deployment image so all the clients I roll out will have this preinstalled.
</p>
<p>Note: You can use security filtering to apply the policy to specific users &amp; computers if you wish.
</p>
<p>
 </p>
<h2>Step2 Install the SHV<br />
</h2>
<p>
 </p>
<p>On the NAP server run FcsNapShv86.msi or FcsNapShv64.msi depending on which version of Windows Server you have installed. The install wizard will guide you through the process.
</p>
<p>
 </p>
<h2>Step3 Configure the SHV<br />
</h2>
<p>
 </p>
<p>Open the NPS snap in. Navigate to: Policies – Health Policies. For all the policies both compliant and non-compliant you must enable the SHV, right click a policy, go to properties and tick the check box for forefront client security.
</p>
<p>Navigate to: Network Access Protection – System Health Validators – Microsoft forefront client security system heath validator – Settings. Right click on the Default Configuration and go to properties and Enable all the Client Service Policy Settings, click the WSUS Server Policy Setting tab and enable Forefront Product Updates &#8211; 14 days, System health agent – 14 Days, Antivirus/antispyware updates – 3 Days.
</p>
<p>Client Service Policy Settings
</p>
<p><img src="http://whobrokeit.files.wordpress.com/2009/12/122409_1228_forefrontin1.jpg">
	</p>
<p>WSUS Server Policy Settings
</p>
<p><img src="http://whobrokeit.files.wordpress.com/2009/12/122409_1228_forefrontin2.jpg">
	</p>
<p>
 </p>
<p>
 </p>
<p>
 </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/whobrokeit.wordpress.com/59/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/whobrokeit.wordpress.com/59/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/whobrokeit.wordpress.com/59/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/whobrokeit.wordpress.com/59/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/whobrokeit.wordpress.com/59/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/whobrokeit.wordpress.com/59/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/whobrokeit.wordpress.com/59/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/whobrokeit.wordpress.com/59/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/whobrokeit.wordpress.com/59/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/whobrokeit.wordpress.com/59/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/whobrokeit.wordpress.com/59/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/whobrokeit.wordpress.com/59/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/whobrokeit.wordpress.com/59/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/whobrokeit.wordpress.com/59/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=whobrokeit.wordpress.com&amp;blog=11062119&amp;post=59&amp;subd=whobrokeit&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://whobrokeit.wordpress.com/2009/12/24/forefront-integration-with-nap-step-by-step-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/40508a410a2841fd2a8cfb0731a95d0a?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Greg</media:title>
		</media:content>

		<media:content url="http://whobrokeit.files.wordpress.com/2009/12/122409_1228_forefrontin1.jpg" medium="image" />

		<media:content url="http://whobrokeit.files.wordpress.com/2009/12/122409_1228_forefrontin2.jpg" medium="image" />
	</item>
		<item>
		<title>How to inject drivers into a windows 7 wim file</title>
		<link>http://whobrokeit.wordpress.com/2009/12/23/how-to-inject-drivers-into-a-windows-7-wim-file/</link>
		<comments>http://whobrokeit.wordpress.com/2009/12/23/how-to-inject-drivers-into-a-windows-7-wim-file/#comments</comments>
		<pubDate>Wed, 23 Dec 2009 09:39:08 +0000</pubDate>
		<dc:creator>Greg</dc:creator>
				<category><![CDATA[Windows Deployment]]></category>
		<category><![CDATA[AIK]]></category>
		<category><![CDATA[DISM]]></category>
		<category><![CDATA[Inject Drivers]]></category>

		<guid isPermaLink="false">http://whobrokeit.wordpress.com/?p=14</guid>
		<description><![CDATA[In order to Make changes to windows 7 wim file you should<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=whobrokeit.wordpress.com&amp;blog=11062119&amp;post=14&amp;subd=whobrokeit&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>How to inject drivers into a windows 7 wim file.</p>
<p>First You need to have the windows 7 AIK installed.</p>
<p>In order to Make changes to windows 7 wim file you should mount the wim to an existing folder.</p>
<p>the tool we will use is DISM which is found in c:\Program Files\Windows AIK\Tools\x86\Servicing&gt;</p>
<p>Dism /Mount-Wim /WimFile:f:.wim /index:1 /MountDir:f:test</p>
<p>add drivers to the image using add driver command</p>
<p>Dism /image:f:test /Add-Driver /driver:C:\driver\graphics          (there should be an inf file in this folder)</p>
<p>Un-mount and commit changes</p>
<p>Dism /Unmount-Wim /MountDir:f:test /commit</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/whobrokeit.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/whobrokeit.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/whobrokeit.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/whobrokeit.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/whobrokeit.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/whobrokeit.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/whobrokeit.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/whobrokeit.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/whobrokeit.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/whobrokeit.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/whobrokeit.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/whobrokeit.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/whobrokeit.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/whobrokeit.wordpress.com/14/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=whobrokeit.wordpress.com&amp;blog=11062119&amp;post=14&amp;subd=whobrokeit&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://whobrokeit.wordpress.com/2009/12/23/how-to-inject-drivers-into-a-windows-7-wim-file/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/40508a410a2841fd2a8cfb0731a95d0a?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Greg</media:title>
		</media:content>
	</item>
		<item>
		<title>WDS &#8211; Windows Deploment Service &#8211; Step by Step guide</title>
		<link>http://whobrokeit.wordpress.com/2009/12/23/wds-guide/</link>
		<comments>http://whobrokeit.wordpress.com/2009/12/23/wds-guide/#comments</comments>
		<pubDate>Wed, 23 Dec 2009 09:24:26 +0000</pubDate>
		<dc:creator>Greg</dc:creator>
				<category><![CDATA[Windows Deployment]]></category>
		<category><![CDATA[unattend.xml]]></category>
		<category><![CDATA[WDS]]></category>
		<category><![CDATA[windows deployment service]]></category>
		<category><![CDATA[WSIM]]></category>

		<guid isPermaLink="false">http://whobrokeit.wordpress.com/?p=7</guid>
		<description><![CDATA[Enter the FQDN of the WDS server and choose an image group. The image will now capture to the local location you chose and then upload directly to the WDS server image group you specified. Now you have an image ready to deploy<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=whobrokeit.wordpress.com&amp;blog=11062119&amp;post=7&amp;subd=whobrokeit&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<h2>DHCP server settings:</h2>
<p>PXE booting requires the following options in DHCP:</p>
<p>option 66 Boot server host name: &#8220;FQDN of WDS server&#8221;</p>
<p>option 67 Boot file name: \boot\x86\wdsnbp.com</p>
<p>This will work as is with DHCP and WDS on separate machines.</p>
<p>Note: if your DHCP server is on a different VLAN than the one you are booting from you must enable DHCP helper or IP helper.</p>
<h2>WDS Server settings:</h2>
<p>Not much you need to change here just a few things worth mentioning.</p>
<p>CLIENT Naming policy can be set with a variable to auto generate the machine name according to your requirements, i usually use something simple like Computer%03# which will increment 001,002 etc.. After the word Computer.</p>
<p>DHCP settings can all be left unchecked if you are using a separate DHCP server.</p>
<p>PXE response can be set to respond to all clients, known and unknown.</p>
<p>PXE boot policy can be set to always continue the PXE boot for all clients known and unknown.</p>
<p>Advanced setting, allow WDS to dynamically discover Directory Servers and authorize this WDS server in DHCP should be enabled.</p>
<p>The rest of the setting can be left as default for now.</p>
<h2>Add a Boot image and create a capture image</h2>
<p>From WDS right click boot image and select the boot.wim file from the windows 7 DVD and it will copy to WDS. Give it a decent name, e.g. Install Microsoft Windows</p>
<p>Now create a capture image, right click the boot image you just added and choose create capture image, again give it a good name e.g. Capture Microsoft Windows.</p>
<p>Note: I have tested capture and deploy with windows 7, Vista and XP using the capture image created from a Windows 7 boot.wim file and it works without issues.</p>
<p>Add an image group, right click install images and choose add image group, eneter the name for you new group.</p>
<h2>Capturing an Image and upload to WDS server</h2>
<p>In order to capture an image you need to Sysprep the machine first so from Windows 7 open the run box and type in Sysprep, it will open the Sysprep location C:WindowsSystem32sysprep. Double click on Sysprep, enable the generalize option and set shutdown option to shutdown (if it reboots and you’re not paying attention you will have to Sysprep again).</p>
<p>Now you can turn on the machine and boot from LAN (f12 button in most cases). Assuming you followed the previous steps You should now be prompted to choose to either install windows or capture windows, choose capture and it will boot the Windows PE capture image we made earlier. Follow the instructions in the image capture wizard, Choose a volume, there should only be one, enter a name and description &amp; click next. Choose a location to save the image, its OK to save to the same drive you are capturing from or you may use a USB drive. Enter the FQDN of the WDS server and choose an image group. The image will now capture to the local location you chose and then upload directly to the WDS server image group you specified. Now you have an image ready to deploy.</p>
<h2>Creating an imageunatend.xml file:</h2>
<p>To truly make your Deployments unattended you need to create an answer file. For this you need to install the Windows 7 Automated Installation Kit – AIK, it doesn’t matter where you install it but I recommend on the WDS server for simplicity sake.</p>
<h2>Windows System Image Manager – WSIM</h2>
<p>WSIM is the tool of choice for creating the imageunattend.xml file.</p>
<p>You will need to select the install.wim file from the windows 7 DVD to get the catalogs; these are binary files that contain the settings and packages found in a windows image.  Because there are far too many catalogs to mention I will just go through the most basic ones required for an x86 version of windows 7.</p>
<ol>
<li>WindowsPE
<ol>
<li>x86_Microsoft-Windows-Internationa-Core-WinPE_neutral
<ol>
<li> i.      InputLocale:          en-US</li>
<li> ii.      UILanguage:         en-US</li>
<li> iii.      SystemLocale:       en-US</li>
<li> iv.      UserLocale:           en-US</li>
</ol>
</li>
<li>X86_Microsoft-Windows-Setup_neutral
<ol>
<li> i.      AcceptEULA:       True</li>
<li> ii.      Fullname:              YourName</li>
<li> iii.      Organization:        YourOrgName</li>
<li> iv.      ProductKey:          Win 7 Product Key</li>
</ol>
</li>
</ol>
</li>
<li>Generalize
<ol>
<li>X86_Microsoft-Windows-Setup_neutral
<ol>
<li> i.      RegisteredOrg:      YourOrganization</li>
<li> ii.      RegisteredOwner: Owner of the License</li>
</ol>
</li>
</ol>
</li>
<li>Specialize
<ol>
<li>X86_Microsoft-Windows-Shell-Setup_neutral
<ol>
<li> i.      ComputerName:    %MACHINENAME%</li>
<li> ii.      TimeZone:             Your Time zone e.g. (UTC+04:00) Abu Dhabi, Muscat</li>
</ol>
</li>
<li>X86_Microsoft-Windows-UnattendJoin_neutral
<ol>
<li> i.      Domain:                Your FQDN e.g. domain.local</li>
<li> ii.      Password:              Password for user</li>
<li> iii.      Username:             Username with premision to join domain</li>
<li> iv.      JoinDomain           Your FQDN e.g. domain.local</li>
</ol>
</li>
</ol>
</li>
<li>oobeSystem
<ol>
<li>x86_Microsoft-Windows-Internationa-Core-WinPE_neutral
<ol>
<li> i.      InputLocale:          en-US</li>
<li> ii.      UILanguage:         en-US</li>
<li> iii.      SystemLocale:       en-US</li>
<li> iv.      UserLocale:           en-US</li>
</ol>
</li>
<li>X86_Microsoft-Windows-Shell-Setup_neutral
<ol>
<li> i.      HideEULAPage:  True</li>
<li> ii.      HideWireless:        True</li>
<li> iii.      NetworkLocale:    Work</li>
<li> iv.      ProtectYourPC:    1</li>
<li> v.      TimeZone:             Your time zone</li>
</ol>
</li>
</ol>
</li>
</ol>
<p>Note: use the tzutil command-line tool on windows 7 to list the time zone from an existing PC to get the correct entry.</p>
<p>Save the file and we are done here, now right click the windows 7 image in WDS and open properties, check the allow image to install in unattended mode box and select the xml file you just saved.</p>
<p>With this done you can now Deploy your image.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/whobrokeit.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/whobrokeit.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/whobrokeit.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/whobrokeit.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/whobrokeit.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/whobrokeit.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/whobrokeit.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/whobrokeit.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/whobrokeit.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/whobrokeit.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/whobrokeit.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/whobrokeit.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/whobrokeit.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/whobrokeit.wordpress.com/7/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=whobrokeit.wordpress.com&amp;blog=11062119&amp;post=7&amp;subd=whobrokeit&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://whobrokeit.wordpress.com/2009/12/23/wds-guide/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/40508a410a2841fd2a8cfb0731a95d0a?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Greg</media:title>
		</media:content>
	</item>
	</channel>
</rss>
