Pages

Friday, June 14, 2019

Auditing Windows server events for changes to local accounts and local group membership changes

Windows system administrators can often be tasked with providing security audit logs to show what local user accounts were created, when were they created and who created them. In addition, auditors can also request logs to show when the memberships for local privilege groups such as Administrators, Power Users, Backup Operators and Remote Desktop Users was modified and by who. 

To simplify these tasks, the Windows Server Administrators need to enable auditing in the local security policy and then use their monitoring tools to track certain event IDs from the server Windows Security logs.

Step 1: Enable auditing

For Windows Server 2008, 2012 and 2016, enable "Audit Security Group Management" and "Audit User Account Management" for Success and Failure.




These settings are located under Computer Configuration -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration -> System Audit Policies -> Account Management.

Once these settings are enabled, monitor the following events under Security Event Logs.

Event source: Microsoft Windows security auditing
Task Category: Security Group Management
Event ID:
4728 (A member was added to a security-enabled global group),
4729 (A member was removed from a security-enabled global group)

4732 (A member was added to a security-enabled local group),

4733 (A member was removed from a security-enabled local group)

Task Category: User Account Management
Event ID:
4720 (A user account was created),
4722 (A user account was enabled),
4724 (An attempt was made to reset an account's password),
4726 (A user account was deleted),
4738 (A user account was changed)

Friday, March 8, 2013

Guest Reclaim Tool


Guest Reclaim reclaims dead space from NTFS volumes hosted on a thin provisioned SCSI disk. The tool can also reclaim space from full disks and partitions, thereby wiping off the file systems on it. As the tool deals with active data, please take all precautionary measures understanding the SCSI UNMAP framework and backing up important data.

Features

  • Reclaim space from Simple FAT/NTFS volumes
  • Works on WindowsXP to Windows7
  • Can reclaim space from flat partitions and flat disks
  • Can work in virtual as well as physical machines
Whats a Thin provisioned (TP) SCSI disks? In a thin provisioned LUN/Disk, physical storage space is allocated on demand. That is, the storage system allocates space as and when a client (example a file system/database) writes data to the storage medium. One primary goal of thin provisioning is to allow for storage overcommit. A thin provisioned disk can be a virtual disk, or a physical LUN/disk exposed from a storage array that supports TP. Virtual disks created as thin disks are exposed as TP disks, starting with virtual Hardware Version 9. 

What is Dead Space Reclamation? Deleting files frees up space on the file system volume. This freed space sticks with the LUN/Disk, until it is released and reclaimed by the underlying storage layer. Free space reclamation allows the lower level storage layer (for example a storage array, or any hypervisor) to repurpose the freed space from one client for some other storage allocation request. For example:
  • A storage array that supports thin provisioning can repurpose the reclaimed space to satisfy allocation requests for some other thin provisioned LUN within the same array.
  • A hypervisor file system can repurpose the reclaimed space from one virtual disk for satisfying allocation needs of some other virtual disk within the same data store.
GuestReclaim allows transparent reclamation of dead space from NTFS volumes.


System requirements

Thin provisioned (TP) SCSI disk
Space can be reclaimed on SCSI disks that advertise themselves as thin provisioned (TP) devices.
GuestReclaim queries the device for its TP status using standard SCSI primitives like reading the vital product data page (B0 vpd). GuestReclaim will issue SCSI Unmap commands to the underlying storage for reclaiming dead space.
Supported Operating Systems
  • Desktop: XP onwards up to Windows 7
  • Server: Until Windows 2008
Administrative Privileges
The tool needs to be executed with Administrator privileges.
Supported Filesystem NTFS only.

Download link

http://labs.vmware.com/flings/guest-reclaim

Instructions

The tool is provided as a standalone binary executable. Unzip the package, and it will contain a program. The tool needs to be executed with Administrator privileges.
Run GuestReclaim.exe from the command prompt. Use the --list option to list available thin provisioned disks on the system. If none show up, it means that the first 16 drives are not thin provisioned. Export an environment variableRECLAIM_DEBUG to see verbose output of the TP querying results.

Thursday, March 7, 2013

VMware ThinApp



What is ThinApp

VMware® ThinApp™ is an agentless application virtualization solution that decouples applications from their underlying operating systems to eliminate application conflict and streamline application delivery and management.

With ThinApp, an entire Windows application and its settings can be packaged into a single executable and deployed to many different Windows operating systems without imposing additional cost and complexity to the server or client. Application virtualization with ThinApp eliminates conflicts at the application and operating system level and minimizes costly recoding and regression testing to speed application migration to Windows 7.

ThinApp virtualizes applications by encapsulating application files and registry settings into a single ThinApp package. IT administrators can deploy, manage, and update these ThinApp packages independently from the underlying operating system (OS). The virtualized applications do not make any changes to the underlying OS and behave the same across different desktop configurations, which provide a stable, consistent end-user experience, and ease of management.



Common Use Cases To Leverage VMware ThinApp

VMware ThinApp simplifies application delivery by encapsulating applications in portable packages that can be deployed to many endpoint devices while isolating applications from each other and from the underlying operating system. Common use cases for ThinApp are:

•    Simplify Windows 7 migration—Migrate legacy applications that run on Internet Explorer 6 to 32- and 64-bit Windows 7 systems by packaging with ThinApp, to eliminate costly recoding, regression testing, and support costs.
•    Eliminate application conflicts—Isolate desktop applications from each other and from the underlying OS to avoid conflicts.
•    Reduce desktop storage costs—Add ThinApp packages to View desktops and leverage the View deployment to reduce desktop storage costs and streamline updates to endpoints.
•    Augment security policies—Deploy ThinApp packages on “locked-down” PCs and allow end users to run their favorite applications without compromising security.
•    Increase mobility for end users—Deploy, maintain, and update virtualized applications on USB sticks for ultimate portability.

Features

·         Agentless Application Virtualization
o   ThinApp requires no agent code on target devices.
o   Entire applications and their settings can be packaged into a single executable that runs independently on any endpoint, allowing multiple versions or multiple applications to run on the same device without any conflict.
o   Application packages run only in user mode, so end users have the freedom and flexibility to run their preferred applications on locked-down PCs without compromising security.

·         Fast, Flexible Application Packaging
o   Package an application once and deploy it to desktops or servers (physical or virtual, 32- or 64-bit)running Windows XP, Windows Vista, Windows 7, Windows Server 2003, or Windows Server 2008.
o   Upgrade existing ThinApp executables to incorporate new ThinApp runtime features quickly and easily without the need for associated project files.
·         Fast, Flexible Application Delivery

o   Automatically apply updates over the web to applications on unmanaged PCs and devices.
o   Deploy, maintain, and update applications on USB storage drives and thin client terminals.
o   Virtualize legacy applications that are supported on Windows 7 to 32- and 64-bit Windows 7 systems.

·         Seamless Integration with Existing Infrastructure
o   Zero-footprint architecture
o   ThinApp creates standard MSI and EXE packages that can be delivered through existing application deployment tools from Microsoft, BMC, HP, CA, Novell, Symantec, LANDesk, and others.
o   Support for Active Directory authentication—Add and remove ThinApp users from active Directory groups, and prevent unauthorized users from executing ThinApp packages.

Pricing* (may vary)

Description
Cost
Qty
Totals
VMware ThinApp 4.6 Suite + Production (24x7 for Severity 1 issues) 3 Year Support
$8,300.00
1
$8,300.00
VMware ThinApp 4.x Client License 100 Pack + Production (24x7 for Severity 1 issues) 3 Year Support
$3,154.00
3
$9,462.00
VMware ThinApp 4.x Client License 100 Pack + Basic (12x5) 3 Year Support
$2,953.36
3
$8,860.08

Note about Horizon Application Manager

VMware has announced the end of availability (“EOA”) of VMware ThinApp Client and Suite, effective on December 31st, 2013.  No further orders for VMware ThinApp will be accepted after this date.  ThinApp Customers with an active Support and Subscription contract will continue to receive support and maintenance through the end of support life as specified in the product lifecycle policies. ThinApp capabilities will still be available in VMware Horizon View, VMware Horizon Mirage, VMware Horizon Workspace, and VMware Horizon Suite. Read the FAQs for more information.
Horizon Application Manager is an enterprise-level, cloud-based application catalog and reporting mechanism that provides secure, managed user access to SaaS applications, federated web applications, and ThinApp virtualized Windows applications, all with a single secure sign-on. VMware Horizon provides a new management platform for entitling, deploying, and monitoring ThinApp packages.

Monday, February 11, 2013

Difference between vSphere Replication and Array based replication in SRM 5.0



Difference between vSphere Replication and Array based replication in SRM 5.0

vSphere replication advantages:-
1.      No requirement for enterprise array based replication at both sites.
2.      Replication between heterogeneous storage, whatever that storage vendor or protocol might be at each site (so long as it’s supported on the HCL).
3.      Replication of local or direct attached storage is possible in VR whereas in Array based replication, the data to be replicated must reside on SAN.
4.      It allows per VM replication.
5.      It’s included in the cost of SRM licensing. No extra VMware or array based replication licenses are needed.

vSphere replication disadvantages:-
1.      Re-Protect and Automated Failback is only supported with array-replicated virtual machines. Virtual machines configured with vSphere Replication cannot be failed back automatically to the original site using existing recovery plans. This feature is available in SRM 5.1.
2.      Cannot replicate powered off virtual machines. Therefore it cannot replicate templates as well. VM would be replicated once they are powered on.
3.      Cannot replicate FT VMs. Note that array based replication can be used to protect FT VMs but once recovered they are no longer FT enabled.
4.      vSphere Replication cannot be used in conjunction with physical raw disk mapping (RDM).
5.      VR has file level consistency only (no application consistency). However, in SRM 5.1, it does offer some type of application consistency.
6.      Asynchronous replication is not supported by VR. Array based replication will replicate a VMware based snapshot hierarchy to the destination site while leaving them intact. VR can replicate VMs with snapshots but they will be consolidated at the destination site.  This is again based on the principle that only changes are replicated to the destination site.
7.      Cannot replicate vApp consistency groups.
8.      With vSphere Replication, RPO is 15 min or higher.
9.      VR does not work with virtual disks opened in “multi-writer mode” which is how MSCS VMs are configured.
10.   Losing a vSphere host means that the vRA and the current replication state of a VM or VMs is also lost.  In the event of HA failover, a full-sync must be performed for these VMs once they are powered on at the new host (and vRA).
11.   In band VR requires additional open TCP ports:
a.      31031 for initial replication
b.      44046 for ongoing replication
12.   VR requires vSphere 5 hosts at both the protected and recovery sites while array based replication follows only general SRM 5.0 minimum requirements of vCenter 5.0 and hosts which can be 3.5, 4.x, and/or 5.0.
13.   Cannot replicate linked clone trees (Lab Manager, vCD, View, etc.)

Other points to consider:-
  • Network address translation (NAT) is not supported with SRM: When configuring vSphere Replication, you must configure the vSphere Replication Server (VR server) with an IP address that is visible to both the protected vSphere Replication Management Server (VRM Server) and the recovery VRM Server. 
  • Neither array-based replication nor vSphere Replication support using Storage DRS: Storage vMotion of a replicated virtual machine results in a full sync, where both the primary and the recovery side disks are read and hashed, and these hashes are exchanged over the wire which can result in heavy I/O, and this can cause latency on the datastore.




Thursday, December 27, 2012

Cannot complete login due to invalid user name and password error: VMware 5.1 upgrade

Error description: "cannot complete login due to invalid user name and password" usually occurs after upgrade to vCenter 5.1. Login to vCenter and the web client fails.

I was able to fix the issue in my environment by enabling the NetBIOS over TCP/IP settings in the vCenter server. 





Other good practice to follow is to use FQDN for all the hostnames (vCenter/Single Sign-on).

Host Profile Path Selection Policy error in ESXi 5.0

You might have come across the following error while checking for compliance against a host profile in ESXi 5.0 Update 1:-

Specification state absent from host: SATP VMW_SATP_ALUA_CX needs to be set to use Path Selection Policy VMW_PSP_FIXED_AP by default
Host state dosen't match specification: SATP VMW_SATP_ALUA_CX needs to be set to use Path Selection Policy VMW_PSP_FIXED by default

To resolve this issue:-

1. Open Host Profiles page on your vCenter server. (Home -> Under Management click on host profiles)

2. Right click the profile which was giving error and select "Enable/Disable Profile Configuration"




3. In the new window that opens up, expand the storage configuration section and uncheck Pluggable Storage Architecture (PSA) and Native Multi-Pathing (NMP).




4. Hit ok.

After the Host Profile has been modified, attach it to the ESXi 5.0 host again and check for compliance.

Per VMware support, this issue occurs due to a bug in the ESXi 5.0 update 1. This issue has been fixed in ESXi 5.0 update 2 and ESXi 5.1

Friday, October 12, 2012

Part 5: VEEAM Backup and Replication v6 setup and config (Troubleshooting performance issues)


This is part 5 of a 5 series post on VEEAM installation and configuration. In this section I will show how to troubleshoot performance issues with the Virtual VEEAM Backup and Replication server.

Read my other posts on this topic:-
Part 1 (Introduction and Pre-requisites)
Part 2 (VEEAM Installation steps)
Part 3 (VEEAM Configuration)
Part 4 (Creating backup jobs)

 So after I started running the backups via my virtual VEEAM backup server, I noticed terribly poor performance on the backup server. The windows task manager showed 100% CPU utilization. 



But the network was hardly being utilized. 




The Windows resource manager showed moderate to high I/O on the backup drive (which is understandable and acceptable, considering that we were running two backup streams simultaneously).



The vSphere performance graphs also confirmed the stats that the Windows task manager was showing. 



To further explore the issue, I looked at the VEEAM backup job logs. The logs clearly had an entry which said that the primary bottleneck in the whole process was our Proxy server (which in our case is also our VEEAM Backup and Replication server). Read the second last line in the job log screenshot below ("Primary bottleneck: Proxy").




To troubleshoot this issue I looked at the task manager performance window, the VM's performance tab in the vSphere client, and the VEEAM backup job logs. I decided to increase the number of vCPUs on the VM from 2 to 8. 

After increasing the number of cores, I was able to run the job faster and without causing any performance impact on the VEEAM Backup server.


This concludes the 5 series blog on VEEAM Backup and Replication. I hope you enjoyed reading the blog. Please feel free to leave any comments and I will reply to them as soon as I can.

Thank you.
Gurpreet Singh Anand

Tuesday, September 18, 2012

Part 4: VEEAM Backup and Replication v6 setup and config (Creating backup jobs)


This is part 4 of a 5 series post on VEEAM installation and configuration. In this section, I will show how to create the backup policies.

Read my other posts on this topic:-

1. On the menu bar click on the Backup icon. In the new window that opens up, enter the name of the backup job and click next.



2. In the next window, click on Add and then select the VMs that you want to backup. You can also exclude certain drive(s) that you do not want to backup.





 3. In the next window, you can specify a particular backup proxy server to use or you can let VEEAM automatically choose any suitable backup proxy server for you.


4. In the next screen, select the VEEAM repository that you want to use to store the backups. Also specify the number of restore points you want to keep on the disk. 


VEEAM will automatically delete any old backup copy after the "14th" copy (as per the screenshot above). But it will make sure that there is always a FULL backup and related incremental backup copies on disk before it deletes any old backup file.


5. Click Advanced.  



Here you can specify if you need synthetic Full Backups (which always run incremental and then in the background a FULL backup is created on the disk). In this case, you would have a FULL Backup file and some incrementals. For e.g. you can specify Saturday to convert your incrementals into a FULL Backup. The backups for the week will run incremental so you can see incremental files in the backup repository. Then on Saturday, a FULL Backup file will be created on the disk where your incremental backups are stored.

You can also check the roll back option, which is basically keeping the latest backup as FULL instead of incremental. So at any point of time, you would have a latest FULL Backup and past incrementals upto the point of FULL.

Under Advanced settings, you can also specify the deduplication level.



In the notification tab, you can enable email and SNMP settings.


In the vSphere tab, you can set the option for Changed block tracking which will allow for faster restores. 
NOTE: You will see warning messages during your VM backup if the changed block tracking is enabled and the VM has an active snapshot. 

Under the Advanced tab, you can enable settings for Integrity checks, VM retention etc. You can leave these settings  to default.
NOTE: VM retention refers to the retention for any information, logs or any data for a VM that has been deleted and not the actual VM backup files retention.

6. Under Guest Processing, you can enable options for application level snapshots or application quiescence. You can also set option for the guest file system indexing. Both these options are self explanatory in the window so I won't spend much time discuss them here. If you have any questions, then please leave a comment at the bottom of the page.


7. In the next Window, you specify the schedule for the backup policy and the failed job retry settings.


8. Click create. Verify the policy details in the next window and hit finish to complete the backup job creation. You can also enable the backup job to run for the first time from this screen.



This completes the VEEAM Backup job creation steps. In my next blog, I will discuss regarding any performance issue that you may face if you install VEEAM on a virtual machine.

Click here to go to Part 5 (VEEAM Troubleshooting performance issues)


Friday, August 24, 2012

New features in Windows Server 2012

Windows server 2012 has been released to the manufacturing. It will be available for general evaluation and purchase by all customers around the world on September 4 2012.

Here is the information on some of the new features in Windows Server 2012:-


Licensing


The Enterprise Licensing has been eliminated. There are only 4 license types in Windows 2012.  
  • Datacenter edition for highly-virtualized private cloud environments.
  • Standard edition for non-virtualized or lightly virtualized environments.
  • Essentials edition for small businesses with up to 25 users running on servers with up to two processors.
  • Foundation edition for small businesses with up to 15 users running on single processor servers.


Here is a comparison of various editions by server role.



Here is a summary of key features:-


Running instances


Running instances can exist either in a physical operating system environment (POSE) or a virtual operating system environment (VOSE).



Powershell

Windows Powershell has over 2300 commandlets as compared to 200 in Windows Server 2008


Task Manager

New Task Manager Window, shows more detailed information about each process/application


File System

New type of file system for File servers is called ReFS (Resilient File System). Max file size of 16 Exabytes and max volume size of 1 yottabytes (hardware restrictions still apply)


CPU and Memory limits

· There is no support for Itanium based processors
· Max logical processors: 640 (It was 256 in Windows Server 2008 R2)
· Max RAM: 4 TB (It was 2 TB in Windows Server 2008 R2)


Some new RDS features

a) Single Sign-On:  In Windows Server 2008 R2, it was possible to configure an RDS deployment so that users will need to enter their credentials only once when connecting to RemoteApps and hosted desktops. However, this configuration was very cumbersome. Windows Server 2012 dramatically simplified this by eliminating the need to use multiple certificates. It is also possible to use locally logged on domain credentials so that users connecting from managed devices can connect seamlessly without any credential prompts.
b) Email and web discovery of Remote Applications and desktops:  Users now can find the correct remote workspace to connect to by just providing their email address. This removes the requirement to remember a long website URL. In addition, Remote Desktop Web Access now supports other browsers such as Chrome, Firefox, and Safari.