On PC hosting the shares:
Elevated Command Prompt:
reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\system /v LocalAccountTokenFilterPolicy /t REG_DWORD /d 1 /f
Caused by windows updates KB4480970 and KB4480960
Source: Computer World
On PC hosting the shares:
Elevated Command Prompt:
reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\system /v LocalAccountTokenFilterPolicy /t REG_DWORD /d 1 /f
Caused by windows updates KB4480970 and KB4480960
Source: Computer World
Get-mailbox
Get-mailbox | get-mailboxstatistics | ft displayname,totalitemsize
Get-mailbox | get-mailboxstatistics | sort-object totalitemsize –descending | ft displayname,totalitemsize
Source: Alex De Jong
To check whats currently whitelisted (Bypassed Recipients):
Get-ContentFilterConfig
To whitelist a single email address:
$list = (Get-ContentFilterConfig).BypassedSenders
$list.add(“new.mail@address.com”)
Set-ContentFilterConfig -BypassedSenders $list
To whitelist an entire domain:
$list = (Get-ContentFilterConfig).BypassedSenderDomains
$list.add(“domain.com”)
Set-ContentFilterConfig -BypassedSenderDomains $list
Source: SBITZ
Administrative command prompt:
w32tm /config /syncfromflags:manual /manualpeerlist:time.nist.gov /update /reliable:yes
w32tm /resync
Check with:
w32tm /query /status
Source: DefaultReasoning
On SBS Server
Command Prompt run as admin:
%windir%\system32\inetsrv\appcmd.exe add backup BeforeRemovalAutodiscover
Exchange Management Shell run as admin:
Get-AutodiscoverVirtualDirectory | fl Name, Server, InternaUrl, Identity
Remove-AutodiscoverVirtualDirectory –Identity “identity value retrieved above”
If for some reason you need to restore autodiscover on the SBS server
Command Prompt run as admin:
%windir%\system32\inetsrv\appcmd.exe restore backup BeforeRemovalAutodiscover
Source: BlogsIISNet
Source: Toronto Help Desk
Create user as per usual, then:
1. Create new security group
2. Add user to security group
3. Group Policy Management: Create new Group Policy Object linked at root of domain
4. Right Click and choose edit.
Navigate to: Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > User Rights Assignment
5. Double-click “Deny log on locally”
6. Click “Add User or Group” and add the group you created in step 1. Apply.
7. Wait for Group Policy synchronisation or gpupdate /force on computers.
Source: ServerFault
A fantastic guide showing the steps to recover SBS 2008 / SBS 2011 from backups:
This occurs when the script has been sourced from the web.
In Windows Explorer:
Right click the .ps1 file and choose Properties
Click the Unblock button under Security on the General tab.