<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Dominik&#039;s Cloud Security Blog</title>
	<atom:link href="http://blog.gocloud-security.ch/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.gocloud-security.ch</link>
	<description>A Swiss blog about Microsoft&#039;s Security &#38; Identity and Access Management solutions for Private and Public Clouds</description>
	<lastBuildDate>Mon, 14 May 2012 19:31:46 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>FIM 2010 R2, SCSM Reporting and the Access to the SQL Server Instance was Denied Error</title>
		<link>http://blog.gocloud-security.ch/2012/05/14/fim-2010-r2-scsm-reporting-and-the-access-to-the-sql-server-instance-was-denied-error/</link>
		<comments>http://blog.gocloud-security.ch/2012/05/14/fim-2010-r2-scsm-reporting-and-the-access-to-the-sql-server-instance-was-denied-error/#comments</comments>
		<pubDate>Mon, 14 May 2012 19:31:46 +0000</pubDate>
		<dc:creator>Dominik Zemp</dc:creator>
				<category><![CDATA[Forefront]]></category>
		<category><![CDATA[Forefront|Forefront Identity Manager]]></category>
		<category><![CDATA[FIM]]></category>

		<guid isPermaLink="false">http://blog.gocloud-security.ch/?p=425</guid>
		<description><![CDATA[If you plan to install (collocate) to System Center Service Manager (SCSM) Management Server on the same server as the FIM Synchronization Service, FIM Service, FIM Portal, etc., for example in your home lab for testing, you have to think &#8230; <a href="http://blog.gocloud-security.ch/2012/05/14/fim-2010-r2-scsm-reporting-and-the-access-to-the-sql-server-instance-was-denied-error/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>If you plan to install (collocate) to System Center Service Manager (SCSM) Management Server on the same server as the FIM Synchronization Service, FIM Service, FIM Portal, etc., for example in your home lab for testing, you have to think about installing multiple SQL server instances. One of the reasons why you should install multiple SQL instances are SCSM’s requirements, for example because of the collation (multi-language support).</p>
<p>But there is something you should be aware of: Please do not use something like <em>MSSQLSERVER_SCSM</em> as the name of the instance, otherwise the SCSM Management Server installation wizard will fail! What you will see in the wizard is the error “access to the sql server instance was denied”, with the instance listed as <em>Default_SCSM</em>. If you use something like <em>SCSM</em> as the name for your instance, everything works smoothly… </p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gocloud-security.ch/2012/05/14/fim-2010-r2-scsm-reporting-and-the-access-to-the-sql-server-instance-was-denied-error/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cloud Security Alliance&#8217;s Consensus Assessments Initiative Questionnaire (CAIQ)</title>
		<link>http://blog.gocloud-security.ch/2012/05/03/cloud-security-alliances-consensus-assessments-initiative-questionnaire-caiq/</link>
		<comments>http://blog.gocloud-security.ch/2012/05/03/cloud-security-alliances-consensus-assessments-initiative-questionnaire-caiq/#comments</comments>
		<pubDate>Thu, 03 May 2012 09:20:33 +0000</pubDate>
		<dc:creator>Dominik Zemp</dc:creator>
				<category><![CDATA[Office 365]]></category>
		<category><![CDATA[Windows Azure]]></category>
		<category><![CDATA[Public Cloud]]></category>

		<guid isPermaLink="false">http://blog.gocloud-security.ch/?p=422</guid>
		<description><![CDATA[Microsoft has responded to the Alliance’s Consensus Assessments Initiative Questionnaire (CAIQ) for Windows Azure, Office365 and Dynamics CRM. The responses have been posted on the CSA web site online: Microsoft Office365 &#8211; https://cloudsecurityalliance.org/star-registrant/microsoft-office-365/ Microsoft Windows Azure &#8211; https://cloudsecurityalliance.org/star-registrant/microsoft-windows-azure/&#160; Microsoft Dynamics &#8230; <a href="http://blog.gocloud-security.ch/2012/05/03/cloud-security-alliances-consensus-assessments-initiative-questionnaire-caiq/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Microsoft has responded to the Alliance’s Consensus Assessments Initiative Questionnaire (CAIQ) for Windows Azure, Office365 and Dynamics CRM. The responses have been posted on the CSA web site online:</p>
<ul>
<li>Microsoft Office365 &#8211; <a href="https://cloudsecurityalliance.org/star-registrant/microsoft-office-365/" target="_blank">https://cloudsecurityalliance.org/star-registrant/microsoft-office-365/</a></li>
<li>Microsoft Windows Azure &#8211; <a href="https://cloudsecurityalliance.org/star-registrant/microsoft-windows-azure/" target="_blank">https://cloudsecurityalliance.org/star-registrant/microsoft-windows-azure/</a>&nbsp;</li>
<li>Microsoft Dynamics CRM Online &#8211; <a href="https://cloudsecurityalliance.org/star-registrant/microsoft-dynamics-crm-online/" target="_blank">https://cloudsecurityalliance.org/star-registrant/microsoft-dynamics-crm-online/</a></li>
</ul>
<p>“<em>In this document we provide our customers with a detailed overview of how Microsoft Online Services fulfill the security, privacy, compliance, and risk management requirements as defined in the Cloud Security Alliance (CSA) Cloud Control Matrix (CCM).</em> ” </p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gocloud-security.ch/2012/05/03/cloud-security-alliances-consensus-assessments-initiative-questionnaire-caiq/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FIM DB Sizing Calculator</title>
		<link>http://blog.gocloud-security.ch/2012/04/26/fim-db-sizing-calculator/</link>
		<comments>http://blog.gocloud-security.ch/2012/04/26/fim-db-sizing-calculator/#comments</comments>
		<pubDate>Thu, 26 Apr 2012 16:36:53 +0000</pubDate>
		<dc:creator>Dominik Zemp</dc:creator>
				<category><![CDATA[Forefront]]></category>
		<category><![CDATA[Forefront|Forefront Identity Manager]]></category>
		<category><![CDATA[FIM]]></category>

		<guid isPermaLink="false">http://blog.gocloud-security.ch/2012/04/26/fim-db-sizing-calculator/</guid>
		<description><![CDATA[David Lundell, the writer of the FIM Best Practices Volume 1, has published a very useful tool when you have to size the two required FIM databases &#8211; FIM Service and FIM Synchronization Service (the database for FIM Certificate Management &#8230; <a href="http://blog.gocloud-security.ch/2012/04/26/fim-db-sizing-calculator/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>David Lundell, the writer of the FIM Best Practices Volume 1, has published a very useful tool when you have to size the two required FIM databases &#8211; FIM Service and FIM Synchronization Service (the database for FIM Certificate Management is not included). The tool is an automated Excel sheet that calculates the database and transaction log sizes, based on the number of users and groups, how many MAs are involved, how long you want (have) to retain requests in the FIM Service database, etc. </p>
<p>You can find the download link for this Excel sheet and some further information on <a title="http://blog.ilmbestpractices.com/2012/04/fim-db-sizing-calculator.html" href="http://blog.ilmbestpractices.com/2012/04/fim-db-sizing-calculator.html" target="_blank">http://blog.ilmbestpractices.com/2012/04/fim-db-sizing-calculator.html</a>. </p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gocloud-security.ch/2012/04/26/fim-db-sizing-calculator/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FIM 2010 Terminology Document</title>
		<link>http://blog.gocloud-security.ch/2012/04/24/fim-2010-terminology-document/</link>
		<comments>http://blog.gocloud-security.ch/2012/04/24/fim-2010-terminology-document/#comments</comments>
		<pubDate>Tue, 24 Apr 2012 08:25:49 +0000</pubDate>
		<dc:creator>Dominik Zemp</dc:creator>
				<category><![CDATA[Forefront]]></category>
		<category><![CDATA[Forefront|Forefront Identity Manager]]></category>
		<category><![CDATA[FIM]]></category>

		<guid isPermaLink="false">http://blog.gocloud-security.ch/2012/04/24/fim-2010-terminology-document/</guid>
		<description><![CDATA[Jeff Ingalls has posted an article about an updated comprehensive FIM 2010 terminology documentation, that he and others have been created. This updated comprehensive terminology documentation ‘replaces’ the original list available on TechNet (http://technet.microsoft.com/en-us/library/ee534910(v=WS.10).aspx) with some very useful descriptions and &#8230; <a href="http://blog.gocloud-security.ch/2012/04/24/fim-2010-terminology-document/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Jeff Ingalls has posted an article about an updated comprehensive FIM 2010 terminology documentation, that he and others have been created. This updated comprehensive terminology documentation ‘replaces’ the original list available on TechNet (<a title="http://technet.microsoft.com/en-us/library/ee534910(v=WS.10).aspx" href="http://technet.microsoft.com/en-us/library/ee534910(v=WS.10).aspx" target="_blank">http://technet.microsoft.com/en-us/library/ee534910(v=WS.10).aspx</a>) with some very useful descriptions and explanations, and contains a Word and PDF file.</p>
<p>But please note, this is not an official FIM 2010 terminology documentation from Microsoft (the FIM product group).</p>
<p>Url: <a title="http://blogs.technet.com/b/jingalls/archive/2012/04/20/a-comprehensive-fim-2010-terminology-document.aspx" href="http://blogs.technet.com/b/jingalls/archive/2012/04/20/a-comprehensive-fim-2010-terminology-document.aspx" target="_blank">http://blogs.technet.com/b/jingalls/archive/2012/04/20/a-comprehensive-fim-2010-terminology-document.aspx</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gocloud-security.ch/2012/04/24/fim-2010-terminology-document/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FIM Object Visualizer now hosted on Codeplex</title>
		<link>http://blog.gocloud-security.ch/2012/04/16/fim-object-visualizer-now-hosted-on-codeplex/</link>
		<comments>http://blog.gocloud-security.ch/2012/04/16/fim-object-visualizer-now-hosted-on-codeplex/#comments</comments>
		<pubDate>Mon, 16 Apr 2012 13:17:14 +0000</pubDate>
		<dc:creator>Dominik Zemp</dc:creator>
				<category><![CDATA[Forefront|Forefront Identity Manager]]></category>
		<category><![CDATA[FIM]]></category>

		<guid isPermaLink="false">http://blog.gocloud-security.ch/2012/04/16/fim-object-visualizer-now-hosted-on-codeplex/</guid>
		<description><![CDATA[Markus Vilcinskas is currently working on a new version of the awesome FIM Object Visualizer (FIMOV), which is now hosted on Codeplex. For those of you how don’t know what the FIMOV is, here a short description: The FIM Object &#8230; <a href="http://blog.gocloud-security.ch/2012/04/16/fim-object-visualizer-now-hosted-on-codeplex/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Markus Vilcinskas is currently working on a new version of the awesome FIM Object Visualizer (FIMOV), which is now hosted on Codeplex.</p>
<p>For those of you how don’t know what the FIMOV is, here a short description:</p>
<p><em>The FIM Object Visualizer is a tool to create reports of various configurations such as:</em></p>
<ul>
<li><em>FIM Active Metaverse Schema configuration </em></li>
<li><em>Attribute Flow Precedence Configuration </em></li>
<li><em>Management Policy Rules </em></li>
<li><em>Synchronization Rules </em></li>
<li><em>Workflows </em></li>
<li><em>FIMMA Schema configuration </em></li>
<li><em>Management Agent Attribute Selection </em></li>
<li><em>Management Agents </em></li>
<li><em>Metaverse Schema </em></li>
<li><em>Replication Configuration</em> </li>
</ul>
<p>The FIMOV is now built with a .NET Windows Forms application and is available as a ClickOnce app as well.</p>
<p>Url: <a title="http://fimov.codeplex.com/" href="http://fimov.codeplex.com/" target="_blank">http://fimov.codeplex.com/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gocloud-security.ch/2012/04/16/fim-object-visualizer-now-hosted-on-codeplex/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft&#8217;s Antimalware Protection in the Cloud &#8211; MEP for Windows Azure CTP</title>
		<link>http://blog.gocloud-security.ch/2012/03/20/microsofts-antimalware-protection-in-the-cloud-mep-for-windows-azure-ctp/</link>
		<comments>http://blog.gocloud-security.ch/2012/03/20/microsofts-antimalware-protection-in-the-cloud-mep-for-windows-azure-ctp/#comments</comments>
		<pubDate>Tue, 20 Mar 2012 10:44:10 +0000</pubDate>
		<dc:creator>Dominik Zemp</dc:creator>
				<category><![CDATA[Endpoint Protection]]></category>
		<category><![CDATA[Windows Azure]]></category>
		<category><![CDATA[Azure]]></category>

		<guid isPermaLink="false">http://blog.gocloud-security.ch/2012/03/20/microsofts-antimalware-protection-in-the-cloud-mep-for-windows-azure-ctp/</guid>
		<description><![CDATA[If you are a subscriber of the Microsoft Downloader Center, then you have already seen this interesting announcement – If not, I hope this post helps! Microsoft Endpoint Protection for Windows Azure provides the ability to include an antimalware protection &#8230; <a href="http://blog.gocloud-security.ch/2012/03/20/microsofts-antimalware-protection-in-the-cloud-mep-for-windows-azure-ctp/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>If you are a subscriber of the Microsoft Downloader Center, then you have already seen this interesting announcement – If not, I hope this post helps! <img style="border-bottom-style: none; border-left-style: none; border-top-style: none; border-right-style: none" class="wlEmoticon wlEmoticon-smile" alt="Smile" src="http://blog.gocloud-security.ch/wp-content/uploads/2012/03/wlEmoticon-smile1.png"></p>
<p><em>Microsoft Endpoint Protection for Windows Azure provides the ability to include an antimalware protection agent in each Windows Azure virtual machine running your Windows Azure service. It extends the Windows Azure SDK by providing an antimalware import which provides antimalware configuration and deployment capabilities. </em></p>
<p>When you deploy MEP to Windows Azure, the following core technologies are enabled by default:</p>
<ul>
<li><strong>Real-time protection</strong> &#8211; monitors activity on the system to detect and block malware from executing.</li>
<li><strong>Scheduled scanning</strong> &#8211; periodically performs targeted scanning to detect malware on the system, including actively running malicious programs.</li>
<li><strong>Malware remediation</strong> &#8211; takes action on detected malware resources, such as deleting or quarantining malicious files and cleaning up malicious registry entries.</li>
<li><strong>Signature updates</strong> &#8211; installs the latest protection signatures (aka “virus definitions”) to ensure protection is up-to-date.</li>
<li><strong>Active protection</strong> &#8211; reports metadata about detected threats and suspicious resources to Microsoft to ensure rapid response to the evolving threat landscape, as well as enabling real-time signature delivery through the Dynamic Signature Service (DSS).</li>
</ul>
<p>And of course, the monitoring of MEP (btw, I just assume that MEP will be the acronym for Microsoft Endpoint Protection, similar to FEP or SCEP) is addressed as well. So obvious, System Center should be your monitoring tool to use (System Center Monitoring Pack for Windows Azure, <a href="http://www.microsoft.com/download/en/details.aspx?id=11324" target="_blank">http://www.microsoft.com/download/en/details.aspx?id=11324</a>)</p>
<p>Download URL and documentations: <a title="http://www.microsoft.com/download/en/details.aspx?id=29209" href="http://www.microsoft.com/download/en/details.aspx?id=29209" target="_blank">http://www.microsoft.com/download/en/details.aspx?id=29209</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gocloud-security.ch/2012/03/20/microsofts-antimalware-protection-in-the-cloud-mep-for-windows-azure-ctp/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Server 8 Beta and Remote Access (DirectAccess and RRAS)</title>
		<link>http://blog.gocloud-security.ch/2012/03/08/windows-server-8-beta-and-remote-access-directaccess-and-rras/</link>
		<comments>http://blog.gocloud-security.ch/2012/03/08/windows-server-8-beta-and-remote-access-directaccess-and-rras/#comments</comments>
		<pubDate>Thu, 08 Mar 2012 08:30:43 +0000</pubDate>
		<dc:creator>Dominik Zemp</dc:creator>
				<category><![CDATA[Windows DirectAccess]]></category>
		<category><![CDATA[DirectAccess]]></category>

		<guid isPermaLink="false">http://blog.gocloud-security.ch/2012/03/08/windows-server-8-beta-and-remote-access-directaccess-and-rras/</guid>
		<description><![CDATA[With the release of the Windows Server 8 beta, Microsoft introduced several new and/or enhanced capabilities within the Remote Access role. One of this new and enhanced capability is DirectAccess, which has slightly been improved since Windows Server 2008 R2. &#8230; <a href="http://blog.gocloud-security.ch/2012/03/08/windows-server-8-beta-and-remote-access-directaccess-and-rras/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>With the release of the Windows Server 8 beta, Microsoft introduced several new and/or enhanced capabilities within the Remote Access role. One of this new and enhanced capability is DirectAccess, which has slightly been improved since Windows Server 2008 R2. <img style="border-bottom-style: none; border-left-style: none; border-top-style: none; border-right-style: none" class="wlEmoticon wlEmoticon-smile" alt="Smile" src="http://blog.gocloud-security.ch/wp-content/uploads/2012/03/wlEmoticon-smile.png"></p>
<p>To keep things simple, Windows Server 8 DirectAccess now includes all features and functions from Forefront UAG DirectAccess, as well as a few new capabilities:</p>
<ul>
<li>DirectAccess and RRAS coexistence</li>
<li>Simplified DirectAccess management for small and medium organization administrators</li>
<li>Removal of PKI deployment as a DirectAccess prerequisite </li>
<li>Built-in NAT64 and DNS64 support for accessing IPv4-only resources</li>
<li>Support for DirectAccess server behind a NAT device</li>
<li>Simplified network security policy</li>
<li>Load balancing support</li>
<li>Support for multiple domains</li>
<li>NAP integration</li>
<li>Support for OTP (token based authentication)</li>
<li>Automated support for force tunneling</li>
<li>IP-HTTPS interoperability and performance improvements</li>
<li>Manage-out support</li>
<li>Multisite support</li>
<li>Support for Server Core</li>
<li>Windows PowerShell support</li>
<li>User and server health monitoring</li>
<li>Diagnostics</li>
<li>Accounting and reporting</li>
<li>Site-to-site IKEv2 IPsec tunnel mode VPN</li>
</ul>
<p>Therefore it is not a surprise, that a Forefront UAG DirectAccess migration is already in place on TechNet (<a title="http://technet.microsoft.com/en-us/library/hh831658.aspx" href="http://technet.microsoft.com/en-us/library/hh831658.aspx">http://technet.microsoft.com/en-us/library/hh831658.aspx</a>).</p>
<ul>
<li>Remove Access overview, <a title="http://technet.microsoft.com/en-us/library/hh831416.aspx" href="http://technet.microsoft.com/en-us/library/hh831416.aspx">http://technet.microsoft.com/en-us/library/hh831416.aspx</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://blog.gocloud-security.ch/2012/03/08/windows-server-8-beta-and-remote-access-directaccess-and-rras/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FIM 2010 Update Rollup 2 (Build 4.0.3606.2)</title>
		<link>http://blog.gocloud-security.ch/2012/02/29/fim-2010-update-rollup-2-build-4-0-3606-2/</link>
		<comments>http://blog.gocloud-security.ch/2012/02/29/fim-2010-update-rollup-2-build-4-0-3606-2/#comments</comments>
		<pubDate>Wed, 29 Feb 2012 14:39:37 +0000</pubDate>
		<dc:creator>Dominik Zemp</dc:creator>
				<category><![CDATA[Forefront|Forefront Identity Manager]]></category>
		<category><![CDATA[FIM]]></category>

		<guid isPermaLink="false">http://blog.gocloud-security.ch/2012/02/29/fim-2010-update-rollup-2-build-4-0-3606-2/</guid>
		<description><![CDATA[In case you have missed this important announcement: http://support.microsoft.com/kb/2635086 Update Rollup 2 (build 4.0.3606.2) is available for Microsoft Forefront Identity Manager (FIM) 2010. This hotfix package resolves several issues and adds several features that are described in the &#8220;More Information&#8221; &#8230; <a href="http://blog.gocloud-security.ch/2012/02/29/fim-2010-update-rollup-2-build-4-0-3606-2/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>In case you have missed this important announcement:</p>
<p><a title="http://support.microsoft.com/kb/2635086" href="http://support.microsoft.com/kb/2635086">http://support.microsoft.com/kb/2635086</a></p>
<p><em>Update Rollup 2 (build 4.0.3606.2) is available for Microsoft Forefront Identity Manager (FIM) 2010. This hotfix package resolves several issues and adds several features that are described in the &#8220;More Information&#8221; section. Additionally, this update contains all servicing fixes that were made since the release of FIM 2010.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gocloud-security.ch/2012/02/29/fim-2010-update-rollup-2-build-4-0-3606-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>[Update2] FIM 2010 and Exchange 2010 Provisioning and which Account must be Member of the Exchange Recipient Administrators Group?</title>
		<link>http://blog.gocloud-security.ch/2012/02/10/update2-fim-2010-and-exchange-2010-provisioning-and-which-account-must-be-member-of-the-exchange-recipient-administrators-group/</link>
		<comments>http://blog.gocloud-security.ch/2012/02/10/update2-fim-2010-and-exchange-2010-provisioning-and-which-account-must-be-member-of-the-exchange-recipient-administrators-group/#comments</comments>
		<pubDate>Fri, 10 Feb 2012 22:53:53 +0000</pubDate>
		<dc:creator>Dominik Zemp</dc:creator>
				<category><![CDATA[Forefront]]></category>
		<category><![CDATA[Forefront|Forefront Identity Manager]]></category>
		<category><![CDATA[FIM]]></category>

		<guid isPermaLink="false">http://blog.gocloud-security.ch/2012/02/10/update2-fim-2010-and-exchange-2010-provisioning-and-which-account-must-be-member-of-the-exchange-recipient-administrators-group/</guid>
		<description><![CDATA[With this short blog, I would like to point you to another confusing statement that you can find in the article on http://technet.microsoft.com/en-us/magazine/ff472471.aspx: If you just add the service account to the Exchange Recipient group, you will see the following &#8230; <a href="http://blog.gocloud-security.ch/2012/02/10/update2-fim-2010-and-exchange-2010-provisioning-and-which-account-must-be-member-of-the-exchange-recipient-administrators-group/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>With this short blog, I would like to point you to another confusing statement that you can find in the article on <a href="http://technet.microsoft.com/en-us/magazine/ff472471.aspx">http://technet.microsoft.com/en-us/magazine/ff472471.aspx</a>:</p>
<p><a href="http://blog.gocloud-security.ch/wp-content/uploads/2012/02/image.png"><img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="image" border="0" alt="image" src="http://blog.gocloud-security.ch/wp-content/uploads/2012/02/image_thumb.png" width="645" height="196"></a></p>
<p>If you just add the service account to the Exchange Recipient group, you will see the following error event in EventLog (and of course, the run profile will stop/fail with the error stopped-extension-dll-exception). </p>
<p><em>There is an error in Exch2010Extension BeginExportToCd() function.Type: System.Management.Automation.Remoting.PSRemotingTransportException</em></p>
<p><em>Message: </em></p>
<p><em>&#8220;Microsoft.MetadirectoryServices.ExtensionException: Processing data from remote server failed with the following error message: The user &#8220;&lt;domain&gt;/<font style="background-color: #ffff00">&lt;ADMAAccount&gt;</font>&#8221; isn&#8217;t assigned to any management roles. For more information, see the about_Remote_Troubleshooting Help topic.</em></p>
<p>So based on the error, it’s clear that you have to add the account used for the Active Directory Management Agent to the Exchange Recipient Administrators group, instead of the FIM Sync Service service account.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gocloud-security.ch/2012/02/10/update2-fim-2010-and-exchange-2010-provisioning-and-which-account-must-be-member-of-the-exchange-recipient-administrators-group/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>[Update] BitLocker and How To Change the User PIN</title>
		<link>http://blog.gocloud-security.ch/2012/02/09/update-bitlocker-and-how-to-change-the-user-pin/</link>
		<comments>http://blog.gocloud-security.ch/2012/02/09/update-bitlocker-and-how-to-change-the-user-pin/#comments</comments>
		<pubDate>Thu, 09 Feb 2012 06:42:45 +0000</pubDate>
		<dc:creator>Dominik Zemp</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Windows BitLocker]]></category>

		<guid isPermaLink="false">http://blog.gocloud-security.ch/?p=401</guid>
		<description><![CDATA[I’ve just seen that this blog post about BitLocker and how a Windows standard user can change the PIN got many hits in the last couple of days. So I’ve just decided to write a short update on that topic… &#8230; <a href="http://blog.gocloud-security.ch/2012/02/09/update-bitlocker-and-how-to-change-the-user-pin/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I’ve just seen that this blog post about BitLocker and how a Windows standard user can change the PIN got many hits in the last couple of days. So I’ve just decided to write a short update on that topic…</p>
<p>My old blog (<a title="http://blog.gocloud-security.ch/2009/12/09/bitlocker-and-how-to-change-the-user-pin/" href="http://blog.gocloud-security.ch/2009/12/09/bitlocker-and-how-to-change-the-user-pin/" target="_blank">http://blog.gocloud-security.ch/2009/12/09/bitlocker-and-how-to-change-the-user-pin/</a>) describes a possible solution/approach with a custom service or process that calls the manage-bde command. Now, since a couple of month, there is a much smarter way to allow your Windows standard users to change the BitLocker PIN – MBAM (Microsoft BitLocker Administration and Monitoring)!</p>
<p>MBAM has been released in August 2011 as part of MDOP and integrates different capabilities that have been missed with BitLocker. For example a helpdesk key recovery UI, single recovery keys (the MBAM client will create a new key once a BitLocker recovery key has been exposed), and different audit and compliance reports.</p>
<p>You can find a technical slide deck with all required information about MBAM<br />
on <a href="http://media.ch9.ms/teched/na/2011/ppt/WCL317.pptx" target="_blank">http://media.ch9.ms/teched/na/2011/ppt/WCL317.pptx</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gocloud-security.ch/2012/02/09/update-bitlocker-and-how-to-change-the-user-pin/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

