65355.book Page 403 Sunday, August 12, 2007 4:51 PM

Index

Note to the Reader: Throughout this index boldfaced page numbers indicate primary discussions of a topic. Italicized page numbers indicate illustrations.

AD () A defined, 366 A (Address) records, 309, 366 overview, 225, 226 AcceptEULA component, 48 user accounts, 366 access control lists (ACLs), 144 ad hoc networks, 285 Access Denied message, 144, 366 Adapter tab, 70 access to resources, 97 adapters auditing, 103–105 defined, 366 BitLocker, 101–103 drivers, 69–70 file-level security, 97–101, 99 requirements, 7 network, 134–135, 134, 325–329, Add Counters dialog box, 205–206, 205 326, 328–329 Add Recovery Agent Wizard, 100 Security Configuration and Analysis Add Setting to Pass 1 windowsPE tool, 105–106 option, 45 troubleshooting, 142–144 Address (A) records, 309, 366 user accounts. See users and user addresses, IP. See Internet Protocol (IP) accounts Admin Approval mode account lockout policy, 366 defined, 366 account policies, 366 prompts, 109, 109 accounts, user. See users and user setting, 110, 148 accounts Admin logs, 165 ACLs (access control lists), 144 administrative rights, 107–109, 108 ACPI (Advanced Configuration and Administrative templates for Group Power Interface), 9 Policy, 127 actions, Task Scheduler, 174, 366 Administrator accounts, 366 Activate trigger option, 178 Administrator Approved Controls GPO Active component, COPYRIGHTED47 MATERIALtemplates, 127 Active Directory (AD) AdministratorPassword component, 49 defined, 366 administrators in Protected Mode, 130 overview, 225, 226 Advanced Attributes dialog box, 98, 99 user accounts, 366 Advanced Configuration and Power ActiveX Installer Service, 94–95, 367 Interface (ACPI), 9 ActiveX Opt-In, 94–95, 95, 367 Advanced Subscription dialog ActivityID object, 242 box, 169–170, 170 Advanced tab in , 290

65355.book Page 404 Sunday, August 12, 2007 4:51 PM

404 Advanced TCP/IP Settings dialog box – At Startup trigger

Advanced TCP/IP Settings dialog box, AppData folder, 73 266, 267, 269, 269 Appearance Color Scheme, 70 Aero interface, 6–7 Appearance tab, 208 defined, 394 /append switch in ImageX, 27 in editions, 12 Application Compatibility GPO tem- support for, 23, 69–70 plates, 127 AIK (Automated Installation Kit), 6, Application Compatibility Toolkit, 4, 5 41, 51 Application Failures category, 210 alerts, 367 Application Information service, 147 All Removable Storage Classes: Deny Application log All Access policy, 68 defined, 367 All Running Tasks dialog box, 183, 183 types, 164–165, 165 /all switch in ipconfig.exe, 311–313 wireless networking, 318 All Users folders, 58 application packages, 340–344, Allow BitLocker Without a Compatible 341–344, 367 TPM option, 103 applications Allow Connections from Computers business environment, 8–9 Running Any Version of Remote compatibility, 70–72, 71–72 Desktop (Less Secure) option, 279 defined, 340 Allow Connections Only from exam essentials, 357 Computers Running Remote for, 340–345, 341–345 Desktop with Network Level maintaining, 355–356 Authentication (More Secure) review questions, 358–363 option, 279 SMS for, 346–347 Allow Previously Unused ActiveX software restrictions. See software Controls to Run Without Prompt restrictions option, 95 summary, 356–357 Allow Scriptlets option, 97 troubleshooting, 136–138, 147 Allow Task to Be Run on Demand task uninstalling, 345–346, 345 condition, 180 upgrading, 345 Allowed Items list, 367 section, 60 Also Apply Redirection Policy option, 77 Apply Redirection Policy option, 76 Alternate IP Configuration feature, 266, /apply switch in ImageX, 27 270–271, 271, 367 Ask Me Later option, 21 Analytic logs, 165 asset management, 347 Analyze Computer Now option, 105 assigned application packages, Answer File pane, 41, 48–49 341–342, 342, 367 answer files, 41–50, 42–46 assistance, Windows Remote antivirus scanners, 136 Assistance, 281–284, 282–283 APIPA (automatic private IP At Log On trigger, 176 addressing), 270–271, 271, 367 At Startup trigger, 176

65355.book Page 405 Sunday, August 12, 2007 4:51 PM

At Task Creation/Modification trigger – business environment 405

At Task Creation/Modification Basic Input/Output System (BIOS) trigger, 177 defined, 368 Attempt to Restart Up To task revisions, 8 condition, 180 Basic template, 213 audit mode, 50 Basic User security level, 351 Audit policies, 367 Battery Meter utility, 368 Audit the Use of and Restore BDD (Business Desktop Deployment) Privilege policy, 104 Solution 2007, 4, 6, 368 auditing Behavior of the Elevation Prompt for security events, 103–105 Administrators in Admin Approval subcategories, 144 Mode setting, 111–112, 148 auditpol.exe tool, 104 Behavior of the Elevation Prompt for auditpolicy.txt file, 104 Standard Users setting, 112 Authenticated Users group, 367 binary numbers, 257–260 authentication issues, 145–146 BIOS (Basic Input/Output System) autoconfiguration, IP, 270–271, 271 defined, 368 automated installation, 367 revisions, 8 Automated Installation Kit (AIK), 6, BitLocker Drive Encryption 41, 51 defined, 368 automatic private IP addressing overview, 101–103 (APIPA), 270–271, 271, 367 removable device interaction with, 68 Automatically Deny Elevate Requests troubleshooting, 142–144 option, 112 BitLocker Recovery Password Viewer, Automatically Use My Windows 143 Logon Name and Password Bluetooth technology, 368 option, 275 boot partitions, 368 automation, USMT for, 57 boot process, 368 autounattend.xml file, 49, 51 boot.wim file, 26 Average option, 207 bottlenecks, 368 Browser Menus GPO templates, 127 build servers, 51 B Business Desktop Deployment (BDD) Solution 2007, 4, 6, 368 background wallpaper, 21 business environment, 2–3 backing up EFS certificates, 99–100, 99 application support and Balanced power plans, 367 compatibility, 8–9 bandwidth deployment tools, 3–6, 4–6 events, 170–171 edition options, 12 wireless networking, 285 hardware requirements, 6–8 base images, 50 networks, 9–10, 10 baselines, 368 organization, 10–11

65355.book Page 406 Sunday, August 12, 2007 4:51 PM

406 CAB file-based installation – /config switch in ImageX

Check for Updates but Let Me Choose C Whether to Download and Install CAB file-based installation, 26 Them option, 115 Calculator, 258 cipher.exe tool, 144, 369 CAPI2-aware applications, 146 cipher text, 369 CAPI2 log, 146 clean installations /capture switch in ImageX, 27–28 defined, 369 CAs (certificate authorities), 130–132 performing, 14–24, 14–24 catalog files, 41 Client for Networks CD and DVD policy, 68 component, 264 CD-ROM drive requirements, 7 client portion in IP addresses, 259 central processing units (CPUs) Client (Respond Only) option, 288 defined, 368 clients Reliability and , defined, 369 196–198, 197 DNS, 268–269, 269 certificate authentication, 368 RDC, 280–281m 280–281 certificate authorities (CAs), 130–132 Collecting Information phase in clean Certificate Export Wizard, 100 installations, 16 Certificate Import Wizard, 143 collector sets, 212 Certificate Manager, 368 creating, 212–214, 213 certificate rules reports, 214, 215 defined, 369 system data collector sets, 214 software restrictions, 352 collectors for events, 167 certificates, 368 colons (:) in IP addresses, 262 EFS, 98–101, 99, 144 color depth, 70 troubleshooting, 130–133, 132–133, Color Management tab, 70 145–146 /commit switch in ImageX, 27–28 Certificates folder, 99, 99 Compatibility Mode, 9 certmgr.msc tool, 142, 146 compatibility of applications, 70–72, Challenge Handshake Authentication 71–72 Protocol (CHAP), 369 Compatibility tab, 72, 72 Change Date and Time setting, 107 /compress switch in ImageX, 27 Change Settings screen, 114, 114 compression, 369 Change Time Zone setting, 107 Computer component of events, 162 CHAP (Challenge Handshake Computer folder, 369 Authentication Protocol), 369 Computer Management tool, 369 Chat option, 284 computer names, 21, 369 Check for Certificate Revocation Computer Selection screen, 237, 240 option, 133 conditions for tasks, 178–180, 178 Check for Updates option, 114 /config switch in ImageX, 27 65355.book Page 407 Sunday, August 12, 2007 4:51 PM

config.xml file – default folders 407

config.xml file, 60–62 credentials, 108, 108 configuration sets, 41, 55 Critical events, 370 Connect to a Network ProjectorEnables CRT monitors, 69 exception, 135 CryptoAPI, 146 Connect to a Network task, 254 Current option, 207 connections Current Activity option, 208 networked printers, 259–260 Custom Classes policy, 68 troubleshooting, 324–325 Custom Installation page, 356 verifying, 303–305 custom option in clean installations, 18 VPNs, 272–277, 274–277 custom scripts, 50 Contacts folder, 73–74 custom views, , 166–167, Continue to This Website (Not 166, 370 Recommended) option, 131 Custom Views folder, 166 , 369 customization CONVERT utility, 369 business environment, 3 converting binary numbers, 258–260 deployment, 50–54, 53 Cookies folder, 74 images, 54–63, 56–57, 61–63 Copy Details option, 117 correlated event views, 243–244, 243 counters, Performance Monitor D defined, 369 data collector sets, 212 overview, 202–203, 203–204 creating, 212–214, 213 selecting, 205–206, 205 defined, 370 CPUs (central processing units) reports, 214, 215 defined, 368 system data collector sets, 214 Reliability and Performance monitor, data compression, 370 196–198, 197 data encryption, 370 Create a Folder for Each User Under the data migration, 24–25, 57–63, 57, Redirection Path option, 76 61–63 Create a Password Reset Disk option, Data tab, 207, 208 145 Database option, 208 Create Basic Task Wizard, 181, 182 Date and Time dialog box, 107, 107 Create Custom View dialog box, date information 166–167, 166 answer files, 46 Create New Certificate option, 100 clean installations, 22, 22 Create New Data Collector Set Wizard, user accounts, 107, 107 212–214, 213 DCName object, 242 Create Task option, 181 Debug logs, 165 Credential Manager, 145 default folders, 73 credential roaming, 145 65355.book Page 408 Sunday, August 12, 2007 4:51 PM

408 default gateways – dial-up networking

default gateways organization, 10–11 defined, 370 review questions, 31–38 IPv4, 259–261 summary, 29–30 IPv6, 262 tools, 3–6, 4–6 pinging, 305 review questions, 81–86 Default option in Performance Monitor, roaming user profiles and folder 206 redirection, 72–78, 76 definition updates for Windows summary, 78–79 Defender, 141 verifying system integrity, 63–64, 64 defragmentation, 371 Deployment Workbench tool, 4, 6, 6, Delay Task for trigger option, 177 370 Delay Task for Up to (Random Delay) descriptions trigger option, 177 counters, 206 /delete switch in ImageX, 27–28 events, 162 deleting temporary Designated File Types Properties dialog files, 150–151 box, 350, 350 deployment, 12 desktop applications. See applications answer files, 41–50, 42–46 Desktop folder, 73–74, 370 applications Destination Host Unreachable reply, 304 compatibility, 70–72, 71–72 Destination Net Unreachable reply, 304 Group Policy for, 340–344, Details tab, 241, 242 341–344 Detect Application Installations and custom images, 54–63, 56–57, 61–63 Prompt for Elevation setting, 110 customized installations, 50–54, 53 device drivers, 370 data and settings migration, 57–63, , 67, 370 57, 61–63 devices device and driver installation, accessing, 230 64–70, 69 installing and configuring, 64–70, 69 exam essentials, 79–80 DHCP (Dynamic Host Configuration overview, 40–41 Protocol) preparation configuring, 269–270 application support, 8–9 defined, 372 clean installations, 14–24, 14–24 NAP for, 320 data and settings migration, troubleshooting, 311–313 24–25 DHCP Enforcement client, 320 editions, 12 DHCP servers, 266, 370 exam essentials, 30 Diagnose and Repair task, 254 hardware requirements, 6–8 Diagnostics and Repair option, 325 imaging in, 25–29 diagrams, network, 10, 10, 319, 319 in-place upgrades, 12–14 dial-up modems, 370 networks, 9–10, 10 dial-up networking, 370 65355.book Page 409 Sunday, August 12, 2007 4:51 PM

Dialing Options section – Dynamic Host Configuration Protocol (DHCP) 409

Dialing Options section, 274 Do Not Display User Policy Settings in /dir switch in ImageX, 27 the Results option, 238 DirectX 9-capable video adapter Documents folder, 73–74, 371 requirements, 7 section, 60 DirectX 10 3D technologies, 69 Domain component, 49 Disable BitLocker Drive Encryption Domain Group Policy, 76, 76, 341 option, 144 Domain Name System (DNS) DisableChangePassword option, 235 client side configuration, 268–269, Disallowed security level, 351 269 Disconnect option, 283–284 defined, 371 discovery, network servers, 371 configuring, 328–329, 329 troubleshooting, 307–311 exceptions, 135 domain names, 371 Network and Sharing Center, 252 domain networks, 254 disk defragmentation, 371 domain profiles, 324 Disk Defragmenter utility, 371 domain user accounts, 371 Disk folder, 47 DomainAccounts folder, 48–49 disk imaging, 371 domains, 371 Disk Management utility, 371 Don’t Allow Connections to This disk partitioning, 371 Computer option, 279 DiskConfiguration folder, 47 Download Unsigned ActiveX Controls DiskID component, 47–48 option, 97 disks Download Updates but Let Me Choose Reliability and Performance monitor, Whether to Install Them option, 115 198–199, 198 Downloads folder, 73–74 requirements, 7 drive letters, 371 Display All Running Tasks option, 183 DriverPaths option, 65 display device configuration, 68–70, 69 drivers and driver files, 371 Display Progress While Connecting injecting, 26 option, 274 installing and configuring, 64–70, 69 Display Settings window, 69–70, 69 support requirements, 7–8 disruptive shutdown events, 211, 371 drives in clean installations, 19 Distribution Share pane, 41 Duration option, 207 DNS (Domain Name System) DVD installation deployment, 55 client side configuration, 268–269, dynamic disks, 371–372 269 Dynamic Host Configuration Protocol defined, 371 (DHCP) servers, 371 configuring, 269–270 troubleshooting, 307–311 defined, 372 Do Not Display Policy Settings for the NAP for, 320 Selected Computer option, 237 troubleshooting, 311–313 65355.book Page 410 Sunday, August 12, 2007 4:51 PM

410 e- – /export switch in ImageX

error 800f020b, 150 E error 80246007, 150 e-mail Error events, 372 actions, 174 ErrorCode object, 242 Task Scheduler, 185 ErrorDescription object, 242 EAP (Extensible Authentication errors, certificate, 132–133, 132–133 Protocol), 373 Ethernet, 372 Easy Transfer Cable, 25 Event Delivery Optimization settings, Easy Transfer Wizard, 13, 24–25, 372 170–171, 372 Edit Query Manually option, 243 event forwarding, 167–168, 168, 372 Edit Trigger dialog box, 176, 176 event logs editions defined, 372 business environment, 12 Group Policy troubleshooting, clean installations, 17 240–244, 242–243 effective rights, 372 event subscriptions, 372 EFS (Encrypted ) Event Viewer, 160–161, 161 defined, 372 custom views, 166–167, 166 setting up, 97–101, 99 defined, 373 troubleshooting, 142–144 event forwarding, 167–169, 168 802.11 standard, 366 events, 161–162, 163 Elevate Without Prompting option, 112 exam essentials, 186 Enable BitLocker Drive Encryption logs, 164–165, 165 option, 144 review questions, 187–194 Enable LCP Extensions option, 275 summary, 185 Enable Logging option, 165 EventIDs Enable Software Compression events, 162 option, 275 Group Policy, 240–241 Enable Transparency option, 70 events Enabled trigger option, 178 auditing, 103–105 Encrypt Contents to Secure Data defined, 372 option, 98, 144 Event Viewer. See Event Viewer Encrypted File System (EFS) exceptions, Windows Firewall defined, 372 adding, 138–139, 139 setting up, 97–101, 99 file and printer sharing, 134–135, troubleshooting, 142–144 134 encryption managing, 290, 291, 322 defined, 372 exclusion files, 52 WEP, 286–287 Expire trigger option, 178 error 80070003, 149–151 Export screen, 100 error 80072efd, 149 /export switch in ImageX, 27 65355.book Page 411 Sunday, August 12, 2007 4:51 PM

exporting tasks – General settings 411

exporting tasks, 182 Floppy Drives policy, 68 Extend component, 47 fluff, 8 extended partitions, 373 , 72–77, 76 Extended Validation certificates, 132 Group Policy for, 229 Extensible Authentication Protocol troubleshooting, 77–78 (EAP), 373 folders, 9 access, 326–327, 326 default, 73 F tasks, 181 Follow Documents setting, 75 Failure Audit events, 373 Force Audit Policy Subcategory Settings FAT (), 373 policy, 104, 144 FAT16 file system, 373 Format component, 47 FAT32 file system, 373 Forwarded events log, 164, 169, 374 fault tolerance, 373 forwarding events, 167–169, 168 Favorites folder, 73–74 FQDNs (fully qualified domain names), File Allocation Table (FAT), 373 304, 374 File and Printer Sharing exception, 135 fragmentation, 374 File and Printer Sharing for Microsoft Frame Relay technology, 374 Networks service, 264 frequencies in wireless networking, 285 file-level security, 97–101, 99 Frequently Asked Questions link, 115 File Sharing setting, 253 Friendly View, 241 file systems, 373 FTP (File Transfer Protocol), 373 File Transfer Protocol (FTP), 373 FullName component, 48 FileRepository folder, 67 fully qualified domain names (FQDNs), files 304, 374 access, 326–327, 326 answer, 41–50, 42–46 security, 97–101, 99 filtering, Pop-up Blocker, 89 G firewalls, 133–134 gateways application issues, 136–138 IPv4, 259–261 configuring, 138–139, 139, IPv6, 262 289–290, 289–290 pinging, 305 defined, 373 General settings resource access issues, 134–135 IP, 266 troubleshooting, 320–325, 323–324 Performance Monitor, 206–207 First Connect option, 273 Task Scheduler, 174–175, 175 Fit to Screen option, 283 VPNs, 273, 274 flat-panel monitors, 69 Windows Firewall, 289–290, 290 Flip 3D, 70 65355.book Page 412 Sunday, August 12, 2007 4:51 PM

412 GPMC (Group Policy Management Console) – History folder

GPMC (Group Policy Management Group Policy Object Editor, 341, 341, Console), 230, 236–240, 237–239, 343–344, 344 374 Group Policy Object Wizard, 226, 227 GPOs. See Group Policy and Group Group Policy Objects. See Group Policy Policy Objects and Group Policy Objects gpresult.exe tool, 230–235 Group Policy Result Tool, 374 GPUpdate.exe tool, 236 Group Policy Results Wizard, 237–240 Grant the User Exclusive Rights to groups, 374 Documents option, 76 Guest accounts, 374 Graph tab, 208 GUI (), 374 Graphical User Interface (GUI), 374 gupdate utility, 100, 129, 346, 354 Group component, 49 Group Policy and Group Policy Objects, 224 H Active Directory for, 225, 226 hard disk drives capabilities, 226–229, 227 defined, 375 defined, 374 Reliability and Performance monitor, for deploying applications, 340–344, 198–199, 198 341–344 requirements, 7 for drivers, 68 hard faults per second, 200 EFS, 101 hardware, 2, 6–8 for folder redirection, 75 Hardware Compatibility List (HCL), 7 new features, 229–230 Hardware failures category, 210 overview, 224–225 hash rules, 352–353, 375 Phishing Filter, 90, 93 HCL (Hardware Compatibility List), 7 templates for, 127–129 help, Windows Remote Assistance, troubleshooting 281–284, 282–283 event logs, 240–244, 242–243 Helpers group, 316 exam essentials, 244 hibernation, 375 GPMC, 236–240, 237–239 Hide Modes That This Monitor Cannot gpresult.exe tool, 230–235 Display option, 70 GPUpdate.exe, 236 Hide Update option, 117 review questions, 245–250 HideEULAPage component, 49 summary, 244 High Performance power plan, 375 for upgrading applications, 345 High Pop-up Blocker option, 89 Windows Firewall, 322–323 histograms in Performance Monitor, Group Policy Management Console 203, 204 (GPMC), 230, 236–240, history, tasks, 181 237–239, 374 History folder, 74 65355.book Page 413 Sunday, August 12, 2007 4:51 PM

HKEY_CURRENT_USER key – interactive users 413

HKEY_CURRENT_USER key, switches, 27–28 129–130 for WIM images, 28–29 HKEY_LOCAL_MACHINE key, imaging in deployment, 25–29 129–130 IMAP and IMAP4 (Internet Message home folder, 375 Access Protocol), 376 HTTPS (Secure Hypertext Transfer importing tasks, 182 Protocol), 95, 133 in-place upgrades, 12–14 hyperlinks, 375 inbound rules, 375 Hypertext Markup Language (HTML), Include Windows Logon Domain 375 option, 274 Hypertext Transfer Protocol (HTTP), /info switch in ImageX, 27 375 Informational events, 375 infrastructure, business environment, 2–3 I infrastructure networks, 284 Initialize and Script ActiveX Controls ICMP (Internet Control Message Not Marked as Safe for Scripting Protocol), 303–305, 321, 376 option, 97 ICMPv4, 321–322 injecting driver files, 26 ICS (Internet Connection Sharing), 276 InputLocale component, 45 idle task conditions, 179 Insert New DomainAccount option, 49 Idle Threshold setting, 274 Insert New DomainAccountList Idle Time Before Hanging Up setting, 274 option, 49 IE. See (IE) Insert New ModifyPartition option, 47 ieinstall.exe process, 130 Insert New PathAndCredentials IEM (Internet Explorer Maintenance) option, 65 extension, 128 InsertDriverUnattend.xml file, 65–66 ieuser.exe process, 130 Install Important Updates Only If Task Fails, Restart Every task option, 21 condition, 180 Install Updates Automatically If the Running Task Does Not End option, 114 When Requested, Force It to Stop install.wim file, 28, 43, 65 condition, 180 installation. See deployment If the Task Is Already Running, then InstallTo folder, 48 the Following Rule Applies Integrated Services Digital Network condition, 180 (ISDN), 375–376 If the Task Is Not Scheduled to Be Integrity Mechanism, 94 Run Again, Delete It After Interactive group, 376 condition, 180 interactive logons, 376 ImageX tool, 4, 52, 54, 56, 65 interactive users, 376 defined, 375 65355.book Page 414 Sunday, August 12, 2007 4:51 PM

414 Internal Options dialog box – kilobytes

Internal Options dialog box, 132–133 Internet service providers (ISPs), 376 international organizations, 11 Internet Settings GPO templates, 127 Internet Connection Sharing (ICS), 276 internetworks, 376 Internet Control Message Protocol invitation files, 316, 376 (ICMP), 303–305, 321, 376 Invite Someone You Trust to Help You Internet Control Panel GPO templates, option, 282 127 IP. See Internet Protocol (IP) Internet Explorer (IE) IP Security (IPSec) defined, 376 configuring, 288 Group Policy for, 229 defined, 376 security, 88 IP Settings tab, IP, 266 ActiveX Opt-In and ActiveX ipconfig.exe tool, 303, 311–313, 376 Installer Service, 94–95, 95 IPv4 Phishing Filter, 90–93, 91–93 autoconfiguration, 270–271, 271 Pop-up Blocker, 88–89, 89 default gateways, 259–261 Protected Mode, 93–94 IP addresses, 256–257 SSL verification, 95–97, 96 reserved addresses, 261 troubleshooting, 126–133, 131–133 subnets, 258–259 Internet Explorer Maintenance (IEM) IPv6, 256–257, 261 extension, 128 autoconfiguration, 271 Internet Message Access Protocol IP addresses, 262 (IMAP and IMAP4), 376 reserved addresses, 262 Internet Options dialog box subnets and default gateways, 262 ActiveX Opt-In, 95 ISDN (Integrated Services Digital Phishing Filter, 90, 92, 92 Network), 375–376 Protected Mode, 130 IsDomainJoined object, 242 SSL, 96, 96 ISPs (Internet service providers), 376 Internet Protocol (IP) autoconfiguration, 270–271, 271 defined, 376 J DHCP, 269–270 junction points, 77 DNS client side configuration, 268–269, 269 IPv4. See IPv4 IPv6. See IPv6 K manual configuration, 263–264, kernel, 377 263–264 Key component, 48 properties, 264–268, 264–265, 267 Key Index setting, 286 Internet Protocol Security (IPSec) keywords, event, 162 configuring, 288 kilobytes, 377 defined, 376 65355.book Page 415 Sunday, August 12, 2007 4:51 PM

L2TP (Layer 2 Tunneling Protocol) – Mail Exchanger (MX) records 415

local groups, 377 L local policies, 377 L2TP (Layer 2 Tunneling Protocol), local security, 378 276, 377 Local Security Policy application, 109, Label component, 47 110, 347, 348 LAN Diagnostics system data collector local user accounts, 378 set, 214 local user profiles, 378 languages Local Users and Groups, 378 answer files, 46 LocalAccounts component, 49 business environment, 11 LocalLow folder, 76 LANs (local area networks), 377 log names, event, 162 Layer 2 Tunneling Protocol (L2TP), Log Properties dialog box, 165, 165 276, 377 Logged component in events, 162 LCD monitors, 69 logical drives, 378 Learn About logical network diagrams, 10 link, 115 logo standards, 7 Legend option, 206 logoff process, 378 Letter component, 48 logon process, 378 levels logons, clean installations, 23, 23 event, 162 logs security, 351 events, 164–165, 165 LGPOs (Local Group Policy Objects), Group Policy troubleshooting, 230, 347, 377 240–244, 242–243 licenses, 16–18 Package Manager, 66 line graphs in Performance Monitor, Performance Monitor, 208 202–203, 203 service and application, 164–165, Link Layer Topology Discovery 165 (LLTD), 329, 377 Windows, 164 Links folder, 73, 75 wireless networking, 318 loadstate.exe, 59–60 loopback addresses LoadState.log file, 63 IPv4, 261 local area networks (LANs), 377 IPv6, 262 local audit settings, 103–104 pinging, 305 Local Computer Policy tool, 226–228, Low Pop-up Blocker option, 89 227, 230, 377 local file access, 322 Local folder, 74–76 M local group policies, 377 Mail Exchanger (MX) records, Local Group Policy Objects (LGPOs), 309–310, 378 230, 347, 377 65355.book Page 416 Sunday, August 12, 2007 4:51 PM

416 Manage Network Connections task – NAP (Network Access Protection)

Manage Network Connections task, migsys.xml file, 61 254, 263 miguser.xml file, 58, 61 Manage Wireless Networks applet, Minimize Bandwidth delivery option, 285–286, 286 170–171 Manage Your Encryption Certificates Minimize Latency delivery option, option, 100 170–171 mandatory profiles, 78, 378 Minimum option, 207 mapped drives, 378 Miscellaneous Failures category, 211 Mark This Key as Exportable mission critical applications, 8 option, 143 MMC (Microsoft Management Master Boot Record (MBR), 378 Console), 105, 379 master custom installations, 51–54, 53 modems, 379 Maximum Frequency counter, 196 Modify Setup Properties page, 356 Maximum option, 207 ModifyPartitions component, 47 MBR (Master Boot Record), 378 monitors, display, 69–70 Media Center Extender (MCE) Most Recent Check for Updates device, 379 setting, 113 Media Sharing setting, 253 /mount switch in ImageX, 28 Medium Pop-up Blocker option, 89 /mountrw switch in ImageX, 28 megabytes, 379 Move Contents of Documents to the megahertz, 379 New Location option, 76 memory MPPE (Microsoft Point-to-Point defined, 379 Encryption), 379 Reliability and Performance monitor, MS-CHAPv2 (Microsoft Challenge 200–201, 200 Handshake Authentication requirements, 7 Protocol Version 2), 379 messages, actions for, 174 .msi files, 355 Messages pane, 41 .mst files, 356 Microsoft Challenge Handshake multibooting process, 379 Authentication Protocol Version 2 Multilingual User Interface (MUI), 11 (MS-CHAPv2), 379 multiple configurations, 11 Microsoft Management Console Music folder, 73–74 (MMC), 105, 379 MX (Mail Exchanger) records, Microsoft Point-to-Point Encryption 309–310, 378 (MPPE), 379 Microsoft Systems Management Server (SMS) program, 346–347 N Microsoft Update, 379 Name component, 49 migapp.xml file, 61 name server lookup, 308–311 migration, data and settings, 24–25, NAP (Network Access Protection), 57–63, 57, 61–63 318–320, 380 65355.book Page 417 Sunday, August 12, 2007 4:51 PM

NAP Agent Service – NoSendingFiles option 417

NAP Agent Service, 320 network profiles, 324, 380 NBTSTAT utility, 380 network protocols, 256, 302–307 Negotiate Multi-Link for Single-Link Network Setup wizard, 272 Connections option, 275 Network Shortcuts folder, 74 NET USE command, 54 network task conditions, 180 NetBIOS (Network Basic Input/Output network zone rules, 352, 381 System), 380 Networking tab, 276, 277 NETLOGON utility, 104 networks .exe command, 138, 323, 324 business environment, 2, 9–10, 10 netstat.exe application, 137–138, 380 clean installations, 22 Network Access Protection (NAP), exam essentials, 292 318–320, 380 IP. See Internet Protocol (IP) network adapters, 380 in migration, 25 Network and Sharing Center, 252–256, Reliability and Performance monitor, 253, 255, 380 199–200, 199 Network Basic Input/Output System remote access. See remote access (NetBIOS), 380 review questions, 293–299 Network Configuration Operators security, 288–290, 289–291 group, 380 summary, 291 Network Connections dialog box, 263, troubleshooting. See troubleshooting 263 VPN settings, 276, 277, 314 Network Diagnostics Framework, 325 wireless networking. See wireless network diagrams, 10, 10, 319, 319 networking network discovery Never Check for Updates option, 115 configuring, 328–329, 329 New Answer File option, 65 defined, 380 New Hash Rule option, 353 exceptions, 135 New Path Rule option, 353 Network and Sharing Center, 252 New Software Restriction Policies Network group, 380 option, 347 network interface cards (NICs), 256, 284 New Technology File System (NTFS), Network Level Authentication (NLA), 380 279–280, 315 NICs (network interface cards), 256, 284 Network Location Awareness (NLA), NLA (Network Level Authentication), 324 279–280, 315 Network Places folder, 380 NLA (Network Location Awareness), Network Policy Servers, 319, 319 324 network portion in IP addresses, 259 NoDispScrSavPage option, 235 network printers Normal delivery option, 170 connecting to, 259–260 normal mode in IEM, 128 defined, 380 NoSendingFiles option, 235 65355.book Page 418 Sunday, August 12, 2007 4:51 PM

418 Not Configured option – passwords

Not Configured option, 75 organization, business environment, 3, nslookup.exe tool, 308–311, 381 10–11 NTFS (New Technology File System), Organization component, 48 380 organizational units (OUs), 225, 381 NTFS permissions, 381 Oscdimg tool, 53 NTLM protocol, 327, 381 OTS (over-the-shoulder) credentials, NTLM2 protocol, 327, 381 108, 381 ntuser.dat file, 78 OUs (organizational units), 225, 381 ntuser.man file, 78 outbound rule, 381 outlook.exe application, 136–138 over-the-shoulder (OTS) credentials, O 108, 381 Override Audit Policy Category Settings Obtain an IP Address Automatically option, 144 option, 266, 268 owners, 381 octets, 257–258 Offer Remote Assistance Helpers group, 316 On a Schedule trigger, 176 P On an Event trigger, 177 Package Manager, 64–65 On Connection to User Session packages trigger, 177 application, 340–344, 341–344 On Disconnect from User Session for drivers, 65–66 trigger, 177 pagefile memory, 381 On Idle trigger, 176 PAP (Password Authentication On Workstation Lock trigger, 177 Protocol), 382 On Workstation Unlock trigger, 177 PartitionID component, 48 Only Elevate Executables That Are partitions Signed and Validated option, 111 BitLocker, 102 Only Elevate UIAccess Applications defined, 382 That Are Installed in Secure Password Authentication Protocol Locations option, 111 (PAP), 382 OOBE component, 49 password policies, 382 oobe.xml file, 41 passwords OpCodes for events, 162 authentication, 145 Operational logs BitLocker, 102, 143 description, 165 certificates, 100 Group Policy, 240–242, 242 clean installations, 20 optimization, 381 smart cards, 146 Options tab for VPNs, 274, 274 Task Scheduler, 175 Order component, 47–48 65355.book Page 419 Sunday, August 12, 2007 4:51 PM

patches – print devices 419

patches, 112 Plug and Play technology, 383 managing, 347 PnP Manager, 66 manual, 115–117, 116 Point-to-Point Protocol (PPP), 383 path rules Point-to-Point Tunneling Protocol defined, 382 (PPTP), 276, 383 software restrictions, 351 policies Pause option, 284 audit, 103–105 PC Cards, 382 defined, 383 PCI (Peripheral Component troubleshooting, 127–129 Interconnect), 382 UAC, 148 PCMCIA (Personal Computer Memory Windows Firewall, 322–323 Card International Association) wireless networking, 288 cards, 382 Pop-up Blocker, 88–89, 89, 383 Performance Information and Tools Pop-up Blocker Settings dialog box, application, 382 88–89, 89 Performance Monitor, 200–201 POP3 (Post Office Protocol 3), 383 configuring, 206–208, 207 population of proxy server, 128 counters ports in Windows Firewall, 135 overview, 202–203, 203–204 Post Office Protocol 3 (POP3), 383 selecting, 205–206, 205 postinstallation defined, 382 devices and drivers installation, Peripheral Component Interconnect 64–70, 69 (PCI), 382 verifying system integrity, 63–64, 64 permissions, 382 power management, 229–230 Persistence Behavior GPO templates, Power-On Self-Test (POST), 383 127 power plans, 383 Personal Computer Memory Card Power Saver power plan, 383 International Association power task conditions, 179 (PCMCIA) cards, 382 Power Users group, 383 phishing, 382 PPP (Point-to-Point Protocol), 383 Phishing Filter, 90–93, 91–93, 382 PPP Settings section, VPNs, 275 Pictures folder, 73, 75 PPTP (Point-to-Point Tunneling pictures in clean installations, 20 Protocol), 276, 383 pilot programs, 3 Preboot Execution Environment (PXE), ping command 6, 383 defined, 383 preference mode in IEM, 128 with Windows Firewall, 321 previous versions, 383 working with, 303–305 primary partitions, 384 Place All Certificates in the Following PrincipalSamName object, 242 Store option, 143 print devices, 384 65355.book Page 420 Sunday, August 12, 2007 4:51 PM

420 Printer Sharing setting – RDC (Remote Desktop Connection) client

Printer Sharing setting, 253 Prompt for Name and Password, Printer Shortcuts folder, 74 Certificate, Etc. option, 274 printers prompts in UAC, 111–112 access, 327–328, 328 Properties pane, 41, 47 connections, 259–260 Protected Mode defined, 384 defined, 384 Group Policy for, 229 Internet Explorer 7, 93–94 sharing troubleshooting, 129–130, 131 access in, 322 ProtectYourPC component, 49 with Network and Sharing Center, protocols, 256 255–256 defined, 384 priorities, 384 troubleshooting, 302–307 privacy statement in clean proxy server population, 128 installations, 16 public connections, 324–325 private address spaces Public Folder Sharing setting, 253 IPv4, 261 Public Key Policies folder, 100 IPv6, 262 public keys, 146 private connections, 324–325 public networks, 254 private networks, 254 published applications, 342 privilege escalation, 384 defined, 384 Problem Reports and Solutions installing, 345 application, 384 PXE (Preboot Execution Environment), processes, 384 6, 383 processor affinity, 384 processors defined, 384 Q Reliability and Performance monitor, quarantined items 196–198, 197 defined, 384 requirements, 7 Windows Defender, 141 Profile folder, 74 Query Filter dialog box, 169, 169, 172 profiles network, 324 roaming, 72–78, 76 Program Compatibility Assistant, 9 R Program Compatibility Wizard, 71, 71 RADIUS (Remote Authentication program startup actions, 174 Dial-In User Service) servers, 287 Programs and Features applet, 342, RAM (random access memory) 342, 345 defined, 385 Prompt for Consent option, 111 requirements, 7 Prompt for Credentials option, 112 RDC (Remote Desktop Connection) client, 280–281, 280–281 65355.book Page 421 Sunday, August 12, 2007 4:51 PM

ReadyBoost program – Remote Installation Services (RIS) 421

ReadyBoost program, 68 exam essentials, 216 ReadyDrive technology, 385 Memory section, 200–201, 200 Really Simple Syndication (RSS), 385 Network section, 199–200, 199 Recent folder, 74 Performance Monitor. See recovery keys on smart cards, 98, 100 Performance Monitor recovery mode in BitLocker, 143 Reliability Monitor, 208–212 recovery passwords in BitLocker, 102 review questions, 217–222 Redial Attempts setting, 274 summary, 215–216 Redial If Line Is Dropped option, 275 for troubleshooting, 211–212 Redialing Options section, 274–275 Reliability Index, 209 Redirect to the Following Location Reliability Monitor, 208–212, 209 option, 76 remote access Redirect to the Local User Profile configuring, 271–272 Location option, 76 defined, 385 Redirect to the User’s Home Directory RDC client, 280–281, 280–281 option, 76 Remote Desktop, 278–281, 278–281 Redirected option, 75 troubleshooting, 314–316, 315–316 redirection, folder, 72–77, 76 VPN, 272–277, 274–277 Group Policy for, 229 Windows Remote Assistance, troubleshooting, 77–78 281–284, 282–283 /ref switch in ImageX, 28 Remote Assistance reference computers, 385 defined, 385 refresh rate, 70 troubleshooting, 316 REGEDIT program, 385 working with, 281–284, 282–283 regional settings Remote Authentication Dial-In User answer files, 46 Service (RADIUS) servers, 287 clean installations, 15 Remote Desktop, 278 registry defined, 385 defined, 385 enabling, 278–279, 278–279 for GPOs, 228 NLA, 279–280 Protected Mode, 129–130 RDC, 280–281, 280–281 for users, 75 troubleshooting, 315, 316 Registry Editor, 385 Remote Desktop Connection (RDC) /release option in ipconfig.exe, 313 client, 280–281, 280–281 Reliability and Performance monitor, 196 Remote Desktop exception, 135 CPU section, 196–198, 197 Remote Desktop Users group, 385 data collector sets, 212–214, remote hosts, pinging, 305 213, 215 remote installation, 386 defined, 385 Remote Installation Services (RIS), Disk section, 198–199, 198 25, 386 65355.book Page 422 Sunday, August 12, 2007 4:51 PM

422 Remote Service Management exception – Run Task As Soon As Possible

Remote Service Management troubleshooting, 142–144 exception, 135 user accounts. See users and user Removable Disks policy, 68 accounts removable media for certificates, 100 Restart if the Idle State Resumes task Removable Storage Access policies, 68 condition, 179 Remove Software dialog box, 345, 345 Restore Hidden Updates link, 115 Render Print Jobs on the Client restore points, 386 Computers option, 327 restrictions, software, 347–350, /renew option in ipconfig.exe, 313 348, 350 Repair Your Computer option, 15 implementing, 355 Repeat Task Every trigger option, 177 rules, 351–354, 352 Replicator group, 386 security levels, 351 reports troubleshooting, 354, 354 collector sets, 214, 215 Resultant Set of Policy (RSoP), 231–235 Performance Monitor, 203, 204 defined, 386 Request Control option, 283 software restrictions, 354 Request Timed Out reply, 304 rights Require Data Encryption option, 275 administrative, 107–109, 108 Require Startup USB Key at Every standard users, 106–107, 107 Startup option, 103 RIS (Remote Installation Services), 386 reserved addresses Roaming folder, 74, 76–77 IPv4, 261 roaming profiles, 72–78, 76, 386 IPv6, 262 rollout, 3 Reset All Zones to Default Level route tracing, 305–307 option, 97 routers, 259, 386 resolutions, display, 69–70 RSoP (Resultant Set of Policy), Resource Overview screen 231–235 CPU section, 196–198, 197 defined, 386 Disk section, 198–199, 198 software restrictions, 354 Memory section, 200–201, 200 RSS (Really Simple Syndication), 385 Network section, 199–200, 199 rules, software restriction, 351–354, resources, 97 352 auditing, 103–105 Run Administrators in Admin Approval BitLocker, 101–103 Mode option, 148 defined, 386 Run All Administrators in Admin file-level security, 97–101, 99 Approval Mode option, 111 network, 134–135, 134, 325–329, Run as Administrator option, 72 326, 328–329 Run Task As Soon As Possible After a Security Configuration and Analysis Scheduled Start Is Missed task tool, 105–106 condition, 180 65355.book Page 423 Sunday, August 12, 2007 4:51 PM

Safe Mode – sessions in Remote Assistance 423

review questions, 119–124 S summary, 117–118 Safe Mode, 386 troubleshooting. See troubleshooting Safe Mode with Command Prompt, 386 updates, 112–117, 113–114, 116 Safe Mode with Networking, 386 wireless networking, 285–288, 287, Sample Every option, 207 317, 317 Save Filter to Custom View dialog Security Configuration and Analysis box, 167 tool, 105–106 Save Your Startup Key option, 103 Security Context settings, 175 Saved Games folder, 73, 75 security events, 103–105 /scannow switch in sfc, 64 Security Health Validator (SHV) scanstate command, 58–60 policy, 320 schedules security identifiers (SIDs), 387 deployment, 3 security levels, 351, 387 task. See Task Scheduler Security log, 164, 387 schtasks.exe command, 181–182 security option policies, 387 scripts Security settings custom, 50 ActiveX, 95, 95 Group Policy for, 229 VPN, 275–276, 276, 314, 315 /scroll switch in ImageX, 28 security zones, 96–97, 96 SCSI (Small Computer Systems Select a Zone to View or Change Interface), 388 Security Settings option, 97 search providers, 387 Select Computer dialog box, 169 Searches folder, 73, 75 Select Group Policy Object Wizard, secpol.msc file, 100 228, 343 Secure Hypertext Transfer Protocol Select Phishing Filter Mode option, 93 (HTTPS), 95, 133 Select Windows Image option, 43, 65 Secure Sockets Layer (SSL), 95–97, 96 Send File option, 284 security Send To folder, 74, 77 defined, 387 Server (Request Security) option, 288 exam essentials, 118 Server (Require Security) option, 288 Group Policy for, 228 Service group, 387 Internet Explorer. See Internet service logs, 164–165, 165, 318 Explorer (IE) service packs, 387 networks, 288–290, 289–291, service set identifiers (SSIDs), 285, 318–325, 319, 321, 323–324 317, 387 patches, 112–117, 113–114, 116, services 347 defined, 387 resource access. See access to event subscriptions, 167–168, 168 resources sessions in Remote Assistance, 316 65355.book Page 424 Sunday, August 12, 2007 4:51 PM

424 Set Up a Connection or Network task – standard user rights

Set Up a Connection or Network task, simple volumes, 388 254, 273 Size component, 47 setting migration, 24–25, 57–63, 57, SkipUserOOBE component, 49 61–63 sleep option, 388 Setup log, 164 Small Computer Systems Interface setupapi.app.log file, 67 (SCSI), 388 setupapi.dev.log file, 67 smart cards setupcomplete.cmd command, 50 defined, 388 setupsnk.exe file, 387 RADIUS for, 287 SetupUILanguage folder, 46 recovery keys on, 98, 100 sfc.exe () tool, 64, 64 troubleshooting, 146 share permissions, 387 SMS (Systems Management Server) shared folders, 387 program, 346–347, 389 Shared Folders utility, 387 SMTP (Simple Mail Transfer Protocol), shares, 387 185, 388 sharing snap-ins, 388 network configuration for, 328–329, software. See also applications 329 business environment, 3 printers, 255–256, 322 Group Policy for, 228 Sharing tab Reliability Monitor for, 210 printers, 328, 328 Software Restriction Policies Are Not VPNs, 276, 277 Defined in This Group Policy ShellUI.mst file, 356 Object option, 347 shortcuts, 387 software restrictions, 347–350, 348, 350 Show Description option, 206 implementing, 355 Show Me All the Shared Network rules, 351–354, 352 Folders on This Computer link, 328 security levels, 351 Shut Down System Immediately if troubleshooting, 354, 354 Unable to Log Security Audits Software Restrictions Polices folder, 350 policy, 104 Source tab in Performance Monitor, 208 SHV (Security Health Validator) sources, event, 162 policy, 320 spanned volumes, 388 side-by-side migration, 24 special groups, 388 SideShow applet, 70 /split switch in ImageX, 28 SIDs (security identifiers), 387 spyware, 140–142, 140–141 signal issues in wireless networking, 318 SSIDs (service set identifiers), 285, 317, SIM (System Image Manager) tool, 4, 5, 387 29, 41–50, 42–46 SSL (Secure Sockets Layer), 95–97, 96 Simple Mail Transfer Protocol (SMTP), Standard User account, 388 185, 388 standard user rights, 106–107, 107 65355.book Page 425 Sunday, August 12, 2007 4:51 PM

standby option – Task Scheduler 425

standby option, 388–389 System Diagnostics system data , 389 collector set, 214 Start Menu folder, 74 System Diagnostics template, 213 Start the Task Only if the Computer Is System File Checker (sfc.exe) tool, 64, 64 Idle For condition, 179 System group, 389 Start the Task Only if the Computer Is System Image Manager (SIM) tool, 4, 5, on AC Power condition, 179 29, 41–50, 42–46 Start Windows Normally option, 389 System Information utility, 389 Startup Repair Tool, 389 system integrity, 63–64, 64 status, Windows Firewall, 323, 323 System log, 164, 389 Stop if the Computer Ceases to Be Idle system partitions, 389 task condition, 179 System Performance system data Stop if the Computer Switches to collector set, 214 Battery Power task condition, 179 System Performance template, 213 Stop Sharing option, 284 System Preparation Tool (), 389 Stop Task if It Runs Longer Than trigger System Properties dialog box, 278–279, option, 177 279 Stop the Task if It Runs Longer Than utility, 390 task condition, 180 System Stability Chart, 209, 209 stripe sets, 389 System Tool, 390 striped volumes, 389 System Tools group, 390 subcategories, auditing, 144 SystemLocale component, 45 subnet masks Systems Management Server (SMS) defined, 389 program, 346–347, 389 IPv4, 258–259 subnets IPv4, 258–259 T IPv6, 262 Tablet PC Input Panel, 390 Subscription Properties dialog box, Tape Drives policy, 68 168, 168 Target folder location for redirection, 76 subscriptions, event, 167–172, 168 Task component event category, 162 Success Audit events, 389 , 390 super mandatory profiles, 389 Task Scheduler, 173, 174 Switch to the Secure Desktop When actions, 174 Prompting for Elevation conditions, 178–180, 178 option, 111 defined, 390 sysprep command, 50 exam essentials, 186 System applet, 278, 278 folders, 181 System Configuration utility, 389 General properties, 174–175, 175 system data collector sets, 214 history, 181 65355.book Page 426 Sunday, August 12, 2007 4:51 PM

426 – troubleshooting

importing and exporting tasks, 182 TPM (Trusted Platform Module), review questions, 187–194 101–103, 143, 391 running and administering tasks, tracert.exe tool, 305–307, 391 182–183, 183 Transmission Control Protocol (TCP), scheduling tasks, 181–182, 182 391 settings, 180 Transmission Control Protocol/Internet summary, 185 Protocol (TCP/IP), 391 triggers, 175–178, 176 Transport Layer Security (TLS), 95 troubleshooting, 184–185 triggers in Task Scheduler, 175–178, 176 Taskbar, 390 Trivial File Transfer Protocol (TFTP), 391 tasklist.exe application, 136–138 troubleshooting TCP (Transmission Control Protocol), applications 391 compatibility, 70–72, 71–72 TCP/IP (Transmission Control deployment, 346 Protocol/Internet Protocol), 391 problems, 136–138 TCP/IP autonetting addresses, 261 certificate issues, 130–133, 132–133 templates configuration, 138–139 data collector sets, 213 driver installation, 66–67 for Group Policy, 127–128 Group Policy Templates folder, 74 event logs, 240–244, 242–243 temporary files in Windows Update, exam essentials, 244 150–151 GPMC, 236–240, 237–239 Temporary Internet Files folder, 74 gpresult.exe tool, 230–235 terabytes (TBs), 390 GPUpdate.exe, 236 Terminal Server User group, 390 review questions, 245–250 test environments, 3 summary, 244 TFTP (Trivial File Transfer Protocol), networks, 302 391 DHCP, 311–313 Setting, 70 DNS, 307–311 threads, 390 exam essentials, 330–331 Time Between Redial Attempts setting, network protocols, 302–307 274 remote access, 314–316, 315–316 time information resource access, 134–135, 134, answer files, 46 325–329, 326, 328–329 clean installations, 22, 22 review questions, 332–338 timeouts in tracert.exe, 307 security, 318–325, 319, 321, TLS (Transport Layer Security), 95 323–324 Token Ring technology, 390–391 summary, 330 Toolbar option, 206 Windows Network Diagnostics Toolbars GPO templates, 127 tool, 325 wireless, 316–318, 317 65355.book Page 427 Sunday, August 12, 2007 4:51 PM

Trusted Platform Module (TPM) – User Profiles dialog box 427

policy-setting issues, 127–129 uninstalling applications, 345–346, 345 Protected Mode, 129–130, 131 Universal Flash Device (UFD), 392 Reliability and Performance monitor Universal Naming Convention (UNC), for, 211–212 392 roaming user profiles and folder Universal Serial Bus (USB), 392 redirection, 77–78 /unmount switch in ImageX, 28 security, 126 Unrestricted security level, 351 authentication, 145–146 updates exam essentials, 151–152 manual, 115–117, 116 Internet Explorer, 126–133, Windows Update, 112–115, 131–133 113–114 resource access, 142–144 Updates Were Installed setting, 113 review questions, 153–158 Upgrade Advisor, 13 summary, 151 upgrades , 146–148 defined, 392 Windows Defender, 140–142, Group Policy for, 345 140–141 in-place, 12–14 Windows Firewall, 133–139 URL Reputation Service, 90, 91 Windows Updates, 149–151 URLs (Uniform Resource Locators), 391 software restrictions, 354, 354 USB (Universal Serial Bus), 392 Task Scheduler, 184–185 USB flash drives Trusted Platform Module (TPM), for installation, 52 101–103, 143, 391 TPM, 102–103 Trusted Sites zone, 130 Use an Older Program with This Turn Off BitLocker option, 144 Version of Windows applet, 71 Turn Off Managing Phishing Filter Use My Internet Connection (VPN) option, 93 option, 273 Type component, 47 Use the Following IP Address option, 266, 268 User Account Control (UAC), 106 U Admin Approval mode, 109, 109 administrative rights, 107–109, 108 UAC. See User Account Control (UAC) configuring, 109–112, 110 UFD (Universal Flash Device), 392 defined, 392 UILanguage component, 46 standard users, 106–107, 107 Ultimate Extras setting, 113 troubleshooting, 146–148 unattend.xml file, 41, 391 user profiles unattended installation, 391 defined, 392 UNC (Universal Naming roaming, 72–78, 76 Convention), 392 User Profiles dialog box, 78 Uniform Resource Locators (URLs), 391 65355.book Page 428 Sunday, August 12, 2007 4:51 PM

428 user right policies – WAIK (Windows Automated Installation Kit)

user right policies, 392 SSL communication, 95–97, 96 User Selection screen system integrity, 63–64, 64 GPMC, 240 /verifyonly switch in sfc, 64 Group Policy Results Wizard, 238 video adapters user state data migration, 24, 57–63, defined, 392 57, 61–63 drivers, 69 User State Migration Tool (USMT), 4, requirements, 7 13, 25, 57–63, 61–63, 392 Videos folder, 73–74 UserAccounts component, 49 View Available Updates option, 115 UserData folder, 48 View Certificate option, 132 UserLocale component, 46 View Computers and Devices task, 254 usernames View Details option, 117 authentication, 145 View Update History link, 115 defined, 392 views smart cards, 146 correlated events, 243–244, 243 users and user accounts Event Viewer, 166–167, 166 business environment, 3, 11 virtual memory, 393 clean installations, 20 virtual private networks (VPNs) events, 162 connections, 272–277, 274–277 managing. See User Account defined, 393 Control (UAC) troubleshooting, 314, 315 Users groups, 392 virtualization issues, 147 USMT (User State Migration Tool), 4, Virtualize File and Registry Write 13, 25, 57–63, 61–63, 392 Failures to Per-User Locations USMT3 directory, 62 policy, 111, 147 USMT3.MIG file, 62 virus definition update failures, 173 vistacustom.wim file, 56 volumes, 393 V VPN hostname or IP address setting, 314 Validate Answer File option, 49, 65 VPNs (virtual private networks) Validation tab, 49 connections, 272–277, 274–277 Value bar option, 206 defined, 393 Value component, 49 troubleshooting, 314, 315 Verbose events, 392 Verify My Identity As Follows option, 275 /verify switch in ImageX, 28 W verifying WAIK (Windows Automated network connectivity, 303–305 Installation Kit), 6, 394 65355.book Page 429 Sunday, August 12, 2007 4:51 PM

Wait for Idle For task condition – Windows Image pane 429

Wait for Idle For task condition, 179 Windows Activation method, 394 Wake the Computer to Run This Task . See Aero interface condition, 179 , 394 wallpaper, 21 Windows Application Compatibility WANs (wide area networks), 393 Toolkit, 9 WAPs (Wireless Access Points), 284 Windows Automated Installation Kit Warn About Invalid Site Certificates (WAIK), 6, 394 option, 132 Windows , 394 Warning events, 393 Windows CardSpace, 394 WDDM (Windows Display Driver Windows Complete PC Backup, 394 Model) compatible drivers, 69 Windows Complete PC Restore, 394 WDS (Windows Deployment Services), Windows Components\RSS Feeds GPO 6, 51, 394 templates, 127 WDS Service, 393 , 394 WDSUTIL utility, 393 Windows Defender web browsers, 393 defined, 394 Welcome Center troubleshooting, 140–142, 140–141 clean installations, 24 Windows Deployment servers, 27 defined, 393 Windows Deployment Services (WDS), WEP (Wired Equivalent Privacy), 6, 51, 394 286–287, 287, 397 Windows Display Driver Model WFAS (Windows Firewall with (WDDM) compatible drivers, 69 Advanced Security), 395 Wizard, 57–59, Wi-Fi Protected Access (WPA), 57, 394 287, 393 Windows Experience Index, 394 wide area networks (WANs), 393 Windows Failures category, 211 wildcard characters , 394 Pop-up Blocker, 89 Windows Firewall, 133–134 software restrictions rules, 352 application issues, 136–138 WillShowUI component, 47–48 configuring, 138–139, 139, WillWipeDisk component, 47 289–290, 289–290 WIM () defined, 395 defined, 395 resource access, 134–135 device drivers, 65–66 troubleshooting, 320–325, 323–324 overview, 25–29 Windows Firewall Setting dialog box, wimscript.ini file, 52 289–290, 290 Win32 services, 394 Windows Firewall with Advanced Window Color and Appearance Security (WFAS), 395 setting, 70 Windows Image pane, 41, 44, 46, Windows 9x computers, 394 48–49 65355.book Page 430 Sunday, August 12, 2007 4:51 PM

430 Windows Imaging Format (WIM) – WSUS (Windows Server Update Services)

Windows Imaging Format (WIM) Enterprise edition, defined, 395 12, 396 device drivers, 65–66 Windows Vista Hardware Assessment overview, 25–29 tool, 4, 4, 8 Windows Internet Name Service Windows Vista Home Basic edition, (WINS), 395 12, 396 Windows logs, 164 Windows Vista Home Premium edition, Windows Mail, 395 12, 396 , 395 Windows Vista Premium Ready 11, 395 hardware, 6–7 , 395 Windows Vista Starter edition, 396 Windows Network Diagnostics tool, Windows Vista Ultimate edition, 325, 395 12, 396 Windows NT , 395 Windows Vista Upgrade Advisor, 396 Windows PE environment, 4, 6 Windows XP Professional, 396 for installation, 52 Windows XP upgrades, 13 for WIM, 26–27 section, 60 Windows Preinstallation Environment, windowsupdate.log file, 142 395 WINS (Windows Internet Name Windows Remote Assistance, 281–284, Service), 395 282–283 WINS servers, 397 Windows Remote Assistance wizard, wipe-and-load migration, 24 282, 282 Wired Equivalent Privacy (WEP), Windows Security Center, 395 286–287, 287, 397 Windows Server Update Services Wireless Access Points (WAPs), 284 (WSUS), 112, 142 Wireless Diagnostics system data Windows Sidebar, 395 collector set, 214 Windows SideShow, 396 wireless networking, 284–285 Windows Sync Center, 396 configuring, 286 Windows System Image policies, 288 Manager, 396 security, 285–288, 287, 317, 317 Windows Update troubleshooting, 316–318, 317 clean installations, 21 WEP, 286–287, 287 configuring, 112–115, 113–114 workgroups, 397 defined, 396 WPA (Wi-Fi Protected Access), patches, 347 287, 393 troubleshooting, 149–151 WPA-Enterprise troubleshooting, 317 Windows Vista, 396 WPD policy, 68 Windows Vista Business edition, 12, 396 WSUS (Windows Server Update Windows Vista Capable hardware, 6–7 Services), 112, 142 65355.book Page 431 Sunday, August 12, 2007 4:51 PM

XDDM (XP display driver model) display driver – zones 431

X Y XDDM (XP display driver model) You Have Windows Set To setting, 114 display driver, 67 You Receive Updates setting, 114 XML files answer files, 41–50, 42–46 tasks, 182 Z USMT, 25 zones, security, 96–97, 96 XML queries, 243 XP display driver model (XDDM) display driver, 67 65355.book Page 432 Sunday, August 12, 2007 4:51 PM 65355.book Page 433 Sunday, August 12, 2007 4:51 PM 65355.book Page 434 Sunday, August 12, 2007 4:51 PM