<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Marc Valk dot Net &#187; Security</title>
	<atom:link href="http://www.marcvalk.net/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.marcvalk.net</link>
	<description>blogging about...... Microsoft, Cloud Computing and all other things I find interesting</description>
	<lastBuildDate>Thu, 02 Sep 2010 08:55:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Integrated Windows Authentication in IE6 and IE7</title>
		<link>http://www.marcvalk.net/2009/12/integrated-windows-authentication-in-ie6-and-ie7/</link>
		<comments>http://www.marcvalk.net/2009/12/integrated-windows-authentication-in-ie6-and-ie7/#comments</comments>
		<pubDate>Wed, 23 Dec 2009 10:13:02 +0000</pubDate>
		<dc:creator>mvalk</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.marcvalk.net/2009/12/integrated-windows-authentication-in-ie6-and-ie7/</guid>
		<description><![CDATA[In IE you can set the checkbox “Enable Integrated Windows Authentication” (Internet Options, Advanced Tab, below the heading Security) Internet Explorer version 6 and 7 will use Integrated Windows Authentication whether you have the checkbox enabled or disabled. The big difference lies in the type of authentication which is kerberos or NTLM. If the option [...]]]></description>
			<content:encoded><![CDATA[<p>In IE you can set the checkbox “Enable Integrated Windows Authentication” (Internet Options, Advanced Tab, below the heading Security)   </p>
<p><a href="http://www.marcvalk.net/wp-content/uploads/2009/12/image17.png" rel="lightbox[419]"><img style="border-bottom: 0px; border-left: 0px; margin: 0px 5px 5px 0px; display: inline; border-top: 0px; border-right: 0px" title="note: IE8 screenshot" border="0" alt="note: IE8 screenshot" align="left" src="http://www.marcvalk.net/wp-content/uploads/2009/12/image_thumb17.png" width="186" height="232" /></a> </p>
<p>Internet Explorer version 6 and 7 will use Integrated Windows Authentication whether you have the checkbox enabled or disabled. The big difference lies in the type of authentication which is kerberos or NTLM. If the option is checked IE will first try Kerberos and then will fallback to NTLM, if the option is unchecked it will just use NTLM. So Microsoft labeled the option wrong, it should say Negotiate Windows Authentication or so. Checking or unchecking this option just sets the registry key “HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnableNegotiate” to 1 or 0.   </p>
]]></content:encoded>
			<wfw:commentRss>http://www.marcvalk.net/2009/12/integrated-windows-authentication-in-ie6-and-ie7/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Installing MS Forefront Security for Exchange Server</title>
		<link>http://www.marcvalk.net/2009/11/installing-ms-forefront-security-for-exchange-server/</link>
		<comments>http://www.marcvalk.net/2009/11/installing-ms-forefront-security-for-exchange-server/#comments</comments>
		<pubDate>Fri, 27 Nov 2009 13:16:54 +0000</pubDate>
		<dc:creator>mvalk</dc:creator>
				<category><![CDATA[Exchange]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.marcvalk.net/2009/11/installing-ms-forefront-security-for-exchange-server/</guid>
		<description><![CDATA[Microsoft Forefront Security for Exchange Server integrates multiple scan engines from industry-leading security firms into a comprehensive, layered solution, helping businesses protect their Microsoft Exchange Server messaging environments from viruses, worms, spam, and inappropriate content. start forefrontexchangesetup.exe Accept the License Agreement and click on [Next] You will be warned with the fact that “Microsoft Exchange [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.marcvalk.net/wp-content/uploads/2009/11/image3.png" rel="lightbox[371]"><img style="border-bottom: 0px; border-left: 0px; margin: 0px 10px 0px 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" align="left" src="http://www.marcvalk.net/wp-content/uploads/2009/11/image_thumb2.png" width="134" height="90" /></a> </p>
<ul>
<p>Microsoft Forefront Security for Exchange Server integrates multiple scan engines from industry-leading security firms into a comprehensive, layered solution, helping businesses protect their Microsoft Exchange Server messaging environments from viruses, worms, spam, and inappropriate content.</p>
</ul>
<ul>
<li>start forefrontexchangesetup.exe</li>
<li>Accept the License Agreement and click on [Next]
<p><a href="http://www.marcvalk.net/wp-content/uploads/2009/11/image4.png" rel="lightbox[371]"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.marcvalk.net/wp-content/uploads/2009/11/image_thumb3.png" width="394" height="320" /></a>       </li>
<li>You will be warned with the fact that “Microsoft Exchange Transport” will be restarted, so if this isn’t possible, abort the setup. Else just click [Next]
<p><a href="http://www.marcvalk.net/wp-content/uploads/2009/11/image5.png" rel="lightbox[371]"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.marcvalk.net/wp-content/uploads/2009/11/image_thumb4.png" width="394" height="320" /></a>       </li>
<li>The next screen prompts you for the installation locations. If you want to change this do so, then click [Next]
<p><a href="http://www.marcvalk.net/wp-content/uploads/2009/11/image6.png" rel="lightbox[371]"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.marcvalk.net/wp-content/uploads/2009/11/image_thumb5.png" width="394" height="320" /></a>       </li>
<li>If you use a <a title="Wikipedia: Proxy Server" href="http://nl.wikipedia.org/wiki/Proxyserver" target="_blank">Proxy Server</a> fill in the details, then click [Next]
<p><a href="http://www.marcvalk.net/wp-content/uploads/2009/11/image7.png" rel="lightbox[371]"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.marcvalk.net/wp-content/uploads/2009/11/image_thumb6.png" width="394" height="320" /></a>       </li>
<li>Enable the Antispam feature (if needed), then click [Next]
<p><a href="http://www.marcvalk.net/wp-content/uploads/2009/11/image8.png" rel="lightbox[371]"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.marcvalk.net/wp-content/uploads/2009/11/image_thumb7.png" width="394" height="320" /></a>       </li>
<li>The next screen is about joining the CEIP (Customer Experience Improvement Program), if you want to be part of it, check the checkbox. Click [Next]
<p><a href="http://www.marcvalk.net/wp-content/uploads/2009/11/image9.png" rel="lightbox[371]"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.marcvalk.net/wp-content/uploads/2009/11/image_thumb8.png" width="394" height="320" /></a>&#160; </li>
<li>Verify your information, and then click [Next] to begin installation
<p><a href="http://www.marcvalk.net/wp-content/uploads/2009/11/image10.png" rel="lightbox[371]"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.marcvalk.net/wp-content/uploads/2009/11/image_thumb9.png" width="394" height="320" /></a>       </li>
<li>After the installation, click [Finish]
<p><a href="http://www.marcvalk.net/wp-content/uploads/2009/11/image11.png" rel="lightbox[371]"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.marcvalk.net/wp-content/uploads/2009/11/image_thumb10.png" width="394" height="320" /></a>       </li>
<li>Your start menu should now contain the “Forefront Protection for Exchange Server Console”. Fire it up.
<p><a href="http://www.marcvalk.net/wp-content/uploads/2009/11/image12.png" rel="lightbox[371]"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.marcvalk.net/wp-content/uploads/2009/11/image_thumb11.png" width="276" height="65" /></a>       </li>
<li>Activate your license, or continue with the evaluation (only valid for 119 days).
<p><a href="http://www.marcvalk.net/wp-content/uploads/2009/11/image13.png" rel="lightbox[371]"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.marcvalk.net/wp-content/uploads/2009/11/image_thumb12.png" width="420" height="316" /></a>       </li>
<li>If you have a Activation Key, you will be prompted to supply your License Agreement Number. Click on the link provided in the dialog screen.
<p><a href="http://www.marcvalk.net/wp-content/uploads/2009/11/image14.png" rel="lightbox[371]"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.marcvalk.net/wp-content/uploads/2009/11/image_thumb13.png" width="420" height="309" /></a>&#160; </li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.marcvalk.net/2009/11/installing-ms-forefront-security-for-exchange-server/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Browsing a local hosted site with IE8</title>
		<link>http://www.marcvalk.net/2009/11/browsing-a-local-hosted-site-with-ie8/</link>
		<comments>http://www.marcvalk.net/2009/11/browsing-a-local-hosted-site-with-ie8/#comments</comments>
		<pubDate>Tue, 17 Nov 2009 13:49:32 +0000</pubDate>
		<dc:creator>mvalk</dc:creator>
				<category><![CDATA[IIS]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.marcvalk.net/2009/11/browsing-a-local-hosted-site-with-ie8/</guid>
		<description><![CDATA[Internet Explorer version 8 has got some annoying loopbackcheck. Whenever you want to browse a local hosted site (IIS), it will pop up a security dialog in which you have to fill in your username and password. Whatever combination you fill in, eventually you will get a 401.1. error. You can resolve it by editing [...]]]></description>
			<content:encoded><![CDATA[<p>Internet Explorer version 8 has got some annoying loopbackcheck. Whenever you want to browse a local hosted site (IIS), it will pop up a security dialog in which you have to fill in your username and password.   <br />Whatever combination you fill in, eventually you will get a 401.1. error.</p>
<p>You can resolve it by editing the the registry.</p>
<ul>
<ol>
<li>Click <strong>Start</strong>, click <strong>Run</strong>, type regedit, and then click <strong>OK</strong>. </li>
<li>In Registry Editor, locate and then click the following registry key:
<p><strong>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa</strong></p>
</li>
<li>Right-click <strong>Lsa</strong>, point to <strong>New</strong>, and then click <strong>DWORD Value</strong>. </li>
<li>Type DisableLoopbackCheck, and then press ENTER. </li>
<li>Right-click <strong>DisableLoopbackCheck</strong>, and then click <strong>Modify</strong>. </li>
<li>In the <strong>Value data</strong> box, type 1, and then click <strong>OK</strong>. </li>
<li>Quit Registry Editor, and then restart your computer.</li>
</ol>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.marcvalk.net/2009/11/browsing-a-local-hosted-site-with-ie8/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Machine SID Duplication Myth</title>
		<link>http://www.marcvalk.net/2009/11/the-machine-sid-duplication-myth/</link>
		<comments>http://www.marcvalk.net/2009/11/the-machine-sid-duplication-myth/#comments</comments>
		<pubDate>Tue, 17 Nov 2009 09:41:26 +0000</pubDate>
		<dc:creator>mvalk</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.marcvalk.net/2009/11/the-machine-sid-duplication-myth/</guid>
		<description><![CDATA[A great article by Mark Russinovich (the creator of the tool NewSID), about the Myth around duplicate Security Identifiers. The NewSID tool is frequently used by System Administrators to change a computer’s SID, for cloning purposes, after you read this article you get a better understanding about SID’s and why the tool has been retired [...]]]></description>
			<content:encoded><![CDATA[<p>A great article by <a href="http://blogs.technet.com/user/Profile.aspx?UserID=10023" target="_blank">Mark Russinovich</a> (the creator of the tool <a href="http://technet.microsoft.com/en-us/sysinternals/bb897418.aspx" target="_blank">NewSID</a>), about the Myth around duplicate Security Identifiers. The NewSID tool is frequently used by System Administrators to change a computer’s SID, for cloning purposes, after you read this article you get a better understanding about SID’s and why the tool has been retired</p>
<p><a title="http://blogs.technet.com/markrussinovich/archive/2009/11/03/3291024.aspx" href="http://blogs.technet.com/markrussinovich/archive/2009/11/03/3291024.aspx">http://blogs.technet.com/markrussinovich/archive/2009/11/03/3291024.aspx</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.marcvalk.net/2009/11/the-machine-sid-duplication-myth/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Forefront Client Security and windows 7</title>
		<link>http://www.marcvalk.net/2009/10/forefront-client-security-and-windows-7/</link>
		<comments>http://www.marcvalk.net/2009/10/forefront-client-security-and-windows-7/#comments</comments>
		<pubDate>Wed, 14 Oct 2009 06:45:30 +0000</pubDate>
		<dc:creator>mvalk</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows 7]]></category>
		<category><![CDATA[Forefront]]></category>

		<guid isPermaLink="false">http://www.marcvalk.net/2009/10/forefront-client-security-and-windows-7/</guid>
		<description><![CDATA[I just installed a new virtual machine with Windows 7 Enterprise. As I wanted to have some good protection from viruses and malware, I decided to go for Forefront Client Security. I copied the installation files for FCS to a local temp folder, and executed the command CLIENTSETUP.EXE /NOMOM (to install FCS with the MOM [...]]]></description>
			<content:encoded><![CDATA[<p>I just installed a new virtual machine with Windows 7 Enterprise. As I wanted to have some good protection from viruses and malware, I decided to go for Forefront Client Security.   </p>
<p>I copied the installation files for FCS to a local temp folder, and executed the command CLIENTSETUP.EXE /NOMOM (to install FCS with the MOM agent). Keep in mind that if you are using a x64 system, execute the clientsetup.exe inside the x64 folder    <br />This installation failed because of UAC.    <br />I changed my UAC settings to low by launching the “Change UAC Settings”, under the tool tab in MSConfig.</p>
<p><a href="http://www.marcvalk.net/wp-content/uploads/2009/10/image2.png" rel="lightbox[301]"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="Change UAC Settings" border="0" alt="Change UAC Settings" src="http://www.marcvalk.net/wp-content/uploads/2009/10/image_thumb2.png" width="340" height="256" /></a> </p>
<p>Again I tried to execute the CLIENTSETUP.EXE /NOMOM.   <br />This time FCS installed correctly.    <br />After installation I pressed the “Check for Updates Now” inside FCS, but it reported that there we’re now updates….strange, because the definition files are from September 14th 2006.</p>
<p><a href="http://www.marcvalk.net/wp-content/uploads/2009/10/image3.png" rel="lightbox[301]"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="FCS reporting &quot;No new definition files&quot;" border="0" alt="FCS reporting &quot;No new definition files&quot;" src="http://www.marcvalk.net/wp-content/uploads/2009/10/image_thumb3.png" width="260" height="84" /></a> </p>
<p>I then found this webpage: <a title="http://support.microsoft.com/kb/935934/" href="http://support.microsoft.com/kb/935934/">http://support.microsoft.com/kb/935934/</a> you can download the antimalware definition files manually and install them. This solved it for me.</p>
<p><a href="http://www.marcvalk.net/wp-content/uploads/2009/10/image5.png" rel="lightbox[301]"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="FCS Status" border="0" alt="FCS Status" src="http://www.marcvalk.net/wp-content/uploads/2009/10/image_thumb4.png" width="340" height="85" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.marcvalk.net/2009/10/forefront-client-security-and-windows-7/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>View Permissions for Reporting Services in SharePoint Integrated Mode</title>
		<link>http://www.marcvalk.net/2009/07/view-permissions-for-reporting-services-in-sharepoint-integrated-mode/</link>
		<comments>http://www.marcvalk.net/2009/07/view-permissions-for-reporting-services-in-sharepoint-integrated-mode/#comments</comments>
		<pubDate>Wed, 15 Jul 2009 06:25:00 +0000</pubDate>
		<dc:creator>mvalk</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[SharePoint]]></category>
		<category><![CDATA[SSRS]]></category>

		<guid isPermaLink="false">http://www.marcvalk.net/2009/07/view-permissions-for-reporting-services-in-sharepoint-integrated-mode/</guid>
		<description><![CDATA[Setting up security for SSRS in SharePoint integrated mode can be a bit tricky, particularly if you want to set up some of your users to only be able to run reports, but not to be able to modify or change them. I found a great post explaining how to create a Reporting group in [...]]]></description>
			<content:encoded><![CDATA[<p>Setting up security for SSRS in SharePoint integrated mode can be a bit tricky, particularly if you want to set up some of your users to only be able to run reports, but not to be able to modify or change them. I found a great post explaining how to create a Reporting group in SharePoint:</p>
<p><a href="http://agilebi.com/cs/blogs/jwelch/archive/2009/07/10/view-permissions-for-reporting-services-in-sharepoint-integrated-mode.aspx">http://agilebi.com/cs/blogs/jwelch/archive/2009/07/10/view-permissions-for-reporting-services-in-sharepoint-integrated-mode.aspx</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.marcvalk.net/2009/07/view-permissions-for-reporting-services-in-sharepoint-integrated-mode/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>EWA: Error Data Refresh Failed</title>
		<link>http://www.marcvalk.net/2009/06/ewa-error-data-refresh-failed/</link>
		<comments>http://www.marcvalk.net/2009/06/ewa-error-data-refresh-failed/#comments</comments>
		<pubDate>Tue, 30 Jun 2009 11:36:40 +0000</pubDate>
		<dc:creator>mvalk</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[SharePoint]]></category>
		<category><![CDATA[Kerberos]]></category>
		<category><![CDATA[SQL Server]]></category>
		<category><![CDATA[SSAS]]></category>

		<guid isPermaLink="false">http://www.marcvalk.net/2009/06/ewa-error-data-refresh-failed/</guid>
		<description><![CDATA[I’ve been struggling for quite a long time with Excel Web Access in combination with a SQL Analysis Server and SharePoint. The problem is that I am able to display an excel file (which is in a SharePoint web part), but whenever I choose to refresh the connection I get the following error: Unable to [...]]]></description>
			<content:encoded><![CDATA[<p>I’ve been struggling for quite a long time with Excel Web Access in combination with a SQL Analysis Server and SharePoint.    <br />The problem is that I am able to display an excel file (which is in a SharePoint web part), but whenever I choose to refresh the connection I get the following error:     </p>
<p><em>Unable to retrieve external data for the following connections:      <br />[ODC File]       <br />The data sources may be unreachable, may not be responding, or may have denied you access.       <br />Verify that data refresh is enabled for the trusted file location and that the workbook data authentication is correctly set.       </p>
<p></em>Here is a screenshot:     </p>
<p><a href="http://www.marcvalk.net/wp-content/uploads/2009/06/image10.png" rel="lightbox[196]"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="EWA: Data Refresh Failed" border="0" alt="EWA: Data Refresh Failed" src="http://www.marcvalk.net/wp-content/uploads/2009/06/image_thumb2.png" width="404" height="152" /></a> </p>
<p>Finally today I got this error resolved.</p>
<p>First of all I did all the action that MVP &#8211; Ton Stegeman did in his blog about this subject. Check it out <a title="Ton Stegeman blog about Excel services and SSAS" href="http://www.tonstegeman.com/Blog/Lists/Posts/Post.aspx?ID=43" target="_blank">here</a> (follow all 4 parts). He ends in part 3 with the error I have, but there was no solution provided.</p>
<p>First of all I needed to make sure that Kerberos is working and did not have a <em>double hop</em> problem, and that I could access the SSAS server and his cube. For that I added a SQL Server 2005 Analysis Services Filter Web Part and specified the same ODC file. It worked great (I could select a dimension and a Hierarchy).</p>
<p>The problem with this error is that I am running MOSS and SSAS both on a Windows 2008 Server (2 different servers btw.). You might think that it should not be any different than a 2003 server, but Server 2008 is “AES aware” (Advanced Encryption System). There is a problem with AES aware systems like W2K8, Vista and the use of Kerberos.    <br />To get it to work, you will have to follow the steps below:</p>
<ol>
<li>Open the following file in Notepad: “c:\Program Files\Microsoft SQL Server\MSAS10.MSSQLSERVER\OLAP\Config\msmdsrv.ini” </li>
<li>There is a section called Security, which looks like this:
<div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:57F11A72-B0E5-49c7-9094-E3A15BD5B5E6:2234dae6-4752-4d59-b7bc-029876ecd26c" class="wlWriterEditableSmartContent">
<pre style="background-color:#FFFFFF;white-space:-moz-pre-wrap; white-space: -pre-wrap; white-space: -o-pre-wrap; white-space: pre-wrap; word-wrap: break-word;overflow: auto;"><span style="color: #000000;">    </span><span style="color: #0000FF;">&lt;</span><span style="color: #800000;">Security</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">
        </span><span style="color: #0000FF;">&lt;</span><span style="color: #800000;">DataProtection</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">
            </span><span style="color: #0000FF;">&lt;</span><span style="color: #800000;">RequiredProtectionLevel</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">1</span><span style="color: #0000FF;">&lt;/</span><span style="color: #800000;">RequiredProtectionLevel</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">
        </span><span style="color: #0000FF;">&lt;/</span><span style="color: #800000;">DataProtection</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">
        </span><span style="color: #0000FF;">&lt;</span><span style="color: #800000;">AdministrativeDataProtection</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">
            </span><span style="color: #0000FF;">&lt;</span><span style="color: #800000;">RequiredProtectionLevel</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">1</span><span style="color: #0000FF;">&lt;/</span><span style="color: #800000;">RequiredProtectionLevel</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">
        </span><span style="color: #0000FF;">&lt;/</span><span style="color: #800000;">AdministrativeDataProtection</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">
        </span><span style="color: #0000FF;">&lt;</span><span style="color: #800000;">RequireClientAuthentication</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">1</span><span style="color: #0000FF;">&lt;/</span><span style="color: #800000;">RequireClientAuthentication</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">
        </span><span style="color: #0000FF;">&lt;</span><span style="color: #800000;">SecurityPackageList</span><span style="color: #0000FF;">/&gt;</span><span style="color: #000000;">
        </span><span style="color: #0000FF;">&lt;</span><span style="color: #800000;">DisableClientImpersonation</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">0</span><span style="color: #0000FF;">&lt;/</span><span style="color: #800000;">DisableClientImpersonation</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">
        </span><span style="color: #0000FF;">&lt;</span><span style="color: #800000;">BuiltinAdminsAreServerAdmins</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">1</span><span style="color: #0000FF;">&lt;/</span><span style="color: #800000;">BuiltinAdminsAreServerAdmins</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">
        </span><span style="color: #0000FF;">&lt;</span><span style="color: #800000;">ServiceAccountIsServerAdmin</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">1</span><span style="color: #0000FF;">&lt;/</span><span style="color: #800000;">ServiceAccountIsServerAdmin</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">
        </span><span style="color: #0000FF;">&lt;</span><span style="color: #800000;">ErrorMessageMode</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">2</span><span style="color: #0000FF;">&lt;/</span><span style="color: #800000;">ErrorMessageMode</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">
        </span><span style="color: #0000FF;">&lt;</span><span style="color: #800000;">CellPermissionMode</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">0</span><span style="color: #0000FF;">&lt;/</span><span style="color: #800000;">CellPermissionMode</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">
    </span><span style="color: #0000FF;">&lt;/</span><span style="color: #800000;">Security</span><span style="color: #0000FF;">&gt;</span></pre>
<p><!-- Code inserted with Steve Dunn's Windows Live Writer Code Formatter Plugin.  http://dunnhq.com --></div>
</li>
<li>Change the tag &lt;DataProtection&gt; and &lt;AdministrativeDataProtection&gt;, so it looks like this:<br />
    </p>
<div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:57F11A72-B0E5-49c7-9094-E3A15BD5B5E6:85b21d9b-97b6-4411-992b-7065bfc14863" class="wlWriterEditableSmartContent">
<pre style="background-color:#FFFFFF;white-space:-moz-pre-wrap; white-space: -pre-wrap; white-space: -o-pre-wrap; white-space: pre-wrap; word-wrap: break-word;overflow: auto;"><span style="color: #000000;">    </span><span style="color: #0000FF;">&lt;</span><span style="color: #800000;">Security</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">
        </span><span style="color: #0000FF;">&lt;</span><span style="color: #800000;">DataProtection</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">
            </span><span style="color: #0000FF;">&lt;</span><span style="color: #800000;">RequiredProtectionLevel</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">0</span><span style="color: #0000FF;">&lt;/</span><span style="color: #800000;">RequiredProtectionLevel</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">
        </span><span style="color: #0000FF;">&lt;/</span><span style="color: #800000;">DataProtection</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">
        </span><span style="color: #0000FF;">&lt;</span><span style="color: #800000;">AdministrativeDataProtection</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">
            </span><span style="color: #0000FF;">&lt;</span><span style="color: #800000;">RequiredProtectionLevel</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">0</span><span style="color: #0000FF;">&lt;/</span><span style="color: #800000;">RequiredProtectionLevel</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">
        </span><span style="color: #0000FF;">&lt;/</span><span style="color: #800000;">AdministrativeDataProtection</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">
        </span><span style="color: #0000FF;">&lt;</span><span style="color: #800000;">RequireClientAuthentication</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">1</span><span style="color: #0000FF;">&lt;/</span><span style="color: #800000;">RequireClientAuthentication</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">
        </span><span style="color: #0000FF;">&lt;</span><span style="color: #800000;">SecurityPackageList</span><span style="color: #0000FF;">/&gt;</span><span style="color: #000000;">
        </span><span style="color: #0000FF;">&lt;</span><span style="color: #800000;">DisableClientImpersonation</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">0</span><span style="color: #0000FF;">&lt;/</span><span style="color: #800000;">DisableClientImpersonation</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">
        </span><span style="color: #0000FF;">&lt;</span><span style="color: #800000;">BuiltinAdminsAreServerAdmins</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">1</span><span style="color: #0000FF;">&lt;/</span><span style="color: #800000;">BuiltinAdminsAreServerAdmins</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">
        </span><span style="color: #0000FF;">&lt;</span><span style="color: #800000;">ServiceAccountIsServerAdmin</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">1</span><span style="color: #0000FF;">&lt;/</span><span style="color: #800000;">ServiceAccountIsServerAdmin</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">
        </span><span style="color: #0000FF;">&lt;</span><span style="color: #800000;">ErrorMessageMode</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">2</span><span style="color: #0000FF;">&lt;/</span><span style="color: #800000;">ErrorMessageMode</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">
        </span><span style="color: #0000FF;">&lt;</span><span style="color: #800000;">CellPermissionMode</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">0</span><span style="color: #0000FF;">&lt;/</span><span style="color: #800000;">CellPermissionMode</span><span style="color: #0000FF;">&gt;</span><span style="color: #000000;">
    </span><span style="color: #0000FF;">&lt;/</span><span style="color: #800000;">Security</span><span style="color: #0000FF;">&gt;</span></pre>
<p><!-- Code inserted with Steve Dunn's Windows Live Writer Code Formatter Plugin.  http://dunnhq.com --></div>
</li>
<li>Stop and restart Analysis Services </li>
<li>Then edit your ODC file and add the following to the connection strong:<br />
    <br />”;SSPI=Kerberos;Protection Level=Connect” (without the quotes) </li>
</ol>
<p>Now try again.</p>
<p class="note">Tip:&#160; <br />-&#160; restart IIS every time you make a change in your ODC file.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.marcvalk.net/2009/06/ewa-error-data-refresh-failed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Internet Explorer behaviors with Kerberos Authentication</title>
		<link>http://www.marcvalk.net/2009/06/internet-explorer-behaviors-with-kerberos-authentication/</link>
		<comments>http://www.marcvalk.net/2009/06/internet-explorer-behaviors-with-kerberos-authentication/#comments</comments>
		<pubDate>Tue, 23 Jun 2009 06:38:41 +0000</pubDate>
		<dc:creator>mvalk</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Kerberos]]></category>

		<guid isPermaLink="false">http://www.marcvalk.net/2009/06/internet-explorer-behaviors-with-kerberos-authentication/</guid>
		<description><![CDATA[A great article from Rob “I Speak Tampa” Greene. He is explaining things that can occur when IE Kerberos authentication fails. You can check it out here.]]></description>
			<content:encoded><![CDATA[<p>A great article from Rob “I Speak Tampa” Greene. He is explaining things that can occur when IE Kerberos authentication fails. You can check it out <a href="http://blogs.technet.com/askds/archive/2009/06/22/internet-explorer-behaviors-with-kerberos-authentication.aspx" target="_blank">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.marcvalk.net/2009/06/internet-explorer-behaviors-with-kerberos-authentication/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>GPO: disable Office ribbon Menu items</title>
		<link>http://www.marcvalk.net/2009/06/gpo-disable-office-ribbon-menu-items/</link>
		<comments>http://www.marcvalk.net/2009/06/gpo-disable-office-ribbon-menu-items/#comments</comments>
		<pubDate>Mon, 15 Jun 2009 09:00:07 +0000</pubDate>
		<dc:creator>mvalk</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Group Policies]]></category>

		<guid isPermaLink="false">http://www.marcvalk.net/2009/06/gpo-disable-office-ribbon-menu-items/</guid>
		<description><![CDATA[Problem: I needed to disable a menu item in Excel 2007. Resolution: First of all download the ADM(X) templates for Office 2007 (keep in mind I am using server 2008). You can download them here Extract it to a folder, and then copy the contents of the admx folder to C:\Windows\PolicyDefinitions Open your Group Policy [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Problem:</strong></p>
<ul>
<li>I needed to disable a menu item in Excel 2007. </li>
</ul>
<p><strong>Resolution:</strong></p>
<ul>
<li>First of all download the ADM(X) templates for Office 2007 (keep in mind I am using server 2008). You can download them <a title="2007 Office system Administrative Template files (ADM, ADMX, ADML) and Office Customization Tool version 2.0" href="\http://www.microsoft.com/downloads/details.aspx?FamilyID=92d8519a-e143-4aee-8f7a-e4bbaeba13e7&amp;displaylang=en" target="_blank">here</a> </li>
<li>Extract it to a folder, and then copy the contents of the admx folder to C:\Windows\PolicyDefinitions </li>
<li>Open your Group Policy Editor (gpmc.msc), and make a new Group Policy (I named it “Office GPO” </li>
<li>If you browse to [User Configuration], [Administrative Templates], you will see all the Office Policy Definitions.      <br /><a href="http://www.marcvalk.net/wp-content/uploads/2009/06/image8.png" rel="lightbox[186]"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Office Policy Definitions" border="0" alt="Office Policy Definitions" src="http://www.marcvalk.net/wp-content/uploads/2009/06/image_thumb.png" width="244" height="199" /></a> </li>
<li>My task was to disable the Menu Items “From Other Sources”, “Existing Connections” and “Connection”.      <br />You can disable menu items under the group policy setting:       <br />[Administrative Templates\Microsoft Office Excel 2007\Disable Items in User Interface\Custom\Disable Commands\ </li>
<li>The Disable Commands works with ID numbers, you can find these <a title="2007 Office System Document: Lists of Control IDs" href="http://www.microsoft.com/downloads/details.aspx?familyid=4329D9E9-4D11-46A5-898D-23E4F331E9AE&amp;displaylang=en#filelist" target="_blank">here</a>       <br />For my problem I had to disable ID’s: 11205, 12495 and 12496
<p><a href="http://www.marcvalk.net/wp-content/uploads/2009/06/image9.png" rel="lightbox[186]"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="Disable Command Properties" border="0" alt="Disable Command Properties" src="http://www.marcvalk.net/wp-content/uploads/2009/06/image_thumb1.png" width="244" height="159" /></a>       </li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.marcvalk.net/2009/06/gpo-disable-office-ribbon-menu-items/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Kerberos fails when using CNAME records</title>
		<link>http://www.marcvalk.net/2009/06/kerberos-fails-when-using-cname-records/</link>
		<comments>http://www.marcvalk.net/2009/06/kerberos-fails-when-using-cname-records/#comments</comments>
		<pubDate>Tue, 09 Jun 2009 12:58:42 +0000</pubDate>
		<dc:creator>mvalk</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Kerberos]]></category>

		<guid isPermaLink="false">http://www.marcvalk.net/2009/06/kerberos-fails-when-using-cname-records/</guid>
		<description><![CDATA[If you’re in the middle of implementing Kerberos for something, remember that Kerberos authentication fails whenever you use CNAME records in DNS, instead of A-Records. Why is this? This is because whenever for example IE asks AD: “which account has a SPN registration for kerberos.marcvalk.net”, and kerberos.marcvalk.net is an CNAME for IIS_Server.marcvalk.net, the reply will [...]]]></description>
			<content:encoded><![CDATA[<p>If you’re in the middle of implementing Kerberos for something, remember that Kerberos authentication fails whenever you use CNAME records in DNS, instead of A-Records.</p>
<p>Why is this?   </p>
<p>This is because whenever for example IE asks AD: “which account has a SPN registration for kerberos.marcvalk.net”, and kerberos.marcvalk.net is an CNAME for IIS_Server.marcvalk.net, the reply will be IIS_Server.marcvalk.net and not the service account.</p>
<p>So you’ll probably see an pop-up authentication box, with a title of IIS_Server.marcvalk.net and not the correct hostheader kerberos.marcvalk.net.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.marcvalk.net/2009/06/kerberos-fails-when-using-cname-records/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
