Latest notes

Print Queue Scripting

http://blogs.technet.com/b/askperf/archive/2011/09/16/print-queue-scripting.aspx

Many methods of programmatically working with printers exist and I’ll be going over the main ones we use on the Windows platform support teams in this blog. These can be real lifesavers for print server administrators if changes need to be made across many queues.

As a quick caveat, please keep in mind that we use many of these scripts and utilities for troubleshooting during the course of support incidents but not all of them are supported. I’ll explicitly call out which tools are eligible for Microsoft support services and which ones are not while we walk through them.

In-Box Print Admin Scripts

Supportability

The print management visual basic scripts provided with the OS are fully supported.

clip_image003 Important Notes

ü These scripts are WMI-based and thus are only for use against a stand-alone print server.

ü The first versions of these scripts were included with the Windows Server 2003 Resource Kit.

ü The Resource Kit versions of these scripts are NOT supported but work against a cluster.

Script List

Location:

· Windows XP / Server 2003 – %windir%\system32

· Windows Vista / 7 / 2008 / 2008R2 – %windir%\system32\printing_admin_scripts

Scripts:

· PRNCNFG.VBS

Configures or displays configuration information about a printer.

· PRNDRVR.VBS

Adds, deletes, and lists printer drivers.

· PRNJOBS.VBS

Pauses, resumes, cancels and lists print jobs.

· PRNMNGR.VBS

Adds, deletes, and lists printers or printer connections, in addition to setting and displaying the default printer.

· PRNPORT.VBS

Creates, deletes, and lists standard TCP/IP printer ports, in addition to displaying and changing port configuration.

· PRNQCTL.VBS

Prints a test page, pauses or resumes a printer, and clears a printer queue.

· PUBPRN.VBS

Publishes a print queue to active directory.

Built-in Self Help

All of the in-box scripts display syntax information and examples if you run them without parameters.

CSCRIPT.EXE <ScriptName.vbs>

Commonly used commands:


Add HP Universal Printer Driver (UPD) 5.3 PCL 6 driver

cscript prndrvr.vbs -a -m "HP Universal Printing PCL 6 (v5.3)" -v 3 -i "C:\TEMP\hpcu115u.inf" -h "C:\TEMP"

Add HP UPD 5.3 Postscript (PS) driver

cscript prndrvr.vbs -a -m "HP Universal Printing PS (v5.3)" -v 3 -i "C:\TEMP\hpcu115v.inf" -h "C:\TEMP"

Add Xerox GPD 2.1 PS driver

cscript prndrvr.vbs -a -m "Xerox GPD PS V2.1" -v 3 -i "C:\TEMP\x2UNIVP.inf" -h "C:\TEMP"

Delete all printer drivers that are not in use

cscript prndrvr.vbs -x

Set a print queue to RAW only (disable Advanced Printing Features)

cscript prncnfg.vbs -t -p printer +rawonly

Set a print queue to print directly to the printer

cscript prncnfg.vbs -t -p printer +direct

Create a Standard TCP/IP port with SNMP status disabled

cscript prnport.vbs -a -md -r IP_127.0.0.1 -h 127.0.0.1 -o raw -n 9100

Print a test page to a queue

cscript prnqctl.vbs -p "HP Color LaserJet" -e

Cancel all print jobs in a queue

cscript prnqctl.vbs -p "HP Color LaserJet" -x

More Information:

The unsupported 2003 Resource Kit versions of these scripts can be run against a 32 or 64-bit cluster.
2466246 – Printer VBScript error: 0x1A8. Object required
http://support.microsoft.com/kb/2466246

PrintUI.dll

Supportability

One-line PrintUI.dll commands are fully supported by Microsoft support services, but the in-box print admin scripts are always the preferred method of getting the same tasks done.

PrintUI.dll Help

PrintUI.dll contains a wealth of information and examples if you run the following command.

RUNDLL32 PRINTUI.DLL,PrintUIEntry /?

clip_image003[1] Important Notes

ü Use the /u switch when connecting to queues or drivers may be downloaded repeatedly.

ü Adding a local port (standard tcp/ip or otherwise) is NOT supported by this tool.

ü An undocumented /x switch is required to map an IPP printer. (Content ID 314486)

ü PrintUI.dll is updated somewhat frequently, so make sure you’re using the latest version.

Commonly used commands:

Connect to a print queue:

rundll32 printui.dll,PrintUIEntry /u /in /n \\machine\printer

Add OEM printer driver using inf:

rundll32 printui.dll,PrintUIEntry /ia /m "Xerox WorkCentre 7775 PS" /h "x64" /v 3 /f C:\Xerox\x2DLEXP.inf

Add in-box printer driver:

rundll32 printui.dll,PrintUIEntry /ia /m "Brother DCP-116C" /h "x64" /v 3

Troubleshooting:

The vast majority of PrintUI.dll problems are related to incorrect or incomplete syntax.

ü Use example syntax as a template.

ü PrintUI.dll switches are case sensitive.

ü Driver names must be exactly as you see them in the GUI. (when installed manually)

ü Drivers require specification of the correct processor architecture using the /h switch. Use a simple “x86” or “x64” parameter to indicate your preference.

ü Drivers also require a version to be specified with the /v switch. You will always use 3 as the parameter for this switch. (There are no supported v2 kernel mode drivers today.)

More Information:

Deploying Printers and Print Drivers Remotely

SetPrinter (SetPrinter API wrapper)

SetPrinter Support Guidelines

SetPrinter.exe is distributed with the Windows Server 2003 Resource Kit and is subject to the Resource Kit Support Policy.

Resource Kit Support Policy

The SOFTWARE supplied in the Windows Resource Kit Tools is not supported under any Microsoft standard support program or service. Customers can, however, report issues and bugs by sending e-mail to rkinput@microsoft.com. Microsoft will, at its sole discretion, address issues and bugs reported in this manner, and responses are not guaranteed. This e-mail address is only for issues related to the Windows Resource Kit Tools and the Windows Deployment and Resource Kits.

The SOFTWARE (including instructions for its use and all printed and online documentation) is provided "AS IS" without warranty of any kind. Microsoft further disclaims all implied warranties including, without limitation, any implied warranties of merchantability or of fitness for a particular purpose. The entire risk arising out of the use or performance of the SOFTWARE and documentation remains with you.

In no event shall Microsoft, its authors, or anyone else involved in the creation, production, or delivery of the SOFTWARE be liable for any damages whatsoever (including, without limitation, damages for loss of business profits, business interruption, loss of business information, or other pecuniary loss) arising out of the use of or inability to use the SOFTWARE or documentation, even if Microsoft has been advised of the possibility of such damages.

Although no support services are available for this tool, it generally works with all OS’s, both clustered and stand-alone, from Windows XP to Windows Server 2008 R2.

A few sample commands are provided later in this document, but consumers of this tool will generally need to use the embedded help to customize the command line for a desired result.

clip_image003[2]Note

ü A custom script (e.g. VBScript, PowerShell, etc.) is a good alternative if SetPrinter will not accomplish a specific goal or functions in an unexpected manner.

SetPrinter Help

Running SetPrinter.exe without any arguments will display the embedded help.

Syntax: SetPrinter [-<mode>] <\\server|printer> <level> [<data> …] [<cmd>]

or SetPrinter -help <level>

or SetPrinter -examples <level>

or SetPrinter -show [-<mode>] <\\server|printer> <level>

where:

\\server : (or \\server\*) change all local printers on this server

(use "" or "*" for all printers on local machine)

\\server\\: change server (not printer) settings

printer : change this printer (printer or \\server\printer)

level : PRINTER_INFO level (0 – 9).

data : (optional) Level specific data in ‘keyword=value keyword=value’

format. Data is unchanged for keywords not specified.

cmd : (optional, but must be last if present) one of:

"pause", "resume", "purge", "setstatus"

-help : show format of data for <level>

-examples : show usage examples for <level>

-show : show current settings (no changes applied – all <data> ignored)

-<mode> : (optional) Only valid on Windows Vista and later.

Possible values: -cached, or -notcached

(See documentation for OpenPrinter2 API, pOptions parameter)

The <level> determines which members of the printer structure are used.

The most common <level> values are:

clip_image001 Level 2: Used to configure most print queue settings.

clip_image001[1] Level 3: Used to set print queue security.

clip_image001[2] Level 8: Used to set global document printing defaults.

Help for each level is available by running SetPrinter –help <level>

If there is a specific setting you are interested in, you may configure a print queue as desired in the GUI and then use the SetPrinter –show option to find the value.

Self-Help Walkthrough:

These scenarios are intended to “teach you to fish”.

Example One:

I need to know what setting controls landscape vs. portrait in the Printing Defaults, and then set that to landscape for all print queues.

1) This is a global setting that I want all clients to get when the print queue is connected to for the first time, so 8 is the appropriate level.

2) Run SetPrinter –help 8 to see the level-specific help.

3) Run SetPrinter –examples 8 to see some examples.

4) Create a printer called HP and configure it to print in portrait mode.

5) Run setprinter -show "HP" 8.

6) Use the GUI to reconfigure the HP printer to print in landscape mode.

7) Run setprinter -show "HP" 8.

8) Compare the SetPrinter –show results to discover dmOrientation has changed from 1 to 2.

9) Roll out the change to all print queues with SetPrinter "” 8 pDevMode=dmOrientation=1.

Example Two:

I need to know what setting controls a print processor, and then switch all queues to WinPrint.

1) This is a general setting for the print queue, so 2 is the appropriate level.

2) Run SetPrinter –help 2 to see the level-specific help.

3) Run SetPrinter –examples 2 to see some examples.

4) Create a printer called Xerox and set it to the WinPrint print processor.

5) Run setprinter –show “Xerox” 2.

6) Use the GUI to reconfigure the Xerox printer to use a 3rd party print processor.

7) Run setprinter –show “Xerox” 2.

8) Compare the SetPrinter –show results to discover pPrintProcessor has changed.

9) Roll out WinPrint to all print queues with SetPrinter "" 2 pPrintProcessor=WinPrint.
Note: Most 3rd party drivers work fine with WinPrint. When in doubt, ask your OEM.

Example Three:

I need to mirror the security settings on one print queue to all other queues.

1) This is a security setting for the print queue, so 3 is the appropriate level.

2) Run SetPrinter –help 3 to see the level-specific help.

3) Run SetPrinter –examples 3 to see some examples.

4) Create a printer called Lexmark and set security as desired.

5) Run setprinter –show “Lexmark” 3 and copy the security descriptor.

6) Roll out the security descriptor to all print queues with SetPrinter "" 3 <Security Descriptor>.

Note: You may need to run this as the local system account. (psexec –s –i cmd.exe)

TechNet Script Repository

The TechNet Script Repository provides printer management scripts with support provided through the forums. Whether you’re a developer or a “script kiddie”, this is the place to go for all of your custom printer management scripting needs. Maybe you can even contribute something to the community? J

TechNet Script Center Repository
http://gallery.technet.microsoft.com/scriptcenter

Disclaimer: The sample scripts are not supported under any Microsoft standard support program or service. The sample scripts are provided AS IS without warranty of any kind. Microsoft further disclaims all implied warranties including, without limitation, any implied warranties of merchantability or of fitness for a particular purpose. The entire risk arising out of the use or performance of the sample scripts and documentation remains with you. In no event shall Microsoft, its authors, or anyone else involved in the creation, production, or delivery of the scripts be liable for any damages whatsoever (including, without limitation, damages for loss of business profits, business interruption, loss of business information, or other pecuniary loss) arising out of the use of or inability to use the sample scripts or documentation, even if Microsoft has been advised of the possibility of such damages.

I hope you’ve enjoyed reading this information as much as I have putting it together for you, and I sincerely hope one or more of these options can save you some time in the near future.

–Aaron Maxwell

Dual Boot Windows 8 from VHD using Windows Setup

http://blog.concurrency.com/infrastructure/dual-boot-windows-8-from-vhd-using-windows-setup/

 

Post Pic

Dual Boot Windows 8 from VHD using Windows Setup

Posted on September 15, 2011 by Shannon Fritz in Infrastructure

Are you running Windows 7 and have things just the way you like them, but you’re really curious to see how Windows 8 looks and feels? Using this method, you can boot your computer between your existing Windows 7 installation or Windows 8 without needing to sacrifice disk space! Using a Dynamic Virtual Hard Disk (VHD), you can install Windows 8 to a single file that is stored on your Windows 7 file system, and then boot directly from that Virtual Hard Disk when you can then choose to load your existing OS or the new Windows 8. You are not doing an in-place upgrade and you are not doing a rebuild. It’s just a new install of Windows 8 and you don’t have to trash your existing setup to do it. Let’s get started!

On the computer which already has windows 7 installed, boot from the Windows 8 media and you’ll launch the installer. Before clicking “Install Now”, hit Shift+F10 and the WinPE command prompt will appear.

Note: If you want to boot from USB instead of burning a DVD, you can use the very handy WUDT tool from CodePlex which will make a bootable USB stick from the ISO for you.

It’s time to create the VHD that will be your Windows 8 drive. Run “diskpart” from the CMD window, then issue the following commands to diskpart:

  1. list disk … This shows your currently attached hard disks. In this example I only have one, Disk 0.
  2. select disk 0 … You want to select the disk where you’re current operating system (Windows 7) is installed, so if you have multiple disks available, you might use a different number.
  3. list vol … Show all the volumes that exist on that disk. Existing installations of Windows 7 will usually have a 100MB volume that is the “System Reserved” partition (used as the boot loader and leveraged by BitLocker) and then the actual OS volume is much larger. In example you can see my Windows 7 volume is actually assigned to letter D (although when booting normally it would be my C: drive).
  4. create vdisk file=d:\Windows8.vhd maximum=100000 type=expandable … This creates a Dynamic VHD that can grow to ~100GB in the root of my Windows 7 partition.
  5. select vdisk file=d:\Windows8.vhd … after selecting this vdisk, the following commands will apply to it
  6. attach vdisk … The VHD will be mounted and the disk will be available to the windows installer
  7. exit … we’re done with diskpart

All those commands will look like this:

Now you can close the Command Prompt and return to the Install Windows wizard and click Install Now. When asked where you want to install Windows, you should see a new Disk 1 listed with Unallocated Space. You’ll notice that when you select this disk the installer will tell you that “Windows cannot be installed to this disk” but the Next button is enabled. If you click Next, it will in fact install Windows there just fine.

Once the installation is complete and your computer reboots, you will see a new boot loader that asks you to “Choose an operating system” and you can select either the new install of Windows 8 or your previously existing OS. The first time this appears you get about 3 seconds and it auto loads Windows 8 to finish the setup. On subsequent reboots it’ll give you 30 seconds before auto selecting it.

Now you can browse around Windows 8 on your Native hardware! You can also still access files on your Windows 7 disk. Open Explorer and you’ll see it appear as a different drive letter (D:\ in this case) and you can browse around and copy/modify files as you wish.

Notice that the D:\ looks full? This is because the VHD you created for Windows 8 is reporting its maximum size instead of its actual size. When you boot into windows 7 you’ll see the VHD is actually only about 8GB.

All done with Windows 8 and can’t figure out how to shut down? Take your mouse and hover over the start button, or touch your mouse cursor to the bottom left corner of the screen and a small start menu will appear. Click on Settings, then Power and choose Shutdown.

Now you can enjoy the best of both worlds…N’joy!

Mapped Drives Are Not Seen From Elevated Command Prompt in Vista

http://www.winhelponline.com/blog/mapped-drives-are-not-seen-from-elevated-command-prompt-in-vista/

 

When I tried to access a network drive via elevated Command Prompt, the drive was not found and I got the error The system cannot find the path specified. However, the drive-letter is listed in (My) Computer and accessible from non-elevated Command Prompt.

Fig 1: Mapped drive not seen from Elevated Command Prompt.

Fig 2: Mapped drive accessible from a standard Command Prompt.

Upon searching the net, I found a Microsoft Knowledgebase article After you turn on User Account Control in Windows Vista, programs may be unable to access some network locations which address the problem. Here is an excerpt from that article that explains everything:

When an administrator logs on to Windows Vista, the Local Security Authority (LSA) creates two access tokens. If LSA is notified that the user is a member of the Administrators group, LSA creates the second logon that has the administrator rights removed (filtered). This filtered access token is used to start the user’s desktop. Applications can use the full administrator access token if the administrator user clicks Allow in a User Account Control dialog box.

If a user is logged on to Windows Vista and if User Account Control is enabled, a program that uses the user’s filtered access token and a program that uses the user’s full administrator access token can run at the same time. Because LSA created the access tokens during two separate logon sessions, the access tokens contain separate logon IDs.

As I created the drive mappings from a standard user token earlier, the drives are not seen from an elevated token (For example, when using an admin Command Prompt.)

The problem was solved after I created the EnableLinkedConnections DWORD value in this registry key and set its Value data to 1:

HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Policies \ System

The EnableLinkedConnections value enables Windows Vista to share network connections between the filtered access token and the full administrator access token for a member of the Administrators group.

You must restart the computer after creating the registry value.

Fig 3: Mapped drive seen from both standard and elevated Command Prompt Windows.

Registry fix

To automate the above setting, dowload enablelinkedconnections.zip, unzip and extract the contents to a folder. Double-click enablelinkedconnections.reg to run it. To reverse the changes use the undo.reg file.

And here is a useful note from James Finnigan [MSFT] posted at the MS Newsgroup.

The "EnableLinkedConnections" policy relies on the user being a member of the Administrators group and sharing across the boundary between non-elevated and elevated (which can lead to intentionally misdirected drive mappings by Malware). It is essentially a workaround for customers that are in the process of moving their users to standard user, but need to do so gradually and keep them as members of the Administrators group in the short-term.

MORE INFORMATION

Mapped drives created from an elevated access token will not be visible from processes running in limited user token. If you use Group Policy to create mapped drives, it uses the elevated access token. As a result, your user account (runs with the limited user token by default) won’t see the mapped drives. For more details and a workaround see: Group Policy Scripts can fail due to User Account Control. The script launchapp.wsf helps you create mapped drives under limited user token via Group Policy.

Fixing when Windows SBS Doesn’t Show Account to Transfer

http://blog.xoc.net/2011/04/fixing-when-windows-sbs-doesnt-show.html

 

I have struggled for a few days trying to get the Windows Small Business Server 2008 connect launcher.exe program to show an existing account in the "Move existing user data and settings" page of the wizard. I tried everything I could think of to determine what was different about the account that was being listed and the account that wasn’t. There are lots of questions being asked about this on the web with no answers that worked for me. (There’s a long and uninteresting story involving an ID-10-T who works for the Microsoft Company Store on why I’m solving SBS2008 problems when 2011 is shipping now…I don’t know if this problem also occurs in SBS2011.)
All of the properties of the accounts were the same. Both had entries in the registry that were identical. I looked at the files that they opened using the SysInternals procmon program. I looked at the network traffic that the launcher program generated using Microsoft Network Monitor 3.4.
Procmon clued me in that there were some log files being generated. They are found in C:\Program Files\Windows Small Business Server\Logs.
Here’s the deal. Launcher downloads an executable called connectcomputer.exe and runs it. Connectcomputer does a huge amount of stuff. I’m not sure it needs to do all that–it has the distinct feel of having been written by an intern. One of the things it does is enumerates your user profile directory and checks every file. If any file in the entire directory tree is not accessible by it, or it runs into any problems with anything, it won’t list that account.
I opened connectcomputer.log in notepad and searched for the account that was missing. It showed an exception. For some reason, there was a recursive reparse point to a directory in my c:\users\myacct\appdata\local\application data directory that looped back to the same directory. A reparsepoint is a fake directory that links to another real directory on the drive. So I (and connectcomputer) could both cd into the "application data" directory forever until the filename became too long and it threw an error. Thus it was finding "c:\users\myacct\appdata\local\application data\application data\application data…" etc. By the way, this will not show up in the Windows Explorer, but does show up in the command line. How this reparse point got created is a mystery…maybe having to do with the account being originally created in Windows XP.
The next trick is removing a reparse point. I had a clue about that, and it just took poking around a little to find it. There is a nifty command line tool that comes with Windows called fsutil. It allows mucking with NTFS from the command line. First you must cd to the the directory that has the bad reparse point. The magic command line that fixed my problem is:
cd \users\myacct\appdata\local
fsutil reparsepoint delete "application data"

I then deleted the log files and reran launcher. This time it complained that it couldn’t read from another directory. That directory wasn’t important to me, so I just deleted it. Having fixed all the problems that the log file complained about, my account showed up in the "Move existing user data and settings" list!

Acrobat Reader X : no toolbar in browser

 

You’re seeing the Read Mode display, with a black heads-up toolbar but no application chrome.

To turn that off, open Adobe Reader X, choose Edit – Preferences – Internet and untick "Display in Read Mode by default", then press OK.

You receive a "Windows Update has encountered an error and cannot display the requested page" error message when you try to install an update

http://support.microsoft.com/kb/883614

Method 1: Verify that the services are started

Make sure that BITS and the Automatic Updates service are started. To do this, follow these steps:

  1. Click Start, click Run, type services.msc, and then click OK.
  2. In the list of services, right-click Automatic Updates, and then click Properties.
  3. In the Startup type list, click Automatic, and then click Apply.
  4. If Service status is set to Stopped, click Start, and then click OK.
  5. Right-click Background Intelligent Transfer Service, and then click Properties.
  6. In the Startup type list, click Manual, and then click Apply.
  7. If Service status is set to Stopped, click Start, and then click OK.

Back to the top

Method 2: One or both of the services do not appear in the Services Control Manager

Note If you manually type the commands in this section, remember that they are case sensitive.
If the Automatic Updates service or the Background Intelligent Transfer Service does not appear in the Services Control Manager, reinstall that service or those services. To do this, use one or both of the following methods, depending on your situation:

The Automatic Updates service is missing

To reinstall the Automatic Updates service, follow these steps:

  1. Click Start, click Run, type the following command, and then click OK:

    %windir%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %windir%\inf\au.inf

  2. If you are prompted to insert your operating system CD, type the following path in the Copy files from box, and then click OK:

    %windir%\ServicePackFiles\i386

    Note This location contains the most recently updated service pack files. If you cannot use this path to copy the required files from, insert your operating system CD, and then click OK.

The Background Intelligent Transfer Service is missing

To reinstall the Background Intelligent Transfer Service, follow these steps:

  1. Click Start, click Run, type the following command, and then click OK:

    %windir%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %windir%\inf\qmgr.inf

  2. If you are prompted to insert your operating system CD, type the following path in the Copy files from box, and then click OK:

    %windir%\ServicePackFiles\i386

    Note This location contains the most recently updated service pack files. If you cannot use this path to copy the required files from, insert your operating system CD, and then click OK.

How to Change the User Account Password if Unable to Login to Windows

Update for Windows 10:

Use utilman.exe for cmd.exe

Create new user:

net user <username> /add

net localgroup administrators <username> /add

Login as new user and then reset original user password:

net user <username> *

 

Here’s how:

1. Boot to WinRE (Windows Recovery Environment).

Name:  1.png
Views: 8346
Size:  70.0 KB

2. Click on the Command Prompt option.
3. Type the following commands and press enter after each one:

  • C:
  • CD Windows\system32
  • ren cmd.exe cmd.old
  • ren magnify.exe cmd.exe
  • ren cmd.old magnify.exe

4. Restart computer.
5. Click on Easy of Access centre left side bottom à Choose Magnify option.

Name:  2.png
Views: 8269
Size:  39.4 KB

Name:  3.png
Views: 8337
Size:  40.4 KB

6. A Command prompt opens up
7. Type: net user administrator /active:yes and press enter.
8. Restart the computer.
9. Logon on administrator account and then using User Accounts page in the Control Panel, remove password for the other account.
10. Type Magnify.exe in Start Menu search box and press enter and open it.
11. Command prompt opens up
12. Type: net user administrator /active:no and press enter.
13. Restart the computer
NOTE: This will disable the administrator account.
14. Now, Boot to winRE again, and click on the Command Prompt option.
15. Type the following commands and press enter after each one:

  • C:
  • CD Windows\system32
  • ren magnify.exe cmd.old
  • ren cmd.exe magnify.exe
  • ren cmd.old cmd.exe
  • exit

16. Restart the computer – system logs on to the User account without asking for password provided there is only one user account.

How to reset local security policy settings to default in Windows XP and Vista

http://helpdeskgeek.com/how-to/reset-local-security-policy/

Have you ever gotten a computer second-hand? Maybe from a company that was shutting down or from someone who no longer needed theirs? Ideally, you would want to simply reformat the computer and start from scratch, right?

However, that’s not always the case. Let’s say you get a computer that has Windows XP or Windows Vista already installed, but you don’t have the original CD that came with the computer. So you really can’t reformat computer without risking Windows not activating properly.

So what’s the problem with just leaving it the way it is? Well, sometimes when you get a computer, it may have been part of an Active Directory environment, which means it was subject to Group Policies.

Even if you remove the computer from the domain and put it into a workgroup, the local security policies that were changed will not be removed. This can be very annoying because local security policies include settings like preventing users from installing printers, restricting who can use the CD-ROM drive, requiring a smart card, restricted logon hours, password requirements and more!

These are all great in a corporate environment, but will cause all kinds of grief to a normal computer user. So what you can do to solve this problem is to reset the local security settings to their default settings.

The way this can be done is by using the default security configuration templates that come with all versions of Windows XP and Vista. This may sound too technical, but all you have to do is run one command.

First, click on Start, Run and then type in CMD. Now copy and paste the following command into the window:

secedit /configure /cfg %windir%\repair\secsetup.inf /db secsetup.sdb /verbose

If you are running Windows Vista and need to reset the security settings to their default values, use this command instead:

secedit /configure /cfg %windir%\inf\defltbase.inf /db defltbase.sdb /verbose

reset local security policy

That’s it! Now just wait for Windows to go through all the registry settings and reset them. It takes a few minutes and you’ll have to restart the computer to see the changes.

But now you should be able to use your computer without any of the remnants of local security settings from previous Group Policies. Enjoy!