<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Bob&#039;s Identity Management Blog &#187; Bob</title>
	<atom:link href="http://www.bobbobel.com/author/rbobel/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.bobbobel.com</link>
	<description>&#34;Anyone can hold the helm when the sea is calm.&#34; - Syrus Publilius</description>
	<lastBuildDate>Mon, 16 Jan 2012 21:47:10 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Matt Hitchcock posted some cool comments about Windows 8 AD</title>
		<link>http://www.bobbobel.com/matt-hitchcock-posted-some-cool-comments-about-windows-8-ad/</link>
		<comments>http://www.bobbobel.com/matt-hitchcock-posted-some-cool-comments-about-windows-8-ad/#comments</comments>
		<pubDate>Mon, 16 Jan 2012 21:47:10 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1186</guid>
		<description><![CDATA[http://matthitchcock.com/2012/01/08/active-directory-in-windows-8-first-look/]]></description>
			<content:encoded><![CDATA[<p><a href="http://matthitchcock.com/2012/01/08/active-directory-in-windows-8-first-look/">http://matthitchcock.com/2012/01/08/active-directory-in-windows-8-first-look/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/matt-hitchcock-posted-some-cool-comments-about-windows-8-ad/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>October was a bad month for computing founders</title>
		<link>http://www.bobbobel.com/october-was-a-bad-month-for-computing-founders/</link>
		<comments>http://www.bobbobel.com/october-was-a-bad-month-for-computing-founders/#comments</comments>
		<pubDate>Tue, 25 Oct 2011 15:51:15 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Bobel]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Founding Fathers of Computing]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1176</guid>
		<description><![CDATA[Apple http://en.wikipedia.org/wiki/Steve_Jobs C http://en.wikipedia.org/wiki/Dennis_Ritchie LISP http://techcrunch.com/2011/10/24/creator-of-lisp-john-mccarthy-dead-at-84/]]></description>
			<content:encoded><![CDATA[<p>Apple <a href="http://en.wikipedia.org/wiki/Steve_Jobs">http://en.wikipedia.org/wiki/Steve_Jobs</a></p>
<p>C <a href="http://en.wikipedia.org/wiki/Dennis_Ritchie">http://en.wikipedia.org/wiki/Dennis_Ritchie</a></p>
<p>LISP <a href="http://techcrunch.com/2011/10/24/creator-of-lisp-john-mccarthy-dead-at-84/">http://techcrunch.com/2011/10/24/creator-of-lisp-john-mccarthy-dead-at-84/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/october-was-a-bad-month-for-computing-founders/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Steve Jobs 1955 &#8211; 2011</title>
		<link>http://www.bobbobel.com/steve-jobs-1955-2011/</link>
		<comments>http://www.bobbobel.com/steve-jobs-1955-2011/#comments</comments>
		<pubDate>Thu, 06 Oct 2011 00:06:32 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Bobel]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Steve Jobs Passing]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1173</guid>
		<description><![CDATA[You have to be impressed by this guys life &#8211; http://www.cnn.com/2011/10/05/us/obit-steve-jobs/index.html?iref=BN1&#38;hpt=hp_t1.]]></description>
			<content:encoded><![CDATA[<p>You have to be impressed by this guys life &#8211; <a href="http://www.cnn.com/2011/10/05/us/obit-steve-jobs/index.html?iref=BN1&amp;hpt=hp_t1">http://www.cnn.com/2011/10/05/us/obit-steve-jobs/index.html?iref=BN1&amp;hpt=hp_t1</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/steve-jobs-1955-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ActiveRoles Update 3663 just released!</title>
		<link>http://www.bobbobel.com/activeroles-update-3663-just-released/</link>
		<comments>http://www.bobbobel.com/activeroles-update-3663-just-released/#comments</comments>
		<pubDate>Tue, 04 Oct 2011 16:10:57 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[ActiveRoles Multi-browser]]></category>
		<category><![CDATA[ActiveRoles Server update 3663]]></category>
		<category><![CDATA[Cloud IDM]]></category>
		<category><![CDATA[Self-Service]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1165</guid>
		<description><![CDATA[Last week development released the 6.7.3663 update for ActiveRoles Server.  Included in the update are some generic fixes as you would expect, but there is also a set of updates for a long standing limitation that only Internet Explorer worked properly. This update adds multi-browser support  and allows the ActiveRoles web interface to be accessed from [...]]]></description>
			<content:encoded><![CDATA[<p>Last week development released the 6.7.3663 update for <strong>ActiveRoles Server</strong>.  Included in the update are some generic fixes as you would expect, but there is also a set of updates for a long standing limitation that only Internet Explorer worked properly. This update adds multi-browser support  and allows the <em>ActiveRoles</em> web interface to be accessed from the following browsers:</p>
<ul>
<li>Firefox 5.0 and 6.0</li>
<li>Google Chrome 13</li>
<li>Safari 4 and 5</li>
<li>Windows Internet Explorer 7.0, 8.0 and 9.0</li>
</ul>
<dl id="attachment_1166" class="wp-caption aligncenter" style="width: 310px;">
<dt class="wp-caption-dt"><a href="http://www.bobbobel.com/wp-content/uploads/2011/10/ActiveRoles_Grey_On_Chrome.png"><img class="size-medium wp-image-1166" title="ActiveRoles_Grey_On_Chrome" src="http://www.bobbobel.com/wp-content/uploads/2011/10/ActiveRoles_Grey_On_Chrome-300x249.png" alt="" width="300" height="249" /></a></dt>
<dd class="wp-caption-dd">ActiveRoles w/3663 installed running on Google Chrome displayed with altered color scheme.</dd>
</dl>
<p>It is interesting that the release notes don&#8217;t mention IE 6.0, but with information like this (<a href="http://en.wikipedia.org/wiki/Internet_Explorer_6">http://en.wikipedia.org/wiki/Internet_Explorer_6</a>) being prevalent around the Internet it is not surprising.  With the everyday increase in hacking and exploits attacks &#8211; anyone still using IE 6 should be afraid, very afraid and move to a secure and supported browser immediately.  My installation experience was good. Installation went as expected with no surprises and things continued to work including the add-ins for QAS and Defender. Changing the color scheme is a bit tricky since you really are setting a single color that will be used in place of the standard Blue UI color. But for many customers this will be a welcome change from modifying XML files with new color codes.</p>
<p>Customers can download the update from Quest support <a href="https://support.quest.com/Search/SolutionDetail.aspx?id=SOL78214">https://support.quest.com/Search/SolutionDetail.aspx?id=SOL78214</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/activeroles-update-3663-just-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bhold what Microsoft bought</title>
		<link>http://www.bobbobel.com/bhold-what-microsoft-bought/</link>
		<comments>http://www.bobbobel.com/bhold-what-microsoft-bought/#comments</comments>
		<pubDate>Fri, 23 Sep 2011 15:04:57 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[aquisitions]]></category>
		<category><![CDATA[Bhold]]></category>
		<category><![CDATA[IAG]]></category>
		<category><![CDATA[Quest]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1160</guid>
		<description><![CDATA[Micrsosoft announced the aquistion of Bhold to enhance the FIM family of products. http://www.microsoft.com/pathways/bhold/ http://blogs.gartner.com/ian-glazer/2011/09/23/bhold-wins-the-microsoft-iag-lottery/ &#160;]]></description>
			<content:encoded><![CDATA[<p>Micrsosoft announced the aquistion of Bhold to enhance the FIM family of products.</p>
<p><a href="http://www.microsoft.com/pathways/bhold/">http://www.microsoft.com/pathways/bhold/</a></p>
<p><a href="http://blogs.gartner.com/ian-glazer/2011/09/23/bhold-wins-the-microsoft-iag-lottery/">http://blogs.gartner.com/ian-glazer/2011/09/23/bhold-wins-the-microsoft-iag-lottery/</a></p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/bhold-what-microsoft-bought/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Defender &amp; ActiveRoles MMC Integration</title>
		<link>http://www.bobbobel.com/defender-activeroles-mmc-integration/</link>
		<comments>http://www.bobbobel.com/defender-activeroles-mmc-integration/#comments</comments>
		<pubDate>Fri, 23 Sep 2011 14:46:27 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[ActiveRoles Integration]]></category>
		<category><![CDATA[Defender]]></category>
		<category><![CDATA[OTP Token Management]]></category>
		<category><![CDATA[Strong Authorization Management]]></category>
		<category><![CDATA[Two Factor Authentication]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1155</guid>
		<description><![CDATA[For ActiveRoles customers using or considering using Quest Defender, integration between the two products is a requirement. Being able to perform OTP token management from the point where user management is performed is one key to efficient management of strong authentication. Token Management from the ActiveRoles Web Console I was working with a customer this [...]]]></description>
			<content:encoded><![CDATA[<p>For <strong>ActiveRoles</strong> customers using or considering using <span style="text-decoration: underline;">Quest Defender</span>, integration between the two products is a requirement. Being able to perform OTP token management from the point where user management is performed is one key to efficient management of strong authentication.</p>
<p style="text-align: center;"><em><strong>Token Management from the ActiveRoles Web Console<br />
</strong></em><img class="aligncenter size-medium wp-image-1156" title="Defender-ARS-Web-Integration" src="http://www.bobbobel.com/wp-content/uploads/2011/09/Defender-ARS-Web-Integration-300x135.png" alt="" width="300" height="135" /></p>
<p>I was working with a customer this week who had a requirement to manage Quest Defender two factor tokens through the <em>ActiveRoles</em> MMC console. While I knew this was under development, I did not realize you can get it today without waiting for the next release of Defender. Integration with the <em>ActiveRoles</em> MMC can be critical for customers who are primarily using the MMC for day-to-day or help desk operations.</p>
<p style="text-align: center;"><em><strong>Token Management from the ActiveRoles MMC<br />
(click to enlarge)</strong></em><a href="http://www.bobbobel.com/wp-content/uploads/2011/09/Defender-ARS-MMC-Integration.png"><img class="aligncenter size-medium wp-image-1157" title="Defender-ARS-MMC-Integration" src="http://www.bobbobel.com/wp-content/uploads/2011/09/Defender-ARS-MMC-Integration-300x262.png" alt="" width="300" height="262" /></a></p>
<p>The <strong>ActiveRoles</strong> integration pack on the Defender 5.6 CD installs property pages and commands into the ActiveRoles Web Interface only. Separately, Defender Software update 5.6.0.2593 adds token management and property tabs into the ActiveRoles MMC on user property pages. This update can be obtained through the Quest support site and you will need to install two components 1) Defender ARS Integration Pack_Update_5.6.0.2593 and 2) Defender Administration Console_Update_5.6.0.2593.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/defender-activeroles-mmc-integration/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HTC Incredible to support Near Field Communciation (NFC)</title>
		<link>http://www.bobbobel.com/htc-incredible-to-support-near-field-communciation-nfc/</link>
		<comments>http://www.bobbobel.com/htc-incredible-to-support-near-field-communciation-nfc/#comments</comments>
		<pubDate>Fri, 16 Sep 2011 19:13:55 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Bobel]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Entitlement]]></category>
		<category><![CDATA[Mobile Computing]]></category>
		<category><![CDATA[Cloud Payment]]></category>
		<category><![CDATA[Droid Incredible S]]></category>
		<category><![CDATA[Near Field Communication]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1144</guid>
		<description><![CDATA[A friend of mine is working on NFC and I wondered if my Android device would support it &#8211; well it didn&#8217;t but there is a new version of the phone in development that was just tested by the FCC for NFC compatibility. http://www.nfcrumors.com/08-17-2011/is-the-htc-incredible-s-the-next-google-wallet-enabled-nfc-phone-it-just-passed-through-the-fcc/]]></description>
			<content:encoded><![CDATA[<p>A friend of mine is working on NFC and I wondered if my Android device would support it &#8211; well it didn&#8217;t but there is a new version of the phone in development that was just tested by the FCC for NFC compatibility.</p>
<p><a href="http://www.nfcrumors.com/08-17-2011/is-the-htc-incredible-s-the-next-google-wallet-enabled-nfc-phone-it-just-passed-through-the-fcc/">http://www.nfcrumors.com/08-17-2011/is-the-htc-incredible-s-the-next-google-wallet-enabled-nfc-phone-it-just-passed-through-the-fcc/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/htc-incredible-to-support-near-field-communciation-nfc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Putting a price on governmental security</title>
		<link>http://www.bobbobel.com/putting-a-price-on-governmental-security/</link>
		<comments>http://www.bobbobel.com/putting-a-price-on-governmental-security/#comments</comments>
		<pubDate>Thu, 15 Sep 2011 14:26:30 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1139</guid>
		<description><![CDATA[My colleague Dmitry Kagansky sharing his insites on Security its cost to government.  http://fedscoop.com/tv/quest-federal-cto-dmitry-kagansky-on-security-in-government/]]></description>
			<content:encoded><![CDATA[<p>My colleague Dmitry Kagansky sharing his insites on Security its cost to government.</p>
<p> <a href="http://fedscoop.com/tv/quest-federal-cto-dmitry-kagansky-on-security-in-government/">http://fedscoop.com/tv/quest-federal-cto-dmitry-kagansky-on-security-in-government/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/putting-a-price-on-governmental-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Working with Field Labels in ActiveRoles</title>
		<link>http://www.bobbobel.com/working-with-field-labels-in-activeroles/</link>
		<comments>http://www.bobbobel.com/working-with-field-labels-in-activeroles/#comments</comments>
		<pubDate>Fri, 02 Sep 2011 12:28:28 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[AcitveRoles Server]]></category>
		<category><![CDATA[ActiveRoles XML]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1137</guid>
		<description><![CDATA[In the past it was common to have a requirement that additional details be presented at the top of a web interface form in ActiveRoles &#8211; this would often require modification to the underlying XML making the solution difficult to maintain during upgrades. If the requirement is simple enough there is a workaround that may [...]]]></description>
			<content:encoded><![CDATA[<p>In the past it was common to have a requirement that additional details be presented at the top of a web interface form in ActiveRoles &#8211; this would often require modification to the underlying XML making the solution difficult to maintain during upgrades. If the requirement is simple enough there is a workaround that may provide relief in this situation. If you would like to provide limited additional information at the top of a form in the ActiveRoles Web Interface you can add this information to the label field of the first entry. This information must be limited as it is subject to the constraints of the form sizing and so you probably won&#8217;t be able to make it look exactly like you require, but you may get it close. Some HTML tags may work, but not all are guaranteed to be available. My suggestion is that you keep things simple like using line breaks and list tags.</p>
<ol>
<li>Logon as a DS Admin to the web interface you wish to modify.</li>
<li>Click <em>&#8220;Click here to customize this form&#8221;</em></li>
<li>Locate the top field and click <em>(edit&#8230;)</em> at the far left end of the entry name.</li>
<li>In the <em>Entry name:</em> field enter the text you want to display at the top of the form. Make sure to add any text to the left of the field name already in that entry so that it will continue to display properly.</li>
<li>For example:<br />
Directions&lt;BR&gt;Contacts may not be used for authentication.You have two choices at this point.&lt;BR&gt;&lt;BR&gt;&lt;ol&gt;&lt;li&gt;If the person will need to authenticate against Active Directory, you should create a user account object on their behalf.&lt;/i&gt;&lt;li&gt;Continue creating this Contact object.&lt;/i&gt;&lt;/ol&gt;&lt;BR&gt; First Name</li>
<li>Click <em>Save</em></li>
<li>Click <em>Reload</em></li>
</ol>
<p>Navigate to the form in the UI so that you can validate your work.</p>
<p><em></em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/working-with-field-labels-in-activeroles/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Smart card presentation at the AFITC</title>
		<link>http://www.bobbobel.com/smart-card-presentation-at-the-afitc/</link>
		<comments>http://www.bobbobel.com/smart-card-presentation-at-the-afitc/#comments</comments>
		<pubDate>Tue, 30 Aug 2011 16:02:50 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Access]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Bobel]]></category>
		<category><![CDATA[Identity]]></category>
		<category><![CDATA[HSBD-12]]></category>
		<category><![CDATA[Microsoft PKI]]></category>
		<category><![CDATA[PowerShell AD CMDLETS]]></category>
		<category><![CDATA[Safenet]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1123</guid>
		<description><![CDATA[Yesterday I had the opportunity to present at the Air Force Information Technology Conference 2011 on HSPD-12 and its impact on logical access control. While preparing for this session I realized I needed to re-visit Microsoft&#8217;s PKI (Public Key Infrastructure); especially changes in Windows 2008, Vista and Windows 7 strong authentication support. The first thing [...]]]></description>
			<content:encoded><![CDATA[<p>Yesterday I had the opportunity to present at the <a href="http://afitc.gunter.af.mil/">Air Force Information Technology Conference </a>2011 on HSPD-12 and its impact on logical access control. While preparing for this session I realized I needed to re-visit Microsoft&#8217;s PKI (Public Key Infrastructure); especially changes in Windows 2008, Vista and Windows 7 strong authentication support.</p>
<p>The first thing that struck me was how many good resources are available for learning Microsoft&#8217;s PKI. Back in 2000 when I first installed a Microsoft CA (Certificate Authority) there didn&#8217;t seem to be enough detailed information and over the past eleven years I have only had infrequent occasions to use the software. At this point I want to recommend Brian Komar&#8217;s book <a href="http://www.amazon.com/Windows-Server%C2%AE-Certificate-Security-ebook/dp/B004OR1Y0A/ref=sr_1_5?ie=UTF8&amp;qid=1314715186&amp;sr=8-5">Windows Server 2008 PKI and Certificate Security</a> (I got the Kindle version for about $39). I also wanted to mention Vadim Podans&#8217; white paper on PKI and using the Quest AD Commandlets to managed. You can download the <a href="http://www.quest.com/documents/landing.aspx?id=12189&amp;amp;technology=&amp;amp;prod=537&amp;amp;prodfamily=&amp;amp;loc=">white paper here </a>and you can get the latest version of the <a href="http://www.quest.com/powershell/activeroles-server.aspx" target="_blank">AD CMDLETS here</a>.</p>
<p style="text-align: center;"><a href="http://www.bobbobel.com/wp-content/uploads/2011/08/Safenet-CertInfo.png"><img class="aligncenter size-medium wp-image-1128" title="SafeNet Token Tools" src="http://www.bobbobel.com/wp-content/uploads/2011/08/Safenet-CertInfo-300x234.png" alt="" width="300" height="234" /></a></p>
<p>I also wanted to give a special thanks to Chen and John from <a href="http://www.safenet-inc.com/" target="_blank">SafeNet </a>for hooking me up with SafeNet middle-ware tools (above) and smart cards that I used for to prep for the session. The software was both intuitive and easy to deploy.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/smart-card-presentation-at-the-afitc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Delegation over mail enabled users and contacts only</title>
		<link>http://www.bobbobel.com/delegation-over-mail-enabled-users-and-groups-only/</link>
		<comments>http://www.bobbobel.com/delegation-over-mail-enabled-users-and-groups-only/#comments</comments>
		<pubDate>Thu, 18 Aug 2011 12:49:21 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Demo]]></category>
		<category><![CDATA[ActiveRoles Server]]></category>
		<category><![CDATA[Bob Bobel]]></category>
		<category><![CDATA[Delegation over mail enabled objects]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1118</guid>
		<description><![CDATA[The ActiveRoles product comes with Roles (a.k.a. Access Templates) that use the native permission model to provide delegation. To perform delegation you need to identify the Role, the Trustee (in this case an OU Admin) and the scope. The first two are simple as you just select an Access Template and a user or group [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>ActiveRoles</strong> product comes with Roles (a.k.a. Access Templates) that use the native permission model to provide delegation. To perform delegation you need to identify the Role, the Trustee (in this case an OU Admin) and the scope. The first two are simple as you just select an Access Template and a user or group while the third can also be simple if you understand how to define custom scopes using Managed Units.  In this video I will show you how to delegate managing email address over mail enabled users and contacts, but not mailbox enabled users or groups.</p>
<p><iframe src="http://www.youtube.com/embed/IiSD2979uSo?hl=en&amp;fs=1" frameborder="0" width="425" height="349"></iframe></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/delegation-over-mail-enabled-users-and-groups-only/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Setting msExchRequireAuthToSendTo during group creation</title>
		<link>http://www.bobbobel.com/setting-msexchrequireauthtosendto-during-group-creation/</link>
		<comments>http://www.bobbobel.com/setting-msexchrequireauthtosendto-during-group-creation/#comments</comments>
		<pubDate>Thu, 18 Aug 2011 08:24:18 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Bobel]]></category>
		<category><![CDATA[Demo]]></category>
		<category><![CDATA[ActiveRole Server]]></category>
		<category><![CDATA[Bob Bobel]]></category>
		<category><![CDATA[msExchRequireAuthToSendTo]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1111</guid>
		<description><![CDATA[I was working with a customer who wanted the option to set the msExchRequireAuthToSendTo attribute during mail enabled group creation. The challenge is that the native Exchange console always defaults this value to TRUE making it easy for the user to forget to un-check the value after the creation of the group. Using ActiveRoles Server [...]]]></description>
			<content:encoded><![CDATA[<p>I was working with a customer who wanted the option to set the msExchRequireAuthToSendTo attribute during mail enabled group creation. The challenge is that the native Exchange console always defaults this value to TRUE making it easy for the user to forget to un-check the value after the creation of the group. Using ActiveRoles Server I created a very-very simply way to accomplish this.</p>
<p><iframe src="http://www.youtube.com/embed/Cm36U_9Z9kM?hl=en&amp;fs=1" frameborder="0" width="425" height="349"></iframe></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/setting-msexchrequireauthtosendto-during-group-creation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Quest Software, Kirk, PowerGUI, PowerShell</title>
		<link>http://www.bobbobel.com/quest-software-kirk-powergui-powershell/</link>
		<comments>http://www.bobbobel.com/quest-software-kirk-powergui-powershell/#comments</comments>
		<pubDate>Mon, 01 Aug 2011 18:02:45 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[PowerShell]]></category>
		<category><![CDATA[Kirk Monroe]]></category>
		<category><![CDATA[PowerGUI]]></category>
		<category><![CDATA[Quest]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1106</guid>
		<description><![CDATA[Dmitry Sotnikov had a good post on Kirk Monroe leaving Quest&#8217;s PowerGUI team. Kirk will be missed. http://dmitrysotnikov.wordpress.com/2011/08/01/quest-software-kirk-powergui-powershell/]]></description>
			<content:encoded><![CDATA[<p>Dmitry Sotnikov had a good post on Kirk Monroe leaving Quest&#8217;s PowerGUI team. Kirk will be missed.</p>
<p><a href="http://dmitrysotnikov.wordpress.com/2011/08/01/quest-software-kirk-powergui-powershell/">http://dmitrysotnikov.wordpress.com/2011/08/01/quest-software-kirk-powergui-powershell/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/quest-software-kirk-powergui-powershell/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Top 10 Reasons ActiveRoles Beat the Competition</title>
		<link>http://www.bobbobel.com/top-10-reasons-activeroles-beats-the-competition/</link>
		<comments>http://www.bobbobel.com/top-10-reasons-activeroles-beats-the-competition/#comments</comments>
		<pubDate>Mon, 25 Jul 2011 09:00:56 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Bobel]]></category>
		<category><![CDATA[Active Directory Help]]></category>
		<category><![CDATA[Active Directory Provisioning]]></category>
		<category><![CDATA[ActiveRoles Server]]></category>
		<category><![CDATA[AD Permission]]></category>
		<category><![CDATA[bv-admin]]></category>
		<category><![CDATA[NetIQ DRA]]></category>
		<category><![CDATA[PowerShell AD CMDLETS]]></category>
		<category><![CDATA[Privilege Account Management]]></category>
		<category><![CDATA[Virtual Directory]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1087</guid>
		<description><![CDATA[I get one question frequently from both customers and colleges. &#8220;Why was ActiveRoles able to so easily beat the competition over the past seven years?&#8221; Unfortunately, there isn&#8217;t a single answer, rather it is a combination of design elements put into the product over time. Purpose Built for Active Directory -Unlike other solutions, ActiveRoles was [...]]]></description>
			<content:encoded><![CDATA[<p>I get one question frequently from both customers and colleges. &#8220;Why was ActiveRoles able to so easily beat the competition over the past seven years?&#8221; Unfortunately, there isn&#8217;t a single answer, rather it is a combination of design elements put into the product over time.</p>
<ol>
<li><strong>Purpose Built for Active Directory -</strong><span>Unlike other solutions, <span>ActiveRoles</span> was purpose built for Active Directory while other solutions were built to manage the Windows NT account database.  Because solutions originally built for Windows NT could only be retrofitted to perform AD management they are not able to take advantage of core AD features many of which are discussed in this brief.<br />
 </span></li>
<li><strong>Integrated and timely support for key Microsoft platforms -</strong><span>Active Directory, Exchange, ADLDS <span>SharePoint</span>, ADSI and <span>PowerShell</span> are critical platform components that must be supported. While other products may take years to support the latest versions of these products, <span>ActiveRoles</span> typically supports them on the day they are released or at a maximum of 60 days post release.<br />
 </span></li>
<li><strong>Compatibility with Active Directory&#8217;s Security Model &#8211; </strong><span>The Active Directory permission model is based on a set of Access Control Lists that link directory rights to delegate trustees allowing the delegated admin to exercise those rights to perform some task in AD. Unlike <span>ActiveRoles</span> Server, most solutions require the use of a proprietary permission that have little or no understandable correlation to AD rights they grant. When the <span>ActiveRoles</span> service starts, the service creates a <span>virtualized</span> version of the AD rights used in the <span>ACLs</span> and then extends the list with several virtual permissions. To the person administrating security in <span>ActiveRoles</span> they seen an almost identically list of rights with the same look and feel of the native AD rights. <span>ActiveRoles</span> Server also has the added advantage of combining these rights into Roles for clarity and accuracy of security assignment and easy delegation of administration. A side benefit of compatibility with the Active Directory Security Model is the vast knowledge available on how AD permissions work and which permissions are required to perform specific tasks.<br />
 </span></li>
<li><strong>Compatibility with Active Directory Service Connection Points &#8211; </strong><span>A standard Active Directory service known as Service Connection Points (<span>SCPs</span>) allow applications to inform Active Directory of the applications presence in the enterprise. It is important to note that <span>SCPs</span> require no agents, customer configuration or changes to Active Directory. When the <span>ActiveRoles</span> Service executes it registers an SCP so that any console or web UI can locate the service instantly.<br />
 </span></li>
<li><strong>Compatibility with Active Directory&#8217;s DirSync service &#8211; </strong><span>A standard Active Directory services known as <span>DirSync</span> allow applications to instantly see what changes are happening within AD. This is the same service Domain Controllers use to exchange change information to determine what items need to be replicated. . It is important to note that the <span>DirSync</span> service requires no agents, customer configuration or changes to Active Directory. The <span>ActiveRoles</span> service listens to the <span>DirSync</span> service for changes made directly to Active Directory that may require <span>ActiveRoles</span> to perform some action such as enforce a group&#8217;s membership or send a change notification.<br />
 </span></li>
<li><strong>Virtual Unified Schema &#8211; </strong><span>Unlike other solutions that use a fixed schema and won&#8217;t recognize schema extensions, <span>ActiveRoles</span> uses a virtual unified schema built from the <span>schemas</span> of the domains being managed. When the <span>ActiveRoles</span> service starts it reads the schema of each domain being managed and adds that schema the <span>ActiveRoles</span> unified virtual schema. This unified virtual schema also includes any schema extensions that may be present in a particular domain so that applications that require data be populated during user provisioning or cleared during user <span>deprovisoning</span> can be supported. <span>ActiveRoles</span> also adds a set of virtual attributes to allow for more granular delegation over attributes or to allow other data not stored in AD to be associated with an object.<br />
 </span></li>
<li><strong>Real-time vs. Cached Data -</strong><span>To avoid the chance that two administrators open an AD object and view different information the retrieval of AD data must be done without caching of the data. Unlike many solutions that either load object data into a cache or into a separate database before an administrator accesses the object,  the <span>ActiveRoles</span> service retrieves the data in real-time.<br />
 </span></li>
<li><strong>Security Integrated <span><span>Workflow</span> </span>-</strong><span>The role based delegation of administration provided by <span>ActiveRoles</span> Server not only allows the customer to control what AD operations each administrator, help desk admin or end user can perform it also provides the security context for change approval and <span>workflow</span>. By integrating a <span>workflow</span> engine and <span>workflow</span> editor directly into <span>ActiveRoles</span>, the customer avoids the need to configure and maintain multiple products and maintain multiple delegation models.<br />
 </span></li>
<li><strong>Unified Storage -</strong><span>Unlike other solutions that may require both Microsoft SQL and Microsoft AD LDS or Microsoft Access, <span>ActiveRoles</span> requires only Microsoft SQL Server for operation. Both <span>ActiveRoles</span> Configuration and reporting utilize Microsoft SQL Server. Less moving parts make <span>ActiveRoles</span> is simpler to deploy and maintain.<br />
 </span></li>
<li><strong>Embedded Extensibility -</strong><span> Because no off the shelf product will meet every need a customer may have the ability for the solution to be extended easily and in a maintainable way. In addition to both an external ADSI and <span>PowerShell</span> interface, <span>ActiveRoles</span> provides an embedded script editor, script library directly in the product so that the system can run a script in response to some event such as when a user performs an operation in Active Directory.</span></li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/top-10-reasons-activeroles-beats-the-competition/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>bv-Admin EOL &#8211; RIP</title>
		<link>http://www.bobbobel.com/bv-admin-eol-rip/</link>
		<comments>http://www.bobbobel.com/bv-admin-eol-rip/#comments</comments>
		<pubDate>Fri, 08 Jul 2011 10:07:54 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Bobel]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[ActiveRoles Server]]></category>
		<category><![CDATA[bv-admin]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1082</guid>
		<description><![CDATA[Some of you may not have heard that Symantec&#8217;s bv-Admin was officially end-of-lifed and is no longer supported as of early in 2011. Originally a Windows NT management tool, later it was retrofitted to manage AD. While bv-Admin had several ground breaking features for its time, the acquisition of Bindview, development challenges and competitive pressures appear [...]]]></description>
			<content:encoded><![CDATA[<p>Some of you may not have heard that Symantec&#8217;s bv-Admin was officially end-of-lifed and is no longer supported as of early in 2011. Originally a Windows NT management tool, later it was retrofitted to manage AD. While bv-Admin had several ground breaking features for its time, the acquisition of Bindview, development challenges and competitive pressures appear to have taken their toll.  <a href="http://www.symantec.com/business/support/index?page=content&amp;id=TECH131120">http://www.symantec.com/business/support/index?page=content&amp;id=TECH131120</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/bv-admin-eol-rip/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

