Monday, 6 January 2014

First Time and Subsequent User Experience with Multi-factor Authentication via Mobile Phone

In a previous article I mentioned about ‘How to Setup Azure Multi-Factor Authentication.

1. After the user has successful provided the correct password during log on through the Office 365 portal page, the following message will be displayed. 'Your admin has required that you set up this account for additional security verification.'

In this article I will continue where I left off.  After a user has been enabled for multi-factor authentication, the steps that outline the user's experience are as follows:

User will need to click the 'Set it up now' button, as shown in below Figure. Remember, this is option is only configured during the first time access however can be changed afterwards by the administrator as required.

1time1

 

2. After the user has clicked Set it up now, the option to have the Azure Multi-Factor Authentication Service call a phone number or text a code to a mobile phone will appear. In this window the user can select the phone numbers that the service will use.

1time2

 

3. After specifying the contact method the user is required to sign in with the password. To complete the Additional Security Verification click on verify to receive the 6 digit security code.

1time4

 

4. Then enter the 6 digit code sent to your mobile phone and Verify. Click Next after successful verification.

1time5

 

5. Complete Additional Security Verification process by following the steps below.

1time6

 

6. Click on Generate App password

1time7

1time8

If call a phone number is chosen as opposed to text a code to a mobile phone; the Azure Multi-Factor Authentication Service will call the phone number.  In this scenario the user is required to answer the call and, should hear the following message: "Thank you for using the Microsoft verification system. Press the pound key to finish verifying your account." The user should press the pound (#) key on the phone. The following message will be heard: "Your account has been verified. Goodbye." The user will be notified on success.

If the user is not able to do this, he/she will receive a verification failure dialog box, but will have the option to click the 'Retry' button.

ecsword

How to Setup Azure Multi-Factor Authentication

How to Setup Azure Multi-Factor Authentication

Multi-Factor Authentication helps safeguard access to your data and applications. Before access is granted users must authenticate by using a mobile app or by responding to an automated text message or phone call.

To set up Azure Multi-Factor Authentication, follow the following steps:

1. Sign in to the Office 365 Admin Centre with your organisational account. Select users and groups, and then click Set up for Set Multi-factor authentication requirements, as shown in below Figure.


smfa1


2. On the multi-factor authentication page, you can select the types of users using the drop-down box, and then select the box of the user that you want to configure for multi-factor authentication.smfa2


Just so you know; multi-factor authentication can be activated for free administrators and for a specified fee for regular users. At the time of writing this document the pricing was as follows.





  • Pay-as-you-go Plan



    • Per User - £1.28/month (unlimited authentication)


    • Per Authentication - £1.28/10 authentications




  • 6 or 12-month Plans



    • Per User - £0.87 - £1.02/month (unlimited authentication)


    • Per Authentication - £0.87 - £1.02/10 authentications




You can receive discount of 20-32% when you make a monthly commitment to Windows Azure for 6 or 12 months. Information on the pricing can be found from the following link. http://www.windowsazure.com/en-us/pricing/details/multi-factor-authentication/


3. Let’s carry on with the configuration. When you select a user, you can see the user's name and two other items under quick steps on the right pane. Click Enable in the action items.


smfa3


 4. On the Enable multi-factor authentication page, click enable multi-factor auth.


smfa4


5. When the activation for the selected user(s) is done, a dialog box will inform that the updates are successful, as shown in below Figure. Multi-factor authentication is now enabled for the selected account(s). Click close.


smfa5


There you go. You have successfully enabled Windows Azure Multi-factor Authentication.


In my next article I will show the First Time and Subsequent User Experience with Multi-factor Authentication with Mobile Phone and Mobile App.


ecsword


 

Thursday, 2 January 2014

Error in proxy URL. Must be HTTP error in Ubuntu

export "http_proxy=user:pass@http://10.107.1.252:8080/"

I have also tried different combinations by playing quote marks and etc. Then I found out the correct syntax should be like below, the key here is the http:// before username as we use is to pass user/pass while opening URLs in browsers;
export http_proxy="http://domain\\user:password@10.107.1.252:8080"

if you want to make it permanent you can add that line to your etc\environment file. You can also check environment variables by running the export command directly or running export | grep "proxy" command to filter values with "proxy

Tuesday, 17 December 2013

PHP Warning: PHP Startup: Unable to load dynamic library '/usr/lib/php5/20090626+lfs/intl.so'

 

Bir Linux sunucumda local mail gönderimi için bir servis kurduktan sonra aşağıdaki hataları otomatik olarak mail adresime almaya başladım.

[ -x /usr/lib/php5/maxlifetime ] && [ -d var/lib/php5 ] && find /var/lib/php5/ -depth -mindepth 1 -maxdepth 1 - type f -cmin +$(/usr/lib/php5/maxlifetime) ! -execdir fuser -s {} /dev/null \; -delete

PHP Warning: PHP Startup: Unable to load dynamic library '/usr/lib/php5/20090626+lfs/intl.so' - /usr/lib/php5/20090626+lfs/intl.so:cannot open shared object file: No such file or directory in Unknown on line 0

Sunucuda /usr/lib/php5# cd 20090626+lfs/ klasöründe intl.so dosyasını göremeyince, eklemek için aşağıdaki komutu kullanarak sorunu çözdüm. Umarım size de yardımcı olur.

sudo apt-get install php5-intl

 

Friday, 13 December 2013

Remote Access Service Start Errors on Windows Server 2008 / FF TMG

If you try to enable VPN client access to provide VPN connections or to enable RRAS for DHCP relay agent etc.

And if RRAS service cannot start? You might have errors below in your event viewer

  • 20103 : Unable to load C:\Windows\System32\iprtrmgr.dll.

  • 7024 : The Routing and Remote Access service terminated with service-specific error A device attached to the system is not functioning.

  • 20103 : Unable to load C:\Windows\System32\iprtrmgr.dll.

  • 21119 : The Remote Access Service configuration for VPN could not be completed. As a result, the Remote Access Service may be stopped.


The steps below solved my problem.

Unbind IPv6 from you NICs

  1. Backup & Delete HKEY_LOCAL_MACHINE\System\currentcontrolset\services\remoteaccess\routermanagers\IPV6

  2. Backup & Delete HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\TCPIP6\Parameters\DisabledComponents

  3. Restart the server , start the RRAS.


Hope it helps.

Tuesday, 10 December 2013

System Center 2012 R2 Configuration Manager Toolkit

A useful announcement from J.C. Hornbeck | Solution Asset PM | Microsoft GBS Management and Security Division

( http://www.microsoft.com/en-us/download/details.aspx?id=36213 )

The Microsoft System Center 2012 R2 Configuration Manager Toolkit contains fifteen downloadable tools to help you manage and troubleshoot Microsoft System Center 2012 R2 Configuration Manager. The following list provides specific information about each tool in the toolkit.

Note: Items with an * are new in the R2 Toolkit and require Microsoft System Center 2012 R2 Configuration Manager for full functionality.

Server Based Tools

  • * DP Job Manager - A tool that helps troubleshoot and manage ongoing content distribution jobs to Configuration Manager distribution points.

  • * Collection Evaluation Viewer - A tool that assists in troubleshooting collection evaluation related issues by viewing collection evaluation details.

  • * Content Library Explorer - A tool that assists in troubleshooting issues with and viewing the contents of the content library.

  • Security Configuration Wizard Template for Microsoft System Center 2012 R2 Configuration Manager - The Security Configuration Wizard (SCW) is an attack-surface reduction tool for the Microsoft Windows Server 2008 R2 operating system. Security Configuration Wizard determines the minimum functionality required for a server's role or roles, and disables functionality that is not required.

  • Content Library Transfer – A tool that transfers content from one disk drive to another.

  • Content Ownership Tool – A tool that changes ownership of orphaned packages (packages without an owner site server).

  • Role-based Administration Modeling and Auditing Tool – This tool helps administrators to model and audit RBA configurations.

  • Run Metering Summarization Tool - The purpose of this tool is to run the metering summarization task to analyze raw metering data


Client Based Tools

  • Client Spy - A tool that helps you troubleshoot issues related to software distribution, inventory, and software metering on System Center 2012 Configuration Manager clients.

  • Configuration Manager Trace Log Viewer – A tool used to view log files created by Configuration Manager components and agents.

  • Deployment Monitoring Tool - The Deployment Monitoring Tool is a graphical user interface designed help troubleshoot Applications, Updates, and Baseline deployments on System Center 2012 Configuration Manager clients.

  • Policy Spy - A policy viewer that helps you review and troubleshoot the policy system on System Center 2012 Configuration Manager clients.

  •   Power Viewer Tool – A tool to view the status of power management feature on System Center 2012 Configuration Manager clients.

  • Send Schedule Tool - A tool used to trigger a schedule on a client or trigger the evaluation of a specified DCM Baseline. You can trigger a schedule either locally or remotely.

  • Wakeup Spy – A tool that provides a view of the power state of Configuration Manager client computers and which operate as managers or manages.

Wednesday, 4 December 2013

SCCM Client : Failed to find the certificate in the store error

 

If you see the entries below in your ClientIDManagerStartup.log file

RegTask: Failed to get certificate. Error: 0x80004005 ClientIDManagerStartup 04/12/2013 11:30:29 5992 (0x1768)  
Error initializing client registration (0x80040222). ClientIDManagerStartup 04/12/2013 11:30:29 5992 (0x1768)  
RegTask - Executing registration task synchronously. ClientIDManagerStartup 04/12/2013 11:30:42 1276 (0x04FC)
Failed to find the certificate in the store, retry 1. ClientIDManagerStartup 04/12/2013 11:30:42 1276 (0x04FC)  
Failed to find the certificate in the store, retry 2. ClientIDManagerStartup 04/12/2013 11:30:42 1276 (0x04FC)  
Failed to find the certificate in the store, retry 3. ClientIDManagerStartup 04/12/2013 11:30:42 1276 (0x04FC)  
Failed to find the certificate in the store, retry 4. ClientIDManagerStartup 04/12/2013 11:30:42 1276 (0x04FC)  
Failed to find the certificate in the store, retry 5. ClientIDManagerStartup 04/12/2013 11:30:42 1276 (0x04FC)  
RegTask: Failed to get certificate. Error: 0x80004005 ClientIDManagerStartup 04/12/2013 11:30:43 1276 (0x04FC)

and SCCM client repair didn't help to fix you client communication.

You can try to do these to fix it, 1.Stop SMS Agent Host Service 2.Delete C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\19c5cf9c7b5dc9de3e548adb70398402_50e417e0-e461-474b-96e2-077b80325612 3.Start SMS Host Agent Service and monitor the log file ClientIDManagerStartup.log  ! : New 19c.... certificate file should also have created automatically in the folder above.

You should be able to see informational log entries if it helped, like

Read SMBIOS (encoded): 54006F002000420065002000460069006C006C00....  
Evaluated SMBIOS (encoded): 54006F002000420065002000460069006C00....  
No SMBIOS Changed ClientIDManagerStartup 04/12/2013 11:33:29 2212 (0x08A4)  ....

If you are still seeing same errors, you can also try to change permissions of C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys by adding Local System.

Ps. The cert. path in XP systems is C:\Documents and Settings\all users\ApplicationData\Microsoft\Crypto\RSA\MachineKeys\