zonemap registry on IE11 on server 2016

Q: zonemap registry on IE11 on server 2016

if I open IE on a 2016 server and add http://faketest to the intranet sites, it populates in the registry

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains
same as it does on any previous OS.
but I have a GPO that pushes some stuff to that location (actually to both the Domains and EscDomains locations) with Preferences. the registry keys are all identical on my 2016, 2012 R2, 2008 R2 servers. the sites all work as expected
on 2012 and 2008, but on 2016, the sites do not appear in IE's Intranet Sites GUI and are not being treated as intranet sites.
I would guess that 2016 uses a different location, but my test of manually adding a site to the GUI intranet sites proves otherwise. what am I missing?

how i can uninstall or disable IE11 on Windows Server 2016?

When i am opening my intranet websites which have security prompts
from IE11 in windows server 2016 as shown below and passing the credential,its not responding after clicking OK button.

Request advise on the same.

Thank you.


Visio files are received as attachments in Outlook 2016. Visio Viewer 2016 and IE11 are also installed on Windows 10 (1607).
Previewing the Visio file (VSD in this case) is successful. However, when you try to open the Visio file, IE11 attempts to open it (as expected) but only displays a blank page.
Does anyone know if there is a fix for this issue?   Other articles suggest that Visio Viewer 2016 does not support IE11.

I am having the KMS Server with Server 2012 KMS Key,which is hosted on Windows server 2012 R2.

We need to update the KMS Server 2K12 Key to 2K16 KMS Key, Is there any way to Get the detail that the key will activate these OS Versions?

MBAM Report Feature Error Alert

The Problem:
The July 2016 Cumulative Security Update for IE11 (KB3170106) Update Fails to Install, giving Error code 80073712. All other updates installed successfully.

AFAIK no malware or other suspicious symptoms, besides a random CHKDSK on boot up a few days / week ago, where it had to repair a tonne of file indexes etc. Could be related, otherwise all seems fine.

Operating System:
Windows 7 Ultimate x64 SP1.

Fully updated besides KB3170106 (This update. Fails) and KBs 2952664, 3021917, 3068708 and 3080149, which I have hidden (Just telemetry crap I believe?).

What I've Tried:
? CHKDSK (Now comes back clean). - Log Attached.

? SFC /Scannow (Detects errors, unable to repair). Also tried this from Safe Mode, and the Repair Mode Command Prompt on my Windows Boot disk, same result. - Log Attached.

? System Update Readiness Tool - (Detects errors, unable to repair) - Log Attached.

? Downloading 2 of the updates that errored in SURT, placed them in Windows\CheckSur\packages directory, which fixed two of the error lines, but still many errors left, as well as errors with the .mum and .cat files of those are updates still present. (This one is strange as one of the updates is KB2952664 which I had hidden and NOT installed..). The log I have attached is from a re-run after this one.

? Downloading the KB3170106 update manually - Still errors. (Said successful once, but obv wasn't).

Resources Available:
? Full Admin access to the problem PC
? A separate Windows 7 Pr... Read more

A:KB3170106 (July 2016 IE11 Security Update) Fails with Error 80073712

I can confirm the problem on Windows 7 Professional x64. We currently have 2 machines on the network with the same error.
With all the common ways (prev post) i was not able to fix it.

After installing the Security Updates from the October 2016 Rollup/Quality Update. IE crashes when you open an .eml file. An application hosting a WebBrowser control (ieframe.dll) also crashes when doing that. This happens on Win7 and Win10 (maybe others
I couldn't test).
Here is the error: 
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<Provider Name="Application Error" />
<EventID Qualifiers="0">1000</EventID>
<TimeCreated SystemTime="2016-10-21T12:47:19.000000000Z" />
<Security />
<Data>C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE</Data>
<Data>C:\Windows\SysWOW64\ntdll.dll</Data> ... Read more

I'm going to buy a new license of one of these product, so any suggest please?
I have used Bitdefender, Avast, Kaspersky ( about 3 years ago), I haven't used Norton and Trend Micro.

A:KIS 2016 vs NIS 2016 vs BIS 2016 vs Avast IS 2016 vs Trend Micro IS 2016

Out of all these,and your prerequisites,I would go with Kaspersky!
PS:This is from personal experience,and other members may have varying opinions!!

We are in testing phase for IE9 to IE11 migration in our environment.

On test system we found that on gpupdate the value of registry "AcceptLanguage" in
HKCU:\Software\Microsoft\Internet Explorer\International becomes blank, and this is not acceptable since some of our applications are dependent on this valueEven if the entry is removed or set with a value, upon gpupdate the entry is reappearing with a blank value.
We have checked all linked GPOs for users & computers and scripts for any settings affecting this value and found noneThe registry was unaffected when the same computer had IE9 and group policy was refreshed
Any help would be greatly appreciated

A:IE11 - registry value for AcceptLanguage becomes blank

Thanks for your time Kate Li, due to policy restriction I'm unable to post logs here, however I was able to find the cause of this problem and here it is:
Within one of the Group Policy Preference, we created a new "Internet Settings for IE 10" for configuring the Home page, and few other settings, additionally we disabled all the other settings (F8 for Red).
We disabled all items with within the language preference dialog as well (there isn't any red dotted line on the list of languages), and this is the culprit, if you configure any of the settings here, there's no way you can disable configuration of the language
list (not atleast through the interface, but can with direct modification in the XML) and have opened a case with MS support

GPO works on first login to the computer
but does not change the value of: HKEY_CURRENT_USER\Software \ Microsoft\ Windows \ CurrentVersion\ Internet Settings\Zones \2\1,201.
Tested also in IE10 but
the policy does exactly the same thing there. But Is
the user profile already on the computer
it manage to change the value of the key
The key value is set to be allowed for the trusted zones.
I'll hope tou understand and if it should be under Another category so put it there.


Spybot found and deleted "zonemap.ranges" for which it restarted system to do, now runs a scan and comes back clean, as well as adaware and nod32,
Could someone please check my log to make sure, and any ideals how I caught this, I thought my system was pretty secure.

Thank you.

Logfile of HijackThis v1.99.1
Scan saved at 08:44:57, on 01/02/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\WinFax\WFXMOD32.EXE
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Ahead\I... Read more


some more info

In the register I found even hundreds of strings with this kind of links.

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\beautypornpost.com

Also many with "casino"

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\casino-onlines.net

Since I didn't trust it, I removed them, but some time later again hundreds showed up.
Found out that Spybot may use this strings?
Are they safe or should I destroy these?

If safe, how to restore that list?

A:Zonemap Domains

ZoneMap\Domains shows the sites set as 'Trusted Sites' in IE (fyi, I only got paypal and my bank in that list). You very probably got some malware that needs to be found and eradicated.

I'm trying to set up a desktop when any user opens IE11, both check marks would be enabled and set to compatibility mode.  Is there a way I can modify the registry file to ensure that the check marks are there?
Thank you,

Read other answers

We have deployed IE11 via IEAK and have a proxy set which currently set to return direct for all sites. This means IE is seeing all external sites in the intranet zone due to the setting 'include all sites that bypass the proxy server' being enabled. If
I manually untick this then everything works as all external sites are in the internet zone and the setting is permanent.
However, I need to deploy this setting site wide and the group policy "Windows Components/Internet Explorer/Internet Control Panel/Security Page - Intranet Sites: Include all sites that bypass the proxy server" (both computer and user) set to disable
only greys out the box unticked but does not actually move external sites into the internet zone.
I've tried using GPP to delete the registry key HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Proxybypass which does work but as soon as I re-launch IE the setting is written back with the value 1 and it is back in the wrong state
Using process monitor I can see it is iexplore.exe that sets this key back to 1 on launch and when I manually untick the box all it does it delete the Proxybypass key and nothing else. Has anyone seen this before and managed to work around it?  It seems
very similar to

Now! ESET has just released their newest security suite: ESET Smart Security 9 (2016 Edition). These products are on the top of security suites which are produced by giants on security companies. Most of them released 2016 editions of their products. I want to compare on their newest products with new features (such as on ESET: Banking Protection, Bitdefender: Ransomware Protection and new Firewall, etc...) and some enhanced features.

And now, which is your choose for your security? Please let me know your opinion!

A:Battle: Kaspersky IS 2016 vs ESET Smart Security 2016 vs Bitdefender IS 2016 vs Emsisoft IS 10

its hard choice choose between Eset,Kaspersky and Emsisoft.
in fact i never test Eset 2016, but i tested kaspersky and Emsisoft, Kaspersky 2016 really go lighter than Emsisoft(now i am Emsisoft useres)
by your budget and your interest u can choose Emsisoft or kaspersky.

Logfile of HijackThis v1.99.1Scan saved at 2:10:04 PM, on 10/10/2005Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\csrss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeC:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Common Files\Symantec Shared\ccProxy.exec:\PROGRA~1\mcafee.com\vso\mcvsrte.exeC:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exeC:\WINDOWS\system32\wdfmgr.exeC:\WINDOWS\wanmpsvc.exec:\PROGRA~1\mcafee.com\vso\mcshield.exeC:\WINDOWS\System32\alg.exeC:\WINDOWS\system32\wscntfy.exeC:\WINDOWS\Explorer.EXEC:\PROGRA~1\mcafee.com\vso\mcvsshld.exeC:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exec:\program files\mcafee.com\agent�... Read more

A:Hjt Log - Neeed Coolwwwsearh, Hkey Zonemap Fixes


Sorry for the late reply, The forum is really busy.

If you still need help, please start with posting a new hijackthislog in this thread, because this log is already a couple of days old and things can be changed.
I'll take a look at it then.

We have IE11's Enterprise Mode enabled and working. I have been given two new URLs to add to the sitelist, but when I add them and apply to a test system, the value in HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\EnterpriseMode\CurrentVersion
does not increment to the new version number; instead the value goes blank.
The format for the new URLs differs slightly from existing entries.
appname.domain.com - this is the format for existing entries and works
app.domain.com/apps/appname - this is the format for the new entries.  Adding either of the two new URLs that use this format causes the VersionNumber value to go blank.
Any ideas on why this would happen?  We are using the v.1 XML schema.

Read other answers

I have a 2008 R2 Standard, 64 bit, 32 GB ram,  that will not install IE11. Plenty of disk space. Windows updates gets applied every month but IE is the pink elephant in the room.
Here is what I have:
"Internet Explorer did not finish installing  For information see the Internet Explorer Troubleshooter. This link is also on your desktop"
When I click the link in the above pop up, I get
application not found.
Looking in event viewer:
In setup - Package KB2841134 failed to be changed to the Installed state. Status: 0x80070002.
In Application Event 1001 -
Fault bucket , type 0
Event Name: CbsPackageServicingFailure2
Response: Not available
Cab Id: 0
Problem signature:
P1: 6.1.7601.23505
P2: Microsoft-Windows-InternetExplorer-Package-TopLevel
P3: 11.2.9600.16428
P4: amd64
P5: unknown
P6: 80070002
P7: Stage
P8: Resolved
P9: Installed
P10: DISM Package Manager Provider
Attached files:
These files may be available here:
Analysis symbol:
Rechecking for solution: 0
Report Id: cfef9c92-d78a-11e8-bea6-6eae8b6019b9

Read other answers

I have installed the Server 2016 Technical Preview 5 and converted my account to a MS account. Id like to set a pin to logon but don't have the option. The option to add a PIN should be here AFAIK.

Is it possible? I've tried setting "Turn on a convenience PIN sign-in" which it says is deprecated and "Use Microsoft passport for work" (which supersedes it) in gpedit.msc but still don't get the option.

It seems from this blog you should be able to it but I can't figure out how Manage identity verification using Windows Hello for Business (Windows 10)

Read other answers

I cannot seem to get HTML5 video working in IE11 on Server 2012 R2, in RDSH mode (Remote Desktop Session Host).
I have the Desktop Experience feature installed, and have tried adding the sites (e.g. youtube, vimeo) to trusted sites and cranked the security down to the lowest (medium-low) for trusted sites but nothing. I don't really want to have to use trusted
sites anyway...
On YouTube I am getting the HTML5 right-click menu over the video area, but no video plays - just a buffering symbol spinning and then a black area where the video should be.
I tried changing the user agent to IE10 via the F12 tools, but no change.
I ran the suite of tests from peacekeeper.futuremark.com and most of the stuff worked, e.g. all the animations, but none of the video, especially videoCodecH264 showed as N/A.
www.w3.org/2010/05/video/mediaevents.html is giving "unknown error" in the video playback window.
I can make YouTube work by adding it to compatibility view, where it then drops back to using Flash player. This does not work for Vimeo.
I have minimal policy settings set on these servers at the moment.
Any suggestions would be most welcome, thanks in advance.

A:No HTML5 video in IE11 on Server 2012 R2

I think it's this:
Even logged on as an administrator, having IE ESC turned on for Users causes the HTML5 stuff to break. If I change the setting for Users to Off and restart IE, HTML5 video works fine. Tested with Vimeo and YouTube so far, both working.
Change the setting back to Users = On and restart the browser, broken again. So that seems fairly conclusive.

Read other 21 answers

Hello everybody,
I have a Question about IE11:
How can I uninstall IE11 in Windows 2012 R2?

I cant find it in features or installed updates...

Thanks for your help!


A:How can I uninstall IE11 from Windows Server 2012 R2?

Based on my knowledge, in Windows server 2012 R2, IE 11 is preinstalled, which cannot downgrade to IE 10.

Thanks for your understanding.We
are trying to better understand customer views on social support experience, so your participation in this
interview project would be greatly appreciated if you have time.
Thanks for helping make community forums a great place.

I have a Windows Server 2012 R2 with users that RDP in to run Quickbooks desktop software.  In quickbooks, they use internet explorer embedded to open an XML file from the local file system with a stylesheet defined.  On the server, internet explorer
always wants to download the XML file and not view the XML using the stylesheet.
Even if I open IE 11 on the server, and try to open the XML file outside quickbooks, it always wants to download and not show the xml file in IE 11.
I have enhanced security turned off for admin and users.
I have tried many different settings for setting this as trusted or intranet without success.
How do get IE 11 to present the XML using the stylesheet?
This is start of the XML file that IE is to open from the local file system:

<?xml version="1.0" encoding="ISO-8859-1"?><?xml-stylesheet type="text/xsl" href="C:\Program Files (x86)\Intuit\QuickBooks 2020\components\payroll\ROE.xsl"?><ROEHEADER FileVersion="W-2.0" SoftwareVendor="Intuit Inc." ProductName="QuickBooks Payroll" ProductVersion="30">

Read other answers

I've recently installed KB4467684 on my 2016 Datacenter SQL server and now when I try to login it just goes black. No GUI no errors. I've rebooted, I've tried safe mode, I've cold powered down and booted up and nothing fixes this. This is my 2nd server 2016
SQL server VM I've installed it on and both have the same issues. I have a Server 2016 datacenter SQL box that I hadn't installed this on yet and it works just fine. Last update it has is KB4467691. 

Anyone else seeing this? Or what else can I do to fix it? I've even tried stopping SQL server and agent to see if that would do it, but no difference. Please help I do not want to rebuild this SQL box. Thankfully its not quite in production yet but this
will put us behind if I have to redo the OS. 

Thank you!

We are experiencing an issue when trying to harden our Server 2016 OS base build.
All patching has been applied, however 'KB4022715 Windows Server 2016 June 2017 Cumulative Update' still appears on the Nessus vulnerability scans with a CVSS rating of 10.0.
I have looked around and can't see that there are any associated registry changes that are required alongside this patch and trying to install the .msu file manually returns "Not applicable to this computer".
The patch itself has been superseded by the following patches since...
2017-06 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4022723)
2017-07 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4025334)
2017-07 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4025339)
2017-08 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4034658)
2017-08 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4034661)
2017-08 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4039396)
2017-09 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4038782)
2017-09 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4038801)
2017-10 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4041688)
2017-10 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4041691)
2017-11 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4048953)
2017-11 Cumula... Read more

I have one machine running Windows XP and I am unable to make a connection via RDP to Windows Server 2016.
I have managed to make successful connection to Windows 2012 and even Windows 10 with latest build.

I have edited these registry keys
-adding tspkg
-adding credssp.dll
Also updated RDP client on winXP to 7.0 enviroment

I have tried 2 different machines with 2016 system.
The connection is not refused by any error (EventViewer is empty on both machines). RDP ask for credentials and then show message "Cant connect to the remote computer try it later" 
Do you have any ideas how to solve it ? 

Thanks for any help

I bought a pc without os installed, then bought an oem server license, where do I get the activation key from?

Read other answers

I'm having an issue customizing the Start Page registry key in Windows Server 2019 (this method works fine in 2016) I would load C:\Users\Default\NTUSER.DAT and add \Software\Microsoft\Internet Explorer\Main\Start Page REG_SZ "Company specific URL"
and when a new user logs in they'd get the "Company specific URL" but with Windows Server 2019 this isn't working.
I have also tried adding "First Home Page" and "Default_Page_URL" and it doesn't make a difference, it seems some sort of mini setup is configuring the registry keys and ignoring or overwriting what I entered into NTUSER.DAT from the
Default user profile.
I've also got IE Enhanced Security Configuration disabled for Admins and Users along with the following other registry keys set that all are working fine.
[HKEY_USERS\DefaultUser\Software\Microsoft\Internet Explorer\Main]
"Friendly http errors"="no"

[HKEY_USERS\DefaultUser\Software\Microsoft\Windows\CurrentVersion\Internet Settings]

[HKEY_USERS\DefaultUser\Software\Policies\Microsoft\Internet Explorer\Main]

Wondering if anyone has found a workaround or missing key that also needs to be set, thanks.

I have an application running .NET Framework 4.7.2 which we have recently started migrating onto Windows Server 2019 servers. We have started receiving reports of issues in Internet Explorer 11 having issues with controls (which we can replicate). Some of
the errors we see in the console include.

'WebForm_FireDefaultButton' is undefined
'WebForm_SaveScrollPositionSubmit' is undefined
'WebForm_DoPostBackWithOptions' is undefined

When an app pool recycle is performed on the application, the issue seems to go away for a period of time, but does return.

I recently came across the following article in which the symptoms appear to be very similar, but for a previous version of Windows Server.


Has anyone else experienced similar issues with software running on Windows Server 2019 accessed with IE11?

==================================================================== 00:00.000: Started: 2016/03/14 (Y/M/D) 20:21:04.691 (local) 00:00.000: Time Format in this log: MM:ss.mmm (minutes:seconds.milliseconds) 00:00.000: Command line: "C:\Windows\SoftwareDistribution\Download\Install\IE11-Windows6.1-x64-en-us.exe"
/WSUS 00:00.000: INFO: Setup installer for Internet Explorer: 11.0.9600.16428 00:00.000: INFO: Previous version of Internet Explorer: 8.0.7601.19104 00:00.000: INFO: Checking if iexplore.exe's current version is between 11.0.9600.0... 00:00.000: INFO: ...and 00:00.000: INFO: Maximum version on which to run IEAK branding is: 00:00.000: INFO: iexplore.exe version check success. Install can proceed. 00:00.000: INFO: Operating System: Windows Server: 6.1.7601 (Service Pack 1) 00:00.000: INFO:
Trying to extract ID: SetupDownloadList.txt (0) as "SetupDownloadList.txt" 00:00.000: INFO: Trying to extract ID: HardwareBlockingList.xml (0) as "HardwareBlockingList.xml" 00:00.000: INFO: Trying to extract ID: 7006 (0) as "IE11-neutral.Extracted.cab"
00:00.125: INFO: Trying to extract ID: 5501 (1033) as "Spelling_en.msu" 00:00.125: INFO: Extracted Spelling dictionary for en to C:\Windows\TEMP\IE1B579.tmp\Spelling_en.msu. 00:00.125: INFO: Trying to extract ID: 5502 (1033) as "Hyphenation_en.msu"
00:00.125: I... Read more

What are the prerequistes to install ie11 on windows server 2008 r2 SP1
I have installed pre-requisites for IE11-Windows6.1-KB2956283-x64 but still not able to install this patch

pavan G Accenture...

I needed to install .NET 3.5 on Server 2016 but have hit all of the roadblocks and need help. Here is what I have tried so far...

I tried to add the feature via the server manager but it ended with code 0x80070002. I did have to provide a path to the sources\sxs folder for the cab file which I expected but that didn't help.I tried using the DISM powershell command to add the feature, both using the source location and also using /All so that it downloads the files from Windows Update. The end result was the same as #1 attempt - 0x80070002.I made sure all updates for the OS have been applied and that updates for 'other Microsoft products' was checked. this made no change in the error.I checked the installed packages via powershell and it shows 3.5 as removed, which again is expected for Server 2016 as they intentionally left it out but provided the cab file in the install media.I have executed a clean sfc /scannow with no errorsI have run a clean dism package commandI have tried installing under a fresh admin user profileI have researched for around 3 hours on the forums so I look forward to the various input
I have uploaded both the DISM and CBS logs. I started fresh with both logs so they contain only details related to a single attempt t install via the server manager.
Thanks for the help!

Hi all, 

I need to enable RC4 cipher on Server 2016 to communicate with a legacy system in a corporate environment. 

I have enabled
RC4 128/128 
RC4 40/128
RC4 56/128
RC4 64/128 

with Dword value as 1 in regedit, yet I still cannot communicate with the device over https am I missing a something here or is there additional steps involved?

I was wondering if there are any known issues or any compability problems if I want to run windows 2016 Server on a Lenovo ThinkPad T480 20L5. It's meant to act as a probe to monitor traffic in a server room but needs to be small and mobile. Hence my question. Thanx =) Magnus

Can someone answer if MBSA supports Server 2016? If it is not supported what product can be used?

Dear IT Pros,
I have 2 questions that need your help and professional advice.
1) Does Microsoft has a tool to check whether a patch (KB) was superseded by another KB? In my case, I'm trying to search whether this KB4022715 and KB4025339 (both of this KB was released in 2017) was superceded
by another KB. This is because a security consultant has advised us to install both of this KB to prevent vulnerabilities but since it was released back in 2017, I suspect there must be a newer KB that supercedes it
2) Can advice what KB I need to download regarding this 2 bulletin ID CVE-2017-5715 and CVE-2019-11135? Can't seem to find it after much googling

Thanks in advance for the help

My objective is to run the tool and analyze the security and software patches on server or computer and produce a list of recommended install.
I read that MBSA (https://docs.microsoft.com/en-us/windows/security/threat-protection/mbsa-removal-and-guidance) only supports up to Windows Server 2012R2.
Is there any tools that support Windows Server 2016 ?
I used WUA and it can't run on some of the computer.
Then, explore Microsoft Security Compliance Toolkit 1.0 but lack of instruction. Not sure it can do the job or not.

Do you have any recommendation on how I can get started ? Thanks.

Fresh build of server 2012 R2.
Ran windows updates 3 times and it's current on it's updates.

Installed Office 2016. When I go to start Word or Excel, I get -
the program can't start because api-ms-win-crt-heap-l1-1-0.dll is missing.
Microsoft says that KB2999226 needs to be installed. Go to install it and the message is that it's not applicable for this system.
MS also says to install C++ redist 2015 on the system. I did that and got an error message on the install. Reboot, run the install again and select repair and it can't repair it.

Short of wiping the server and re-installing the OS and other software I've installed on it, I'm stuck.

Any ideas?

I am trying to join a server 2016 standard to a domain hosted on a 2012 R2 server.  When I input the domain\username of a user authorized to join the domain, it fails with the message. "the account is not authorized to login from this station". 
The 2016 server is straight out of the box with no changes.  What do I need to do the get this server joined to the domain?

Thanks, JTB


Hi there,
I have installed a Silverlight application in Internet Explorer 11 on a remote desktop server with 64GB RAM and 12 VCPU's. The application gets very slow as soon as several people are using it. The cause of this seems to be the CPU usage: a single instance
of IE11 already uses more than 25% of the available CPU.

Is this a known problem? Is there any solution for this? All suggestions are welcome!

Good morning,
After noticing that random websites were failing to load consistently, I looked through my IE11 settings and saw that the option to use a proxy server was checked. If I uncheck the proxy server option:
The proxy server option sometimes will be enabled again when restarting IE11
New tabs I open during the same session of IE11 will again have that Proxy Server option enabled
Occasionally, the same tab will revert back to having the Proxy Server option enabled
The proxy server address field remains blank through all of this (there was a value in there some time ago, but clearing it out once eliminated that issue. I have tried the following in addition to manually clearing the proxy server check box and address field:
Adware Cleaner
Significant malware and adware was cleaned up by these programs. With regard to this issue, the only improvement was that sometimes (but not always) the first tab only has the proxy server box unchecked when opening my IE11.
I am using this computer at home. I have never knowingly used a proxy server.
Please help. Thank you!

A:Windows 8.1 IE11, browser starts with proxy server enabled

I cannot run DDS on my PC. I can download it, but running it gives an error that DDS will not run in Compatibility mode.
Not sure if this blocking of DDS is part of my issue.
Please advise.

So I have a client who just got 10 new windows 10 machines and added them to the windows 2008R2 domain. By default, Edge is the set browser and I know I can manually go into the profile and set the preferred browser but the problem is multiple users connect to each machine (this is in a DR office) the nurses move around and log into their profiles on each machine. So they would have to do this on each machine for each user which they don't want to do.

Is there a way to enforce the browser for all windows 10 machines via GPA to use IE11 that comes with windows 10?

My idea was to either domain wide on windows 10 machines use IE11 or if not possible created a GPA based on OS and set the default browser.

Or worst case figures out a way to remove Edge from the machines.

Does anyone happen to know a way or ran into this issue previously?

A:Any way to force IE11 as default browser via domain GP? Server 2008

Check with Microsoft before attempting to remove Edge, you might end up with in-valid/un-authentic Windows. If memory serves me, I think the IT people had to develop a PUSH technology, a forced net-station download and a forced Top/Down maintenance, in order to enforce certain defaults.

We have a 2016 server and BITS service getting stopped automatically after 2 minutes, We have done the troubleshooting like restore system health, sfc
/scan now and rename the software distribution and cat root but issue still same?

Source One: System Center 2016 to launch in September

"We are pleased to announce that Microsoft System Center 2016 will be launched at the Microsoft Ignite conference in late September."​
Source Two: Windows Server 2016 new Current Branch for Business servicing option

"Windows Server 2016 is the cloud-ready operating system that delivers new layers of security and Azure-inspired innovation for the applications and infrastructure that power your business.

New capabilities will help you:

Increase security and reduce business risk with multiple layers of protection built into the operating system.
Evolve your datacenter to save money and gain flexibility with software-defined datacenter technologies inspired by Microsoft Azure.
Innovate faster with an application platform optimised for the applications you run today, as well as the cloud-native apps of tomorrow.
Windows Server 2016 includes 3 main editions:

Datacenter: This edition continues to deliver significant value for organisations that need unlimited virtualisation along with powerful new features including Shielded Virtual Machines, software-defined storage and software-defined networking.
Standard: This edition is ideal for organisations that need limited virtualisation but require a robust, general purpose server operating system.
Essentials: This edition is designed for smaller organisations with less than 50 users.
These editions will be available for purchase on the October 2016 price list... Read more

A:Windows Server 2016 to launch in September

Nice share @Huracan wonder if it is going to be more secure than Windows 10.

I currently have two virtual 2012 R2 servers in my ATA infrastructure: one ATA gateway server and one ATA center server.  I was wondering if it is possible to in place upgrade these servers to server 2016 or is there a migration process for moving
to new servers?

