Import Accounts: Block Microsoft accounts

I may maybe a dumb question , but i  want to import the security setting gpo for 8.1 into a forest level 2008r2.
I know there not admx file , but i sure there a way around faster then installer a server 2012r2  pdc
cause i have all the 8 and 8.1 template import running fine 
I miss like : computer configuration/windows setting /security setting /security option 
Accounts: Block Microsoft accounts
I did try to run a export out of a w8 box but did not work.
any one have hint ?

Hello,
create your own central store as mentioned in
http://blogs.technet.com/b/askpfeplat/archive/2011/12/12/how-to-implement-the-central-store-for-group-policy-admin-templates-completely-hint-remove-those-adm-files.aspx and then download and use
http://www.microsoft.com/de-de/download/details.aspx?id=41193
Be aware that at least a Windows 8.1 or Windows Server 2012 R2 machine, NOT DC, with GPMC must be used to configure the settings. No way around this.
Best regards
Meinolf Weber
MVP, MCP, MCTS
Microsoft MVP - Directory Services
My Blog: http://blogs.msmvps.com/MWeber
Disclaimer: This posting is provided AS IS with no warranties or guarantees and confers no rights.
Twitter:  

Similar Messages

  • Synchronize between promatric account and microsoft account

    hi
    i try to make Synchronize  between promatric account and microsoft account but he con not find the certificate i toke it,

    Hi ahmad_alnjjar,
    It might seems that the training center have created a new MCP ID for you. To solve your problem just give a call to your Microsoft Region Service Centers (https://www.microsoft.com/learning/en-us/help.aspx) by calling them to merge your 2 MCP IDs to one
    account.
    Hope this helps :)

  • Unlink mu account from microsoft account

    hepl me to unlink my skype account.my user name is "[Removed for privacy]" without quotes.
    Attachments:
    Screenshot (55).png ‏155 KB

    Hi, Ritu..., and welcome to the Community,
    As the error message you posted the screen shot of states, you will need to contact Skype Customer Service directly.  We here in the Community do not have the facility to unlink Skype and Microsoft accounts.
    Here is a link to the instruction on how to contact Skype Customer Service via their secure portal: Contact Customer Service
    If you experience difficulty reaching Skype Customer Service or find yourself redirected back to the Community, please try again using a different web browser and choosing a different path through the various drop-down menu options presented.
    Also, look to approve a pop-up dialogue box which would connect you to start an instant message chat with a customer service agent. If you have pop-ups blocked in your browser settings, this will also block reaching an agent.
    Last and not least, when you reach the last step of the process, remember to click on the "Start Chat" link when you are provided the choice of visiting the Community or starting an instant message chat with a customer service agent.
    Regards,
    Elaine
    Was your question answered? Please click on the Accept as a Solution link so everyone can quickly find what works! Like a post or want to say, "Thank You" - ?? Click on the Kudos button!
    Trustworthy information: Brian Krebs: 3 Basic Rules for Online Safety and Consumer Reports: Guide to Internet Security Online Safety Tip: Change your passwords often!

  • Best approche with domain account and Microsoft account?

    HI,
    We presently try Windows 8.1 in my company. And we have a user/domain account, and this is perfect. Now I discovers we can sync/connect with a Microsoft account. I try to connect to a "business" Microsoft account. But if I do that I can't use Skype
    with my personal account !
    So my real question is when we use a domain account when we connect to a Microsoft Account, best utilization is to use our personal or a business Microsoft account?
    And if I use a business account, how I can use Skype with my personal account?
    Eric

    This is an issue. 
    Linking the domain account to one online account is not something I am happy about at all.  We need more flexibility around account settings please.
    S. O'Neill,
    Did you ever find a solution to this issue?   I am hoping to migrate our company from an in house SBS server to Office 365, I had expected that this issue would have been resolved by the Office 365 account also being a Microsoft Account. But I
    have since learned that this is not the case, and for at least one good reason. Windows Store App licenses and payment information is linked to the Microsoft Account.
    Please consider a  small business of 50 to 100 users using Office 365 Enterprise where Users stay in the company between 1 to 3 years.
    Not all staff joining the company would have a personal Microsoft Account, and even if the User did have a personal Microsoft Account, as the User's computer is a company asset, the company cannot violate the user's privacy by having the User use their own
    Microsoft Account. And the company cannot risk the security implications of having the User's personal Microsoft account connected to their corporate computer and network.
    The company IT department could create company owned Microsoft accounts for each User as well as Office 365 User accounts. And when a User leaves, log into the User's company Microsoft Account and check to ensure that the user has not placed any company
    records on their Microsoft Account's OneDrive before deleting their User account.  It will also mean deleting and creating a new Microsoft Account each time a User leaves the company and their replacement is hired.
    However there is an issue here  when the IT Department deletes the Microsoft Account the company looses the license for any software that they have purchased for the user.
    So far the only solution I have been able to determine is to create company "role" based Microsoft Accounts and Office 365 accounts, then use Email Aliases to manage a personalised email address for any user working in that "role". For example we would have
    roles "CEO", "Business.Manager", "Finance.Manager", "Finance.Assistant_1", "Communications.Office", "Marketing.Manager", "Sales.Rep_1", etc.
    I understand that Enterprise organisations do not use Microsoft Accounts at all, but use Side-loading administered from an AD server to manage Windows Store Apps.
    I would very much like to hear how companies are managing the issues caused by Microsoft Accounts, including the issue of there being two OneDrives, a Microsoft Account OneDrive and an Office 365 OneDrive for Business.

  • Linking old skype account to Microsoft account..

    I have been using normal Skype account for years without a problem until I was forced to login using a microsoft account. Now I have microsoft account and it is set-up in Skype. As I could not login to Skype using old Skype account, I downloaded the Skype for Windows desktop. I can login to Skype Windows desktop using ether accounts.Now,,, how can I merge these two Skype accounts?.It does not give an option for me to do so. 

    This Website will show you how, if you have not done so all ready http://www.gcflearnfree.org/skype/merging-skype-with-your-microsoft-account

  • Missing bluetooth icon on the wireless area windows8 & & unable to switch from local account to microsoft account

    pls i feel like hitting this my laptop against the wall! but i will wait for 4 more days......it refuse to see devices likewise the same with devices trying to connect the laptop, icon gone on the wireless area of the pc, supported device only is what
    i see on the services.msc and its running. I have uninstalled and installed like never before yet all effort seems to be useless. Network and sharing center i have set and reset;  on the bluetooth setting page only options COMport and hardware is what
    i see pls help by any means you can for i'm running out of patient................

    Hi,
    According to your description, it should be Bluetooth driver problem, have you tried to access your PC official site to download the Bluetooth driver for test?
    Roger Lu
    TechNet Community Support

  • Connect MS account instantly fails 0xd0000022 "We're sorry but something went wrong. Your Microsoft account wasn't connected to this domain account"

    First. I'll make another post about this but worth mentioning - the dialogue when opening Cortana then having to connect with a MS account is barely usable. The "Next" button is completely black so had to guess that was where to click. When I select
    any other window or click outside the dialogue disappears until I hit the Start button, Windows Key or the Cortana/Search button. Makes it near impossible to say copy what is written there when something goes wrong...
    Not that MS will care or do anything right?
    Anyway. Domain account, no restrictions that I know of from that side (my home/test domain). Attempt to connect MS account and get below literally not even a second later, it's basically an instant failure with the message:
    So what now?

    Nevermind, did have GPO there blocking it!
    Policy
    Setting
    Winning GPO
    Accounts: Block Microsoft accounts
    Users can't add or log on with Microsoft accounts
    CFG_SOE

  • Connect Microsoft Account to Multiple Domain Accounts

    We are currently trialing windows 8.1 tablets in a school environment and would like for the students to have access to the 'Windows Store'
    All students log in with a domain account. (Their own domain account)
    All of these tablets are being imaged Via SCCM 2012 Task Sequence.
    What I would like to see happen either during the SCCM TS or via GPO or some other method would be to have the same Microsoft account connected to anyone logging into these devices this way the student would never require the account credentials
    and they would never be prompted to log into the store as well as be able to openly download and install free apps... I'll tackle the paid app issue separately...
    I would enable the GPO:
    computer configuration\windows settings\security settings\local policies\security options\'accounts: block Microsoft account'
    so that they couldn't link any additional personal Microsoft accounts.
    thoughts?

    More update...
    created the following script (autoit) to create the appropriate reg key entries to connect a Microsoft account to the current logged on user.
    #include <Security.au3>
    Local $aArrayOfData = _Security__LookupAccountName(@UserName)
    $SID = $aArrayOfData[0]
    RegWrite("HKEY_USERS\.DEFAULT\Software\Microsoft\IdentityCRL\StoredIdentities\<Microsoft Live Account Name>\", "AccountsCount", "REG_DWORD", "<Enter Applicable Value>")
    RegWrite("HKEY_USERS\.DEFAULT\Software\Microsoft\IdentityCRL\StoredIdentities\<Microsoft Live Account Name>\", "AssociatedCount", "REG_DWORD", "<Enter Applicable Value>")
    RegWrite("HKEY_USERS\.DEFAULT\Software\Microsoft\IdentityCRL\StoredIdentities\<Microsoft Live Account Name>\", "CID", "REG_SZ", "<Enter Applicable Value>")
    RegWrite("HKEY_USERS\.DEFAULT\Software\Microsoft\IdentityCRL\StoredIdentities\<Microsoft Live Account Name>\", "Keywords", "REG_SZ", "<Enter Applicable Value>")
    RegWrite("HKEY_USERS\.DEFAULT\Software\Microsoft\IdentityCRL\StoredIdentities\<Microsoft Live Account Name>\" & $SID, "AccountType", "REG_SZ", "<Enter Applicable Value>")
    RegWrite("HKEY_USERS\.DEFAULT\Software\Microsoft\IdentityCRL\StoredIdentities\<Microsoft Live Account Name>\" & $SID, "ChildFlags", "REG_SZ", "<Enter Applicable Value>")
    RegWrite("HKEY_USERS\.DEFAULT\Software\Microsoft\IdentityCRL\StoredIdentities\<Microsoft Live Account Name>\" & $SID, "DefaultCredSaved", "REG_SZ", "<Enter Applicable Value>")
    RegWrite("HKEY_USERS\.DEFAULT\Software\Microsoft\IdentityCRL\StoredIdentities\<Microsoft Live Account Name>\" & $SID, "DisplayName", "REG_SZ", "<Enter Applicable Value>")
    RegWrite("HKEY_USERS\.DEFAULT\Software\Microsoft\IdentityCRL\StoredIdentities\<Microsoft Live Account Name>\" & $SID, "FirstName", "REG_SZ", "<Enter Applicable Value>")
    RegWrite("HKEY_USERS\.DEFAULT\Software\Microsoft\IdentityCRL\StoredIdentities\<Microsoft Live Account Name>\" & $SID, "Flags", "REG_SZ", "<Enter Applicable Value>")
    RegWrite("HKEY_USERS\.DEFAULT\Software\Microsoft\IdentityCRL\StoredIdentities\<Microsoft Live Account Name>\" & $SID, "Keywords", "REG_SZ", "<Enter Applicable Value>")
    RegWrite("HKEY_USERS\.DEFAULT\Software\Microsoft\IdentityCRL\StoredIdentities\<Microsoft Live Account Name>\" & $SID, "LastName", "REG_SZ", "<Enter Applicable Value>")
    I am applying this script on logon to the users so they all end up using the same account to access the store.
    last challenge is to set it so they don't have to enter a password. where is the password stored?????

  • Deployment of Windows 8 and Microsoft account

    Hi,
    I have a situation where I am deploying Windows 8.1 to desktops connected to a 2008 R2 domain
    Scenario:
    * Each client PC is running Windows 8.1
    * Each client PC signs on to internal domain controller ([email protected])
    * Each user account has an office 365 sign on which is syncronised with active directory (Microsoft organisational account)
    It would now appear that each user requires a microsoft / live account to benefit from apps, windows store etc..
    Does anyone know of a procedure where the organisational account for office 365 can be used for this (which i dont think is possible) or perhaps any way of bulk registering my office 365 users for a microsoft/live account and syncronise the passwords.
    Anyone come across this issue before?
    **Mods, if i have put this in the wrong category, please feel free to move it**
    Thanks,
    M
    If you find my information useful, please rate it. :-)

    Having similar issues/concerns to yourself, I have been researching for a solution. While I have not found any real solution, there are two work-arounds that I am contemplating. Please let me know if either of these could help yourself, or if you have found
    better or improved solutions.
    Process 1.
    1) For each Office 365 account, also create a Microsoft Account
    2) Computer Configuration\Administrative Templates\Windows Components\OneDrive\"Prevent the usage of OneDrive for file storage" to "Enabled", to ensure that the Microsoft Account's OneDrive is disabled so the user does not accidental store company data to the
    Microsoft Account's OneDrive but only has access to the Office 365's OneDrive for business.
    3) When a user leaves, delete their Office 365 account and then also delete their Microsoft Account (see http://windows.microsoft.com/en-us/windows-live/account-close-account). Remember to transfer any required company data from their Office 365 OneDrive account
    to the corporate Team Sites before deleting their Office 365 account.
    or
    Process 2.
    1) You can totally disable the use of Microsoft Accounts and the Windows Store, while still allowing users to make used of already installed Windows Store Apps.  
    2) If you have a Windows AD server you can use side-loading to install apps. Or you could install the apps before disabling Windows Store.
    3) You can still enable the automatic updating of Windows Store Apps, even when the Windows Store is disabled.
    Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\"Accounts: Block Microsoft accounts" to "Users can't add or log on with Microsoft accounts"
    Computer Configuration\Administrative Templates\System\Internet Communications Management\Internet Communications settings\"Turn off access to the Store" to "Disabled"
    Computer Configuration\Administrative Templates\Windows Components\App runtime\"Allow Microsoft accounts to be optional" to "Enabled"  (NB: allows the use of Windows Store apps even when the use of a Microsoft Account is disabled)
    Computer Configuration\Administrative Templates\Windows Components\Store\"Turn off the Store application" to "Enabled"
    Computer Configuration\Administrative Templates\Windows Components\Store\"Turn off Automatic Download and Install of updates" to "Enabled"
    Computer Configuration\Administrative Templates\Windows Components\Store\"Turn off Automatic Download of updates on Win8 machines" to "Enabled"
    If you want to disable Syncing of data, see;
    Computer Configuration\Administrative Templates\Windows Components\Sync your settings\"Do not sync passwords"
    I am very interested to learn if there are more Group Policies that could be, or should be, used to manage Microsoft Accounts and the Windows Store.

  • Is it possilbe to totally disable the use of Microsoft Accounts in Windows 8.x ?

    The existence and need of "Microsoft Accounts" in Windows 8.x causes many issues for corporate IT management.
    1) To access Windows 8.x Mail App, Calendar App, etc, OneDrive, Skype, to upgrade from Windows 8.0 to Windows 8.1, and the Windows Store requires a Microsoft Account.
    2) Not all users have or will want to have their own personal Microsoft Account
    3) It is possible for the corporate IT department to create Microsoft Accounts for each of the company Users, but it is an extra burden and difficult to manage these accounts.
    Potentially the simplest solution is to be able to totally disable the use of Microsoft Accounts in Windows 8.x, is this possible?

    Hello,
    You have the choice of uninstalling the metro apps ou use the GPO to block the use of Microsoft account.
    Please see the followings links:
    Uninstall metro apps:
    http://www.deploiementwindows.com/supprimer-les-applications-dans-windows-8-1/
    GPO: Block Microsoft accounts
    http://technet.microsoft.com/en-us/library/jj966262%28v=ws.10%29.aspx
    http://4sysops.com/archives/control-windows-store-access-with-group-policy/
    regards,
    - Yannick Plavonil

  • Login Credentials Error "Your PC is offline." with Microsoft Account

    i use windows 8.1 whenever i try to sign into my laptop this error shows up " your pc is offline. Please sign in with the last password used on this P C. " I recently switched from my local account to microsoft account. my passwords for local
    and microsoft account are different I tried entering both the passwords but it still shows the same error.

    i just want to add 2 more
    try to disable your WIFI and try to connect using your local account or Microsoft Account
    You can also try your Microsoft account login at another online PC to make sure there is no issue with Account or internet connection
    Refresh PC will be last option
    Yes, I suspect you used the wrong password

  • Why can't I connect one Windows 8.1 PC to other Windows 8.1 PCs in my workgroup when using a Microsoft Account?

    I finally decided to convert some of my local accounts to Microsoft Accounts on my Windows 8.1 PCs. Big mistake to this point.
    I have two PC's with the same Microsoft Account set up, neither PC can browse to the other or map a drive through browsing.
    I'm not using a homegroup. My daughter has one setup on her laptop and desktop, and I don't want my PC's on her homegroup. Until Microsoft makes it possible to have 2 homegroups on the same subnet, this is not an option.
    The local accounts on both PC's have no problem browsing, mapping, etc. I can connect to the other PC's just fine using local accounts, so I know physical connectivity isn't an issue, neither is my anti-virus or really anything else system wide on either
    computer. 
    I just can't attach automatically using a Microsoft Account. I have to manually map a drive every logon/reboot.
    I have also found that running a logon script doesn't work. The drives will not map automatically.
    The Microsoft Account users can map a drive using "Connect using different credentials." However, the credentials don't hold across reboots.
    I can manually (using either a Microsoft Account or a local account) map a drive using "net use" which then opens up all of my mapped drives and allows for browsing to the other PC. However, this doesn't work across reboots/logons either.
    Entering credentials in the Credentials Manager (Whether I use the Microsoft Account credentials or one of the local user credentials) doesn't work across reboots either.
    Yes, I have the same Microsoft Account setup on both PCs. I have tried giving them both Admin and Standard user rights on both PCs.
    I have turned off UAC as recommended in some posts.
    Again - This problem is ONLY related to MICROSOFT ACCOUNTS, not local accounts.
    I have put a batch file on the desktop with a "net use" statement in it to connect as a work around, but this is very annoying and truly unacceptable. Is there anyway to make this work seamlessly without running a batch file or something else where
    the password exists on the PC in clear text?
    I can't find other posts asking this question - am I the only one who is trying to do this? What memo did I miss?
    Thanks for any help!

    Hello Steve Hengen,
    I apologize for the delay.
    I have test in my own environment and can normally map the network driver when logon as Microsoft account.
    Do you check the option Reconnect at logon?
    If you use Connect using different credentials, do you check the option Remenber my credentials?
    Please take a look at the following article about map a network drive.
    http://windows.microsoft.com/en-HK/windows-8/create-shortcut-to-map-network-drive
    Best regards,
    Fangzhou CHEN
    Fangzhou CHEN
    TechNet Community Support

  • Can't sync anything with my microsoft account and can't create a new one?

    Hi,
    I have recently done a software update to Windows 8.1 and now every time I try to access an app it prompts me to sign in to sync my data. I follow the screen prompts using my email address and password (the same as the one I have used to access this forum
    so my current working microsoft account) and it says a microsoft account with this email address already exists on this PC. 
    I get through to the validation code page section, the code is sent to my phone, I enter it, the cloud information page is displayed the switch to microsoft account option appears I click switch and it says an account already exists on this PC???
    If  I try to choose the alternative option of creating a new account with the same email address (my main email account) I have the same issue which is an account already exists. 
    I have lost data and can't sync any music tracks etc - hugely frustrating!
    What do I do??

    Hi,
    What's your current User Account? Local Account or Microsoft Account? If local account, please sign out and switch to Microsoft Account. If not, it should have problem with your Microsoft Account, please try to delete it from your system and readd it for
    test.
    Roger Lu
    TechNet Community Support

  • Need to merge my skype account with Microsoft acco...

    I can not use my skype account in my Lumia 820. Its asking for Microsoft account. Now Need to merge my skype account with Microsoft account. How to do that ? For your kind information. I was use skype(most) and live too. So I do not get the automatice merge option.
    Please advice ASAP. I need to use skype in mobile very urgently.
    Solved!
    Go to Solution.

    When you sign in with your unlinked Microsoft account, you will be prompted to enter your Skype credentials.
    Here are more specific instructions:
    http://community.skype.com/t5/Windows-Phone/Skype-for-Windows-Phone-Sign-In-Process-Changes/m-p/2946...
    Follow us @SkypeSupport.
    To get the most out of Skype I recommend Skype Premium.
    Download Skype for Windows Phone from the Store.
    Found this post useful? Please give Kudo. Helped to fix your issue? Mark it as a solution to help others, Thanks.

  • How to claim for Hacked/Missing Live/Hotmail account from Microsoft Support

    Recently We've seen tons of people submitting request on retrieve his hacked/Missing Hotmail/Live account or related from feedback system, then gather below ways on retrieving your account:
     #1 If you are a Hotmail customer who needs help with your Hotmail account, go to
    Microsoft Answers—Hotmail, Windows Live Messenger & Microsoft SkyDrive or to your
    Account overview.
     #2 Visit here:
    http://windows.microsoft.com/en-us/windows-live/microsoft-account-help#microsoft-account=tab0
     #3 Watch this useful video:
    http://windows.microsoft.com/en-us/windows-live/account-reset-password-forgot-faq
     #4 Visit here:
    https://support.msn.com/default.aspx?locale=en-us, then change your location accordingly --> Hit 'My MSN' --> Fill in relevnat fields to address your request:
    Pan Zhang Customer Support Visual Studio Cloud Service team

    Thanks Pan!
    I turned this into a Wiki article here and gave you credit:
    http://social.technet.microsoft.com/wiki/contents/articles/15627.how-to-get-microsoft-support-for-a-hacked-or-missing-livehotmail-account.aspx
    Ed Price (a.k.a User Ed), SQL Server Customer Program Manager (Blog,
    Small Basic,
    Wiki Ninjas,
    Wiki)
    Answer an interesting question?
    Create a wiki article about it!

Maybe you are looking for