Quantcast
Channel: Directory Services forum
Viewing all 31638 articles
Browse latest View live

Service Accounts required permissions

$
0
0

Hi

We have many service accounts which are part of local Administrators group, through GPO we are planning to restrict the membership of Administrators group and to provide these service accounts "Log on as a service" permission through GPO. What we understood is, by providing service accounts these permission, then there is no need to add these accounts to local administrators group.

Your suggestions please

Thanks in advance


LMS


Account configured to use DES encryption with Windows 2012 R2 Domain Controller

$
0
0

Hi

We have configured one account to "Use Kerberos DES encryption type" with AD, which is using by SAP for single sign on. The account was created and configured before introducing Windows 2008 R2 DCs. Our current Domain & Forest functional level is Windows 2008 and all DCs are running on Windows 2012 R2. We are planning to upgrade to Windows 2016 DCs and same with functional levels. DES support is not enabled on DCs (not enabled & selected the GPO setting :- Computer Configuration\ Windows Settings\ Security Settings\ Local Policies\ Security Options - Network security: Configure encryption types allowed for Kerberos option & there are no Reg entries :- HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\Kerberos\parameters\). Also as per KB "https://support.microsoft.com/en-au/help/977321/kdc-event-id-16-or-27-is-logged-if-des-for-kerberos-is-disabled" we didn't find event IDs 27 or 16 with DCs. 

For testing purpose we are planning to remove the DES setting from the account and will check the SSO with SAP. In case of any issue we will re-select the option. We are looking for any suggestion on disabling DES with this account

Thanks in advance


LMS

Active Directory and LDS Schema Mismatch

$
0
0

I have been struggling to get the AD LDS instance schema upgrade to match with the Active Directory Domain. LDS instance is synchronizing data from active directory. Domain was upgraded to Windows Server 2008 and therefore Active Directory domain schema version is 44. LDS Schema version is 30. 

I have used ADAMschemaanalyzer tool to import the difference LDIF file in LDS instance and upon manual check I see all the attributes are modified but still LDS schema version is set to 30.

Can someone explain how can I get this version incremented?

As a note, upperrange for title attribute for Windows Server 2003 is 64 and for Windows Server 2008 it is 128. After importing the LDIF file there is no change in rangeupper value for this attribute. I am stuck please help!

Deleting an object in AD DS

$
0
0

Hello,

I want to know what is the difference when I deleting an object with recycle bin enabled and when recycle bin is disable

I read that don't changes to tombstone but is-deleted attribute of that enables 

What is the difference between them

Thanks for your help


Kerberos Attacks Questions

$
0
0

Hey, It's amazing how many "Attacks on Kerberos" articles exist out there and almost none really explains the small details.

My guess is that usually they assume it's basic knowledge and sometimes, they just don't know enough.

Anyway, here are the questions:

  1. How is PtT (Pass the Ticket) possible? You can easily take someone's ticket but to use it you need to create an Authenticator, which means you need to get one of the keys that the client possess (it depends on which step you are in) and even forge the IP address embedded in the ticket stolen.
  2. It does not sound reasonable to me that given access to client's computer memory, you would extract only Kerberos tickets and no session keys or clear text/hashed passwords. 
  3. If only Kerberos is used, where am I going to find any NTLM hash to commit OPtH (Over-Pass the Hash)?
  4. They encryption of RC4_HMAC_MD4 is not used by default in nowadays windows operation systems, so how would I use NTLM hash in OPtH? Is downgrade the answer?
  5. I read in some article, that kerberoast's brute-force phase is done by trying different NTLM hashes. It seemed weird, so I assumed that it is done by trying clear text passwords which will be used to generate NTLM hashes which will be used in their turn as keys in order to try decrypt the ticket's encryption. But that's not suppose to be the case, RC4_HMAC_MD4 is not used by default. AES does, and it has PBKDF2 as a hash algorithm (which suppose to be BF resistant).
  6. How is Silver Ticket is done when the victim sever does check the PAC against the DC?
  7. Golden Ticket attack builds on the TGS to cooperate with any given TGT? Which means that it will sign on the PAC even if its forged?

Thank you all.

If there is another forum similar to TechNet please let me know.

2008 R2 domain group policy not works on 2016 server

$
0
0
2 x 2008 R2 servers as domain controller. Found that the group policies are not apply on my newly added 2016 servers. Is this the product design?

Tanium on a Domain Controller - Experiences? Advice?

$
0
0

Right now were doing patching of out 2016 DCs as a manual monthly process.
We have options of SCCM or Tanium with the Security wonks pushing Tanium very hard.
I'm not fond of the Tanium client getting installed as 'Local System' on the DCs as it means Tanium Admins can "do what they will" on the Domain Controllers.
Has anyone worked with Tanium installed on Domain Controllers, and if so what was your experience?  Are there other minimum permissions necessary alternatives?

Also, any experience with ADFS servers and/or MIM servers?

Thank You

-Kyle



Outlook prompt for credentials

$
0
0
Hi Experts for one of my user outlook is always prompting for credentials after changing password. how to check in AD the user is getting locked. how to troubleshoot this issue, cleared windows cred mgr, reconfigured profile but no luck

FGP Policy for a Server

$
0
0
Is it possible to create an FGP Policy for a server rather than a user? I have software that authenticates against an SQL server in which the SQL server gets its Password policy from the Default domain Policy. However I need the SQL server to issue a different Password policy. Can this be done with FGP?

Support analyst

Default domain controller and computer OUs

$
0
0
Why are computers and domain controllers when added put in a default OU? I know that pre-staged computer is a thing, but why do they have to be in one particular ou in the first place? Are the default OUs more secure, ie stricter GPO settings applied or is there a better reason than just better organization?

server 2012 users and remote access-domain confusion

$
0
0

It was my understanding a user could not access any computers in a domain, unless that user was added to the domain controller.

In my test, I added a user to a vm server 2012, and can rdp onto that server, without being a user on the domain.

Normal??

Serve 2012 - New User access to other servers

$
0
0

I have a server 2012 environment with a DC. The domain includes 3 server 2012 vm machines for rdp/terminal services.

I added a user to a domain. I expected the newly added user would be able to log onto the rdp/terminal services vm's.

Since the other rdp/terminal services vm servers are part of the domain, I thought the new

user would be able to log onto those servers. But they cannot.

How can this be accomplished?

Audit user actions

$
0
0

Dear All,

Does anyone know how to record user actions (audit trails) and review them when required in the Microsoft Active Directory User and computers, version 6.2.9200.16384 (Windows server 2012)?

Lost And Found Folder in Active Directory

$
0
0

We have a central management console which works with Active directory. We enumerate users/computers/groups etc and use it inside our console for applying the policy. Is it a good idea to consider "Lost And Found Folder" as a valid group just like others containers?

-- Vikram

Domain user does only appears in root ad directory

$
0
0

We are experiencing a very strange issue with the AD. 

A user war created in the AD unser domain.de. The user shows properly in the in the AD snap in. and is located under domain/users.

However, when we want to assign user rights on the server (selecting the directory, properties etc) and selecting the domain in the search dialog box for the user - this user does not appear. This user only appears when we adjust the path to the root directory. But even then - when we then select this user and click ok - it does not appear in the user list. 

In the user search dialog box the path is also correct domain.de/users (as all the other users).

The user is active and can sign in.

Would appreciate if anyone has an idea what could be wrong.

Thank you.

Uli


Reconnect child domain to parent AD forest without demoting child domain controllers

$
0
0
Hi all,

At my parent AD forest with 2 domain controllers, I cannot see both my child domain controlers in AD Sites and Services. Repadmin status is all "0" which is good but it is only replicating between both parent domain controllers. DCdiag shows KCC event errors below.

"The partition DC=child,DC=parent,DC=gov,DC=sg should be hosted at site CN=HQ,CN=Sites,CN=Configuration,DC=parent,DC=gov,DC=sg, but has not been instantiated yet. However, the KCC could not find any hosts from which to replicate this partition."

At my disconnected child domain, in AD Sites and Services, I can see both parent domain DCs and child domain DCs. DCdiag shows KCC errors below.

"The event log Directory Service on server dc.parent.gov.sg could not be queried, error 0x6ba "The RPC server is unavailable."          

"The event log Directory Service on server dc.parent.gov.sg could not be queried, error 0x5 "Access is denied."

How can I create the replication pairs in the parent domain? As the child domain controller is missing, I cannot manually create a NTDS connection. I tried running repadmin /kcc but it did not help. I have also verified that there is no lingering objects in Active Directory. Domain and trust ports between parent and child are allowed as well.

Regards,
Chiew Sheng

ADMT Migration failed

$
0
0

I am trying to do a cross forest migration and i get a error message unable to update sid history ID.below is the error log i get.

Trust is establish successfully. Able to ping the servers across the domains. Replication of the servers is fine.

ERR2:7111 Failed to add sid history for user to user. RC=31.

Thanks in advance.

Shabeeb Khan

klist shows no tickets

$
0
0
I'm logged on (via RDP) to a Windows 10 machine. This computer has a network share mounted some hours ago and is writing a file to it. Nevertheless, klist doesn't show any cached tickets. Why? Windows 10 is member of a Win2k12 domain, the mounted drive is on a samba domain member of the same domani.

How to auto create/renew the kerberos tickets generated by domain controllers?

$
0
0
We recently installed/setup kerberos authentication on SAS which means tickets get generated when a SAS user logs into the SAS client (which is enterprise guide) and runs any code. Now this ticket that gets generated is valid only for 10 hours. So now the issue is there are few users whose job runs for more than 3 days and they are not able to run their jobs due to this security feature. We unfortunately cannot extend the time on the domain controller side as that would affect all the servers. As a workaround we followed the below link and set up the "krb5.cache.infinite.renewal: true" on the SAS server and are able to keep generating the kerberos tickets infinitely, however we want to implement this on the AD side. Is there any way to do that?

AD health check finds old PDC

$
0
0
I am experiencing problems with my domain and decided to run a AD health check. I ran the command dcdiag /v /c /d /e. In the results I find the name of a old DC, my previous PDC. How do I proceed from here?
Viewing all 31638 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>