Quantcast
Channel: Directory Services forum
Viewing all 31638 articles
Browse latest View live

Unable to modify the wellKnownObjects attribute when changing default computer target OU

$
0
0

Hello, I'm preparing for the 70-640 exam.  In attempting to redirect the default domain computer OU, I entered the command redircmp "CN=CLIENTS,DC=contoso,CD=com".  I get the error -unable to modify the wellKnownObjects attribute.  Verify that the domain functional level of the domain is at least windows Server 2003.

I have verified that the forest and domain functional level are 2008 R2.

I cannot find any suggestions in any threads other than removing "protected from deletion" check box in objects tab of advanced view properties of the target OU (this does not fix the error in my case).  Any other suggestions?


Delegate permission to modify UPN

$
0
0

Hello all

Please let us know how to delegate permission for User to modify UPN for user object in an OU.

regards

Aamir


NA

Password Not Required: Computers

$
0
0
I was running a utility to check our AD for password problems. It comes from KnowBe4 and is called the Password Exposure Test. It found some computers, not users, that were listed as "Password Not Required". I didn't even know that computers used passwords, only users. But when I looked at the attributes in AD for the listed computers the UserAccountControl attribute did list it as no password required. I don't know what the decimal setting was, but it wasn't 4096 (0X1000) workstation trust account. So I set it to 4096 which corrected them. Others were listed as 512, normal account. If I changed them to 4096, the user can't logon. It looks like those need to remain at 512 in UserAccountControl to be able for them to log in, but it makes them show up as "Password Not Required". What should the setting be?

Active Directory Security Group membership based on specific attribute

$
0
0

Trying to figure out if there's a way to create an AD security group and populate its members with user objects that have a specific attribute.


Example:


ABC Security Group


User XYZ has attribute countryCode = 0


User CDE has attribute countryCode = 1


User FGH has attribute countryCode = 1


I want to populate ABC Security Group with all the users who have attribute countryCode = 1, automatically


The idea  is that I've got thousands of users with countryCode = 1 and I really don't want to have to add them, or remove them, manually.  I would like if their countryCode ever changes from 0 to 1 or 1 to 0, it will automatically add or remove them from ABC Security Group.


Thanks,

Daniel


Thanks, Daniel

AD FS Unable to find Expired certificate

$
0
0

Hello,

I recently setup an ADFS connection with an external service and get a "connection not secure message" when I am redirected to our /adfs page due to a certificate that has expired
I have looked everywhere on the server I am unable to find it to get the service working.

In the AD FS console, all 3 certificates (Service communication, Token-decrypting and Token-signing) are all valid.

Can you please help me find where the expired certificate is?

Thanks!

Windows Server 2019 domain controller deployment

$
0
0

Hello, we have 4 domain controllers.  Three are running windows server 2008 R2 and 1 is running windows server 2012 R2.  Our primary domain controller is one of the windows 2008 R2 servers.  Our domain fuctional level is "Windows Server 2008 R2" and our forest functional level is "Windows Server 2003."  Are there any implications in introducing a windows server 2019 domain controller into this environment?  We would eventually like to retire the windows server 2008 R2 domain controllers.

Thank you for your assistance!

Default Domain Controller Policy

$
0
0

Hello Everyone

We have a domain controller environment and as it is, we have a default domain controller policy in place. The Default domain controller has following setting:

Enforced : No

Link Enabled : No

Will the settings in the policy work if there are no additional GPOs in place?

Thanking You

Avinash Yadav

Repadmin /replsummary Error (8606)

$
0
0

Hi,

I have 5 DC in 3 different networks (DEV, TST, PRD), all DC are are2012 R2 except PRD-ADV3 that is 2008 R2.

if I run the command Repadmin /replsummary from all DC I receive the error below:

C:\Users\admin>Repadmin /replsummary

Replication Summary Start Time: 2020-04-02 10:24:14

Beginning data collection for replication summary, this may take awhile:
  .........
Source DSA          largest delta    fails/total %%   error
 DEV-ADV1              12m:34s    0 /  15    0
 PRD-ADV1              32m:30s    0 /  20    0
 PRD-ADV2     >60 days            2 /  10   20  (8606) Insufficient attributes were given to create an object. This object may not exist because it may have been deleted and already garbage collected.
 PRD-ADV3              33m:17s    0 /  10    0
 TST-ADV1              32m:31s    0 /  10    0
 TST-ADV2              39m:13s    0 /  10    0


This is the result from PRD-DC2

C:\Users\admin>repadmin /showrepl

Repadmin: running command /showrepl against full DC localhost
Production\PRD-ADV2
DSA Options: IS_GC
Site Options: (none)
DSA object GUID: fd0814d7-df3d-4547-b29d-xxxxxxxxxxxx
DSA invocationID: 3090f21b-4ffc-4c65-8b0b-xxxxxxxxxxxx

==== INBOUND NEIGHBORS ======================================

DC=mydomain,DC=local
    Development\DEV-ADV1 via RPC
        DSA object GUID: 07030400-79c8-4f2d-b48a-xxxxxxxxxxxx
        Last attempt @ 2020-04-02 10:11:40 was successful.
    Production\PRD-ADV3 via RPC
        DSA object GUID: 9a69e59f-8385-4634-95a7-xxxxxxxxxxxx
        Last attempt @ 2020-04-02 12:04:24 was successful.
    Production\PRD-ADV1 via RPC
        DSA object GUID: 061a84d5-db2d-4da0-a2b9-xxxxxxxxxxxx
        Last attempt @ 2020-04-02 12:06:01 was successful.

CN=Configuration,DC=mydomain,DC=local
    Development\DEV-ADV1 via RPC
        DSA object GUID: 07030400-79c8-4f2d-b48a-xxxxxxxxxxxx
        Last attempt @ 2020-04-02 10:11:40 was successful.
    Production\PRD-ADV1 via RPC
        DSA object GUID: 061a84d5-db2d-4da0-a2b9-xxxxxxxxxxxx
        Last attempt @ 2020-04-02 11:58:39 was successful.
    Production\PRD-ADV3 via RPC
        DSA object GUID: 9a69e59f-8385-4634-95a7-xxxxxxxxxxxx
        Last attempt @ 2020-04-02 11:58:45 was successful.

CN=Schema,CN=Configuration,DC=mydomain,DC=local
    Development\DEV-ADV1 via RPC
        DSA object GUID: 07030400-79c8-4f2d-b48a-xxxxxxxxxxxx
        Last attempt @ 2020-04-02 10:11:40 was successful.
    Production\PRD-ADV1 via RPC
        DSA object GUID: 061a84d5-db2d-4da0-a2b9-xxxxxxxxxxxx
        Last attempt @ 2020-04-02 11:58:39 was successful.
    Production\PRD-ADV3 via RPC
        DSA object GUID: 9a69e59f-8385-4634-95a7-xxxxxxxxxxxx
        Last attempt @ 2020-04-02 11:58:39 was successful.

DC=DomainDnsZones,DC=mydomain,DC=local
    Development\DEV-ADV1 via RPC
        DSA object GUID: 07030400-79c8-4f2d-b48a-xxxxxxxxxxxx
        Last attempt @ 2020-04-02 10:11:40 was successful.
    Production\PRD-ADV3 via RPC
        DSA object GUID: 9a69e59f-8385-4634-95a7-xxxxxxxxxxxx
        Last attempt @ 2020-04-02 11:58:39 was successful.
    Production\PRD-ADV1 via RPC
        DSA object GUID: 061a84d5-db2d-4da0-a2b9-xxxxxxxxxxxx
        Last attempt @ 2020-04-02 11:58:39 was successful.

DC=ForestDnsZones,DC=mydomain,DC=local
    Development\DEV-ADV1 via RPC
        DSA object GUID: 07030400-79c8-4f2d-b48a-xxxxxxxxxxxx
        Last attempt @ 2020-04-02 10:11:40 was successful.
    Production\PRD-ADV1 via RPC
        DSA object GUID: 061a84d5-db2d-4da0-a2b9-xxxxxxxxxxxx
        Last attempt @ 2020-04-02 11:58:39 was successful.
    Production\PRD-ADV3 via RPC
        DSA object GUID: 9a69e59f-8385-4634-95a7-xxxxxxxxxxxx
        Last attempt @ 2020-04-02 11:58:39 was successful.


This is from other server (PRD-DC1):

C:\Users\Admin>repadmin /showrepl

Repadmin: running command /showrepl against full DC localhost
Production\PRD-ADV1
DSA Options: IS_GC
Site Options: (none)
DSA object GUID: 061a84d5-db2d-4da0-a2b9-xxxxxxxxxxxx
DSA invocationID: 0cd47770-7f80-4672-bd71-7a7743e34c38

==== INBOUND NEIGHBORS ======================================

DC=mydomain,DC=local
    Production\PRD-ADV2 via RPC
        DSA object GUID: fd0814d7-df3d-4547-b29d-xxxxxxxxxxxx
        Last attempt @ 2020-04-02 11:51:33 was successful.
    Development\DEV-ADV1 via RPC
        DSA object GUID: 07030400-79c8-4f2d-b48a-xxxxxxxxxxxx
        Last attempt @ 2020-04-02 12:05:57 was successful.
    Test\TST-ADV1 via RPC
        DSA object GUID: 8951dd52-2a9d-4d79-a2b4-xxxxxxxxxxxx
        Last attempt @ 2020-04-02 12:05:57 was successful.
    Production\PRD-ADV3 via RPC
        DSA object GUID: 9a69e59f-8385-4634-95a7-xxxxxxxxxxxx
        Last attempt @ 2020-04-02 12:09:15 was successful.

CN=Configuration,DC=mydomain,DC=local
    Production\PRD-ADV2 via RPC
        DSA object GUID: fd0814d7-df3d-4547-b29d-xxxxxxxxxxxx
        Last attempt @ 2020-04-02 11:50:57 failed, result 8606 (0x219e):
            Insufficient attributes were given to create an object. This object
may not exist because it may have been deleted and already garbage collected.
        13955 consecutive failure(s).
        Last success @ 2019-12-06 16:19:54.
    Production\PRD-ADV3 via RPC
        DSA object GUID: 9a69e59f-8385-4634-95a7-xxxxxxxxxxxx
        Last attempt @ 2020-04-02 11:58:42 was successful.
    Development\DEV-ADV1 via RPC
        DSA object GUID: 07030400-79c8-4f2d-b48a-xxxxxxxxxxxx
        Last attempt @ 2020-04-02 12:05:57 was successful.
    Test\TST-ADV1 via RPC
        DSA object GUID: 8951dd52-2a9d-4d79-a2b4-xxxxxxxxxxxx
        Last attempt @ 2020-04-02 12:05:57 was successful.

CN=Schema,CN=Configuration,DC=mydomain,DC=local
    Production\PRD-ADV2 via RPC
        DSA object GUID: fd0814d7-df3d-4547-b29d-xxxxxxxxxxxx
        Last attempt @ 2020-04-02 11:50:57 was successful.
    Production\PRD-ADV3 via RPC
        DSA object GUID: 9a69e59f-8385-4634-95a7-xxxxxxxxxxxx
        Last attempt @ 2020-04-02 11:50:57 was successful.
    Development\DEV-ADV1 via RPC
        DSA object GUID: 07030400-79c8-4f2d-b48a-xxxxxxxxxxxx
        Last attempt @ 2020-04-02 12:05:57 was successful.
    Test\TST-ADV1 via RPC
        DSA object GUID: 8951dd52-2a9d-4d79-a2b4-xxxxxxxxxxxx
        Last attempt @ 2020-04-02 12:05:57 was successful.

DC=DomainDnsZones,DC=mydomain,DC=local
    Production\PRD-ADV2 via RPC
        DSA object GUID: fd0814d7-df3d-4547-b29d-xxxxxxxxxxxx
        Last attempt @ 2020-04-02 11:50:57 was successful.
    Production\PRD-ADV3 via RPC
        DSA object GUID: 9a69e59f-8385-4634-95a7-xxxxxxxxxxxx
        Last attempt @ 2020-04-02 11:50:57 was successful.
    Development\DEV-ADV1 via RPC
        DSA object GUID: 07030400-79c8-4f2d-b48a-xxxxxxxxxxxx
        Last attempt @ 2020-04-02 12:05:57 was successful.
    Test\TST-ADV1 via RPC
        DSA object GUID: 8951dd52-2a9d-4d79-a2b4-xxxxxxxxxxxx
        Last attempt @ 2020-04-02 12:05:57 was successful.

DC=ForestDnsZones,DC=mydomain,DC=local
    Production\PRD-ADV2 via RPC
        DSA object GUID: fd0814d7-df3d-4547-b29d-xxxxxxxxxxxx
        Last attempt @ 2020-04-02 11:50:57 was successful.
    Production\PRD-ADV3 via RPC
        DSA object GUID: 9a69e59f-8385-4634-95a7-xxxxxxxxxxxx
        Last attempt @ 2020-04-02 11:50:57 was successful.
    Development\DEV-ADV1 via RPC
        DSA object GUID: 07030400-79c8-4f2d-b48a-xxxxxxxxxxxx
        Last attempt @ 2020-04-02 12:05:57 was successful.
    Test\TST-ADV1 via RPC
        DSA object GUID: 8951dd52-2a9d-4d79-a2b4-xxxxxxxxxxxx
        Last attempt @ 2020-04-02 12:05:57 was successful.

Source: Production\PRD-ADV2
******* 13955 CONSECUTIVE FAILURES since 2019-12-06 16:19:54
Last error: 8606 (0x219e):
            Insufficient attributes were given to create an object. This object
may not exist because it may have been deleted and already garbage collected.

I tried to run this command on PRD-DC2, but I didn't solve my problem:

repadmin /removelingeringobjects ACC-PRD-ADV2 fd0814d7-df3d-4547-b29d-xxxxxxxxxxxx CN=Configuration,DC=mydomain,DC=local /advisory_mode

repadmin /removelingeringobjects ACC-PRD-ADV2 fd0814d7-df3d-4547-b29d-xxxxxxxxxxxx CN=Configuration,DC=mydomain,DC=local 
repadmin /removelingeringobjects ACC-PRD-ADV2 fd0814d7-df3d-4547-b29d-xxxxxxxxxxxx CN=Schema,CN=Configuration,DC=mydomain,DC=local
repadmin /removelingeringobjects ACC-PRD-ADV2 fd0814d7-df3d-4547-b29d-xxxxxxxxxxxx DC=DomainDnsZones,DC=mydomain,DC=local 
repadmin /removelingeringobjects ACC-PRD-ADV2 fd0814d7-df3d-4547-b29d-xxxxxxxxxxxx DC=mydomain,DC=local 
repadmin /removelingeringobjects ACC-PRD-ADV2 fd0814d7-df3d-4547-b29d-xxxxxxxxxxxx DC=ForestDnsZones,DC=mydomain,DC=local 








RODC in DMZ - User Accounts can authenticate - Computer Accounts can not

$
0
0

Hi everyone,

i am having a RODC in a DMZ. Useraccount Authentication works fine (IIS and RDS Gateway) - but computer authentication does not.

Our RDS Gateway works with non domain joined computers. But when i try to connect from a domain joined - it fails.

Our Software Deployment Webserver can be accessed by browser with username and password but fails with the computer account.

Is the setup just not right for this purpose or did i miss something?

I removed the global catalog from the RODC because "some applications may not work right" but this did not fix it.

Anyone can help me out?

Best regards

Stephan


<h3>Regards Stephan</h3>

Record SRV issue with domain controler

$
0
0

Hi,

I have an issue in a customer environment.

2 Domain controller AD1 + AD2. Both 2016 server and both DNS.

AD1 is configured with AD2 as first DNS and AD2 is configured with AD1 as first DNS (127.0.0.1 second for both).

There is event 5774 when netlogon service is restarted.

I check all what I can find on the internet but nothing help.

event 5774 mentions AD1 can't write AD2 srv record on zone xxx .... because access denied.

I have issue with domaine zone name and _msdcs too. The issue is on both domain controller.

Only solution to avoid this issue is to put AD1 with AD1 as first DNS. Then if I restard netlogon -> no error.

-I enabled netlogon log but nothing more than I can see in eventlog.

-I don't have any cname with AD1 name.

I don't know really how I can find informations...

Thank you for your help :)


Merci de marquer comme reponses les interventions qui vous ont ete utile.

LAPS Install: Update-AdmPwdADSchema : The requested attribute does not exist

$
0
0

has anyone seen this issue before, I'm having problem running the following command for LAPS to work but its takes me nowhere using online search

This is what i have done

1. I'm an schema master admin, domain admin and enterprise admins and running the powershell command on FSMO server

2. Running the commands from elevated powershell

3. running update-admpwdADSchema works for the first two entries AddSchemaAttribute, third step update-admpwdadschema throws an error message "Update-AdmPwdADSchema : The requested attribute does not exist."

4. there is no logs i can see why its breaking. 

Group User Update - VPN

$
0
0

When the user is on Cisco VPN or any third party VPN on a Windows 10 device the user group membership does not enumerate properly. For example, we have a group called W10RemMedia that we add users that needed USB access. When on the VPN, if the user is being added to the group, then it never updates on the user end device. Running gpupdate/force or logoff/login/restart did not work since its not on the domain yet. So after connecting to VPN if i run whoami /groups or gpresult /r the group name never shows up. I tried klist -lh 0 -li <Hexadecimal> purge, but of no use. The other workaround is to kill the explorer and launch it again. But here the map drive are lost. Any other solution ?

Hexadecimal Value is retrieved using - 

gwmi Win32_LogonSession | % { $one = $_ ; $one.GetRelated('Win32_Account') | Select Domain, Name, SID, @{ n = 'LogonSessionHEX' ; e = { '0x{0:X}' -f ([int] $one.LogonId) } }, @{ n = 'LogonSessionDEC' ; e = { $one.LogonId } } , @{ n = 'LogonType' ; e = { $one.LogonType } } }

Access Denied while updating GPO from Domain Controller &

$
0
0

I have OU for Server in DC (blocked inheritance) with over 100 Servers in it, there are around 6 policies applied. I have two issues described below:

1. While applying "Group Policy update" from OU in the DC, 70 Servers return 'Successful' and remaining return error '0x80070005'Access denied. these server have no special permissions and having same OS.

2. I have configured policy for Auditing and applied to all servers, i have checked the Servers after update and all of them couldn't configure it with message "the policy engine didn't attempt to configure the settings". i doubled checked and there is no duplicated policy for Auditing.

(see the attached image)

How to find out which users are going to be disabled and how to send out a request for approval to extend to manager?

$
0
0

I'm new to this, so bare with me please... 

We have contractors that have access to well everything until their contract ends. What I need to do is a bullet list of things, and if I can find a way to do it, it would be greatly appreciated. 

  1. Search for users that are going to lose access within two weeks. 
  2. Send a request to reporting manager asking if user contract to be extended. 
  3. Send manager response to an email address which will be checked by us. 

Is this possible using the Active Directory Admin Center? 


trying to applocker modern Snip and Sketch packaged app, error on client computer is: MicrosoftWindows.Client.CBS was prevented from running

$
0
0

Environment is Server 2019, client computers are Windows 10 Enterprise SAC 2004.

Applocker is enforced, default is no apps are allowed.  Goal is to whitelist the modern Snip and Sketch packaged app via applocker.  An applocker packaged app rule was created and its associated GPO pushed out.  The packaged app rule done is apparently working in the sense that on a client computer the modern (from Store) Snip and Sketch packaged app will launch successfully, you can see the initial starting GUI for it,  and in event logs "MICROSOFT.SCREENSKETCH was allowed to run." appears.  But when you click on the "New" button in Snip & Sketch GUI, the classic applocker error  'This app has been blocked by your administrator' appears. 

In the event logs this always coincides with clicking the 'New' button in the Snip GUI: 

MicrosoftWindows.Client.CBS was prevented from running.

-System
-Provider
[ Name]Microsoft-Windows-AppLocker
[ Guid]{cbda4dbf-8d5d-4f69-9578-be14aa540d22}
EventID8025
Version0
Level2
Task0
Opcode0
Keywords0x1000000000000000
-TimeCreated
[ SystemTime]2020-04-21T22:21:09.7372225Z
EventRecordID1117
-Correlation
[ ActivityID]{cfac03a8-1802-0000-648a-accf0218d601}
-Execution
[ ProcessID]5892
[ ThreadID]4344
ChannelMicrosoft-Windows-AppLocker/Packaged app-Deployment
Computer
-Security
[ UserID]S-1-5-21-3304803338-235052546-3618928178-34741
-UserData
-RuleAndFileData
PolicyNameLength4
PolicyNameAPPX
RuleId{00000000-0000-0000-0000-000000000000}
RuleNameLength1
RuleName-
RuleSddlLength1
RuleSddl-
TargetUserS-1-5-21-3304803338-235052546-3618928178-34741
TargetProcessId5892
PackageLength27
PackageMicrosoftWindows.Client.CBS
FqbnLength128
FqbnCN=MICROSOFT WINDOWS, O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US\MICROSOFTWINDOWS.CLIENT.CBS\APPX\119.21101.11830.00

My question is, does anyone have any suggested workaround for this?  On the test computer that we use to capture packaged apps and applocker them, "MicrosoftWindows.Client.CBS" does not show up as an installed packed app.  I'm reluctant to create an applocker rule enabling 'MicrosoftWindows.Client.CBS' (if that even is possible) since I don't understand the overall scope of what it or an applocker allow rule would do.  On that same test computer, I did press the "New" GUI button in the Snip app, and compared the packaged app footprint before and after, but didn't see any new packaged apps there.

Thank you very much in advance if anyone has any ideas, this is a vexing matter for environments like ours where we don't want to allow the Store and all packaged apps by default, but still want to allow some approved ones like the modern Snip and Sketch.  We have other packaged apps whitelisted via applocker, and they are working OK.


DCPROMO never completes

$
0
0

Hi All,

I'm busy with 2 new DCs for a client. Done numerous DCPROMO's without an issue up until now.

When I DCPROMO, the prerequisites all pass with no issues. It then starts to prepare the installation, and seemingly stalls on preparing the local computer for ADDS. There is 1 error in the event log:

8524 - The DSA Operation is unable to proceed because of a DNS lookup failure.

However, I can perform an NSLOOKUP with no issues to any of the 3 existing DCs.

Things I have done:

* Restarted the VMs, and then uninstalled DNS / ADDS before restarting and trying again (I deleted any SYSVOL/NTDS folders);

* Deleted the computer object out of AD Sites & Services;

* Checked NSLOOKUP as I mentioned and it passes;

* Firewalls turned off on source / destination VMs;

* No traffic passing through a firewall on the network.

I am a member of the Domain Admins group, and the existing DCs are running Windows Server 2016 v. 1607 (14393.3564) while the new DCs are running Windows Server 2016 v. 1607 (14393.3504).

Any help would be appreciated.

Thanks!

NIS server alternatives for Windows Server 2016

$
0
0

It seems NIS server is no longer available since Windows Server 2016.

Currently we're using Windows Server 2012:

Anyone knows alternatives for Windows Server 2016?

thanks in advance,

oli


oli

An operation error occoured - when implementing LAPS on Win2012 server

$
0
0

I’m trying to implement LAPS (Local Administrator Password Solution) on a Server 2012.

The LAPS software has been installed with the Management Tools as the documentation describes.

The import of the AdmPwd.PS works fine but when running the “Update-AdmPwdSchema” I get the following error:

“An operation error occoured.”

*****************************************************************************************************
PS C:\Windows\system32> Update-AdmPwdADSchema
Update-AdmPwdADSchema : An operation error occurred.
At line:1 char:1
+ Update-AdmPwdADSchema
+ ~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : NotSpecified: (:) [Update-AdmPwdADSchema], DirectoryOperationException
    + FullyQualifiedErrorId : System.DirectoryServices.Protocols.DirectoryOperationException,AdmPwd.PS.UpdateADSchema

*****************************************************************************************************I've ensured that I am a part of Schema, Enterprise, and Domain admins, the schmmgmt.dll has been registered and I can see Active Directory Schemaas a valid MMC snap-in, and the PowerShell has been run as Administrator.

Please advise how I can proceed.

Br

Enabling SSO with ADConnect

$
0
0

When I try to enable Single Sing-On with ADConnect (fresh install, just yesterday first synced), it says "An Error Occurred while locating computer account". I do enter valid Domain Admin credentials.

Normal sync works fine without SSO.


MCSA Win10, MCSE Mobility, MCSA M365.

GPO for outlook auto archiving features

$
0
0

Good Morning Team,

My client is running a on prem Exchange 2016 organization with several servers in a DAG. They are running the latest CU16, and clients are in a Windows 2016 single forest/domain with their workstations using Windows 10 and office 2013/2016.


Here is the request, due to some space disk constraints, we are asked to implement Outlook Auto Archiving feature.
This would allow our users to move their mail to PST.  The option is located in File -> Options -> Advanced -> Auto Archive Settings and it is currently disabled.

Can you please provide me step by step instructions to setup a GPO user to implement this feature? Please, provide as much details as you can

By the way, this should be scoped to a group of users and not everyone in the organization.


Franki

Viewing all 31638 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>