Quantcast
Channel: Directory Services forum
Viewing all 31638 articles
Browse latest View live

ADUC Error

$
0
0

Hi,

We are frequently having problem opening ADUC in our Windows 2012 Data Center Primary Domain Controller and getting the below error. The only way we can get it back is after restarting the server. The second DC is working fine which is Windows 2012 Std R2.

Any solution to this problem? We tried many things for troubleshooting but nothing worked.


Delegate permission to modify UPN

$
0
0

Hello all

Please let us know how to delegate permission for User to modify UPN for user object in an OU.

regards

Aamir


NA

How to find out which users are going to be disabled and how to send out a request for approval to extend to manager?

$
0
0

I'm new to this, so bare with me please... 

We have contractors that have access to well everything until their contract ends. What I need to do is a bullet list of things, and if I can find a way to do it, it would be greatly appreciated. 

  1. Search for users that are going to lose access within two weeks. 
  2. Send a request to reporting manager asking if user contract to be extended. 
  3. Send manager response to an email address which will be checked by us. 

Is this possible using the Active Directory Admin Center? 


Limit users who query AD ldap

$
0
0

Hi,

How do I prevent ordinary users from querying ldap? We have an application which we had one account used for application to connect to AD Ldap. What we have noticed is that ordinary users can do query against ldap. Can we apply delegation so that ordinary users cannot do query? If so, what would be the permissions? If ever we apply these permissions will it prevent them from logging in to the domain controller or use some other services?

Thanks,

Janus

Account Lockout Policy

$
0
0

Current settings :-

Account Lockout Duration - 0 minutes
Account Lockout Threshold - 5 invalid login attempts
Reset account lockout counter after - 60 minutes

I understand with above settings the user will never get unlocked automatically but admins will have to unlock the account.

I'm just confused with the below statement from Reset account lockout counter after settings:-

"If Account lockout threshold is set to a number greater than zero, thisreset time must be less than or equal to the value of Account lockout duration"

As you see the reset time(60 minutes) in my settings is not less that or equal to the value of account lockout duration(0 minutes).Is that wrong or what will be the impact ?

Thanks



migrate from 2008

$
0
0

hi guys,

is it feasible to install active directory 2016 in an organization running active directory 2003 and 2008?

i am planning to migrate to 2016

many thanks

Servers are not getting authenticated with their Gateway servers through Kerberos.

$
0
0

Hi ,

We recently faced a issue where some of the servers are not getting authenticated with their Gateway servers through Kerberos. So we received few alerts for heartbeat failure. When we check the status of the server, they were pingable and able to RDP. 

we tried restarting the Microsoft Monitoring Agent service(MMA) but still the alert is not getting cleared from SCOM.

Here the environment is Parent and Child. for example: AAA.local is the Parent domain and bbbb.AAA.local is the child domain.

Servers in child domain have alerted as unable to authenticate Gateway server in Parent domain through kerberos 

We are asked by the client to check Kerberos authentication between Parent and Child in the domain.

Following troubleshooting steps we performed:

1>We checked the Trust between Parent and Child domain, its getting validated. No errors.

2> We checked the PDC emulator of child domain, its showing no errors.

3>We checked few servers which alerted and no event found for the same at the time when alert got generated.

Looking for some advice/suggestion in this case. Please assist.

Virtual smart card

$
0
0

Hi,

Is there any way of using virtaul smart card when logging in with RDP besides doing that with tpm?

I have some flashback of some tool that could simulate smart card when logging with rdp.

Regards,


Delegate Permission to user in Specific organisation unite in Active directory 2012

$
0
0

Hello Dears,<o:p></o:p>

We have to delegate permission to specific IT support account in specific organization unite which is belong to all IT support team to make enable and disable their account, I did all the steps for delegation control in the IT support OU but it is not working, because all the IT members are member in another security account to have permission to join computers to the domain.<o:p></o:p>

Kindly any solution appreciates.<o:p></o:p>

Active Directory User Reports

$
0
0
I would like to generate reports for AD users on criteria like newly created, deleted, modified users, enable, disable and inactive users. I want to generate these reports for past 30 days only. Is there any script or reporting tool available for this purpose?

A user account was locked out.

$
0
0

Hello team,

We are using one AD FTP account where it is getting "A user account was locked out" alerts every day.How to fix it?

----------------------

A user account was locked out.

Subject:
Security ID: SYSTEM
Account Name: DC03$
Account Domain:PRODUCT

Account That Was Locked Out:
Security ID: PRODUCT\SSTEST
Account Name: SSTEST

Additional Information:
Caller Computer Name:CMF04

-----------------

Regards,

PR

AD Initial Replication and SYSVOL and NETLOGON Folder not Created Error: 1753

$
0
0

Hello ,

We have DC but its SYSVOL folder and NETLOGON Folder not getting created.

As per Event log : 1753

I have checked as per support artical that required ports are Listening and all services are working.

https://support.microsoft.com/en-in/help/2089874/active-directory-replication-error-1753-there-are-no-more-endpoints-av

I have also tried to reset that SYSVOL restiry from 0 to 1 but still folder is not replicated.

any help would be greate appicated.

The DFS Replication service encountered an error communicating with partner MYDC for replication group Domain System Volume.

 

Partner DNS address: MYDC.MYDCOMAIn.com

 

Optional data if available:

Partner WINS Address: MYDC

Partner IP Address: 20.3.200.103

 

The service will retry the connection periodically.

 

Additional Information:

Error: 1753 (There are no more endpoints available from the endpoint mapper.)

Thanks



Thanks , Prakash ,Please Note: My Posts are provided “AS IS” without warranty of any kind, either expressed or implied.

Dcdiag failed test VerifyReferences (Windows 2008 R2 Enterprise)

$
0
0

Hi All,

I have gone through Knowledge Base Article: Q312862 and it did not resolve the issue, any input or suggestions is welcomed!

My goal here is trying to safely upgrade our domain controller to 2012 R2, if we can safely ignore this error then that's good enough for me.

TIA,

Ron

Starting test: VerifyReferences

         The system object reference (serverReference)

         CN=ALPHA1,OU=NO_WSUS,OU=Domain Controllers,DC=rpmcsi,DC=com and

         backlink on

         CN=ALPHA1,CN=Servers,CN=SBC-Co-location,CN=Sites,CN=Configuration,DC=rpmcsi,DC=com

         are correct. 
         The system object reference (serverReferenceBL)

         CN=ALPHA1,CN=Topology,CN=Domain System Volume,CN=DFSR-GlobalSettings,CN=System,DC=rpmcsi,DC=com

         and backlink on

         CN=NTDS Settings,CN=ALPHA1,CN=Servers,CN=SBC-Co-location,CN=Sites,CN=Configuration,DC=rpmcsi,DC=com

         are correct. 
         Some objects relating to the DC ALPHA1 have problems: 
            [1] Problem: Missing Expected Value

             Base Object:

            CN=ALPHA1,OU=NO_WSUS,OU=Domain Controllers,DC=rpmcsi,DC=com

             Base Object Description: "DC Account Object"

             Value Object Attribute Name: frsComputerReferenceBL

             Value Object Description: "SYSVOL FRS Member Object"

             Recommended Action: See Knowledge Base Article: Q312862

             
         ......................... ALPHA1 failed test VerifyReferences

Permissions for External Monitoring of Domain Controllers

$
0
0

We have eight domain controllers being hosted by an external data center. The data center administrators requested a domain administrator account for their monitoring tools and to apply monthly Windows Update patches.

Question: Is there a set of permissions I can assign their account which will allow their monitoring and update tools to work without the full domain administrator assignment?

Thanks for your thoughts.

Can't open word doc because path is too long in Windows 2012

$
0
0

Can't open word doc because path is too long in Windows 2012.

Is it a normal behaviour or there is a fix for that?


ADUC, Right-Click, Context Menu

$
0
0
Is there a way to add a menu item with sub-menu items on the, right-click, context menu of a user object in Active Directory.
I want to add a few menu items to the context menu, but I'd rather not lengthen the menu with 4 additional menu items if I can create a menu item, with sub-menu's.

AD Replication not Working All DC are in inital sync in DFS state = 2 = Initial Sync

$
0
0

Hello ,

We have 8 Domain controllers and all  DCs  sysvol folder is not replicating with each other including PDC.and

all  DC 's DFS state is   = Initial Sync instead of Normal= 4 and all DCs are logged events as waiting initial sync

Ref  : https://support.microsoft.com/en-in/help/2958414/dfs-replication-how-to-troubleshoot-missing-sysvol-and-netlogon-shares 

The "state" values can be any of the following:

0 = Uninitialized

1 = Initialized

2 = Initial Sync

3 = Auto Recovery

4 = Normal

5 = In Error


How can I make all them to state to Normal.

Any help would much apricated.

Please see below screen shot.



Thanks , Prakash ,Please Note: My Posts are provided “AS IS” without warranty of any kind, either expressed or implied.

C:\Windows\System32\lsass.log

$
0
0

Hello Team,

C:\Windows\System32\lsass.log size 45 GB and its not a doamin controller, please let me know if i can delete the log.


Ashok

Event ID's Monitoring

$
0
0

Do we need to explicitly configure in GPO in order to make sure below events registered in event viewer when ever respective action happened? or by default this settings will exist?

Event IDDescription
1100The event log service has shutdown
1102The audit log was cleared
4704A user right was assigned
4705A user right was removed
4715The audit policy (SACL) on an object was changed
4719System audit policy was changed
4728A member was added to a security-enabled global group
4729A member was removed from a security-ena-bled global group
4771Kerberos pre-authentication failed
4772A Kerberos authentication ticket request failed
4773A Kerberos service ticket request failed
4780The ACL was set on accounts which are mem-bers of administrators groups

AD Group Migration vs Group Membership vs SID History

$
0
0

Hello,

Recently, I migrated groups from source to target domain including SID History. I'm planning to administer group membership in only the target domain. However, all resources are in the source domain. Source groups are applied on resource ACL in source domain.

If I add a non-migrated user (newly created in the target domain) into a migrated group in the target domain then

Question: Should the user be able to access resource (based on permissions granted to source group) in the source domain just via sidhistory because user token will have the sid of source group in sidhistory attribute of migrated group?

Kindly reply with explanation.

Thanks in advance

Alex Lee

Viewing all 31638 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>