Quantcast
Channel: Directory Services forum
Viewing all 31638 articles
Browse latest View live

Join two different active directories in one

$
0
0

Hi,

I have two different domains and the CIO is thinking to join both domains in one, with a different name of these.

I would like to know the advantages and disadvantages of this and, how to do the integration.

Can anybody help me or give any link with this information?

Thanks in advance.

Regards.


SPN management of Managed Service Accounts

$
0
0

Hi,

Managed Service Accounts has two main benefits, first, simplified password management (so clear), and the second one, SPN management.

Exactly (an overview description will be enough), what are the main Service Principal Name management benefits of MSA?


Thanks in advance

Update AD-User Group-Membership for "offline" Notebooks

$
0
0

The Environement: I have a notebook in active directory and a domain user. The connection to DC is only available after the login process (when the WLAN-connection is established). This give us some elegant simplifications to fix a notebook to one user. We prepare the notebooks over LAN, log on the correct user and disconnect LAN. After this it is not possible for another user to login because there is no logon-server available.

The Problem: When I change a group membership of the user on the AD, this change is never committed to the (ad-)user on notebook.

gpupdate didn't work: The GPs are updated after the network change when user is logged in - all settings are taken directly or at next logon, but the group membership is still the same.

some tries with klist didn't work: Tickets are created, purged and recreated, the group membership is still the same.

I read the group membership with an PS-Script around the statement:

[System.Security.Principal.WindowsIdentity]::getCurrent().Groups

Forest Wide DNS Zone

$
0
0

If I make a DNS Zone forest wide, would all the DC in the forest be able to edit the DNS zone.

Bitlocker - permission for deleting computer with bitlocker key

$
0
0
Hello,

I'm in process of delegating permissions in our Active Directory. I found problem when i try delete computer with bitlocker key using non-Domain Admin account. It's not possible, I got error stating not enough permission.

Of course I added Create/Delete Computer permission but its not enough for such computers. Regular computer without any child object can be deleted successfully.

Do you have any idea what I need more to be able to delete computer with bitlocker key?


Thanks in advance.

Regards

Arek

adprep /domainprep error 0x208d

$
0
0

Hi,

I need to replace my current DC with new one and I want to degrade current DC to backup (second DC).

My current DC is:
- Windows 2003 SP2 x86, language: PL
- Domain functional Level: 2003
- Forest functional level: 2003
- AD schema version: 47

My new DC is:
- Windows 2008 R2 SP1 x64, language: EN

My plan is: promote new DC as additional DC for an existing DC, transfer FSMO, DHCP, etc...

But during promotion I have an error:

On current DC I executed adprep32.exe (from install CD of Windows 2008 R2) with /domainprep option but I had errors:

Adprep was unable to modify the security descriptor on object CN=IP Security,CN=System,DC=main,DC=domain,DC=local.

[Status/Consequence] 
ADPREP was unable to merge the existing security descriptor with the new access control entry (ACE).


Adprep encountered an LDAP error. 

Error code: 0x20. Server extended error code: 0x208d, Server error message: 0000208D: NameErr: DSID-031001CD, problem 2001 (NO_OBJECT), data 0, best match of:
	'CN=System,DC=main,DC=domain,DC=local'
.

Adprep was unable to update domain information. 

[Status/Consequence]
Adprep requires access to existing domain-wide information from the infrastructure master in order to complete this operation.


Could this be due to differed language versions on current DC and new DC?


Moving from 2008DC to 2012DC

$
0
0

Hello, have a few questions regarding moving from a 2008DC to a 2012DC. This is my first time adding/replacing DCs, so trying to make sure I have taken care of everything.

What I've done so far:

  1. Built 2012 server and installed AD/DNS roles
  2. Transferred over Schema Master, Domain Naming Master, PDC, RID, Infrastructure Mgr ROLES
  3. DCpromo the old 2008DC

Is this the correct process and does it sound like there are any steps I've missed?

When doing the DCPromo on 2008DC, it gave me an error "failed because is not the last AD DC in the Domain", which I was able to get around by using the /forceremoval switch. Is that normal? I figured it would allow you to demote a DC once a new one was built, or did I do something wrong here?

Which brings me to the next part, there are a ton of references left pointing to the old DC, mainly in DNS, which I've gone and deleted them all following this guide:

http://awinish.wordpress.com/2011/05/08/metadata-cleanup-of-a-domain-controller/

Should I just go ahead and delete the object in ADUC?

Should I also delete the "DC08" object in AD Sites and Services?

Thanks for any help folks!

dcpromo remove domain controller 2008 R2 fails - could not transfer the remaining data in directory partition.

$
0
0

Most Domain Controllers are now Windows 2012
Forest and Domain functional level is Windows 2008 R2

---

Trying to dcpromo a Windows 2008 R2 domain controller down to member server and during dcpromo got a message:

The operation failed because:

Active Directory Domain Services could not transfer the remaining data in directory partition
DC=ForestDNSZones, DC=<domainname>,DC=org to
Active Directory Domain Controller \\DCNAME.domainname.org.

"The directory service is missing mandatory configuration
information, and is unable to determine the ownership of floating
single-master operation roles."

---

Running DCDIAG on the server - NCSecDesc fails
      Starting test: NCSecDesc
         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
            Replicating Directory Changes In Filtered Set
         access rights for the naming context:
         DC=DomainDnsZones,DC=domain,DC=org
         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
            Replicating Directory Changes In Filtered Set
         access rights for the naming context:
         DC=ForestDnsZones,DC=domain,DC=org

One of the TechNet articles says that adprep /rodcprep  from Windows 2008 R2 needs to be run and would eliminate the NCSecDesc fail error.

Can I still run adprep /rodcprep even after Windows 2012 domain controllers have been added to the domain (which I understand changes the schema during insertion of Windows 2012 domain controller)?

What options do I have to resolve getting the Windows 2008 R2 domain controller dcpromo'ed down to member server?

Thanks,


F.Palacio


sIDHistory for groups

The security database on the server does not have a computer account for this workstation trust relationship

$
0
0
This problems exists in the below Environment

ForestA, has been around awhile, has one domain Called DomainQ

ForestC, is new, has one domain called DomainR

ForestC has a one way transitive trust to ForestA and shares a namespace. Dns connectivity is in place, NTP is working correctly where ForestC pulls its time from ForestA and users in ForestA have been permissioned on devices in ForestC.

Below is the netlogon dump and log files that look relevant, it's odd because I get a successfully logged on message but the users is prompted with "The security database on the server does not have a computer account for this workstation trust relationship" and when the click on they are back at the logon prompt. Nothing related to that error message that I have tried has helped.

http://technet.microsoft.com/en-us/library/ee849847%28WS.10%29.aspx

The above was not any help as this is a one way transitive forest trust so the trust level is already 2. The other 5 suggested links were also not useful.

07/18 12:18:29 [LOGON] [556] SamLogon: Network logon of DomainQInForestA\UserInDomainQ from UsersDesktopInDomainQ Returns 0x0
07/18 12:18:33 [LOGON] [556] SamLogon: Network logon of DomainQInForestA\UserInDomainQ from UsersDesktopInDomainQ Entered
07/18 12:18:33 [LOGON] [556] SamLogon: Network logon of DomainQInForestA\UserInDomainQ from UsersDesktopInDomainQ Returns 0x0
07/18 12:18:33 [MISC] [556] DsGetDcName function called: client PID=1636, Dom:DomainQInForestA Acct:(null) Flags: RET_DNS
07/18 12:18:33 [MISC] [556] NetpDcInitializeContext: DSGETDC_VALID_FLAGS is c03ffff1
07/18 12:18:33 [MAILSLOT] [556] NetpDcPingListIp: DomainQInForestA.My.Forest.Name: Sent UDP ping to IPv6AddressUniquetoDCinDOmainQ
07/18 12:18:33 [MISC] [556] NetpDcAllocateCacheEntry: new entry 0x000000D29F24EB50 -> DC:DCinDomainQ DnsDomName:DomainQInForestA.My.Forest.Name Flags:0x71fc
07/18 12:18:33 [MISC] [556] NetpDcGetName: NetpDcGetNameIp returned 0
07/18 12:18:33 [MISC] [556] DsGetDcName: results as follows: DCName:\\DCinDomainQ.DomainQInForestA.My.Forest.Name DCAddress:\\IPv6AddressUniquetoDCinDOmainQ DCAddrType:0x1 DomainName:DomainQInForestA.My.Forest.Name DnsForestName:My.Forest.Name Flags:0xe00071fc DcSiteName:SiteInDomainQ ClientSiteName:SiteInDomainQOfClients
07/18 12:18:33 [MISC] [556] DsGetDcName function returns 0 (client PID=1636): Dom:DomainQInForestA Acct:(null) Flags: RET_DNS
07/18 12:18:33 [MISC] [2800] DsGetDcName function called: client PID=4, Dom:DomainRinForestC.SpecialProject.My.Forest.Name Acct:(null) Flags: IP KDC
07/18 12:18:33 [MISC] [2800] NetpDcInitializeContext: DSGETDC_VALID_FLAGS is c03ffff1
07/18 12:18:33 [MISC] [2800] NetpDcGetName: DomainRinForestC.SpecialProject.My.Forest.Name using cached information ( NlDcCacheEntry = 0x000000D29F269FC0 )
07/18 12:18:33 [MISC] [2800] DsGetDcName: results as follows: DCName:\\DCinDomainRinForestC.DomainRinForestC.SpecialProject.My.Forest.Name DCAddress:\\IPv4AddressofDCinDomainRinForestCDCAddrType:0x1 DomainName:DomainRinForestC.SpecialProject.My.Forest.Name DnsForestName:DomainRinForestC.SpecialProject.My.Forest.Name Flags:0xe00071fc DcSiteName:Default-First-Site-Name ClientSiteName:Default-First-Site-Name
07/18 12:18:33 [MISC] [2800] DsGetDcName function returns 0 (client PID=4): Dom:DomainRinForestC.SpecialProject.My.Forest.Name Acct:(null) Flags: IP KDC
07/18 12:18:34 [SESSION] [2912] I_NetLogonGetAuthData called: (null) DomainRinForestC (Flags 0x1)  
07/18 12:19:16 [SESSION] [1968] I_NetLogonGetAuthData called: (null) DomainRinForestC (Flags 0x1)  
07/18 12:19:29 [MISC] [2912] DsGetDcName function called: client PID=916, Dom:(null) Acct:(null) Flags: DS BACKGROUND
07/18 12:19:29 [MISC] [2912] NetpDcInitializeContext: DSGETDC_VALID_FLAGS is c03ffff1
07/18 12:19:29 [MISC] [2912] NetpDcGetName: DomainRinForestC.SpecialProject.My.Forest.Name. using cached information ( NlDcCacheEntry = 0x000000D29F269FC0 )
07/18 12:19:29 [MISC] [2912] DsGetDcName: results as follows: DCName:\\DCinDomainRinForestC.DomainRinForestC.SpecialProject.My.Forest.Name DCAddress:\\IPv4AddressofDCinDomainRinForestCDCAddrType:0x1 DomainName:DomainRinForestC.SpecialProject.My.Forest.Name DnsForestName:DomainRinForestC.SpecialProject.My.Forest.Name Flags:0xe00071fc DcSiteName:Default-First-Site-Name ClientSiteName:Default-First-Site-Name
07/18 12:19:29 [MISC] [2912] DsGetDcName function returns 0 (client PID=916): Dom:(null) Acct:(null) Flags: DS BACKGROUND
07/18 12:22:17 [SESSION] [1040] DomainRinForestC: NlTimeoutApiClientSession: Unbind from server \\DCinDomainRinForestC.DomainRinForestC.SpecialProject.My.Forest.Name (TCP) 1.

An account was successfully logged on.

Subject:
    Security ID:        NULL SID
    Account Name:        -
    Account Domain:        -
    Logon ID:        0x0

Logon Type:            3

Impersonation Level:        Impersonation

New Logon:
    Security ID:        DomainQInForestA\UserInDomainQ
    Account Name:        UserInDomainQ
    Account Domain:        REDMOND
    Logon ID:        0x81D94
    Logon GUID:        {00000000-0000-0000-0000-000000000000}

Process Information:
    Process ID:        0x0
    Process Name:        -

Network Information:
    Workstation Name:    UsersDesktopInDomainQ
    Source Network Address:    -
    Source Port:        -

Detailed Authentication Information:
    Logon Process:        NtLmSsp
    Authentication Package:    NTLM
    Transited Services:    -
    Package Name (NTLM only):    NTLM V2
    Key Length:        128

AD site to forest ws 2012

$
0
0

Hello,

I have one new forest and site up and running.

this single site has one DC (ws 2012) with AD, DHCP, DNS, file, AC CA. Direct access and vpn (wizard walkthrough and working) with subnet 10.10.0.0 / 16
this site is de main office and has an fix public IP, and is behind a ISP managed Router. (the ports and protocol for VPN & direct access are forward to the WS2012 server) I can connect from a public network with vpn to this site. These and the new site have no "hardware VPN tunneling hardware" so I want to us the RRAS in the WS2012 to accomplish this.

In "sites and services" I have created for the moment 2 sites one with the subnet 10.10.0.0 /16 (main office) and renamed "default site" to the appropriate name
and one with 10.11.0.0 /16 for the new site and give it a name.

then I installed de new WS2012 in the main site en promoted it to be also a DC and dhcp and dns,
so it would receive a computer certificate an domain policy of the first DC in de main office.

No I want to take de new WS2012 out to de new site (with public changing ip (I have Dyndns for that)) this network is also behind a ISP managed modem/router/nat device. I will also look to forward the necessary ports and protocol and connect it to the main private subnet with the vpn site-to-site function of the ws2012 server. that's where I am stuck. I have look over the internet and found numerous examples to connect a site-to-azure but not site-to-site with the native ws2012 software. I think I have to bring op the vpn tunnel before I can do al the other settings like AD replication, DFS file replication .. ...

I have working with AD for the past 8 years but never used site and services ...
If I open up the RRAS console I do not find where I can define the vpn tunnel with the endpoints and subnet, if I use the remote access wizard I (with is for client connection not for site to site) I do not find a option to configure site-to-site...

both servers have 1 NIC, this setup is for a non profit social enterprise, and this way I can manage al the user en clients from on domain, and there is a possibility to share document to each other instead of using Googles drive or drop box, :(  in the future there is one main office and 6 sub sites across town, no it is really hard to manage everything because all the client are in different workgroups with one NAS device per location :-(.  Changing to Azure is no option here there is no funding for that, I can get cheap licensing and hardware because thy are registered as "social ware VZW".

can any help me with setting up this Forest wit sites across town, and for the easy configuration one domain name is adequate for the forest, so I do not think I need sub domain names, unless this is necessary of a technical point of view (direct access for the site clients, replication, .... ), or are there some partners that can teach me this on site ? (Belgium -West-Flanders ) I can pay a small amount if necessary.

I would appreciate faze by faze help,

if any info is still missing pleas give me a sign.

Thank you very, very much.

(sorry for my grammatical errors I am native Dutch speaking )

AD LDS windows principal fails to authenticate with ADSI Edit

$
0
0

I have created and LDS standalone instance (on a box not in a domain) and am able to authenticate LDS native users with a simple bind using ldp.exe 3.0 or my app.  Now  I have added windows principal (local user acct) to the member attribute of the readers role.  I cannot bind to it using ldp.exe and  have put in on another thread.  I also am not able to bind to the configuration partition using ADSI Edit (from another machine) as follows:

Start > ADSI Edit

right click ADSI Edit > connect to...

name: StandAlone

Select a well known: Configuration

servername:50000

Advanced

Specify credentials

I have tried both servername\username and just username here

pw

check   simple bind (I have also tried unchecking)

OK

Then it keeps asking for creds.

I know the creds are correct because I can use the same creds to bind to the Schema partition using ADSI Edit and I can also rdp to the lds box using those creds.

I am running ADSI Edit Version: 6.1.7601.17514 on Windows Server 2008 R2 Enterprise.  The LDS box is running R2 Standard.

What is wrong?

Thanks.


leo


Netlogon and sysvol folder share error

$
0
0

Hi,

We have a domain, and 3 domain controllers. and all DCs are Windows Server 2012 OS.

DC01 and DC02 are in one site and DC03 is in another site.
DC02 is a role box
on DC03 we are getting below error message while running dcdiag command


Starting test: NetLogons        
 Unable to connect to the NETLOGON share! (\\DC03\netlogon)  
 [DC03] An net use or LsaPolicy operation failed with error
 67, The network name cannot be found..  
 ......................... DC03 failed test NetLogons     

and net share result:-

Share name   Resource                        Remark

-------------------------------------------------------------------------
C$           C:\                             Default share
D$           D:\                             Default share
E$           E:\                             Default share
IPC$                                         Remote IPC
ADMIN$       C:\Windows                      Remote Admin
The command completed successfully.

Please suggest..

Thanks in Advance


Abhishek

DNS on 2008 r2

$
0
0

Have creatd a standalone server , added a couple of primary zones, but I can't get this to reslove anything but 'A' records. Nothing like MX records come back. All that is returned are a list of root servers.

This server is not recursive, I'm just trying to resolve what is in the local zones.

Could it have anyhting to do with Global QueryBlock List? I have disabled it.

Thanks


MJK

Child Domain vs Trust Relationship

$
0
0
So here is the scenario-

We are in the process of centralizing IT to a data center in a single location.  I currently have 12 different operating companies that need a shared security and exchange functionality.  As it stands they are all separate individual domains of varying levels.  There is a company wide accounting system that needs to be integrated with AD currently running in a completely separate domain as well that I would like to see people using their own AD log on info to use.

Here is my question-

Knowing that all the Active directory domains need to be touched regardless to get them all up to a uniform functional level and that there is significant work to be done no matter what, which configuration would be best?  I know there are several points to each one, but I want to make sure I am covering my bases now before choosing a path.  Do I go for a single forest\parent domain?  Or separate domains using trusts between the corporate domain and the operating companies like a spoke and hub config? What are the pros and cons of each?

Thanks-

Active Directory questions

$
0
0

What happens when an active directory server were to get turned off by accident for 6 months. After 6 months the DC get turned back on and it is out of sync from the other DCs. Since it is passed the default tombstone of AD, replication will occur or try to occur. Will the 6 month dc that was turned off, replicate the missing changes or try to replicate the missing changes that the other DCs dont have but itself has causing stale records or will the other DCs try to update it with all the new information?

Second question is related to AD Replication. I ran the command repadmin /showpostmail /latency DC=va,DC=postmail,DC=com   and it showed me SIDS below instead of showing me the site link and DC name. The entries are expired, but just trying to understand what they are doing their and if they will harm anything if I leave them or will they eventually disappear automatically.

c992b4e5-4bb9-4183-a9d3-57c82c4a6e6f @ USN    135422 @ Time 2012-01-26 18:48:58

8cce4140-02d9-4c05-94y4-80235eeae424 @ USN    131209 @ Time 2012-02-17 19:59:56

Event ID 1168, ActiveDirectory_DomainService Any suggestions?

$
0
0

Internal error: An Active Directory Domain Service error has occurred.

Additional Data

Error value (decimal):

-1032

Error value (hex):

fffffbf8

Internal ID:

160207ce

Task Category: Internal Processing

The error message has appeared on the system the last 5 days. Any suggestions for solving it?

How to Enable the Check box "Allow inheritable permissions from parent to propagate to this object" on all Users

$
0
0

I have to enable the Check Box in Active Directory 2008 R2,  "Allow inheritable permissions from parent to propagate to this object" on all Users of about 300.

We have about 50 OUs.

I try to apply the Scripts Mentioned here:

http://social.technet.microsoft.com/Forums/windowsserver/en-US/db378974-9cbf-4712-9978-f6a1a5234c16/allow-inheritable-permissions-from-parent-to-propagate-checkbox

It not seems to work.

What is the Exact way to apply these scripts in 2008 r2.

is there Program to achieve this goal?


Problems creating a child domain - Verification of outbound replication failed

$
0
0

Hello,

I have seen other threads relating to this issue, but nothing has yet solved my problem.

All my servers are Windows Server 2012

So far, I have a DC for Domain.co.uk

I am trying to create the child domain int.Domain.co.uk

The main error that I receive when using ADDS config wizard, is:

Verification of outbound replication failed. Error reading the options property of the NTDS settings. Unknown error (0x8000500c)

Also, when on the 'Deployment Configuration' page of the wizard, when I click the Parent Domain Name 'Select...' button, and it prompts me to select a domain in the forest, the only thing that is available to select is a long string of numbers. Example - '01 363 747 838 292 28 298 363 363 767 35 536 367 67 678 687'.

So far I have attempted to turn off the firewall, have the child DC joined onto the domain, re-enabled recursion on the parent DC ...

Any help appreciated :D

Thanks

Server 2012 restrict active directory dynamic ports

$
0
0

Hello,

Has anyone encountered issues with restricting the Active Directory dynamic ports for Netlogon and NTDS in Server 2012?  I have followed the added the typical registry entries as described below but I still see my RDS gateway in the DMZ trying to communicate to my internal DC over other ephemeral ports (49158).  I have rebooted the DC after the registry changes and still no effect.  Are the reg entries the same in 2012?  Any help would be appreciated.  Thank you

Registry key 1 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS\Parameters 
Registry value: TCP/IP Port 
Value type: REG_DWORD 
Value data: 49152 (This value needs to be specified in decimal format)

Registry key 2 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters 
Registry value: DCTcpipPort 
Value type: REG_DWORD 
Value data: 49153 (This value needs to be specified in decimal format)



Eddie Espino | Secure Data Solutions | Miami, Florida | Microsoft Partner

Viewing all 31638 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>