HI
I need to make IE as default browser on windows 7 machines in my domain. Also no any user can change default browser to other browser like firefox and chrome.
How can i achieve it.. Please suggest.
HI
I need to make IE as default browser on windows 7 machines in my domain. Also no any user can change default browser to other browser like firefox and chrome.
How can i achieve it.. Please suggest.
Hello Technet,
After installing the update KB2843639 that addresses vulnerabilities for ADFS Service (see MS-13066) my ADFS service is not able to authenticate anymore.
In the event viewer I see:
364 Errors
Encountered error during federation passive request.111 Errors
The Federation Service encountered an error while processing the WS-Trust request.I tried setspn -a http/adfs serviceAccountName which did not solve it.
The only solution that I found is to remove the update and hide it so it does not come back.
I also have a second ADFS environment which was affected the same way by the update.
Anyone had the same issue?
I'm not quite sure if this is neccessarily the best place to ask for a solution to the actual issue we're having, but as we already have a workaround, I'm more looking for a generic overview of what happens during the domain join process in regards to our issue. If you can provide me with a shortcut solution to the problem, I won't complain, but my main goal is to understand what's going on.
Now for my question:
Basically, some clients are not trusting a certificate that they should. We have a workaround but I'd like to understand why it works, and if there's a better way to fix it. That is, if we remove one of the affected clients from the domain, reset the account, and rejoin, the problem is resolved.
What I'm wondering is, what is exactly is happening during the domain join process that changes certificate trust? How is it possible that some domain member computers trust a cert issued by our CA without any additional special configuration, while others do not trust that cert. Could the availability of the CA during the join process have affected this? (i.e., if the CA was down for maintenance when the computer was joined to the domain, would it alter whatever is normally done to make it trust certs issued by that server?)
For those of you who would like more context, here's what's going on:
We have an in-house web app that was recently updated and moved to a new server, and we're having a few issues with certificate trust. Shortly before the new server was built, we migrated to AD for our DS, and we are running a single 2008 domain. The new server is a domain member, and the certificate used by the application server was issued by an internal CA, which is currently still accessible. The old cert was self-signed, and installed manually on all of our OS images, and is therefore trusted by all of our PCs. I should also add that all of our desktops in this problem are currently members of the same domain as the server and CA.
The problem we're running into is that when removing the old version off the app (which points to the old server), and installing the new versions, some of the PCs are complaining that the new server certificate is not trusted. We can still connect, but the app is written such that it expects the PC to trust the server, and therefore fails to install properly. So far, this seems limited to *some* of our Windows XP client machines. Most XP machines, and, so far, all of our Win7 machines, have no issues.
we are replacing a 2003 DC with a 2012 DC.
and all the sysvol folder looks good, and the replication is working as well.
but once i open the GPMC , i found some of GPOs are able to edit, some of GPOs are unable to edit. and show below
Faild to open GPO, you might not have appropriate rights,
Details
the system cannot find the specific path
so how could I debug this. i didn't see any message in the event log.EventLog
Event Type: Failure Audit
Event Source: Security
Event Category: Account Logon
Event ID: 680
Date: 7/5/2011
Time: 3:03:08 PM
User: NT AUTHORITY\SYSTEM
Computer: DC
Description:
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon account: biswasd
Source Workstation: server01-isa
Error Code: 0xC000006A
Event Type: Failure Audit
Event Source: Security
Event Category: Account Logon
Event ID: 680
Date: 7/5/2011
Time: 3:03:09 PM
User: NT AUTHORITY\SYSTEM
Computer: DC
Description:
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon account: biswasd
Source Workstation: server01-isa
Error Code: 0xC0000234
Hi,
I keep getting the below event logged when a DC's Dns services are restarted.
The DNS server was unable to create a resource record for 899494f1-fac0-4405-8bf4-d3d2326d0449._msdcs.domain.local. in zone domain.local. The Active Directory definition of this resource record is corrupt or contains an invalid DNS name. The event data contains the error.
The server was demoted and promoted and the server received a new GUID but the server is still trying to register the 899494f1-fac0-4405-8bf4-d3d2326d0449._msdcs.domain.local entry. The entry does not exist in the domain.
I used the below article before we demoted the server and it however did not resolve the problem:
http://technet.microsoft.com/en-us/library/cc735667(v=ws.10).aspx
Does anyone have any ideas?
Thanks
Don
Kind Regards Don
What is the best way to deploy Distributed File System (DFS) to a large enterprise where you want user folders created for all domain accounts? Is there a script or powershell script to create the namespace subfolders? or is this part of the setup possibly?
For example:
\\domain.contoso.com\user\john
\\domain.contoso.com\user\beth
\\domain.contoso.com\user\bob
thanks!
Also, is there a way to change there documents folder to point to the \\domain.contoso.com\user\ with possibly a login script or home directory?
I am attempting to do an ADFS Proxy install on Server 2012. I am installing ADFS via the Add Roles/Features.
I have installed the main ADFS server and am attempting to install the ADFS Proxy. I have mapped the 443 bindings on the Default Web Site. When I attempt to run the ADFS Proxy Configuration I get an error stating that the SSL bindings need to be configured on the Default Website. I have ensured that the bindings are set and in fact working properly.
I have installed multiple test servers in my lab and my colleague has done the same, with the same results. We have uninstalled/reinstall ADFS and IIS, changed the IIS bindings to a multitude of configurations, ensured that Everyone/Anonymous has access to the certificate private keys, disabled the firewall, basically done everything we could think of to get past this error.
I am not able to find a single thing on the internet with anyone with the same problem, which I find hard to believe considering I can so easily reproduce and a few of our clients are having the same problem.
I have an incident open with MS Support but so far they haven't came up with anything either.
Anyone have any ideas?
Try this again, hopefully dillhole won't move my question to some visual studio forum for no reason...
I'm going to be setting up AD FS and DirSync for a hybrid Office 365 implementation, and in the past I just used TMG as the AD FS proxy. I do not have access to TMG for this client, but I'm hoping that using IIS ARR shouldn't be a problem, but haven't been able to find any documentation as such. Assuming it works, can someone point me in the right direction?
I uninstalled the following patches:
KB2843638
KB2843639
Then rebooted the servers but the Office365 webaccess still does not work.
I newly installed win2012 and AD DS but I got error by DCDIAG.
How could I resolve that and how could I English result of Dcdiag ?
C:\Users\Administrator>dcdiag /vWe currently have one domain with one site, with multiple domain controllers at multiple physical branch offices. I'm getting ready to add sites, subnets, and site-links to match our physical branch office topology. I'm confident on the process and layout. My only question is, when I move the respective domain controllers to their new sites in AD, how will that effect existing clients that are authenticated to these domain controllers? Will they stay connected to the DC if it is the correct one for their subnet? What if they are connected to a DC that isn't in their subnet, will they automatically connect to the new respective DC? Does this require a restart? Will there be any loss of connectivity?
Any input would be greatly appreciated! Thanks!
Hi all,
Having a problem the forums and Google have been unsuccessful in helping me with. Server is Windows 2003 R2, migrating to Windows Server 2012 foundation. Have tried the AD Migration on the new 2012 Foundation server both as a standalone server and a domain server member before running the migration. I get the following error:
ADPrep execution failed --> System.ComponentModel.Win32Exception (0x80004005): A device attached to the system is not functioning
I've checked the ADprep logs and have found the following:
[2013/01/22:11:15:01.000]We did have AVAST Antivirus installed on the server but this was removed. Any idea's?
Jason.
Consultant | Nerd | Visionary. http://www.ethertech.com.au/ | http://www.deeperstates.com.au
I have a very small domain (25 users) with the server being used as the DC and some very limited (36 Gb) file sharing, including a QuickBooks Db. I'm going t replace this with a new server running 2012 standard. Is there any 3rd party software out there to assist with this migration or would I be better off just doing it manually, creating the file shares and users, then joining the computers to the domain on site?
-Jim
-Jim
Hi people!
In GPO " ...-> Public Key Policies -> Certificate Service Client - Auto-Enrollment" is option "Additional stores. Use "," to separate multiple stores. For example:"stores1, stores2, stores3"".
What does this mean?
Thank youfor your answers!
Hi All,
I am posting this after making so many search in internet. One the AD user is continuously getting lockout, I have used lockoutStatus.exe and other method but not able to find out the reason. In Netlogon its showing the server name but it is our Exchange Server from where the hits is coming. I have checked in my exchange server but didn't find the cause.
1
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon account: username
Source Workstation: Exchange Server name
Error Code: 0xC0000064
2
Logon Failure:
Reason: Unknown user name or bad password
User Name: User name
Domain:
Logon Type: 3
Logon Process: Advapi
Authentication Package: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Workstation Name: Exchange Server name
Caller User Name: Exchange Server name$
Caller Domain: Domain Name
Caller Logon ID: (0x0,0x3E7)
Caller Process ID: 9844
Transited Services: -
Source Network Address: -
Source Port: -
Any one have idea about this, I have checked user machine, mobile and other options.
Thanks
Mukesh
Mukesh Bisht
I am running a Windows SBS Server 2011 Standard as a DC and Exchange Server.
After encountering issues with upgrading Sophos I restored the previous night's System State backup using Backup Exec. The Restore appeared to work ok, but after rebooting the server, I cannot access AD, email is not working, and other services fail to start.
When I run DCDIAG I obtained the following problem:
C:\Windows\system32>dcdiag
Directory Server Diagnosis
Performing initial setup:
Trying to find home server...
Home Server = XXXXXXXX
[XXXXXXXX] LDAP connection failed with error 0,
The operation completed successfully..
An error occurred during DNS host lookup, that the program could not recover
from.
[XXXXXXXXX] Unrecoverable LDAP Error 89:
I undertook more investigation and determined that the DNS Server is not running. When I manually try to start it the server responds with the following error:
I have not run out of disk storage.
In reviewing the eventlog, the DNS server cannot start as the service could not create a UDP socket (see extract from log)
Log Name: DNS Server
Source: Microsoft-Windows-DNS-Server-Service
Date: 16/08/2013 22:53:59
Event ID: 406
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: XXXXXXXX.xxxxx.local
Description:
The DNS server could not create a User Datagram Protocol (UDP) socket. The event data is the error code. Restart the DNS server or reboot your computer.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-DNS-Server-Service" Guid="{71A551F5-C893-4849-886B-B5EC8502641E}" EventSourceName="DNS" />
<EventID Qualifiers="49152">406</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2013-08-16T21:53:59.000000000Z" />
<EventRecordID>707</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>DNS Server</Channel>
<Computer>XXXXXXXX.xxxxx.local</Computer>
<Security />
</System>
<EventData Name="DNS_EVENT_CANNOT_CREATE_UDP_SOCKET">
<Binary>7A270000</Binary>
</EventData>
</Event>
I think that the system state has not restored the System Files or Registry correction. Because DNS is not working I also do a complete restore from Backup Exec as the service will not see the Server.
Any advice on how I can rectify the issue or repair the DNS server would be greatly appreciated.
Thanks
Allan