Quantcast
Channel: Directory Services forum
Viewing all 31638 articles
Browse latest View live

logon script for network desktop

$
0
0

Hey, i'm trying to figure out how i should change the desktop location from a script.

What i'm trying to do is, when the user logs in with the active directory user, the desktop should be changed to a desktop folder for the specific user on the server.

Does anyone know how this could be done ?


Problematic issues in installing backup domain controller on Virtual Machine

$
0
0

Hello,<o:p></o:p>

I have a physical domain controller - windows Server 2012 R2 Standard installed
in my domain environment and this is a first root domain controller.
I have also Hyper-V Server 2012 R2 installed and joined in that domain. 


Now I want to install an additional (Backup) domain controller as a virtual
machine hosted on Hyper-V Server. So while promoting VM as a DC all actions and
steps go well but the problem arise when I press the install button at the end
of the promotion - installation gets stuck in the process of writing some
configuration files on first DC and also in the process of replication. Unfortunately
VM does not promote as a DC and it goes to restart.

The error event log with - NETLOGON source is logged on the virtual machine as
well.

Do you have some suggestions with this issue, or experience how to resolve this..

Thanks a lot in advance,

GMG

<o:p></o:p>




Installing additional domain controller on remote site

$
0
0

Hi, we have two locations Mumbai and Banglore and connected both using vpn connectivity. We are able to ping each other networks. We have primary domain controller in mumbai and want to install additional domain controller in banglore. Mumbai network - 192.168.1.0/32 and banglore 192.168.2./32. Now before installation starts on banglore site i have to create new site and subnet at mumbai end for banglore server?  If yes then while installation in banglore server i need to select the default-first-site-name or need to use the correspond ip add from list 192.168.2.0/32?

Please help.

ADFS queries

$
0
0
When we create RPT with only URL without any signature certificate, then 


1. How the username and password traverse in internet(HTTP ?, How the authenticated cookies going to be secured?).


2. Can we send Kerberos token over HTTPS?


3. Only reliance on SAML is not enough


       Things SAML Does not Do:


                Determine how secure the IdP webserver is - Server hardening should be done?


                Ensure that web forms are secure - Pen testing for web forms?


                Standardize authentication mechanisms - Consider 2FA?


                Determine where data is extracted from, and what ID is asserted - 


                Enforce how an event is logged


4. As there is no public certificate provided , so there will no “Encryption” or “Signature” certificate in the relying party trust. - How the trust is maintained then?


5. How secure the communications is in the architecture?

Can you please help me with these queries.

ADFS 3.0 Migration for Office 365 Federation

$
0
0

I currently have Office 365 federated to our ADFS 2.0 deployment. We have a limited number of federations (but crucial) and felt more comfortable in standing up a completely separate ADFS 3.0 deployment outside the ADFS 2.0 production environment.  What I'm looking for is any guidance on how to the move the federation for Office 365 from our ADFS 2.0 implementation over to ADFS 3.0.  I've seen several posts about creating federation to O365 with ADFS 3.0 but I haven't found any guidance on how to move the federation from one environment to the other.

Any help would appreciate.  Thanks in advance.

Any downside to making Windows 2012 DC, in a Windows 2008 R2 native domain, the FSMO owner?

$
0
0

I have recently added a Windows 2012 Server to my older Windows 2008 R2 native Active Directory domain, and made it a domain controller.

Is there any disadvantage to giving the new Windows 2012 Server the primary AD roles (i.e. FSMO, Schema Master, Domain Naming Master)?   

What are the caveats of moving a Windows 2008 R2 domain controller, from one IP subnet to another?

$
0
0

We are relocating a large portion of our current infrastructure to a new location, and there will be a new IP subnet in place at the new facility.    Right now we have an IPSec tunnel connecting our current IP subnet to the IP subnet at the new facility, to connect the two networks.   Both subnets are under the same single Windows domain site.

Is it safe to move a Windows 2008 R2 domain controller from our current subnet, assign it a new IP address and then have it re-register in DNS once it's on the new subnet at our new location?

AD BA - Windows 81 and Office 2013

$
0
0

Windows 2012 server and Windows 8 KMS can be imported to Volume Activation tool as AD objects

But Windows 8.1 and Office 2013 KMS has error while importing.

Any update / patch is need to be installed to KMS host (Windows 2012 server)?

Thanks a lot.


PowerShell AD Module

$
0
0

Hi all,

I want to use new AD cmdlets introduced with PowerShell 3.0. For instance Get-ADReplicationSite

I just downloaded PowerShell 3.0 and installed on Windows Server 2008 R2. But couldn't find commands related site and services.

Is that mean, to be able to use new commands introduced with PowerShell 3.0, I need to use it on Windows Server 2012? If so why did microsoft make a seperate download for PowerShell 3.0 for Windows Server 2008 R2?

Thanks.

Active Directory Domain Name Convention

$
0
0

Hi All

I'm creating a brand new domain for a new company I have just started at. We currently use Office 365 so sharepoint and Exchange are both in the cloud and our website is also outsourced.

I am now rolling out our first DC on Windows 2012 Server and I'm find conflicting reports on what naming convention I should use for AD with use with hosted exchange.

Most seem to point at using a subdomain of our main site, like corp.mydomain.com whereas I come from a background using Server 2003 where its always been mydomain.local

Can anyone advise me on this one and are there any additional thoughts around implementing with an existing Office 365 setup?

Chinese Characters in Netlogon.log

$
0
0

Hello,

I have enabled netlogon logging, and am noticing a few things that I am unable to diagnose after further research. My main concern is with a critical error that seems to occur every ten minutes. Occasionally the Chinese characters change but always translate to roughly the same message. Searching google for information about "I_NetlogonLdapLookup" has provided no helpful information either. Does anybody know what could cause this? We have 3 DCs (Server 2008R2, 2012) and this shows up in all three netlogon logs.

08/26 17:55:40 [CRITICAL] I_NetlogonLdapLookup: unrecognized parameter 湄䡳獯乴浡ѥ䠗偙剅㍖渮

All client computers are Windows 7 Pro x64. Any help is appreciated, thanks.


Alex Tester Information Technology Assistant National Automotive Experts

Problem creating external trust between domains

$
0
0

Hello,

When I try to create one-way incoming external trust between 2 domains (to DomainA from DomainB) in separate forests I get this info:

This domain already has a one-way trust relationshp with specified domain.

But I cannot see it on the list of trusts either incoming or outgoing (in both domains).

For sure trust was never setup before.

In DomainA there are several other external not transitive trusts with other domains. But for sure DomainB do not have any incoming or outgoing trusts on list. Name resolution betwen domains is OK. I can ping domain name on both sides.

Any help is welcome.

Darek.

application authentication issue with DCs

$
0
0

Hi

I have one Application of life image.. that was working fine before today.

Today I got issue that authentication is not happening..

I checked and found application are hosted on Linux box and LDAP configuration are below:

domain:
DN:
LDAP Path:
Username:
Password:

When I put DC name on LDAP path, it autheticated but when I put enterprise.contoso.com, application doesn't get authenticate 

What can be issue or troubleshooting steps.


I checked the dcdiag and no issue founds

Changing AD forest from foobar.com to foo.com

$
0
0

Hello,

We have a website and e-mail which are hosted for us at foo.com.  The internal network has an AD forest of foobar.com  All computers within the company are on XYZ.foobar.com domain.  I want the forest to be foo.com to match the external domain name and have internal computers be in XYZ.foo.com domain.

What is involved in changing the forest over to foo.com?  Currently the DNS for foo.com is hosted by godaddy.

Am I going to run into any problems with the Windows DNS server when doing this? 

Any common problems in making such a change?

Thanks!!!


Test connection to AD from remote site

$
0
0

Hi MSFT Community!

I need to bind to an AD domain controller from a remote datacenter. There dialogue box that I need to configure for the directory service binding is shown below. Now, I'm pretty handy with AD, but no I'm not having any luck getting this connection to succeed.

Is there a utility I can use to diagnose if even their is connectivity across the link to my remote DC on 389 or 3268?

Thanks!


AD replication issue. had 1722 error after running repadmin

$
0
0

Hi,

I got 1722 error ( The RPC server is unavailable) when I run repadmin /replsummary. The result points that one source DSA is having 1722 error and the problem DC is the DC I run repadmin command from.

Do it make sense. Why DC itself cannot rpc to itself?

Thanks

Qing

 

New 2012 Active Directory Domain - Naming Convention

$
0
0

Hi Guys,

I am working for a start-up company, who currently use Office 365 (Mid-Size Business) for their email and for the use of SharePoint.

I have been tasked with designing and building a fresh new 2012 Active Directory, but I am a little unsure of how to name the new domain with Server 2012, previously I would have used a ".local" name, but I have read a lot of articles that say this should not be done anymore, rather we use the external domain name of the company with a sub-domain prefixed.

Whilst I have read quite a bit about this method, there doesn't seem to be a clear right or wrong answer, can someone advise what would be best practice in my situation?

Kind Regards

Simon

DC 2012 R2 reboot every 15 minutes after Upgrade from Win Server 2008 R2

$
0
0

After upgrade DC 2008 R2 to 2012 R2 Server Core, DC reboot every 15 minutes, this is the error:

Event ID 1015, Source Wininit:

A critical system process, C:\Windows\system32\lsass.exe, failed with status code c0000005.  The machine must now be restarted.

Faulting application name: lsass.exe, version: 6.3.9600.16384, time stamp: 0x5215e25f
Faulting module name: ntdsai.dll, version: 6.3.9600.16421, time stamp: 0x524fcaed
Exception code: 0xc0000005
Fault offset: 0x000000000019e45d
Faulting process id: 0x214
Faulting application start time: 0x01cefa6743edbeec
Faulting application path: C:\Windows\system32\lsass.exe
Faulting module path: C:\Windows\system32\ntdsai.dll

Server 2008R2 with dhcp and dns ( LICENCING question ) With SAMBA4 AD-DC

$
0
0

Hai, im having a licencing question. 

what i want is the following.

1) windows AD DC member server with dhcp and DNS

2) multiple linux samba 4 AD/DC servers, are replicating DNS and AD  ( windows pusses the dns /ad  to bind9 samba4)

3) al my pc's wil authenticate through my linux servers.

4) NO pc of other client is connecting to my windows servers.

Do i need CALs, and if so please explain why.
I can understand thats i need cals for the multiple linux servers, but not for my pc's phones or tablets.

How to prevent computers to logon remote site's domain controllers

$
0
0

Hi,

We have 3 sites (HQ, remote site A and remote site B) in a Windows 2008 r2 domain, the clients are win XP and win 7, if remote site A's DC and HQ's DC are offline, we don't want remote site B's DC to authenticate remote site A and HQ client, how to prevent remote site B's DC to authenticate remote site A and HQ client except remote site B local client?

Regards,

Ray NG.

Viewing all 31638 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>