Quantcast
Channel: Directory Services forum
Viewing all 31638 articles
Browse latest View live

Universal Group Replication to Non GCs

$
0
0

Recently, a Global Group was changed to a Universal Group.  The environment is a multi domain single forest.  Within the environment are Global Catalogs and Domain Controllers which are not GCs.  One of the members of the Universal group was moved from one OU to another.  All of the GCs replicated the change referencing the user object in the new OU correctly.  All but one of the DCs that are not GCs have the previous OU path for the member user.  I am not interrogating all DCs in the child domain to determine if the user object itself was updated correctly on all DCs in the child domain.  Any insight from this group would be helpful. 

Thanks,

TS

 

256 Character Limitation in Windows

$
0
0

Hi,

We have Windows 2k8 server which we are using as a File Server. One of our department who is working on this server are frequently creating long path name folder. since long path name has been created, the files are in that folder are not able to open due to long file path character.

Kindly advice how to overcome this problem.

Regards 

Configuring custom screen saver for GPO

$
0
0

Hi, 

Looking for help on how to do the following:

I need to roll out a custom screen saver using GPO, the screen saver I plan to make is a series of photos (originally a PPT)

Can anyone advise me on how best to do this?


Grant

Add Windows Server 2003 to a Windows Server 2008 R2 domain

$
0
0

Is it possible to add a Windows Server 2003 to a Windows 2008 R2 native domain?

Thank you


Frank

DCPROMO failed

$
0
0

Can some explain as to why this would happen during a promotion?

"failed to configure encrypting files services"

thanks

event logs entries after adding a computer or server to domain controller

$
0
0

Hello, I have win 2012 R2 domain controller.. I want to know when one computer joins the domain controller successfully.. what logs entries and registry entries are generated in the domain controller and in the computer. where I can see logs specific to only the computer joined the domain controller.. and where I can see the registry entries specific to only the computer joined the domain controller..

appreciate your quick response on the same.

thank you

Adding universal groups from domain a to domain local groups on domain b

$
0
0
Hi, In the past we had users in a Global Group in one domain and was able to add that group to a Domain Local Group of another domain and they were able to access the resources just fine. Now from some reason they decide to create the groups asuniversal groups and when I add the new group they do not have access. If I add their domain account they work fine. We do not want to start adding people to the domain local groups because this is a nightmaire to control. Why if it allows me to add univerisal groups to outside domain local groups do the people not have access to outside resources unless they are in a global group or we add them directly to the outside domain local group. We (the ouside domain) are running a Server 2003 (Mix mode) I think and the other domain is a 2008 domain,

Domain Rename

$
0
0

Hi,

We recently renamed our company that consist about 8 sites with 1000+ users, we have the responsibilities to rename the domain to reflect the new companies name. The more and more I read this the more I believe this is an extremely demanding tasks. Do to our great integration with MS products within our domain we are using Exchange / Lync / Sharepoint and SQL.

The largest challenge seem to be Exchange and Lync. My challenge is to migrate everything at once I do not believe this will be possible.

Is there a best practice how to make these 2 environment co-exist while we migrate all users slowly.

Is this the best practice?


George S.


Domain controller name changed

$
0
0

Hi

I have three domain controllers. A colleague of mine changed the name of the one and

did not follow the correct procedure now my domain controller name and Server name are

different and no replication can happen. i have tried to do a domain controller  name change

however i get a error saying that Unable to add DCname as an alternative name for the computer.

The error is. the specified account does not exist. The command failed to complete. Can you please

advise with a solution if possible.

DirectoryVirtualListView with LDAP query scope, SearchScope.OneLevel - problems with results

$
0
0

Hi 

I was trying to perform ldap query against AD and in most cases it's working very well.

In specific case, when I try to bring all first level Organizational Units defined on specific bind DN with DirectoryVirtualListView I have a some trouble:

When bind DN was other than the Root, I didn't encountered problems.

When I used the root bind DN, I found out that the:

1) In 2008 and 2012 server the ApproximateTotal number is mach larger while in many other cases it is accurate.

2) In AD 2012, on the second page, I keep getting the last entity from the first page

Is these items are bugs?

BTW, On AD 2003 server, I always got ApproximateTotal = 0, is DirectoryVirtualListView should work against AD 2003?

I also used different LDAP SDK, and the results are the same.

Recommended DNS zone replication scope for single domain environment

$
0
0

Hi, in my company we have domain/forest functional level Windows Server 2008 R2 - there is only one domain. AD DS is installed on 5 servers -AD integrated DNS zone is used.

I noticed today that on both forward lookup DNS zones, _msdcs.internaldomain.com& internaldomain.com, zone replication scope was set toAll DNS servers in this domain and also for one reverse lookup zone. I changed this setting for all these zones toAll domain controllers inthis domain but later (10-15 mins at most) I reverted these settings back toAll DNS servers in this domain.

Which zone replication scope for mentioned zones is recommended keeping in mind this is single domain environment? Also could I do any harm to DNS and AD in all when I changed zone replication scope and later reverting it back for these zones? How to check that dns related informations (zones) are located where they should be in Active Directory and that there is no any garbage in other locations (partitions) in AD database.


Migrate only SIDHistory from source domain account

$
0
0

Hello,

I have user account for John Doe in source domain.

I have created completely new user account for John Doe in the target domain (not migrated with ADMT)

There's two-way external trust between source and target domain.

Now, there's need to grant John Doe same permissions to the source domain file servers like the John's account in the source domain did.

Is it possible to migrate only SID History of John's account from source domain and merge it with John's account in the target domain in order to achive this goal? Is there any adverse impact in doing so?

Other alternative I can think, would be

1. Delete John's account in target domain

2. Migrate John's account from source domain to target domain with ADMT with SID history

need your help!

$
0
0
we have one site link config between site A and site B
replicate every 5760 minutes(frequency). but, on site B, the connection object
between site A and site B is scheduled only one hour on Wednesday and
Friday.  So, what's final replication schedule for these two DCs
between site A and site B?

Windows active directory logs

$
0
0

Hi,

We are using Windows active directory to manage our users. Another company has configured the same for us.

Currently we don't have permissions to create a new user. They have given us one account and by using that account, we are able to create new groups in AD, add users to the groups, etc. We would like to get the logs for each user removal or addition to the AD groups. How do we enable the same. We would like to know who  and when each user is getting added to the AD groups. Please help us in this.

Active Directory Report

$
0
0
how to extracta reportofmachines thatdo not communicate withactive directoryto more than90 days,inwindows server2003 R2.anyscript?

Does a domain controller need a certificate

$
0
0

Hi,

I have a certificate related question.  While checking the logs on our domain controller, I discovered a certificate problem.  In the Personal store is a Domain controller Template certificate that expired last year.  It was created by an enterprise CA that no longer exists and was not properly removed from the domain.  My question is:  Is the certificate needed for anything?    I inherited the administration of the domain and I am trying to clean it up.

Thansk


Ron Soulliard


Ron Soulliard Systems Administrator Polaris Ventures

Enabling Secure SSL on IIS for ADFS causes Citrix VIP and two Server svc Accounts on Citirx Netscaler to fail

$
0
0

I'm hoping that I can provide all the details to the issue I am having with regard to getting AD FS, SSL Certificates to work with our Citrix Netscaler 5500 device. However, before I delve into that I would like to state that I was able to use Windows NLB successfully. NetScaler has proven to be most difficult and I'm not certain why.

I've read a ton of information on setting up AD FS Server, AD FS Proxy and using SSL and feel I have a pretty good handle on it, but, I may be missing some relevant information or just may not know how to troubleshoot it thoroughly enough. In addition, for the sake of keeping this post more brief, I'm only concerned with getting the AD FS Servers, SSL working in the On-Premise environment and not really concerned with the AD FS Proxy setup portion here. Baby steps, right!?

Our environment:

An AD FS Farm with two (2) AD FS Servers installed on Server 2012 Standard w/ Service Pack updates. AD FS Server names are fs1.myco.com and fs2.myco.com. They each have a static IP address or Host (A) Record in our DNS Server. Also, I've setup an 3rd static IP for the DNS Service name of sso.myco.com. It also has a Static IP Address. It will be the DNS name we will use as our AD FS Service name, the Subject Name in our SSL Certificate and will Serve as the Virtual IP Address I've setup on the NetScaler device for Load Balancing between the two Servers fs1 and fs2.

I setup two test files called test.html. One that says "You've connected to Server fs1 successfully" and the other "You've connected to Server fs2 successfully". When I had Windows NLB installed I was using one NIC with Unicast configured on it. I could successfully connect to the two servers using https://fs1.myco.com/test.html, https://fs2.myco.com/test.html, and when I hithttps://sso.myco.com/test.html it would balance out between the two servers nicely. I tried this from a number of workstations successfully.

When I go to set it up in NetScaler, the VIP and the two Server Services, i.e. svc_FS1 AND svc_FS2, are both down. The main culprit here seems to be when I enable the "SSL Settings" option called "Enable SSL" and if I use any of the "Ignore", "Accept" or "Require" options. I've binded the IP Address on each IIS Server to https and have set it to use the SSL Certificate w/ Subject Name of sso.myco.com. I also import the SSL Certicate and it's correlating Private Key onto the NetScaler device successfully and added it to the Service Server accounts during setup. If I choose uncheck "require" SSL and re-configure the IP / Port bindings to Port 80, then the NetScaler VIP and Server Service accounts come up right away.

So, w/o making this an entire novel on this post, has anyone been down this "endless road" of issues and come across this type of issue that might lead me to some sort of epiphany?

Thank you for taking the time to read this and a little bit of patience to go with it. :)

Wally


Wallace Davis

upgarde domain controller to windows 2008 R2

$
0
0

Hi,

we have 2 domain controller on windows 2003 R2 (primary & additional) now we would like to upgrade to windows 2008 R2 can I do in the following ways with no issues...

I will prepare windows 2008 R2 machine and make it as additional domain controller then I will transfer all the FSMO roles to newly created windows 2008 R2 machine and then remove the old windows 2003 R2 machines 

please suggest if this works fine other wise if there any other better way kindly let me know 

Regards,

Ehsan 

how to find custome attribute value of user

$
0
0

Hi,

I need to find the custom attribute value of users, How can I achive this?

" in my senareo I need to find,what custom attribute 13 is set for"

Need help....

 

Many Tnaks.


Joy, Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.

how to Add custome attribute value of user id

$
0
0

Hi my friend.

from below cmd i can able to view the current attribute value. but i wanted to modify the value. so can you please provide dsmod cmd for modify

dsquery * domainroot -filter "&(objectCategory=person)(objectClass=user)(sAMAccountName=username)" -attr extensionattribute2

Dsmod ...................?

James

8892722073

Viewing all 31638 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>