Quantcast
Channel: Directory Services forum
Viewing all 31638 articles
Browse latest View live

Active Directory: Permission to read users' groups.

$
0
0
Our product uses Windows user groups as a means of user authentication and authorization. This has worked fine, up until now.

At the site of a new customer, the product was unable to read the group membership of users that attempted to log in. The customer's IT team found that for each user's account, they had to give explicit permission to our product (i.e. the user account it runs under) to read each user's "group membership" and "groupMembershipSAM". Having done this, users were able to log in.

The problem is, the customer has a large number of users, and it would take a long time to perform this setting for all of them individually.

My question is - is there a way to perform these settings for groups of users, such as by using a domain policy? So far I have not been able to find any information that suggests this might be possible.

Thanks & regards
Chris

Login to Domain Controller which is not in network

$
0
0

Scenario

I've taken an online clone of one of my Virtual Window 2003 Enterprise Domain Contoller which doesn't hold any roles. Removed the Clone Domain Controller from Network & powered it on.

Now I want to log into that Domain Controller using my Domain Admin credentials but it's not working.Is there a way to log in to that Domain Controller which is taken out of network USING DOMAIN ADMIN ID ?

I can log in to Restore Mode but that's not what I'm looking for, I need to log in to that DC using my Domain Admin credentials while It's not in network.

This is for lab purpose.


Cannot Remove IP Address From Dial-in Tab Using RSAT ADUC on Windows 7

$
0
0

I am running RSAT version of ADUC on Windows 7.  I have done the work-around to display the Dial-in tab, which is not displayed by default in that version of ADUC.  I have noticed some odd behavior and I am wondering if someone call tell me if the behavior is by design.

When I remove an IP address from the Dial-in tab, I don't just clear the "Assign a static IPv4 address" checkbox, I actually backspace out the numbers.  I have a PowerShell script that I can run to pull all the accounts in AD that are configured with IP addresses, and if I run that script the account does not show up in the results.  This is good.  However, if I go back into the AD account and check the "Assign Static IP Addresses" checkbox on the Dial-in tab, the Static IP Addresses dialog box appears and the IP that I just removed is back in there but grayed out.  If I run my script again, the account does appear in the results.  This is bad.  We have an established process for requesting VPN access, and this behavior makes it easy for people to add an IP address back onto an account without going through the proper process.

It's as if the tool remembers the last IP address that was entered on the account and automatically adds it back when you go back into that dialog box.  What I would like is for the IP address to remain blank so that people will need to manually enter a new IP address, which they would obtain during the VPN request process.

Is there a way to prevent the last IP address used on the account from being put back in automatically when the Static IP Addresses dialog box is opened?

Thanks for any help that you can offer!

--Tom

Calling all Windows Server users! May TechNet Gurus announced!

$
0
0

The results for May's TechNet Guru competition have been posted!

http://blogs.technet.com/b/wikininjas/archive/2014/01/16/technet-guru-awards-december-2013.aspx

Congratulations to all our new Gurus for May!

We will be interviewing some of the winners and highlighting their achievements, as the month unfolds.

 

Post your JUNE contributions here:

http://social.technet.microsoft.com/wiki/contents/articles/24692.technet-guru-contributions-for-june-2014.aspx

Read all about June's competition, hopefully in a stickied post, at the top of this forum.

 

Below is a summary of the medal winners for May. The last column being a few of the comments from the judges.

Unfortunately, runners up and their judge feedback comments had to be trimmed from THIS post, to fit into the forum's 60,000 character limit, however the full version is available on TechNet Wiki.

Some articles only just missed out, so we may be returning to discuss those too, in future blogs.
 

Guru Award BizTalk Technical Guru - May 2014  

Gold Award Winner

Peter LindgrenBizTalk 2010: Call SSO from OrchestrationTGN: "I bet a few people will love you for this, I often see this question at the forums, and you answered it well. Good work!"
Mandi Ohlinger: "Great topic and great explanation. It also makes SSO seem less scary :)"
Sandro Pereira: "Very useful sample, well explained with all the necessary code "

Silver Award Winner

boatsellerBizTalk: Using an Orchestration Sync or AsyncSandro Pereira: "Good sample provide by boatseller and well explained."
TGN: "Hey, great work man! This is a well done article and I love it!"

Bronze Award Winner

Steef-Jan WiggersExposing data through BizTalk Service Hybrid ConnectionsSandro Pereira: "Nice article with a good overview about BizTalk Service Hybrid Connections and how you can configure them."
TGN: "Good article, well explained and good pictures. Again Steef-Jan, you know what you're doing!"
Mandi Ohlinger: "Nice set-up overview. "

Guru Award Forefront Identity Manager Technical Guru - May 2014  

Gold Award Winner

Sheldon.JaquayForefront Identity Manager - RCDC - Regular ExpressionAM: "Great contribution! Option C is clever, and the other examples are also a useful reference. Thanks for sharing your work with the community."
Ed Price: "Nice short article. Great topic, and great blend of code, color, and images!"
Søren Granfeldt: "Nice with a little focus on RegEx with FIM and good help for people wanting to have the portal be just a little more company specific"
GO: "Thanks for the article, but the images weren't clear enough."

Silver Award Winner

Scott EastinInstalling Oracle MA for FIM R2 on Windows 2012GO: "EX-CE-LL-EN-T article!"
AM: "Very nice article with clear step-by-step instructions - thanks for putting this together. "
Ed Price: "I love the sections with numbered bullets at the end. They're very clear and easy to read!"

Guru Award Microsoft Azure Technical Guru - May 2014  

Gold Award Winner

João SousaMicrosoft Azure - Remote Debbuging How To?GO: "Clever. Well Explained and written. Thanks! You absolutely deserve the GOLD medal."
Ed Price: "Fantastic topic and great use of images!"

Silver Award Winner

Alex MangThe Move to the New Azure SQL Database TiersEd Price: "Great depth and descriptions! Very timely topic! Lots of collaboration on this article from community members!"
GO: "great article but images are missing"

Bronze Award Winner

Alex MangSeparating Insights Data In Visual Studio Online Application Insights For Production And Staging Cloud ServicesEd Price: "Good descriptions and clarity!"
GO: "great article but images are missing"

Guru Award Microsoft Visio Technical Guru - May 2014  

Gold Award Winner

Mr XHow to export your Orchestrator Runbooks to Visio and Word

Ed Price: "A basic tip, but very helpful. Good job!"
GO: "Thanks for that!"
SR: "Nice "How To" article explaining the basic steps."
AH: "This article is to the point takes a simple tasks and describes it accurately.

Guru Award SharePoint 2010 / 2013 Technical Guru - May 2014  

Gold Award Winner

Dan ChristianBuild a loop workflow using SharePoint 2010Jinchun Chen: "Excellent article. Personally speaking, the biggest challenge is SharePoint Designer workflow is “while-loop”. Many customers had the same scene as this article set. I am sure they are like this article. "
Benoît Jester: "An AWESOME, huge, detailed article by Dan. Did I mention the videos? Thanks Dan!"
GO: "Great article Dan! Thanks!"
Margriet Bruggeman: "Detailed explanation which I admire, but wouldn't be using a vs workflow be more logical in this case?"

Silver Award Winner

Geetanjali AroraExport User Profile Properties using CSOMBenoît Jester: "Great article on this new SharePoint 2013 development capability. I appreciate the code explanations."
GO: "This is a great article. Love the way how you explain it."
Margriet Bruggeman: "I will use this piece of code in the future!"
Jinchun Chen: "Nice. How about customized properties? It would be nice more, if a CSOM script version can be attached. "

Bronze Award Winner

Inderjeet SinghUnable to restore site collection issueGO: "Simple. Good Written. Clear and Clever. Great article."
Margriet Bruggeman: "Quite handy reference for this particular problem"
Benoît Jester: "Good explanation on the site collection deletion process."

Guru Award Small Basic Technical Guru - May 2014  

Gold Award Winner

Philip ConrodProgramming Home Projects with Microsoft Small Basic: Chapter 1: Writing Programs Using Small BasicRZ: "Very systematic introduction."
Ed Price: "Good overview article that covers all the basics!"
Michiel Van Hoorn: "Nice introduction into the history of Basic. Needs to be updated to reflect current support for Windows version (Windows NT? LOL )"

Silver Award Winner

Philip ConrodProgramming Home Projects with Microsoft Small Basic: Chapter 6: Flash Card Math Quiz ProjectMichiel Van Hoorn: "This article (or book chapter) is excellent material to learn how to envision, design and build your program. The actual example program is also very usable."
Ed Price: "I love how this tutorial keeps building on itself as it goes!"

Bronze Award Winner

Nonki TakahashiSmall Basic: VariableRZ: "Very nice explanation of the concept of variables!"
Michiel Van Hoorn: "Clear explanation and not frills"
Ed Price: "Great article with fantastic formatting!"

Guru Award SQL BI and Power BI Technical Guru - May 2014  

Gold Award Winner

Durval RamosSSIS - Event Handling with "OnError" ou "OnTaskFailed"Ed Price: "The images are very helpful! Could use a grammar pass. Great descriptions!"
GO: "This article has everything. A conclusion, reference, see also, other languages section. everybody should write actually like this."
NN: "An interesting topic and article but unfortunately a bit hard to understand due to grammar problems"
PT: "This is a good article on a useful topic. Please have your article reviewed and edited for proper language."

Silver Award Winner

S KamathExpansion of Time dimension in Analysis ServicePT: "Your article is concise and to the point, and contains useful information. It would be good to conclude with a short summary and perhaps compare this technique to others, discussing best practices."
Ed Price: "Good details on Time Dimension. The images help us understand as we go."
GO: "I like this one, but something is missing. Do not know what, but I had a blast reading the other two's. Does not mean that this one is bad, but there is something missing, maybe my knowledge..."
NN: "Good article, but seems to be missing conclusion. It will also benefit from adding See Also section"

Bronze Award Winner

Sherry LiSSAS – Ignore unrelated dimension or notNN: "Good and interesting article based on the blog"
GO: "Wonderful article!"
PT: "This is an important topic and contains helpful information but this is a simple topic that can be explained in fewer words. I found this article to be overly detailed and hard to read. I suggest having it reviewed and edited for proper language."
Ed Price: "Good descriptions. Could be shorter. Good use of images!"

Guru Award SQL Server General and Database Engine Technical Guru - May 2014  

Gold Award Winner

ShankyCurious Case Of Logging In Online and Offline Index Rebuild In Full Recovery ModelJinchun Chen: "Good article. Thank you!"
GO: "One of the best Wiki Articles ever! Thanks buddy!"
DRC: "-- This is a great article which provides in-depth information on internals of Online & Offline rebuild index and Transaction logging. -- The following statement need to be re-written for more clarity. “The less logging can be attributed to the fact that no information about page allocation is logged information about de-allocation is logged please see below figure 13. Also if you compare amount of record returned in this case we had output containing just 64 rows while offline index rebuild had ____ rows.” -- Overall, a great article, thoroughly enjoyed reading it."
NN: "Very interesting article, another great contribution by Shanky"
Ed Price: "Thorough descriptions and great solution! Good article!"

Silver Award Winner

Uwe RickenSQL Server: Be aware of the correct data type for predicates in queriesEd Price: "Incredibly well formatted! Great breakdown of sections!"
GO: "Whoo, this is a wonderful article!"
DRC: "-- This article explains the Query execution behaviour when the Query is not optimally written which could cause increased execution time. Great article. -- This topic is clearly explained and documented using a simple example and sample output which is easy is understand. -- Simple, very well written and great article to read. "
NN: "Very good, easy to understand article and important information to know to all SQL Server developers"

Guru Award System Center Technical Guru - May 2014  

Gold Award Winner

Mr XCentral Management of DSRM password on Domain Controllers using OrchestratorEd Price: "The images really carry you through this article. Great execution!"
GO: "Great article. I like your article Mr X! Thanks for your passion!"
Kevin Holman: "Nice to see real world examples of Orchestrator in action solving problems that all customers have. This was very simple, but provides an excellent solution."

Silver Award Winner

W P ChomakSystem Center Operations Manager 2012 R2 - Customizing E-Mail NotificationsAB: "Easy reading info that can help many"
Ed Price: "Short and sweet. An incredibly valuable topic and needed addition to the Wiki!"
GO: "Clever and well written. Thanks"

Bronze Award Winner

Christoffer SSystem Center Configuration Manager 2012 R2 - Install applications in a task sequence based on AD-GroupsEd Price: "Good mix of code, images, and information. Could use more in-depth descriptions. Great article!"
GO: "Clear and simple! Thank you!"

Guru Award Transact-SQL Technical Guru - May 2014  

Gold Award Winner

Naomi NT-SQL: Random Equal DistributionJinchun Chen: "Nice."
JS: "The crucial thing about such a procedure is to check the data before the randomization and afterwards. You might encounter situations where "John Smith" and "John Meyers" might have exchanged their First names which is technically correct, but logically and obviously wrong. So make sure that there is one additional check afterwards that makes sure that eventual privicy concerns will not survive the random process. Normally this would not happen, but I have already checked this is one of my older blog entries, where we exactly had that problem obfuscating data to make that operational and live data will not be recognized afterwards. http://blogs.msdn.com/b/jenss/archive/2009/04/08/when-is-random-random-enough.aspx In addition to this some attributes are sticky to each other like gender and First Name. You also have to make sure that your distribution might change statistically in relation to other attributes."
Richard Mueller: "Very instructive. Perhaps the See Also section should have more links."
Ed Price: "Great formatting and topic! Could benefit from more descriptions. Great article!"
GO: "Naomi, your article is nice. Simple to understand the 'problem' and execute the 'solution""
Manoj Pandey: "Nice article with a different way to resolve a given problem. I think this can also be done by using NTILE() function. I've added the code in comments section."

Silver Award Winner

Rogge HExtending SYS.Geometry to Utilize Temporal DataGO: "Great article, I enjoyed reading it. Thank you"
Manoj Pandey: "I like the idea, but it took me some more time to understand the overall logic as I'm new to Geo datatypes, Thanks."
JS: "For me not using this sort of things regularly, I don't see the problem and the benefit. I have no doubt that this is a brilliant explanations how to cope with a problem, but for me this is missing yet the red line. More pictures would be helpful describing the problem and outlining the results produced."
Richard Mueller: "Needs more explanation, and perhaps an example. There should be links to relevant references."
Ed Price: "Good job on the opening descriptions! Could benefit from breaking up and explaining the code more. Images and references would be helpful. Good article!"

Bronze Award Winner

Hasham NiazDataCleanUp() Function Implementation in MS SQL ServerJinchun Chen: "Good."
JS: "-Does actually not work for Case senstive areas where I want to remoce certain Upper/lower case characters. This might be not interesting for some people, but is extremely important and relevant to other people. The limitation is that I can´t pass multiple values to be removed from the string, right ? Could this be implemented as well as many people wash out their data from unused / unimportant control characters. "I have tested it on a table which has got more than 11 Million rows and it executed fine returning the correct results. Since this is a scalar function you will notice decrease in performance." Once you want to maintain the old data and keep the new cleaned up one seperately, you could suggest something like persisting the data in a computed column which could be indexed and then help improving the performance. This would not be the case for any adhoc queries though."
Richard Mueller: "Very clever and also very useful. There should be links to references, for example to explain the PATINDEX function."
Ed Price: "Great job on this article! Very clear and well executed! See JS's comments for some thoughts about what's possible. Great article!"
Manoj Pandey: "A good utility Function that I can use and tweak for my future needs, Thanks."

Gold Award Winner

Jaliya UdagedaraCalling WCF Service from a Stored Procedure in Microsoft SQL Server 2012GO: "Gold Winner. For sure!"
Ed Price: "Amazing article! The depth, images, and code formatting make this fantastic!"
NN: "Great article, thorough explanations, great interaction in the comments - very useful tutorial"
Søren Granfeldt: "Nice work."

Silver Award Winner

João SousaASP.NET MVC 5 - Bootstrap 3.0 in 3 StepsGO: "Thanks for that great article"
Ed Price: "Great formatting! Good use of images!"
NN: "Nice introduction to Bootstrap in ASP.MVC project"
Søren Granfeldt: "Just a little more technical explanation would be nice"

Bronze Award Winner

Critical_stopUsing 64-bit shortcuts from a 32-bit applicationNN: "Good and short article, right to the point"
Søren Granfeldt: "Mixing and matching 32/64 bit always seems to give people a hassle. This will help those having issues."
GO: "good one!"
Ed Price: "Good article. Short and sweet."

Guru Award Wiki and Portals Technical Guru - May 2014  

Gold Award Winner

XAML guyTechNet Guru Competition: Judge System ExplanationGO: "No one could do it beter than you Pete! Thanks!"
Richard Mueller: "Excellent explanation of the judging system. Perhaps could use a See Also section."
Ed Price: "Good quote from Shanky in the comments, "Awesome....Kudos to your for your beautiful work" -- Great job!"
NN: "Very good article. It may also benefit from See Also section"

Silver Award Winner

Payman BiukaghazadehTechNet Wiki Persian CouncilGO: "Go Persion GOOO!"
Richard Mueller: "The Persian Council is an excellent idea. The link to "How to Write an Article" should be in a See Also section, along with other articles."
NN: "Great article, missing a link to other portals and councils pages"
Ed Price: "Thank you to Payman and the Persian community for jumping in! The Wiki is warm!"

Bronze Award Winner

Durval RamosWiki: Best Practices for building TechNet Wiki PortalsEd Price: "Fantastic job from Durval on helping us standardize the portals!"
NN: "Good article, but unfortunately a bit hard to read and understand due to bad grammar. "
Richard Mueller: "Excellent and important topic. Grammar still needs work. I like the links and See Also."

Guru Award Windows Phone and Windows Store Apps Technical Guru - May 2014  

Gold Award Winner

Sara SilvaAuthentication using Facebook, Google and Microsoft account in WP8.0 App (MVVM)Ed Price: "Great article! Great code formatting and good use of code comments for descriptions of what your code's doing! Could be improved by breaking out the code with more descriptions in the article (in addition to the code comments). Very in-depth article! "
Peter Laker: "An excellent article, pulling together all the bits you need to make this happen"

Silver Award Winner

SubramanyamRaju.BWindowsPhone Facebook Integration:How to post message/image to FaceBook Fan Page(C#-XAML)Ed Price: "Good topic! Code blocks would help with the formatting. Good job on this article!"
Peter Laker: "Love this, very useful to many I'm sure, thanks!"

Bronze Award Winner

Saad MahmoodCreating a custom control in Expression Blend with Custom Properties (WindowsPhone& Store)Ed Price: "This has a good mix of descriptions and clarity! The images help a lot!"
Peter Laker: "A nice introduction to our beloved Blend. Great work!"

Guru Award Windows Presentation Foundation (WPF) Technical Guru - May 2014  

Gold Award Winner

Magnus (MM8)WPF/MVVM: Merging Cells In a ListViewKJ: "Ah the collectionViewSource -- never used it myself but this looks like a good reference article if I ever needed to..."
GO: "Thank you!"
Ed Price: "Great formatting and good descriptions. Short and sweet! Another fantastic entry from Magnus!"
Peter Laker: "Thank you again Magnus"

Guru Award Windows Server Technical Guru - May 2014  

Gold Award Winner

Mr XHow to implement User Activity Recording for AD-Integrated Critical Servers by combining the use of Group Policy, Powershell and OrchestratorPhilippe Levesque: "Really good information and detailed step."
JH: "brilliant, love how it combines different technologies to achieve a solution, clearly written and well illustrated."
JM: "Another excellent article, thanks again for your many great contributions"
Richard Mueller: "Very creative solution. Great to have such detailed steps and images."
GO: "I like the conclusion. Thanks"

Silver Award Winner

Mr XHow Domain Controllers are located in WindowsGO: "Super article Mr X! Merci!"
JM: "Yet again, excellent article."
Richard Mueller: "Good documentation. An explanation of how the priorities and weights are determined would help. A See Also section would also help."
Philippe Levesque: "Good "In deep" information. Good to know to help diagnose computer problem in AD's site."
JH: "another good article, great diagrams. Some repetition but it does help clarify a complex issue. "

Bronze Award Winner

Mahdi TehraniDetailed Concepts:Secure Channel ExplainedJH: "great article. This fills an important gap in this content space. Editing is a little rough, but diagrams and explanations are clear."
JM: "This is a very good article, however you need to provide more detail in the section on how to fix a broken Channel."
Richard Mueller: "Excellent topic. Grammar needs work. Good images. Could use a See Also section."
Philippe Levesque: "Really good explanation of the secure's channel, I like the debugging step included ! "
GO: "Thanks for this, not everybody know about secure channel."

As mentioned above, runners up and their judge feedback were removed from this forum post, to fit into the forum's 60,000 character limit.

 

A great big thank you to EVERYONE who contributed an article to last month's competition.

Hopefully we will see you ALL again in this month's listings?

As mentioned above, runners up and comments were removed from this post, to fit into the forum's 60,000 character limit.

You will find the complete post, comments and feedback on the main post.

Please join the discussion, add a comment, or suggest future categories.

If you have not yet contributed an article for this month, and you think you can write a more useful, clever, or better produced wiki article than the winners above, here's your chance! :D

More about the TechNet Guru Awards:



#PEJL

Got any nice code? If you invest time in coding an elegant, novel or impressive answer on MSDN forums, why not copy it over to the one and onlyTechNet Wiki, for future generations to benefit from! You'll never get archived again!

If you are a member of any user groups, please make sure you list them in the Microsoft User Groups Portal. Microsoft are trying to help promote your groups, and collating them here is the first step.

How to backup and restore Windows 2012R2 ADFS

$
0
0

I am looking for the "Official" instructions for backing up and restoring an ADFS server which uses Full Remote SQL 2012. I know the database is backed up but what are the procedures for DR on the ADFS servers themselves?

The migration of ADFS 2.1 to 2012 R2 ADFS include an export of the ADFS metadata and Import into 2012R2 ADFS. Is this a possible solution to schedule for 2012 R2 ADFS in order to quickly restore in the event that the Farm dies?

AD LDS Replica instance creation failing

$
0
0

Hoping someone can assist.

Have an environment with multiple AD LDS deployments replicating without issue between Windows 2008 Servers

Trying to add on a 4th AD LDS instance and have the role installed on the server, however when using the AD LDS Setup Wizard to add the instance, running through all the options, towards the end of the wizard get the following error :

----------------------------------------------------------------------------------------------------------------------------------------------------------------

Active Directory Lightweight Directory Service Setup Wizard

The selected service account cannot authenticate with the replica source <other AD LDS instance:50000> using Negotiate authentication. Either the service account is invalid or the computer's configuration does not support NTLM authentication with the replica source.

The authentication failed with error 0x6ec: The list of RPC servers available for the binding of auto handles has been exhausted.

----------------------------------------------------------------------------------------------------------------------------------------------------------------

The AD LDS service account is Using a domain account that has local administrator rights, log on as service rights on all servers, along with 'Access this computer from the network' policy settings for the account.

No software or hardware firewall in place.

also used 'nltest /sc_verify:domainnamehere' on all servers and returns results okay.

Any other suggestions to check please?

Thanks

Error: Missing SRV record at DNS server - [Error details: 9003 (Type: Win32 - Description: DNS name does not exist.)]

$
0
0

in an attempt to transfer FSMO roles to the 2012r2 DC the first thing I ran was dcdiag /e /c /v and after correcting some minor errors, I came upon this one in the DNS portion where a SRV record is missing and I have no idea how to fix/remove this. there's only two DCs, 200.5 and 200.6 where the former is a Hyper-V VM running 2012r2 and the latter is a physical 2003r2 machine. I was able to successfully raise the levels to 2003 and join the 2012r2 DC. this missing SRV record does not look fatal and only warrants a warning from dcdiag, however I would like to fix this so there's no trouble down the road. I've tried ipconfig /registerdns, but no dice. here is the message I'm concerned about:

                    Error:
                    Missing SRV record at DNS server 192.168.200.5:
                    _ldap._tcp.9a5f3c17-e7ac-48f7-ab42-bf1ea621a6f5.domains._msdcs.cmedia.local
                    [Error details: 9003 (Type: Win32 - Description: DNS name does not exist.)]


the bottom portion of the DNS section that contains this message is in the RReg section and is as follows:

              TEST: Dynamic update (Dyn)
                 Test record dcdiag-test-record added successfully in zone cmedia.local
                 Test record dcdiag-test-record deleted successfully in zone cmedia.local
 
              TEST: Records registration (RReg)
                 Network Adapter [00000010] Microsoft Hyper-V Network Adapter:
                    Matching CNAME record found at DNS server 192.168.200.5:
                    a29d12f1-2869-44bf-8e43-adf7ddf33865._msdcs.cmedia.local
 
                    Matching A record found at DNS server 192.168.200.5:
                    CM-DC1-HV-NYC01.cmedia.local
 
                    Matching  SRV record found at DNS server 192.168.200.5:
                    _ldap._tcp.cmedia.local
 
                    Error:
                    Missing SRV record at DNS server 192.168.200.5:
                    _ldap._tcp.9a5f3c17-e7ac-48f7-ab42-bf1ea621a6f5.domains._msdcs.cmedia.local
                    [Error details: 9003 (Type: Win32 - Description: DNS name does not exist.)]
 
                    Matching  SRV record found at DNS server 192.168.200.5:
                    _kerberos._tcp.dc._msdcs.cmedia.local
 
                    Matching  SRV record found at DNS server 192.168.200.5:
                    _ldap._tcp.dc._msdcs.cmedia.local
 
                    Matching  SRV record found at DNS server 192.168.200.5:
                    _kerberos._tcp.cmedia.local
 
                    Matching  SRV record found at DNS server 192.168.200.5:
                    _kerberos._udp.cmedia.local
 
                    Matching  SRV record found at DNS server 192.168.200.5:
                    _kpasswd._tcp.cmedia.local
 
                    Matching  SRV record found at DNS server 192.168.200.5:
                    _ldap._tcp.Default-First-Site-Name._sites.cmedia.local
 
                    Matching  SRV record found at DNS server 192.168.200.5:
                    _kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.cmedia.local
 
                    Matching  SRV record found at DNS server 192.168.200.5:
                    _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.cmedia.local
 
                    Matching  SRV record found at DNS server 192.168.200.5:
                    _kerberos._tcp.Default-First-Site-Name._sites.cmedia.local
 
                    Matching  SRV record found at DNS server 192.168.200.5:
                    _ldap._tcp.gc._msdcs.cmedia.local
 
                    Matching A record found at DNS server 192.168.200.5:
                    gc._msdcs.cmedia.local
 
                    Matching  SRV record found at DNS server 192.168.200.5:
                    _gc._tcp.Default-First-Site-Name._sites.cmedia.local
 
                    Matching  SRV record found at DNS server 192.168.200.5:
                    _ldap._tcp.Default-First-Site-Name._sites.gc._msdcs.cmedia.local
 
                    Matching CNAME record found at DNS server 192.168.200.6:
                    a29d12f1-2869-44bf-8e43-adf7ddf33865._msdcs.cmedia.local
 
                    Matching A record found at DNS server 192.168.200.6:
                    CM-DC1-HV-NYC01.cmedia.local
 
                    Matching  SRV record found at DNS server 192.168.200.6:
                    _ldap._tcp.cmedia.local
 
                    Error:
                    Missing SRV record at DNS server 192.168.200.6:
                    _ldap._tcp.9a5f3c17-e7ac-48f7-ab42-bf1ea621a6f5.domains._msdcs.cmedia.local
                    [Error details: 9003 (Type: Win32 - Description: DNS name does not exist.)]
 
                    Matching  SRV record found at DNS server 192.168.200.6:
                    _kerberos._tcp.dc._msdcs.cmedia.local
 
                    Matching  SRV record found at DNS server 192.168.200.6:
                    _ldap._tcp.dc._msdcs.cmedia.local
 
                    Matching  SRV record found at DNS server 192.168.200.6:
                    _kerberos._tcp.cmedia.local
 
                    Matching  SRV record found at DNS server 192.168.200.6:
                    _kerberos._udp.cmedia.local
 
                    Matching  SRV record found at DNS server 192.168.200.6:
                    _kpasswd._tcp.cmedia.local
 
                    Matching  SRV record found at DNS server 192.168.200.6:
                    _ldap._tcp.Default-First-Site-Name._sites.cmedia.local
 
                    Matching  SRV record found at DNS server 192.168.200.6:
                    _kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.cmedia.local
 
                    Matching  SRV record found at DNS server 192.168.200.6:
                    _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.cmedia.local
 
                    Matching  SRV record found at DNS server 192.168.200.6:
                    _kerberos._tcp.Default-First-Site-Name._sites.cmedia.local
 
                    Matching  SRV record found at DNS server 192.168.200.6:
                    _ldap._tcp.gc._msdcs.cmedia.local
 
                    Matching A record found at DNS server 192.168.200.6:
                    gc._msdcs.cmedia.local
 
                    Matching  SRV record found at DNS server 192.168.200.6:
                    _gc._tcp.Default-First-Site-Name._sites.cmedia.local
 
                    Matching  SRV record found at DNS server 192.168.200.6:
                    _ldap._tcp.Default-First-Site-Name._sites.gc._msdcs.cmedia.local
 
              Warning: Record Registrations not found in some network adapters

Can't join AD Domain using FQDN - Fails with Error 53 "Network Path not Found"

$
0
0

06/22/2014 08:28:20:209 NetpDoDomainJoin
06/22/2014 08:28:20:209 NetpMachineValidToJoin: 'MDMSRV01'
06/22/2014 08:28:20:209 OS Version: 6.1
06/22/2014 08:28:20:209 Build number: 7601 (7601.win7sp1_gdr.140303-2144)
06/22/2014 08:28:20:209 ServicePack: Service Pack 1
06/22/2014 08:28:20:209 SKU: Windows Server 2008 R2 Enterprise
06/22/2014 08:28:20:209 NetpDomainJoinLicensingCheck: ulLicenseValue=1, Status: 0x0
06/22/2014 08:28:20:209 NetpGetLsaPrimaryDomain: status: 0x0
06/22/2014 08:28:20:209 NetpMachineValidToJoin: status: 0x0
06/22/2014 08:28:20:209 NetpJoinDomain
06/22/2014 08:28:20:209 Machine: MDMSRV01
06/22/2014 08:28:20:209 Domain: phamnet.int
06/22/2014 08:28:20:209 MachineAccountOU: (NULL)
06/22/2014 08:28:20:209 Account: phamnet.int\GlobalAdmin
06/22/2014 08:28:20:209 Options: 0x27
06/22/2014 08:28:20:209 NetpLoadParameters: loading registry parameters...
06/22/2014 08:28:20:209 NetpLoadParameters: DNSNameResolutionRequired not found, defaulting to '1' 0x2
06/22/2014 08:28:20:209 NetpLoadParameters: DomainCompatibilityMode not found, defaulting to '0' 0x2
06/22/2014 08:28:20:209 NetpLoadParameters: status: 0x2
06/22/2014 08:28:20:209 NetpValidateName: checking to see if 'phamnet.int' is valid as type 3 name
06/22/2014 08:28:20:318 NetpCheckDomainNameIsValid [ Exists ] for 'phamnet.int' returned 0x0
06/22/2014 08:28:20:318 NetpValidateName: name 'phamnet.int' is valid for type 3
06/22/2014 08:28:20:318 NetpDsGetDcName: trying to find DC in domain 'phamnet.int', flags: 0x40001010
06/22/2014 08:28:20:427 NetpLoadParameters: loading registry parameters...
06/22/2014 08:28:20:427 NetpLoadParameters: DNSNameResolutionRequired not found, defaulting to '1' 0x2
06/22/2014 08:28:20:427 NetpLoadParameters: DomainCompatibilityMode not found, defaulting to '0' 0x2
06/22/2014 08:28:20:427 NetpLoadParameters: status: 0x2
06/22/2014 08:28:20:427 NetpDsGetDcName: status of verifying DNS A record name resolution for 'DOMCON02.phamnet.int': 0x0
06/22/2014 08:28:20:427 NetpDsGetDcName: found DC '\\DOMCON02.phamnet.int' in the specified domain
06/22/2014 08:28:20:427 NetpJoinDomainOnDs: NetpDsGetDcName returned: 0x0
06/22/2014 08:29:08:707 [000002e0] NetpGetLsaPrimaryDomain: status: 0x0
06/22/2014 08:29:10:345 NetUseAdd to \\DOMCON02.phamnet.int\IPC$ returned 53
06/22/2014 08:29:10:345 NetpJoinDomain: status of connecting to dc '\\DOMCON02.phamnet.int': 0x35
06/22/2014 08:29:10:345 NetpJoinDomainOnDs: Function exits with status of: 0x35
06/22/2014 08:29:10:345 NetpDoDomainJoin: status: 0x35

So it looks like Windows Server 2012 is vry fussy with the DNS records. I had no issues joining machines to the domain until Server 2012 came along. Can someone help here? If triple checked the SRV records in the DNS and ive screwed around with DNS suffixes etc. 


ADSever Issue ldap_connect failed

$
0
0

I created a windows server 2008 r2 Active Directory Server.
But I see two error events:
>
    Active Directory Domain Services was unable to establish a connection with the global catalog.

    Additional Data
    Error value:
    8430 The directory service encountered an internal failure.
    Internal ID:
    3200db0

    User Action:
    Make sure a global catalog is available in the forest, and is reachable from this domain controller. You may use the nltest utility to diagnose this problem.


>    
      LDAP over Secure Sockets Layer (SSL) will be unavailable at this time because the server was unable to obtain a certificate.

    Additional Data
    Error value:
    8009030e No credentials are available in the security package


When I try to join my linux box to this windows AD sever using msktutil I get below error:
    # msktutil --precreate --host DNS-SERVER.mydomain.com
    Error: ldap_sasl_interactive_bind_s failed (Local error)
    Error: ldap_connect failed
    --> Is your kerberos ticket expired? You might try re-"kinit"ing.

Why is this happening any idea?
Any way to resolve this issue?

The time has come! Step up Windows Server Gurus! Your community needs heroes like you!

$
0
0

TechNet Gurus... we salute you!

You're awesome, and we know it!

Your knowledge uploads and nifty info nuggets are our life blood at TechNet Wiki.

Every awesome article that gets an award is just the start. We are building up the most sensational collection of gifts of knowledge from eminent community heavy weights and young guns alike. And we plan to promote you and your work wherever we can.

Reputations are being forged.

History is being made.

Generations will know your name.

Your children, grandchildren and great-grandchildren will marvel at your technical prowess.

And now, my mighty code warriors, cool consultants and platform specialists, now your chance is here again.

A new month of possibilities. Another chance to prove YOU are the ONE!

The mighty TechNet Guru medal winner for June!

Take up your mouse and keyboard!

Unleash your mighty words of wisdom and bask in the glory that we bestow upon you!

GO GO Gurus! Give, give, give!

All you have to do is add an article to TechNet Wiki from your own specialist field. Something that fits into one of the categories listed on the submissions page. Copy in your own blog posts, a forum solution, a white paper, or just something you had to solve for your own day's work today.

Drop us some nifty knowledge, or superb snippets, and become MICROSOFT TECHNOLOGY GURU OF THE MONTH!

This is an official Microsoft TechNet recognition, where people such as yourselves can truly get noticed!

HOW TO WIN

1) Please copy over your Microsoft technical solutions and revelations toTechNet Wiki.

2) Add a link to it on THIS WIKI COMPETITION PAGE (so we know you've contributed)

3) Every month, we will highlight your contributions, and select a "Guru of the Month" in each technology.

If you win, we will sing your praises in blogs and forums, similar to the weekly contributor awards. Once "on our radar" and making your mark, you will probably be interviewed for your greatness, and maybe eventually even invited into other inner TechNet/MSDN circles!

Winning this award in your favoured technology will help us learn the active members in each community.

Feel free to ask any questions below.

More about TechNet Guru Awards

Submit now : http://social.technet.microsoft.com/wiki/contents/articles/24692.technet-guru-contributions-for-june-2014.aspx

Thanks in advance!
Pete Laker


#PEJL

Got any nice code? If you invest time in coding an elegant, novel or impressive answer on MSDN forums, why not copy it over to the one and onlyTechNet Wiki, for future generations to benefit from! You'll never get archived again!

If you are a member of any user groups, please make sure you list them in the Microsoft User Groups Portal. Microsoft are trying to help promote your groups, and collating them here is the first step.


Implementing AD LDS to Authenticate for External Users

$
0
0

Hello,

I'm able to find documentation on AD LDS but I can't confirm if it's what I want.

My client is setting up an ecommerce site through Volusion and they want to be able to authenticate using Active Directory for their customers.

I personally don't like the idea of opening up the network for customers. AD LDS seems to be the right solution on a tight budget but I can't confirm if it will work.

The Environment:
Server 2012 1: DC; AD; Hyper-V
VM Server 2012 2: File Server (Hosted on Server 1)
VM Server 2012 3: DirSync (Hosted on Server 1)

MS documentation suggests AD LDS not be setup on a DC as well as placing the server in a DMZ. Unfortunately I can't implement a DMZ at the moment. I would like to put AD LDS on the File Sever. There is a web developer working on the ecommerce side, I just have to provide the authentication. I'm going to try a trial version of OneLogin, but for a couple thousand users, it could get expensive.

Questions:
What resources are recommended for AD LDS? (RAM, HDD Space, etc.) I only need AD LDS right now for 5-10 users but if I decide to go with it, it would need to handle a couple thousand accounts.
Is there special process of creating a SSL Certificate for authentication? Or should one be purchased?
How secure is AD LDS?
Does anyone know of any good how-to guides for linking AD LDS to an external PHP site?

Thanks in advance!

-Jake

Cannot add user from trusted domain to Administrators group

$
0
0

I have a migration scenario where I Plan to use ADMT for migration.

The source domain is windows 2003 r2 and the target domain (newly created) is windows 2008 r2. I have already created a two-way external trust between the two domains. However when I want to add the 'administrator' user from the target domain to the source domain built-in "administrators" group it does not allow me to do this. why??

can anyone help?

ADFS-Resource forest Web server sample files

$
0
0

Team,

Help required. Setup 4 Servers & need ADFS-Resource forest Web server sample files. Include webconfig.

Can you pls provide a link where I can download those files? Thanks in advance.

Want to deploy Test ADFS Scenario.


Regards~Biswajit

Disclaimer: This posting is provided & with no warranties or guarantees and confers no rights.

MCP 2003,MCSA 2003, MCSA:M 2003, CCNA, MCTS, Enterprise Admin

MY BLOG

Domain Controllers inventory-Quest Powershell

Generate Report for Bulk Servers-LastBootUpTime,SerialNumber,InstallDate

Generate a Report for installed Hotfix for Bulk Servers

Delegation Rights not working Properly.

$
0
0

Hi

I have created a Security Group, and delegate below rights to this Group.

Delegated can reset the password, but after resetting the users password, on account tab, user must change password at next logon got selected automatically.

And when delegated user try to uncheck this option or try to check another option it says access denied.

Even delegated user is not able change any option on account tab of users properties.

Same thing happening while delegated user created a new user with password never expire option

Below is Error Message.

Note:- delegated user can delete/Disable the user and can change the other properties

In my test environment these delegation rights working fine


Balwan Singh

repadmin replsum still shows old DC which completely demoted

$
0
0

Hi All,

Recently we have demoted some Directory servers from the Forest. it was demoted successfully. then we checked in sites, ADSIEdit, DNS to find any stale record for that. we couldn't find any but when runs the repadmin the DCs which removed comes to the result.

Replication Summary Start Time: 2014-06-22 21:37:15



Beginning data collection for replication summary, this may take awhile:

  ..............................





Source DSA          largest delta    fails/total %%   error

 DC01    >60 days            6 /   6  100  (1908) Could not find the domain controller for this domain.

 DCVM        >60 days           12 /  12  100  (1908) Could not find the domain controller for this domain.

 ADDC01              13m:42s    0 /  47    0  

 ADDC02              13m:42s    0 /  47    0  

 ADDC03              13m:42s    0 /  48    0  

 first 2 DCs we have removed 2 months back and still it comes to the repadmin summery.

appreciate everyone's ideas to remove this stale records,

many thanks


Facing Certificate issue while installing ADFS - Windows Server 2012.

$
0
0
Team,

Facing Certificate issue while installing ADFS - Windows Server 2012.

Error:
The certificates with the CNG private key are not supported.

Based on BING, found Article: http://blogs.technet.com/b/mspfe/archive/2013/11/29/adfs-configuration-wizard-fails-with-error-the-certificates-with-the-cng-private-key-are-not-supported.aspx

Which I have tried, but still not good.
Its been 2 days since I am trying my best, but cant get a solution.
My ADFS deployment is not moving forward and impacting my timelines.

Please suggest a concrete solution.

Regards, Dematri

Can't search from AD

$
0
0

Hello there

I am trying to write a C# code that search for a user which exist in Active Directory

when I run the code in virtual environment with AD 2012 server and windows 8, it works fine with no exceptions. But when I run it in production environment which contains AD 2008 R2 and windows 8, the exceptions starts to appear. I searched for the exceptions throw the internet but I couldn't find a solution that solve my problem.

I have two exceptions:

1-  an operations error occurred , the exception type is: DirectoryServicesCOMException

this exception appears when I run this code and it is thrown by the last line of the code because findOne() returns null:

DirectoryEntry entry = new DirectoryEntry(LDAP://10.10.60.32/DC=parts, DC=mars, DC=com,"user1","password",AuthenticationTypes.Secure);

DirectorySearcher search = new DirectorySearcher(entry); search.ReferralChasing = ReferralChasingOption.All; search.Filter = "(sAMAccountName=" + logonID+")"; search.PropertiesToLoad.Add("sn"); SearchResult result = search.FindOne(); String last_name=result.Properties["sn"][0].ToString();


2- object reference not set to an instance of an object, the exception type is: NullReferenceException

this exception appears when I run this code and it is thrown by the last line of the codebecause findOne() returns null:

DirectorySearcher search = new DirectorySearcher();

search.ReferralChasing = ReferralChasingOption.All;
                
search.Filter = "(sAMAccountName=" + logonID+")";

search.PropertiesToLoad.Add("sn");
SearchResult result = search.FindOne();

                
String last_name=result.Properties["sn"][0].ToString();

Please Help me. I am trying to solve this problem for three days and no result. The logon ID (sAMAccountName) is exist in AD and I am sure about it because I copied it directly from the AD but I don't know why findOne() returns null.

regards




Time Server configuration on Domain workstations

$
0
0

Hello!!

I have couple of questions regarding the Time service on a AD domain.

1. It is the normal way that workstation>DC>PDC hierarchy is followed in a domain and runningw32tm /query /status on a client workstation returns my domain controllers.

HOwerever the following registry key;

hklm/system/controlset001/services/w32time/parameters/ntpserver is test totime.windows.com,0x9.

hklm/system/controlset001/services/w32time/parameters/type is set to NT5DS

is this normal?

2. why doesn't this registry value change to my domain controller?

3. what's the value after the comma stands for? (0x9 in this case)

Modify rangeUpper value of Log on to Workstation attribute in Active Directory Schema

$
0
0
I'm trying to increase the rangeUpper value of the Log on to Workstation attribute in the AD schema as detailed in kb article 938458 support.microsoft.co*/kb/938458

However, after I modify the value, I still get the message that the limit is 64 workstations when I try to add a 65th. 

Is there anything I need to do in order to apply the change? I read an article which said I need to edit the registry to allow changes to the schema. I did this but have not rebooted yet. Is a reboot necessary in general to apply changes made to the schema?


Thanks for the help.

DNS Server

$
0
0

Dear All,

I have the big problem with my ADDS Server running with Windows Server 2008 standard Edition as the following log :-

Error Event ID: 404

The DNS server could not bind a Transmission Control Protocol (TCP) socket to address 0.0.0.0.  The event data is the error code.  An IP address of 0.0.0.0 can indicate a valid "any address" configuration in which all configured IP addresses on the computer are available for use.
Restart the DNS server or reboot the computer.

Error Event ID: 408

The DNS server could not open socket for address 0.0.0.0.
Verify that this is a valid IP address for the server computer.  If it is NOT valid use the Interfaces dialog under Server Properties in the DNS Manager to remove it from the list of IP interfaces.  Then stop and restart the DNS server. (If this was the only IP interface on this machine and the DNS server may not have started as a result of this error.  In that case remove the DNS\Parameters\ ListenAddress value in the services section of the registry and restart.)
 
My solution is reboot the ADDS server. But do you have any better solution that reboot the system?

I'm looking to hearing from you.

Warmly

Khemarin

 

Viewing all 31638 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>