Quantcast
Channel: Directory Services forum
Viewing all 31638 articles
Browse latest View live

Permissions are incorrectly ordered Error

$
0
0

I was looking to change some permissions on out AD when I right clck on the root in our domain hit properties then the security tab I get a Pop up

The permissions on THISMOMAON.COM are incorrectly ordered, which may cause some entries to be innefective.

Tor order the permissions correctly click reorder.
To leave the permissions unchanged (the view will be read only) Click cancel.

If this were just a folder or OU I'd just hit reorder but since I don't know exactly what it does it makes me nervous hitting reorder on the root. But since I don't all the settings are grayed out as in read only. Does anyone know what this means?

Jason


Create parent domain

$
0
0

Hello,

I have a domain italy.global.lan, I want to create an other one like poland.global.lan.

I would like to have it as a child.

If needed and if possible I could create also a parent one call global.lan, but if I could avoid it... (I would prefer)

Is it possible ?

Thanks in advance

Alex

Forest Root Domain Permanently Disconnected - How to reclaim Schema And Enterprise Admins group or move domain to new forest

$
0
0

Hello.

I have a customer that has a company and domain that was bought by another company and their corporate domain root forest domain was just disconnected one day.

They now want to ADPREP their Forest, but the schema admins and enterprise admins groups are in is this unavailable corporate domain.

Is there any recourse to recreate these security groups or to move their domain to a new forest?

Thanks,

Aaron

Restoration of Additional DC ...

$
0
0

Hello,

I have a question about restoration of additional dc (server 2008r r2).

There two dc on domain and adc has a few roles also.
If additional dc crash and if I restore it from VM backup made 3 days ago, the USN number would be changed, can it cause replication problem ?
Can usn rollback happen ?

Best Regards


how change order "the following...

$
0
0

how to change the order of the "the following domain controllers were identify by the query:

dc2.domain.com

dc1.comain.com

while adding to the domain

question on FRS

$
0
0


Hi

We have one forest and one domain with Windows 2003 and Windows 2008 DCs.
Now, we get rid of Windows 2003 DCs.  we upgrade forest and domain function
level to Windows 2008 R2. 

Will FRS still in use?  should we disable FRS? Will it use FRS for SYSVOL replication?

BTW, it seems that FRS is still in use from event log after functional level is raised.

Thank you!


Long Domain Name - Login difficulty

$
0
0

I have a corporate domain(windows 2012 R2) with a long domain name - CORP.DOMAIN.LOCAL. This is single domain single forest structure.

When users try to login to any app/machine, They need to give CORP.DOMAIN\USER &Password to login. This seems difficult.

Is there a way I can modify/reduce the format such that users can use something like CORP\USER  to login to apps/machines?

can not configure tree domain on windows server 2012

$
0
0
i have configured AD on windows server 2012 and configured one domain. After this i require to add second domain as a tree domain but can not do so. The attached image explain the problem. Can someone help regarding this problemexplain the scenario. Kindly help

Migrate ADFS 2.0 to ADFS 3.0 on different servers/farm

$
0
0

Hello,

We have to migrate an adfs 2.0 farm which federates an on-prem AD with the company's Office 365 tenant AD.

I read through the following technet article https://technet.microsoft.com/en-us/library/dn486815.aspx but this procedure only mentions an in-place upgrade of the existing ADFS servers.  Can anyone point me to an article or document which describes the process of migrating to a new farm? 

Thanks

Martin 

there is no trust relationship between this workstation and primary dc

$
0
0

first question

what is reason for this message (there is no trust relationship between this workstation and primary dc)

and i found this happened on apc which is shutdown yesterday and today have the error !! i mean not 30 day this computer didnt open

second question

i want to solve centeralized from domain which mean i dont go to this pc locally to rejoin to domain ineed apowershel comand any thing helping in solving centeralized

AD ACCOUNT GETTING DISABLED ALL THE TIME

$
0
0

Hi all,

Helpdesk has reported that user account get's disabled all the time & they have to enable it.

What could be the cause of this & how to troubleshoot.

Replication Issues Sysvol Inaccessible

$
0
0

I'm not sure what I am doing wrong here. In my test lab I have two physical boxes, each runs a 2012 R2 domain controller VM.  One is DC1 and the other is DC2.  I have moved FSMO rolls to the following: schema master and domain naming master are on DC1.  PDC, RID and Infrastructure master are on DC2.  They have static ipv4 addresses configured as such.  

DC1
IP:10.0.0.30
SNM:255.255.255.0
GW:10.0.0.1
DNS: P-127.0.0.1
Alt-10.0.0.31 

DC2
IP: 10.0.0.31
SNM:255.255.255.0
GW:10.0.0.1
DNS: P-10.0.0.30
Alt-127.0.0.1

All machines have an IPv6 address via the DHCPv6 server on my pfsense box which has a tunneled IPv6 address through hurricane electric.  They all can pass the IPv6 test pages.  On all my computers I noticed that looking at the network connection details the IPv6 DFGW has the address of fe80::xxxxxxxxxxxxx.  Im not sure if this has any significance at all so i'm just including it. As well as the IPv6 DNS servers are set to ::1

The DNS servers on DC1 and DC2 are each configured with forwarders.  Both DNS servers forwarders are set to 10.0.0.1, 2001:20:470::2, which is the hurricane electric IPv6 DNS server, and two google DNS servers 8.8.8.8 and 8.8.4.4.  Running an nslookup for google.com on the domain controllers yields the following results

server: unknown

address: ::1

non-authoritative answer:

name: google.com

addresses: 2607:f8b0:4009:801::1003
74.125.225.72
74.X
74.X
and so on..

Running nslookup for google.com on any other client computer yields the following results: 

DNS request timed out
Timeout was 2 seconds
Server: unknown
address: 2001:470:20::2

DNS Requst timed out
timeout was 2 seconds
DNS Requst timed out
timeout was 2 seconds
DNS Requst timed out
timeout was 2 seconds
DNS Requst timed out
timeout was 2 seconds
***request to unknown timed-out***

Now each computer passes IPv6 tests and has no issues on the internet so i'm not sure why that's what i get when doing an nslookup on the clients when the domain controllers appear to lookup fine.

Now that you know my configuration getting to my issue/s at hand.  I seem to be having replication issues.  When I open GPMC and click on my domain and then on the status tab click detect now it comes back under the status details 1 domain controller with replication in progress.  It has listed next to it SysVol Inaccessible.  

What am I doing wrong? Why is it inaccessible causing replication issues which I first noticed with GPOs not applying?  I only have a few test GPOs.

One other thing I noticed is when you click change and select a new baseline DC the IP for DC1 is a DHCP IPv6 address while DC2 has fe80::xxxxxxxx for its IP address. They both have the same number of GPOs.  It would appear that they are replicating or at least I think since I created a blank GPO on DC2 and it immediately showed up on DC1 and vise versa.  When I do a gpupdate on a client i get the computer policy could not be updated successfully.  The user policy was successful.

Running gpreport on the client results in under the computer policy 2 errors detected, a fast link detected and the following GPOs have special alerts which lists a few and next to them says AD / SysVol Version Mismatch.  Clicking on the 2 errors I get event ID 1096 and 7016.

The results under the user policy are no errors detected, a fast link detected, and one GPO has special alerts which is the same AD / SysVol Version Mismatch

Thanks!






Restrict Access to Domain Admin/Admin Group for all.

$
0
0

Hello Everyone,

We have a pretty old setup which was managed by our client. They could manage anymore and they have outsourced the entire Datacentre to us.
Everything is messed up right now. Nothing in place correctly and i have taken in charge of it to.

Its a 5000-10000 User, 5 Forest with single domain each environment ( Yes 5 forests root domain). The company kept acquiring other companies and instead of making it a child domain, every company acquired has been made as a forest and forest trust is created among them.

Every tom, dick or harry is having the access to the Domain Admin. Even a service desk guy has been added to the Domain Admin or other sensitive groups.

First and the foremost thing i thought of making changes to the environment is to restrict the access of unwanted people to the DC and other servers and to give least access required to perform their work.

How can i start achieving this. Need your help/suggestions as how should i plan to go ahead.

Thanks in Advance

DNS issue on ADDS 2012R2

$
0
0

Gents,

my AD environment host two domains in single forest each domain contain tow AD DNS integrated zones also I have two NPS servers in one of the domains sometimes NPS's cant find domain controllers in both domains so I have to restart the domain controller then it will be fixed

all servers has been virtualized

I'm suspecting DNS related issues

is there any test that verify all DNS records and show the missing ones ?

what are the DNS tools or command that verify DNS records ?

best

shad


Unable to add Addtional DC In Existing Domain

$
0
0

Hello Team,
I've three sites configured for replication,there are 3 domain controllers in each site, i demoted one domain controller and now i again i am promoting it as DC but unable to do so .. i gives me error saying could not retrieve domain controllers , system cannot find file specified..

event id 1202 , source : DFSR

what does that mean.?

what should i do ?


two forest domains with 2-way trust

$
0
0

I have a dilemma... I have two domains setup. Same network ready for transittion from old domain to new. 

Old domain named: MSI.org.uk  - with domain suffix of mariestopes.org

UPN's for some users is set to mariestopes.org for Office 365 purposes.

The new domain is named: Mariestopes.org  - because we own this internet domain name.


Is there a way of setting up a 2-way trust if these two conflict with each other. Any one got any options I could consider, other than renaming the new domain to something different?

GPO interaction with AD - Password never Expires

$
0
0

I'm not an expert of GPO but I was tasked to look at a solution either ways (just joined a new team).
Our security team wants to make sure that every single person in the company has to change his password every tot days. Now, that's done already, except for global accounts.

 

Let's say _No-Expiration is a group containing all the users that I want their password not to expire. Now, what I want to achieve is to get a GPO set for all OU's which has to overwrite the Password never expires option in AD and unflag it (unless that user is a member of the above group).
So I actually want to:

  1. Overrule AD
  2. Actually change the flag of the object

 

Is this possible?

 

Thank you

Need help in pulling ADLDS user details

$
0
0

Hi,

I am trying to pull all the user details with a certain search criterea from a ADLDS with more than 20 user attributes. I tried both directory searcher and Powershell for gathering the information (out of this powershell works fast). Due to formating the attributes it takes more than 30 minutes to run the script. Could some suggest me a better solution for this.

Thanks

Pradeep

Outdated error messages in AD RST

$
0
0

Hi,

I'm currently running a daily AD RST compilation of the day's AD replication.  I've cleaned up a lot of errors but I have one that's embedded within a successful sync.  It did originally extend beyond the TSL but, as I said, I've cleaned up that replication issue.

How do I remove this old error message? 

Thanks,

Stan


Stanley E. Noel Jr

Trust between ADFS 3.0 sites

$
0
0

Hi,

First of all I'm sorry if I may have selected the incorrect forum category but I couldn't find a forum category which fits my question.

We have servers hosted on Azure so that we could centrally have the servers setup for ADFS 3.0 (Server 2012 r2) for SSO capabilities with Office365 platform. Another company within the group is already using Office365 and wants to enable some kind of trust between the two companies (the main interest is sharing and collaboration), however we were told that in Office365 there is no option for this and the two tenants are treated exactly like an external customer.

I wanted to confirm that there is another way to enable trust between the two tenants through ADFS.

Thanks,

Viewing all 31638 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>