Quantcast
Channel: Directory Services forum
Viewing all 31638 articles
Browse latest View live

KCC won't generate connections - A database error has occurred (8409)

$
0
0

I'm having a whole heap of trouble with this AD Forest I've inherited at a new job.  The previous admins set up manual connection objects all over the place instead of using a proper Site Links-based design.  As I understand it they wanted "redundancy" between the various DCs in the child domains.  

Oh yeah, I should probably explain the environement.

It's a single Forest.  It contains a single domain (HQ.local) and 3 child domains (bangkok, nairobi, managua).  Now, it's complicated by the fact that each of the child domains has it's own, sort of "main office" site and then there are several other remote sites (each with their own DC) that can ONLY connect to main office site and not to any other remote site.

So, for example, take the Bangkok child domain.  It has a site (Bangkok) with 2 DCs.  That can connect to HQ.  Then there are 3 other remote sites (Kabul, Manila, Almaty) each with their own DC but they can only communicate with Bangkok (and NOT HQ or each other).

I'm trying to get the Site Links set up properly by disabling BASL first off and creating Site Link Bridges.

I've deleted the manually created objects from each servers NTDS settings but now when I run repadmin /kcc site:bangkok I get

DsReplicaConsistencyCheck() failed with status 8409 (0x20d9):
    A database error has occurred.

I strongly suspect replication is irrevocably broken between the DCs or, at best, they've become very disjointed.

I've been wrestling with this for days so any help would be greatly appreciated




DNS Settings for DR Site

$
0
0

Hello guys,

I use VEEAM Backup & Replication for the Disaster Recovery Site. Replication works without problem but i would like to know which is the best configuration for my local DNS Server when use a Server DR Site.

In Veeam i use the Re-IP for network mapping and automatic IP address transformation.


I have the following settings

192.168.10.x (Local Network)

192.168.10.50 (Windows Server that i will use in DR Site)

192.168.5.x (DR Site)

192.168.5.50 (Windows Server in DR Site).

I would like to have DNS Records for my DR Site and don't add the time that must be tranfer the workload in my DR Site.

RODC krbtgt deleted

$
0
0

Hello,

user management in my company deleted krbtgt accounts for RODCs.

We don't have recycle bin implemented and I would like to avoid authoritative restore.

I restored krbtgt accounts using tombstone reanimation (adrestore utility). But it does not work either...probably because password is not kept when object is deleted.

IS THERE A WAY HOW TO RECREATE RODC KRBTGT ACCOUNT?

Thank you for advice

How to deploy the web app using ADFS

$
0
0

Hi there

I installed ADFS windows server 2012 r2 on 2 servers [ Account partner organisation and resource partner organisation]

I think I've done the configuration correctly.

https://mysite/adfs/ls/IdpInitiatedSignon.aspx

I can authenticate the user and log to the url correctly.

The part I don't understand is I've installed a web application in the server. I don't know how can I access the webs app using ADFS?

Please let me know how to proceed ?

I haven't installed the proxy server.

Thanks

Sathish


Active Directory Design ... Multiple Domains or Organizational Units

$
0
0

I've been trying to find some Best Practices on whether to have multiple domains or just use a single domain with multiple organizational units.  We have three locations each having their own separate domain right now.  We want to consolidate our Domains into one Forest under our primary site.  We've thought of making the smaller domains a part of our primary forest so we could manage the other domains at the enterprise level when needed (our remote systems administrators currently manage their smaller domains which causes us some management issues).  We are only talking about 100 to 125 servers across the enterprise and about 400 workstations...our primary location has about 400 users while the other locations have less than a dozen users.

We've also thougth of just expanding our domain to cover all locations and just create organizational units for each of the remote locations rather than having multiple domains.  Seems like this would be easier to manage than having multiple domains.

We'd like to find some best practices and case studies on this but have been coming up pretty empty so far.  Any help or pointing in the right direction would be appreciated!  Thanks.

What's the risk of updating ADMX files?

$
0
0

Our regular Group Policy guy left the company recently so I'm trying to make what I think of as a fairly simple update but I wanted to ask someone more familiar with it before I break everything. :)

We want to block the upgrade to Office 2016from Office 365 and they say you do it through a GPO. Fair enough. I downloaded the ADMX file in the article and found that one already exists in the repository with the same name. Comparing the XML, it seems to be an older version and just doesn't have some of the settings that the new one has.

So if I just replace that ADMX, is there any danger to my users? Are the existing policies going to be affected if they use the existing ADMX? I don't want to kill the DC or anything and I know the changes are replicated so if it goes south, I can see things replicating out of hand very quickly.

Am I being overly cautious? Thanks!

Keith

Trust Relationship Issue

$
0
0

Hello everyone,

I am currently getting an error on my domain anytime a user is prompted to change their passwords. First, the popup doesn't come up to warn about the password change. Once they are forced to change their password, they get an error stating "The trust relationship between this workstation and the primary domain failed." I have to go into AD and manually enter in a new password for this user. I cannot figure out what the issue is. Any help would be greatly appreciated.

Thank you,

Mike

Audit Failures

$
0
0

I'm getting a ton of audit failures. Problem is I can't ID the source. Any suggestions?

- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
  <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" /> 
  <EventID>4625</EventID> 
  <Version>0</Version> 
  <Level>0</Level> 
  <Task>12544</Task> 
  <Opcode>0</Opcode> 
  <Keywords>0x8010000000000000</Keywords> 
  <TimeCreated SystemTime="2016-06-06T17:09:42.562073700Z" /> 
  <EventRecordID>135472195</EventRecordID> 
  <Correlation /> 
  <Execution ProcessID="732" ThreadID="34820" /> 
  <Channel>Security</Channel> 
  <Computer>FVC.FLOERKE.local</Computer> 
  <Security /> 
  </System>
- <EventData>
  <Data Name="SubjectUserSid">S-1-5-18</Data> 
  <Data Name="SubjectUserName">FVC$</Data> 
  <Data Name="SubjectDomainName">FLOERKE</Data> 
  <Data Name="SubjectLogonId">0x3e7</Data> 
  <Data Name="TargetUserSid">S-1-0-0</Data> 
  <Data Name="TargetUserName" /> 
  <Data Name="TargetDomainName" /> 
  <Data Name="Status">0xc000006d</Data> 
  <Data Name="FailureReason">%%2313</Data> 
  <Data Name="SubStatus">0xc0000064</Data> 
  <Data Name="LogonType">3</Data> 
  <Data Name="LogonProcessName">Schannel</Data> 
  <Data Name="AuthenticationPackageName">Kerberos</Data> 
  <Data Name="WorkstationName">FVC</Data> 
  <Data Name="TransmittedServices">-</Data> 
  <Data Name="LmPackageName">-</Data> 
  <Data Name="KeyLength">0</Data> 
  <Data Name="ProcessId">0x2dc</Data> 
  <Data Name="ProcessName">C:\Windows\System32\lsass.exe</Data> 
  <Data Name="IpAddress">-</Data> 
  <Data Name="IpPort">-</Data> 
  </EventData>
  </Event>


Windows Server Gurus! Where are you!?

$
0
0

Behold! It's the June TechNet Guru Contest!

Your chance to get your name known, raise your profile, get credit where credit is due!

Yes my friends, this is your chance to get listed along-side some of the industry's greatest community heroes!

All you have to do is add an article to TechNet Wiki from your own specialist field. Something that fits into one of the categories listed on the submissions page. Copy in your own blog posts, a forum solution, a white paper, or just something you had to solve for your own day's work today.

Drop us some nifty knowledge, or superb snippets, and become MICROSOFT TECHNOLOGY GURU OF THE MONTH!

This is an official Microsoft TechNet recognition, where people such as yourselves can truly get noticed!

HOW TO WIN

1) Please copy over your Microsoft technical solutions and revelations toTechNet Wiki.

2) Add a link to it on THIS WIKI COMPETITION PAGE (so we know you've contributed)

3) Every month, we will highlight your contributions, and select a "Guru of the Month" in each technology.

If you win, we will sing your praises in blogs and forums, similar to the weekly contributor awards. Once "on our radar" and making your mark, you will probably be interviewed for your greatness, and maybe eventually even invited into other inner TechNet/MSDN circles!

Winning this award in your favoured technology will help us learn the active members in each community.

June's articles are with the judges, but below are the previous month's mighty winners and contenders!

Guru Award BizTalk Technical Guru – April 2016 
Gold Award WinnerEldert GrootenboerUsing BizTalk Deployment Framework with MSBuild to bypass reserved placeholdersJS: “BTDF if getting quite popular. Nice to see some advanced use cases.”
LG: “Good practical tip. Thank you sharing!”
Sandro Pereira: “Well written, excellent article for BTDF lovers”
Silver Award WinnerSMSVikasKIntegration Between Microsoft BizTalk Server 2013 & Microsoft Dynamics CRM Online 2016LG: “BizTalk Dynamic CRM is a very hot topic.”
JS: “Microsoft CRM’s API is very (maybe too :)flexible, this is a simple and expandable pattern to start a BizTalk integration app with. “
Bronze Award WinnerSandro PereiraBizTalk Server DevOps: Configuring Receive and Send Handlers in BizTalk Ports with PowerShellJS: “Great addition to BizTal’s PowerShell story. Super useful for VM provisioning and similar cases.”
LG: “Thank you sharing!”

Guru Award Forefront Identity Manager Technical Guru – April 2016 
Gold Award WinnerJeff IngallsManaging Contacts in the FIM/MIM PortalPG: “Wow, nice! Keep up the good work!”
Søren Granfeldt: “Good and detailed walk-through”

Guru Award Microsoft Azure Technical Guru – April 2016 
Gold Award WinnerSandro PereiraAzure Logic Apps: Dynamic Hello World using Azure Functions inside Logic AppsJH: “Good articles from Sandro this month. This one is a good entry into Azure Functions.”
AN:“Very good”
Silver Award WinnerBhushan GawaleAzure Remote Apps – In Depth WalkthroughJH: “Nice Azure Remote Apps walkthrough with a good mixture of text and pictures.”
AN: “Great walkthrough!”
Bronze Award WinnerJanshair KhanUnderstanding and Creating Azure Deployment SlotsJH: “Short overview about deployment slots. A little bit more on their usage would be great.”
AN:“Another great article!”

Guru Award Miscellaneous Technical Guru – April 2016 
Gold Award WinnerNamrah KhurramGetting started with the Raspberry Pi – A walk-throughRichard Mueller: “Great images and good explanation”
Silver Award WinnerSYED SHANUDraw MVC Pie Chart using WEB API, AngularJS and JQueryRichard Mueller: “More good images and code.”
Bronze Award WinnerJanshair KhanUnderstanding Docker for Absolute BeginnersRichard Mueller: “A great tutorial to explain what it is.”

Guru Award SharePoint 2010 / 2013 Technical Guru – April 2016 
Gold Award WinnerNathanaël StassartSharePoint 2013 – Crawl file shares beyond the 260 MAX_PATH limit – Issue with ErrorID 808 829 – The object is not foundTN: “This article is extremely helpful providing real-world experience when working with fileshare”
Silver Award WinnerWaqas SarwarSharePoint 2016 Rename Site Collection URL Best PracticeTN: “Great article in SharePoint 2016 which is very new to the community.”
Bronze Award WinnerNathanaël StassartSharePoint 2016 – Crawl Error List [ErrorID]TN: “Thanks Nat”

Guru Award Small Basic Technical Guru – April 2016 
Gold Award WinnerNonki TakahashiSmall Basic: FlickrMichiel Van Hoorn: “Nice to see updated doc”
DEVA: “Great one Nonki. You rock onemore time…!!”

Guru Award SQL BI and Power BI Technical Guru – April 2016 
Gold Award WinnerGreg Deckler (Fusion Alliance)Power Query: Using Recursion to Solve Hex to Decimal ConversionPT: “A very good wiki contribution. Thank you! This post is deep and specific to solve a particular challenging issue.”

Guru Award Transact-SQL Technical Guru – April 2016 
Gold Award WinnerNatig GurbanovSql Server: Using Parameterized FunctionsJS: “”
Richard Mueller: “Interesting code. Grammar needs work.”

Guru Award Universal Windows Apps Technical Guru – April 2016 
Gold Award WinnerRavindra Singh ChhabraHow to install native Service into Windows 10 mobileRC: “Great work”
Silver Award WinnerManisha BiswasMicrosoft Hololens a walkthroughRC: “Very nice”
Bronze Award WinnerRavindra Singh ChhabraLocalization for Windows Universal AppsRC: “Another good one”

Guru Award Visual Basic Technical Guru – April 2016 
Gold Award WinnerEmiliano MussoCreate a versioning service with Visual Basic .NETCarmelo La Monica: “Congrats Emiliano, very goos article, image and video. Good work.”
MR: “Good walkthrough!”
Richard Mueller: “Very well explained. Great images.”
Silver Award Winner.paul.Vb.Net – Animations and MoviesRichard Mueller: “Well written and an interesting topic.”
MR: “Great little utility!”
Carmelo La Monica: “Great, very useful for to create animation with images. Congrats!”

Guru Award Visual C# Technical Guru – April 2016 
Gold Award WinnerSibeesh VenuHow To Create Dynamic Angular JS Tabs In MVCJaliya Udagedara: “Great article with a step by step explanation. Love the fact that it’s using Angular Material. Hint: You can upload the sample code to MSDN Code Gallery. “
Silver Award WinnerSYED SHANUC# Winform Animated Image Slide Show in WinformJaliya Udagedara: “Good article with images and code snippets. And the sample code is available for download from MSDN Code Gallery.”
Bronze Award WinnerSibeesh VenuProgrammatically Extract or Unzip Zip,Rar Files And CheckJaliya Udagedara: “Good article explaining the whole process including file upload and file extraction. You can always use MSDN Code Gallery to upload the source code, so anyone can view/download from there.”

Guru Award Windows PowerShell Technical Guru – April 2016 
Gold Award WinnerVZSandzWindows MAK activation with PowerShellJan Egil Ring: “Nice start, needs a polish”
Richard Mueller: “Good code to know about. Grammar needs work.”

Guru Award Windows Presentation Foundation (WPF) Technical Guru – April 2016 
Gold Award WinnerAndy ONeillHide The Visual Studio 2015 Update 2 In App MenuLL: “Thanks for the top Andy”
Peter Laker:“Thanks Andy”

Guru Award Windows Server Technical Guru – April 2016 
Gold Award WinnerNathanaël StassartAD FS 4.0: Discover, Setup and Publish Application: Part1Mark Parris: “Good Information on ADFS v4.”
JM: “Your two articles on Web Application Proxy are excellent, thanks for your contribution”
Richard Mueller: “Great code and good images.”
Silver Award WinnerAvendilActive Directory: Transferring and Seizing the RID Master roleRichard Mueller: “Great use of Wiki guidelines, great references and links. Very important information to know. I like the detailed steps and alternative methods. And I love the cross-links. An excellent article.”
Mark Parris: “PowerShell replacing the GUI process, handy to have in Onenote.”
JM: “This is a great article on the RID Master role, thanks for your contribution”
Bronze Award WinnerKia Zhi Tang (Ryen Tang)Nano Server: Deploying PHP 7.0.6 on Internet Information Services (IIS) Web ServerRichard Mueller: “Very good references and lots of good code.”
JM: “This is an excellent article on Nano Server, thanks for contributing”
Mark Parris: “Good Insight.”

Thanks in advance!
Pete Laker


#PEJL
Got any nice code? If you invest time in coding an elegant, novel or impressive answer on MSDN forums, why not copy it over toTechNet Wiki, for future generations to benefit from! You'll never get archived again, and you could win weekly awards!

Have you got what it takes o become this month's TechNet Technical Guru? Join a long list of well known community big hitters, show your knowledge and prowess in your favoured technologies!

Active Directory GPO lookup failure. Windows cannot query for the list of Group Policy objects.

$
0
0
I am getting the following SCOM alert about “Active Directory GPO lookup failure” from one of our domain controllers (dc-server1) that is running on Windows Server 2003 OS. The rest of domain controllers are on Windows 2008 and 2012 (domain functional level is 2003). I did enable UserEnv logging and attaching the userenv.log that I captured. Also attaching the events that appear to be relevant in the event logs on dc-server1.

I have a suspicion that this could be caused by another issue that we are experiencing, but not 100% sure, hence wanted to ask you to confirm. The other issue is: we have a domain account called "stuffadmin" which get locked up every 10 minutes or so. Most likely there is a job or service running somewhere that has an old password for this account and it is locking the account with bad password requests. I tried to track it. From PDC (p-dc1) I traced it to the domain controller above (dc-server1), and from there to a a server that is running "E:\Program Files (x86)\Spiceworks\spiceworks_desktop.exe" among other things. I wasn’t able to find the exact process or program that is trying to use that account. some of the event logs from below complain about that specific account at the same time that the SCOM error was issued.

The SCOM alert and event logs are below, and userenv.log and userenv.bak can by downloaded by clicking on their names.


Alerts and Event Logs:

Machine account policy failure - Active Directory GPO lookup failure 

Alert Description 
Source:    dc-server1 
Full Path Name:    dc-server1.TheCompany.com\dc-server1 
Alert Rule:    Machine account policy failure - Active Directory GPO lookup failure 
Created:    5/5/2016 3:20:52 PM 
  Windows cannot query for the list of Group Policy objects. Check the event log for possible messages previously logged by the policy engine that describes the reason for this.

Knowledge:     View additional knowledge... 
 
Summary
UserEnv experienced an error applying Group Policy to the domain controller. Group Policy must be applied successfully for domain controllers to function properly because domain controllers get several critical permissions, such as Access this computer from network, through policy. Because of the architecture of UserEnv, Microsoft Operations Manager (MOM) is unable to directly report the specific problem.

Sample Event: Windows cannot query for the list of Group Policy objects. Check the event log for possible messages previously logged by the policy engine that describes the reason for this.

Causes: This may indicate that the Active Directory® directory service has failed. Problems with replication are the main cause of this error.

Resolutions
To enable UserEnv logging, see Knowledge Base article 221833, “How to Enable User Environment Debug Logging in Retail Builds of Windows,” at http://go.microsoft.com/fwlink/?LinkId=25636. The log file provides details for the specific error. 

External Knowledge Sources
• Microsoft Help and Support for Microsoft Windows Server 2003
• Microsoft Knowledge Base




--- Application Log ---

Event Type:Error
Event Source:Userenv
Event Category:None
Event ID:1030
Date:5/5/2016
Time:3:20:52 PM
User:TheCompany\stuffadmin
Computer:dc-server1
Description:
Windows cannot query for the list of Group Policy objects. Check the event log for possible messages previously logged by the policy engine that describes the reason for this.


Event Type:Error
Event Source:Userenv
Event Category:None
Event ID:1058
Date:5/5/2016
Time:3:20:52 PM
User:TheCompany\stuffadmin
Computer:dc-server1
Description:
Windows cannot access the file gpt.ini for GPO cn={D2192853-520B-42FC-86BC-D09381B1FA45},cn=policies,cn=system,DC=TheCompany,DC=com. The file must be present at the location <\\TheCompany.com\SysVol\TheCompany.com\Policies\{D2192853-520B-42FC-86BC-D09381B1FA45}\gpt.ini>. (The system detected a possible attempt to compromise security. Please ensure that you can contact the server that authenticated you. ). Group Policy processing aborted. 


--- System Log ---
Event Type:Warning
Event Source:LSASRV
Event Category:SPNEGO (Negotiator) 
Event ID:40960
Date:5/5/2016
Time:3:20:52 PM
User:N/A
Computer:dc-server1
Description:
The Security System detected an authentication error for the server cifs/p-dc1.TheCompany.com.  The failure code from authentication protocol Kerberos was "The referenced account is currently disabled and may not be logged on to.
 (0xc0000072)".

Data:
0000: 72 00 00 c0               r..À    




--- Directory Service Log ---

Event Type:Warning
Event Source:NTDS Replication
Event Category:Replication 
Event ID:1083
Date:5/5/2016
Time:3:35:58 AM
User:NT AUTHORITY\ANONYMOUS LOGON
Computer:dc-server1
Description:
Active Directory could not update the following object with changes received from the domain controller at the following network address because Active Directory was busy processing information. 
 
Object:
CN=Workstation Adminstation,OU=Admins,OU=IT,OU=El Dorado,DC=TheCompany,DC=com 
Network address:
a1cb9e05-9ec2-4c82-b344-dcf52d3760ef._msdcs.TheCompany.com 
 
This operation will be tried again later.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

Found IP address when searching Computer Object

$
0
0

Hi,

when I search computer name with *.* in Domain Controller , the results shows few ipaddress in computer object column.

Does anyone know what is this ? and why it shows ipaddress ?


DFSR Domain System Volume Replication

$
0
0

Multi Site ADDS

Sysvol replication with DFSR-

Replication of Sysvol and netlogon folders occurs very slowly (hours) between DC on different Sites, but immediately within the same site.

I was looking for a way to configure the Replication Group schedule. Even with powershell I cannot get information of Domain System Volume replication group. I suppose the replication schedule of DFSR is not the same of ADDS Intersite Site Link.

If I use the dfsrdiag syncnow ... I can force the replication successfully, but I would like to have more control on the Replication Group parameters.

I thank you very much for  your help.

Kind regards,

Enrico Giacomin

prevent locally creation of userprofiles

$
0
0

Hi,

How do I prevent when a user logs in for the first time, there is locally created a userprofile under “C:\Users”. 

Kind regards,

Ruben

2 RODC's are showing same IP address in DNS server

$
0
0

I have a domain xxxx.in with 4 AD-DC & 7 RODC servers, one of my RODC IP is xxx.xx.72.x & others is xxx.xx.74.x, both the servers are RODC & are in same domain. But in dns server of my writable DC ip of both the servers are showing xxx.xx.72.x.

Now if i delete these dns entries from all 4 of my writable DC's, it reverts the same IP after quarter or half an hour later.

I tried removing the RODC with IP address xxx.xx.74.x from active directory, dns server, ADSI Edit & AD Sites & services & formatted the server & again run DCPROMO & installed RODC on the server, after installing Active directory & DNS to the server its IP was showing absolutely correct in DNS server of writable DC's, but after half an hour it again started showing the old dns of my other RODC xxx.xx.72.x in my writable DC.

Anybody can help??

How to configure AD User Accounts with access to servers in a trusted forest, but not to resources in local domain/forest?

$
0
0

I've been tasked with creating user accounts for external users.  These accounts are to provide access to RDP servers in a trusted forest.  We do not have access to create new accounts directly in the trusted forest.  These users should not have any access to resources in the domain or forest which they are members of, only the remote forest. 

How can I create user accounts in one domain to allow access to servers in a trusted domain, while preventing them access to anything in that domain/forest?


tools dnscmd /zoneadd

$
0
0
Hello,

I have a root domain cont^roler on windows 2000 sp4 with one primaruy dns zone integrated in Active diretory and thousand reverse dns sont not integrated.

I have to change this server for a new server , by keeping name and ip address and all dns zone.

i found this command line "dnscmd /zoneadd /primary /file 10.x.x.x.dns" to add thousand reserse zone, but there is log file.

With this command line, is the record content in the dns zone file are created ?

and

Do i have to copy the dns log file ?

ragards

need your help! urgent

$
0
0

Hi,

We have one forest with functional level 2008 R2.

Currently, all domain controllers certificates are manually enrolled through certreq -new to generate request file on a request.inf and request cert on http://ourinternalrootCA/certsrv.  these internalrootCA are not in our forest.  Right now, we need to renew all domain controllers certificates (30 DCs).  Is it possible to automate the renew process?

When I try to renew through mmc certificate,I got "the request contains no certificate template information".  does it mean that we need enterprise CA in our own forest to get auto-renew work?

Can anyone share insight how to get auto-renew certificates on domain controllers?

Thank you! 

Active Directory Sync - Not finding objects

$
0
0

I have an external application that I am trying to sync user objects from. Whenever I make the call to AD, I get a credential error displayed in the external app. 

Here are the rrors I am seeing in the log from the LDAPSync program that is utilized by the external app

20160607/103425.460 - err->code=51002, err->text='SearchResultDone|noSuchObject|0000208D: NameErr: DSID-03100238, problem 2001 (NO_OBJECT), data 0, best match of:
'DC=<DC NAME>,DC=ca'

This repeats 3 times before the call exits. One thing that is VERY odd is that the DC=ca is only a partial for the entire domain entry. I don't know if it is cropping it or what might be happening.

If a dcdiag is needed I will happily generate,scrub,upload it.

Thanks in advance!!

ADFS Claim Rule - Device Registration

$
0
0

We have successfully implemented device registration in ADFS with Office 365 using Azure AADConnet with device writeback.  We see the device registration container and it is populated with all the devices that we have workplace joined (registered). Also we can see the devices in Azure AD for each user.

Now we are trying to set up a claim rule that states, if you are external AND your device is not registered then enforce multifactor.  Here is our claim rule we are using to try and accomplish this:

c:[Type == "http://schemas.microsoft.com/2012/01/devicecontext/claims/isregistereduser", Value == "false"] 
&& c1:[Type == "http://schemas.microsoft.com/ws/2012/01/insidecorporatenetwork", Value == "false"] 
=> issue(Type = "http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationmethod", Value = "http://schemas.microsoft.com/claims/multipleauthn");

We have set that as an additionalauthenticationrule using powershell for our O365 relying party trust.

On my device which I have absolutely confirmed is a registered device, when I go the O365 web portal and login, I am still getting a multifactor prompt.  Since I'm going to the web portal on a registerd device, shouldnt I not get multifactor?  Also tried using the Outlook app to set up email,  I'm also getting MFA prompt when setting up my 365 account using that app as well.  

If I connect to our works wifi so that my device gets an internal IP, I do not get MFA so I know the claim rule is working but for some reason it is not detecting that my  device is registered.  We have tried on multiple devices that are for sure registered but its the same result.

Any help is greatly appreciated.


Rich

New certificate

$
0
0
We currently have an ADFS server setup for office 365.  I purchased a new certificate, and imported it.  Do I need to do anything else?  When the current certificate expires will the new one automatically kick in?
Viewing all 31638 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>