Decom 2012 DC but need the new DC to use the same IP Address and Name
Hello, I want to build a brand new 2016 DC but there is a hard requirement to have the new DC replace and old one using the old DC's name and IP address (2012 R2). I see many people say not to do this...
View ArticleFunctional Level Upgrade / Domain Level Upgrade from 2003 to 2008R2/2012R2...
Hi, we are planning to raise our AD Functional level from 2003 to 2008R2 then to 2012R2. All or DC's/GC's are on Windows Server 2012R2.We know of the .NET 3.5 or lower issues, and that we need to...
View Articleunchecked Allow inheritable permissions from parent to propagate to this...
i unchecked "Allow inheritable permissions from parent to propagate to this object and all child objects. Include these with entries explicitly defined here"in a folder's advance permission. now i cant...
View ArticlePatching Information
Hi Team,A need in simple quick answers. We had run a nessus scan we had found few of the vulnerability for which they had mentioned to install the patches. The patches which they had mentioned is of...
View ArticleDrive mappings
In our environment, 2008 R2 AD, we have batch files that run on login mapping users to specific drives. The GPO's used to do this point to a specific AD servers sysvol for the login scripts. So, if...
View ArticleActive Directory Upgrade 2003 to 2016
Hi all, I was recently hired to upgrade an Active Directory infrastructure based on Windows Server 2003 R2. Is it possible to go directly to 2016? The client is also concerned with their Windows XP...
View Articlecreate a banned password list
Hello, We got a client with a problem with weak passwords, currently the complexity level is 3/4 but it is not enough and we would like to create a banned password list in order to forbids 123456aA...
View ArticleProtected user group in 2012 R2
Hi, I have few privileged user account in my domain, planing to implement "protected user group" authentication mechanism. All my NetApp shares can be connected using IP address. Technically if user is...
View Articleunchecked Include inheritable permissions from this object's parent
i unchecked "Include inheritable permissions from this object's parent"in a folder's advance permission setting. now i cant access that folder but can access its sub folders.i am the domain admin. what...
View ArticleDomain Controller shows Public Network
Dear Support, Could it have any impact on Domain Controller when the network of Domain Controller is "Public network"? How could the network be changed from "Public" to "Domain" if it have impact on...
View ArticleWhat is a replicated "constructed attribute"?
Hi,As per the definition, for a "Constructed Attribute" in AD, it's value is generated on the fly when a client requests for the same. But, some Constructed Attributes like...
View ArticleInstallation of Certificate Authority Role
Where should I install certificate authority role ? do I need to have dedicated machine in a domain, can I install in domain controller where Active Directory is installed.Thanks, Ram Ch
View ArticleDC decommission, Keytab and kerberos
Hi team,We have two domain controllers in the HO site running Windows server 2012 R2. We're in the process of upgrading the environment to WS 2016. We have completed one server and one is remaining.The...
View ArticleAD Kerberos question
Hi All! We currently run Microsoft Advanced Threat Analytics, and we quite often get the following error for Windows client PCs and ADFS servers: Encryption downgrade activity The encryption method of...
View ArticleNTLM Kerberos Question
I have \\server\share that is accessed by help desk. This share has several shortcuts pointing to other \\x.x.x.x\share at remote sites. Note the IP. It needs to be an IP, it's a remote site that...
View ArticleControlAccessRight RightsGUID Values
Hi I'm working on Powershell script to create a machine account and as part of giving right to users / groups to have access to add that machine to the Domain im looking for some Rights GUID values...
View ArticleUpgrade 2008 R2 to 2016 with 2012 R2 Domain & Functional Level
Hi,I'm seeking to understand whether the following scenario is a supported / recommended / possible upgrade path for AD DS.We currently have a 2008 R2 domain (native) with around 20 domain controllers...
View ArticleConnect to domain
Hello y'all,I've installed a brand new fresh copy of Windows Server 2016 Standard on a virtual machine (VMware if it matters) and installed Active Directory - promoted to domain controller and created...
View ArticleAD CS: Issues getting the Root CA back to the Trusted CAs cert store
Hi,Two weeks ago we renewed our Entreprise CA cert and it was properly deployed to all our clients. I was able to even use certultil -pulse to get it updated on my laptiop as soons as I finished the...
View ArticleCreating password policy for individual group
Hi I seem to be having issues with creating a seperate Password policy for certain users aside from the default domain password policy in AD. This new password Policy is set so that the only group that...
View Article