Local account locks domain account
Hello! I have domain account CONTOZO\user1 and local account SERVER\user1 with different passwords. When I log into to the SERVER with a local account it sends several "Transitive Network logon" to the domain controller and locks domain…
Windows Server Essential on an another AD ?
Hello, We need to put a Windows Server 2019 Essentials in a DC AD of another Windows Server 2019 Essentials. The problem being that afterwards we have errors. The errors appeared 3 months after the integration in the AD. Can…
Introducing a Windows 2019 Server DC into a Windows 2012 r2 Domain
Hello, Hoping to avoid any pitfalls. We will be introducing a Windows Server 2019 DC into a domain run by a Windows 2012 R2 DC without upgrading the original DC. The Windows 2012 R2 DC will still act as the primary domain controller. I am trying to…
Query list of Users in Active Directory Security Group (SG)
I have a Active Directory Security Group, I am not completely sure on the LDAP information for this. I would like to write a T-SQL Query to return the list of all users in the Security Group. Thanks
Metadata Cleanup of a Domain controller - SERVER 2012R2
Hi, For Server 2012R2: After a DC is dead, we have to use the following to cleanup metadata: https://video2.skills-academy.com/en-us/windows-server/identity/ad-ds/deploy/ad-ds-metadata-cleanup As far I understand, this will not remove the DNS…
How can add all member of a Dynamic Distribution group to a new Security Group
Hi everyone We have a dynamic distribution group in our Exchange Server, I need to create a new Security Group in Active Directory and add all members of the dynamic distribution group to this Security Group (for other purpose), I think PowerShell…
Why are LDAP queries using PrincipalContext very slow since upgrading to Windows Server 2019
We recently upgraded from Windows 2008 R2 to Windows Server 2019 and since the upgrade the piece of code below now takes over a minute to run when it previously took 1 to 2 seconds. Using netmon I can see that the server is making multiple DNS calls to…
restore deleled objects from recycle bin
Hi Some users and computer objects deleted accidentally. Is it possible use active directory recycle bin to restore them?
Adprep and proper FSMO roles present
Hi, In order to run adprep successfully, particular switches need to have some FSMO roles present(not mentioning the proper permissions). So what FSMO roles particular adprep switch need to connect? Schema Master for /forestprep. What about…
Replication error 8341
Hi, When I stop Netlogon and KDC service in a DC, I receive "operational errors trying to retrieve replication information" with error code 8341. This does not happen in my other environment when I stop these 2 services.
Domain computers do not trust certificates generated from active directory certificate authority
Hello, We have active directory domain running on Windows Server 2016 virtual machines. Where Active Directory Certificate Authority is deployed in a different machine acting as Radius server. After renewing the root certificate, the new certificate…
Export AD Group members
Hi Experts i have a AD Security group and mail enabled security group, i want to export their members. when i use the below syntax i am getting output. Get-ADGroupMember -identity "group@Anonymous .com" | select name | Export-csv -path…
Explorer restrcition
Hi, Based on role based access through domain controller policy , i have to restrict access to explorer. If HDD /Pend rive inserted it shows "open devices printers" icon in system tray i con. when i click on that, its opening windows…
Event 4624, wrong WorkstationName
Hello! Windows Server 2016\2019, Active Directory I see in some 4624 events wrong WorkstationName (my DC's name). For example: Real host is server1.main.contoso.com, IP 192.168.1.50 Real DC is DC-01.main.contoso.com, IP 192.168.1.10 In…
Proper way of replacing Domain Controller on a new hardware (+ changing version old-2008r2, new- 2012r2)
Hi, I'd like to pick the brain of some of you for the proper way of replacing Domain Controller on a new hardware (old-2008r2, new- 2012r2)? What will be the steps to achieve this one? I presume I leave 2008r2 up and running, while installing 2012 r2,…
Functional Level / Sysvol Migration Question
Hello - I have an Active Directory environment that is at Forest Functional Level 2003 (Domain fl of 2008R2). Also, the sysvol migration from FRS to DFSR was partially completed and all DC's are in State 2 (REDIRECTED). My question is.. should we…
Account lockout from a computer without a line of site to active directory VIA MECM
Hi everyone Here is a weird story: Since COVID, most of our domain laptops haven't arrived to the office to connect to active directory. Meaning, users who still wanted to work had to use 2 different passwords - 1 for the local computer (because there…
ADMT 3.2 Supported Servers ( 2012 R2 and 2016 )
Hello Folks, Needs some information on ADMT 3.2 and PES 3.1 whether they will support the below operating systems. Source: Win 2016 and Win 10 Machines Target: Win 2016 and Win 10 Machines Official Link:…
domain controller and internet
Hi, Does a domain controller need internet connection?
Moving to Office 365 / rename domain / hybrid vs cutover
I have a domain with approximately 35 users running Windows 2008R2 server and Exchange 2010. lets say the name is domain1.com However at some point sometime ago company name changed and as such emails changed, so while is AD is still domain1.com the…