active directory not working after demote a dc 2016
Hello, I have a big problem!!! I have 2 Domain controllers on 2016 STD Servers. I transfer all the roles from DC1 to DC2 and i demote DC1. Now DC2 don't work correcly. Active directory tools don't work. Can you help me please??? DC1 => ARTHRO-DC1 …
ADSS Security references obsolete Exchange admin accounts
Good afternoon, all! I have been tasked with validating and cleaning up a customer's ADSS structure. One of the things I've found is that there are some orphaned SIDs that refer back to an obsolete Exchange installation and transporting Exchange…
Force authentication and GPO to get from DC in Azure
Hello all, I'm migrating on-prem DCs to the DC in Azure and trying to make sure that all will be ready for shutting down the on-prem DCs. I've spin up a VM in Azure, joined the domain and promoted to DC. I've moved all FSMO roles to the DC in Azure.…
Amend my LDAP query
I have this openquery that I use to extract data from AD and it works fine. However I need to add an additional criteria but am struggling to do so. Currently the query looks like this OpenQuery ( ADSI, 'SELECT mail, mobile, telephoneNumber,…
Upgrade Domain Controller /w a Child domain
Hello First I want to tell you I have preformed many upgrades from 2003 to 2019. All those steps in between, I know. But never when there is a child domain. I have four DC's, 2008R2. two of these are for the parent XYZ.com and two are the child…
Domain Controller Replication - Modification Date
Hi, I recently upgraded our domain from 2008 to 2016 however I had some issues with replication on the Sysvol. Initially it was ACL which I found out where related to a duplicated "Domain Admins" created when upgraded. I have resolved that…
Rename Users
Hi All, We need to rename around 100 user accounts on our Domain. Basically we need to change from abc001 to xyz001. We need to ensure the users keep all their profile settings locally and on our file server so they are able to reach back to their…
Upgrading Child Domain: Running Adprep in 2012r2
Hi, In order to upgrade a domain to 2012r2, one has to run adprep. Adprep has to have connection to schema fsmo and other roles (infra/rid ?), and needs 3 types of permissions when we run /forestprep, 1 when running /domainprep. Now, how does this…
Active Directory Quotas in both Domain and Configuration partition
Hi, I noticed so called Active Directory Quotas are accessible from BOTH domain and configuration partitions...Can somebody explain this plus implications on both? There is great article on the topic here "Active Directory Quotas"…
Any point in installing high available RODCs?
Hi, We know RODC is "special" kind of domain controller, but is there any reason to install highly available RODCs? How to do it- clusters/nlb? Any deployment tips/tricks/gotchas? Thank you!
Explorer window to netlogon share stays open after login
Hi, we have recently migrated from Desktop Authority to Group Policy with Windows Server 2016 Domain Controllers. Some of our users, not all are experiencing a quirk where after they login a Windows Explorer window stays open to the Netlogon share. No…
AD upgrade from 2008R2 to 2019 or move to new Server 2019.
Hello, We got 1 AD DC in our infrastructure. (Windows serve 2008 R2) DC have such roles: AD DS AD CS NPS (which is not working currently) DNS We need to either upgrade this server to 2019 or make a new server and transfer all roles to…
Windows server backup
Dear team, I have tested to restore backup in windows server backup, we have using different servers with model 2012, 2008. and 2016 but when i tried to restore backup from 2016 it only getting last 45 days to recover back, but in 2012 and 2008 it…
How to delegate permissions on AdminSDHolder users???
Hi, I was wondering how to delegate permissions on AdminSDHolder users??? I found out that some of the accounts are protected by ADMINSHOLDER, but don't really get how to do it. Examples of those accounts would be: Admins, KRBTGT and more: …
remote desktop users
Hi i wanted to know if i can allow remote desktop connection to several pc-s from active directory configuration.I know that i can do it through control panel of each pc but i need to do it to many pc's at one time. any solutions?
Best practices to apply GPO to only one computer in an OU
Hi All, I am currently running 2012R2 DC in my environment. I am going to add on another 2016 or 2019 as the 2nd DC. I do need to apply some setting via GPO (as requested by Security Team) on the new DC. There is an existing GPO for the 2012R2 but…
Powershell Insert Blank Cell for Nonexistent Users in a csv
Hello, I am trying to find managers for each user listed in a csv, then export the results. Here is what I have so far: $list = import-csv "C:\users.csv" $managers = ForEach($User in $list){ Get-ADUser $User.name -Properties…
Domain Password Expiration When Using an RDS Server Published App
Hello We have recently put in place a password policy on our domain which requires regular changes of users passwords. We have a Windows RDS Server 2012 R2 from which we publish our SAP program for remote users to use as we don't want them to use a…
Get-ADPrincipalGroupMembership
That I'm running the command Get-ADPrincipalGroupMembership On dc servers, the command succeeds . But on other servers I get the following error: Anyone have an idea how to solve?
win server 2016 Active Directory Report an error
Environment: There is a domain control, for the time being DC1, the server2016 ip address has been configured, the domain has been added, and the Remote Procedure Call (RPC) and Remote Procedure Call (RPC) locater services have been turned on. Now you…