Working of kerberos during authorization on the server.
Hello. I have read the documentation how Kerberos works, but I don't understand the algorithm a bit. For example, a client from a Windows 11 workstation logs into a Windows Server 2019 server via RDP. The first step is to request a kerberos ticket. How…
there is a folder on your computer called "c:\program" which could cause certain application not function correctly. renaming to "c:\program1" would solve this problem this waring to all my domain PC and server. there is a folder on your computer called
there is a folder on your computer called "c:\program" which could cause certain application not function correctly. renaming to "c:\program1" would solve this problem this waring to all my domain PC and server. there is a folder on…
Warning: DC is not advertising as a time server...I've tried non-authoritative sync of sysvol data, lots of time command,
I ran w32tm /monitor, I have 4 DC.....for the life of me can't get group policy and the server time Warning: SUM22RAD19 is not advertising as a time server. ......................... SUM22RAD19 failed test Advertising ERROR TO GO AWAY...Any…
How can I troubleshoot sync errors between Entra ID and M365
We have on-premises Active Directory synced with Azure/Entra, which then updates Microsoft 365 (M365) and Exchange Online with user details. However, I have one user whose details are syncing to Azure but not to M365. My main goal is to add a proxy…
Get error "AADSTS50079" with Azure Intra ID via OpenID Connect (OIDC) on Refresh Token with MFA
I am using OpenId Connect (OIDC) to authenticate my users to IntraID, we have MFA enabled and initially work as expected. The user is able to authenticate and access our application in the cloud, and we see tokens get refreshed. After some length of…
Unable to create the synchronization service account for Azure Active Directory.
Unable to create the synchronization service account for Azure Active Directory.
Unable to authenticate with Google Federation to Entra using on-premise AD account
I currently have it set to let the students/staff login with their Google accounts when accessing Microsoft services, these were created with Google (Microsoft 365 app is configured through SAML in Google Admin). This apps creates an account…
Roaming profiles: System Icons disappear when user change computer from Window 11 to Windows 10 (icons for clock, network, battery)
Hello, I have troubles in company with 200 computers. We have mixed operation system Windows 10 and Windows 11. We are using Active directory with roaming profiles. A problem occurs when user logoff from Windows 11 and then log to Windows 10…
SuccessFactors to Active Directory user provisioning service, wrong employment profile synced to AD
Hi, When using SAP SuccessFactors to Active Directory User Provisioning model, for some users who has concurrent employments, we get the wrong profile synced to ActiveDirectory (not primary employment). For example, if we have a user who had…
Unable to activate the Microsoft Entra ID P1 for the Group creation.
Dear Team, I am unable to activate the Microsoft Entra ID P1 for the Group creation in the Enterprises application. Could you please assist on this. How to activate the Microsoft Entra ID P1 How to create a Group in the App Registration for the…
How to deny Active directory Default Domain user to disjoin/join computers from AD?
Hello there, I was working on Active directory and there were more than 1 domain admins. i just found out that domain user account which is just created without any kind of group is able to join and disjoin computers to AD. I have removed any GPO that we…
Connecting to Active Directory from Java Using Native JGSS
How can a connection to an Active Directory server be established from Java code using the native JGSS implementation (i.e., without JAAS)?
Proxy exceptions maximum character limit gpp
Is there a maximum character limit when deploying proxy exceptions via group policy preference? The clients are windows 10. I think there was a character limit when used IEAK in the past but I am not sure if there is one now. Thanks a lot for the help.
Configuring the Microsoft Edge browser for the Profile autologin with current user login name?
I need help automating the Microsoft Edge Browser auto login using the Group Policy with Edge Administrative Template. The problem in every login in all of the servers and Windows desktop using the Edge Browser: This is the GPO I configured so far: I…
How can i correct a script that is not working in powershell and wpf displaying a active directory treeview
I don't want to load everything at the same time but when i click on a node display inside objects only permitting to not freeze the load , as almost is done in dsa.msc on active directory. Code copy below: this script was given by chatgpt and i…
Azure Active Directory /Entra SSO login throughout all registered apps
I am currently working on a React project for my organization where I need to implement single sign on to get the users email and name. The app is registered under the same subgroup in which all the employees belong to. There are currently multiple apps…
remotely join to the domain
Hi All, I am connected to a VM, let's say 192.168.10.10 (srv01.contoso.com), and I am trying to join a remote VM (192.168.10.52) to the domain from this VM. 192.168.10.52 is a new Azure VM that has been created. My requirement is to join this newly…
External OIDC Connection SSO in Entra External ID and custom user flow
Hi there, We are currently using B2C with custom policies. Our sign in page, takes in user's email address and based on the email domain, it tries to authenticate with external tenant, if no configured external tenant matches, it asks the user to enter…
New device cannot be added to domain, option is grayed out
We recently received some new laptops with windows 11 and I cannot add them to the active directory. Member of "domain" is grayed out. And only shows "work group". I will need them added to the directory to pass out to…
How to sync Mobile number field from Windows AD to Entra ID?
I need to take the contents of the "Mobile" field within Windows AD user records, i.e: https://imgur.com/a/7FGR9ap ...and synchronise this across to the "Mobile phone" field within the corresponding user record in Azure Entra ID…