Rollback plan for DFL & FFL upgrade from Windows server 2003
I need to upgrade my AD DFL and FFL from Windows server 2003 to 2008R2. As the functional level downgrade is available to server 2008 only. Hence, I would like to know is there any way that I could downgrade it back to 2003 or any recovery plan if…
0x12 KDC_ERR_CLIENT_REVOKED ERROR
Kerberos Error Message received: Login session: DOMAIN.LOCAL\USERNAME$ Client Time: server time: 1:52:25.0000 3/4/2022 Z Error Code: 0x12 KDC_ERR_CLIENT_REVOKED Extended Error: 0xc0000234 KLIN(0) Server Zone: DOMAIN Server…
Adding new domain with different suffix.
I have been searching for solutions but couldn't find. If anyone could help with my current scenario? Example, I have an existing domain forest name contoso.com. Due to organisation requirement, I would like to add a domain with different suffix…
Can you assign AD groups to a Azure Resource Group?
I am trying to explore the possibility of using Azure Resource groups for RBAC. So my question is can AD groups be applied to an Azure Resource Group? Example we have JobTitle1. JobTitle1 needs access to AD Groups x, y, and z. Could I create a Resource…
Curl fails to connect to proxy server with NTLM auth when called from a protected process
Hi folks, We have a protected service which needs to connect to our backend servers through a proxy server which supports only one method of authentication - NTLM. We use CURL to make the connection but inside CURL, the API…
Create a local user admin account on each computer in domain based on the name of domain user account
Hi, I want to create a local user admin account on each computer in domain client Computers based on the name of domain user account as per requirements given below 1) Set password for “localuser” as “password” 2) Make “user” the member of local…
Migrating Acitve Directory, DNS and DHCP from Windows 2012 to Windows 219 while keeping the same hostaname and IP addresses
Hi, Currently I have 3 DCs, (DC1 and DC2 with DNS and Domain controller roles installed, DC3 with DNS, Domain Controller and DHCP) running on windows server 2012, and I want to migrate them to Windows Server 2019, the requirements are keeping the…
Unable to join domain. My Active Directory Domain Name is same as the company web domain.
When I try to join my local domain which has same name as Website the system responds as An Active Directory Domain Controller (AD DC) for the domain "domain name" could not be contacted. pinging domain name returns public IP address of the…
Merge two accounts in AD with one account in azure AD
Hi, I would like to know how can you merge the attributes of 2 accounts on two different domains in AD onpremises with one account in azure AD. Actually there are few accounts in our enviroment that works like that, but we don't know how to do that…
Restrict Outlook and Onedrive only to authorized devices
Hello I would like to ask something to know if it is possible to do or not. As an Office 365 security measure, we want to deploy a policy which restrict the use of onedrive and outlook only in the corporative computers. There are some externals…
Best practices to protect account with high privilege
Hi, What's the best practice to secure domain account with high privilege ?
Active Directory Replication Problems ERROR >60 days 4 / 10 40 (8606) Insufficient attributes were given to create an object.
I have 3 domain controllers, single site. dc1, dc2, dc3. dc1 and dc2 are in the same VLAN x.x.130.22, x.x.130.23 dc3 in a different VLAN x.x.140.20 dc1 is set to replicate with dc2 and dc3 automatticaly generated dc2 is set to replicate with dc1…
How to establish a connection with domain controller virtual machine
Scenario: How to establish a connection with domain controller virtual machine (Customer On-premises tenant) for performing active directory operations such as add/modify/delete AD user from the web application (Management tenant). Pre-Conditions: …
AD users were unable to login with the message password is incorrect
Environment: • Main site has 3 Domain Controllers (2 – Read-Write DC and 1 Read-Only DC) • 30+ remote locations, each have 1 read-only domain controller • DR site with one (1) Read-Write Domain Controller • All sites are connected via SD-WAN …
Active Directory Domain Services Stops after 10-15 minutes.
A client is using 2012R2 DC, all the fsmo roles are installed in the same one. Everytime the customer start the DC the ADDS service stops working after 10-15 minutes. Customer has 5 DCs including one 2008R2. All the DCs having same issue. I have…
Windows Server 2022 - Instal license CAL and RDS - Host or Virtual Machine with AD
Hello, Like in the topic, I would find out, what is best practice in Windows Server to install licenses RDS and CAL. For this moment I have a host (physical server) with Windows Server Core + Hyper-V on board. On hyper-V I have Virtual Machine with…
What all ports required for AD replication between DCs
What are all ports required for AD replication between DCs.
Newbie questions about Azure AD and AADConect
Hi, Newbie here, forgive me if I screw up the terminology. We have a Windows 2008 R2 domain, slowly migrating to Windows 2016. We are going to migrate our email from on-premise Exchange 2010 to O365 in the cloud soon (I hope). As part of that,…
advice azure sync AD for future hybrid exchage implementation
Hi guys, i need an advice. I must configure a AD connector to use some local AD user with teams and later also with exchange online (but not now). i have an exchange 2016 installation So, the first question. When i configure the AD Connector is…
(User Config) Set action to take when logon hours expire - Troubleshooting - Do no work on prodution enviromment.
Hi, I can not do this policy work in production. The same policy in a lab environment work normally. We can see the policy applied in rsop and directed in regisctry HKCU. Is there another troubleshooting tool? Or even another variable that I…