Translate between Certificate Template Permissions and ActiveDirectoryRights enum
I'm trying to generate a report containing details about all certificate templates published in my forest. One of the things I want to show in the report is what principals have Read, Write and Enroll permissions on each template. In order to do…
GP preferences for IE settings - ie 9,10,11 missing
In Windows 2008 R2 SP1 (datacenter ed.) I downloaded latest administrative templates (https://www.microsoft.com/en-us/download/101445) may 2020 and I extracted and replaced the only inetres.admx/adml to my centrale store. Nevertheless in Group Policy…
AGPM "The directory is not empty" when using import from production option.
Hi All, Its not like a queue but the solution which I want to share with everyone. We had an issue where a single GPO reporting the error message when trying to import from production on AGPM console on a OS 2012 R2. As same mentioned in below link. …
change hostname of standalone servers remotely
Hi, In my Windows Network, I have a computer acting as lightweight standalone server. It has a small lightweight App running under Windows 7 x64. App is licensed and has specific requirements so Operating System etc. can't be upgraded. I need to change…
How can configure "Account Operator Rights" to cannot User Account in Domain Admin Group ?
How can configure "Account Operator Rights" to cannot User Account in Domain Admin Group ?
Missing CN=DFSR-LocalSettings on a Domain Controller?
Hi Experts, This new DC has replication issues with the PDC and its not replicating Sysvol and Netlogon shares. Then we found this article on how we could fix it by performing an Authoritative DFSR Sync. However, as we follow the guide, we bump into…
FRS to DFSR migration issue
Hi All, I have migrate the FRS to DFSR migration in test.com domain. under test.com 2 child domain. My question is again need to follow the migration steps in child domain also ? test.com asia.test.com us.test.com Regards, Yogesh
What is the use of service account.
Hi, What is the use of services account.
The DNS server has encountered a critical error from the Active Directory. Client cannot authenticated.
Hello, I have four DCs, one of them in personal site. Client in same site could not authenticate in AD because server is not available if I reboot one of DC from other site, for example DC01 On primary DC for this clients (for example DC03), I…
Output results of Remove-ADComputer
I need to remove a list of computers from Active Directory. I also need the results to be output to a log or text file. The remove command works and a file is generated, but the generated file is empty. I am using the following command: …
Error when trying to promote DC (the specified network name is no longer available)
We just deployed a new VM in a different site to act as an RODC. But the issue is when we try to promote to DC, we get the following error; The wizard cannot access the list of domains in the forest. the error is: The specified network…
Replication issues after ungraceful DC restore/restore from backup
Hi, I had a major issue with one of my domain controllers where it could not be gracefully demoted and had to be restored from backup. I know this is a no no but there was no other option at the time. Unfortunately I went back too far, 1 month to be…
Powershell Script to Retrieve AD User, Group, Group Members Info
Good morning and Hi to all! I am a newbie to Powershell scripting and have a task on hand but unable to get the results I needed and hope I can get some help here. There are many Groups in AD, but I need to focus only on 2 distinct Groups namely…
List extended permissions on AD
Hello I'm searching for a way to list the permissions and extended permissions on my active directory root. I've tried with the get-acl command and some others, but I’m not able to get it. Is it the correct way?
KERBEROS refresh clients
Good morning, in our infrastructure have all clients windows 10, and 2 DC 2019 Server (FFL 2012 R2), when change (add or remove) users from groups, all client, need to reset manually kerberos token with cmd (klist purge –li 0x3e7). It's the only metod.…
Bind some servers to a specific DC
Hi, I need to bind some of my members servers to always use a specific DC for AD Authentication. How it can be done? Thanks.
Problem with NTP Server PDC
I am the administrator of an Active Directory that consists of 4 domain controllers. 3 of them are Windows 2012 R2, and one Windows 2008 R2. Our Palo Alto firewall is ntp time syncronized against the PDC domain controller, one of the Windows 2012 R2.…
Account Lockout Due to failed attempts
Hi, My Domain Account was suddenly locked out. How can I find out from which pc someone tried to log in to my account before it got locked out? Thanks.
Domain Bound to a single DC
Hi, By mistake, I ran klist add_bind CONTOSO.COM KDC.CONTOSO.COM. Does this mean the whole domain is bound to a single DC? If yes then how can i remove it immediately. I just need to bind some servers to use a specific DC. Thanks for quick replies.
How to connect or test ldap server connection in windows through command prompt or Powershell cmdlet without GUI
In our company infrastructure we have an ldap directory service hosted. Currently I'm using Ldap tool to connect to ldap directory service to search for the records. Now I have a task to modify few attributes for several users. Manually its taking…