1,923 questions with Windows for business | Windows Server | Devices and deployment | Configure application groups tags
How to capture audit log for the following packet filters DR-F0401-032, DR-F0401-036, DR-F0401-037 and DR-F0401-117?
How to capture audit log for the following packet filters DR-F0401-032, DR-F0401-036, DR-F0401-037 and DR-F0401-117?
Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups

How to identify strong and weak ciphers?
Hi All, We have a doubt on how to identify the strong and weak ciphers from below: TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (0xc030) TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 (0xc028) TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (0xc013) Can anyone help me…
Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups

SMB Signing not required vulnerability
This regarding below fixes where I need difference between the two fixes and clarifications: As per the below article, Once I updated Microsoft network server: Digitally sign communications (always). value as Enabled the vulnerability is not seen in…
Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups

Event ID's 5829-31 Not Visible in Domain Controller logs after August 2020 Patches
Hello, we have applied the August 2020 patches on our Domain Controllers but do not see any logs with Event ID 5829-5831 since the updates. There is at least one Server 2003 machine (i.e. out of support OS) on our domain which I assume is still using…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Server | User experience | PowerShell
Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups
Windows for business | Windows Client for IT Pros | User experience | Other

Exporting GPO setting on Member Servers using Secedit not Working
OS Windows server 2012 R2 Datacenter I want to be able to export some Software Restriction Policies from the Local Security Policy. I am trying this on member server machines. The command I am trying to run is: In powershell run as …
Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups
Windows for business | Windows Client for IT Pros | User experience | Other

Struggle with Winows event log collectors
Hi Log collectors or SIEM tools are useful because the native Windows Event Viewer is slow, can search a limited number of logs only (around 4GB = 24h Security Log on DC), does not work across systems and cannot perform analysis or send alerts. …
Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups

start a script at session start
Hi everyone, I must start a script at start the session not desktop not other programs. I have tried has create user on activity directory and in the tab "Environment" I have set to the path of script. but in my laboratory it works.…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups

SMB Signing not required vulnerability
Hi All, We are seeing SMB Signing not required vulnerability in our domain joined servers, but this vulnerability is not reported in our ADDS server. could you please let me know why vulnerability is not appeared in ADDS but appearing in domain joined…
Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups

Windows CA WebEnrollement certificate problems
We are using a Windows Server 2012 R2 as Windows CA for our Windows 10 environment. Certificates are getting automatically enrolled through GPO which is great, unless you get Mac devices in your environment. To get them the required User and Machine…
Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups

Deny acces rights for members in group are not enforced
Hello, I'm using Windows 2016 standard server that is joined in a domain. The domain admins are placed in the local administrators group, but I don't want the domain admins to be able to write or change data on the D-drive of the server. I've set the…
Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups

Certificates export?
Hello, I was trying to export our certificates but apparently for several of them I am limited as an export of the certificates without its key which make them useless. Anyway to get the key? The certificate request was generated on this…
Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups

NTFS permission
Hi I'm trying to assign permission for users in a specific group where they will be able to see folder and file names without being able to open them. I'v used list folder content but this doesn't show file names. Thanks
Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups

Network Audit logging
I have enabled the advanced audit policy configuration in windows server 2016 and wanted to capture the below network related events: Packet filter matches, DR-F0401-032, DR-F0401-036, DR-F0401-037 and DR-F0401-117. System scan for open ports and…
Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups

How to generate program Inventory logs in event viewer
Hello, Good morning, Have tried to generate the program Inventory but no luck.
Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups

AD CS: Deploying Cross-forest Certificate Enrollment
With reference to the article https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/ff955845(v=ws.10) can somebody please clarify if I already have a Enterprise CA in an Account Forest can I establish a 'Cross…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups

GPO - restrics access to disk c:\ for users. Allow access for domain administratos to network \\pcname\c$
What is the proper way to restrict access to system disk to users? But at the same time: Allow the operation system, especially drivers, and already installed software work properly. Allow domain administrators to have access to user's system…
Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups

Defender Report
Hi All, Need some advice on below I have deployed Defender Antivirus Policy from Group policy to Servers and Few Windows 10 machines. Where can i see the anti virus definition update status for all clients? Just to check if all are getting…
Windows for business | Windows Client for IT Pros | Devices and deployment | Configure application groups
Windows for business | Windows Server | Devices and deployment | Configure application groups
Windows for business | Windows Client for IT Pros | User experience | Other
Using gMSA for replacing the Task Scheduler service account?
What steps should I follow to change the current Task Scheduler service account from using the regular AD Account in the format of CORP\service.account to a gMSA? When I try to change it manually by double-clicking on the task, it prompts for the…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Client for IT Pros | Devices and deployment | Configure application groups
Windows for business | Windows Server | Devices and deployment | Configure application groups

laps installation on domain controller procedure
Hello, I had found an article on installing LAPS and went through installing on a domain controller. I setup a test OU and put a few pc's in it and only ran commands so that the one OU and pc's in it were managed as a test. I did install the full LAPS…
Windows for business | Windows Server | Devices and deployment | Configure application groups
What are the steps and procedure to use gMSA as the Windows Server Service Account?
After creating the gMSA using the below PowerShell, how can I successfully replace the services in all of my Windows Server Application servers? New-ADServiceAccount -Name New-gMSA -DNSHostName Mydomain.com -PrincipalsAllowedToRetrieveManagedPassword…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Server | User experience | PowerShell
Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups
