Forum Widgets
Latest Discussions
- Deploying Multiple NPS ServersI have been working on ditching our password-based WiFi with WPA2-Enterprise. On DC1 I deployed internal CA, NPS, and group policies that auto-request certs and deploy wireless network settings. Cisco AP is pointed to DC1 as the radius server. NPS has been registered in AD and wireless network policy has been created. Test laptops get their cert and connect just fine. It's working. For redundancy, I installed NPS on DC2. This NPS instance has also been registered in AD, and I imported the NPS config from DC1 to DC2 NPS. Cisco AP has DC1 as first radius server and DC2 as second radius server. If I stop NPS on DC1 to force the Cisco AP to authenticate against DC2, test laptops won't authenticate and connect. What am I missing? They're configured exactly the same (except DC1 hosts the CA...I was under the assumption the CA is AD integrated).44Views0likes1Comment
- Demoting DC Windows Server 2019Windows Server 2019 with Domain controller forest version 2016. When demoting our Domain controller XYDC01 in Site XY, it is the only DC and DNS in the site, but all other 20 sites have a DC with DNS. We get this error when demoting our DC. Active Directory domain controller appears to be the last DNS server for the following Active Directory-integrated zones: enterpriseregistration.jens.be If you demote this domain controller, you may be unable to resolve any DNS names in these zones. If you wish to proceed, specify the 'IgnoreLastDNSServerForZone' option. I have tested: #other DC and DNS server in other site Resolve-DnsName enterpriseregistration.jens.be -Server XXDC02 Test-NetConnection XXDC02-Port 135 Test-NetConnection XXDC02-Port 53 Get-DnsServerZone -Name "enterpriseregistration.jens.be" repadmin /syncall /AdeP All test have passed and succesfull. Replication scope = Forest Other DCs have DNS role Zone contains NS records for other DCs Zone exists on other DCs But still having the same issue when trying to demotejensstevensOct 31, 2025Copper Contributor35Views0likes3Comments
- Advice for replacing a Windows 2012R2 file serverWe have a small company network that includes one Windows Server 2012R2 file server necessary to run Sequel for two server hosted business applications, file and print services for the user accounts and is also the Domain Controller for the Active Directory local forest and domain. Six Windows 11 Pro workstations are domain attached to the file server. The workstations all have a local user account and after domain attaching to the file server, a user.Acme user account with Administrator rights to their local computer. Each has its own 192.168.1.x static address and uses their domain user account with mapped drives to access the fileserver. The existing file server name is ACMEWS2012R2, local public static ip 192.168.1.12, DNS Domain Acme.LAN, Netbios name ACME, local accounts are located in \Users\username, and runs SQL Server Express 2012 with default MSSQL database name and mixed security using the SA with password credentials. The new file server will be using Windows Server 2022 (the company apps are not yet certified for 2025) and SQL SVR Express 2022 and I am looking for information about what configuration decisions I can make to hopefully minimize the need to install new user accounts on the workstations, copy all the user folders between users accounts and reinstall applications. My understanding of Domain security is limited, knowing just enough to get workstations attached and properly accessing the file server SQL based applications. My Google results have provided some piecemeal answers, but I would like to better understand the big picture before starting the server upgrade and make some irreversible configuration choices that would cause unnecessary work re-attaching the workstations. I would first ask for recommendations whether and why to keep or change each of the following: The file server machine name The file server 192.168.1.12 IP address The file server Administrator account and password. The Acme.LAN forest and root domain name that was defined after adding the Active Directory Domain Service role that also added File and Print Services and Group Policy Management. The SQL Server Express default MSSQL database name The SQL Server Express SA account name and password I would also ask about the best steps for disconnecting workstations from the old domain then joining the new domain to hopefully retain the existing workstation user account, or if not, to minimize the need to copy users folders between the user accounts and / or uninstall then reinstall the workstation applications to properly authenticate to the new user account. I would greatly appreciate some experienced insights for how to best accomplish these upgrade goals. Thanks, all!JeffreyKOct 30, 2025Copper Contributor3Views0likes0Comments
- Certificate authentication with SID not workingWhen trying to login to Windows (against AD) using a certificate with the SID extension present in the certificate, it will not work if the SAN UPN is missing in the certificate. The error message "Your credentials could not be verified" will be displayed. Changing the certificate template to include SAN UPN will make the login work as expected. Is it by design?SolvedJan LiikamaaOct 30, 2025Copper Contributor77Views0likes2Comments
- Not able to update the parameter "UserRightsGenerateSecurityAudits" for OSConfigDesiredConfigurationHello, I want to add my AD group as part of "UserRightsGenerateSecurityAudits" in order to be able to collect audit logs but when I run the command, the change is not applied (Processed 0 out of 1 settings) : "Set-OSConfigDesiredConfiguration -Scenario SecurityBaseline/WS2025/MemberServer -Setting UserRightsGenerateSecurityAudits -Value @("*S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415","*S-1-5-20","*S-1-5-19","*S-1-5-21-2654652530-1219913000-911364509-1603") Warning : Cannot process the settings 'UserRightsGenerateSecurityAudits': 0x82d0000a. Verify the value and try again. Processed 0 out of 1 settings. Using GPO, I'm able to update the value, but OsConfig is overwriting it after some time after because the group is not part of defaut values allowed by OsConfig. Your assitance will be ready appreciated. ThanksQuadraOct 30, 2025Occasional Reader7Views0likes0Comments
- Allow “Edit/Save/Rename Without Delete” NTFS PermissionProblem Description: I manage shared folders using NTFS permissions. I want users to edit, save, and rename files without being able to delete them. Currently, if “Delete” and “Delete subfolders and files” are unchecked, users cannot delete, but they also cannot save or rename files because most applications temporarily delete/rename files during saving. If delete is allowed, users can save but also delete files. Request: Introduce an NTFS permission that allows file editing and renaming without granting delete rights, to prevent accidental data loss while maintaining normal file operations. Observation: This limitation is inherent in the current NTFS permission model. NTFS does not distinguish between: Intentional deletion by user File replacement/temporary deletion by application As a result, administrators cannot fully protect shared folder data while still allowing normal file editing workflows. Impact: Prevents enterprise administrators from enforcing safe file editing without risk of accidental deletion. Creates workarounds such as Shadow Copies or backups, but these do not prevent the deletion itself. Suggested Improvement: Introduce a new NTFS permission or enhanced behavior that allows: Edit, save, rename files without granting delete rights Deny manual deletion of files/folders by users Maintain compatibility with standard application save workflows Such a feature would significantly improve data protection in enterprise file shares, reduce accidental data loss, and simplify NTFS permission management.asadjawaid80Oct 30, 2025Copper Contributor34Views0likes1Comment
- Windows Server unable to install Cumulative update 21H2 for x64-based Systems (KB5066782)Hi All, Unable to install the above update. I tried things like sfc/scan, dism tool features but non works. all other updates install except the above. Tried running the update manually but failed. Think this is also breaking functionality of the virus /malware guard. ACS (azure Code signing). The last option that I am thinking of is to run a sever repair with the installation media. I also tried windows trouble-shooter for updates. Any ideas ? This is installed as a virtual machine on Hyper-V. Don't want to rebuild the server. Looking for a solution. The Error code is 0x80073701shehan31Oct 30, 2025Copper Contributor406Views1like2Comments
- windows 2019 KB5066586 & KB5070883 both have error 0x800f0985Stuck and need suggestions, I have tried SFC & DISM recovery commands, Resetting the Windows Update subsystem Manually downloading the patches Trying to patch though power shell get-windwosupdatelog doesn't provide any insight. cbs.log & dism.log don't provide any insight Tried to update the Servicing Stack Update (SSU) for Windows Server with KB070883 that came out on Oct 23 2025, but it won't install either I get 0x800f0985. Suggestions other than in Place upgrade?184Views0likes1Comment
- Unable to manage DFS namespace(updated post) Hi, We have an issue with DFS at our site. It has been working fine for years, but recently the ability to manage it using the DFS MMC no longer works. DFS is still working for the users fine and we can map to it manually, but the MMC tool no longer connects. We can create and manage new namespaces fine though. The error is: " The namespace cannot be queried. The specified domain either does not exist or could not be contacted. " We can't risk recreating the namespace due to the impact on users, so anyone have any idea to fix this and get DFS MMC working to allow management of the namespace? Many thanks DB59Views0likes1Comment
- How to Reset Windows Server 2008 R2 Administrator Password?I am struggling to reset the administrator password on my Windows Server 2008 R2 machine. Unfortunately, I do not remember the password and cannot access the system. I have tried use a password reset disk or access the built-in administrator account, but have been unsuccessful thus far. I am worried about losing access to critical files and applications as a result of being unable to log in. Therefore, I am seeking advice and guidance on the most effective and secure way to reset administrator password for Windows Server 2008 R2. I am hoping that other forum members who have encountered similar issues in the past can share their experiences and offer tips and solutions. Thanks.FendiStaveOct 30, 2025Brass Contributor14KViews0likes7Comments
Resources
Tags
- windows server2,218 Topics
- Active Directory830 Topics
- management386 Topics
- Hyper-V333 Topics
- networking321 Topics
- security291 Topics
- storage213 Topics
- clustering152 Topics
- powershell147 Topics
- AMA102 Topics