active directory
1043 TopicsADFS migration issue from 2016 OS to 2025 OS.
We have an ADFS 2016 farm (10.0.14393.6078, Farm Behavior Level 3) using a gMSA service account. We are trying to add an ADFS 2025 node (10.0.26100.33158) using Add-AdfsFarmNode. HTTP SPNs are correctly registered and visible in Active Directory, yet Add-AdfsFarmNode fails with "There were no SPNs set on the service account". Is direct Windows Server 2025 federation server expansion into a Windows Server 2016 ADFS farm supported, and are there known issues with gMSA-based farms?42Views0likes2CommentsClarification Regarding msDFSR-Options After Authoritative SYSVOL Synchronization
Hello, I had a SYSVOL synchronization issue between my domain controllers, so I had to perform an authoritative synchronization of DFSR-replicated SYSVOL. The procedure starts by setting msDFSR-Options=1 on the healthy domain controller. However, after completing the procedure and returning the other DFSR-related values on all domain controllers to their default settings, I could not find any clear information about whether msDFSR-Options should also be returned to its default value. Could you please clarify the following points? Should msDFSR-Options=1 remain configured on DC01 after the authoritative synchronization has been successfully completed, or should the attribute be returned to its default/not-set value? Does keeping msDFSR-Options=1 mean that DC01 will remain the authoritative/source domain controller for future SYSVOL replication? If we later migrate our domain controllers to new servers running Windows Server 2022 or Windows Server 2025, do we need to configure msDFSR-Options=1 on one of the new domain controllers? Or is msDFSR-Options=1 only required temporarily when performing an authoritative SYSVOL synchronization? Thank you in advance for your clarification.Solved98Views0likes5CommentsForce a specific default lock screen and logon image
Dear, I currently have a DC deployed on Windows Server 2019. i want to configure a specific default image on lock screens on Windows 10 pro clients via group policy. Is this possible or is it only compatible with Enterprise or Education editions? Thanks in advance,2.2KViews0likes3CommentsCómo delegar la administración de DNS y DHCP en Windows Server 2025 sin dar permisos de Domain Admin
Hola a todos. Soy estudiante de un ciclo de informática y estoy montando un laboratorio con Windows Server 2025 (Standard con entorno gráfico) como controlador de dominio con los roles de DNS y DHCP instalados. Quiero que un segundo usuario pueda gestionar las zonas DNS y los ámbitos DHCP, pero sin que forme parte del grupo Domain Admins. He visto los grupos integrados DNSAdmins y Administradores de DHCP, pero he leído que DNSAdmins puede suponer un riesgo de escalada de privilegios. ¿Cuál es la forma recomendada de hacerlo aplicando el principio de mínimo privilegio? ¿Delegar permisos sobre la zona, usar una unidad organizativa aparte u otra opción?66Views0likes0Comments¿Cómo podemos mejorar la seguridad de un servidor Windows Server 2025?
Hola, tengo una duda sobre la seguridad en Windows Server 2025. ¿Qué medidas recomendáis para proteger un servidor frente a accesos no autorizados? Por ejemplo, ¿es suficiente con configurar el Firewall de Windows y utilizar políticas de contraseñas, o sería recomendable añadir otras medidas como MFA, auditorías y políticas de grupo (GPO)?132Views0likes1CommentHA Print Service Windows 2025 Server
There are two servers running Windows Server, both with the Print Spooler service enabled. They share the same printer queues. I created a CNAME alias named "printcore" pointing to Server01; the client can successfully connect to the printer using the UNC path `\\printcore\hpprincipal`, but if I change the alias to point to Server02, the client's connection to the printer fails. I enabled the Service Principal Name (SPN), but that didn't solve the issue. I need help setting up a High Availability (HA) environment for the print service. Alias: `printcore` (pointing to Server01 and Server02)173Views0likes1CommentKerberos Event ID 4771 (0x18) across multiple users while interactive logons succeed
Users are able to perform interactive/manual logons successfully with their current credentials. The failures are also generated outside normal working hours. The Client Address in the 4771 events corresponds to the workstation/IP of the respective user. We have observed many different Client Addresses (at least 15 different source IPs), so the failures are not originating from a single host. As an initial troubleshooting step, we executed: klist purge for one affected user. The Kerberos ticket cache was cleared successfully, but the Event ID 4771 failures continued afterward with no noticeable change. Previous guidance suggested checking for stale/stored credentials, scheduled tasks, Windows services, Credential Manager entries, mapped resources, proxy authentication, or background applications that might be attempting authentication with outdated credentials. Another recommendation was to use Sysmon on an affected workstation and correlate outbound Kerberos traffic on port 88 with the timestamp of the 4771 event in order to identify the process or executable generating the request. Before making changes or deploying additional monitoring software in the client's environment, we would like to determine the safest and most appropriate troubleshooting approach. Given that: interactive logons work normally; 0x18 failures occur for many users; each user's Client Address generally corresponds to their own workstation; the issue occurs across many different workstations; and clearing the Kerberos ticket cache did not change the behavior, what would be the recommended Microsoft troubleshooting method to identify the exact process, service, application, or stored credential generating these failed Kerberos pre-authentication requests? Thank you.76Views0likes0CommentsActive Directory Schema Attributes vs Version
Hi all, i'm searching documentations about the attributes used in active directory schema based on its version. My versions range is from "Windows 2008 R2" (v47) to "Windows 2019" (v88). The target of my search is a document/wiki that i can use to check if an attribute exist in my versions range, or, if the usage change in some versions, to prevent exception when a software try to access to it. At the moment, i find only this wiki: https://docs.microsoft.com/en-us/windows/win32/adschema/attributes-all Here i can find all attributes vs schema version and the related information (data type, name, access, etc), but seems not cover the newer schema versions. For example, if i want to check the attribute "department", i can go to the detailed description: https://docs.microsoft.com/en-us/windows/win32/adschema/a-department an see the implementation in older versions (typically the newer is windows server 2012). Exist a list that include newer versions (from windows server 2012 r2 to 2019)? Thanks for any info Stefano1.7KViews0likes1CommentHow to Backup Active Directory (recovery when have Ransomware)
Currently we only backup system state root and child, is this backup method enough (We want can restore Active Directory in case all server have Ransomware from backup )? wbadmin start systemstatebackup -backuptarget:<targetDrive>: please anyone help here465Views0likes1Comment