active directory
1033 TopicsTwo-tier AD Certificate Services error importing cert into SubCA
Hello, I'm new here, but excited about being able to hob nob with all you in furthering our IT goals. I'm setting up my root and Subordinate CA and I'm importing my rootCA issued, subCA certificate into the subCA. I get I get the same error when the subCA automatically exports its cert req to the root Ca and when I do it manually. I also get this error whether i'm using X.509 or p7b files. what's unusual about this error is that it seems to be referencing a .req file with a '(1)' added to the end of the title. Original .req did not have the '(1)'. any assistance I can get from the community would be appreciated.88Views0likes1CommentIssue with Temporary Profile on Windows Server 2025 after renaming built-in Administrator account
Hi everyone, I am facing an issue with a temporary profile on Windows Server. Environment details: ・OS: Windows Server 2025 Datacenter ・Setup: On-premises environment with 2 servers (AD DS Domain Controller and Web Server) ・Affected Server: Web Server (Domain joined) Recently, I renamed the built-in Administrator account on the Web Server. After that, the system became completely unresponsive, so I had to force a power off. Upon signing in after the reboot, I received the error message: "We can't sign in to your account" (or "You've been signed in with a temporary profile"). It seems the profile folder or registry mapping for the renamed Administrator account was corrupted due to the force shutdown. I tried restarting the server, but the issue persists. Could anyone please advise on the proper way to resolve this registry/profile conflict and safely restore the renamed Administrator profile? Please note that I am a native Japanese speaker and a beginner in IT, so I may not fully understand complex technical English. Simple, step-by-step instructions would be greatly appreciated! Thank you in advance for your help! Translated by Gemini, grammar checked by DeepL256Views2likes7CommentsCan't share a folder on a local network in Microsoft Windows Server 2025 STD
We have two Microsoft Windows Server 2025 Standard (Version 24H2, Build Number 26100.32995) servers in our Active Directory. We can't share folders; it constantly asks for a username and password. We've tried every solution, but nothing worked. I found a similar thread, but the solutions there didn't work either. topic : https://learn.microsoft.com/en-us/answers/questions/5559013/opening-fire-share-on-2025-server-from-another-202 How can i solve this sharing problem ?139Views0likes3CommentsRemoval of old CA server stale data
Hi, I'm rebuilding some DC's and figured I'd tidy everything up before doing so as I've come into this with a messy environment. from this, I found an old Trusted Root CA, the certificate authority server was decommissioned in 2021 and all certificates have had an expiry date from 2021. its still being pushed out to domain devices such as servers and desktops. I tried running the 'certutil -dsdelca' command however this comes back with invalid command. I guess the best option is just to remove the class objects from the ADSI edit? as there is a class in AIA, CDP, Certification Authorities, KRA with the certificate nameSolved213Views0likes1CommentHow to check RDP access to the server
Hello, I have a virtual machine running Windows Server 2019 Datacenter with Active Directory, and all users access it via RDP. No specific access configurations have been set up; I wanted to know if it is possible to check how many times a specific user has connected and from which IP address—is that possible? Also, I wanted to ask if it is possible to determine whether a specific user copied files to their local PC using copy/paste during a session. Thank you234Views0likes2CommentsLooking for an on-prem MFA solution for Active Directory and RDP
Hi everyone, We're reviewing options for adding MFA to our on-premises Active Directory environment. Most of our users authenticate with Active Directory, while administrators also use RDP for managing Windows servers. Because part of our infrastructure is isolated from the Internet, we'd prefer an on-premises MFA solution instead of relying on a cloud-only service. Has anyone implemented something similar recently? I'm interested in hearing: Which solution did you choose? How difficult was the deployment? Did you run into any compatibility or performance issues? Is there anything you'd do differently if you were deploying it again? Any real-world experience or recommendations would be greatly appreciated. Thanks!280Views1like6CommentsCan the built-in "No account? Create one" link redirect to a custom sign-up page?
I'm using Microsoft Entra External ID with a built-in sign-in/sign-up user flow. On the Microsoft-hosted sign-in page, the "No account? Create one" link always redirects users to the default Entra sign-up page. I already have a custom registration page and would like this built-in link to redirect to my custom URL instead. Is there any supported way to customize the destination of this link in a built-in user flow? If not, could someone confirm whether this behavior is fixed by design? Thanks!145Views0likes2CommentsUsing Cloud sync to sync AD to existing Entra Accounts
I want to sync in premise AD accounts with existing Entra accounts. The email on both accounts is the same, and I added the Entra/o365 suffix to the domain and set the UPN to that suffix, making both UPN(s) the same. It did not sync. It created a NEW Entra account. I thought I covered all my bases. How can I get on premise AD and existing Entra accounts to sync? thank youSolved230Views0likes5CommentsServer 2016 Windows Update disabled?
I have Windows 2016 and 2019 Servers. All in in the same OU and getting the same Group Policy. This is confirmed via gpresult. I am using GP to disable Automatic Updates. This looks to be working in 2019: But with Server 2016, it says this: Should I expect these servers to update?971Views0likes6Comments