I have a few of my sites with a trust relationship among two different forests with a single domain in each AD forest.
I'll skip all the politics and details that don't matter and just ask the question:
Will having a machine with a computer account in one domain and their user account in another cause any issues?
(besides GPO behavior that would…
Will be putting a new Windows 2008 SE Server into a single domain network with two domain controllers, both running Windows 2000 Server. The functional level of the domain is mixed mode/2000.
Until a second 2008 DC can be purchased, I'd like to leave the current Win2k operational master DC as a backup DC as the other member servers running 2003…
I'm not well-versed in AD, so would like to resolve a question I have with regards to AD information.
I understand that it is possible to apply group policy to OU's, thereby restricting access. What I'd like to know is, is it possible to do the same with OU attributes.
Some context would help. There's a requirement to store address…
Our old Small Business Server 2003 (acting as our domain controller) was on the fritz, so we replaced it with a new Windows Server 2008 box and set the server up as our new domain controller. In hindsight, it may have been a mistake, but we set up the new server as a replacement and tried to keep as much the same as possible, including…
How can I reset local CRL (in OS local cash) in Windows OS (XP, Windows 7) manual? We need to reset local CRL because otherwise the OS will use local CRL until "next update" period.
As described in "Manually publish the CRL":
Clients that have a cached copy of the previously-published CRL or delta CRL will continue using it until…
I'm trying to deploy a custom Windows Service (written in C#; installed through a VS setup project) using a group policy. To help debug this, I also have two additional MSIs in the same policy. All three packages are deployed as a machine policy, not a user one.
On one machine (runs Windows Server 2008; no UAC), all three deploy…
I'm in the process of setting up a VM environment for a MS certification exam (70-462). Following the training kit's instructions, I've set up a domain controller (DC) and two members (SQL-A, SQL-B) thus far. I can't figure out why I can't join the domain.
DC
IPv4 Address . . . : 10.10.10.10(Preferred)
Subnet Mask. . . . :…
We are contemplating moving our SBS2k8 server to our datacenter. We would be setting up a VPN-VPN tunnel between everything to handle AD. Has anyone done this before? Any particular issues that anyone can remember?
So the flow for AD would now become.
SBS<-VPN---VPN<-Internal office network
Assume there's this folder structure:
D:\ --+-- Acctg --+-- Payable
| +-- Receivable
|
+-- Fin --+-- Inv
| +-- Tax
| +-- Treas
|
+-- Mrktg --+-- Ads
+-- Promo
Users are not allowed to change the structure, but they are free to create…
It's not uncommon to see entries in Windows ACLs (NTFS files/folders, registry, AD objects, etc.) with the name "Account Unknown (SID)". Obviously these are because of old AD users or groups which at some point had permissions manually configured on the relevant object and have since been deleted.
Does anyone know if it…
My company is currently trying to migrate a Windows Small Business Server 2003 to Windows Server 2012. We know the general procedure, but we want to make sure we aren't going to mess anything up tremendously. Here's the steps we were planning on taking:
1. Uninstall exchange
2. Remove legacy GPO's
3. Demote the domain…
Is it possible to create domain accounts that can only be accessed via a domain administrator or similar access?
The goal is to create domain users that have certain network access based on their task but these users are only meant for automated jobs. As such, they don't need passwords and a domain admin can always…
After reading Valve's new employee handbook, I was really interested in setting up a company map like they described on page 6:
"The fact that everyone is always moving around within the company makes people hard to find. That’s why we have http://user — check it out. We know where you are based on where your…
Currently i'm working with ADFS to establish a federated trust between two separated domains. My question is simple: does ADFS v. 2.0 support transitive trust across federated identity providers? I know that ADFS v 1.0 does not, as stated in this document on page 9.
But when looking on the claims rules that come…
Given a resource limited setup consisting of 2 host machines (HyperV-01 and HyperV-02), is it OK to put the domain controllers in parent partition, instead of their own VM?
The main reason is that if the DCs go into a child partition, starting from cold on both machines could lead to a bit of an issue, as…
I want to create an account that will perform the following:
Join computers to a domain (not restricted to 10, like a normal user)
Check for computer accounts in AD
Delete computers from AD
Move computers between OUs
I don't want to allow it to do anything else, so don't want a domain admin account.
…
I have a customer with two point of sale systems, a few workstations and a Windows 2003 SBS Server.
The point of sale systems are typically running QuickBooks Point of Sale and are logged in with a user who has restricted permissions / access (via Group Policy). Occasionally, one of the managers needs…
So we have some folders which are shared over the AD Domain (Windows Server 2003). It was just noticed that in 2 of those folders (which contain only Excel and Word files), whenever a file is opened and closed, the temp file which was opened corresponding to that file still remains. Apparently, this's…
when I am trying to seize the role from my child domain server the naming master I get the following error
fsmo maintenance: seize naming master
Attempting safe transfer of domain naming FSMO before seizure.
ldap_modify_sW error 0x34(52 (Unavailable).
Ldap extended error message is 000020AF: SvcErr:…
Hi Guys,
arrived to work this morning just to find that I couldn't log on to my computer.
As it turned out my computer had been "unjoined" from our domain.
I am positive that I didn't "unjoin" manually yesterday before I closed the computer down.
Have anyone experienced this behavior before and is it…
Very odd problem...
I have a Dell Latitude D830 with XP Pro that has been running on my local domain for many years. I recently Installed Windows 7 Enterprise on the D830 using a brand new HDD so that I could still use XP if I needed by just swapping out the HDD's. I added the W7 installed system…
Need Help on the following questions.
When a users login (on a computer in the network) is validated against AD what is/are the authentication method used?
When a users login is validated in Windows NT environment (not AD) what is/are the authentication method used?
If all user's account is on AD,…
I have a small office network with router (running OpenWRT), Windows Domain Controller (used to be 2008R2; I just backed it up and upgraded to 2012), about a dozen AD clients (3 server and windows workstation) and several non-AD clients (network printer, PBX).
The problem is that the clients can't…
I have a server running on windows server 2008. Recently we created a domain and added it to the domain. A domain user account was created with same username and password as my previous local administrator account. Now I unable to login using my local account. I tried loggin in using…