Impacts on CIFS server after November 2022 cumulative updates and CVE-2022-38023 on Active Directory
Hi all We need to understand what the impacts on CIFS server are after applying the November 2022 cumulative updates on AD…
SSPR Writeback Issue: "A call to SSPI failed" Error with CommunicationException
Hello Community, I am facing an issue with SSPR (Self-Service Password Reset) writeback functionality. The error log indicates a problem with the communication between the client and the server, stating they "do not possess a common algorithm."…
DC connection reset
Hi All, One of my Linux VMs is using the kinit command to connect to one of my Domain Controllers. The kinit command, I believe, sends Kerberos requests to the Domain Controller on port 88. Currently, port 88 is allowed between the Linux VM and the…
Domain netbios rename of empty root domain
We have a forest with an empty root domain and a child domain containing users, exchange,... We would like to change the netbios name of the root domain. Is it supported? As this domain doesn't have any service bound to it , I suppose that the answer…
Active Directory Replication Status Tool 1.1 Download page offers wrong file version
Hi, the 1.1 version of the Active Directory Replication Status Tool is supposed to be available here: https://www.microsoft.com/en-us/download/details.aspx?id=30005 However the adreplstatusInstaller.msi is actually version 1.0. So there is no way to…
Mobile Number not syncing in Hybrid AD
Hybrid AD setup and everything except for Mobile Number is syncing. In Microsoft Admin center the field for Mobile Number is editable, but it isn't saving changes and just says "Retry not possible" Any idea what is causing this?
Get Directory roles which assigned to users (Eligible or active both)
Hi, I am working on to collect details of directory roles which are assigned on user and get that details by powershell cli and mggraph api. I have "Get-MgUserTransitiveMemberOfAsDirectoryRole -UserId " but that is providing me only roles…
API-driven provisioning to on-premises Active Directory - Provisioning Failure
Hi. Hoping someone can help with this. I have a logic app that handles multiple user remediations, and one of those is to disable accounts. This works fine in a cloud only environment, however; I want to extend the disable account element to on-prem…
Error When Switching User Flow from User Sign-In to Vendor Sign-Up in Azure AD B2C
Hi Azure Team, I have implemented two separate user flows in Azure AD B2C for my application: User Sign-In (User Login Flow) Vendor Sign-Up (Vendor Registration Flow) When a user is already logged in through the User Sign-In flow and attempts to…
Have to remove/disable the firewall rules in GPO and gpupdate /force successfully without any error.
Hi Experts, We are creating firewall rules in GPO, and we are applying firewall rules from GPO to all the member servers. Now we wanted to remove all the firewall rules which we created from GPO. If you are removing the rules and trying to update the…
Question regarding Hybrid AD join in Entra Connect
Hi all, I am working on configuring Hybrid AD join for our company, and running through the Entra wizard for device configurations on one of our servers. For the initial Entra sync I had setup a test OU, and would like to add only a few computers as a…
Distribution list delegation not working, only for specific OU users
I have created a restriction for a distribution group for group-A, using powershell for group-B the group-B have two users user-A in OU-A and user-B in OU-B, restriction is only applying for user in OU-A, i even swap the users but still same OU-B user…
System shutdown and system logout based on idle time
Hi Team, We are implementing the ISO 27001 policy for Clear desk and clear screen as documented on below Clear desk policy according to ISO 27001 - What does it mean? The policy has three main points : lock the system log out the system shutdown the…
[Active Directory] Export group members to CSV with their emails
Hello, I work in a larger globally managed company. I need to export a list of users from a particular group to a CSV file. I am using a simple command in PowerShell: "Get-AdGroupMember -identity "group-name" | select name |…
How to renew/request a new certificate with same key if the active directory certificate is expired without impacting any services?
How to renew/request a new certificate with same key if the active directory certificate is expired without impacting any services?--
Date & Time Greyed out on Windows server 2022, even if I´m logged in as Domain Admin
I´ve just installed a Domain Controller, now I want to configure Time sync But It´s greyed out Im logged with an account that is both Enterprise Admin and Domain Admin. Login as local Administrator account (that account I used when created the DC) seems…
Collecting msDS-LastSuccessfulInteractiveLogonTime Without Displaying Logon Data
How can the msDS-LastSuccessfulInteractiveLogonTime attribute be collected without enabling the "Display information about previous logons during user logon" Group Policy? This attribute is important for gathering interactive logon times for…
Issues logging into Admin console
Our corpoate domain is synced with Microsoft 365 using ADFS. I am unable to login to Microsoft 365 using my corporate credentials. When I try logging in, I automatically get authenticated using domain.onmicrosoft.com credential and not domain.com…
how we can add aws ec2 instnace to Azure entra
Customer is having two environment one is on azure and another one aws. on Azure there is entra ID. on AWS customer has created the two ec2 instances. which he wanted to be authenticated using the Azure Entra ID . could you please help us what all things…
User principal name change in AD not syncing to Microsoft
We having users changing their last names but experiencing issues with sync from on-premise AD to microsoft. This post Why does the userPrincipalName not sync from AD to Azure AD like - Microsoft Community is basically what we are experiencing but…