How to fix error 0x801c03f2 when enrolling device into Entra ID
I have made a new Entra ID and a new resource so that i can enrol a few devices in my household so i can control them. I have made a user and a password and put Device registration in Entra ID to ALL but whenever i try to enrol the device i get hit with…
Azure / Domain Controller problem
I have a strange problem and need help Case: Domain Controller DC with Windows 2012R Domain Controller DC1 with Windows 2022 They are both in the same domain. When I turn off DC and only use DC1, users who connect via a VPN connection cannot…
DISABLING UNUSED AD ACCOUNTS
A script that used to work last year throws an error on -Identity I am trying to disable accounts that have no longer been used in over 180 days and move them to a separate OU #Disable ad user not logged in 180 days #define Ou domain…
Renaming a server
How to revert a server name back to its original. Account already exits is the message received every time I tried. it is a Windows 2003 server and the DC is a 2012 Rs server. I see the 2003 server listed in the servers folder (AD users and computers). I…
API-driven inbound provisioning to on-premises AD - Unable to assign Manager
API-driven inbound provisioning to on-premises AD - Unable to assign Manager We have configured API-driven inbound provisioning to the on-premises Active Directory (AD), and it is functioning as expected. However, we have identified an issue: whenever a…
Understanding question, password hash synchronization, entra audit log
We manage multiple M365 tenants, all of which are similarly structured. There is a local AD domain that is synchronized with the AAD via Azure AD-Connect (passwordhash-sync and password-writeback are enabled). When a user changes their password, the…
Powershell script export users have unlimited membership
Hello, Is it possible to create powershell script of exporting users that have unlimited membership excluding groups like Domain users etc? Right now I am using this script for temporary group assignment but since I started using this just recently I…
User changed last name. their profile on a different site that syncs with our AAD still shows old Info
I have a user that got married a few years ago. it looks like the admin at the time updated the information to the new name and new email on that original AD profile. They made the new email the primary and the old email the alias. There are still some…
I would like to block the URL /owa/auth/logon.aspx from IIS
Dear All. If any url matches hhtps://abc.com/owa/auth/logon.aspx it has to be blocked How do I do ti I tried multiple steps on IIS but no luck
Enrollment fails error 0x801c03f2
Today i made a new Entra ID with a personal account and just made a resource... i am trying to locally manage a few devices i got in my household such as putting software installation limitation etc. So i made the user i want along with their user and…
Unable login to my Azure directory
Hey My company has provided me an azure account. I also had enabled visual studio subscription, and had transferred to another directory(my directory). Previous, I used to SSO to my directory from my company email id. But 2 months ago, SSo to my…
Querying and Setting Computer Account Attributes Without LDAP
Hi, I am looking for a way to query and set specific computer account attributes in Active Directory without using the LDAP protocol. Currently, I am using the DRSUAPI protocol to set the servicePrincipalName property. However, I couldn't find an…
ADB2C | Signing a user out
Hi I have an azure b2c tenant made via custom policy. Assume I have logged in on two browsers : 1 on chrome and other on firefox. Now I want to change my username using the b2c custom policy.. I do it .. and now I want to kill all sessions.. so basically…
How to lower ActiveDirectory functional levels
Hello! I run 2 AD servers with Windows Server 2016 ,and have a forest composed of these 2 servers. The domain and forest functional levels are 2012 now, and I want to rise them to 2016. Just in case,I made backups of ver.2012 and then increased the…
Configure a domain controller to be isolated
I want to validate what I think I need to do. Here is the situation. Company is selling a location that has an onprem Domain Controller, this domain controller has no schema roles assigned to it. It is the DHCP and DNS server locally as well. The…
Issue with Entra Connect wizard setup and MFA requirements/conditional access
Hi all, Our company is moving from an on-prem AD to a hybrid AAD setup and we want to utilize intune to manage a few policies. The issue I am having is with the initial Entra connect setup, the installation wizard fails each time with this error. and…
"User must change password at next logon" only works on the user's SECOND log on attempt
I have a fairly mundane network with AD servers (six in total in three locations) all running Windows Server 2022 Standard updated with the latest patches, etc. The network clients are majoritively Windows 11, with some still on Windows 10. The…
Migrating from Onprem to Azure AD as a Service
I am looking to move our onprem AD environment to Azure AD as A Service and be 100% in the cloud. I know there are a number of factors to look at like file shares, printers, Apps etc.. but I have not finding any guides on the best way to move from onprem…
How to Check if Migration from MFA and SSPR was Sucessful
My Migration shows complete but MFA is still showing with one users, How can I Test that the Migration was completed sccessfully,
Successfactors to active directory user provisioning
I have an issue with the integration Successfactors to active directory user provisioning. The attribute personalIdExternal is mapped with employeeId and set to match AD objects using this attribute. However, even I clear the employeeId attribute, the…