Questions tagged [domain-controller]

A domain controller is a server in a Microsoft Active Directory or NT4 domain that is responsible for central authentication.

In Microsoft Active Directory and NT4 domains, a domain controller is the central repository for all of the user account authorization information. It allows a person to sign on once and be allowed access to many different resources.

1589 questions
0
votes
1 answer

Kerberos: ticket with no REALM after principal name (i.e. `principal@`)

When I run a klist after ssh-ing into a Kerberized instance, I obtain the TGS for the principal host/vmtest001, however, why do I get two of them including one with no REALM after the @ separator? Here is the output of klist: Ticket cache:…
0
votes
2 answers

minimal percentage of domain controllers online

Good day, for a recovery test we restored one (out of 5) domain controller and the needed servers. however we found out that the domain controller (wich hold the PDC-Emulator) was functioning in a failsafe mode. the quick work around was to delete…
0
votes
1 answer

Administrator - A user account was locked out. But it wasn't?

I've enabled a lockout threshold on our domain now and my DC audit log is FILLED with 4740 "A user account was locked out" for the Domain Administrator account however it is NOT locked out and the Caller Computer Name is blank. Any ideas what's…
Killian
  • 37
  • 2
0
votes
3 answers

Exchange 2013 Hybrid EAC not seeing mailboxes in a second domain

We have a hybrid setup. I have a situation where certain users are not showing up on the local on-prem Exchange 2013 server under recipients. We have two domains in our single forest. I will call our primary domain abc.com and the second domain…
Scot
  • 303
  • 1
  • 2
  • 5
0
votes
1 answer

I cannot join machines to domains when primary DC fails, everything else works fine

So we have two domain controllers on our little network and they both have DHCP and DNS replication. Active Directory was set up with replication betweens these two. Information that is created on any of these three services is replicated flawlessly…
0
votes
1 answer

Remote Site Domain Controller Failure

We have a remote office with defined AD Site and local DC that has failed. Clients cannot authenticate. We have a private WAN to HQ but I'm unclear of change needed or impact. Do I just move the subnet to the HQ site? What will that do to the DC…
0
votes
0 answers

How to configure DFS Replication group in Active Directory

A newbie question here. I have two Windows 2008 R2 servers. DFS Management installed. When I go to "New Replication Group", and try to create a group in the domain, I get "Insufficient Permissions", which makes sense because I am not a member of the…
0
votes
1 answer

Can a single DC be demoted?

I'm running WSE 2016, which must be the only DC in the domain. According to the documentation, it is incompatible with a PDC/BDC construct. For some unknown reason, Windows Updates have been failing for some time now. I've been working with…
0
votes
2 answers

Remove Old Server2008 DC Offsite

we (still) have an outdated Domain with 3 Server 2008R2 DCs. One DC, which was from a remote (VPN) location, is now on my desk in main office. The goal is to demote and remove it from Domain. 2 will then remain. Since the network onsite is different…
David
  • 1
  • 1
0
votes
0 answers

Share DFS location and Change Name of DFS folders

I want to simplify file server access from displaying multiple drives to instead, share the DFS location that lists all of the shortcuts to the actual folders and files my users need access to. The reason being is we have MULTIPLE drives and it…
mrlljones
  • 53
  • 4
0
votes
1 answer

2x Windows Server for 2 labs in different parts of a building - what kind of failover to use

I have two servers and two labs in different parts of the building with Hyper-V 2019 with VMs for Windows Server Standard (2012 R2, will be upgrading in a few years). I want to: configure ServerA for Lab1 and ServerB for Lab2 (I don't need help…
0
votes
2 answers

Missing DNS records after fresh AD+DNS Server installation {Server 2019}

I've installed Win Server 2019 from an empty template I had of a fresh server. Installed Domain Services, promoted to Domain Controller, created an entirely new forest but then noticed I couldnt join nor add anymore DCs to it. Looking at the DNS…
JustAGuy
  • 639
  • 3
  • 23
  • 38
0
votes
0 answers

Promotion Windows Server 2019 to domain controller takes a week?

Setup first: I had a Windows Server 2008 domain for testing. The PDC died a horrible death, I was able to seize most FSMO roles (but not all) and drop them on another DC, but missed the RID Master role (if I recall correctly). The machine was shaky,…
0
votes
0 answers

SSL on Domain Contollers

Our internal and external domain is the same - domain.com, and for the internal users to be able to reach our website hosted externally, we installed IIS with redirection on all DCs. So when internal users type in http://example.com they are…
YGK
  • 1
0
votes
0 answers

Why does svchost.exe gradually consume more and more CPU on a Server 2016 Domain Controller?

We have a physical server that is running Windows Server 2016 and is acting as a domain controller. We are monitoring several services/parameters on this server via Nagios/Check MK and are noticing that Nagios is reporting svchost.exe is gradually…