Microsoft Q&A
Active Directory
3,594 questions
A set of directory-based technologies included in Windows Server.
Content
export users
Hi All i have samaccount names in the below format in the csv file. some of the users are disabled. i want to import this csv file and pull only enabled samaccount account users . i want the output with samaccountname,displayname,UserPrincipalName.…


Changed Default Domain Policy Password not taking effect
We changed the Default Password Policy for the maximum password age. We have some users where the change is not taking effect. Even after the change, they are getting prompted to change their password as its set to expire. We ran GPO update and it was…


Migrate Active directory
I have a server. This server has a 2008r2 functional level of the foresta.I Need insert new 2022 server as domani controller.Is It possible?How can I do It?


AD Auditing
Dear Community, I want to know that who is setting the "Password Never Expire option" for users in our Domain. We have 5 AD Admins(two global and three with limited rights) We have a Policy of Password to expire every one Month. …


I cannot control Print Servers on Active directory
Hello, Environment: I have a domain server which contains Active Directory, and I want to add another server to this active directory and the purpose of adding that server is for print management. I can add the server but I cannot control the printers on…


DCGIAD DNS Test Fail for all Child Domains except of one!
hey Guys, Sorry, I am no native speaker for english! I have a very misterious problem! I have a forest domain, Parent and 8 Child Domains. We had some DNS issues caused by missconfigured VPN Tunnel between sites, that was solved in one day, DNS recoverd,…
Windows 11 deployment via MECM
Dear all, We are planning to rollout w11 22h2 along with w10 22h2 in our organisation due some business requirement. I would like to clarify on couple of things: WADK: In my sccm enviroment If I update the ADK to the latest 10.1.22621.1, will it also W10…
sspi handshake failed with error code 0x80090304 on SQL server after updating DC
Dears , we have problem that started after we installed windows updates on our DCs in the environment , now when we are trying to connect remotely to sql database server we got the below errors kindly note that authentication works fine…


Outlook 2019 - Exchange 2016 On Premises - Non-Domain Login
Just purchased a new laptop that I was not planning on joining to our domain for a remote employee. Purchased 2019 Office and tried to connect Outlook to our on-premises Exchange Server 2016. Anyway, entered his information to get outlook setup, and…


azure ad connect installation
Ideally, Azure AD Connect should be installed on a dedicated domain-joined server, but you can also install it on your domain controller. If I want to sync two different forests then my question is which forest's domain-joined server should be used to…


How to Add Edge's "PrintPreviewStickySettings" policy into Active Directory?
I found that Edge's printing is not working after it updated to Ver. 109.0.1518.55, because the PC was under Active Directory, Then I got an answer says that might cause of "PrintPreviewStickySettings" policy, I wonder how should I confirm…


Child domain controller unable to enroll for certificate in parent domain
I set up a quick lab with a couple of Windows Server 2022 hosts. The first host was promoted to a domain controller (dc-0.example.com) and a domain certificate authority was installed. That domain controller automatically enrolled itself for a…


DNS query overload followed by Site/Domain performance degraded
We have two AD sites, each with two DC's running DNS. During business hours, we frequently get SCOM alerts that indicate DNS Query Overload at each/both sites, followed by AD Site Performance Degraded, then AD Domain Performance Degraded alerts. These…
How to pull a list of all groups I do not have permission to modify in Active Directory?
I am a newer desktop admin trying to determine what groups I don't have permission to modify in Active Directory so I can send a list to get permission to access them. Is there a script I can run in PowerShell or a way otherwise to pull a list of such? I…


Active Directory password expiration notification.
Hello, We have many users who complain about not getting AD passwords expiration notification pop up on their PC, and they have to call the help desk to get their password resettled. Further troubleshooting indicates that some of the users don't log off…


Windows Server 2003 share fails to authenticate after install cumulative update 11-2022 on DCs
Hi Everyone, I had a issue on my environment after install cumulative update November 2022 on my Domain Controllers. Clients running any version of Windows had a issue when try access network share or any resource use Kerberos when the server is…


Device write back Azure AD
A side question to enabling Device write back in AD Sync. Prior to enabling Azure AD listed 5000 stale devices, after enabling it still shows 5000 stale devices. I can confirm the count from on prem AD is less than 1000. What is the expectation on time…


Migrating On Prem to Azure, Azure AD replacing On Prem Ad?
We are in the process of migrating our resources from On Prem to Azure, We have migrated over our severs to Azure, and also setup an Azure based DC and made that DC the master of all 5 roles. On prem, we have two DCs. Currently we have the local lan…


"The directory service is unavailable" when modifying sAMAccountName with Windows 11 22H2
Hello On my Windows 22H2 machine, I am unable to modify the sAMAccountName attribute on any account : I get "the directory service is unavailable" error. This only happens on the sAMAccountName attribute. All other attributes are working…

