7,073 questions with Windows for business | Windows Client for IT Pros | Directory services | Active Directory tags

Sort by: Updated
1 answer One of the answers was accepted by the question author.

Active Directory: MachineAccountQuota 0 vs SeMachineAccountPrivilege and per-user computer account limits

Working on remediating "Non-privileged users can add computer accounts to the domain." Current default: ms-DS-MachineAccountQuota (MAQ) = 10 SeMachineAccountPrivilege granted to Authenticated Users Requirement: one service-account group…

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
asked 2026-10-01T04:44:20.7666667+00:00
Vishal Kumar 125 Reputation points
accepted 2026-10-01T11:34:02.8466667+00:00
Vishal Kumar 125 Reputation points
3 answers

I got this option: save your secret key to Azure AD

when i wanna enable bitlocker on disk D,After i set unlock password, the next step shows: How do you want to save your secret key ? There are some options below. save your key on Azure AD(A) save your key on U disk(U) save your key in File(F) print…

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
asked 2026-09-04T08:13:32.7766667+00:00
jacky lau 0 Reputation points
answered 2026-09-29T05:31:53.1766667+00:00
Jason Nguyen Tran 27,210 Reputation points Independent Advisor
1 answer

Unable to create gMSA with DNSHostName error PermissionDenied, UnauthorizedAccessException

I have a new install of Windows Server 2019 on a VMware VM. There are two domain controllers, DC-01 and DC-02. I'm trying to create gMSA to start SQL Server services. I run the command: Add-KDSRootKey -EffectiveTime ((get-date).addhours(-10)) This works…

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Server | User experience | Other
asked 2021-12-20T15:50:19.517+00:00
Jack Turner 16 Reputation points
answered 2026-09-25T18:47:27.2366667+00:00
Leonardo Bazterrica 0 Reputation points
1 answer

how to open active directory on windows 11 home

hello, i wanted to shut down my kids ipad i cant close it beacause i need active directory can you please help me

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
asked 2026-09-22T13:03:32.29+00:00
Machecosafaii Lovebestfriend 0 Reputation points
answered 2026-09-22T14:10:49.5966667+00:00
Tracy Le 13,210 Reputation points Independent Advisor
2 answers

Managed Chrome browser failing to install required security extension via GPO

I need to resolve an issue with managed Google Chrome browsers across our Windows workstations following a recent Group Policy rollout. It says the enterprise policy fails to automatically push and install the required corporate security extension,…

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
asked 2026-09-18T17:50:38.27+00:00
Sarah Williams 40 Reputation points
answered 2026-09-18T19:06:15.5666667+00:00
Tracy Le 13,210 Reputation points Independent Advisor
1 answer One of the answers was accepted by the question author.

Windows Hello for Business for local domain user MFA.

I need to implement MFA for users logging into Windows workstations in a traditional on-prem Active Directory environment. The main issue is IT support. Sometimes I need to sign in as the user's domain account to troubleshoot their workstation, but if…

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
asked 2026-09-12T06:01:09.34+00:00
Tina D 40 Reputation points
accepted 2026-09-13T10:02:30.6066667+00:00
Tina D 40 Reputation points
1 answer

event.code 4771 and 4768 status 0x6

Hello! I’m trying to understand the difference between events 4768 and 4771 with status 0x6. I’ve tried various ways on test environments to trigger event 4771 with status 0x6, but I always get event 4768 with status 0x6 instead. I don't understand why…

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
asked 2026-09-10T13:39:21.1933333+00:00
Machado Darin 0 Reputation points
answered 2026-09-10T14:15:30.5666667+00:00
Harry Phan 33,720 Reputation points Independent Advisor
2 answers One of the answers was accepted by the question author.

Is there any impact on users (maybe user profile, apps, etc) if I configure the laptops to be Entra Hybrid Joined.

Currently my org has the Laptops on the AD. And on EntraID, those laptops show up as Entra Registered. The users are already synced to EntraID from the AD but the devices are not and I'm planning to sync them to EntraID. I wanted to understand if…

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
asked 2026-09-07T11:55:10.1433333+00:00
0x1 20 Reputation points
commented 2026-09-08T08:53:33.5666667+00:00
0x1 20 Reputation points
4 answers One of the answers was accepted by the question author.

Disable Win 11 factory reset (GPO/MDM)

I want to create a GPO & a MDM ( Hybrid environment) policy to disable users from performing factory reset to their Win11 PCs/Laptops. (Something like denying access to C:\Windows\system32\systemreset.exe = Which I cannot find on Win 11) Also, it…

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Client for IT Pros | User experience | Other
Microsoft Security | Intune | Other
asked 2024-11-26T17:22:17.37+00:00
lmgmcg 130 Reputation points
commented 2026-09-07T10:55:19.1733333+00:00
JuliaMarvin 23,010 Reputation points Volunteer Moderator
1 answer One of the answers was accepted by the question author.

Entra Connect Password Writeback Fails Due to RPC Filtering

Cloud password resets fail to sync back to on-prem AD. How can we restrict RPC ports for AD Sync without breaking password writeback?

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
asked 2026-09-01T02:20:56.99+00:00
Ahmad Ibrahim 60 Reputation points
accepted 2026-09-05T05:59:38.88+00:00
Ahmad Ibrahim 60 Reputation points
5 answers

Renamed a DC now can't login.

I was adding a new 2022 DC to our domain. Everything went fine but after it was added I noticed the name had a spelling mistake so I used the GUI to change this new DC's name and reset the DC(I now know I should have used netdom). Now I can't login to…

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Server | User experience | Other
asked 2021-12-18T19:55:53.79+00:00
LukeDin 11 Reputation points
commented 2026-09-01T12:48:26.42+00:00
Sergi Riofrio 0 Reputation points
1 answer

Need help recovering an orphaned AD child domain before Tech Refresh – missing Forest-level FSMO roles and Enterprise Admins

Hi Microsoft Community, I need advice on an Active Directory environment that appears to have been left in an incomplete state after the original parent/forest-root domain was decommissioned. Current environment For example, the original AD structure…

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
asked 2026-08-31T09:20:45.77+00:00
Nicholas How (Malifax SG) 0 Reputation points
answered 2026-08-31T16:33:02.9966667+00:00
Allan Solomon Mejia 10,225 Reputation points
1 answer

August 2026 CU breaks/fixes secure channel trust with Credential Manager enabled

It seems that a constant fail/repair occurs in netlogon.log where Windows 11 patched servers on August 2026 have issues and report NETLOGON 5419 errors in the system event log. This does not happen if CM is disabled. example: 08/24 10:40:54 [SESSION]…

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
asked 2026-08-25T14:20:16.2166667+00:00
Rich Siegel 0 Reputation points
answered 2026-08-25T21:52:11.6233333+00:00
Allan Solomon Mejia 10,225 Reputation points
4 answers One of the answers was accepted by the question author.

How to switch from Private to Domain network - Windows server 2019 RODC

I have created a windows server 2019 RODC, it is working fine. But, it automatically goes to "Private Network". I have other windows server 2012 R2 RODC, they are in "Domain Network". I read some article to restart "Network…

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Server | User experience | Other
asked 2021-03-19T07:13:32.267+00:00
Mohd Arif 301 Reputation points
answered 2026-08-23T20:29:05.77+00:00
Josh B 0 Reputation points
1 answer

How to get a hold of Microsoft technicians to help with Domain Controller issue?

We have some questions about some logs that we are seeing on our domain controllers and Microsoft has made it impossible to get a hold of a live technician. The Engage Center says that we cannot purchase services for the issues that we are experiencing…

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
asked 2026-08-19T22:14:33.54+00:00
Admin Justin 0 Reputation points
answered 2026-08-20T01:16:13.2666667+00:00
Hoang Le 6,275 Reputation points Independent Advisor
2 answers

Forest trust SID filtering vs SID history — are these the same setting or two different things?

Hello, Working through an AD security finding in an isolated lab and want a sanity check on my understanding before I take this to a client. The finding: "Domain trust to a third-party domain without quarantine" (ANSSI…

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
asked 2026-08-18T09:26:48.41+00:00
Vishal Kumar 125 Reputation points
answered 2026-08-18T12:10:40.9266667+00:00
Marcin Policht 109.8K Reputation points MVP Volunteer Moderator
1 answer

msExchHideFromAddressLists isn't in AD and I can't add it but need to remove people from GAL

We have some users who are no longer with the organization, but we can't remove them from EAC - getting "Couldn't update mailbox ‎global address list‎ info". Please help.

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
asked 2026-08-14T16:02:35.59+00:00
Nick 0 Reputation points
answered 2026-08-14T20:20:37.8166667+00:00
Allan Solomon Mejia 10,225 Reputation points
2 answers One of the answers was accepted by the question author.

How to enforce Edge Browser to stop using Personal and only allows Work account to sync?

Would it be possible to enforce and only allow the Microsoft Edge browser to log in and open as a Work Account instead of as a Personal account? My corporate workstation has been configured as Hybrid Azure AD Joined and managed by Intune, so I wonder if…

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Microsoft Security | Intune | Configuration
Microsoft Security | Intune | Grouping
Microsoft Security | Intune | Other
Microsoft Edge | Microsoft Edge development
asked 2024-09-16T04:40:37.32+00:00
EnterpriseArchitect 6,416 Reputation points
commented 2026-08-14T11:51:19.7766667+00:00
Jean-Seb 25 Reputation points
2 answers One of the answers was accepted by the question author.

access ro remote computer via computer management

In microsoft domain what requirements to connect remote computer via computer management ? My client is Window 11 and I use AD account which belongs to local administrators group of remote computer (Windows 10) When I open computer management to explore…

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
asked 2026-08-11T14:48:35.75+00:00
MidNight Sender 66 Reputation points
accepted 2026-08-13T19:30:33.3833333+00:00
MidNight Sender 66 Reputation points
2 answers

Microsoft NTLM Retirement.

Microsoft is retiring NTLM (New Technology LAN Manager), a legacy authentication protocol that has been part of Windows environments for more than 30 years. By when Microsoft is going to stop or deprecate completely, is there any deadline for…

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
asked 2026-08-11T08:58:29.17+00:00
Patra, Anil 0 Reputation points
answered 2026-08-12T07:39:07.48+00:00
Brian Huynh 3,815 Reputation points Microsoft External Staff