7,073 questions with Windows for business | Windows Client for IT Pros | Directory services | Active Directory tags
Active Directory: MachineAccountQuota 0 vs SeMachineAccountPrivilege and per-user computer account limits
Working on remediating "Non-privileged users can add computer accounts to the domain." Current default: ms-DS-MachineAccountQuota (MAQ) = 10 SeMachineAccountPrivilege granted to Authenticated Users Requirement: one service-account group…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
I got this option: save your secret key to Azure AD
when i wanna enable bitlocker on disk D,After i set unlock password, the next step shows: How do you want to save your secret key ? There are some options below. save your key on Azure AD(A) save your key on U disk(U) save your key in File(F) print…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Unable to create gMSA with DNSHostName error PermissionDenied, UnauthorizedAccessException
I have a new install of Windows Server 2019 on a VMware VM. There are two domain controllers, DC-01 and DC-02. I'm trying to create gMSA to start SQL Server services. I run the command: Add-KDSRootKey -EffectiveTime ((get-date).addhours(-10)) This works…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Server | User experience | Other
how to open active directory on windows 11 home
hello, i wanted to shut down my kids ipad i cant close it beacause i need active directory can you please help me
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Managed Chrome browser failing to install required security extension via GPO
I need to resolve an issue with managed Google Chrome browsers across our Windows workstations following a recent Group Policy rollout. It says the enterprise policy fails to automatically push and install the required corporate security extension,…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows Hello for Business for local domain user MFA.
I need to implement MFA for users logging into Windows workstations in a traditional on-prem Active Directory environment. The main issue is IT support. Sometimes I need to sign in as the user's domain account to troubleshoot their workstation, but if…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
event.code 4771 and 4768 status 0x6
Hello! I’m trying to understand the difference between events 4768 and 4771 with status 0x6. I’ve tried various ways on test environments to trigger event 4771 with status 0x6, but I always get event 4768 with status 0x6 instead. I don't understand why…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Is there any impact on users (maybe user profile, apps, etc) if I configure the laptops to be Entra Hybrid Joined.
Currently my org has the Laptops on the AD. And on EntraID, those laptops show up as Entra Registered. The users are already synced to EntraID from the AD but the devices are not and I'm planning to sync them to EntraID. I wanted to understand if…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Disable Win 11 factory reset (GPO/MDM)
I want to create a GPO & a MDM ( Hybrid environment) policy to disable users from performing factory reset to their Win11 PCs/Laptops. (Something like denying access to C:\Windows\system32\systemreset.exe = Which I cannot find on Win 11) Also, it…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Client for IT Pros | User experience | Other
Microsoft Security | Intune | Other
Other Intune-related topics, including unsupported scenarios and platform-specific behaviors
Entra Connect Password Writeback Fails Due to RPC Filtering
Cloud password resets fail to sync back to on-prem AD. How can we restrict RPC ports for AD Sync without breaking password writeback?
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Renamed a DC now can't login.
I was adding a new 2022 DC to our domain. Everything went fine but after it was added I noticed the name had a spelling mistake so I used the GUI to change this new DC's name and reset the DC(I now know I should have used netdom). Now I can't login to…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Server | User experience | Other
Need help recovering an orphaned AD child domain before Tech Refresh – missing Forest-level FSMO roles and Enterprise Admins
Hi Microsoft Community, I need advice on an Active Directory environment that appears to have been left in an incomplete state after the original parent/forest-root domain was decommissioned. Current environment For example, the original AD structure…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
August 2026 CU breaks/fixes secure channel trust with Credential Manager enabled
It seems that a constant fail/repair occurs in netlogon.log where Windows 11 patched servers on August 2026 have issues and report NETLOGON 5419 errors in the system event log. This does not happen if CM is disabled. example: 08/24 10:40:54 [SESSION]…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
How to switch from Private to Domain network - Windows server 2019 RODC
I have created a windows server 2019 RODC, it is working fine. But, it automatically goes to "Private Network". I have other windows server 2012 R2 RODC, they are in "Domain Network". I read some article to restart "Network…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Server | User experience | Other
How to get a hold of Microsoft technicians to help with Domain Controller issue?
We have some questions about some logs that we are seeing on our domain controllers and Microsoft has made it impossible to get a hold of a live technician. The Engage Center says that we cannot purchase services for the issues that we are experiencing…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Forest trust SID filtering vs SID history — are these the same setting or two different things?
Hello, Working through an AD security finding in an isolated lab and want a sanity check on my understanding before I take this to a client. The finding: "Domain trust to a third-party domain without quarantine" (ANSSI…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
msExchHideFromAddressLists isn't in AD and I can't add it but need to remove people from GAL
We have some users who are no longer with the organization, but we can't remove them from EAC - getting "Couldn't update mailbox global address list info". Please help.
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
How to enforce Edge Browser to stop using Personal and only allows Work account to sync?
Would it be possible to enforce and only allow the Microsoft Edge browser to log in and open as a Work Account instead of as a Personal account? My corporate workstation has been configured as Hybrid Azure AD Joined and managed by Intune, so I wonder if…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Microsoft Security | Intune | Configuration
Setting up and managing device configurations using Intune
Microsoft Security | Intune | Grouping
Organizing devices and users into groups for policy application
Microsoft Security | Intune | Other
Other Intune-related topics, including unsupported scenarios and platform-specific behaviors
Microsoft Edge | Microsoft Edge development
Developing and testing features or extensions for Microsoft Edge
access ro remote computer via computer management
In microsoft domain what requirements to connect remote computer via computer management ? My client is Window 11 and I use AD account which belongs to local administrators group of remote computer (Windows 10) When I open computer management to explore…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Microsoft NTLM Retirement.
Microsoft is retiring NTLM (New Technology LAN Manager), a legacy authentication protocol that has been part of Windows environments for more than 30 years. By when Microsoft is going to stop or deprecate completely, is there any deadline for…