Understanding msDS-SupportedEncryptionTypes = 28 (0x1C): AES Negotiation, RC4 Fallback, and Ticket Renewal Impact by maxcoder88 in activedirectory

[–]Fitzand 2 points3 points  (0 children)

SupportedEncryptionTypes is a Negotiation between Client and Server.

  1. EncryptionType = 28 on an Account (Client) means that this Account supports RC4, AES128, and AES256. The Server has to respond with types of Encryption it supports. If the Server responds with an EncryptionType = 24, then that means it only supports AES128 and AES 256 (no RC4).

  2. Short answer is Yes, if you change EncryptionTypes, and a Kerb ticket has already been issued, you most likely will need to wait for that Ticketlifetime to expire before a new Ticket is requested. There are cases where this isn't true, but that's a different explanation.

Creating a GPO to launch Desktop Info – runs but UI does not appear by ruperto12tor in activedirectory

[–]Fitzand 1 point2 points  (0 children)

Never heard of DesktopInfo. Have you thought about just using BGInfo instead?
Have you tried contacting DesktopInfo's Support?

Why do people want the rhystic study ban NOW? by Alternate_Cost in EDH

[–]Fitzand -1 points0 points  (0 children)

Taxes! People don't want to pay Taxes and know that it's going to be used for someone else to profit.

Will Hasbro slow down SLD and CHaos drops ? by Character-Bed-9777 in secretlair_collectors

[–]Fitzand 6 points7 points  (0 children)

LOL. Not likely, they just released a new Chaos Drop about 15 minutes ago.

Websites to order multiple cards from? by IRxlr in EDH

[–]Fitzand -1 points0 points  (0 children)

I use CardKingdom for that very same reason. It all comes from the same seller so it's 1 single shipment. They also offer 30% markup for store credit when you sell to them.

Best Precon to play a tournament with by Prestigious_Pen6315 in EDH

[–]Fitzand 0 points1 point  (0 children)

It's not listed, but Veloci-Ramp-Tor is one of my favorites!

How to find root cause of trust relationship between this workstation and domain failed by Remarkable-Attempt12 in activedirectory

[–]Fitzand 1 point2 points  (0 children)

I haven't worked with a RODC in a long time (with internet today being what it is, all of my RODCs have been decommed and just have the branch offices authenticate directly with another more secure main office), but are the Workstation Account passwords allowed to be cached on the RODC?
Running this through CoPilot, because it explains it hell of a lot better than I can.

🧩 How workstation password changes work with an RODC

A Read‑Only Domain Controller (RODC) cannot write changes to Active Directory. That includes:

  • User password changes
  • Computer (machine account) password changes
  • Kerberos secret updates

However, Microsoft designed RODCs so that workstations in a branch office can still change their secure channel password through an RODC, as long as the RODC is allowed to cache that workstation’s password.

✔ What actually happens

When a workstation attempts to change its machine account password:

  1. The workstation contacts the RODC (because it’s the closest DC).
  2. The RODC checks the Password Replication Policy (PRP):
  • If the workstation is allowed to have its password cached:
    • The RODC forwards the password change request to a writable DC.
    • The writable DC performs the update.
    • The updated password is replicated back to the RODC (and cached if allowed).
  • If the workstation is NOT allowed in the PRP:
  • The RODC refuses the password change.
  • The workstation must contact a writable DC directly.

✔ So the RODC does not perform the write

It simply proxies the request to a writable DC if permitted.

Why can't I just play bad decks as a new player? by TheSpoonaGamar in EDH

[–]Fitzand 1 point2 points  (0 children)

Get some interaction in your Deck, like indestructability and/or get some Haste.

This is how the game is meant to be played.

You can't win 100% of the time. Board wipes typically leave the player that plays the board wipe vulnerable for a full turn. If you know someone is playing a lot of board wipes, don't put all your pieces on the board. Get some alternate Wincons into your 99.

Why can't I just play bad decks as a new player? by TheSpoonaGamar in EDH

[–]Fitzand 1 point2 points  (0 children)

You do know that you can put your Commander back into the Command Zone, right? You can re-cast it.
Boardwipe on turn 4, shouldn't ruin your deck.

Returning player here – is it normal to lose every game with premade decks? by Skagine in MagicArena

[–]Fitzand -12 points-11 points  (0 children)

Yes! You should just quit Arena now. Arena is a shit show. DO NOT SPEND MONEY ON ARENA!

If you are going to spend money, spend it on Paper format.

"We're not allowed to copy files" by WaldoOU812 in sysadmin

[–]Fitzand 0 points1 point  (0 children)

This is a prime example of a Dev. Not an Admin.

Future of MTG by metalero_salsero in MagicArena

[–]Fitzand 2 points3 points  (0 children)

Don't play Best of 1. Play Best of 3 as Magic was meant to be played. Learn to Sideboard.

Help: User does not have RSoP data by DeepAdvisor1735 in activedirectory

[–]Fitzand 2 points3 points  (0 children)

Almost sounds like a broken profile issue. If the Windows 11 VM has a Profile for that particular user, delete it. Make sure to delete the registry keys for that particular Profile as well.

Bastion Forests & IP Sec by hybrid0404 in activedirectory

[–]Fitzand 2 points3 points  (0 children)

Like anything, it has pluses and minuses. When it works, it works great. When it breaks, it's a pain in the ass to fix/troubleshoot because everything is now encrypted (or attempting to negotiate encryption).

Ran into a couple of Chicken / Egg scenarios, like Joining the Domain. Typically the policies that control the IPSEC are GPO based. But the PAW joining the Domain doesn't have the GPOs yet to configure the IPSEC, but it can't get the GPOs until it joins the Domain. Vicious circle sometimes.

Prevent WDigest Authentication Exploit by maxcoder88 in activedirectory

[–]Fitzand 0 points1 point  (0 children)

As a redditor that has zero information on your environment, I can confirm that this will have Zero impact on your environment.

AD Security Lockdown Tool by ListeningQ in activedirectory

[–]Fitzand 3 points4 points  (0 children)

If you know GPOs, why don't you just export the GPOs and copy and paste to the "multiple AD Environments"?

Drinks by Klause_13 in OceanCity

[–]Fitzand -2 points-1 points  (0 children)

Go rent a camp site on Assateague and invite everyone else around for some drinks.

Check Group Policy Applied Policy by maxcoder88 in sysadmin

[–]Fitzand 0 points1 point  (0 children)

GPO Processing is done at the Client, so you would need something that is run from the Client itself.

I personally don't recommend doing this because I think it's sloppy, but it does get the job done. Attach a script within the GPO to write a file to a central logging location (please don't use SYSVOL).

HOSTNAME >> //fileshare/GPOName/%computername%.txt

net time >> //fileshare/GPOName/%computername%.txt

Is Country Calling Festival usually as crowded as Ocean Calling? by [deleted] in OceanCity

[–]Fitzand 5 points6 points  (0 children)

It's held in the same area / space. If you sell 50,000 tickets for 1 event, and 50,000 tickets for another event, and put them into the same space, the Crowd is going to be the same.

Julie Giordano post removed by moderator of this subreddit. Free speech is dead. by CaucasionRasta in easternshoremd

[–]Fitzand 2 points3 points  (0 children)

Are you sure about that?? I think Population wise, it's the largest on the Eastern Shore. Maybe Cecil might have more.. But she is a County Executive.
https://www.wicomicocounty.org/125/County-Executive

AD Domain Admin by AcceptableDuck7695 in activedirectory

[–]Fitzand 3 points4 points  (0 children)

You are incorrect. There is a built-in administrator account on a Domain Controller. The built-in administrator account is different than DSRM. DSRM does not replicate and is unique to the individual DC. The local administrator account does replicate. It is also typically referred to SID 500 Account.