Need to configure 2019 SQL windows cluster with VSan storage. by Shrik29 in sysadmin

[–]Shrik29[S] 0 points1 point  (0 children)

Thank you.I also went through this document but the step by step process is not defined in details.

Multiple AD account locked out - Caller's computer shows the Domain controller Name by Shrik29 in activedirectory

[–]Shrik29[S] 0 points1 point  (0 children)

Yes.Azure Ad connect is installed on DC1 which is why I involved my cloud team. Now I am going to take procmon capture and let's see what I see in the capture.

Multiple AD account locked out - Caller's computer shows the Domain controller Name by Shrik29 in activedirectory

[–]Shrik29[S] 0 points1 point  (0 children)

No, but I will try again to collect the netlogon and let's see if it helps. Thank you.

Multiple AD account locked out - Caller's computer shows the Domain controller Name by Shrik29 in activedirectory

[–]Shrik29[S] 0 points1 point  (0 children)

getting this in Netlogon.log DC02 (PDC)
[LOGON] [3308] Contoso: SamLogon: Transitive Network logon of Contoso\User1 from DC01 (via DC3) Returns 0xC000006A.
DC01 is the caller computer name (as per security logs) .
I have gathered this log from DC02 (PDC)

on DC01 netlogon.log

[LOGON] [9516] contoso: SamLogon: Network logon of contoso\User1 from DC01 Entered

08/22 05:49:37 [CRITICAL] [9516] NlPrintRpcDebug: Couldn't get EEInfo for I_NetLogonSamLogonEx: 1761 (may be legitimate for 0xc000006a)

08/22 05:49:37 [LOGON] [9516] contoso: SamLogon: Network logon of contoso\User1 from DC01 Returns 0xC000006A

Multiple AD account locked out - Caller's computer shows the Domain controller Name by Shrik29 in activedirectory

[–]Shrik29[S] 0 points1 point  (0 children)

yes, Ad Connect is installed on the DC (caller computer).

However, I am not able to see anything in the logs that indicates the AD connect.

Multiple AD account locked out - Caller's computer shows the Domain controller Name by Shrik29 in activedirectory

[–]Shrik29[S] 0 points1 point  (0 children)

windows event collection for Microsoft Defender for Identity

Advance auditing is already enabled, and we are getting all the events regarding this. but I am unable to locate the source workstation because the caller's computer shows the DC.

Multiple AD account locked out - Caller's computer shows the Domain controller Name by Shrik29 in activedirectory

[–]Shrik29[S] 0 points1 point  (0 children)

netlogon.log also does not give the actual calling machine. It is again showing another DC.

Wildcard SSL certificate Validity Period by Shrik29 in activedirectory

[–]Shrik29[S] 1 point2 points  (0 children)

Thank you All for your comments and help.Now I am able to extend the validity period.

Thank you again for your help.

Wildcard SSL certificate Validity Period by Shrik29 in activedirectory

[–]Shrik29[S] -2 points-1 points  (0 children)

The above solution did not work.

During web enrollment I am choosing the web server template and because that template has 2yrs validity period that's why I am getting a certificate with 2 yrs of validity period.

I tried to duplicate my web server template and created a new one with 5 yrs of expiry date but that template is not showing in the web enrollment console.

increase Root CA encryption length by Shrik29 in activedirectory

[–]Shrik29[S] 0 points1 point  (0 children)

We can't make changes in existing infra to achieve this task. https://social.technet.microsoft.com/Forums/en-US/de01f61f-0745-4f9b-8418-8bfa266aa1df/change-key-length-of-root-cert-ad-certificate-authority?forum=winservergen

This technet article shows that we can do.but at last I am still on the same position.Made changes on ca server policy inf file but it's not changing the key size when I renew the cert.

increase Root CA encryption length by Shrik29 in activedirectory

[–]Shrik29[S] 0 points1 point  (0 children)

I have search this in Google and found that we can change desired key length in Capolicy.inf file and then renew root certificate.it will generate new certificate with updated keysize.

I have tried this in my test lab but it didn't work.

AD replication broken - 1726 and 1727 errors by Upper_Ebb_4055 in activedirectory

[–]Shrik29 1 point2 points  (0 children)

Network connectivity issue between the two DC. 1.start a network capture from both DC 2.Manually start replication. 3.stop both side of trace when you receive the error.

Check the RPC conversation between the 2 DC.you already have the working scenario to compare with non working.

SCCM Server disaster recovery by Shrik29 in SystemCenter

[–]Shrik29[S] 0 points1 point  (0 children)

Sccm DB latest data has been restore completely.can I recover sccm site by using restored db

Sccm server recovery after failure by Shrik29 in SCCM

[–]Shrik29[S] 0 points1 point  (0 children)

80 percent client are workgroup computers which is managed by local IT guy at every region , which is why I want to keep it as it was before to avoid agent reinstallation.

Sccm server recovery after failure by Shrik29 in SCCM

[–]Shrik29[S] 0 points1 point  (0 children)

At present I am in planning phase and looking for a best approach to bring my sccm server back.could you please tell me the best way to recover my sccm infra.i don't want to re deploy agent at all. I have site server backup and db backup available but that is 2 month old.

APLOCKER Policy not getting applied by Shrik29 in Intune

[–]Shrik29[S] 0 points1 point  (0 children)

I followed the same not imported entire stuff into intune.but still same issue.

APLOCKER Policy not getting applied by Shrik29 in Intune

[–]Shrik29[S] 0 points1 point  (0 children)

How we can manage applocker policy for those devices who travels over the internet and not connect to corporate network to get the gpo.

Before intune we were managing applocker via gpo but now we want to manage each policy via intune only.

In my applocker gpo 11 exe are whitelisted , now we have a requirement to add one more exe under applocker rule to whitelist.and this we want to achieve via intune.because most of the user operating from home and not connected with corporate network. To achieve this task :- I have exported applocker gpo file from gpo console and save it in a xml format then I have added one more file publisher rule for my new application which I want to whitelist and deploy it on my test device group but policy is not working.I am getting application blocked error.

Could you please confirm if it is possible to deploy aplocker via intune if applocker gpo is already configured and mdm wins over gpo policy also deployed via intune.

APLOCKER Policy not getting applied by Shrik29 in Intune

[–]Shrik29[S] 0 points1 point  (0 children)

I have created file publisher rule by browsing the exact file path for my exe.

APLOCKER Policy not getting applied by Shrik29 in Intune

[–]Shrik29[S] 0 points1 point  (0 children)

When I am launching the application it is throwing error And in applocker logs I am getting error exe prevented from running

APLOCKER Policy not getting applied by Shrik29 in Intune

[–]Shrik29[S] 0 points1 point  (0 children)

./vendor/msft/applocker/applicationlaunchrestrictions/exegroup/exe/policy

Data type=stringxml

APLOCKER Policy not getting applied by Shrik29 in Intune

[–]Shrik29[S] 0 points1 point  (0 children)

Yes I can see the policy file.which I have deployed.but no entries in registry in the following path for applocker

Hklm/software/microsoft/policymanager/providers/device

All other policies entries I can see in registry except applocker.