Sign in
Chicken Soup for the Techie
Translate This Page
Translate this page
Powered by
Microsoft® Translator
Options
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search Blogs
Tags
“Your organization could not sign you in to this service”
account
AD Mgmt
AD Replication
ADFS
Authentication
email
Federated user
GPO
Kerberos
lockout
O365
Office 365
Onmicrosoft.com
password
proxyaddresses
Single Sign On
SSO
SupportMultipleDomain
threshold
Archive
Archives
April 2013
(4)
February 2013
(1)
May 2011
(1)
May 2010
(1)
July 2009
(4)
June 2009
(3)
TechNet Blogs
>
Chicken Soup for the Techie
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Chicken Soup for the Techie
How an incorrectly configured account lockout policy can give more pain than security.
Posted
27 days ago
by
Abizer
0
Comments
I don't believe this..... we still see environments with Account Lockout policy set with a threshold of 3, with lockout duration of 2 or 5 minutes etc. Most of them, spend a good amount of money and time addressing these lockouts, and affecting business...
Chicken Soup for the Techie
Possible causes of Authentications failures for federated users in Office 365.
Posted
28 days ago
by
Abizer
0
Comments
Here I’m assuming that we are using ADFS 2.0, for SSO to O365 services: 1. Active Directory replication issue If AD replication is broken, changes made to user/group may not be in sync across DCs. Between DCs, we may have password/upn/groupmembersip...
Chicken Soup for the Techie
More information about SSO experience when authenticating via ADFS
Posted
1 month ago
by
Abizer
1
Comments
Common understanding about SSO: Which may mean user enters username/password once, and does not need to reenter again during the same session. It may also mean that when accessing different application/resources, we need not enter different credentials...
Chicken Soup for the Techie
Information about Email addresses assigned to a licensed user in O365
Posted
1 month ago
by
Abizer
0
Comments
The Onmicrosoft.com email address gets stamped the time an Exchange license is assigned to the user. When creating the Onmicrosoft.com email address for the user, we look at the mailNickname attribute value for this user on the cloud. The mailNickName...
Chicken Soup for the Techie
SupportMultipleDomain switch, when managing SSO to Office 365
Posted
3 months ago
by
Abizer
2
Comments
Use of SupportMultipleDomain switch, when managing SSO to Office 365 using ADFS When a SSO is enabled for O365 via ADFS, you should see the Relying Party (RP) trust created for O365. Commands that would create the RP trust for O365 are...
Chicken Soup for the Techie
Kerberos Error KDC_ERR_POLICY while trying to access a resource in the Trusted forest (Forest Trust)
Posted
over 2 years ago
by
abizer_hazrat
0
Comments
Symptoms Forest1 = 2003dom.local Forest2 = 2008dom.local 2-way Forest Trust created between them, with forest level authentication. **User from Forest2 access a server in Trusted Forest1 i.e. \\2003-dc1.2003dom.local Here is what I see in the network...
Chicken Soup for the Techie
Tracing down user and computer account deletion in Active Directory
Posted
over 3 years ago
by
abizer_hazrat
1
Comments
In order to find out about user and computer account deletion, you must keep the “Account Management” auditing enabled , beforehand. The Account Management auditing needs to be enabled as follows: At Domain Controller OU level, edit the “Default...
Chicken Soup for the Techie
Netmon's view of Kerberos communication, when accessing resources across domains in the same forest.
Posted
over 4 years ago
by
abizer_hazrat
2
Comments
Domain setup: Both Child1 and Child2 are in the same forest with the same parent domain R2dom.local. Administrator of the Child domain ( CHILD1 ) login to a member server ( CH1-Mem ) in CHILD1 domain . After login in the user tries...
Chicken Soup for the Techie
Should IIS be installed on Domain Controller
Posted
over 4 years ago
by
abizer_hazrat
0
Comments
I have come across various scanarios where System Administrators have installed IIS on Domain Controllers. They do it to efffectively utilize that server hardware, to cut down cost by preventing a need for another server for IIS, some application that...
Chicken Soup for the Techie
Error: "The parameter is incorrect" when connecting to a server using WMI.
Posted
over 4 years ago
by
abizer_hazrat
3
Comments
You test WMI connectivity remotely using WBEMTEST > Error: "The parameter is incorrect" Analysis: Network trace during the issue shows that communication is happening with TCP Port 135 but after that secondary connection other DCOM/WMI interface...
Chicken Soup for the Techie
Troubleshooting the error "Not enough storage is available to complete this operation"
Posted
over 4 years ago
by
abizer_hazrat
6
Comments
I have come across a few issues where I have seen the above error. Below are two scenarios of the issue and the symptoms that I've noticed during that time. · Domain Workstations going into a state where they are unable to access resources over...
Chicken Soup for the Techie
Troubleshooting “RPC server is unavailable” error, reported in failing AD replication scenario.
Posted
over 4 years ago
by
abizer_hazrat
3
Comments
In this scenario when are troubleshooting AD replication between 2 DCs separated by a firewall. In order to ensure that the important well-known ports required in a domain environment are open on the firewall between these DCs, use the PortqryUI...
Chicken Soup for the Techie
Windows 7 - Applocker
Posted
over 4 years ago
by
abizer_hazrat
0
Comments
Windows AppLocker is a new feature in Windows 7 and Windows Server 2008 R2 is an alternative to the Software Restriction Policies feature. New with AppLocker ================== · Define rules based on file attributes derived from the digital...
Chicken Soup for the Techie
Preventing Unwanted/Accidental deletions and Restore deleted objects in Active Directory
Posted
over 4 years ago
by
abizer_hazrat
0
Comments
Preventing Unwanted/Accidental deletions Windows 2003 Use Delegation to restrict the deletion activity , to only selected Admins. · Create group which contains users, who you want should NOT have the delete permission of set of objects...
Page 1 of 1 (14 items)