New Active Directory Documents for IT Pros
Active Directory Documentation Team - Site Home - TechNet Blogs
Sign In
Active Directory Documentation Team
Information for IT Professionals who work with Active Directory. All blog posts are provided "AS IS" with no warranties, and confer no rights.
Translate This Page
Translate this page
Powered by
Microsoft® Translator
Options
About
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search Blogs
Advanced search options...
Search In:
Everything
Blogs
Forums
People
Groups
Places
Pages
Date range:
All Time
Last Year
Last 6 Months
Last 3 Months
Last Month
Last Week
Last Two Days
Tags
"Active Directory"
"Active Directory" "Active Directory Domain Services"
Active Directory
Active Directory Certificate Services (AD CS)
Active Directory Domain Services
Active Directory errors
Active Directory Maximums
Active Directory PowerShell
Active Directory troubleshooting
Active Directory User Assistance
AD CS
certificate services
certification authority
computer accounts
dsforum2wiki
Group Policy
Hyper-V
Limitations
limits of Active Directory
PowerShell
PowerShell Scripting
Service Principal Name
SPN
Windows Server 2008
Windows Server 2008 R2
Archive
Archives
May 2012
(1)
April 2012
(3)
March 2012
(1)
October 2011
(1)
August 2011
(3)
July 2011
(3)
June 2011
(2)
May 2011
(2)
April 2011
(5)
March 2011
(3)
February 2011
(3)
January 2011
(7)
December 2010
(2)
November 2010
(7)
September 2010
(1)
August 2010
(1)
July 2010
(1)
June 2010
(2)
May 2010
(2)
April 2010
(6)
March 2010
(1)
January 2010
(2)
October 2009
(4)
September 2009
(2)
August 2009
(4)
July 2009
(1)
June 2009
(1)
May 2009
(1)
April 2009
(6)
March 2009
(3)
February 2009
(2)
January 2009
(9)
December 2008
(1)
November 2008
(4)
TechNet Blogs
>
Active Directory Documentation Team
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Active Directory Documentation Team
Using PowerShell to clear or remove all AIA and CDP entries in Active Directory Certificate Services for Windows Server 2012
Posted
12 days ago
by
Kurt Hudson
0
Comments
You may have already seen that you can deploy most Windows Server 2012 role services with Windows PowerShell. If you are interested in Active Directory Certificate Services (AD CS), you've probably noticed the PowerShell commands for deploying all six...
Active Directory Documentation Team
Update for SetSPN - Syntax for SetSPN.exe
Posted
1 month ago
by
Kurt Hudson
0
Comments
Breaking guidance change: Although you can use Setspn -A , you should use Setspn -S instead because -S will verify that there are no duplicate SPNs. However, if you are using Windows Server 2003 or earlier, you will not be able to use the -S switch because...
Active Directory Documentation Team
After enabling AD Recycle Bin, can you lower tombstoneLifetime value?
Posted
1 month ago
by
Justin Hall MSFT
0
Comments
Here is a great question and reply from a lead developer for AD Recycle Bin. Q: After enabling the AD Recycle Bin, is there any downside to bringing the tombstoneLifetime value down to, e.g. 7 days? On the face of it it seems sensible to do this to...
Active Directory Documentation Team
Resource for understanding NTLM MaxConcurrentApi problems and how to address them
Posted
1 month ago
by
Justin Hall MSFT
0
Comments
Just want to make people aware of a new topic recently posted by colleagues: Configuring MaxConcurrentAPI for NTLM pass-through authentication . This was written by the authentication product group team themselves and has a deep explanation of how...
Active Directory Documentation Team
Deploying Active Directory Certificate Services (AD CS) PKI two-tier hierarchy
Posted
1 month ago
by
Kurt Hudson
0
Comments
When I was first learning about Active Directory Certificate Services (AD CS), a colleague told me that I should search on Step-by-Step Guide with AD CS. He was right, that was a good place to get started. Starting with Windows Server 2008 R2, the Test...
Active Directory Documentation Team
Printing results from an Active Directory Administrative Center query
Posted
7 months ago
by
Davanand Bahall - MSFT
1
Comments
Recently a question was asked on the blog regarding printing queries from Active Directory Administrative Center (ADAC). There is no native functionality for printing queries performed in ADAC, but there is a workaround. 1. Open ADAC and create a query...
Active Directory Documentation Team
The Hyper-V and the virtual floppy shuffle
Posted
9 months ago
by
Kurt Hudson
0
Comments
One of the favorite ice breakers for computer geek get-together is to talk about your first computer. Hey, I still remember the TRS 80 (who people in the know call it the Trash80). If you liked something and you are proud of it and still refer to it as...
Active Directory Documentation Team
ADCS FAQ or AD CS FAQ?
Posted
9 months ago
by
Kurt Hudson
1
Comments
I was recently alerted to the situation that not all of our Microsoft customers have adjusted their language based on the new branding of Active Directory to include more than just Active Directory Domain Services. For example, people might just be searching...
Active Directory Documentation Team
Updates just posted to Active Directory Certificate Services (AD CS) documentation
Posted
9 months ago
by
Kurt Hudson
0
Comments
A few updates were just posted, so I am putting out an FYI post. I should do this more often, so I will! Anyways, here goes: 1. Slowly, but surely, the AD CS documentation is being consolidated into a single download center page: Active Directory Certificate...
Active Directory Documentation Team
Finding the RIDs in your domain video
Posted
10 months ago
by
Kurt Hudson
0
Comments
Here is a video I shot a while back that demonstrates how to use ADSI Edit to find the number of RIDs remaining in your domain. However, you can do this more quickly by running the following command: dcdiag /test:ridmanager /v | find /i "available...
Active Directory Documentation Team
Forest schema version 47: Windows Server 2008 R2 Adprep /forestprep
Posted
10 months ago
by
Kurt Hudson
2
Comments
When you run adprep /forestprep, you are updating the Active Directory schema forest version. Several people have asked, what is the forest schema version for Windows Server 2008 R2. To learn more about adprep and forestprep and schema versions, read...
Active Directory Documentation Team
A delegation for this DNS server cannot be created because the authoritative parent zone cannot be found or it does not run Windows DNS server.
Posted
10 months ago
by
Kurt Hudson
5
Comments
A common warning message for anyone who has installed Active Directory on Windows Server 2008 or Windows 2008 R2, especially on the first domain controller in a forest or domain is: A delegation for this DNS server cannot be created because the authoritative...
Active Directory Documentation Team
Important Security Update that affects sample pages in AD CS
Posted
11 months ago
by
Kurt Hudson
0
Comments
An important security update, described in MS11-051 ( http://go.microsoft.com/fwlink/?LinkId=217101 ) was released today. The update fixes a cross-site scripting vulnerability in the sample web enrollment ASP pages that are part of Active Directory Certificate...
Active Directory Documentation Team
Typo in the mnemonic of DCLocator DNS Record in Windows Server 2003 Active Directory Branch Office Guide
Posted
11 months ago
by
Justin Hall MSFT
1
Comments
There is a typo in the Windows Server 2003 Active Directory Branch Office Guide that has affected some customers. The typo appears in the section of the guide that explains the mnemonics of DC Locator DNS Records that should not be registered by the DCs...
Active Directory Documentation Team
Incompatibilities with CNG or V3 templates
Posted
over 1 year ago
by
Kurt Hudson
0
Comments
If you have heard of Certificates Next Generation (silly name, I know), which is why people call them V3 templates at Microsoft most of the time, then you might wonder or already know that there could be some compatibility issues - the same is true for...
Active Directory Documentation Team
PKI Design "Brief Overview"
Posted
over 1 year ago
by
Kurt Hudson
0
Comments
I am really trying to make this TechNet Wiki article PKI Design Brief Overview a place from which we can answer the basic questions regarding PKI design and then point off to the more detailed information. http://social.technet.microsoft.com/wiki/contents...
Active Directory Documentation Team
Troubleshooting Certificate Autoenrollment field notes posted on TechNet Wiki
Posted
over 1 year ago
by
Kurt Hudson
0
Comments
If you have trouble with Certificate Autoenrollment or have ever had issues troubleshooting certificate autoenrollment in Active Directory Certificate Services (AD CS), take a look at the notes compiled by Roger Grimes and turned into a TechNet Wiki article...
Active Directory Documentation Team
Active Directory Troubleshooting
Posted
over 1 year ago
by
Kurt Hudson
0
Comments
We are developing an Active Directory troubleshooting guide on the TechNet Wiki. Been working on it since February, so it is ready for some feedback and feel free to help us out with comments, feedback, and so on. del.icio.us Tags: Active Directory troubleshooting...
Active Directory Documentation Team
Updates made to Certificates How To. based on your feedback
Posted
over 1 year ago
by
Kurt Hudson
0
Comments
I just went through and updated 16 or more resources that were posted online a while ago regarding Windows Server 2003. Seems there was not enough context with the information that was appearing in TechNet regarding the Certificates Console (certmgr.msc...
Active Directory Documentation Team
How do I install Active Directory Certificate Services (AD CS)?
Posted
over 1 year ago
by
Kurt Hudson
0
Comments
Be sure that you've planned your PKI . Then, see Offline Root CA . del.icio.us Tags: Active Directory Certificate Services , AD CS design , installing AD CS , PKI design , CA hierarchy , installing Active Directory Certificate Services (AD CS)
Active Directory Documentation Team
Why do people use offline root certification authorities?
Posted
over 1 year ago
by
Kurt Hudson
0
Comments
To get the answer to that and other questions, like "How do I patch an offline root CA?" see the new TechNet Wiki article Offline Root Certification Authority (CA). del.icio.us Tags: certification authority , CA , AD CS , Active Directory Certificate...
Active Directory Documentation Team
DSForum: KDC Event ID 26
Posted
over 1 year ago
by
Davanand Bahall - MSFT
0
Comments
The DSForum post, EventID 26 & 27 : KDC: suitable keys , has been consolidated into the following TechNet Wiki article: KDC Event ID 26 (dsforum2wiki) Please look the article over and let us know what you think. You can edit the Wiki article...
Active Directory Documentation Team
Problems running Active Directory Users and Computers due to a C++ runtime error?
Posted
over 1 year ago
by
Kurt Hudson
0
Comments
Check out this TechNet Wiki article that describes a potential solution. Turns out that clearing out the files saved in Active Directory Sites and Services might be the answer.
Active Directory Documentation Team
DSForum: Event ID 5719 source Netlogon
Posted
over 1 year ago
by
Justin Hall MSFT
0
Comments
The DS forum posts, Netlogon error 5719 and Event 5719 Netlogon Problem , have been consolidated into the following TechNet Wiki article: Event ID 5719 source Netlogon (dsforum2wiki) Please look the article over and let us know what you...
Active Directory Documentation Team
A new test lab guide (TLG) about securing DC communication was just published.
Posted
over 1 year ago
by
Kurt Hudson
0
Comments
Test Lab Guide - Deploy Windows Firewall with Advanced Security to Protect Network Communication to a Domain Controller Description: This Test Lab Guide contains an introduction to Windows Firewall with Advanced Security (WFAS) and step-by-step instructions...
Page 1 of 4 (95 items)
1
2
3
4