Windows 10: Domain server question.

Discus and support Domain server question. in Windows 10 Software and Apps to solve the problem; Hi Gentlemen! Reply to *** Email address is removed for privacy *** Sorry/apologies for starting a new thread again, but I am out because of Arthritis.... Discussion in 'Windows 10 Software and Apps' started by jetfly32, Jan 20, 2025.

  1. jetfly32 Win User

    Domain server question.


    Hi Gentlemen! Reply to *** Email address is removed for privacy *** Sorry/apologies for starting a new thread again, but I am out because of Arthritis. I am using two laptops and have only Windows 11 Home installed, except having both. For this I am having two email accounts with you, one under Outlook and the other Hotmail with 2-factor authorization. But because of that the system is set up as only Workgroup and not domain and therefore a difference. For this I wanted to get in touch with a mentor who is in charge of me, but working for city government where domain is still used. Here the stuff is a little

    :)
     
    jetfly32, Jan 20, 2025
    #1
  2. changari Win User

    Raising the windows domain and forest issues?


    hi,

    I run a domain that was all 2003 r2 servers. I recently upgraded all my domain controllers to windows 2012 r2.
    That went off without any problems.. Our trust relationships had no issues also.

    My first step was to raise the Domain and Forest levels past 2003 to 2008. This went off without a hitch.
    These are the features for raising the levels to 2008:

    • Features and benefits include all default Active Directory features, all features from the Windows Server 2003 domain functional level, plus:
    • Read-Only Domain Controllers – Allows implementation of domain controllers that only host read-only copy of NTDS database.
    • Advanced Encryption Services – (AES 128 and 256) support for the Kerberos protocol.
    • Distributed File System Replication (DFSR) – Allows SYSVOL to replicate using DFSR instead of older File Replication Service (FRS). It provides more robust and detailed replication of SYSVOL contents.

    Forest Level Windows Server 2008

    • Features and benefits include all of the features that are available at the Windows Server 2003 forest functional level, but no additional features. All domains that are subsequently added to the forest will operate at the Windows Server 2008 domain functional level by default.


    My next step is to raise the domain and forest to 2008 r2, then 2012, and finally 2012 r2. I have been trying to find out exactly what I could expect from raising the Domain and Forest for each step.

    The step involving 2008 r2 seems relatively a non issue. But getting the couple of new features seem very nice

    Domain Level Windows Server 2008 R2

    • All default Active Directory features, all features from the Windows Server 2008 domain functional level, plus 2 new features

    Forest Level Windows Server 2008 R2

    • All of the features that are available at the Windows Server 2003 forest functional level, plus the following features:


    • Active Directory Recycle Bin, which provides the ability to restore deleted objects in their entirety while AD DS is running. <== New Feature very cool
    • All domains subsequently added to the forest will operate at the Windows Server 2008 R2 domain functional level by default.

    Here is my big concerns for the next raising of domain and forest to 2012.

    Forest Level Windows Server 2012:

    • All of the features that are available at the Windows Server 2008 R2 forest functional level, but no additional features.
    • All domains subsequently added to the forest will operate at the Windows Server 2012 domain functional level by default.

    Domain Level Windows Server 2012 R2: <=====
    Need to investigate more and why this post

    • DC-side protections for Protected Users. Protected Users authenticating to a Windows Server 2012 R2 domain can no longer:


    • Authenticate with NTLM authentication <==============(what issues may arise)
    • Use DES or RC4 cipher suites in Kerberos pre-authentication
    • Be delegated with unconstrained or constrained delegation
    • Renew user tickets (TGTs) beyond the initial 4-hour lifetime


    Will this affect my exchange anywhere users with remote access authenticating either clear of NTLM???
    and what would/may not to work properly day 1 when I raise the domain and forest to 2012. I cant really find anyone that can answer a straight question.

    Has anyone gone through this? what problems did you have, if any , if a lot???

    Any thoughts and suggestions will be much appreciated??

    thanks


    - - - Updated - - -

    One more point... I am not sure if I posted this to the correct forum.. So if I was wrong and it should be in a different one..
    PLEASE LET ME KNOW
     
    changari, Jan 20, 2025
    #2
  3. sammy Win User
    Question:- How to add client to domain from domain controller side?

    Hi Guys,

    -I have domain called lab.com created on virtual machine Windows Server 2008
    -I have added a client machine Linux machine rhel6 to domain lab.com in /etc/host file
    -I am able to ping DC from linux machine by IP and hostname .
    But from DC I can only ping Linux machine by IP address and not by its hostname "rhel61.lab.com"

    I don't want to add linux machine entry to DC's hosts file as it is DC so it should resolve it

    But I wish to know what step or doings I am missing from DC side that I am not able to ping linux machine by its hostname.

    Please suggest.

    Thanks.
     
    sammy, Jan 20, 2025
    #3
  4. bdanmo Win User

    Domain server question.

    UnattendedJoin error: failed to find the domain data (0x6e)

    Thanks for the suggestion! I don't want to add a domain account, as this is a generic unattended install that will be used for all company machines. Do you think it's possible that the computer would join the domain if, instead of using UnattendedJoin in specialize, I used your steps but left out the specific account? The other thing I was thinking was to use a generic account to allow the domain join during the specialize step. I added a machine password in the UnattendedJoin component, and instead of getting the error listed above, I got an authentication error, which makes me think I could probably do a secure join instead of the unsecure join. Thoughts?
     
    bdanmo, Jan 20, 2025
    #4
Thema:

Domain server question.

Loading...
  1. Domain server question. - Similar Threads - Domain server question

  2. Domain server question.

    in Windows 10 Gaming
    Domain server question.: Hi Gentlemen! Reply to *** Email address is removed for privacy *** Sorry/apologies for starting a new thread again, but I am out because of Arthritis. I am using two laptops and have only Windows 11 Home installed, except having both. For this I am having two email accounts...
  3. Domain file server and folder redirection user's recycle bin question

    in Windows 10 Gaming
    Domain file server and folder redirection user's recycle bin question: I have a site that we have folder redirection on the server and each domain user has a path to a recycle bin that shows up on their redirected Desktop folder Some of the folders are massive in size, 14 to 20 GB in size Is there some GPO setting that I can set or a utility or...
  4. Domain file server and folder redirection user's recycle bin question

    in Windows 10 Network and Sharing
    Domain file server and folder redirection user's recycle bin question: I have a site that we have folder redirection on the server and each domain user has a path to a recycle bin that shows up on their redirected Desktop folder Some of the folders are massive in size, 14 to 20 GB in size Is there some GPO setting that I can set or a utility or...
  5. Domain file server and folder redirection user's recycle bin question

    in Windows 10 Software and Apps
    Domain file server and folder redirection user's recycle bin question: I have a site that we have folder redirection on the server and each domain user has a path to a recycle bin that shows up on their redirected Desktop folder Some of the folders are massive in size, 14 to 20 GB in size Is there some GPO setting that I can set or a utility or...
  6. no domain servers available message

    in Windows Hello & Lockscreen
    no domain servers available message: windows 10 pc that has joined a domain working at home, switching between domain users gives problem. pc has been removed and added to the domein, problem persists. while at the logon screen vpn is not available. users gets error "no domain servers available" when...
  7. Question about server domain and Windows 7

    in Windows 10 Network and Sharing
    Question about server domain and Windows 7: What is the difference if I create a folder and share it in my Windows 7 (workstation) and if I do the same thing in my server (domain controller)? I created a folder in my domain controller(windows server) and I gave this folder full control to everyone. After that I log in...
  8. Question about server domain and Windows 7

    in Windows 10 Support
    Question about server domain and Windows 7: What is the difference if I create a folder and share it in my Windows 7 (workstation) and if I do the same thing in my server (domain controller)? I created a folder in my domain controller(windows server) and I gave this folder full control to everyone. After that I log in...
  9. Server 2012 question

    in Windows 10 Installation and Upgrade
    Server 2012 question: I have a computer running windows 10, the upgraded version from 8. It has a windows server 2012 R2 running on it and I would like to do a reinstall for the windows 10 to clean up my system but how do I get the 2012 R2 back on there? As far as I know I do not have a disc for...
  10. domain server problems

    in Windows 10 Network and Sharing
    domain server problems: I have had windows 10 a couple weeks and if this issue had not starter a week before that I would blame 10. My internet cuts off at random times, sometimes just for seconds and sometimes I have to turn off modem and restart. At first the troubleshooter said dns problems,...