Windows 10: How to administer logons on family PCs, compared to AD domains

Discus and support How to administer logons on family PCs, compared to AD domains in User Accounts and Family Safety to solve the problem; As an experienced system administrator, I'm used to administering user accounts, passwords, login problems, lost passwords and so on via Active... Discussion in 'User Accounts and Family Safety' started by Ken Wallewein, Jan 29, 2021.

  1. How to administer logons on family PCs, compared to AD domains


    As an experienced system administrator, I'm used to administering user accounts, passwords, login problems, lost passwords and so on via Active Directory.


    Microsoft seems to be promoting the use Family and Microsoft accounts for user ID management on Windows 10 PCs. I would like to know how that is supposed to work, what the benefits are, and how it compares to the use of Active Directory. I.e., is there any sort of "family administrator" or anything like that?


    Where can I find more information on this?


    --KW

    :)
     
    Ken Wallewein, Jan 29, 2021
    #1
  2. marekjs Win User

    Family settings for parental control Windows 10 in domain

    Hi,

    Yes, they are logged in and I am logged in.

    I am the admin and I can’t see Family settings in Accounts even the web can see my PCs healthy with latest updates.

    Any further steps to perform, you think?

    Do I need to logon to Microsoft before my local domain logon? Shall “link” somehow those accounts further even they are linked already?
     
    marekjs, Jan 29, 2021
    #2
  3. changari Win User
    Raising the windows domain and forest issues?


    hi,

    I run a domain that was all 2003 r2 servers. I recently upgraded all my domain controllers to windows 2012 r2.
    That went off without any problems.. Our trust relationships had no issues also.

    My first step was to raise the Domain and Forest levels past 2003 to 2008. This went off without a hitch.
    These are the features for raising the levels to 2008:

    • Features and benefits include all default Active Directory features, all features from the Windows Server 2003 domain functional level, plus:
    • Read-Only Domain Controllers – Allows implementation of domain controllers that only host read-only copy of NTDS database.
    • Advanced Encryption Services – (AES 128 and 256) support for the Kerberos protocol.
    • Distributed File System Replication (DFSR) – Allows SYSVOL to replicate using DFSR instead of older File Replication Service (FRS). It provides more robust and detailed replication of SYSVOL contents.

    Forest Level Windows Server 2008

    • Features and benefits include all of the features that are available at the Windows Server 2003 forest functional level, but no additional features. All domains that are subsequently added to the forest will operate at the Windows Server 2008 domain functional level by default.


    My next step is to raise the domain and forest to 2008 r2, then 2012, and finally 2012 r2. I have been trying to find out exactly what I could expect from raising the Domain and Forest for each step.

    The step involving 2008 r2 seems relatively a non issue. But getting the couple of new features seem very nice

    Domain Level Windows Server 2008 R2

    • All default Active Directory features, all features from the Windows Server 2008 domain functional level, plus 2 new features

    Forest Level Windows Server 2008 R2

    • All of the features that are available at the Windows Server 2003 forest functional level, plus the following features:


    • Active Directory Recycle Bin, which provides the ability to restore deleted objects in their entirety while AD DS is running. <== New Feature very cool
    • All domains subsequently added to the forest will operate at the Windows Server 2008 R2 domain functional level by default.

    Here is my big concerns for the next raising of domain and forest to 2012.

    Forest Level Windows Server 2012:

    • All of the features that are available at the Windows Server 2008 R2 forest functional level, but no additional features.
    • All domains subsequently added to the forest will operate at the Windows Server 2012 domain functional level by default.

    Domain Level Windows Server 2012 R2: <=====
    Need to investigate more and why this post

    • DC-side protections for Protected Users. Protected Users authenticating to a Windows Server 2012 R2 domain can no longer:


    • Authenticate with NTLM authentication <==============(what issues may arise)
    • Use DES or RC4 cipher suites in Kerberos pre-authentication
    • Be delegated with unconstrained or constrained delegation
    • Renew user tickets (TGTs) beyond the initial 4-hour lifetime


    Will this affect my exchange anywhere users with remote access authenticating either clear of NTLM???
    and what would/may not to work properly day 1 when I raise the domain and forest to 2012. I cant really find anyone that can answer a straight question.

    Has anyone gone through this? what problems did you have, if any , if a lot???

    Any thoughts and suggestions will be much appreciated??

    thanks


    - - - Updated - - -

    One more point... I am not sure if I posted this to the correct forum.. So if I was wrong and it should be in a different one..
    PLEASE LET ME KNOW
     
    changari, Jan 29, 2021
    #3
  4. RWOne Win User

    How to administer logons on family PCs, compared to AD domains

    Can't login as local user after adding a computer to a domain


    Your logon username for local is incorrect.

    If the username created was "Admin", then the local machine logon is:

    Workstation001\Admin (Omit "Local") It already knows you are logging onto the machine from the machine header.
     
    RWOne, Jan 29, 2021
    #4
Thema:

How to administer logons on family PCs, compared to AD domains

Loading...
  1. How to administer logons on family PCs, compared to AD domains - Similar Threads - administer logons family

  2. "How to logon to another domain"

    in Windows Hello & Lockscreen
    "How to logon to another domain": On Windows on the login screen for Windows, there is the option for the "Logon to another domain" so I added the computer to my AD list and tried to login and it said "the security database for this computer does not have a computer domain trust relationship" I'm just...
  3. Best way to compare performance on 2 PCs streaming

    in Windows 10 Performance & Maintenance
    Best way to compare performance on 2 PCs streaming: HI, I have 2 towers much the same vintage both with Win 10 x64 1909 and I would like to be able to compare them for possible streaming. Same programs etc. Because of the random nature of things just happening to slow a PC down, is there a basic way to at least see if the...
  4. Your Phone App on Domain PCs

    in Windows 10 Software and Apps
    Your Phone App on Domain PCs: Is it possible to get this App to function in a domain environment? I have a Note 10+ that connects to my home PC without any issues at all, so I know that side of the setup is working fine. My situation is I have a PC where I log into it with domain credentials, but I...
  5. Is there a way to change the passwords to a group of PCs in an AD domain?

    in AntiVirus, Firewalls and System Security
    Is there a way to change the passwords to a group of PCs in an AD domain?: Wondering if there is any way to do this. My staff support a small organization with roughly 1600 PCs. We are a public office, so we have about 200 "kiosk" PCs where the public can come in and look up information using very locked down desktops. The PCs are all running...
  6. how to log in as windows administator

    in Windows 10 Customization
    how to log in as windows administator: I have just down loaded Garmin Express on my PC and it won't let me install the program as I am not logged as Administrator, How do I log in as Administrator....
  7. Some PCs are not discoverable on the domain network

    in Windows 10 Network and Sharing
    Some PCs are not discoverable on the domain network: Some of the PCs at work are defining the network as "Domain Network". These PCs are neither discovering the other PCs on the same network, nor they are discoverable to the other PCs. On the other hand, some other PCs are defining the same domain network as "Private Network",...
  8. Some PCs are not discoverable on the domain network

    in Windows 10 Network and Sharing
    Some PCs are not discoverable on the domain network: Some of the PCs at work are defining the network as "Domain Network". These PCs are neither discovering the other PCs on the same network, nor they are discoverable to the other PCs. On the other hand, some other PCs are defining the same domain network as "Private Network",...
  9. Adding Email to add on domain?

    in Browsers and Email
    Adding Email to add on domain?: is it possible to make an email, via cpanel, to an add on domain. I have had a look but cannot see anything obvious. 105077
  10. Slow Logon Times with Domain Account

    in Windows 10 Performance & Maintenance
    Slow Logon Times with Domain Account: Hi all, I use my work laptop as my personal machine. When I logon away from the domain it takes about 3 minutes of the verbose message "waiting for user profile service" before it will show the desktop. Any ideas how to change the time out period for how long it waits to...