Windows 10: Issue with domain login

Discus and support Issue with domain login in Windows 10 Software and Apps to solve the problem; Very strange problem, I got called from a user that they couldn't access their active directory account, I logged in remotely with her account no... Discussion in 'Windows 10 Software and Apps' started by RD Plumbing, Jul 14, 2024.

  1. Issue with domain login


    Very strange problem, I got called from a user that they couldn't access their active directory account, I logged in remotely with her account no problem, I reset her password and she still couldn't login I thought it was a corrupt use profile, I went out to site and when I check audit failure logs it shows that even though login screen showed correct active directory username, when she was hitting enter it was failing on another active directory user e.g. instead of having correct username for Jane Doe with correct password, Windows 11 was attempting to login via John Doe username, I logged i

    :)
     
    RD Plumbing, Jul 14, 2024
    #1
  2. changari Win User

    Raising the windows domain and forest issues?


    hi,

    I run a domain that was all 2003 r2 servers. I recently upgraded all my domain controllers to windows 2012 r2.
    That went off without any problems.. Our trust relationships had no issues also.

    My first step was to raise the Domain and Forest levels past 2003 to 2008. This went off without a hitch.
    These are the features for raising the levels to 2008:

    • Features and benefits include all default Active Directory features, all features from the Windows Server 2003 domain functional level, plus:
    • Read-Only Domain Controllers – Allows implementation of domain controllers that only host read-only copy of NTDS database.
    • Advanced Encryption Services – (AES 128 and 256) support for the Kerberos protocol.
    • Distributed File System Replication (DFSR) – Allows SYSVOL to replicate using DFSR instead of older File Replication Service (FRS). It provides more robust and detailed replication of SYSVOL contents.

    Forest Level Windows Server 2008

    • Features and benefits include all of the features that are available at the Windows Server 2003 forest functional level, but no additional features. All domains that are subsequently added to the forest will operate at the Windows Server 2008 domain functional level by default.


    My next step is to raise the domain and forest to 2008 r2, then 2012, and finally 2012 r2. I have been trying to find out exactly what I could expect from raising the Domain and Forest for each step.

    The step involving 2008 r2 seems relatively a non issue. But getting the couple of new features seem very nice

    Domain Level Windows Server 2008 R2

    • All default Active Directory features, all features from the Windows Server 2008 domain functional level, plus 2 new features

    Forest Level Windows Server 2008 R2

    • All of the features that are available at the Windows Server 2003 forest functional level, plus the following features:


    • Active Directory Recycle Bin, which provides the ability to restore deleted objects in their entirety while AD DS is running. <== New Feature very cool
    • All domains subsequently added to the forest will operate at the Windows Server 2008 R2 domain functional level by default.

    Here is my big concerns for the next raising of domain and forest to 2012.

    Forest Level Windows Server 2012:

    • All of the features that are available at the Windows Server 2008 R2 forest functional level, but no additional features.
    • All domains subsequently added to the forest will operate at the Windows Server 2012 domain functional level by default.

    Domain Level Windows Server 2012 R2: <=====
    Need to investigate more and why this post

    • DC-side protections for Protected Users. Protected Users authenticating to a Windows Server 2012 R2 domain can no longer:


    • Authenticate with NTLM authentication <==============(what issues may arise)
    • Use DES or RC4 cipher suites in Kerberos pre-authentication
    • Be delegated with unconstrained or constrained delegation
    • Renew user tickets (TGTs) beyond the initial 4-hour lifetime


    Will this affect my exchange anywhere users with remote access authenticating either clear of NTLM???
    and what would/may not to work properly day 1 when I raise the domain and forest to 2012. I cant really find anyone that can answer a straight question.

    Has anyone gone through this? what problems did you have, if any , if a lot???

    Any thoughts and suggestions will be much appreciated??

    thanks


    - - - Updated - - -

    One more point... I am not sure if I posted this to the correct forum.. So if I was wrong and it should be in a different one..
    PLEASE LET ME KNOW
     
    changari, Jul 14, 2024
    #2
  3. bdanmo Win User
    UnattendedJoin error: failed to find the domain data (0x6e)

    Thanks for the suggestion! I don't want to add a domain account, as this is a generic unattended install that will be used for all company machines. Do you think it's possible that the computer would join the domain if, instead of using UnattendedJoin in specialize, I used your steps but left out the specific account? The other thing I was thinking was to use a generic account to allow the domain join during the specialize step. I added a machine password in the UnattendedJoin component, and instead of getting the error listed above, I got an authentication error, which makes me think I could probably do a secure join instead of the unsecure join. Thoughts?
     
    bdanmo, Jul 14, 2024
    #3
  4. Arun B J Win User

    Issue with domain login

    Can't login to new computer w/Windows 10

    Hi,

    Thank you for your reply.


    • Are you able to login to Microsoft Account on Web?

    • Have you installed any language pack?
    I suggest you to follow the steps below and check if it helps.

    Step 1: I suggest you to select the appropriate language in login screen at the bottom right corner and check if it helps.

    Steps 2: Use On-screen keyboard in the login screen to login and check if it helps.

    Hope this helps. If the issue remains unresolved, please get back to us and we would be happy to help.
     
    Arun B J, Jul 14, 2024
    #4
Thema:

Issue with domain login

Loading...
  1. Issue with domain login - Similar Threads - Issue domain login

  2. Slow login and black screen issue on domain computers

    in Windows Hello & Lockscreen
    Slow login and black screen issue on domain computers: I have experienced an issue with domain computers, when attempting to log in via the windows hello screen by password \ pin number, its take up to fine minutes additionally, these computers do not have local admin privileges, when trying to install new software and entering...
  3. Slow login and black screen issue on domain computers

    in Windows 10 Gaming
    Slow login and black screen issue on domain computers: I have experienced an issue with domain computers, when attempting to log in via the windows hello screen by password \ pin number, its take up to fine minutes additionally, these computers do not have local admin privileges, when trying to install new software and entering...
  4. Slow login and black screen issue on domain computers

    in Windows 10 Software and Apps
    Slow login and black screen issue on domain computers: I have experienced an issue with domain computers, when attempting to log in via the windows hello screen by password \ pin number, its take up to fine minutes additionally, these computers do not have local admin privileges, when trying to install new software and entering...
  5. Domain notebooks login issue on wireless netwok without 802.1x

    in Windows 10 Gaming
    Domain notebooks login issue on wireless netwok without 802.1x: I have deployed 802.1x on wired ethernet. Wireless adapter keeps without 802.1x until all ethernet issues fixed. All the domain joinned notebooks found they can only login with wired connection but not wireless connection with the error prompt "We can't sign you in with this...
  6. Domain notebooks login issue on wireless netwok without 802.1x

    in Windows 10 Software and Apps
    Domain notebooks login issue on wireless netwok without 802.1x: I have deployed 802.1x on wired ethernet. Wireless adapter keeps without 802.1x until all ethernet issues fixed. All the domain joinned notebooks found they can only login with wired connection but not wireless connection with the error prompt "We can't sign you in with this...
  7. Issue with domain login

    in Windows 10 Gaming
    Issue with domain login: Very strange problem, I got called from a user that they couldn't access their active directory account, I logged in remotely with her account no problem, I reset her password and she still couldn't login I thought it was a corrupt use profile, I went out to site and when I...
  8. Login Issues with PIN and Domain Server Unavailability on Windows 11

    in Windows 10 Gaming
    Login Issues with PIN and Domain Server Unavailability on Windows 11: My notebook is part of an Active Directory domain. To access my account in the office, I always use the PIN. On Sunday, I turned on the notebook at home. I don't remember if I entered the wrong PIN, but at some point, Windows informed me that logging in with the PIN was...
  9. Login Issues with PIN and Domain Server Unavailability on Windows 11

    in Windows 10 Software and Apps
    Login Issues with PIN and Domain Server Unavailability on Windows 11: My notebook is part of an Active Directory domain. To access my account in the office, I always use the PIN. On Sunday, I turned on the notebook at home. I don't remember if I entered the wrong PIN, but at some point, Windows informed me that logging in with the PIN was...
  10. Unable to Login to Domain

    in User Accounts and Family Safety
    Unable to Login to Domain: Have Lenovo with Win 10 Home installed. Run upgrade to 10 Pro. Joined to domain. Assigned 2-3 domain users to be able to login to this machine. Failed to login with any domain users, says" The user name or password is incorrect. Try again". Tried to use static IP,...