Windows 10: One CAL per domain user?

Discus and support One CAL per domain user? in User Accounts and Family Safety to solve the problem; Hello there, I'd like to know if I need two separate User-CAL's, if I want to use one PC but with two different A/D accounts. The background is that... Discussion in 'User Accounts and Family Safety' started by XCASE, Nov 23, 2020.

  1. XCASE Win User

    One CAL per domain user?


    Hello there,

    I'd like to know if I need two separate User-CAL's, if I want to use one PC but with two different A/D accounts. The background is that my company wants to give every employee one account with admin rights and one account without.

    Additionally it would be great if you know an official source from Microsoft that supports your answer.

    Thanks!

    :)
     
    XCASE, Nov 23, 2020
    #1
  2. changari Win User

    Raising the windows domain and forest issues?


    hi,

    I run a domain that was all 2003 r2 servers. I recently upgraded all my domain controllers to windows 2012 r2.
    That went off without any problems.. Our trust relationships had no issues also.

    My first step was to raise the Domain and Forest levels past 2003 to 2008. This went off without a hitch.
    These are the features for raising the levels to 2008:

    • Features and benefits include all default Active Directory features, all features from the Windows Server 2003 domain functional level, plus:
    • Read-Only Domain Controllers – Allows implementation of domain controllers that only host read-only copy of NTDS database.
    • Advanced Encryption Services – (AES 128 and 256) support for the Kerberos protocol.
    • Distributed File System Replication (DFSR) – Allows SYSVOL to replicate using DFSR instead of older File Replication Service (FRS). It provides more robust and detailed replication of SYSVOL contents.

    Forest Level Windows Server 2008

    • Features and benefits include all of the features that are available at the Windows Server 2003 forest functional level, but no additional features. All domains that are subsequently added to the forest will operate at the Windows Server 2008 domain functional level by default.


    My next step is to raise the domain and forest to 2008 r2, then 2012, and finally 2012 r2. I have been trying to find out exactly what I could expect from raising the Domain and Forest for each step.

    The step involving 2008 r2 seems relatively a non issue. But getting the couple of new features seem very nice

    Domain Level Windows Server 2008 R2

    • All default Active Directory features, all features from the Windows Server 2008 domain functional level, plus 2 new features

    Forest Level Windows Server 2008 R2

    • All of the features that are available at the Windows Server 2003 forest functional level, plus the following features:


    • Active Directory Recycle Bin, which provides the ability to restore deleted objects in their entirety while AD DS is running. <== New Feature very cool
    • All domains subsequently added to the forest will operate at the Windows Server 2008 R2 domain functional level by default.

    Here is my big concerns for the next raising of domain and forest to 2012.

    Forest Level Windows Server 2012:

    • All of the features that are available at the Windows Server 2008 R2 forest functional level, but no additional features.
    • All domains subsequently added to the forest will operate at the Windows Server 2012 domain functional level by default.

    Domain Level Windows Server 2012 R2: <=====
    Need to investigate more and why this post

    • DC-side protections for Protected Users. Protected Users authenticating to a Windows Server 2012 R2 domain can no longer:


    • Authenticate with NTLM authentication <==============(what issues may arise)
    • Use DES or RC4 cipher suites in Kerberos pre-authentication
    • Be delegated with unconstrained or constrained delegation
    • Renew user tickets (TGTs) beyond the initial 4-hour lifetime


    Will this affect my exchange anywhere users with remote access authenticating either clear of NTLM???
    and what would/may not to work properly day 1 when I raise the domain and forest to 2012. I cant really find anyone that can answer a straight question.

    Has anyone gone through this? what problems did you have, if any , if a lot???

    Any thoughts and suggestions will be much appreciated??

    thanks


    - - - Updated - - -

    One more point... I am not sure if I posted this to the correct forum.. So if I was wrong and it should be in a different one..
    PLEASE LET ME KNOW
     
    changari, Nov 23, 2020
    #2
  3. Forum users with Hotmail/Outlook/Exchange account

    The two-step verification emails show up in my inbox but I added a rule to mark the domain name safe a long time ago (verified that "techpowerup.com" is still in the safe sender list).
     
    FordGT90Concept, Nov 23, 2020
    #3
  4. One CAL per domain user?

    CAL License Clarification

    I want to know about the CAL (Client Access License), Is it necessary to purchase the CAL license. if we use to access the Server without domain or active directory setup. Please help.
     
    Parminder Singh Gosal, Nov 23, 2020
    #4
Thema:

One CAL per domain user?

Loading...
  1. One CAL per domain user? - Similar Threads - CAL per domain

  2. RDS Per User CAL Windows Server 2019

    in Windows 10 Gaming
    RDS Per User CAL Windows Server 2019: Hi,I am trying for weeks now to figure out how can I get proper report.I have multiple Windows Server 2019 Per User CAL-s installed on my licensing server 2019.When I try to get report RD Licensing Manager to see available and issued licenses, I only received Installed but...
  3. RDS Per User CAL Windows Server 2019

    in Windows 10 Software and Apps
    RDS Per User CAL Windows Server 2019: Hi,I am trying for weeks now to figure out how can I get proper report.I have multiple Windows Server 2019 Per User CAL-s installed on my licensing server 2019.When I try to get report RD Licensing Manager to see available and issued licenses, I only received Installed but...
  4. Is the user CAL and device CAL license is transferrable to other user or device Windows...

    in Windows 10 Gaming
    Is the user CAL and device CAL license is transferrable to other user or device Windows...: Is the user CAL and device CAL license is transferrable to other user or device Windows Server and SQL Server https://answers.microsoft.com/en-us/windows/forum/all/is-the-user-cal-and-device-cal-license-is/c3231726-aa7b-4846-9b10-e141f0ea3fde
  5. Is the user CAL and device CAL license is transferrable to other user or device Windows...

    in Windows 10 Software and Apps
    Is the user CAL and device CAL license is transferrable to other user or device Windows...: Is the user CAL and device CAL license is transferrable to other user or device Windows Server and SQL Server https://answers.microsoft.com/en-us/windows/forum/all/is-the-user-cal-and-device-cal-license-is/c3231726-aa7b-4846-9b10-e141f0ea3fde
  6. After installed RDS CAL per user 2019 on Windows server 2012, get the error message

    in Windows 10 Software and Apps
    After installed RDS CAL per user 2019 on Windows server 2012, get the error message: Windows Server 2019 says the license server is activated but I getting the following message with the RD Diagnostics: It says the RD Host Server is in Per User licensing mode and NO redirect mode, but license server does not have any installed licenses with the following...
  7. Server 2022 user cal activation

    in Windows 10 Gaming
    Server 2022 user cal activation: Dear community,I have acquired a 5 user cal license and I am trying to activate the license using the Remote Desktop licensing role that I installed I don’t have a subscription, I am using an home lab for testing and training.I am not planning any productive service.I managed...
  8. how can i remove RDS per user cals which are unused?

    in Windows 10 Updates and Activation
    how can i remove RDS per user cals which are unused?: want to remove un-used Remote Desktop Licenses CALs from RDS server. If i directly uninstall the Cals using below command. will Microsoft still charge for it or it will be removed from license as well? wmic /namespace:\\root\cimv2 path win32_TSlicenseKeyPack CALL...
  9. User@Domain / Domain\User problem

    in Windows 10 Ask Insider
    User@Domain / Domain\User problem: So I was checking my Windows 10 computer and saw that there was no domain, it was in a WORKGROUP. I needed to use the format "User@Domain" or "Domain\User" for something, and I do not know what to put. The username is just "User" and there is no password. submitted by...
  10. User CALs

    in Windows 10 Network and Sharing
    User CALs: I work on a netowrk with several terminal servers and one of those servers is reserved for GPA. We have, roughly, 170 administrators and only 75 User CALs. I am aware that the licenses are good for 60 days and then they are returned back to the repository for redistribution....