Windows 10: Some settings blocked as of in a domain (I'm not in a domain)

Discus and support Some settings blocked as of in a domain (I'm not in a domain) in Windows 10 Ask Insider to solve the problem; I just got a new NVMe SSD so did a fresh windows reinstall on it, and used my 'old' SATA SSD for storage. After the install, updates, drivers, etc I... Discussion in 'Windows 10 Ask Insider' started by /u/Ashlander0, Jan 3, 2020.

  1. Some settings blocked as of in a domain (I'm not in a domain)


    I just got a new NVMe SSD so did a fresh windows reinstall on it, and used my 'old' SATA SSD for storage. After the install, updates, drivers, etc I noticed the option "Use my sign-in info to automatically finish setting up my device after an update or restart" on the Accounts settings was grayed out, and I have a red message at the top saying that some settings are hidden or managed by my organization.

    At first I figured I just had a corrupt or outdated media installer (created in March last year), so I downloaded the current media creation tool and made a new install USB. Installed windows again and the issue appeared to be gone, but then after updates, drivers, etc, it was doing it again.

    From looking online that specific setting should only ever be grayed out if the machine is part of a domain, which it's not.

    I used cmd prompt and "gpresults /scope user /v" (as well as the /scope computer) to check if there were any group policies restricting it for some reason, and both came back with no policies in effect.

    I've been able toggle the setting on/off in the registry at "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System" and changing "DisableAutomaticRestartSignOn", but the option itself is still grayed out and it defaults back after a restart, so it's effectively a one-time use.

    Be talked to MS support 3 times now and they all just checked the registry, gpedit, and wanted to reinstall Windows (which I did yet again with one of them), and waiting for a teir 2 agent to call but was told it could be up to 2 days.

    Does anybody have any ideas what's going on to test in the meantime? I've pretty much tried everything I could think of at this point.

    submitted by /u/Ashlander0
    [link] [comments]

    :)
     
    /u/Ashlander0, Jan 3, 2020
    #1
  2. Helmut Win User

    Block domain in Hotmail

    Not much you can do yourself, these domain names are faked and/or randomised intentionally.
    Sure, you can try by blocking a domain but almost instantly that will change and you are back to square one.

    You will find that your long list of blocked senders and domains will be totally useless in a very short time.
    Sad but true unfortunately.

    Fortunately the Mail providers filters are much more effective these days.

    What has worked for me, to some extent, is to severely limit where your Email Address(s) are known or exposed. Spammers have Software to auto-farm Email addresses from various sources.
     
    Helmut, Jan 3, 2020
    #2
  3. Block domain in Hotmail

    I've added icu.com to the blocked list but I'm still getting the junk.

    The junk mail is always in the format "L: [email protected]". The "xxx" is different in every message.

    I tried to add "*@*.icu.com" to the blocked list. (i.e. using wildcards) but got an error message telling me that the e-mail address was not formatted correctly.

    Did I need to add the domain icu.com differently so that everything gets blocked?
     
    dsscottage, Jan 3, 2020
    #3
  4. changari Win User

    Some settings blocked as of in a domain (I'm not in a domain)

    Raising the windows domain and forest issues?


    hi,

    I run a domain that was all 2003 r2 servers. I recently upgraded all my domain controllers to windows 2012 r2.
    That went off without any problems.. Our trust relationships had no issues also.

    My first step was to raise the Domain and Forest levels past 2003 to 2008. This went off without a hitch.
    These are the features for raising the levels to 2008:

    • Features and benefits include all default Active Directory features, all features from the Windows Server 2003 domain functional level, plus:
    • Read-Only Domain Controllers – Allows implementation of domain controllers that only host read-only copy of NTDS database.
    • Advanced Encryption Services – (AES 128 and 256) support for the Kerberos protocol.
    • Distributed File System Replication (DFSR) – Allows SYSVOL to replicate using DFSR instead of older File Replication Service (FRS). It provides more robust and detailed replication of SYSVOL contents.

    Forest Level Windows Server 2008

    • Features and benefits include all of the features that are available at the Windows Server 2003 forest functional level, but no additional features. All domains that are subsequently added to the forest will operate at the Windows Server 2008 domain functional level by default.


    My next step is to raise the domain and forest to 2008 r2, then 2012, and finally 2012 r2. I have been trying to find out exactly what I could expect from raising the Domain and Forest for each step.

    The step involving 2008 r2 seems relatively a non issue. But getting the couple of new features seem very nice

    Domain Level Windows Server 2008 R2

    • All default Active Directory features, all features from the Windows Server 2008 domain functional level, plus 2 new features

    Forest Level Windows Server 2008 R2

    • All of the features that are available at the Windows Server 2003 forest functional level, plus the following features:


    • Active Directory Recycle Bin, which provides the ability to restore deleted objects in their entirety while AD DS is running. <== New Feature very cool
    • All domains subsequently added to the forest will operate at the Windows Server 2008 R2 domain functional level by default.

    Here is my big concerns for the next raising of domain and forest to 2012.

    Forest Level Windows Server 2012:

    • All of the features that are available at the Windows Server 2008 R2 forest functional level, but no additional features.
    • All domains subsequently added to the forest will operate at the Windows Server 2012 domain functional level by default.

    Domain Level Windows Server 2012 R2: <=====
    Need to investigate more and why this post

    • DC-side protections for Protected Users. Protected Users authenticating to a Windows Server 2012 R2 domain can no longer:


    • Authenticate with NTLM authentication <==============(what issues may arise)
    • Use DES or RC4 cipher suites in Kerberos pre-authentication
    • Be delegated with unconstrained or constrained delegation
    • Renew user tickets (TGTs) beyond the initial 4-hour lifetime


    Will this affect my exchange anywhere users with remote access authenticating either clear of NTLM???
    and what would/may not to work properly day 1 when I raise the domain and forest to 2012. I cant really find anyone that can answer a straight question.

    Has anyone gone through this? what problems did you have, if any , if a lot???

    Any thoughts and suggestions will be much appreciated??

    thanks


    - - - Updated - - -

    One more point... I am not sure if I posted this to the correct forum.. So if I was wrong and it should be in a different one..
    PLEASE LET ME KNOW
     
    changari, Jan 3, 2020
    #4
Thema:

Some settings blocked as of in a domain (I'm not in a domain)

Loading...
  1. Some settings blocked as of in a domain (I'm not in a domain) - Similar Threads - settings blocked domain

  2. Demote Domain Controller blocked by Certificate

    in Windows 10 Gaming
    Demote Domain Controller blocked by Certificate: Moving 2012r2 Domain Controllers DC1 to new 2016 Domain Controllers DC01.Roles for DNS & DHCP are already removed and now trying to remove ADDC1 has Active Directory Certificate Services Role blocking me from Demoting the ServerHow do I proceed to move Schema Master and...
  3. Demote Domain Controller blocked by Certificate

    in Windows 10 Software and Apps
    Demote Domain Controller blocked by Certificate: Moving 2012r2 Domain Controllers DC1 to new 2016 Domain Controllers DC01.Roles for DNS & DHCP are already removed and now trying to remove ADDC1 has Active Directory Certificate Services Role blocking me from Demoting the ServerHow do I proceed to move Schema Master and...
  4. WDAG is blocking the domain users on the laptop.

    in Windows 10 Gaming
    WDAG is blocking the domain users on the laptop.: When I enable the service Microsoft Defender Application Guard on the laptop. It immediately blocks the domain users on the laptop and the desktop icons will go missing and the window will start behaving weirdly when logged on as domain user. And when I go and check the users...
  5. WDAG is blocking the domain users on the laptop.

    in Windows 10 Software and Apps
    WDAG is blocking the domain users on the laptop.: When I enable the service Microsoft Defender Application Guard on the laptop. It immediately blocks the domain users on the laptop and the desktop icons will go missing and the window will start behaving weirdly when logged on as domain user. And when I go and check the users...
  6. WDAG is blocking the domain users on the laptop.

    in AntiVirus, Firewalls and System Security
    WDAG is blocking the domain users on the laptop.: When I enable the service Microsoft Defender Application Guard on the laptop. It immediately blocks the domain users on the laptop and the desktop icons will go missing and the window will start behaving weirdly when logged on as domain user. And when I go and check the users...
  7. Some settings blocked as of in a domain (I'm not in a domain)

    in Windows 10 Ask Insider
    Some settings blocked as of in a domain (I'm not in a domain): I just got a new NVMe SSD so did a fresh windows reinstall on it, and used my 'old' SATA SSD for storage. After the install, updates, drivers, etc I noticed the option "Use my sign-in info to automatically finish setting up my device after an update or restart" on the...
  8. Block domain in Hotmail

    in Browsers and Email
    Block domain in Hotmail: I've recently started to receive many junk e-mail messages fro, L: [email protected] in my on line Hotmail account (at least 25.day). The "xxx" in every message is different. I've used the block option in Hotmail to block the specific sending e-mail address. However, every...
  9. domain and email blocked

    in Browsers and Email
    domain and email blocked: Hi guys I have my company email address which for some reason last week stopped working (can't connect to the server) on this laptop. My computer guy was at at a loss as all the settings were correct as nothing had been changed. He suggested try thunderbird, which also times...
  10. domain and email blocked

    in Windows 10 Support
    domain and email blocked: Hi guys I have my company email address which for some reason last week stopped working (can't connect to the server) on this laptop. My computer guy was at at a loss as all the settings were correct as nothing had been changed. He suggested try thunderbird, which also times...