Windows 10: WDAG is blocking the domain users on the laptop.

Discus and support WDAG is blocking the domain users on the laptop. in Windows 10 Gaming to solve the problem; When I enable the service Microsoft Defender Application Guard on the laptop. It immediately blocks the domain users on the laptop and the desktop... Discussion in 'Windows 10 Gaming' started by Renuka Audiraju, Aug 1, 2022.

  1. WDAG is blocking the domain users on the laptop.


    When I enable the service Microsoft Defender Application Guard on the laptop. It immediately blocks the domain users on the laptop and the desktop icons will go missing and the window will start behaving weirdly when logged on as domain user. And when I go and check the users on the laptop. I could see the Container user, Container Administrator and WDAGUtiliyAccount. The actual domain user won't appear here.Where as If I login as the Local Administrator. I won't see any issues. Can someone help me with this as I have been go through this issues with all the new version of Dell Latitude 7430

    :)
     
    Renuka Audiraju, Aug 1, 2022
    #1

  2. Block domain in Hotmail

    I've added icu.com to the blocked list but I'm still getting the junk.

    The junk mail is always in the format "L: [email protected]". The "xxx" is different in every message.

    I tried to add "*@*.icu.com" to the blocked list. (i.e. using wildcards) but got an error message telling me that the e-mail address was not formatted correctly.

    Did I need to add the domain icu.com differently so that everything gets blocked?
     
    dsscottage, Aug 1, 2022
    #2
  3. changari Win User
    Raising the windows domain and forest issues?


    hi,

    I run a domain that was all 2003 r2 servers. I recently upgraded all my domain controllers to windows 2012 r2.
    That went off without any problems.. Our trust relationships had no issues also.

    My first step was to raise the Domain and Forest levels past 2003 to 2008. This went off without a hitch.
    These are the features for raising the levels to 2008:

    • Features and benefits include all default Active Directory features, all features from the Windows Server 2003 domain functional level, plus:
    • Read-Only Domain Controllers – Allows implementation of domain controllers that only host read-only copy of NTDS database.
    • Advanced Encryption Services – (AES 128 and 256) support for the Kerberos protocol.
    • Distributed File System Replication (DFSR) – Allows SYSVOL to replicate using DFSR instead of older File Replication Service (FRS). It provides more robust and detailed replication of SYSVOL contents.

    Forest Level Windows Server 2008

    • Features and benefits include all of the features that are available at the Windows Server 2003 forest functional level, but no additional features. All domains that are subsequently added to the forest will operate at the Windows Server 2008 domain functional level by default.


    My next step is to raise the domain and forest to 2008 r2, then 2012, and finally 2012 r2. I have been trying to find out exactly what I could expect from raising the Domain and Forest for each step.

    The step involving 2008 r2 seems relatively a non issue. But getting the couple of new features seem very nice

    Domain Level Windows Server 2008 R2

    • All default Active Directory features, all features from the Windows Server 2008 domain functional level, plus 2 new features

    Forest Level Windows Server 2008 R2

    • All of the features that are available at the Windows Server 2003 forest functional level, plus the following features:


    • Active Directory Recycle Bin, which provides the ability to restore deleted objects in their entirety while AD DS is running. <== New Feature very cool
    • All domains subsequently added to the forest will operate at the Windows Server 2008 R2 domain functional level by default.

    Here is my big concerns for the next raising of domain and forest to 2012.

    Forest Level Windows Server 2012:

    • All of the features that are available at the Windows Server 2008 R2 forest functional level, but no additional features.
    • All domains subsequently added to the forest will operate at the Windows Server 2012 domain functional level by default.

    Domain Level Windows Server 2012 R2: <=====
    Need to investigate more and why this post

    • DC-side protections for Protected Users. Protected Users authenticating to a Windows Server 2012 R2 domain can no longer:


    • Authenticate with NTLM authentication <==============(what issues may arise)
    • Use DES or RC4 cipher suites in Kerberos pre-authentication
    • Be delegated with unconstrained or constrained delegation
    • Renew user tickets (TGTs) beyond the initial 4-hour lifetime


    Will this affect my exchange anywhere users with remote access authenticating either clear of NTLM???
    and what would/may not to work properly day 1 when I raise the domain and forest to 2012. I cant really find anyone that can answer a straight question.

    Has anyone gone through this? what problems did you have, if any , if a lot???

    Any thoughts and suggestions will be much appreciated??

    thanks


    - - - Updated - - -

    One more point... I am not sure if I posted this to the correct forum.. So if I was wrong and it should be in a different one..
    PLEASE LET ME KNOW
     
    changari, Aug 1, 2022
    #3
  4. bdanmo Win User

    WDAG is blocking the domain users on the laptop.

    UnattendedJoin error: failed to find the domain data (0x6e)

    Thanks for the suggestion! I don't want to add a domain account, as this is a generic unattended install that will be used for all company machines. Do you think it's possible that the computer would join the domain if, instead of using UnattendedJoin in specialize, I used your steps but left out the specific account?

    The other thing I was thinking was to use a generic account to allow the domain join during the specialize step. I added a machine password in the UnattendedJoin component, and instead of getting the error listed above, I got an authentication error, which makes me think I could probably do a secure join instead of the unsecure join.

    Thoughts?
     
    bdanmo, Aug 1, 2022
    #4
Thema:

WDAG is blocking the domain users on the laptop.

Loading...
  1. WDAG is blocking the domain users on the laptop. - Similar Threads - WDAG blocking domain

  2. WDAG is blocking the domain users on the laptop.

    in Windows 10 Software and Apps
    WDAG is blocking the domain users on the laptop.: When I enable the service Microsoft Defender Application Guard on the laptop. It immediately blocks the domain users on the laptop and the desktop icons will go missing and the window will start behaving weirdly when logged on as domain user. And when I go and check the users...
  3. WDAG is blocking the domain users on the laptop.

    in AntiVirus, Firewalls and System Security
    WDAG is blocking the domain users on the laptop.: When I enable the service Microsoft Defender Application Guard on the laptop. It immediately blocks the domain users on the laptop and the desktop icons will go missing and the window will start behaving weirdly when logged on as domain user. And when I go and check the users...
  4. User@Domain / Domain\User problem

    in Windows 10 Ask Insider
    User@Domain / Domain\User problem: So I was checking my Windows 10 computer and saw that there was no domain, it was in a WORKGROUP. I needed to use the format "User@Domain" or "Domain\User" for something, and I do not know what to put. The username is just "User" and there is no password. submitted by...
  5. Some settings blocked as of in a domain (I'm not in a domain)

    in Windows 10 Ask Insider
    Some settings blocked as of in a domain (I'm not in a domain): I just got a new NVMe SSD so did a fresh windows reinstall on it, and used my 'old' SATA SSD for storage. After the install, updates, drivers, etc I noticed the option "Use my sign-in info to automatically finish setting up my device after an update or restart" on the...
  6. Block domain in Hotmail

    in Browsers and Email
    Block domain in Hotmail: I've recently started to receive many junk e-mail messages fro, L: [email protected] in my on line Hotmail account (at least 25.day). The "xxx" in every message is different. I've used the block option in Hotmail to block the specific sending e-mail address. However, every...
  7. Sandbox/WDAG not opening on domain-connected machine

    in AntiVirus, Firewalls and System Security
    Sandbox/WDAG not opening on domain-connected machine: I have noticed that if I try to launch Windows Sandbox OR Windows Defender Application Guard on a machine that is connected to our domain it will not launch. However, if the machine stays off or leaves the domain these features return back to normal. When connected to the...
  8. domain and email blocked

    in Browsers and Email
    domain and email blocked: Hi guys I have my company email address which for some reason last week stopped working (can't connect to the server) on this laptop. My computer guy was at at a loss as all the settings were correct as nothing had been changed. He suggested try thunderbird, which also times...
  9. domain and email blocked

    in Windows 10 Support
    domain and email blocked: Hi guys I have my company email address which for some reason last week stopped working (can't connect to the server) on this laptop. My computer guy was at at a loss as all the settings were correct as nothing had been changed. He suggested try thunderbird, which also times...
  10. Domain users?

    in Windows 10 Installation and Upgrade
    Domain users?: Our company has about 40 Laptops that all have windows 7 on them. Since they are all connected to our domain the GWX app will not appear on any. Would running the upgrade from a WIN 10 DVD activate properly? 9968